Regulations

EU GMP Annex 11, clause by clause

Annex 11 is the EU GMP guideline for computerised systems. Here is each clause that applies to this system, quoted from the 2011 text, with what the software does and what your procedures cover.

GMP workspace, sample data
The Validation page in the GMP workspace, showing the system version, the regulatory map, the validation package download and the control reports.
The Validation page. Sample data.

How to read it

Who meets each clause

Annex 11 applies to product for the EU market. The European Commission consulted on drafts of a revised Annex 11 and a new Annex 22 on artificial intelligence from 7 Jul 2025 to 7 Oct 2025. On 25 Sep 2026, EudraLex Volume 4 still listed the January 2011 revision of Annex 11. We will update this page when the revision is adopted. Sources: the consultation(opens the official source) and EudraLex Volume 4(opens the official source).
Software
The workspace provides the control. Your validation confirms it.
Software and site
Both the software and your procedures have a part.
Your procedures
Your procedures, training or infrastructure meet it. The software has no part, or only supports it.
Site deployment
The software part needs the installation at your site, such as sign-in through your identity provider.
met by the software
4
shared by the software and your procedures
5
met by your procedures
9
need the installation at your site
4

The clauses

18 Annex 11 clauses, quoted

  1. Annex 11, principle: Validation and qualification

    Your procedures
    “The application should be validated; IT infrastructure should be qualified. Where a computerised system replaces a manual operation, there should be no resultant decrease in product quality, process control or quality assurance.”

    Official textfor Annex 11, principle (opens in a new tab)Checked 24 Sep 2026

    The software
    The validation package covers the application; the IQ scripts cover the installed infrastructure.
    Your procedures
    Validate the application and qualify the infrastructure it runs on.
  2. Annex 11, clause 1: Risk management

    Your procedures
    “Risk management should be applied throughout the lifecycle of the computerised system taking into account patient safety, data integrity and product quality. As part of a risk management system, decisions on the extent of validation and data integrity controls should be based on a justified and documented risk assessment of the computerised system.”

    Official textfor Annex 11, clause 1 (opens in a new tab)Checked 24 Sep 2026

    The software
    The risk assessment rates each function high, medium or low, with its rationale, and sets how much testing it gets.
    Your procedures
    Review and approve the risk assessment, adjusting it for your process.
  3. Annex 11, clause 3.1: Agreements with suppliers

    Your procedures
    “When third parties (e.g. suppliers, service providers) are used e.g. to provide, install, configure, integrate, validate, maintain (e.g. via remote access), modify or retain a computerised system or related service or for data processing, formal agreements must exist between the manufacturer and any third parties, and these agreements should include clear statements of the responsibilities of the third party.”

    Official textfor Annex 11, clause 3.1 (opens in a new tab)Checked 24 Sep 2026

    The software
    The validation package includes a supplier quality agreement template.
    Your procedures
    Sign a quality agreement with ConductScience before GMP use.
  4. Annex 11, clause 3.2: Supplier assessment

    Your procedures
    “The competence and reliability of a supplier are key factors when selecting a product or service provider. The need for an audit should be based on a risk assessment.”

    Official textfor Annex 11, clause 3.2 (opens in a new tab)Checked 24 Sep 2026

    The software
    The system description and change control record support a supplier assessment.
    Your procedures
    Decide from your risk assessment whether to audit ConductScience.
  5. Annex 11, clause 4.3: System description

    Your procedures
    “For critical systems an up to date system description detailing the physical and logical arrangements, data flows and interfaces with other systems or processes, any hardware and software pre-requisites, and security measures should be available.”

    Official textfor Annex 11, clause 4.3 (opens in a new tab)Checked 24 Sep 2026

    The software
    The validation package includes a system description: components, data flows, interfaces and security.
    Your procedures
    Complete it with your network, storage and identity details.
  6. Annex 11, clause 4.4: User requirements

    Your procedures
    “User Requirements Specifications should describe the required functions of the computerised system and be based on documented risk assessment and GMP impact. User requirements should be traceable throughout the life-cycle.”

    Official textfor Annex 11, clause 4.4 (opens in a new tab)Checked 24 Sep 2026

    The software
    Each user requirement traces to its regulations, its function and its tests in the traceability matrix.
    Your procedures
    Review and approve the requirements, adding any of your own.
  7. Annex 11, clause 4.7: Test evidence

    Your procedures
    “Evidence of appropriate test methods and test scenarios should be demonstrated.”

    Official textfor Annex 11, clause 4.7 (opens in a new tab)Checked 24 Sep 2026

    The software
    The IQ, OQ and PQ scripts give steps and expected results, with space for actual results and signatures.
    Your procedures
    Execute the scripts, record the results and resolve deviations.
  8. Annex 11, clause 7.1: Data storage

    Software and siteSite deployment
    “Data should be secured by both physical and electronic means against damage. Stored data should be checked for accessibility, readability and accuracy. Access to data should be ensured throughout the retention period.”

    Official textfor Annex 11, clause 7.1 (opens in a new tab)Checked 24 Sep 2026

    The software
    Clips and frames stay on the site network; records are kept as structured data.
    Your procedures
    Secure the storage, and check stored data for access, readability and accuracy.

    Validation: URS-02, URS-24; tests IQ-01, IQ-04, IQ-05, OQ-01, PQ-03

    More: Aseptic behavior monitoring

  9. Annex 11, clause 7.2: Backups

    Your proceduresSite deployment
    “Regular back-ups of all relevant data should be done. Integrity and accuracy of back-up data and the ability to restore the data should be checked during validation and monitored periodically.”

    Official textfor Annex 11, clause 7.2 (opens in a new tab)Checked 24 Sep 2026

    The software
    A site deployment backs up its records on the schedule you set.
    Your procedures
    Back up regularly, test a restore in validation, and repeat the test periodically.

    Validation: URS-24; tests IQ-04, PQ-03

  10. Annex 11, clause 9: Audit trail

    Software
    “Consideration should be given, based on a risk assessment, to building into the system the creation of a record of all GMP-relevant changes and deletions (a system generated "audit trail"). For change or deletion of GMP-relevant data the reason should be documented. Audit trails need to be available and convertible to a generally intelligible form and regularly reviewed.”

    Official textfor Annex 11, clause 9 (opens in a new tab)Checked 24 Sep 2026

    The software
    Every decision is recorded with its reason, the audit trail exports in readable form (PDF, XLSX and CSV), and the audit trail review report supports its regular review.
    Your procedures
    Review the audit trail regularly.

    Validation: URS-06, URS-07, URS-08; tests OQ-04, OQ-05, OQ-18

    More: Audit trail, Validation package

  11. Annex 11, clause 10: Change control

    Software and site
    “Any changes to a computerised system including system configurations should only be made in a controlled manner in accordance with a defined procedure.”

    Official textfor Annex 11, clause 10 (opens in a new tab)Checked 24 Sep 2026

    The software
    Changes reach the system only in a versioned release, recorded with its validation impact.
    Your procedures
    Approve each release under your change control procedure before use.

    Validation: URS-26, URS-27; tests IQ-01, IQ-02, OQ-18, OQ-19, PQ-01

    More: Validation package

  12. Annex 11, clause 11: Periodic evaluation

    Software and site
    “Computerised systems should be periodically evaluated to confirm that they remain in a valid state and are compliant with GMP.”

    Official textfor Annex 11, clause 11 (opens in a new tab)Checked 24 Sep 2026

    The software
    The change control record, audit trail review and user access review give the evidence for a periodic review.
    Your procedures
    Evaluate the system periodically and record the result.

    Validation: URS-16; tests OQ-18

    More: Validation package

  13. Annex 11, clause 12.1: Access control

    Software
    “Physical and/or logical controls should be in place to restrict access to computerised system to authorised persons.”

    Official textfor Annex 11, clause 12.1 (opens in a new tab)Checked 24 Sep 2026

    The software
    Only authorized people open the workspace; anyone else sees a page that names nothing.
    Your procedures
    Grant access under your access procedure.

    Validation: URS-14; tests OQ-10

  14. Annex 11, clause 12.3: Access changes recorded

    Software and siteSite deployment
    “Creation, change, and cancellation of access authorisations should be recorded.”

    Official textfor Annex 11, clause 12.3 (opens in a new tab)Checked 24 Sep 2026

    The software
    A site deployment records who gave or removed each role, and when.
    Your procedures
    Review access changes in the periodic access review.

    Validation: URS-16, URS-17; tests IQ-06, OQ-18

  15. Annex 11, clause 12.4: Who entered data, and when

    Software
    “Management systems for data and for documents should be designed to record the identity of operators entering, changing, confirming or deleting data including date and time.”

    Official textfor Annex 11, clause 12.4 (opens in a new tab)Checked 24 Sep 2026

    The software
    Every decision records the person, role, date and time.
    Your procedures
    Confirm it in validation.

    Validation: URS-03; tests OQ-02, PQ-02

    More: Audit trail

  16. Annex 11, clause 14: Electronic signatures

    Software
    “Electronic records may be signed electronically. Electronic signatures are expected to: a. have the same impact as hand-written signatures within the boundaries of the company, b. be permanently linked to their respective record, c. include the time and date that they were applied.”

    Official textfor Annex 11, clause 14 (opens in a new tab)Checked 24 Sep 2026

    The software
    Signatures carry the name, date, time and meaning, and are bound to the report data they sign.
    Your procedures
    Give electronic signatures the same standing as handwritten ones in your procedures.

    Validation: URS-09, URS-10; tests OQ-06, OQ-07

    More: Electronic signatures, Validation package

  17. Annex 11, clause 16: Business continuity

    Software and siteSite deployment
    “For the availability of computerised systems supporting critical processes, provisions should be made to ensure continuity of support for those processes in the event of a system breakdown (e.g. a manual or alternative system).”

    Official textfor Annex 11, clause 16 (opens in a new tab)Checked 24 Sep 2026

    The software
    Detection and clip storage run on the monitoring computer, apart from the workspace.
    Your procedures
    Write a continuity procedure: what reviewers do while the workspace is down, and how they catch up.

    Validation: URS-25; tests PQ-04

    More: Aseptic behavior monitoring

  18. Annex 11, clause 17: Archiving

    Your procedures
    “Data may be archived. This data should be checked for accessibility, readability and integrity. If relevant changes are to be made to the system (e.g. computer equipment or programs), then the ability to retrieve the data should be ensured and tested.”

    Official textfor Annex 11, clause 17 (opens in a new tab)Checked 24 Sep 2026

    The software
    Records export as PDF, XLSX and CSV, which open without the system.
    Your procedures
    If you archive records, check that they stay readable and retrievable, including after system changes.

Questions

Common questions

Does Annex 11 apply to us?
Annex 11 is part of the EU guidelines for good manufacturing practice, which apply to medicines for the EU market. Your regulatory team confirms which markets and inspectorates apply to your site.
How is Annex 11 different from Part 11?
Part 11 is a binding US regulation about electronic records and electronic signatures. Annex 11 is an EU guideline about the whole life of a computerised system: risk management, suppliers, validation, data, audit trails, security, change and continuity.
What about the revised Annex 11 and the new Annex 22?
The European Commission consulted on drafts of a revised Annex 11 and a new Annex 22 on artificial intelligence from 7 Jul 2025 to 7 Oct 2025. On 25 Sep 2026, EudraLex Volume 4 still listed the January 2011 revision of Annex 11. We will update this page when the revision is adopted.
Where do we start with Annex 11 for this system?
With the validation package. Its requirements and test scripts trace to the Annex 11 clauses the software supports, and its Part 11 and Annex 11 assessment lists every clause on this page with a column for your quality unit's conclusion.

See it with sample data

We show the review queue, a signed monitoring report, the audit trail review and the validation package, then answer your team's questions.

Request a walkthrough