Regulations
EU GMP Annex 11, clause by clause
Annex 11 is the EU GMP guideline for computerised systems. Here is each clause that applies to this system, quoted from the 2011 text, with what the software does and what your procedures cover.

How to read it
Who meets each clause
- Software
- The workspace provides the control. Your validation confirms it.
- Software and site
- Both the software and your procedures have a part.
- Your procedures
- Your procedures, training or infrastructure meet it. The software has no part, or only supports it.
- Site deployment
- The software part needs the installation at your site, such as sign-in through your identity provider.
- met by the software
- 4
- shared by the software and your procedures
- 5
- met by your procedures
- 9
- need the installation at your site
- 4
The clauses
18 Annex 11 clauses, quoted
Annex 11, principle: Validation and qualification
Your procedures“The application should be validated; IT infrastructure should be qualified. Where a computerised system replaces a manual operation, there should be no resultant decrease in product quality, process control or quality assurance.”
Official textfor Annex 11, principle (opens in a new tab)Checked 24 Sep 2026
- The software
- The validation package covers the application; the IQ scripts cover the installed infrastructure.
- Your procedures
- Validate the application and qualify the infrastructure it runs on.
More: Validation package
Annex 11, clause 1: Risk management
Your procedures“Risk management should be applied throughout the lifecycle of the computerised system taking into account patient safety, data integrity and product quality. As part of a risk management system, decisions on the extent of validation and data integrity controls should be based on a justified and documented risk assessment of the computerised system.”
Official textfor Annex 11, clause 1 (opens in a new tab)Checked 24 Sep 2026
- The software
- The risk assessment rates each function high, medium or low, with its rationale, and sets how much testing it gets.
- Your procedures
- Review and approve the risk assessment, adjusting it for your process.
More: Validation package
Annex 11, clause 3.1: Agreements with suppliers
Your procedures“When third parties (e.g. suppliers, service providers) are used e.g. to provide, install, configure, integrate, validate, maintain (e.g. via remote access), modify or retain a computerised system or related service or for data processing, formal agreements must exist between the manufacturer and any third parties, and these agreements should include clear statements of the responsibilities of the third party.”
Official textfor Annex 11, clause 3.1 (opens in a new tab)Checked 24 Sep 2026
- The software
- The validation package includes a supplier quality agreement template.
- Your procedures
- Sign a quality agreement with ConductScience before GMP use.
More: Validation package
Annex 11, clause 3.2: Supplier assessment
Your procedures“The competence and reliability of a supplier are key factors when selecting a product or service provider. The need for an audit should be based on a risk assessment.”
Official textfor Annex 11, clause 3.2 (opens in a new tab)Checked 24 Sep 2026
- The software
- The system description and change control record support a supplier assessment.
- Your procedures
- Decide from your risk assessment whether to audit ConductScience.
More: Validation package
Annex 11, clause 4.3: System description
Your procedures“For critical systems an up to date system description detailing the physical and logical arrangements, data flows and interfaces with other systems or processes, any hardware and software pre-requisites, and security measures should be available.”
Official textfor Annex 11, clause 4.3 (opens in a new tab)Checked 24 Sep 2026
- The software
- The validation package includes a system description: components, data flows, interfaces and security.
- Your procedures
- Complete it with your network, storage and identity details.
Annex 11, clause 4.4: User requirements
Your procedures“User Requirements Specifications should describe the required functions of the computerised system and be based on documented risk assessment and GMP impact. User requirements should be traceable throughout the life-cycle.”
Official textfor Annex 11, clause 4.4 (opens in a new tab)Checked 24 Sep 2026
- The software
- Each user requirement traces to its regulations, its function and its tests in the traceability matrix.
- Your procedures
- Review and approve the requirements, adding any of your own.
More: Validation package
Annex 11, clause 4.7: Test evidence
Your procedures“Evidence of appropriate test methods and test scenarios should be demonstrated.”
Official textfor Annex 11, clause 4.7 (opens in a new tab)Checked 24 Sep 2026
- The software
- The IQ, OQ and PQ scripts give steps and expected results, with space for actual results and signatures.
- Your procedures
- Execute the scripts, record the results and resolve deviations.
More: Validation package
Annex 11, clause 7.1: Data storage
Software and siteSite deployment“Data should be secured by both physical and electronic means against damage. Stored data should be checked for accessibility, readability and accuracy. Access to data should be ensured throughout the retention period.”
Official textfor Annex 11, clause 7.1 (opens in a new tab)Checked 24 Sep 2026
- The software
- Clips and frames stay on the site network; records are kept as structured data.
- Your procedures
- Secure the storage, and check stored data for access, readability and accuracy.
Validation: URS-02, URS-24; tests IQ-01, IQ-04, IQ-05, OQ-01, PQ-03
Annex 11, clause 7.2: Backups
Your proceduresSite deployment“Regular back-ups of all relevant data should be done. Integrity and accuracy of back-up data and the ability to restore the data should be checked during validation and monitored periodically.”
Official textfor Annex 11, clause 7.2 (opens in a new tab)Checked 24 Sep 2026
- The software
- A site deployment backs up its records on the schedule you set.
- Your procedures
- Back up regularly, test a restore in validation, and repeat the test periodically.
Validation: URS-24; tests IQ-04, PQ-03
Annex 11, clause 9: Audit trail
Software“Consideration should be given, based on a risk assessment, to building into the system the creation of a record of all GMP-relevant changes and deletions (a system generated "audit trail"). For change or deletion of GMP-relevant data the reason should be documented. Audit trails need to be available and convertible to a generally intelligible form and regularly reviewed.”
