Data Integrity & CSV

EU GMP Annex 11 Revision: Draft Changes You Must Know

The EU GMP Annex 11 revision 2025 rewrites the rules for computerised systems: 17 chapters with a strong focus on security, audit trails, access management and cloud services. Here is what changes compared to 2011 and how to start your gap analysis today.

G GuideGxP 4 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Illustrazione editoriale GuideGxP a colori sul tema GMP: revisione Annex 11 e sistemi computerizzati con audit trail e cloud.

The EU GMP Annex 11 revision 2025 is the draft update of EU GMP Annex 11 "Computerised Systems", published on 7 July 2025 by the European Commission together with PIC/S and open for public consultation until 7 October 2025. It is the first complete rewrite since 2011: the document grows from roughly 5 to 19 pages and resets inspectors' expectations on validation, audit trails, security and cloud services. For anyone working in QA, CSV or IT Quality the message is clear: GxP computerised systems will no longer be judged on initial validation alone, but across their entire lifecycle, with far more weight on data integrity and access control.

EU GMP Annex 11 revision: what was published and why

The revision does not come alone. On 7 July 2025 three EudraLex Volume 4 documents, prepared by the EMA Inspectors' Working Group together with PIC/S, went into joint consultation:

  • the revision of Chapter 4 – Documentation, which formally embeds data integrity principles (raw data, metadata, hybrid systems);
  • the revision of Annex 11 – Computerised Systems, the subject of this article;
  • the new Annex 22 – Artificial Intelligence, dedicated to the use of AI/ML models in GMP.

The logic is obvious: the current Annex 11 dates from 2011, an era when cloud, SaaS, mobile apps and machine learning played a marginal role in pharmaceutical operations. The draft brings the regulatory perimeter up to date with technologies that are now everywhere, from cloud-hosted LIMS to MES systems integrated with the ERP.

The new structure: 17 chapters plus a glossary

The draft abandons the concise list of 17 clauses from 2011 and adopts a thematic chapter structure: scope, principles, pharmaceutical quality system, risk management, personnel and training, system requirements, supplier and service management, alarms, qualification and validation, handling of data, identity and access management, audit trails, electronic signatures, periodic review, security, backup and archiving, plus a final glossary. Text analysis shows a clear shift in emphasis: while validation is by far the most developed topic in the current Annex 11, the most substantial chapters in the draft are security, identity and access management, qualification and validation, audit trails and supplier management.

Topics like this evolve month by month between drafts, consultations and final versions. If you want a practical, no-fluff weekly update on GMP and data integrity, subscribe to The Pragmatic GMP, our free newsletter: the easiest way to be ready when the final Annex 11 lands.

What really changes compared to Annex 11 (2011)

The table summarises the most relevant differences from an operational standpoint:

AreaAnnex 11 (2011)Draft 2025
ScopeComputerised systems used in GMP activitiesExplicitly extended to cloud, SaaS, mobile apps, industrial IoT and systems with an indirect impact on quality and data integrity
Audit trailsRequired for changes and deletions of GMP-relevant dataSecure, time-stamped, tamper-evident audit trails linked to the user; structured, risk-based review
AccessGeneric access controlsDedicated chapter on identity and access management: unique credentials, roles, segregation of duties
Suppliers and cloudRisk-based supplier auditsFormal service-provider management: GMP responsibility cannot be outsourced, not even to cloud or AI providers
Electronic signaturesEquivalence to handwritten signaturesTwo-factor authentication or biometrics recommended
Artificial intelligenceNot addressedReference to the new Annex 22, limited to static, deterministic models

One point deserves special attention: the supplier chapter. With the massive migration to SaaS platforms, the draft reiterates that supplier qualification, technical agreements and ongoing oversight are an integral part of system compliance, and that the pharmaceutical company remains solely accountable in front of the inspector.

Annex 22: AI enters GMP — cautiously

The new Annex 22, in just 11 sections, governs the use of artificial intelligence models in GMP and is limited to static, deterministic models: documented intended use, measurable acceptance criteria, independence of test data and explainability of results. Generative models and dynamically learning models remain outside the perimeter of critical applications. For most manufacturing sites the immediate impact will be limited, but the direction is set: anyone bringing AI into GxP processes will have to treat it with the same documentation rigour as any other computerised system.

Timeline: where we stand

The consultation closed on 7 October 2025 and the final versions of Annex 11, Annex 22 and Chapter 4 are expected from mid-2026, with the operative date to be set in the final texts. At the time of writing the final version has not yet been published: the 2011 Annex 11 remains the rule, but the draft is already the most concrete reference for understanding where inspections are heading. Several authorities are, after all, already citing deficiencies in audit trail review and access management under existing data integrity principles.

GuideGxP recommendation

Do not wait for the final text to act: the draft requirements are stable enough to justify a gap analysis now. In practice:

  1. Update your inventory of GxP computerised systems to include cloud services, mobile apps and interfaces, with a criticality assessment for each.
  2. Run a chapter-by-chapter gap analysis of the draft, prioritising audit trails, identity and access management and security.
  3. Review contracts and qualification of SaaS/cloud providers: make sure roles, responsibilities and data access are defined and defensible in audit.
  4. Formalise (or strengthen) risk-based audit trail review, with frequencies and responsibilities written into a procedure.
  5. Bring the evidence into your PQS: change control, periodic system review and data integrity KPIs discussed in management review.

If you want a ready-made framework for setting up validation and system lifecycle in an audit-ready way, our Operational Guide to Computer System Validation (CSV) in GxP covers exactly this: inventory, risk assessment, validation protocols and maintenance of the validated state, with ready-to-use templates.

Official sources

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP