EMA

European Medicines Agency

European UnionEuropeNational / regional regulator

EU agency coordinating scientific evaluation and GMP/GVP guidance across member-state authorities.

What this page does not claim

SPEQ curates and cross-references these bodies. It is not affiliated with, accredited by, or endorsed by any of them, and a count of decoded standards is a measure of SPEQ’s coverage, not of a body’s importance.

WHAT EMA COVERS

The European Medicines Agency is the EU’s scientific agency for human and veterinary medicines. It coordinates evaluation and safety monitoring across the Union, most visibly through the centralised authorisation procedure that produces a single marketing authorisation valid in all member states. Its scientific committees — CHMP for human medicines, PRAC for pharmacovigilance risk, CVMP for veterinary — do the assessment work.

WHAT EMA PUBLISHES

  1. 01Scientific guidelines and reflection papers for human and veterinary medicines
  2. 02Good Pharmacovigilance Practices (GVP) Modules I–XVI
  3. 03European Public Assessment Reports (EPARs) for authorised products
  4. 04EudraGMDP entries — GMP/GDP certificates and non-compliance reports
  5. 05Q&A documents that often carry the practical detail behind a guideline

HOW ITS REQUIREMENTS BITE

EMA is a coordinating agency, not an inspectorate: GMP and GCP inspections are performed by the national competent authorities of the member states, and EMA coordinates them, maintains the shared EudraGMDP database of certificates and non-compliance reports, and manages EudraVigilance for safety data. Legal decisions on centralised authorisations are taken by the European Commission on EMA’s scientific opinion.

What practitioners get wrong

  • EMA does not inspect — member-state authorities do; a "EMA inspection" is really a national inspection coordinated through EMA.
  • EMA gives a scientific opinion; the legally binding decision on a centralised authorisation is the European Commission’s.
  • GMP text itself is published by the Commission in EudraLex Volume 4, not by EMA.
  • EudraGMDP is the public record of who holds a valid GMP certificate — and who has a non-compliance report.
PROFESSIONAL · INSPECTION INTELLIGENCE · SPEQ SYNTHESIS

What an inspection under this authority actually probes

CHECKING ACCESS

Checking your Professional access…

WHERE IT SITS INTERNATIONALLY

EMA is an ICH member, and EU authorities are founding participants in PIC/S. The EU-US Mutual Recognition Agreement allows reliance on each other’s GMP inspections for many human medicines, reducing duplicate inspection of the same site.

