
Annex 11 vs Part 11
Explore this topic in more depth to build a complete picture of your quality and compliance operations.
ExploreThe EU's computerised-systems rules for GMP — and the biggest revision in over a decade is imminent.
Annex 11 is the EU counterpart every Part 11 conversation eventually reaches: system-and-lifecycle-centric rules for computerised systems in GMP, currently being rewritten for the cloud and AI era.

Annex 11 — Computerised Systems is part of EudraLex Volume 4, the EU's Good Manufacturing Practice guidelines for medicinal products for human and veterinary use. It applies to any computerised system used as part of GMP-regulated activities, and it is system-and-lifecycle-centric: where the US Part 11 focuses on electronic records and signatures, Annex 11 governs the whole life of the system that produces them.
The text in force is the 2011 revision — a deliberately principle-based document of seventeen numbered sections covering risk management, personnel, supplier and service-provider responsibility, validation, data, accuracy checks, data storage, printouts, audit trails, change and configuration management, periodic evaluation, security, incident management, electronic signatures, batch release, business continuity, and archiving. PIC/S publishes an equivalent Annex 11 used by participating authorities beyond the EU, which keeps its expectations globally relevant.
Its opening principle does a lot of work: when a computerised system replaces a manual operation, there must be no resultant decrease in product quality, process control, or quality assurance — and no increase in overall risk. Every clause that follows is an elaboration of that sentence.
A draft revised Annex 11 was published on 7 July 2025 — alongside a brand-new Annex 22 on Artificial Intelligence and a revised Chapter 4 on documentation — with public consultation closed in October 2025 and the final version expected around mid-2026. The draft grows the 2011 text substantially: explicit expectations for cloud and SaaS, cybersecurity controls (penetration testing, patching, incident response), and sharper accountability for regulated users of outsourced services. Until adoption, the 2011 text remains the version in force — but buying decisions made today should anticipate the draft's direction.
For any company manufacturing or releasing product for the EU market, Annex 11 is the lens an EU inspector applies to every computerised system in GMP scope — the eQMS included. The questions follow its clauses: is the system validated for its intended use, who is responsible for it, what does the supplier do versus what do you do, is the data accurate and protected, can you show an audit trail and is it reviewed, what happens when the system changes, and what happens when it fails.
Two Annex 11 themes hit cloud eQMS buyers hardest. First, supplier responsibility (clauses 3.1–3.4): outsourcing the system never outsources the accountability — formal agreements must exist, the regulated user must be able to assess the supplier's quality system, and audits of the provider must be possible. Second, lifecycle governance: validation is not a go-live event but a state to be maintained through change control (clause 10), configuration management, and periodic evaluation (clause 11). The 2025 draft revision sharpens both, adding explicit cybersecurity and service-oversight expectations.
Annex 11 findings also travel: because PIC/S authorities use an equivalent text, a gap exposed in one inspection framework tends to be a gap everywhere — which is why global companies treat Annex 11 alignment as the de-facto baseline for system governance even outside the EU.
Annex 11 never operates alone. The pieces it interlocks with:
In practice, Annex 11 review is concrete. A typical walk-through of a GMP computerised system covers:
Inventory and validation. An up-to-date inventory of GMP systems (clause 4.3); for the system at hand, validation evidence proportionate to risk covering its intended use, with requirements traceable to tests. For purchased products, evidence the supplier and product were assessed; for SaaS, how the customer's intended use was qualified on top of the vendor's own lifecycle work.
Access and data controls. Individual accounts with appropriate privileges (clause 12), physical and logical security, accuracy checks where data is entered manually (clause 6), and an audit trail of GMP-relevant changes and deletions — reviewed on a defined cadence, not merely enabled (clause 9).
Lifecycle discipline. Changes evaluated and authorized through change management (clause 10); configuration baselined; periodic evaluation confirming the validated state still holds (clause 11) — covering current functionality range, deviations, incidents, upgrade history, performance, and security.
Continuity and signatures. Data backed up and restore-tested, archiving arrangements (clause 17), business continuity for critical systems (clause 16), incident management with records (clause 13), and — where electronic signatures are used — signatures with the same standing as handwritten ones, permanently linked to their records with time and date (clause 14).
