Application of GLP Principles to Computerised Systems
The OECD advisory document that applies the GLP Principles to computerised systems used in non-clinical health and environmental safety studies — covering the system life cycle, validation, security, electronic records and signatures, audit trails, and data integrity. Supplement 1 (2023) extends the guidance to cloud computing.
What this does not cover
stated in the document's own scope- Applies to computerised systems within GLP non-clinical safety studies; GMP computerised systems are governed by EU GMP Annex 11 and clinical systems by GCP expectations.
- Interprets the OECD GLP Principles; it is not itself the legal GLP regulation, which each authority implements nationally.
- Addresses the application of GLP to computerised systems; broader GLP data-integrity guidance is Advisory No. 22.
Always verify against the current published text before relying on it for a submission or inspection.
Overview
OECD GLP Advisory Document No. 17 applies the OECD Principles of Good Laboratory Practice to computerised systems used in non-clinical health and environmental safety studies. It covers the whole system life cycle — requirements, validation, operation, maintenance, security and access control, electronic records and signatures, audit trails, back-up and archiving, and retirement — so that data generated or managed by a computerised system remain attributable, reliable, and reconstructable to GLP standards. Supplement 1 (2023) extends the guidance to cloud computing, addressing the responsibilities of the test facility and its cloud service providers.
Scope & applicability
GLP test facilities and their computerised systems (LIMS, instrument data systems, electronic records). It is the GLP-sector counterpart to GAMP 5 and Annex 11 / Part 11 for the computerised-system-assurance discipline, distinct from Advisory No. 22 on data integrity.
Legal basis & how it acquires force
The advisory document is issued by the OECD Working Group on GLP to help member authorities and test facilities apply the OECD GLP Principles consistently; it interprets those Principles rather than creating new obligations. The GLP Principles themselves are given legal force through national implementation (for example FDA’s 21 CFR Part 58 in the United States and equivalent regulations in OECD member states) and through the OECD Mutual Acceptance of Data framework. The main advisory dates from 2016; Supplement 1 on cloud computing was published in 2023.
Document structure
| Part | Covers |
|---|---|
| Life cycle and validation | Applying a risk-based system life cycle and validation appropriate to the GLP use of the system |
| Security and access | User access control, physical and logical security, and protection of raw data |
| Electronic records and audit trails | Attributability of electronic data, audit-trail generation and review, and electronic signatures |
| Continuity and archiving | Back-up, business continuity, archiving, and retrieval across the retention period |
| Cloud computing (Supplement 1, 2023) | Responsibilities of the test facility and cloud service providers when GLP data are held in the cloud |
Key requirements
- A validated, life-cycle-managed computerised system appropriate to its GLP use
- Security and access controls that keep raw data attributable and protected
- Audit trails that capture creation, change, and deletion of GLP-relevant electronic data
- Electronic records and signatures managed so the study reconstruction remains complete
- Cloud-service arrangements and responsibilities addressed (Supplement 1, 2023)
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
International alignment
Advisory No. 17 is the GLP-sector counterpart to the computerised-system-assurance expectations in GAMP 5, EU GMP Annex 11, and FDA 21 CFR Part 11, sharing their life-cycle and data-integrity concepts while remaining framed for the GLP study environment. It is distinct from OECD GLP Advisory No. 22, which addresses data integrity in GLP more broadly.
OECD GLP Advisory No. 17: frequently asked questions
Quick answers to common questions about OECD GLP Advisory No. 17.
What does OECD GLP Advisory No. 17 cover?
How to apply the OECD GLP Principles to computerised systems in non-clinical safety studies — validation, security, electronic records and signatures, audit trails, back-up and archiving across the system life cycle.
Does Advisory No. 17 address cloud computing?
Yes — Supplement 1, published in 2023, extends the guidance to cloud computing and the responsibilities shared between the GLP test facility and its cloud service providers.
How does Advisory No. 17 relate to GAMP 5 and Annex 11?
It shares the same life-cycle and data-integrity concepts but is framed for the GLP study environment, whereas GAMP 5 and EU GMP Annex 11 sit in the GMP world.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.