EMA STANDARDS SPEQ DECODES · 11

DISCIPLINES IN EMA’S REMIT

TOPIC EXPLAINERS CITING EMA STANDARDS
Data Integrity & ALCOA+
ALCOA+, the data lifecycle, and why integrity is the foundation every GxP claim rests on.
Computer System Validation & CSA
GAMP 5, the risk-based lifecycle, Part 11, and the shift from documentation to critical thinking (CSA).
Contamination Control & Annex 1
The Contamination Control Strategy, cleanroom classification, and the 2022 Annex 1 revision.
Process Validation Lifecycle
The three-stage lifecycle — design, qualification, continued verification — and the science behind it.
Cleaning Validation
Documented proof that cleaning removes residues below health-based limits — HBEL/PDE, MACO, and the shift from arbitrary limits.
Technology Transfer
Moving a validated process between sites without losing control — the sending/receiving-unit model, knowledge transfer, and comparability.
Media Fill & Aseptic Process Simulation
How aseptic process simulation validates that a sterile process keeps product sterile — design, acceptance criteria, and the interventions that decide the result.
Master Batch Record (MBR) & Batch Production Records
The approved manufacturing template and the contemporaneous execution record — 21 CFR 211.186/211.188, EU GMP Chapter 4, and the move to electronic batch records.
RABS & Isolators — Aseptic Barrier Systems
How restricted access barrier systems and isolators separate operators from the sterile core — open vs closed RABS, isolators, and what EU GMP Annex 1 now expects.
Pharmacovigilance Signal Management
How a safety signal is detected, validated, assessed, and acted on — the GVP process that turns individual case reports into a change to a medicine’s benefit-risk balance.
Informed Consent & Ethics Oversight
The two structural safeguards that make a clinical trial ethical — independent ethics review before it starts, and a genuine informed-consent process for every participant — and why consent is a process, not a signature.
Commissioning & Qualification (C&Q)
The risk- and science-based approach to proving a facility, utility, or piece of equipment is fit for GMP use — and how ASTM E2500 replaced "qualify everything" with "verify what matters to the patient".
Periodic Safety Reporting: PSURs & PBRERs
The scheduled aggregate safety reports through which a marketing-authorisation holder periodically re-evaluates a medicine’s benefit-risk balance — the periodic complement to continuous signal management.
Audit Trail Review
Having an audit trail is not reviewing it — the distinction regulators built an entire enforcement wave on, and how a risk-based review finds the deleted run instead of drowning in keystrokes.
Equipment Qualification (IQ / OQ / PQ)
What DQ, IQ, OQ, and PQ each actually prove, why USP <1058> qualifies a lab instrument differently from a mixer, and how the classical four-stage model relates to the risk-based C&Q approach.
Environmental Monitoring (EM)
The programme that proves a cleanroom’s controlled state actually holds during production — viable and non-viable, why a single Grade A recovery is not a normal result, and the alert-vs-action-limit distinction people get wrong.
ICSRs & Expedited Reporting
The atomic unit of pharmacovigilance and the clock attached to it — the four things that make a case valid, why "serious" is not "severe", and what actually triggers a 15-day report.
QPPV & the Pharmacovigilance System Master File
The named human who is personally accountable for a company’s safety system, and the single document that describes it — why the EU built pharmacovigilance around a person and a map, not just processes.
Sponsor Oversight of Clinical Trials
A sponsor can outsource the work of a trial to a CRO but never the responsibility for it — what real oversight looks like beyond signing a contract, and what ICH E6(R3) changed.
Protocol Deviations & Serious Breaches
Deviation → important deviation → serious breach looks like one escalating ladder. It is not — a serious breach is a different axis with a statutory reporting clock, and a systemic GCP failure with no protocol departure can be one.
The Trial Master File (TMF) & TMF Reference Model
The document set that lets a trial be reconstructed and its GCP compliance proven — why "the TMF was complete at the end" misses the point, and who actually stewards the Reference Model now.
Pharmaceutical Water & WFI
Water is the most-used ingredient in pharma and it cannot be released like an ingredient — the system is validated and monitored so the water is trusted as it is used, and why WFI is a category apart.
Extractables & Leachables (E&L)
Extractables are what a container could release under stress; leachables are what actually migrates into the product in real life — and confusing the two is why E&L programs over- or under-test.
Container Closure Integrity (CCI)
The sterile barrier has to hold for the whole shelf life, not just pass a test at release — why modern CCI is a deterministic, validated measurement and the 2022 Annex 1 pushed it past the dye-bath.
Literature Monitoring in Pharmacovigilance
The scientific literature is a legally-mandated source of adverse-event cases — a systematic, documented search with defined databases and a weekly rhythm, not an occasional look.
RMP vs REMS: EU & US Risk Management
The EU requires a risk management plan for essentially every new medicine; the US imposes a REMS only when a specific safety problem demands it — a default-on system versus an exception-based one.
