RegulationsEU GMP
EU GMP Annex 11 revision: where it stands, and what it asks
EU GMP Annex 11 is the EU GMP guideline for computerized systems used in GMP-regulated activities, part of EudraLex Volume 4. It asks for risk-based validation, formal supplier agreements, access security and periodic evaluation of computerized systems used in GMP work, with audit trails based on risk and rules for electronic signatures where they are used.
The version in force is the 2011 revision, in operation since June 30, 2011. The EU GMP Annex 11 revision was published as a draft on July 7, 2025, and consultation closed on October 7, 2025. As of September 25, 2026 it has not been adopted: the European Commission still lists the 2011 text, and no final version or date of application has been published.
This page maps the 2011 text to QMSdesk™ controls, then sets out what the draft adds, from the draft itself.
18 requirements, each with the QMSdesk control, its evidence and what you still own.
The Annex 11 in force today, section by section
Annex 11 covers the whole life of a computerized system, and most of it is about how you run and govern the system. The last column is your share.
| Requirement (2011 section, paraphrased) | How QMSdesk supports it | Evidence available | What you still own |
|---|---|---|---|
| Principle. Validate the application and qualify the IT infrastructure. Where a system replaces a manual operation, there should be no decrease in product quality, process control or quality assurance, and no increase in the overall risk of the process. | QMSdesk's core platform is validated under a QA-approved Validation Summary Report. We'll walk you through the full record under a mutual NDA. QMSdesk is hosted with a cloud infrastructure provider that holds a SOC 2 Type II attestation; that attestation is the provider's, not ours. | Validation Summary Report, walked through under a mutual NDA | Validating for your intended use; assessing the infrastructure in your supplier assessment |
| §1 Risk management. Apply risk management across the lifecycle, and base the extent of validation and data-integrity controls on a justified, documented risk assessment. | QMSdesk's core platform is validated under a QA-approved Validation Summary Report. We'll walk you through the full record under a mutual NDA. Your own risk assessment can run in QMSdesk as a controlled document, with signed review and approval. | Validation Summary Report, walked through under a mutual NDA; your signed risk assessment | Your risk assessment for your intended use |
| §2 Personnel. Close cooperation; appropriate qualifications, access levels and defined responsibilities. | Nine core roles with granular permissions; training and competency records; the Administrator role holds no authority to review, approve, verify or close quality records. | Role assignments, training records | Naming process and system owners, and defining responsibilities |
| §3 Suppliers and service providers. Formal agreements with clear responsibilities; audit by risk; review supplier documentation; supplier quality information available to inspectors. | Every engagement includes a written validation scope, and we'll walk you through the full validation record under a mutual NDA. The supplier quality module qualifies and reviews your suppliers by risk, us included. | Written validation scope, your supplier file | The agreement, the decision to audit us, and your review of our documentation |
| §4 Validation. Lifecycle documentation; traceable user requirements; supplier assessment; test evidence; checks on data migration. | QMSdesk's core platform is validated under a QA-approved Validation Summary Report. We'll walk you through the full record under a mutual NDA. You configure and test in your real tenant, and go-live takes two signed attestations. Migrated documents carry a signed batch attestation and a permanent "Migrated" badge. | Your go-live test records, kept in your tenant; go-live and migration attestations | Your user requirements, system inventory, intended-use validation and migration checks |
| §5 Data. Built-in checks for data exchanged with other systems. | System-to-system access runs through an external API with explicit scopes and credentials tied to a named owner. An integration may carry out work but can't sign. | API credentials, managed by your administrators | Validating any interface you connect |
| §6 Accuracy checks. A second check on critical data entered manually. | Workflows put an independent reviewer or approver on critical records, enforced at signing. Your procedure decides whether that review is the second check on manually entered data. | Signatures by different people | Deciding which data is critical |
| §7 Data storage. Protect data; keep it accessible through the retention period; back it up. | Tenant isolation by row-level security; a retention floor set by your profiles; quality records never hard-deleted; a suspended module stays readable and exportable. | Retention sweep log | Covering backup and restore of hosted data in your supplier assessment |
