What does EU Annex 11 require for computerized systems?
Annex 11 sets 17 specific requirements across risk management, validation, and operational controls for any computerized system used in a GMP-regulated activity. Its foundational principle: a system replacing a manual process must produce no decrease in product quality, process control, or quality assurance, and no increase in overall risk. Every section — audit trails, access control, periodic review — exists to make that principle checkable.
The Excel sheet nobody validated because "it's just for tracking" is still a computerized system under Annex 11 if it influences a release decision. Here's a checklist for all 17 sections — including the one most teams quietly skip.
The Core Principle Behind All 17 Sections
Annex 11, part of EudraLex Volume 4, has been in force since June 30, 2011. Its foundational statement is simple: when a computerized system replaces a manual operation, there should be no decrease in product quality, process control, or quality assurance — and no increase in overall risk. The 17 sections that follow exist to make that principle checkable rather than a vague assurance nobody can verify.
The Full Annex 11 Compliance Checklist
| # | Section | What to Verify |
|---|---|---|
| 1 | Risk Management | Risk assessment ranks functions by patient/product impact and drives control depth |
| 2 | Personnel | Roles, competencies, and training are documented and mapped to system responsibilities |
| 3 | Suppliers & Service Providers | Formal quality agreements exist with vendors, including cloud and SaaS hosts |
| 4 | Validation | Documented, risk-based validation with traceable requirements and migration verification |
| 5 | Data | Data integrity controls apply to every system that creates or holds GMP data, not just "official" ones |
| 6 | Accuracy Checks | Critical manually entered data has an independent verification step |
| 7 | Data Storage | Data is protected against damage, with regular backups verified for restorability |
| 8 | Printouts | Printed records clearly indicate if data has been changed since original entry |
| 9 | Audit Trails | Changes and deletions to GMP data are tracked, time-stamped, and reviewed before use |
| 10 | Change & Configuration Mgmt | All changes assessed for GMP impact and approved before implementation |
| 11 | Periodic Evaluation | Systems reviewed on a risk-based schedule to confirm continued validated state |
| 12 | Security | Access is role-based, and administrator rights are segregated from routine use |
| 13 | Incident Management | Incidents are recorded, investigated, and root-caused, not just resolved and forgotten |
| 14 | Electronic Signature | Signatures are unique to an individual and permanently linked to their record |
| 15 | Batch Release | The system supports the Qualified Person's ability to confirm batch conformance |
| 16 | Business Continuity | A tested plan exists for system unavailability, including manual fallback if needed |
| 17 | Archiving | Archived data remains protected, complete, and retrievable for its full retention period |
Where Compliance Programs Actually Fail
The shadow spreadsheet problem: Section 5 doesn't say "validate your LIMS and ERP." It says data integrity applies to any system that creates or holds GMP-relevant data. A spreadsheet an analyst built to track trending, that a supervisor now references before signing off a batch, meets that bar — validated or not, official or not. It's the single most common Annex 11 gap, precisely because it doesn't look like "a system" to the people using it.
The other recurring failure is treating Section 11, periodic evaluation, as a calendar reminder rather than a substantive review. A system reviewed on schedule with nobody actually checking its current configuration against its validated baseline satisfies the letter of the requirement and none of its intent.
How GoVal Supports Annex 11 Compliance
GoVal maps each of the 17 sections above to a corresponding control in its platform — GAMP 5-scaled risk assessment, validated audit trails, change control with revalidation triggers, and periodic review scheduled by risk tier — so compliance is a structured, evidenced state maintained continuously, rather than a checklist reconstructed from scattered documents every time an inspection is announced.
Related Topics
Frequently Asked Questions
What is EU GMP Annex 11? +
How many sections does Annex 11 have? +
Does Annex 11 apply to cloud and SaaS systems? +
What is the "no decrease" principle in Annex 11? +
Is Annex 11 being updated, and when does the new version take effect? +
What's the difference between Annex 11 and 21 CFR Part 11? +
How does GoVal support Annex 11 compliance? +
Turn all 17 Annex 11 sections into one evidenced record
Risk-based validation, audit trails, change control, and periodic review — mapped to Annex 11, in GoVal.
