Ad Code

EU GMP Annex 11 Computerized Systems Validation

WebOfPharma · EU GMP Computerized Systems

EU GMP Annex 11 Computerized Systems Validation

A practical guide to validating computerized systems used in GMP-regulated activities, from risk assessment and user requirements to audit trails, security, business continuity, and archiving.

Annex 11 lifecycle Risk-based validation Data integrity Supplier oversight

Quick answer

EU GMP Annex 11 computerized systems validation requires a lifecycle approach for systems used in GMP-regulated activities. The application should be validated, the supporting IT infrastructure should be qualified, and the depth of controls should be justified by documented risk assessment considering patient safety, product quality, and data integrity. A compliant program also controls suppliers, user requirements, testing, data migration, audit trails, security, incidents, electronic signatures, business continuity, and archiving.

Scope

What does Annex 11 cover?

All forms of computerized systems used as part of GMP-regulated activities, including applications, infrastructure, interfaces, and data services.

Strategy

What drives validation depth?

A documented risk assessment focused on patient safety, product quality, data integrity, and process control.

Evidence

What must be shown?

Traceable requirements, suitable testing, controlled deviations, reliable records, security, and approved lifecycle reports.

Operations

What continues after release?

Periodic evaluation, access control, incident management, change control, backup, continuity, and archive retrieval.

What Is EU GMP Annex 11?

EU GMP Annex 11 is the EudraLex Volume 4 annex for computerized systems used in GMP-regulated activities. It explains how manufacturers should validate applications, qualify IT infrastructure, manage risk, protect data, and keep computerized systems in a compliant state.

Annex 11 applies to more than a single laboratory or manufacturing application. The scope can include LIMS, MES, electronic batch records, QMS, ERP, stability systems, environmental monitoring, instrument software, building-management interfaces, spreadsheets, cloud platforms, databases, middleware, and archives whenever they support a GMP process or regulated record.

Published-versus-draft status: The European Commission's current EudraLex Volume 4 page lists Annex 11 as “Computerised Systems (revision January 2011).” The Commission also published revised Annex 11 consultation materials in 2025. Those draft materials should be monitored, but they should not be described as the operative final annex until formally adopted.

Build the system strategy within your site's cGMP framework and confirm the current EU, national, and marketing-authorisation obligations for the products and activities involved.

Annex 11 Principle: Application Validation and IT Qualification

Annex 11 separates two related responsibilities. The computerized application should be validated for its intended GMP functions, while the supporting IT infrastructure should be qualified and maintained in a controlled state.

LayerWhat it includesTypical evidence
ApplicationWorkflows, calculations, reports, user roles, audit trails, signatures, limits, interfaces, and business rules.URS, functional specifications, risk assessment, test protocols, traceability, validation summary, SOPs.
IT infrastructureServers, operating systems, databases, networks, virtualization, storage, time services, backup, and security components.Infrastructure qualification, configuration baseline, monitoring, patching, backup/restore, disaster-recovery and security evidence.
Process and peopleProcess owner, system owner, Qualified Person, IT, Quality, users, suppliers, and reviewers.Role matrix, training, procedures, access approvals, review records, incident and change-control evidence.

When a computerized system replaces a manual operation, the change must not decrease product quality, process control, or quality assurance, and must not increase overall process risk.

EU GMP Annex 11 Requirements at a Glance

The published annex is organized into a principle, general requirements, project-phase controls, and operational-phase controls. The table below translates its 17 numbered topics into practical validation questions.