ATMPs: Cell & Gene Therapy Manufacturing
When the batch is one patient, the process is the product, and starting material is a living donation, the classical GMP model bends — why advanced therapies needed their own rulebook.
EU GMP Annex 11 (2025 Revision)
The draft revision of the EU GMP computerised-systems annex — lifecycle validation, data integrity, cloud, AI, and cybersecurity as a core GMP requirement.
Decentralized Clinical Trials
How DCT elements — remote visits, telehealth, DTP shipping and eConsent — fit the GCP quality-by-design framework.
AI/ML Validation in GxP
Validating machine-learning and AI systems in regulated environments — data provenance, model lifecycle, and the static-vs-adaptive distinction.
Viral Safety (ICH Q5A)
The three-pillar viral-safety framework for biotech products — cell-line testing, raw-material control, and validated clearance.
Annex 15: Qualification & Validation
The EU GMP framework for qualification and validation — URS through PQ, the V-model, and its ASTM E2500 relationship.
Parametric Release
Releasing terminally sterilized product on validated process data instead of the sterility test — when it is permitted and what it demands.
Lyophilization (Freeze-Drying)
Sterile freeze-drying — the process, its critical parameters, and the aseptic and validation controls that govern it.
Single-Use Systems
Disposable process equipment in biomanufacturing — extractables/leachables, integrity, and supply-chain qualification.
Rapid Microbiological Methods
Faster alternatives to growth-based micro testing — how RMMs work, and how to validate them against the compendial method.
Continued Process Verification
Stage 3 of process validation — ongoing monitoring, trending and statistical control that proves the process stays validated.
Contemporaneous Recording
The "C" in ALCOA — recording at the time of the activity — and why deferred entries are a data-integrity finding.
Correcting GxP Records
How to change a GxP record defensibly — single-line strike-through, reason, initials, date — on paper and in electronic systems.
The EU Risk Management Plan (RMP)
The structure of the EU-RMP — safety specification, pharmacovigilance plan, risk-minimisation — and how it evolves across a product’s life.
Additional Monitoring & Black Triangle
The inverted black triangle, the EU additional-monitoring list, and why "▼" means report every suspected reaction.
PV Audits & Inspections
How the PV system is assured — risk-based internal audit, the CAPA loop, and what a GVP inspection actually examines.
GEP: Engineering Behind Qualification
The engineering foundation beneath qualification — science- and risk-based design, documentation, and the GEP/GxP boundary.
Aseptic Processing
How sterile drug products are filled and assembled without a terminal sterilization step, and the contamination controls that make it possible.
Sterilization Methods Overview
A comparative map of the sterilization technologies used across sterile manufacturing — moist heat, dry heat, filtration, irradiation, and gas — and how a manufacturer chooses among them.
Moist Heat Sterilization
How saturated steam autoclave cycles are designed, qualified, and monitored to deliver a validated sterility assurance level.
Depyrogenation
Removing or inactivating bacterial endotoxin from containers, components, and equipment surfaces before they meet a sterile product.
Bacterial Endotoxins Test
The LAL-based assay used to detect and quantify bacterial endotoxin in parenteral products, water systems, and components.
Sterility Testing
The compendial test used to verify the absence of viable microorganisms in a sterile product batch, and why a pass does not prove sterility assurance.
Visual Inspection & Particulates
The 100% and statistical inspection programs that catch visible particulate matter and container defects before a sterile product is released.
Disinfectant Efficacy Qualification
How cleanroom disinfectants are selected, rotated, and proven — against real surfaces and real organisms — to actually reduce bioburden.
Aseptic Gowning & Technique
How personnel are qualified to enter classified aseptic environments without becoming the contamination source they are being protected from.
Cleanroom HVAC Qualification
How the air handling systems behind ISO-classified cleanrooms are designed, commissioned, and qualified to hold their classification under real operating conditions.
Personnel & Viable Monitoring
The gloved-finger, gown-surface, and viable air sampling program that tracks whether personnel are staying within their qualified contamination limits.
Pure Steam & Clean Utilities
The generation, distribution, and qualification of pure steam, clean compressed gases, and other utilities that touch sterile product or product-contact surfaces.
Filter Integrity Testing
The non-destructive tests — bubble point, diffusive flow, and pressure hold — that confirm a sterilizing-grade filter actually retained its rated bacterial challenge.
Blow-Fill-Seal
The advanced aseptic technology that extrudes, fills, and seals a plastic container in one continuous, largely automated cycle.
Isolator Decontamination (VHP)
How vaporized hydrogen peroxide cycles are developed and validated to decontaminate isolator and RABS interiors between aseptic campaigns.
Real-Time Release Testing
Releasing a batch based on validated in-process monitoring and process data, in place of or alongside finished-product laboratory testing.