| §8 Printouts. Clear printed copies; for records supporting batch release, printouts that show whether data changed since original entry. | PDF reports, controlled copies and closure records. QMSdesk holds no batch records. Where its records, such as batch deviations, support batch release, the audit-trail export lists the recorded changes. | Logged downloads, audit-trail export | Deciding which QMSdesk records support batch release and how you show changes to them; batch-release printouts in your batch system |
| §9 Audit trails. Based on risk, record GMP-relevant changes and deletions; document the reason; keep trails available, intelligible and regularly reviewed. | A hash-chained, insert-only audit trail capturing who, what, old and new values, the reason and the time. Export, and a signed periodic review over a risk-focused view. | Audit trail, daily verification, signed review | Your review procedure and cadence |
| §10 Change and configuration management. Change only in a controlled way, by a defined procedure. | After go-live, a validation-affecting setting can't be written until approved change control reaches implementation. Administrators can't edit workflow steps. | Change-control records, signed setting changes | Your change procedure, and assessing each QMSdesk release against your validated state |
| §11 Periodic evaluation. Confirm the system stays in a valid state and in line with GMP. | The records an evaluation draws on live in QMSdesk: deviations, incidents, CAPAs, change controls, signed audit-trail and access reviews, and a signed System Boundary Statement. | Those records | Running and documenting the evaluation |
| §12 Security. Restrict access; record changes to access authorizations; record who entered or changed data, and when. | Multi-factor authentication, lockout, an inactivity timeout and SAML single sign-on. Role grants and deactivations carry a signature meaning, and every audit entry records who and when. | Audit trail, access reviews | Physical security at your sites, and access decisions |
| §13 Incident management. Report and assess all incidents; the root cause of a critical incident drives CAPA. | An incident workflow with containment for major and critical incidents and a signed CAPA decision, then CAPA with effectiveness checks. | Incident and CAPA records | Reporting system incidents into it |
| §14 Electronic signature. Where records are signed electronically: same impact as handwritten within the company; permanently linked; time and date. | Re-authentication at every signature, a recorded meaning, and the signature committed with the change it approves. A daily job re-checks every link. | Signature records, daily linkage results | Your policy giving e-signatures handwritten weight |
| §15 Batch release. Where a computerized system records certification and batch release, only Qualified Persons can certify release, by electronic signature. | Outside QMSdesk's scope. The GMP profile adds a QP role, but QMSdesk has no batch-certification workflow. | — | Batch certification in your release system |
| §16 Business continuity. Documented, tested fallback arrangements. | Your procedure. | — | Your continuity plan |
| §17 Archiving. Archived data stays accessible, readable and intact. | Quality records are archived, never hard-deleted, and stay readable. The audit-trail chain is verified daily. | Chain verification results | Testing retrieval in your periodic evaluation |
What the EU GMP Annex 11 revision adds (July 2025 draft)
The draft is a full rewrite: 19 pages in 17 sections, against five pages in 2011. It was prepared by the EMA GMP/GDP Inspectors Working Group with PIC/S. Everything below is draft text and can change before adoption.
- Cloud and software as a service. The duty to set and approve system requirements applies whether a system is built in-house, bought off the shelf or provided as a service. A vendor may supply the requirements specification, but you review, approve and own it for your implemented version.
- Annex 11 supplier requirements. Relying on a vendor's qualification doesn't change your obligations. The draft asks for an audit or thorough assessment by risk, oversight through agreed SLAs and KPIs, and supplier documentation you can access and explain from your own site. Vendor qualification documents may be used, but you review and authorize them. The contract should cover nine elements: the activities and documentation provided; the procedures and regulatory requirements to meet; regular, ad hoc and incident reporting and oversight, including SLAs and KPIs; supplier audits; support during inspections; issue resolution; communication of quality and security issues; an exit strategy that keeps you in control of your data; and how new versions are released and whether you can test them first.
- Audit trails, in ten subsections. Log every manual user interaction. Capture who, what (old and new values), when and why, prompting for the reason. Keep the trail switched on and uneditable, searchable or exportable. Review it under a documented procedure, by someone not involved, targeted by risk. Provide a complete, searchable electronic copy.
- Electronic signatures. Full re-authentication at signing, not reliance on the earlier sign-in. The displayed signature shows full name, username, role where relevant, meaning, date and time. A signed record can't change without appearing unsigned.
