Skip to content

Evidence request lists

Annex 11 to EU GMP - Computerised Systems

Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

General Requirements (Annex 11)

Clause 1
Risk management

Risk assessment should be performed throughout the lifecycle to determine the level of validation and data integrity controls.

Artefacts an auditor will ask for
  • Risk assessments across the system lifecycle driving validation extent & controls
Where this commonly fails
  • No documented risk-based approach to the system
Clause 2
Personnel

Requires appropriate qualifications, access levels and defined responsibilities for all personnel using computerised systems.

Artefacts an auditor will ask for
  • Defined roles/responsibilities; cooperation between process owners, system owners, QP and IT
Where this commonly fails
  • Roles/responsibilities for the system undefined
Clause 3
Suppliers and service providers

Formal agreements with third parties must establish well-defined responsibilities for computerised system services.

Artefacts an auditor will ask for
  • Supplier agreements/quality agreements
  • Supplier assessment/audit records
Where this commonly fails
  • Suppliers used without formal agreements or assessment

Operational Phase - Change and Configuration

Clause 10
Change and configuration management

All changes to computerised systems must follow defined change management procedures and be documented.

Artefacts an auditor will ask for
  • Change control records for the computerised system
Where this commonly fails
  • Changes made without change control
Clause 11
Periodic evaluation

Regular assessments of system functionality, deviations, incidents, security measures and validation status must be performed.

Artefacts an auditor will ask for
  • Periodic evaluation reports confirming the system remains valid & compliant
Where this commonly fails
  • System never periodically re-evaluated

Operational Phase - Data Management

Clause 5
Data

Built-in checks must ensure correct and secure entry and processing of electronically exchanged data.

Artefacts an auditor will ask for
  • Built-in checks for correct & secure entry/processing of data at interfaces
Where this commonly fails
  • No integrity checks on data exchanged between systems
Clause 6
Accuracy checks

Critical manually entered data requires verification by a second operator or validated electronic means.

Artefacts an auditor will ask for
  • Accuracy checks for critical data entered manually or electronically
Where this commonly fails
  • Critical data entered without an accuracy/second check
Clause 7
Data storage

Data must be protected through physical and electronic means with regular accessibility, readability and accuracy checks.

Artefacts an auditor will ask for
  • Data secured against damage (physical/electronic)
  • Regular backups; backup integrity & restore checks
Where this commonly fails
  • No backup or restore verification
Clause 8
Printouts

Clear printed copies of stored data must be obtainable and must indicate whether data has been modified since original entry.

Artefacts an auditor will ask for
  • Ability to obtain clear printed copies of electronically stored data
  • Records of changes reflected in printouts
Where this commonly fails
  • Cannot produce readable copies of e-records
Clause 9
Audit trails

Time-stamped audit trail records of all GMP-relevant changes and deletions must be maintained with documented reasons.

Artefacts an auditor will ask for
  • Audit trails for GMP-relevant changes/deletions
  • Audit-trail review process
Where this commonly fails
  • No audit trail or audit trails not reviewed

Operational Phase - Release and Continuity

Clause 15
Batch release

System access for batch release must be limited to Qualified Persons with required electronic signature identification.

Artefacts an auditor will ask for
  • Certification/batch-release function restricted to the authorised person (QP)
Where this commonly fails
  • Batch release not controlled in the system
Clause 16
Business continuity

Documented and tested procedures for alternative or manual operations must be maintained for system breakdowns.

Artefacts an auditor will ask for
  • Contingency/business-continuity arrangements for system unavailability
Where this commonly fails
  • No continuity plan for critical system failure
Clause 17
Archiving

Periodic checks for accessibility, readability and integrity of archived data with retrieval capability after system changes.

Artefacts an auditor will ask for
  • Archived data checked for accessibility, readability & integrity
  • Archive retrieval testing
Where this commonly fails
  • Archived data not retrievable or readable

Operational Phase - Security and Access

Clause 12
Security

Physical and logical access controls must restrict system use to authorised personnel only.

Artefacts an auditor will ask for
  • Physical/logical access controls limited to authorised persons
  • Records of authorised users & access levels
Where this commonly fails
  • Inadequate access controls over the system
Clause 13
Incident management

All system failures and data errors must be reported, assessed, investigated and documented.

Artefacts an auditor will ask for
  • Incident/problem records, assessment and corrective actions
Where this commonly fails
  • System incidents not recorded or assessed
Clause 14
Electronic signatures

Electronic signatures must be equivalent to handwritten ones, permanently linked to records with date and time stamps.

Artefacts an auditor will ask for
  • E-signatures bound to records; permanent linkage; date/time
Where this commonly fails
  • E-signatures not equivalent/controlled

Project Phase

Clause 4
Validation

Computerised systems must be validated throughout their lifecycle with documented protocols and user requirement specifications.

Artefacts an auditor will ask for
  • Validation documentation across the lifecycle
  • Inventory of validated systems; URS; traceability
Where this commonly fails
  • System not validated for intended use
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Annex 11 to EU GMP - Computerised Systems framework page.