Annex 11 to EU GMP - Computerised Systems
Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
General Requirements (Annex 11)
Risk assessment should be performed throughout the lifecycle to determine the level of validation and data integrity controls.
- Risk assessments across the system lifecycle driving validation extent & controls
- No documented risk-based approach to the system
Requires appropriate qualifications, access levels and defined responsibilities for all personnel using computerised systems.
- Defined roles/responsibilities; cooperation between process owners, system owners, QP and IT
- Roles/responsibilities for the system undefined
Formal agreements with third parties must establish well-defined responsibilities for computerised system services.
- Supplier agreements/quality agreements
- Supplier assessment/audit records
- Suppliers used without formal agreements or assessment
Operational Phase - Change and Configuration
All changes to computerised systems must follow defined change management procedures and be documented.
- Change control records for the computerised system
- Changes made without change control
Regular assessments of system functionality, deviations, incidents, security measures and validation status must be performed.
- Periodic evaluation reports confirming the system remains valid & compliant
- System never periodically re-evaluated
Operational Phase - Data Management
Built-in checks must ensure correct and secure entry and processing of electronically exchanged data.
- Built-in checks for correct & secure entry/processing of data at interfaces
- No integrity checks on data exchanged between systems
Critical manually entered data requires verification by a second operator or validated electronic means.
- Accuracy checks for critical data entered manually or electronically
- Critical data entered without an accuracy/second check
Data must be protected through physical and electronic means with regular accessibility, readability and accuracy checks.
- Data secured against damage (physical/electronic)
- Regular backups; backup integrity & restore checks
- No backup or restore verification
Clear printed copies of stored data must be obtainable and must indicate whether data has been modified since original entry.
- Ability to obtain clear printed copies of electronically stored data
- Records of changes reflected in printouts
- Cannot produce readable copies of e-records
Time-stamped audit trail records of all GMP-relevant changes and deletions must be maintained with documented reasons.
- Audit trails for GMP-relevant changes/deletions
- Audit-trail review process
- No audit trail or audit trails not reviewed
Operational Phase - Release and Continuity
System access for batch release must be limited to Qualified Persons with required electronic signature identification.
- Certification/batch-release function restricted to the authorised person (QP)
- Batch release not controlled in the system
Documented and tested procedures for alternative or manual operations must be maintained for system breakdowns.
- Contingency/business-continuity arrangements for system unavailability
- No continuity plan for critical system failure
Periodic checks for accessibility, readability and integrity of archived data with retrieval capability after system changes.
- Archived data checked for accessibility, readability & integrity
- Archive retrieval testing
- Archived data not retrievable or readable
Operational Phase - Security and Access
Physical and logical access controls must restrict system use to authorised personnel only.
- Physical/logical access controls limited to authorised persons
- Records of authorised users & access levels
- Inadequate access controls over the system
All system failures and data errors must be reported, assessed, investigated and documented.
- Incident/problem records, assessment and corrective actions
- System incidents not recorded or assessed
Electronic signatures must be equivalent to handwritten ones, permanently linked to records with date and time stamps.
- E-signatures bound to records; permanent linkage; date/time
- E-signatures not equivalent/controlled
Project Phase
Computerised systems must be validated throughout their lifecycle with documented protocols and user requirement specifications.
- Validation documentation across the lifecycle
- Inventory of validated systems; URS; traceability
- System not validated for intended use
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Annex 11 to EU GMP - Computerised Systems framework page.