GAMP 5 Software Categories
The risk-based classification scheme, from GAMP 5, that determines how much validation effort a given piece of GxP software actually needs.
21 CFR Part 11 — Electronic Records and Signatures
The FDA rule setting the criteria under which electronic records and electronic signatures are considered equivalent to paper records and handwritten signatures.
OT & ICS Security in Regulated Manufacturing
Securing the PLCs, DCS, SCADA and historians that run regulated production — where availability outranks confidentiality and a patch is a change.
Software Supply-Chain Security & SBOM
Third-party components, software bills of materials, vulnerability intake, and supplier assurance for the software a regulated organisation did not write.
Identity & Access Management in GxP Systems
Unique identity, authority checks, segregation of duties, privileged access and periodic review — the controls that make a GxP record attributable.
Cyber Incident Response for Regulated Records
What happens to GxP records, batch disposition and reporting clocks when a security incident lands — and why containment is only half the response.
Cybersecurity Governance in Regulated Organisations
Who owns cyber risk, what residual risk the business has actually accepted, and how an ISMS meets a pharmaceutical quality system.
Asset Inventory & Attack Surface
Every other control depends on knowing what exists — and in regulated manufacturing the forgotten assets are the ones connected to production.
Data Privacy & Protection in GxP Environments
Where GDPR meets GxP record-keeping — the retention-versus-erasure conflict, health data as a special category, and encryption that survives an audit trail.
Network, Cloud & Endpoint Security for GxP Systems
Segmentation as the control that stops an ordinary compromise becoming a production outage — plus cloud responsibility and endpoints that cannot be touched.
Third-Party Cyber Risk in Regulated Supply
Suppliers hold credentials into the estate and copies of regulated data — and concentration is the risk that appears on nobody’s register.
Vulnerability & Patch Management Under Change Control
Most compromises exploit something known and unpatched — and in validated environments the window between disclosure and remediation is structurally wider.
Business Continuity & Recovery
Ransomware made recovery the primary control — and in regulated manufacturing a system that is running again is not yet back in a validated state.
Security Awareness & Human Factors in GxP
People are the most-attacked control and the fastest detector — and which one dominates depends entirely on whether reporting a mistake is safe.
Automation Strategy & Architecture
Architecture decides what can be changed independently later — which is why obsolete control systems stay in service past the point of support.
Process Instrumentation & Measurement
Every control action and recorded value begins at an instrument — and a correctly calibrated one can still be wrongly installed.
Alarm Management & Safety Instrumented Systems
An alarm asks a person to act; a safety instrumented function acts itself. Collapsing the two removes the independence the risk assessment assumed.
Automation Lifecycle & Support
Control systems outlive the projects that install them and the people who configured them — support arrangements made at handover decide year eight.
Management Accountability & Decision Rights
Regulators hold an organisation to decisions, not intentions — and "everyone assumed someone else had checked" is a decision-rights failure.
Manufacturing Strategy & Operating Model
Campaign or dedicated, in-house or contract — each model concentrates a different risk, and the control burden follows the choice.
Operational Readiness, Startup & Ramp-Up
The deviation rate during ramp-up is the highest the process will ever see — and that is the clearest information about it anyone will get.
Requirements Traceability & Critical Aspects
Traceability converts a stack of test results into an argument — that the testing covered what mattered, which is the question actually asked.
Control System Assurance
Where a small configuration change has a direct physical consequence — and can be made by someone whose role is not framed as regulated.
Maintaining the Validated State
Validation is a claim about the present, maintained by work nobody sees — and most loss of validated state is cumulative and undramatic.
Process Characterisation & Design Space
Process understanding is what makes validation an argument rather than a demonstration.
Site Feasibility, Startup & Management
Sites are where the protocol meets reality — and a site activated before it is ready produces the deviations that consume the study.
Study Closeout & Results Disclosure
Disclosure obligations are legal duties with deadlines, enforced independently of how the trial went.
Safety Governance & Benefit-Risk
Benefit-risk changes as evidence accumulates — and where safety governance reports into commercial ownership, the structure itself is a finding.
Postauthorisation Studies & Real-World Evidence
Real-world data were collected for another purpose — whether they can support the question is a judgement that must be made explicitly.
Medical Information & Inquiry Handling
A high-volume front door through which adverse events and complaints arrive disguised as questions.