Annex 11 topicPractical validation question
1. Risk managementIs validation depth and data-integrity control justified by patient, product, process, and data risk?
2. PersonnelAre process owners, system owners, Qualified Persons, Quality, IT, and users qualified with defined responsibilities?
3. Suppliers and service providersAre responsibilities, competence, contracts, audits, and supplier documentation controlled?
4. ValidationDoes the lifecycle package cover inventory, system description, URS, testing, migration, deviations, and change control?
5. DataDo system-to-system exchanges include checks for correct and secure entry and processing?
6. Accuracy checksAre critical manual entries checked by a second operator or validated electronic means?
7. Data storageAre data protected, accessible, readable, accurate, backed up, and restorable throughout retention?
8. PrintoutsCan the site generate clear copies and show whether batch-release data changed after entry?
9. Audit trailsAre GMP-relevant changes and deletions traceable, intelligible, reasoned, and regularly reviewed?
10. Change and configuration managementAre application and configuration changes made only through a defined controlled procedure?
11. Periodic evaluationDoes review confirm that functionality, performance, security, incidents, upgrades, and validation status remain acceptable?
12. SecurityAre logical and physical access controls appropriate to system criticality and recorded?
13. Incident managementAre all incidents reported, assessed, investigated, and connected to corrective and preventive action?
14. Electronic signatureIs the signature permanently linked to its record and accompanied by date and time?
15. Batch releaseCan only authorized Qualified Persons certify release, with identity and electronic signature recorded?
16. Business continuityAre alternative arrangements documented, risk-based, available, and tested for critical processes?
17. ArchivingCan archived data be retrieved, read, and shown to remain intact after technology changes?

Risk-Based Annex 11 Validation Lifecycle

Annex 11 expects risk management throughout the lifecycle. A practical lifecycle begins with the GMP process and ends only when the system is retired and its records remain available.

01
Inventory and GMP impactList applications, infrastructure, interfaces, spreadsheets, instruments, archives, and the GMP functions they support.
02
Process and system ownershipAssign process owner, system owner, Quality, IT, Qualified Person, users, and supplier responsibilities.
03
Risk assessmentAssess patient safety, product quality, data integrity, release decisions, interface failure, security, and availability risks.
04
User requirementsDefine functions, data, records, reports, audit trails, signatures, retention, security, interfaces, and continuity needs.
05
Supplier and design reviewAssess supplier quality systems, configuration, architecture, data flows, service commitments, and technology prerequisites.
06
Qualification and testingQualify infrastructure and execute risk-based functional, security, migration, interface, recovery, and performance tests.
07
Release and trainingResolve deviations, approve the validation report, establish procedures, train users, and authorize GMP use.
08
Operate and retirePerform periodic evaluation, access review, audit-trail review, change control, continuity testing, migration, and archiving.

Annex 11 Risk Management and Data Integrity

Risk management should determine the extent of validation and the strength of data-integrity controls. The assessment should be documented and reassessed when the process, system, data flow, supplier, or technology changes.

Risk areaExample riskControl and validation response
Patient or product riskA calculation, status, or release decision is wrong.Critical-function testing, boundary challenges, independent review, controlled approvals, and monitoring.
Data-integrity riskOriginal data, metadata, rejected results, or audit-trail history cannot be reconstructed.Native-data retention, audit-trail tests, ALCOA+ review, access controls, and archive retrieval.
Interface riskValues are lost, duplicated, truncated, or changed during transfer.Data mapping, reconciliation, positive/negative transfer tests, error queues, and migration checks.
Availability riskA critical manufacturing or laboratory process stops after a system failure.Backup/restore, business continuity, manual alternative, recovery objectives, and periodic exercises.
Supplier riskA vendor changes infrastructure, code, or service without adequate impact assessment.Quality agreement, supplier monitoring, release notices, change assessment, and customer regression testing.

Use ALCOA+ as a practical data-integrity lens, while remembering that Annex 11 also requires system governance, security, supplier management, business continuity, and operational oversight.

Personnel, Roles, and Responsibilities

Annex 11 expects close cooperation among process owners, system owners, Qualified Persons, IT, Quality, and users. A validation report cannot compensate for unclear ownership after go-live.

RoleTypical responsibility
Process ownerDefines the GMP process, critical decisions, controls, records, and business acceptance criteria.
System ownerMaintains availability, configuration, security, data protection, vendor coordination, and system lifecycle status.
Quality/QAProvides quality oversight, approves risk and validation decisions, reviews deviations, and verifies continued compliance.
Qualified PersonConfirms that systems supporting certification and batch release permit authorized and traceable certification.
IT/infrastructureControls infrastructure, patching, backup, monitoring, access technology, disaster recovery, and technical support.
Supplier/service providerDelivers agreed services, documentation, support, changes, incident notifications, and evidence under formal agreements.

Training should be role-based and cover normal operation, data review, audit trails, electronic signatures, error handling, security, incident escalation, and approved manual alternatives.

Supplier and Service Provider Qualification

When a third party supplies, configures, integrates, validates, maintains, remotely accesses, or retains a computerized system, responsibilities must be defined formally. A quality agreement or equivalent contract should state who owns data, security, backup, incident reporting, change notification, validation support, and record retrieval.

  • Supplier competence and reliability are assessed before selection.
  • Supplier audit need is justified by risk and service criticality.
  • Commercial off-the-shelf documentation is reviewed against user requirements.
  • Remote-access, support, and privileged-administrator controls are defined.
  • Supplier changes, releases, defects, incidents, and security notifications are communicated.
  • Service-level expectations include availability, backup, recovery, and data export.
  • Supplier quality-system and audit information can be made available to inspectors.
  • Customer-specific configuration, roles, workflows, interfaces, and reports are tested.

For a cloud or SaaS service, vendor evidence is useful but does not replace an assessment of the customer's intended use, configuration, data flows, record retention, exit plan, and risk-critical controls.

Validation Documentation, Inventory, and URS

Annex 11 expects lifecycle documentation, an up-to-date inventory of relevant systems and GMP functionality, and a current system description for critical systems. The description should cover physical and logical arrangements, data flows, interfaces, prerequisites, and security measures.

Core documents to plan

  • Computerized-system inventory with GMP function and criticality.
  • Validation master plan or project validation plan.
  • Process map, system boundary, architecture, data flow, and interface diagrams.
  • Approved URS based on GMP impact and documented risk.
  • Functional, configuration, security, interface, migration, and reporting specifications.
  • Risk assessment and traceability matrix maintained through the lifecycle.
  • Validation protocols, objective evidence, deviations, and approved reports.
  • Configuration baseline, release notes, access matrix, and controlled procedures.

User requirements should remain traceable through design, configuration, testing, operation, changes, and retirement. Avoid copying supplier features into the URS without deciding which functions are actually needed for the GMP process.

Test Methods, Limits, Error Handling, and Data Migration

Annex 11 expects evidence that test methods and scenarios are appropriate. Testing should consider process-parameter limits, data limits, error handling, automated test tools, test environments, and the risk that data may change in value or meaning during transfer.

Test categoryExample challengeEvidence to retain
FunctionalComplete a representative GMP workflow from data entry to review, approval, report, and archive.Executed protocol, expected result, actual result, screenshots or system reports, reviewer sign-off.
Boundary and limitsEnter values at, below, and above critical limits; test invalid formats and missing fields.Acceptance criteria, error message, blocked action, exception workflow, and risk conclusion.
Audit trailChange, correct, delete, reprocess, approve, and reject a GMP-relevant record.User, time, old/new values, reason, record linkage, review output, and escalation decision.
InterfaceTransmit complete, partial, duplicate, delayed, corrupted, or out-of-sequence data.Data mapping, reconciliation, message logs, error handling, and recovery evidence.
MigrationMove representative records to a new database, format, archive, or application.Before/after comparison showing unchanged values, meaning, metadata, signatures, and audit history.
RecoveryRestore data and resume a critical process after system, network, or storage failure.Backup identity, restore result, completeness check, recovery time, business decision, and approval.

Automated testing tools and test environments should themselves be assessed for suitability. A fast test is not useful if its data, environment, or results cannot support a defensible GMP decision.

Data, Accuracy Checks, Storage, and Printouts

Annex 11 places operational emphasis on data quality. Systems exchanging data electronically should include built-in checks for correct and secure entry and processing. Critical manual entries need an additional accuracy check by a second operator or validated electronic means.

A
Input validationCheck format, range, completeness, units, identity, duplicate entry, and required fields before data are accepted.
B
Data storageProtect data physically and electronically; verify accessibility, readability, accuracy, and access throughout retention.
C
Backup and restoreBack up relevant data regularly and periodically check backup integrity, accuracy, and restore capability.
D
Printouts and copiesGenerate clear copies and show whether batch-release data changed after original entry when that distinction is required.

Include metadata, audit-trail history, calculation context, attachments, signature meaning, and linked records in the copy and retrieval assessment where those elements are needed to understand the GMP decision.

Audit Trails and Electronic Signatures

Audit trails and electronic signatures are not isolated software features. They are controls that let a reviewer reconstruct who did what, when, why, and under which approved workflow.

ControlAnnex 11 expectationValidation and operation
Audit trailGMP-relevant changes and deletions are recorded, reasons are documented, and the trail is intelligible and regularly reviewed.Test old/new values, user, date/time, reason, record link, report export, privileged actions, and review procedure.
Electronic signatureThe signature has the same internal impact as a handwritten signature, remains permanently linked to the record, and includes date/time.Test identity, meaning, linkage, version, co-signature, cancellation, delegation, credentials, and unauthorized use.
Batch releaseOnly authorized Qualified Persons certify release and the releasing person is clearly identified using an electronic signature.Test role restriction, approval sequence, signature manifestation, release status, and record retrieval.

For organizations operating in both EU and U.S. markets, map Annex 11 controls to the applicable 21 CFR and predicate-rule requirements rather than assuming that one checklist proves every jurisdictional obligation.

Change and Configuration Management

Any change to software, configuration, infrastructure, master data, interface, security, report, workflow, or supplier service should be assessed through a defined procedure. The question is not only “Did the software version change?” but also “Could the change affect a GMP function, record, decision, or control?”

  • Change request defines the reason, scope, owner, risk, and affected GMP functions.
  • Configuration baseline and approved version are identified before implementation.
  • Impact assessment covers requirements, validation, security, data integrity, interfaces, and procedures.
  • Regression testing targets functions and controls affected by the change.
  • Data migration and report changes are verified for unchanged value and meaning.
  • Training, SOPs, access, support documentation, and release notes are updated.
  • Post-implementation review confirms successful operation and closed actions.

When a change or incident reveals a systemic weakness, document investigation and corrective action through CAPA new or the approved site process.

Periodic Evaluation and Security

Periodic evaluation confirms that a computerized system remains in a valid state and compliant with GMP. The review should be evidence-based, not a signature-only exercise.

Review inputWhat to assess
Functionality and performanceCurrent use, new modules, capacity, reliability, errors, response, availability, and critical-function performance.
Deviations and incidentsRecurring failures, data errors, security events, audit-trail findings, investigations, and CAPA effectiveness.
Upgrade and change historySupplier releases, patches, configuration changes, migrations, interfaces, and regression evidence.
Security and accessAccount review, privileged access, leavers, password controls, vulnerabilities, remote access, and monitoring.
Validation statusOpen actions, overdue reviews, traceability, current procedures, training, backup tests, and archive retrieval.

Security controls should be proportionate to system criticality. Record creation, change, and cancellation of access authorizations, and ensure data and document management systems identify operators with dates and times.

Incident Management, Business Continuity, and Archiving

Annex 11 extends beyond system failures. All incidents should be reported and assessed, including data errors, unexpected behavior, security events, interface failures, backup problems, and procedural workarounds.

