Compliance
Annex 11 in Plain English
A practical guide to the questions GMP teams should ask about computerised systems, from risk and responsibilities to data integrity, change control, and recovery.
When a GMP activity depends on a computerised system, the important question is not simply whether the software works. It is whether the organisation can trust the data, the process, the people, and the decisions that depend on it.
This is Annex 11 in plain English: a practical guide to the questions GMP companies should ask when they introduce, operate, change, integrate, or retire computerised systems.
This article is a practical interpretation of the Annex 11 themes. It is not legal advice, a validation protocol, or a determination that a particular system is compliant. The applicable regulatory text, intended use, risk assessment, and quality system remain the controlling references.
The central idea: trust in GMP decisions
Annex 11 is about the reliability of GMP activities supported by computerised systems. A team should be able to explain how the system is used, show that risks are controlled, demonstrate that records are trustworthy, and recover when something goes wrong.
The practical test is simple:
If a computerised system performs all or part of a task that was previously manual, what new risks have been introduced, and how will the organisation know that control has been retained?
1. Risk management
Not every system needs the same level of assessment, testing, or ongoing review. The effort should reflect what could go wrong if the system fails, produces incorrect data, restricts the wrong person, or changes the way a GMP decision is made.
Start by identifying the process impact, critical records, decisions, interfaces, users, and failure modes. Link the resulting controls and testing to the risk rather than treating every system as if it carried the same consequence.
2. People and responsibilities
Someone must own the system and the process it supports. Responsibility should be clear across the process owner, system owner, IT or infrastructure team, and Quality.
The organisation should be able to answer who owns the business process, who operates the system, who manages the technical environment, who approves access, and who provides GMP oversight. Shared responsibility is useful; assumed responsibility is not.
3. Suppliers matter
Using a supplier does not transfer accountability for the organisation's GMP use of the system. Supplier assessment should consider quality processes, security, change management, support, incident handling, and the evidence available for the intended use.
The practical question is not whether a vendor has validated the product in the abstract. It is whether the organisation has justified reliance on the supplier and controlled its own use of the service.
4. Validation
Validation is evidence that the system is fit for its intended use. It is not a claim that every possible feature has been tested, and it is not something a vendor can complete on the customer's behalf without understanding the customer's process.
A proportionate validation approach normally connects requirements, implementation, testing, results, deviations, and a conclusion about fitness for use. The evidence should remain understandable when the system, team, or supplier changes.
The GMP AI evaluation guide explores the same lifecycle discipline for AI-assisted use cases.
5. User requirements
User requirements should describe the problem the organisation needs to solve and the controls the process requires. They become the basis for evaluating options, defining acceptance criteria, and showing that the implemented system meets the intended use.
Ask what the process needs the system to do, what information must be captured, which decisions must be supported, and which controls must be visible. A feature list alone is not a user requirement.
6. Data integrity
Data integrity asks whether people can trust the record throughout its lifecycle. Consider whether data is attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available when needed.
The practical questions include:
- Who created or changed the record?
- Can the organisation tell what changed and why?
- Are records protected from inappropriate alteration or deletion?
- Can the information be retrieved and understood for the required retention period?
The evidence and traceability guide for GMP AI applies these questions to AI-assisted work as well.
7. Interfaces and integrations
Whenever systems exchange information, the transfer becomes part of the controlled process. The organisation should know what data moves, where it goes, how errors are handled, and how it can show that the receiving system received the correct information.
Examples may include an ERP to eQMS transfer, a LIMS to MES interface, SharePoint to Power Automate, or an electronic balance to a spreadsheet. The technology changes, but the questions about completeness, accuracy, reconciliation, and exception handling remain.
8. Backups and storage
A backup that has never been restored is an assumption, not evidence of recovery capability.
Document where data is stored, how often it is backed up, how long it is retained, who can access it, and how restoration is tested. Frequency and recovery objectives should reflect the process and the consequences of data loss.
9. Audit trails
When a GMP-relevant record changes, the organisation should be able to understand who changed it, when it changed, what changed, and why. Audit trails are part of the evidence that makes a record trustworthy.
They should be reviewed in a way that is meaningful for the process, with findings assessed and escalated where the change could affect quality, data integrity, or a regulated decision.
10. Change control
Change itself is not the problem. Uncontrolled change is.
Assess changes to workflows, configuration, software versions, integrations, reports, permissions, and surrounding procedures for their potential effect on GMP functionality and validated state. The change record should explain the impact assessment, testing, approval, implementation, and any required follow-up.
See controlled change for GMP AI workflows for the corresponding questions when models, prompts, retrieval, tools, or AI workflows change.
11. Periodic review
Validation is not a one-time declaration that remains sufficient forever. Periodic review asks whether the organisation still has justified confidence in the system based on what has changed and what has been learned.
Review the process, risks, users, access, supplier, incidents, deviations, upgrades, interfaces, and performance evidence. The outcome should be a documented decision about continued use, remediation, requalification, or retirement.
12. Security
Access should be restricted according to role and need. The organisation should know who has privileged access, who approves it, how access is reviewed, and how leavers or role changes are handled.
Security protects more than confidentiality. In a GMP system, inappropriate access can affect data integrity, records, approvals, audit trails, and the reliability of quality decisions.
The SharePoint governance pathway provides related guidance for controlled information, permissions, and process structure in Microsoft 365.
13. Incident management
When a system or record fails, a quick fix is not the same as an investigation. The organisation should understand what happened, why it happened, whether it could happen again, and whether the validation or control state needs to be updated.
Incidents, deviations, root causes, corrective actions, and follow-up evidence should connect in a way that lets the organisation learn rather than repeatedly restore the same failure.
14 and 15. Electronic signatures and batch release
An electronic signature needs to be attributable and meaningful. The record should make clear who signed, when they signed, and what the signature represented, such as review, approval, or release.
Where a computerised system supports batch release or another critical quality decision, the organisation should be able to explain the decision path, the evidence considered, the authority of the signatory, and the controls that prevent ambiguity.
16 and 17. Business continuity and archiving
Ask what would happen if the system disappeared now. Could production, Quality, investigation, or batch release continue? Critical processes need documented fallback arrangements that are understood and tested.
Archiving is more than storing data. The organisation must be able to retrieve, read, understand, and trust the record at the end of the retention period, including the context needed to interpret it.
The questions to keep asking
Across all 17 themes, Annex 11 can be translated into a small set of operating questions:
- Is the system fit for the intended GMP use?
- Are risks understood and controlled in proportion to their impact?
- Are responsibilities, permissions, and decisions attributable?
- Are data, interfaces, audit trails, and changes trustworthy and traceable?
- Can the organisation recover, investigate, learn, and demonstrate continued control?
The Regulatory compliance pathway places these questions in the wider context of practical quality practice. For AI-assisted work, the Practical, Governed AI for GMP Quality Operations hub adds questions about output boundaries, human oversight, evaluation, evidence, and controlled change.
Annex 11 is therefore not only a software checklist. It is a way to test whether a computerised system supports quality work without weakening control, visibility, accountability, or trust.