EudraLex Volume 4, Annex 11 — Computerised Systems
Annex 11 applies GMP principles to computerized systems and addresses lifecycle risk management, personnel, suppliers, validation, data, accuracy checks, storage, printouts, audit trails, change control, incident management, periodic evaluation, security, signatures, continuity, and archiving.
What the authority record establishes
Annex 11 applies GMP principles to computerized systems and addresses lifecycle risk management, personnel, suppliers, validation, data, accuracy checks, storage, printouts, audit trails, change control, incident management, periodic evaluation, security, signatures, continuity, and archiving.
Official GMP guidance applied within the EU medicinal-product legal framework
The exact official title, issuing body, jurisdiction, version or application record, and linked source define the scope of this page. Readers should not transfer the authority's status to a commercial product or infer transaction-, patient-, system-, site-, or organization-specific applicability from this summary.
Why it matters to this market
Annex 11 shapes how buyers assess both the product and the supplier lifecycle. A provider feature list is insufficient without evidence for intended use, risk, validation, data integrity, security, change, continuity, and ongoing evaluation.
Affected operating stages
- Supplier Assessment
- Requirements And Risk Assessment
- Validation
- Operation And Access
- Audit-Trail And Data Review
- Change And Incident Management
- Periodic Evaluation
- Continuity And Archiving
Capabilities to examine
Controlled Documents
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for controlled documents.
Training Management
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for training management.
Change Control
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for change control.
Audit And Inspection Management
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for audit and inspection management.
Quality Risk Management
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for quality risk management.
Computerized-System Validation Support
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for computerized-system validation support.
Analytics And Management Review
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for analytics and management review.
Affected buyer audiences
- EU medicinal-product manufacturers and importers
- quality and validation teams
- information technology and security
- system and process owners
- software suppliers supporting GxP processes
Implementation questions
- Which entities, products, populations, transactions, systems, sites, or jurisdictions are actually within scope?
- What is binding, what is guidance, and what is a technical or consensus standard?
- Which publication, adoption, effective, application, transition, and enforcement dates differ?
- Who owns legal, clinical, quality, regulatory, policy, or operational interpretation?
- How will a source revision affect open work and historical decisions?
Interpretation boundary
Annex 11 does not certify commercial platforms. The regulated organization remains responsible for intended use, supplier oversight, validation, procedures, data governance, and the system's maintained state.