AreaMinimum practical expectationValidation evidence
Incident managementReport, triage, investigate, identify root cause for critical incidents, and assess impact on data and product decisions.Incident SOP, assessment form, investigation, data review, escalation, CAPA, and effectiveness evidence.
Business continuityProvide a risk-based manual or alternative system for critical processes and make the recovery time appropriate to the process.Continuity plan, role assignments, tested scenario, recovery result, manual records, reconciliation, and approval.
ArchivingPreserve accessibility, readability, and integrity; test retrieval after equipment, program, or format changes.Archive inventory, retention rationale, retrieval challenge, metadata check, migration comparison, and owner sign-off.

Do not treat an archive as a storage location only. It is part of the record lifecycle and must preserve the context needed to understand and defend a GMP decision.

Qualification and Validation Evidence: DQ, IQ, OQ, and PQ

Annex 11 does not prescribe one universal protocol naming convention. The evidence should be proportionate to risk and should demonstrate that the application, infrastructure, configuration, and process perform as intended.

ActivityAnnex 11 focusExample question
DQDesign and intended-use fitDoes the architecture support GMP data flows, security, audit trails, signatures, retention, and continuity?
IQInstallation or configuration baselineAre approved versions, infrastructure, prerequisites, interfaces, security settings, and documentation present?
OQFunctional, security, and error behaviorDoes the system enforce limits, roles, workflows, audit trails, signatures, and error handling?
PQRoutine GMP useCan trained users complete representative processes and produce reliable records under expected conditions?

Use an approved SOP to define how protocols, deviations, approvals, release decisions, and requalification or revalidation are managed.

Practical Annex 11 Test Scenarios

Test scenarios should reflect real GMP decisions. A system can pass a configuration check and still fail when an operator corrects a result, a reviewer rejects a batch step, or an interface is unavailable.

System exampleRisk-critical scenarioEvidence to capture
LIMS and instrumentsAcquire, process, reprocess, review, approve, correct, and report a laboratory result.Raw data, methods, metadata, audit trail, result history, signatures, report, and rejected-data handling.
MES or electronic batch recordExecute a manufacturing step, exceed a limit, invoke an exception, and obtain authorized approval.Step sequence, operator identity, limit response, exception rationale, approval, and batch record copy.
QMS deviation/CAPACreate, investigate, approve, extend, close, and reopen a quality event.Workflow, roles, due dates, attachments, audit trail, signatures, and closure rationale.
Stability systemSchedule a pull, record an out-of-trend result, assess a missed time point, and approve a report.Sample identity, time point, result history, alerts, investigation, approvals, and archive retrieval.
ERP or material systemChange material status, block release, transfer inventory, and reconcile an interface.Authorization, transaction history, interface message, error handling, reconciliation, and report.
Cloud platformRestore data, change configuration, remove a user, export a record, and review supplier release impact.Tenant settings, user history, backup/restore, export, supplier notice, impact assessment, and regression result.

Annex 11 Validation Documentation Checklist

Use this checklist for a readiness review or validation master plan. Mark each item complete, open, not applicable with rationale, or requiring action.

  • System inventory identifies GMP function, owner, supplier, interfaces, and criticality.
  • Risk assessment considers patient safety, product quality, data integrity, and availability.
  • Process owner, system owner, Quality, IT, Qualified Person, and supplier responsibilities are defined.
  • System description covers architecture, data flow, interfaces, prerequisites, and security.
  • Approved URS is based on risk and GMP impact and remains traceable throughout the lifecycle.
  • Supplier assessment and formal agreements define responsibilities, data access, support, and changes.
  • Validation protocols cover critical functions, limits, errors, interfaces, audit trails, signatures, and migration.
  • Infrastructure qualification and application validation are connected but appropriately scoped.
  • Backups, restoration, continuity, archiving, and record retrieval have been challenged.
  • Access creation, change, cancellation, periodic review, and privileged activity are controlled.
  • Audit trails are available, intelligible, reasoned, and regularly reviewed.
  • Electronic signatures are linked to records and include date/time and meaningful approval context.
  • Incidents, deviations, and critical data errors are investigated and connected to CAPA where appropriate.
  • Periodic evaluation covers functionality, incidents, upgrades, performance, security, and validation status.
  • Retirement and data migration plans protect record readability, accessibility, and integrity.