Safety Systems & Partner Data Exchange
Every exchange with a partner is a place a case can be delayed or lost — and reconciliation only works if it is periodic and two-way.
Quality & Technical Agreements
It decides who does what when something goes wrong — written while nothing has.
Procurement & Contracting for Regulated Supply
Procurement decisions create quality obligations that quality did not negotiate.
Workforce Planning & Critical Skills
Qualification takes months, so staffing gaps cannot be closed at the speed they open.
Learning, Training & Effectiveness
Retraining a person who already knew the procedure addresses nothing — effectiveness evaluation is what separates a capability gap from a convenient CAPA.
Organisational Change & Adoption
A change implemented but not adopted prohibits the old way without establishing the new one — and people improvise in the gap.
Network, Capacity & Capital Strategy
Capacity that is technically available but concentrated in one site is a supply risk no downstream quality work can offset.
Facility & Process Design
A cross-flow designed in is a permanent procedural burden — mitigated forever by people rather than by geometry.
Construction, Installation & Field Quality
Qualification verifies what exists, not what was drawn — and an unreliable as-built record poisons every later change.
Systems Completion & Turnover
Turnover is the moment accountability moves — declared with open items, qualification begins on an asset nobody can fully describe.
Laboratory Network & Operating Model
Testing scattered across laboratories with different quality systems produces results that are individually defensible and collectively inconsistent.
Sampling Plans, Specifications & Standards
A result describes the sample — and the sample describes the batch only if the plan makes it representative.
Metrology & Calibration Management
A calibration failure is retrospective by nature — which is why the as-found condition matters more than the as-left one.
Digital Strategy & Application Portfolio
Regulated organisations accumulate systems faster than they retire them, and each carries a validation obligation for life.
Integration & Interoperability for GxP Data
Errors here are silent by construction — a successful transfer looks identical to a correct one.
Platforms, Cloud & Infrastructure for GxP
Moving to a managed platform moves the work, not the accountability.
Analytics & Decision Support in GxP
Self-service lets a good question be answered quickly and lets a wrong metric spread before anyone checks it.
Records, Content & Retrieval
A record that cannot be found within the time an inspection allows is functionally missing.
Digital Service Management in Regulated Operations
The validated state is maintained or lost in routine service management, not in projects.
Capital Planning & Project Economics
Contingency cut at approval reappears as scope reduction during execution — and the scope cut is usually qualification and spares.
Occupational Safety in Regulated Manufacturing
Personal protection and product protection are the same gowning decision made for two reasons — and they can conflict.
Biosafety & Biological Containment
Containment protects people from the product; cleanroom design protects the product from people — and they impose opposite pressure regimes.
Potent Compounds & Specialised Hazards
One toxicological assessment, two obligations — the limits driving cleaning validation and containment come from the same work.
Environmental Compliance & Permits
A permit breach can stop production as effectively as a quality event — and pharmaceutical effluent carries specific scrutiny.
Sustainability in Regulated Operations
Every meaningful sustainability change in a regulated plant is a GMP change — and public claims are now regulated in their own right.
Physical Security & Site Protection
Someone in the room can defeat most logical controls — and controlled substances carry federally prescribed security, not risk-based security.
Emergency Management & Crisis Response
An evacuation that abandons a batch mid-process creates a quality decision — far easier to make if it was anticipated.
Construction & Contractor Safety on Live Sites
The activity that endangers a worker — a breached wall, an isolation, hot work — is the one that threatens the area beside it.

EMA: frequently asked questions

Reference answers on European Medicines Agency’s mandate, what it publishes, and how its requirements acquire force.

Does the EMA inspect manufacturers?

No. EMA is a coordinating agency, not an inspectorate. GMP and GCP inspections are performed by the national competent authorities of the member states; EMA coordinates them and maintains the shared EudraGMDP database of certificates and non-compliance reports. An "EMA inspection" is really a national inspection coordinated through EMA.

Who takes the legal decision on a centralised marketing authorisation?

EMA gives a scientific opinion through committees such as the CHMP; the legally binding decision on a centralised authorisation is taken by the European Commission on that opinion. The result is a single marketing authorisation valid in all EU member states.

Where is EU GMP text published?

Not by EMA. GMP text itself is published by the European Commission in EudraLex Volume 4. EMA publishes scientific guidelines, Good Pharmacovigilance Practices modules, European Public Assessment Reports, and EudraGMDP entries.