- Identity and access. Personal accounts; multi-factor authentication for remote access to critical systems; automatic lock after failed attempts; an inactivity logout users can't switch off; an access log; segregation of duties and least privilege; recurring access reviews.
- Security, in twenty subsections. From an information security management system and awareness training to disaster recovery, patching, penetration testing and encrypted remote connections.
- Also new: dedicated sections on the pharmaceutical quality system, system requirements, alarms and backup, and a fuller periodic review.
- Artificial intelligence sits elsewhere. The draft Annex 11 doesn't address it; the separate draft Annex 22 does.
Where QMSdesk's controls are designed to support the draft
- Personal accounts, with user IDs never reissued, and multi-factor authentication for the tenant or by role.
- An audit trail that records who, what, old and new values, the reason and the time, that nobody can edit, and that you can export and review with a signature.
- Re-authentication at every signature, with its meaning recorded and a content hash of what was signed.
- An Administrator role with no authority to review, approve, verify or close quality records, and periodic access reviews.
- Records in a suspended module stay readable and exportable. Agree your exit terms, including how your data is handed back, in the contract.
Use the nine contract elements as your checklist for any computerized-system supplier, including us.
Annex 11 vs Part 11, side by side
| EU GMP Annex 11 (2011) | 21 CFR Part 11 | |
|---|---|---|
| What it is | EU GMP guideline, EudraLex Volume 4 | US federal regulation |
| Scope | Computerized systems used in GMP-regulated activities | Electronic records and signatures required by FDA rules, or submitted to FDA |
| Risk | Risk management sets the extent of validation | Not addressed in the rule text |
| Suppliers | Formal agreements and supplier assessment | No supplier-agreement requirement; §11.10(i) covers the education, training and experience of people who develop, maintain or use the system |
| Audit trail | Risk-based; changes with a reason; reviewed regularly | Secure, computer-generated, time-stamped; kept at least as long as the record must be kept |
| Signatures | Same impact as handwritten; linked; time and date | Name, date, time and meaning; linked; two components for non-biometric signatures; certification to FDA |
Selling into both markets means working to both. Read the Part 11 map.
Kept current
What changed recently
July 7, 2025
The European Commission opened consultation on a revised Annex 11, a revised Chapter 4 (Documentation) and a new Annex 22 (Artificial Intelligence).
October 7, 2025
The consultation closed.
September 25, 2026
The Commission's EudraLex Volume 4 page still lists Annex 11 and Chapter 4 as their January 2011 versions and does not list an Annex 22. No final text or date of application has been published for any of the three.
PDF and Excel
Regulation checklist
The tables from this page, with a column for your own evidence. No form to fill in.
EU GMP Annex 11 FAQ
Has the revised Annex 11 been adopted?
Not as of September 25, 2026. The 2011 text remains in force, and the July 2025 draft is still a draft. We review this page every quarter and will update it when the final text is published.
Does Annex 11 apply to a cloud eQMS?
Yes. The 2011 text applies to all forms of computerized systems used in GMP-regulated activities. The draft names systems provided as a service explicitly.
What are the Annex 11 supplier requirements?
Today: formal agreements that set out the supplier's responsibilities, an audit decision based on risk, and supplier quality information available to inspectors. The draft adds oversight through SLAs and KPIs and a nine-element contract, including an exit strategy for your data.
Is there an Annex 11 certification?
No. There's no official certification scheme for Annex 11. QMSdesk is designed to support many of its controls, and the checklist shows which. The GMP regulatory profile lists EU GMP, including Annex 11, among its regulations.
Should we prepare for the draft now?
The final text may change, but its direction is clear: supplier oversight, audit-trail review, access control and security. Your supplier assessments and audit-trail review procedure are sensible places to start.
Reviewed by a practitioner
Abdul Azam, Founder & CEO, 25 years in regulated life-sciences quality Last reviewed September 26, 2026. Next review December 2026. This guide is general information, not legal or regulatory advice.
Bring one workflow. We'll show you QMSdesk running it.
Bring your audit-trail review or a supplier assessment. We'll walk it through QMSdesk.