Common EU GMP Annex 11 Gaps

GapWhy inspectors and auditors careBetter practice
Inventory is incompleteUnlisted spreadsheets, instruments, interfaces, or archives can bypass validation and oversight.Maintain an owner-approved inventory tied to GMP functions and record types.
Validation focuses only on application screensInfrastructure, time services, interfaces, storage, backup, and security can affect record integrity.Qualify infrastructure and map the end-to-end data lifecycle.
Supplier package is accepted without reviewCustomer configuration and intended use may not match supplier test scope.Assess supplier evidence, then execute customer-specific risk-based testing.
Audit trail is enabled but not reviewedPotential data changes remain undetected or unexplained.Define event scope, reviewer, frequency, sampling, escalation, and investigation.
Backups exist but restore is untestedAvailability and record continuity are assumed rather than demonstrated.Perform periodic restore and reconciliation tests with documented results.
Periodic review is a signature-only exerciseIncidents, changes, security, performance, and open validation actions may be missed.Use evidence-based review inputs and record a clear continued-valid-state decision.
Business continuity is theoreticalCritical GMP processes may not continue after a system breakdown.Test manual or alternate arrangements, recovery time, reconciliation, and re-entry.

How Annex 11 Connects With Part 11, cGMP, and Process Validation

Annex 11 is an EU GMP framework for computerized systems. It should be implemented alongside the site's broader cGMP procedures, data-integrity program, qualification strategy, and quality risk management system.

ConnectionPractical relationship
EU GMP Annex 11 and 21 CFRMap common controls such as validation, access, audit trails, signatures, records, and security while retaining jurisdiction-specific requirements.
Annex 11 and ALCOA+Use data-integrity principles to evaluate the quality, traceability, completeness, and availability of records across the lifecycle.
Annex 11 and qualificationUse DQ, IQ, OQ, and PQ or equivalent evidence according to risk.
Annex 11 and process validationConnect electronic process data, manufacturing records, laboratory results, and release decisions to Process Validation in Pharmaceuticals.
Annex 11 and quality eventsUse CAPA and CAPA new when incidents, deviations, or periodic reviews identify systemic weaknesses.

Regulatory Reference Points

Use primary regulatory sources when updating a validation plan, writing an SOP, or confirming whether draft wording has become operative:

Publishing note: Regulatory text and guidance can change. Always confirm the current EudraLex status, national implementation, product-specific obligations, and approved site procedures before relying on this article for a compliance decision.

Key Takeaways

  • Annex 11 applies to all forms of computerized systems used in GMP-regulated activities.
  • Validate the application and qualify the supporting IT infrastructure; do not treat infrastructure as invisible.
  • Use documented risk assessment throughout the lifecycle, considering patient safety, product quality, data integrity, and process control.
  • Maintain an accurate inventory, system description, traceable URS, supplier oversight, test evidence, and deviation records.
  • Protect records with access control, audit trails, electronic signatures, backups, secure storage, and reliable retrieval.
  • Review incidents, upgrades, performance, security, and validation status through periodic evaluation.
  • Test business continuity and archiving rather than assuming that backup or retrieval will work when needed.
  • Monitor the 2025 Annex 11 revision work, but distinguish draft consultation material from the currently published operative annex.

Conclusion

EU GMP Annex 11 computerized systems validation is a lifecycle discipline that connects technology with pharmaceutical quality. A defensible program begins with the GMP process and intended use, applies documented risk management, controls suppliers and infrastructure, verifies critical functions, and preserves trustworthy records throughout operation and retirement.

The strongest systems are not simply “validated at go-live.” They remain in a controlled state because teams review audit trails, manage changes, investigate incidents, test continuity, reassess security, and prove that records can still be read and retrieved. That is how Annex 11 becomes practical evidence of product quality, patient protection, and data integrity.

