Skip to main content

EU Annex 11 Compliance Checklist for Computerized Systems

Ready to modernize?

See GoVal in Action

Book a 30-minute walkthrough with our validation specialists. No slides — just your questions, answered live.

Contact Us
Summary

EU GMP Annex 11 governs computerized systems used in GMP-regulated activities across 17 sections, from risk management and validation to audit trails, periodic evaluation, and archiving. Its foundational principle: a computerized system replacing a manual operation must produce no decrease in quality, process control, or quality assurance, and no increase in risk. The most commonly missed scope gap is unvalidated spreadsheets that influence a GMP decision — Annex 11 applies regardless of how informal the tool looks. The 2011 version remains in force; a 2025 draft revision is still in consultation. GoVal maps each section to a corresponding control, keeping compliance a structured, audit-trailed state rather than a checklist rebuilt before every inspection.

What does EU Annex 11 require for computerized systems?

Annex 11 sets 17 specific requirements across risk management, validation, and operational controls for any computerized system used in a GMP-regulated activity. Its foundational principle: a system replacing a manual process must produce no decrease in product quality, process control, or quality assurance, and no increase in overall risk. Every section — audit trails, access control, periodic review — exists to make that principle checkable.

The Excel sheet nobody validated because "it's just for tracking" is still a computerized system under Annex 11 if it influences a release decision. Here's a checklist for all 17 sections — including the one most teams quietly skip.

The Core Principle Behind All 17 Sections

Annex 11, part of EudraLex Volume 4, has been in force since June 30, 2011. Its foundational statement is simple: when a computerized system replaces a manual operation, there should be no decrease in product quality, process control, or quality assurance — and no increase in overall risk. The 17 sections that follow exist to make that principle checkable rather than a vague assurance nobody can verify.

The Full Annex 11 Compliance Checklist

#SectionWhat to Verify
1Risk ManagementRisk assessment ranks functions by patient/product impact and drives control depth
2PersonnelRoles, competencies, and training are documented and mapped to system responsibilities
3Suppliers & Service ProvidersFormal quality agreements exist with vendors, including cloud and SaaS hosts
4ValidationDocumented, risk-based validation with traceable requirements and migration verification
5DataData integrity controls apply to every system that creates or holds GMP data, not just "official" ones
6Accuracy ChecksCritical manually entered data has an independent verification step
7Data StorageData is protected against damage, with regular backups verified for restorability
8PrintoutsPrinted records clearly indicate if data has been changed since original entry
9Audit TrailsChanges and deletions to GMP data are tracked, time-stamped, and reviewed before use
10Change & Configuration MgmtAll changes assessed for GMP impact and approved before implementation
11Periodic EvaluationSystems reviewed on a risk-based schedule to confirm continued validated state
12SecurityAccess is role-based, and administrator rights are segregated from routine use
13Incident ManagementIncidents are recorded, investigated, and root-caused, not just resolved and forgotten
14Electronic SignatureSignatures are unique to an individual and permanently linked to their record
15Batch ReleaseThe system supports the Qualified Person's ability to confirm batch conformance
16Business ContinuityA tested plan exists for system unavailability, including manual fallback if needed
17ArchivingArchived data remains protected, complete, and retrievable for its full retention period

Where Compliance Programs Actually Fail

The shadow spreadsheet problem: Section 5 doesn't say "validate your LIMS and ERP." It says data integrity applies to any system that creates or holds GMP-relevant data. A spreadsheet an analyst built to track trending, that a supervisor now references before signing off a batch, meets that bar — validated or not, official or not. It's the single most common Annex 11 gap, precisely because it doesn't look like "a system" to the people using it.

The other recurring failure is treating Section 11, periodic evaluation, as a calendar reminder rather than a substantive review. A system reviewed on schedule with nobody actually checking its current configuration against its validated baseline satisfies the letter of the requirement and none of its intent.

How GoVal Supports Annex 11 Compliance

GoVal maps each of the 17 sections above to a corresponding control in its platform — GAMP 5-scaled risk assessment, validated audit trails, change control with revalidation triggers, and periodic review scheduled by risk tier — so compliance is a structured, evidenced state maintained continuously, rather than a checklist reconstructed from scattered documents every time an inspection is announced.

Related Topics

Frequently Asked Questions

What is EU GMP Annex 11? +
EU GMP Annex 11 is the section of EudraLex Volume 4 governing computerized systems used in activities regulated under Good Manufacturing Practice. Effective since June 30, 2011, it applies to any system — commercial, custom, or cloud-hosted — that can influence a batch outcome, release decision, or other GMP record. Its core principle is that a computerized system replacing a manual process must produce no decrease in product quality, process control, or quality assurance, and no increase in overall risk.
How many sections does Annex 11 have? +
Seventeen, organized into four areas: General (risk management, personnel, suppliers and service providers), Project Phase (validation), and Operational Phase, which covers data, accuracy checks, data storage, printouts, audit trails, change and configuration management, periodic evaluation, security, incident management, electronic signatures, batch release, business continuity, and archiving. Each section sets a specific, checkable expectation rather than a general principle.
Does Annex 11 apply to cloud and SaaS systems? +
Yes. Annex 11 doesn't exempt systems based on hosting location or delivery model — a cloud-hosted or SaaS platform used for GMP-regulated activities is in scope the same way an on-premise system is. Section 3, Suppliers and Service Providers, specifically requires formal agreements and competence assessment for third parties providing GxP services, which explicitly covers cloud hosting and SaaS vendors.
What is the "no decrease" principle in Annex 11? +
It's the foundational statement underlying the entire annex: when a computerized system replaces a manual operation, there should be no decrease in product quality, process control, or quality assurance, and no increase in overall risk. Every subsequent section — validation, audit trails, access control — exists to make that principle checkable and demonstrable, rather than left as an abstract assurance.
Is Annex 11 being updated, and when does the new version take effect? +
A draft revision was published for consultation in July 2025, alongside a new Annex 22 covering artificial intelligence. As of this writing, the 2011 version remains legally in force, and the revised text is still a consultation document. Organizations should treat the draft's direction — expanded audit trail scope, dedicated cybersecurity provisions, and more prescriptive periodic review cadences — as a strong preview to prepare for, not a current requirement.
What's the difference between Annex 11 and 21 CFR Part 11? +
Annex 11 is the EU's broader framework covering the full lifecycle of a computerized system — risk management, suppliers, validation, and operations — while 21 CFR Part 11 is the FDA's narrower regulation focused specifically on electronic records and electronic signatures. Both require audit trails, access control, and validated systems, but each has sections with no direct equivalent in the other.
How does GoVal support Annex 11 compliance? +
GoVal maps each of Annex 11's 17 sections to a corresponding control in its platform — GAMP 5-scaled risk assessment, validated audit trails, change control with revalidation triggers, periodic review scheduling, and vendor qualification tracking. Compliance exists as a structured, evidenced state rather than something reconstructed from scattered spreadsheets and email threads before each inspection, with the rationale behind every risk-based decision captured and retrievable.

Turn all 17 Annex 11 sections into one evidenced record

Risk-based validation, audit trails, change control, and periodic review — mapped to Annex 11, in GoVal.

Book a Free Demo →