EMAExecution MethodologyRegulationHIGH INSPECTION RISK
EU GMP Annex 11

Computerised Systems

Establishes requirements for computerised systems used in GxP-regulated activities. Covers validation, data integrity, access control, audit trails, and disaster recovery. The EU counterpart to FDA 21 CFR Part 11.

LAST REVISED
June 2011
PRODUCT AREAS
SterileSolid DoseBiotechApi

What this does not cover

stated in the document's own scope
  • Covers computerised systems within GMP activities; it is not itself a validation methodology, a role filled by GAMP 5.
  • Addresses systems used in manufacturing and quality; qualification of the underlying equipment and utilities is the subject of Annex 15.
  • Sets EU GMP expectations for electronic records and signatures, not the separate US regulation 21 CFR Part 11.
  • Concerns record and system integrity in GMP, not the pharmacovigilance or clinical-data systems governed by GVP and the Clinical Trials Regulation.
SOURCE & PROVENANCE
ISSUING BODY
European Medicines Agency
JURISDICTION
European Union
DOCUMENT ID
EU GMP Annex 11
EDITION
2011
EFFECTIVE
30 Jun 2011
SPEQ REVIEWED
Aug 2026
Official source document

Always verify against the current published text before relying on it for a submission or inspection.

Overview

EU GMP Annex 11, "Computerised Systems", is the guidance that governs computerised systems used as part of GMP-regulated activities — anything from a chromatography data system or a manufacturing execution system to a spreadsheet used to make a GMP decision. It sets expectations across the system lifecycle: risk management, supplier and service-provider arrangements, validation, data storage and integrity, audit trails, electronic signatures, access control, change and configuration management, incident handling, business continuity and archiving. Its guiding principle is that introducing a computerised system must not reduce product quality, process control or quality assurance below what the manual process delivered.

Scope & applicability

All GxP computerised systems in EU-regulated facilities including LIMS, DCS, SCADA, MES, ERP modules used for GxP purposes, and QMS software.

Legal basis & how it acquires force

Annex 11 forms part of Volume 4 of EudraLex, the EU GMP Guide, and interprets the GMP requirements that the EU GMP Directives place on holders of a manufacturing authorisation. Like the other annexes it is guidance rather than a stand-alone regulation, but adherence is a condition of the manufacturing authorisation and it is read alongside Chapter 4 (Documentation) of the main guide. The current version took effect on 30 June 2011; a substantial revision has been under public consultation to reflect data-integrity thinking, cloud services and emerging technologies.

Document structure

PartCovers
Principle and generalRisk management, personnel, and suppliers/service providers across the lifecycle
Project phase — validationValidation documentation, the system inventory, and requirements traceability
Operational phase — dataAccuracy checks, data storage, and protection of records against damage or loss
Audit trails and signaturesGeneration and review of audit trails and the use of electronic signatures
Access, change and incident controlSecurity and access management, change and configuration control, and incident handling
Continuity and archivingBusiness continuity, periodic evaluation, and archiving with retrieval capability

Key requirements

  • Risk-based approach to validation — system inventory with GxP impact assessment
  • Supplier assessment and ongoing monitoring for commercial off-the-shelf (COTS) systems
  • Validation documentation: URS, FS, CS, IQ, OQ, PQ with traceability matrix
  • Data integrity controls: access management, audit trails, backup/restore procedures
  • Change management — all changes go through formal change control with impact assessment
  • Periodic review of validated systems — evidence of continuing validated state

Implementation tips

  • Maintain a GxP system inventory with impact classification — this is the audit starting point
  • Supplier qualification for SaaS/cloud systems needs specific clauses: data ownership, audit rights, incident notification
  • Audit trail review frequency must be documented in your data governance procedure

Revision notes

The June 2011 version remains the current text. The revision is no longer merely expected: a draft was published 7 July 2025 and consulted alongside Chapter 4 (Documentation) and the new Annex 22 (Artificial Intelligence); that consultation closed 7 October 2025 and no final text has been published as of 4 September 2026. ISPE GAMP 5 (2022) remains the primary implementation reference.

CHECKING ACCESS

Checking your Professional access…

Where this control fails

live FDA enforcement
See all FDA enforcement →

Live FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.

International alignment

Annex 11 is the EU counterpart to the US electronic-records and electronic-signatures rule, 21 CFR Part 11, and the two are typically implemented together for global systems. In practice it is applied alongside the GAMP 5 methodology for risk-based computerised-system validation and the PIC/S PI 041 data-integrity guidance, which share its ALCOA data-integrity framing. It supports, rather than duplicates, the data-integrity expectations already implicit in GMP.

EU GMP Annex 11: frequently asked questions

Quick answers to common questions about EU GMP Annex 11.

What is EU GMP Annex 11 the counterpart of?

Annex 11 is the EU GMP guidance on computerised systems, and it is the counterpart of the US FDA rule 21 CFR Part 11 on electronic records and electronic signatures. Systems serving both markets are usually built to satisfy both texts.

Does Annex 11 require validation of spreadsheets?

Annex 11 applies to any computerised system that forms part of a GMP activity, and its scope explicitly extends to systems as simple as a spreadsheet where that spreadsheet is used to make or support a GMP decision. The extent of validation is risk-based.

When did the current Annex 11 take effect?

The current version of Annex 11 became effective on 30 June 2011. A revision has since been through public consultation to modernise it for data integrity, cloud computing and newer technologies.