Official textfor Annex 11, clause 9 (opens in a new tab)Checked 24 Sep 2026
- The software
- Every decision is recorded with its reason, the audit trail exports in readable form (PDF, XLSX and CSV), and the audit trail review report supports its regular review.
- Your procedures
- Review the audit trail regularly.
Validation: URS-06, URS-07, URS-08; tests OQ-04, OQ-05, OQ-18
More: Audit trail, Validation package
Annex 11, clause 10: Change control
Software and site“Any changes to a computerised system including system configurations should only be made in a controlled manner in accordance with a defined procedure.”
Official textfor Annex 11, clause 10 (opens in a new tab)Checked 24 Sep 2026
- The software
- Changes reach the system only in a versioned release, recorded with its validation impact.
- Your procedures
- Approve each release under your change control procedure before use.
Validation: URS-26, URS-27; tests IQ-01, IQ-02, OQ-18, OQ-19, PQ-01
More: Validation package
Annex 11, clause 11: Periodic evaluation
Software and site“Computerised systems should be periodically evaluated to confirm that they remain in a valid state and are compliant with GMP.”
Official textfor Annex 11, clause 11 (opens in a new tab)Checked 24 Sep 2026
- The software
- The change control record, audit trail review and user access review give the evidence for a periodic review.
- Your procedures
- Evaluate the system periodically and record the result.
Validation: URS-16; tests OQ-18
More: Validation package
Annex 11, clause 12.1: Access control
Software“Physical and/or logical controls should be in place to restrict access to computerised system to authorised persons.”
Official textfor Annex 11, clause 12.1 (opens in a new tab)Checked 24 Sep 2026
- The software
- Only authorized people open the workspace; anyone else sees a page that names nothing.
- Your procedures
- Grant access under your access procedure.
Validation: URS-14; tests OQ-10
Annex 11, clause 12.3: Access changes recorded
Software and siteSite deployment“Creation, change, and cancellation of access authorisations should be recorded.”
Official textfor Annex 11, clause 12.3 (opens in a new tab)Checked 24 Sep 2026
- The software
- A site deployment records who gave or removed each role, and when.
- Your procedures
- Review access changes in the periodic access review.
Validation: URS-16, URS-17; tests IQ-06, OQ-18
Annex 11, clause 12.4: Who entered data, and when
Software“Management systems for data and for documents should be designed to record the identity of operators entering, changing, confirming or deleting data including date and time.”
Official textfor Annex 11, clause 12.4 (opens in a new tab)Checked 24 Sep 2026
- The software
- Every decision records the person, role, date and time.
- Your procedures
- Confirm it in validation.
Validation: URS-03; tests OQ-02, PQ-02
More: Audit trail
Annex 11, clause 14: Electronic signatures
Software“Electronic records may be signed electronically. Electronic signatures are expected to: a. have the same impact as hand-written signatures within the boundaries of the company, b. be permanently linked to their respective record, c. include the time and date that they were applied.”
Official textfor Annex 11, clause 14 (opens in a new tab)Checked 24 Sep 2026
- The software
- Signatures carry the name, date, time and meaning, and are bound to the report data they sign.
- Your procedures
- Give electronic signatures the same standing as handwritten ones in your procedures.
Validation: URS-09, URS-10; tests OQ-06, OQ-07
Annex 11, clause 16: Business continuity
Software and siteSite deployment“For the availability of computerised systems supporting critical processes, provisions should be made to ensure continuity of support for those processes in the event of a system breakdown (e.g. a manual or alternative system).”
Official textfor Annex 11, clause 16 (opens in a new tab)Checked 24 Sep 2026
- The software
- Detection and clip storage run on the monitoring computer, apart from the workspace.
- Your procedures
- Write a continuity procedure: what reviewers do while the workspace is down, and how they catch up.
Validation: URS-25; tests PQ-04
Annex 11, clause 17: Archiving
Your procedures“Data may be archived. This data should be checked for accessibility, readability and integrity. If relevant changes are to be made to the system (e.g. computer equipment or programs), then the ability to retrieve the data should be ensured and tested.”
Official textfor Annex 11, clause 17 (opens in a new tab)Checked 24 Sep 2026
- The software
- Records export as PDF, XLSX and CSV, which open without the system.
- Your procedures
- If you archive records, check that they stay readable and retrievable, including after system changes.
More: Electronic signatures
Questions
Common questions
- Does Annex 11 apply to us?
- Annex 11 is part of the EU guidelines for good manufacturing practice, which apply to medicines for the EU market. Your regulatory team confirms which markets and inspectorates apply to your site.
- How is Annex 11 different from Part 11?
- Part 11 is a binding US regulation about electronic records and electronic signatures. Annex 11 is an EU guideline about the whole life of a computerised system: risk management, suppliers, validation, data, audit trails, security, change and continuity.
- What about the revised Annex 11 and the new Annex 22?
- The European Commission consulted on drafts of a revised Annex 11 and a new Annex 22 on artificial intelligence from 7 Jul 2025 to 7 Oct 2025. On 25 Sep 2026, EudraLex Volume 4 still listed the January 2011 revision of Annex 11. We will update this page when the revision is adopted.
- Where do we start with Annex 11 for this system?
- With the validation package. Its requirements and test scripts trace to the Annex 11 clauses the software supports, and its Part 11 and Annex 11 assessment lists every clause on this page with a column for your quality unit's conclusion.
See it with sample data
We show the review queue, a signed monitoring report, the audit trail review and the validation package, then answer your team's questions.