The EU GMP Annex 11 revision 2025 is the draft update of EU GMP Annex 11 "Computerised Systems", published on 7 July 2025 by the European Commission together with PIC/S and open for public consultation until 7 October 2025. It is the first complete rewrite since 2011: the document grows from roughly 5 to 19 pages and resets inspectors' expectations on validation, audit trails, security and cloud services. For anyone working in QA, CSV or IT Quality the message is clear: GxP computerised systems will no longer be judged on initial validation alone, but across their entire lifecycle, with far more weight on data integrity and access control.
EU GMP Annex 11 revision: what was published and why
The revision does not come alone. On 7 July 2025 three EudraLex Volume 4 documents, prepared by the EMA Inspectors' Working Group together with PIC/S, went into joint consultation:
- the revision of Chapter 4 – Documentation, which formally embeds data integrity principles (raw data, metadata, hybrid systems);
- the revision of Annex 11 – Computerised Systems, the subject of this article;
- the new Annex 22 – Artificial Intelligence, dedicated to the use of AI/ML models in GMP.
The logic is obvious: the current Annex 11 dates from 2011, an era when cloud, SaaS, mobile apps and machine learning played a marginal role in pharmaceutical operations. The draft brings the regulatory perimeter up to date with technologies that are now everywhere, from cloud-hosted LIMS to MES systems integrated with the ERP.
The new structure: 17 chapters plus a glossary
The draft abandons the concise list of 17 clauses from 2011 and adopts a thematic chapter structure: scope, principles, pharmaceutical quality system, risk management, personnel and training, system requirements, supplier and service management, alarms, qualification and validation, handling of data, identity and access management, audit trails, electronic signatures, periodic review, security, backup and archiving, plus a final glossary. Text analysis shows a clear shift in emphasis: while validation is by far the most developed topic in the current Annex 11, the most substantial chapters in the draft are security, identity and access management, qualification and validation, audit trails and supplier management.
Topics like this evolve month by month between drafts, consultations and final versions. If you want a practical, no-fluff weekly update on GMP and data integrity, subscribe to The Pragmatic GMP, our free newsletter: the easiest way to be ready when the final Annex 11 lands.
What really changes compared to Annex 11 (2011)
The table summarises the most relevant differences from an operational standpoint:
| Area | Annex 11 (2011) | Draft 2025 |
|---|---|---|
| Scope | Computerised systems used in GMP activities | Explicitly extended to cloud, SaaS, mobile apps, industrial IoT and systems with an indirect impact on quality and data integrity |
| Audit trails | Required for changes and deletions of GMP-relevant data | Secure, time-stamped, tamper-evident audit trails linked to the user; structured, risk-based review |
| Access | Generic access controls | Dedicated chapter on identity and access management: unique credentials, roles, segregation of duties |
| Suppliers and cloud | Risk-based supplier audits | Formal service-provider management: GMP responsibility cannot be outsourced, not even to cloud or AI providers |
| Electronic signatures | Equivalence to handwritten signatures | Two-factor authentication or biometrics recommended |
| Artificial intelligence | Not addressed | Reference to the new Annex 22, limited to static, deterministic models |
One point deserves special attention: the supplier chapter. With the massive migration to SaaS platforms, the draft reiterates that supplier qualification, technical agreements and ongoing oversight are an integral part of system compliance, and that the pharmaceutical company remains solely accountable in front of the inspector.
Annex 22: AI enters GMP — cautiously
The new Annex 22, in just 11 sections, governs the use of artificial intelligence models in GMP and is limited to static, deterministic models: documented intended use, measurable acceptance criteria, independence of test data and explainability of results. Generative models and dynamically learning models remain outside the perimeter of critical applications. For most manufacturing sites the immediate impact will be limited, but the direction is set: anyone bringing AI into GxP processes will have to treat it with the same documentation rigour as any other computerised system.
Timeline: where we stand
The consultation closed on 7 October 2025 and the final versions of Annex 11, Annex 22 and Chapter 4 are expected from mid-2026, with the operative date to be set in the final texts. At the time of writing the final version has not yet been published: the 2011 Annex 11 remains the rule, but the draft is already the most concrete reference for understanding where inspections are heading. Several authorities are, after all, already citing deficiencies in audit trail review and access management under existing data integrity principles.
GuideGxP recommendation
Do not wait for the final text to act: the draft requirements are stable enough to justify a gap analysis now. In practice:
- Update your inventory of GxP computerised systems to include cloud services, mobile apps and interfaces, with a criticality assessment for each.
- Run a chapter-by-chapter gap analysis of the draft, prioritising audit trails, identity and access management and security.
- Review contracts and qualification of SaaS/cloud providers: make sure roles, responsibilities and data access are defined and defensible in audit.
- Formalise (or strengthen) risk-based audit trail review, with frequencies and responsibilities written into a procedure.
- Bring the evidence into your PQS: change control, periodic system review and data integrity KPIs discussed in management review.
If you want a ready-made framework for setting up validation and system lifecycle in an audit-ready way, our Operational Guide to Computer System Validation (CSV) in GxP covers exactly this: inventory, risk assessment, validation protocols and maintenance of the validated state, with ready-to-use templates.