Computerised Systems
Establishes requirements for computerised systems used in GxP-regulated activities. Covers validation, data integrity, access control, audit trails, and disaster recovery. The EU counterpart to FDA 21 CFR Part 11.
What this does not cover
stated in the document's own scope- Covers computerised systems within GMP activities; it is not itself a validation methodology, a role filled by GAMP 5.
- Addresses systems used in manufacturing and quality; qualification of the underlying equipment and utilities is the subject of Annex 15.
- Sets EU GMP expectations for electronic records and signatures, not the separate US regulation 21 CFR Part 11.
- Concerns record and system integrity in GMP, not the pharmacovigilance or clinical-data systems governed by GVP and the Clinical Trials Regulation.
Always verify against the current published text before relying on it for a submission or inspection.
Overview
EU GMP Annex 11, "Computerised Systems", is the guidance that governs computerised systems used as part of GMP-regulated activities — anything from a chromatography data system or a manufacturing execution system to a spreadsheet used to make a GMP decision. It sets expectations across the system lifecycle: risk management, supplier and service-provider arrangements, validation, data storage and integrity, audit trails, electronic signatures, access control, change and configuration management, incident handling, business continuity and archiving. Its guiding principle is that introducing a computerised system must not reduce product quality, process control or quality assurance below what the manual process delivered.
Scope & applicability
All GxP computerised systems in EU-regulated facilities including LIMS, DCS, SCADA, MES, ERP modules used for GxP purposes, and QMS software.
Legal basis & how it acquires force
Annex 11 forms part of Volume 4 of EudraLex, the EU GMP Guide, and interprets the GMP requirements that the EU GMP Directives place on holders of a manufacturing authorisation. Like the other annexes it is guidance rather than a stand-alone regulation, but adherence is a condition of the manufacturing authorisation and it is read alongside Chapter 4 (Documentation) of the main guide. The current version took effect on 30 June 2011; a substantial revision has been under public consultation to reflect data-integrity thinking, cloud services and emerging technologies.
Document structure
| Part | Covers |
|---|---|
| Principle and general | Risk management, personnel, and suppliers/service providers across the lifecycle |
| Project phase — validation | Validation documentation, the system inventory, and requirements traceability |
| Operational phase — data | Accuracy checks, data storage, and protection of records against damage or loss |
| Audit trails and signatures | Generation and review of audit trails and the use of electronic signatures |
| Access, change and incident control | Security and access management, change and configuration control, and incident handling |
| Continuity and archiving | Business continuity, periodic evaluation, and archiving with retrieval capability |
Key requirements
- Risk-based approach to validation — system inventory with GxP impact assessment
- Supplier assessment and ongoing monitoring for commercial off-the-shelf (COTS) systems
- Validation documentation: URS, FS, CS, IQ, OQ, PQ with traceability matrix
- Data integrity controls: access management, audit trails, backup/restore procedures
- Change management — all changes go through formal change control with impact assessment
- Periodic review of validated systems — evidence of continuing validated state
Implementation tips
- Maintain a GxP system inventory with impact classification — this is the audit starting point
- Supplier qualification for SaaS/cloud systems needs specific clauses: data ownership, audit rights, incident notification
- Audit trail review frequency must be documented in your data governance procedure
Revision notes
The June 2011 version remains the current text. The revision is no longer merely expected: a draft was published 7 July 2025 and consulted alongside Chapter 4 (Documentation) and the new Annex 22 (Artificial Intelligence); that consultation closed 7 October 2025 and no final text has been published as of 4 September 2026. ISPE GAMP 5 (2022) remains the primary implementation reference.
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
International alignment
Annex 11 is the EU counterpart to the US electronic-records and electronic-signatures rule, 21 CFR Part 11, and the two are typically implemented together for global systems. In practice it is applied alongside the GAMP 5 methodology for risk-based computerised-system validation and the PIC/S PI 041 data-integrity guidance, which share its ALCOA data-integrity framing. It supports, rather than duplicates, the data-integrity expectations already implicit in GMP.
EU GMP Annex 11: frequently asked questions
Quick answers to common questions about EU GMP Annex 11.
What is EU GMP Annex 11 the counterpart of?
Annex 11 is the EU GMP guidance on computerised systems, and it is the counterpart of the US FDA rule 21 CFR Part 11 on electronic records and electronic signatures. Systems serving both markets are usually built to satisfy both texts.
Does Annex 11 require validation of spreadsheets?
Annex 11 applies to any computerised system that forms part of a GMP activity, and its scope explicitly extends to systems as simple as a spreadsheet where that spreadsheet is used to make or support a GMP decision. The extent of validation is risk-based.
When did the current Annex 11 take effect?
The current version of Annex 11 became effective on 30 June 2011. A revision has since been through public consultation to modernise it for data integrity, cloud computing and newer technologies.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.