Related Pharmaceutical Validation Guides

Continue the WebOfPharma computerized-system and quality-assurance series:

Frequently Asked Questions

What is EU GMP Annex 11?

EU GMP Annex 11 is the EudraLex Volume 4 annex that sets expectations for computerized systems used in GMP-regulated activities. It covers validation, risk management, suppliers, data, security, audit trails, electronic signatures, continuity, and archiving.

Does Annex 11 apply to every computerized system in a pharmaceutical company?

It applies to computerized systems used as part of GMP-regulated activities. Systems that do not support regulated processes may fall outside the direct scope, but the organization should document the assessment and consider interfaces and shared infrastructure.

What is the difference between application validation and IT infrastructure qualification?

Application validation demonstrates that the software performs its intended GMP functions. Infrastructure qualification demonstrates that the hardware, operating systems, databases, networks, storage, and related technical environment are installed and controlled to support the application.

Does Annex 11 require a specific number of validation batches or test scripts?

No. Annex 11 expects justified, risk-based validation evidence. The number and depth of tests should reflect intended use, criticality, complexity, data risk, supplier evidence, interfaces, and the impact of failure.

What does risk management mean under Annex 11?

Risk management means using a documented assessment throughout the lifecycle to determine controls and validation depth based on patient safety, product quality, data integrity, process control, availability, and regulatory decisions.

What should be included in an Annex 11 URS?

The URS should describe required GMP functions, critical data, users, roles, workflows, limits, calculations, audit trails, electronic signatures, interfaces, reports, retention, security, backup, recovery, and business continuity needs.

Are audit trails mandatory for every field and every system?

Annex 11 expects risk-based consideration of system-generated audit trails for GMP-relevant changes and deletions. The organization should define which events are critical, ensure reasons are documented where applicable, make the trail intelligible, and review it regularly.

How does Annex 11 address electronic signatures?

Electronic signatures should have the same internal impact as handwritten signatures, remain permanently linked to their records, and include the date and time applied. Validation should test identity, meaning, linkage, and authorized use.

Is supplier validation evidence enough for a SaaS system?

Supplier evidence is valuable but does not usually cover customer-specific configuration, roles, workflows, interfaces, record retention, data export, and intended use. Perform a documented supplier assessment and customer risk-based testing.

How often should an Annex 11 system undergo periodic evaluation?

The frequency should be justified by risk, system criticality, change rate, incidents, supplier releases, and process impact. The review should consider functionality, deviations, incidents, upgrades, performance, reliability, security, and validation status.

What does Annex 11 require for backup and restore?

Relevant data should be backed up regularly, and backup integrity, accuracy, and the ability to restore should be checked during validation and monitored periodically. Restoration should be demonstrated with representative records and reconciliation.

What is required for business continuity?

Critical processes should have documented, risk-based manual or alternative arrangements that can be brought into use within an appropriate time. The arrangements should be tested and include reconciliation when the system returns.

How should data migration be validated under Annex 11?

Migration validation should show that data retain their value and meaning when transferred to another format or system. Compare representative records, metadata, signatures, audit history, attachments, calculations, and retrieval behavior.

Are IQ, OQ, and PQ still used for Annex 11 systems?

Yes, when they are appropriate to the system and risk. DQ, IQ, OQ, PQ, functional testing, configuration verification, or combined evidence can be used, provided the lifecycle package demonstrates intended use and continued control.

How does Annex 11 connect with ALCOA+?

Annex 11 provides technical and operational controls that help records remain attributable, accurate, complete, consistent, enduring, and available. ALCOA+ is a broader data-integrity framework applied across systems, people, procedures, and records.

What happens when an Annex 11 incident affects a GMP record?

Report and assess the incident, determine the impact on records and product decisions, preserve evidence, investigate root cause, assess the validated state, and implement corrective and preventive action when required.

WebOfPharma editorial note: confirm the current EudraLex status, national requirements, product-specific obligations, and approved site procedures before using this article as a compliance decision.