Data Integrity & CSV

EU GMP Annex 11: 2025 Draft and 2026 Revision Explained

EU GMP Annex 11 is undergoing its first complete rewrite since 2011: draft consulted in 2025, final version expected between 2026 and 2027. What changes for audit trails, access management, cloud and AI, and how to start the gap analysis of your GxP systems now.

G GuideGxP 5 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Illustrazione editoriale GuideGxP a colori sul tema GMP: revisione Annex 11, sistemi computerizzati, audit trail e cloud.

EU GMP Annex 11 "Computerised Systems" is undergoing its first complete rewrite since 2011: the draft published on 7 July 2025 by the European Commission together with EMA and PIC/S is now being finalised, and the revision expected between 2026 and 2027 will redefine inspectors' expectations on validation, audit trails, access management and cloud services. For anyone working in QA, CSV or IT Quality the message is clear: GxP computerised systems will no longer be judged on initial validation alone, but across their entire lifecycle, with far greater weight on data integrity and security. In this article we look at what the draft contains, what changes compared with the 2011 text, and how to be ready for the final version.

EU GMP Annex 11: why the revision and what was published

The revision does not come alone. On 7 July 2025, three EudraLex Volume 4 documents, prepared by the EMA Inspectors' Working Group together with PIC/S, were released for joint consultation:

  • the revision of Chapter 4 - Documentation, which formally embeds data governance, metadata, hybrid systems and ALCOA+ principles into documentation management;
  • the revision of Annex 11 - Computerised Systems, the subject of this article;
  • the new Annex 22 - Artificial Intelligence, dedicated to the use of AI/ML models in GMP.

The logic is clear: the Annex 11 currently in force dates back to 2011, an era when cloud, SaaS, mobile apps and machine learning were marginal in pharmaceutical operations. The draft updates the regulatory perimeter to technologies that are now everywhere, from cloud LIMS to MES systems integrated with the ERP, and explicitly includes systems with an indirect impact on product quality and data integrity. The public consultation closed on 7 October 2025 and the texts are now with the joint EMA-PIC/S working group for finalisation.

The new structure: from 17 clauses to thematic chapters

The draft abandons the concise list of 17 clauses of the 2011 version and adopts a structure of thematic chapters: scope and principles, pharmaceutical quality system, risk management, personnel and training, system requirements, management of suppliers and services, qualification and validation, data management, identity & access management, audit trail, electronic signatures, security, backup and archiving, periodic review, plus a final glossary. The centre of gravity shifts markedly: while validation is the most developed topic in the current text, the most substantial chapters in the draft concern security, identity and access management, audit trails and supplier oversight. It is a snapshot of where inspections are already heading.

Topics like this evolve month by month between drafts, consultations and final versions. If you want a practical, no-frills weekly update on GMP, data integrity and computerised systems, subscribe to The Pragmatic GMP, our free newsletter: the easiest way to be ready when the final Annex 11 lands.

What really changes compared with the 2011 Annex 11

The table summarises the most operationally relevant differences:

Area Annex 11 (2011) 2025 draft / revision
Scope Computerised systems used in GMP activities Explicitly extended to cloud (SaaS, PaaS, IaaS), mobile apps, industrial IoT, static AI/ML models and systems with indirect impact
Audit trail Required for changes and deletions of GMP-relevant data Secure, time-stamped, tamper-evident, user-attributable audit trails; structured, risk-based review
Access Generic access controls Dedicated identity & access management chapter: unique credentials, role-based access, segregation of duties
Suppliers and cloud Risk-based supplier audits Formal service-provider categories (SaaS, cloud, AI) with SLAs, audits and quality agreements: GMP responsibility cannot be outsourced
Electronic signatures Equivalence to handwritten signatures Secure, traceable, validated signatures; two-factor authentication or biometrics recommended
Backup and recovery Regular data backups Validated, documented and tested backups, preserving metadata and enabling demonstrable full recovery
Artificial intelligence Not addressed Static, deterministic models in scope; detailed requirements referred to the new Annex 22

One point deserves particular attention: the supplier chapter. With the massive migration to SaaS platforms, the draft reiterates that supplier qualification, technical agreements and ongoing oversight are an integral part of system compliance, and that the pharmaceutical company remains solely accountable to the inspector, even when the system runs in someone else's data centre.

Annex 22 and Chapter 4: the complete digital package

The new Annex 22 governs the use of artificial intelligence in GMP, limited to static, deterministic models with a direct impact on quality: documented intended use, measurable acceptance criteria, independence of test data, explainability of results and continuous performance monitoring. Generative models (such as large language models) and dynamically learning models remain outside the perimeter of critical applications. The revised Chapter 4, for its part, brings the data lifecycle into documentation management: electronic records, signatures, hybrid paper-digital systems and metadata become the subject of explicit requirements. The three texts must be read together: they define a single data-governance framework for the manufacturing site.

Where the revision stands: status as of September 2026

At the time of writing, the final version has not yet been published: the 2011 Annex 11 remains in force, and finalisation of Annex 11, Annex 22 and Chapter 4 is expected between late 2026 and 2027, with application dates to be set in the final texts (typically with a 6-12 month transition period). Waiting would nonetheless be a mistake: the draft is already the most concrete reference for understanding where inspections are heading, and several authorities are already citing deficiencies in audit trail review and access management using existing data integrity principles. Those who start their gap analysis now can work calmly; those who wait for final publication will do it under pressure.

GuideGxP recommendation

The draft's requirements are stable enough to justify an action plan today. In practice:

  1. Update your inventory of GxP computerised systems to include cloud services, mobile apps and interfaces, with a criticality assessment for each.
  2. Run a chapter-by-chapter gap analysis of the draft, prioritising audit trails, identity & access management and security.
  3. Review contracts and qualification of SaaS/cloud providers: check that roles, responsibilities and data access are defined and defensible in an audit.
  4. Formalise (or strengthen) risk-based audit trail review, with frequencies and responsibilities written into procedures.
  5. Bring the evidence into the PQS: change control, periodic system review and data integrity KPIs discussed in management review.

If you want a ready-made path to set up validation and system lifecycle management the audit-ready way, our Operational Guide to Computer System Validation (CSV) in GxP (second edition, updated precisely with the new Annex 11 in mind) covers exactly this: inventory, risk assessment, validation protocols and maintaining the validated state, with ready-to-use templates.

Official sources

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP →