EU GMP Annex 11 "Computerised Systems" is undergoing its first complete rewrite since 2011: the draft published on 7 July 2025 by the European Commission together with EMA and PIC/S is now being finalised, and the revision expected between 2026 and 2027 will redefine inspectors' expectations on validation, audit trails, access management and cloud services. For anyone working in QA, CSV or IT Quality the message is clear: GxP computerised systems will no longer be judged on initial validation alone, but across their entire lifecycle, with far greater weight on data integrity and security. In this article we look at what the draft contains, what changes compared with the 2011 text, and how to be ready for the final version.
EU GMP Annex 11: why the revision and what was published
The revision does not come alone. On 7 July 2025, three EudraLex Volume 4 documents, prepared by the EMA Inspectors' Working Group together with PIC/S, were released for joint consultation:
- the revision of Chapter 4 - Documentation, which formally embeds data governance, metadata, hybrid systems and ALCOA+ principles into documentation management;
- the revision of Annex 11 - Computerised Systems, the subject of this article;
- the new Annex 22 - Artificial Intelligence, dedicated to the use of AI/ML models in GMP.
The logic is clear: the Annex 11 currently in force dates back to 2011, an era when cloud, SaaS, mobile apps and machine learning were marginal in pharmaceutical operations. The draft updates the regulatory perimeter to technologies that are now everywhere, from cloud LIMS to MES systems integrated with the ERP, and explicitly includes systems with an indirect impact on product quality and data integrity. The public consultation closed on 7 October 2025 and the texts are now with the joint EMA-PIC/S working group for finalisation.
The new structure: from 17 clauses to thematic chapters
The draft abandons the concise list of 17 clauses of the 2011 version and adopts a structure of thematic chapters: scope and principles, pharmaceutical quality system, risk management, personnel and training, system requirements, management of suppliers and services, qualification and validation, data management, identity & access management, audit trail, electronic signatures, security, backup and archiving, periodic review, plus a final glossary. The centre of gravity shifts markedly: while validation is the most developed topic in the current text, the most substantial chapters in the draft concern security, identity and access management, audit trails and supplier oversight. It is a snapshot of where inspections are already heading.
Topics like this evolve month by month between drafts, consultations and final versions. If you want a practical, no-frills weekly update on GMP, data integrity and computerised systems, subscribe to The Pragmatic GMP, our free newsletter: the easiest way to be ready when the final Annex 11 lands.
What really changes compared with the 2011 Annex 11
The table summarises the most operationally relevant differences:
| Area | Annex 11 (2011) | 2025 draft / revision |
|---|---|---|
| Scope | Computerised systems used in GMP activities | Explicitly extended to cloud (SaaS, PaaS, IaaS), mobile apps, industrial IoT, static AI/ML models and systems with indirect impact |
| Audit trail | Required for changes and deletions of GMP-relevant data | Secure, time-stamped, tamper-evident, user-attributable audit trails; structured, risk-based review |
| Access | Generic access controls | Dedicated identity & access management chapter: unique credentials, role-based access, segregation of duties |
| Suppliers and cloud | Risk-based supplier audits | Formal service-provider categories (SaaS, cloud, AI) with SLAs, audits and quality agreements: GMP responsibility cannot be outsourced |
| Electronic signatures | Equivalence to handwritten signatures | Secure, traceable, validated signatures; two-factor authentication or biometrics recommended |
| Backup and recovery | Regular data backups | Validated, documented and tested backups, preserving metadata and enabling demonstrable full recovery |
| Artificial intelligence | Not addressed | Static, deterministic models in scope; detailed requirements referred to the new Annex 22 |
One point deserves particular attention: the supplier chapter. With the massive migration to SaaS platforms, the draft reiterates that supplier qualification, technical agreements and ongoing oversight are an integral part of system compliance, and that the pharmaceutical company remains solely accountable to the inspector, even when the system runs in someone else's data centre.
Annex 22 and Chapter 4: the complete digital package
The new Annex 22 governs the use of artificial intelligence in GMP, limited to static, deterministic models with a direct impact on quality: documented intended use, measurable acceptance criteria, independence of test data, explainability of results and continuous performance monitoring. Generative models (such as large language models) and dynamically learning models remain outside the perimeter of critical applications. The revised Chapter 4, for its part, brings the data lifecycle into documentation management: electronic records, signatures, hybrid paper-digital systems and metadata become the subject of explicit requirements. The three texts must be read together: they define a single data-governance framework for the manufacturing site.
Where the revision stands: status as of September 2026
At the time of writing, the final version has not yet been published: the 2011 Annex 11 remains in force, and finalisation of Annex 11, Annex 22 and Chapter 4 is expected between late 2026 and 2027, with application dates to be set in the final texts (typically with a 6-12 month transition period). Waiting would nonetheless be a mistake: the draft is already the most concrete reference for understanding where inspections are heading, and several authorities are already citing deficiencies in audit trail review and access management using existing data integrity principles. Those who start their gap analysis now can work calmly; those who wait for final publication will do it under pressure.
GuideGxP recommendation
The draft's requirements are stable enough to justify an action plan today. In practice:
- Update your inventory of GxP computerised systems to include cloud services, mobile apps and interfaces, with a criticality assessment for each.
- Run a chapter-by-chapter gap analysis of the draft, prioritising audit trails, identity & access management and security.
- Review contracts and qualification of SaaS/cloud providers: check that roles, responsibilities and data access are defined and defensible in an audit.
- Formalise (or strengthen) risk-based audit trail review, with frequencies and responsibilities written into procedures.
- Bring the evidence into the PQS: change control, periodic system review and data integrity KPIs discussed in management review.
If you want a ready-made path to set up validation and system lifecycle management the audit-ready way, our Operational Guide to Computer System Validation (CSV) in GxP (second edition, updated precisely with the new Annex 11 in mind) covers exactly this: inventory, risk assessment, validation protocols and maintaining the validated state, with ready-to-use templates.