Technical · Validation & data

Annex 11 — computerised systems

Annex 11 sets the GMP requirements for computerised systems used in regulated activities, covering the full lifecycle from supplier assessment and validation through operation, security and retirement.

In one line

Annex 11 sets the GMP requirements for computerised systems used in regulated activities, covering the full lifecycle from supplier assessment and validation through operation, security and retirement.

Plain-English explanation, then the primary regulation it comes from.

Explanation

Understanding annex 11 — computerised systems

Annex 11 is structured around a lifecycle: a project phase covering risk management, personnel, suppliers and validation, then an operational phase covering data, accuracy checks, storage, printouts, audit trails, change and configuration management, periodic evaluation, security, incident management, electronic signatures, batch release, business continuity and archiving. Reading it as a checklist of that shape is the quickest way to find your gaps.

Risk management runs through the whole annex, which means the depth of everything else is a decision you must justify. A system whose failure could affect patient safety, product quality or data integrity warrants more validation, tighter access control and closer audit trail review than a system whose failure is merely inconvenient. Applying uniform rigour to everything is both expensive and, paradoxically, a way of under-controlling what matters.

Supplier and service provider management is explicit. Where third parties supply, install, configure, integrate, validate, maintain or host a system, formal agreements should exist, and supplier competence should be assessed — with audits based on risk. Cloud and hosted arrangements bring this sharply into focus, because the controls you rely on are largely someone else's.

Two operational requirements account for a disproportionate share of findings: audit trails that are enabled but never reviewed, and access control that has drifted so that leavers retain accounts and privileges exceed roles. Both are visible to an inspector within minutes and both suggest the system is not actually being managed.

What it requiresThe substance of the requirement, stated plainly.
Risk-based throughout
The extent of validation and controls is justified by the system's impact.
Supplier assessment and agreements
Formal agreements where third parties provide or host systems; competence assessed.
Data and accuracy checks
Critical data entered manually requires an additional check on accuracy.
Audit trails
Generated for GMP-relevant changes and deletions, and regularly reviewed.
Security and access
Access restricted to authorised persons; individual identities; privileges matched to role.
Periodic evaluation
Systems periodically evaluated to confirm they remain valid and compliant.
Business continuity and archiving
Provision for system unavailability, and archived data remaining readable and retrievable.
Where it goes wrongThe part a definition alone will not tell you.

Common failure modes

  • Leaver accounts still active, and privileges that exceed the role the person actually performs.
  • Audit trail review with no named owner, no frequency and no record that it happened.
  • Cloud or hosted systems with no agreement covering GMP responsibilities.
  • Periodic evaluation never performed, so systems validated once drift for years unchecked.
Primary sourcesAlways verify against the primary source before acting; guidance is revised.

Where this is written down

Related

Read next

Looking for a definition rather than an explanation? The GMP glossary covers the abbreviations in one line each.

Applying this to your site

Knowing the requirement is not the same as closing the gap

If you want to know where your site actually stands against this, the readiness score covers seven quality-system domains in twenty questions, and takes about ten minutes.