For cloud systems, every one of these extends into the provider: hosting model, data location, isolation, the provider's change and release discipline, and how the customer learns about changes that affect the validated state. The 2025 draft makes that extension explicit rather than implied.
Sites that pass Annex 11 scrutiny consistently have these controls in place — most map directly to a numbered clause:
Clause 3.1: formal agreements must exist with third parties, including 'clear statements of the responsibilities of the third party'. Inspectors increasingly ask SaaS customers to produce exactly that — the agreement language describing who validates what, who controls changes, and how the customer is informed. If your vendor contract can't answer clause 3.1, the gap is yours, not the vendor's.
Complere's controls were built with Annex 11's clause structure in mind, and the clause-by-clause story is designed to be producible during supplier assessment rather than reconstructed for it.
On access and records: role-based access with individual accounts, configurable privileges, and per-tenant isolation address clause 12; time-stamped audit trails on regulated records — capturing who, what, when, and old/new values — address clause 9, with the review obligation supported by readable, filterable trail exports. Electronic signatures re-authenticate the signer and bind name, date, and meaning to the record, addressing clause 14's equivalence and permanence expectations.
On lifecycle: the validation pack delivers the clause 4 evidence per module — URS, risk assessment, traceability, IQ/OQ/PQ — generated against the customer tenant; controlled change with impact assessment covers clause 10 for the customer's configuration; and on releases that affect validated functionality, release notes map changes to affected requirements and the affected evidence regenerates, supporting the clause 11 periodic-evaluation posture with current rather than stale documentation.
On supplier responsibility: the formal-agreement and assessment expectations of clauses 3.1–3.4 are met with the artifacts a regulated user needs — the validation pack itself, security and hosting documentation, and per-customer regional residency (application, database, and file storage in the customer-selected region) for the data-location questions that EU assessments ask first.
What stays with your team is the regulated-user share: your system inventory entry and risk classification, your intended-use qualification, your audit-trail review cadence, your periodic evaluation, and your business-continuity arrangements around the service. The clause-level walkthrough continues on Electronic Records & Signatures and the Annex 11 validation playbook.
Common questions about EU GMP Annex 11 sourced from regulatory references and inspection patterns.
Part 11 (US FDA) is record-and-signature-centric: it governs electronic records and signatures used in place of paper. Annex 11 (EU GMP) is system-and-lifecycle-centric: it governs the whole computerised system — validation, suppliers, security, change, periodic review, business continuity. Global systems generally need to satisfy both.
Annex 11 is part of EudraLex Volume 4, the EU GMP guidelines that interpret the GMP directives. In practice it carries the force of GMP expectation: EU inspectors assess computerised systems against its clauses, and gaps surface as GMP deficiencies.
A draft revised Annex 11 was published on 7 July 2025 — together with a new draft Annex 22 on artificial intelligence and a revised Chapter 4 — with public consultation closed in October 2025 and final adoption expected around mid-2026. Until adoption, the 2011 text remains in force. The draft adds explicit cloud/SaaS, cybersecurity, and service-provider-oversight expectations.
Yes. The 2011 text already covers outsourced services through its supplier clauses — the regulated user stays accountable for systems run by providers. The draft revision makes cloud expectations explicit: provider oversight, data location, security controls, and knowing how provider changes affect your validated state.
The 2011 text covers outsourced services through its supplier clauses (3.1-3.4): formal agreements must exist with clear statements of the third party's responsibilities, and the regulated user must be able to assess and audit the provider. The 2025 draft revision makes cloud expectations explicit - data location, isolation, the provider's change discipline, and how the customer learns of changes affecting the validated state. In all cases the regulated user stays accountable for the system, even when a provider runs it.
Explore related topics, modules, and compliance resources for a deeper understanding of your quality system.

Explore this topic in more depth to build a complete picture of your quality and compliance operations.
Explore
Explore this topic in more depth to build a complete picture of your quality and compliance operations.
Explore
Explore this topic in more depth to build a complete picture of your quality and compliance operations.
ExploreWalk through the modules and workflows that address this area inside a controlled, validation-ready quality system.