· ANNEX 11 · 2025 DRAFT

EU GMP Annex 11 (2025 Revision)

EU GMP Annex 11 governs computerised systems used in GMP. Its 2025 draft revision — published on 7 July 2025 by the European Commission together with PIC/S — is its first modernisation since 2011, expanding from roughly five pages to nineteen across seventeen sections plus a glossary. It hardens lifecycle management, supplier and cloud oversight, identity and access management, audit trails and data integrity, and, for the first time, treats cybersecurity as a core GMP requirement while addressing cloud platforms and AI-enabled systems. It is a draft: public consultation closed in October 2025 and a final version is expected around mid-2026.

What an explainer is not

A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 26 LINKS

The draft 2025 revision of EU GMP Annex 11 (published 7 Jul 2025 with PIC/S) modernises computerised-systems GMP for cloud and AI, makes cybersecurity a core requirement, and reframes validation as risk-based lifecycle control.

06 · QUALITY MATURITY — EU GMP ANNEX 11 (2025 REVISION), REACTIVE TO ADAPTIVE

L1
Reactive

Computerised systems are validated once at go-live; the 2011 annex is read literally and cloud, SaaS, and AI fall through the gaps.

L2
Defined

A CSV SOP exists, but supplier/cloud oversight, IAM, and audit-trail review are inconsistent and cybersecurity is out of scope.

L3
Controlled

Validation is risk-based lifecycle management; audit trails, IAM, and supplier oversight meet the data-integrity guidance the draft consolidates.

L4
Predictive

Cloud and SaaS hosts are governed as extensions of the quality system; audit-trail review and access are monitored risk-based.

L5
Adaptive

Systems, including AI-enabled ones, are governed across their lifecycle with cybersecurity and data governance designed in.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 2

Derived from the 2 standards SPEQ maps to this subject, across 2 regulatory bodies: FDA, EMA.

RECORDS & OBJECTIVE EVIDENCE

  • A risk-based validation lifecycle for each GMP computerised system
  • Supplier and cloud/SaaS oversight agreements with proportionate evidence
  • Identity and access management tying every action to an accountable person
  • Audit trails that ordinary users cannot disable, with risk-based review
  • A cybersecurity posture assessment for regulated computerised systems

COMMON INSPECTION FINDINGS

  • GMP systems validated at go-live but not maintained across their lifecycle
  • A cloud or SaaS host treated as an outsourced black box, accountability not retained
  • Audit trails disabled, or enabled but never reviewed
  • Shared accounts breaking the link between an action and a person
  • No cybersecurity controls over systems holding GMP data
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

Why Annex 11 was revised

The 2011 Annex 11 predates the cloud, SaaS, mobile, and machine-learning systems that now run regulated processes. Fourteen years of technology change opened a gap between what the annex described and how computerised systems are actually built, hosted, and attacked. The revision closes that gap, and aligns Annex 11 with the intervening data-integrity guidance (MHRA, PIC/S PI 041) that industry had been using to fill it.

Because it is issued jointly with PIC/S, the revision’s reach extends well beyond the EU to every PIC/S participating authority — making it one of the most consequential computerised-systems documents in GxP even before it is finalised.

What is new — scope and structure

The draft roughly triples the annex’s length and organises it into seventeen sections with a glossary for consistent terminology. Risk management is the central pillar: expectations for integrity, reliability, and safety are set across the entire lifecycle of a computerised system rather than treated as a one-time validation event. It brings supplier oversight, identity and access management, audit trails, and configuration and change control into explicit focus.

The single most-cited addition is cybersecurity as a core GMP requirement — the first time an EU GMP annex has stated it directly. Where the 2011 text was largely silent on the threat model around regulated systems, the revision makes protecting those systems and their data an in-scope GMP obligation.

Lifecycle, risk-based validation, and supplier/cloud oversight

The revision reframes validation as risk-based lifecycle management: the depth of validation and the ongoing controls follow the risk the system carries and the criticality of the data it holds. It strengthens expectations on suppliers and service providers — including cloud and SaaS hosts — so that a regulated company remains accountable for a system it does not itself operate, with oversight, agreements, and evidence proportionate to risk.

This is the GAMP 5 (2nd ed.) posture written into the annex: leverage supplier activity where it is trustworthy, but retain and evidence accountability. For cloud, that means treating the host as an extension of the quality system, not an outsourced black box.

Data integrity, audit trails, and access

Data integrity moves from implicit to explicit. The draft carries the ALCOA+ expectations into requirements on audit trails that cannot be disabled by ordinary users and are reviewed risk-based, on identity and access management that ties every action to an accountable person, and on the prevention of unauthorised change or deletion. It reads as the convergence of Annex 11 with the data-integrity guidance that has governed inspections for the last decade.

AI-enabled systems

For the first time, the draft addresses AI and machine-learning components in GMP computerised systems — an area where behaviour can change with data and where conventional static validation does not fully apply. Treat the specifics here as emerging and draft: the direction (lifecycle control, data governance, and human oversight of adaptive systems) is clear, but the exact expectations may move before the final text. Do not overfit a validation strategy to draft wording.

Status and how to prepare

Annex 11 (2025) is a draft: consultation closed in October 2025 and a final is expected around mid-2026, so its provisions are not yet enforceable and the wording may change. The pragmatic move is to gap-assess computerised-system inventories, supplier and cloud agreements, IAM, audit-trail review, and cybersecurity posture against the draft’s direction now, without hard-coding draft clauses into SOPs. SPEQ synthesis: prepare for the direction, commit to the details only when the final publishes.

FREQUENTLY ASKED

Is the 2025 Annex 11 revision final?

No. The European Commission and PIC/S published the draft on 7 July 2025; public consultation closed in October 2025 and a final version is expected around mid-2026. Its provisions are not yet enforceable and the wording may still change, so prepare for its direction rather than hard-coding draft clauses into procedures.

What are the biggest changes in the draft?

It expands from about five pages to nineteen across seventeen sections plus a glossary; makes risk-based lifecycle management (not one-time validation) the frame; strengthens supplier, cloud, identity/access, audit-trail and data-integrity expectations; and — for the first time in an EU GMP annex — treats cybersecurity as a core GMP requirement and addresses AI-enabled systems.

Does Annex 11 now require cybersecurity?

The draft revision introduces cybersecurity as a core GMP requirement for computerised systems — the first EU GMP annex to state it directly. The 2011 version was largely silent on it. Because the document is issued jointly with PIC/S, this expectation would extend to all PIC/S participating authorities once finalised.

How does the draft treat cloud and AI systems?

For cloud and SaaS, it strengthens supplier oversight so the regulated company remains accountable — with oversight and evidence proportionate to risk — for systems it does not operate itself. For AI/machine-learning components it introduces expectations around lifecycle control, data governance, and human oversight, but treat these as emerging and draft: the direction is clear, the exact requirements may move before the final text.

PROFESSIONAL · INSPECTION PLAYBOOK · SPEQ SYNTHESIS

The inspection-readiness playbook for this topic

CHECKING ACCESS

Checking your Professional access…