Annex 11 covers the system and the way it is used
EU GMP Annex 11 applies to computerised systems used as part of GMP-regulated activities. It describes expectations across risk management, personnel, suppliers, validation, data, accuracy checks, data storage, printouts, audit trails, change management, periodic evaluation, security, incident management, electronic signatures, batch release, and business continuity. It is not a software procurement checklist. It is a control framework for the complete regulated use of a system.
The themes worth translating into requirements
- Risk management: identify critical functions and data, then apply controls and evidence proportionate to risk.
- Supplier oversight: define responsibilities, assess supplier competence, and control contracts and service arrangements.
- Validation: demonstrate that the system can achieve the required results consistently for the defined use.
- Data and accuracy: protect data, check critical inputs, and preserve meaningful records and metadata.
- Audit trails and change control: make relevant changes traceable and manage system changes through a controlled process.
- Security and continuity: limit access, handle incidents, and keep critical processes operating or recoverable.
- Periodic evaluation: revisit the system as technology, data, functionality, incidents, and regulatory expectations change.
The supplier contract does not transfer responsibility
A cloud or outsourced service can change who performs an activity, but it does not remove the regulated organisation’s need to understand and control the service. Define ownership for access, data, backups, incidents, change notification, support, testing, retention, and exit. Ask for evidence that is relevant to your intended use, not a generic certificate detached from the process.
Build the Annex 11 matrix around the lifecycle
Create a matrix that maps each applicable expectation to a requirement, risk, control, evidence source, owner, and review point. Use it during selection, implementation, release, change, and periodic review. Include interfaces and manual steps. A system can pass a functional test and still fail the process if a human export, approval, or reconciliation is uncontrolled.
For teams building a broader programme, the VLMS benchmarks framework provides a useful starting structure. Adapt it to the product, process, and jurisdiction. Annex 11 is a guide to control design, not a substitute for your quality system.
Structure an Annex 11 readiness review
Start with the system, process, and evidence questions that matter to your team.
Talk with VLMS about your validation programme →