EU Annex 11 Compliance: What Has Changed and What Organisations Need to Do
EU GMP Annex 11 establishes the requirements for computerised systems in pharmaceutical manufacturing. This article examines its key requirements, how they are interpreted in current inspections and the most common gaps identified during CSV assessments.
Scope and Applicability
EU GMP Annex 11 applies to all computerised systems used in GMP-regulated activities, manufacturing execution systems (MES), laboratory information management systems (LIMS), chromatography data systems (CDS), building management systems (BMS), warehouse management systems (WMS) and quality management systems (QMS). The scope is broad: if a system is used in a GMP activity and produces data that forms part of the GMP record, Annex 11 applies.
Annex 11 applies to both in-house developed systems and off-the-shelf commercial systems. For commercial systems, the expectation is that the supplier's development and quality management processes have been assessed, typically through supplier audits and review of supplier documentation, to provide assurance equivalent to internal development controls.
Risk-Based Validation
Annex 11 requires that validation effort is commensurate with risk. This principle, now embedded in most CSV frameworks through GAMP 5, means that the depth of validation testing, the extent of documentation and the rigor of the validation lifecycle should reflect the complexity of the system and the risk to product quality and data integrity if the system fails.
In practice, a risk-based approach requires:
- A documented system risk assessment that identifies the GMP impact of system functions
- Validation scope defined by the risk assessment, not by a uniform protocol applied regardless of system criticality
- Test scripts that cover the functions identified as GMP-critical in the risk assessment
- Documented rationale for any functions not tested
Inspectors assess whether risk assessments are genuine, whether the identified risks reflect the actual GMP impact of system functions, or whether they are formulaic documents designed to justify a pre-determined scope.
Audit Trails
Annex 11 requires that computerised systems record who changed data, what was changed, the previous value and when the change was made. These records must be available and must be reviewed regularly. This is not optional, audit trail review is a regulatory requirement, not a quality system enhancement.
Common audit trail deficiencies:
- Audit trail function present in the system but not enabled in the configuration
- Audit trail capturing changes to data but not capturing attempts to access data outside normal working patterns
- No defined process for reviewing audit trails as part of batch record review or routine quality oversight
- Audit trail records that cannot be exported or printed for regulatory inspection review
- Audit trail retention period shorter than the GMP record retention period
Access Controls
Annex 11 requires that access to computerised systems is controlled and that access rights are defined and documented. Access should be granted on a role-based basis, personnel should have access to the functions they need to perform their role, not broader access for convenience.
Access control assessments consistently identify: users with access rights beyond their role requirements; no formal process for removing access when personnel change roles or leave the organisation; administrator accounts used for routine operations; and inadequate password controls (no expiry, no complexity requirements, shared credentials).
Periodic Review
Annex 11 requires that computerised systems are periodically reviewed to confirm they remain in a validated state. Periodic review assesses whether any changes have occurred, to the system, its operating environment, its use or the regulatory requirements applicable to it, that affect validation status.
Periodic review is an area where many organisations are found deficient during inspection. Common scenarios: systems validated at implementation with no subsequent periodic review; periodic reviews conducted that note no changes without substantive review of change records, incident records or deviation history; and no documented process for defining when a change requires revalidation versus documented justification for not revalidating.
Annex 11 Key Requirements
- Risk-based validation
- Supplier assessment
- Audit trail capture & review
- Access controls
- Data backup & recovery
- Change control
- Periodic review
- Business continuity
- Data archiving
Independent CSV and Annex 11 Assessment
Sthira Assure conducts computer system validation assessments aligned to EU GMP Annex 11 and GAMP 5.