[{"data":1,"prerenderedAt":320},["ShallowReactive",2],{"\u002Fblog\u002Fannex-11-in-plain-english":3},{"id":4,"title":5,"author":6,"body":7,"category":302,"date":303,"description":304,"draft":305,"excerpt":306,"extension":307,"heroImage":306,"heroImageAlt":306,"meta":308,"navigation":309,"path":310,"seo":311,"slug":306,"stem":312,"tags":313,"__hash__":319},"blog\u002Fblog\u002Fannex-11-in-plain-english.md","Annex 11 in Plain English","QikSolve",{"type":8,"value":9,"toc":281},"minimark",[10,14,17,20,25,28,31,37,41,44,47,51,54,57,61,64,67,71,74,77,86,90,93,96,100,103,106,122,129,133,136,139,143,146,149,153,156,159,163,166,169,177,181,184,187,191,194,197,204,208,211,214,218,221,224,228,231,234,238,241,259,271,274],[11,12,13],"p",{},"When a GMP activity depends on a computerised system, the important question is not simply\nwhether the software works. It is whether the organisation can trust the data, the process, the\npeople, and the decisions that depend on it.",[11,15,16],{},"This is Annex 11 in plain English: a practical guide to the questions GMP companies should ask\nwhen they introduce, operate, change, integrate, or retire computerised systems.",[11,18,19],{},"This article is a practical interpretation of the Annex 11 themes. It is not legal advice, a\nvalidation protocol, or a determination that a particular system is compliant. The applicable\nregulatory text, intended use, risk assessment, and quality system remain the controlling\nreferences.",[21,22,24],"h2",{"id":23},"the-central-idea-trust-in-gmp-decisions","The central idea: trust in GMP decisions",[11,26,27],{},"Annex 11 is about the reliability of GMP activities supported by computerised systems. A team\nshould be able to explain how the system is used, show that risks are controlled, demonstrate\nthat records are trustworthy, and recover when something goes wrong.",[11,29,30],{},"The practical test is simple:",[32,33,34],"blockquote",{},[11,35,36],{},"If a computerised system performs all or part of a task that was previously manual, what new\nrisks have been introduced, and how will the organisation know that control has been retained?",[21,38,40],{"id":39},"_1-risk-management","1. Risk management",[11,42,43],{},"Not every system needs the same level of assessment, testing, or ongoing review. The effort\nshould reflect what could go wrong if the system fails, produces incorrect data, restricts the\nwrong person, or changes the way a GMP decision is made.",[11,45,46],{},"Start by identifying the process impact, critical records, decisions, interfaces, users, and\nfailure modes. Link the resulting controls and testing to the risk rather than treating every\nsystem as if it carried the same consequence.",[21,48,50],{"id":49},"_2-people-and-responsibilities","2. People and responsibilities",[11,52,53],{},"Someone must own the system and the process it supports. Responsibility should be clear across\nthe process owner, system owner, IT or infrastructure team, and Quality.",[11,55,56],{},"The organisation should be able to answer who owns the business process, who operates the\nsystem, who manages the technical environment, who approves access, and who provides GMP\noversight. Shared responsibility is useful; assumed responsibility is not.",[21,58,60],{"id":59},"_3-suppliers-matter","3. Suppliers matter",[11,62,63],{},"Using a supplier does not transfer accountability for the organisation's GMP use of the\nsystem. Supplier assessment should consider quality processes, security, change management,\nsupport, incident handling, and the evidence available for the intended use.",[11,65,66],{},"The practical question is not whether a vendor has validated the product in the abstract. It is\nwhether the organisation has justified reliance on the supplier and controlled its own use of\nthe service.",[21,68,70],{"id":69},"_4-validation","4. Validation",[11,72,73],{},"Validation is evidence that the system is fit for its intended use. It is not a claim that every\npossible feature has been tested, and it is not something a vendor can complete on the customer's\nbehalf without understanding the customer's process.",[11,75,76],{},"A proportionate validation approach normally connects requirements, implementation, testing,\nresults, deviations, and a conclusion about fitness for use. The evidence should remain\nunderstandable when the system, team, or supplier changes.",[11,78,79,80,85],{},"The ",[81,82,84],"a",{"href":83},"\u002Fproduct\u002Fevaluating-gmp-ai-before-and-after-release","GMP AI evaluation guide"," explores the\nsame lifecycle discipline for AI-assisted use cases.",[21,87,89],{"id":88},"_5-user-requirements","5. User requirements",[11,91,92],{},"User requirements should describe the problem the organisation needs to solve and the controls\nthe process requires. They become the basis for evaluating options, defining acceptance criteria,\nand showing that the implemented system meets the intended use.",[11,94,95],{},"Ask what the process needs the system to do, what information must be captured, which decisions\nmust be supported, and which controls must be visible. A feature list alone is not a user\nrequirement.",[21,97,99],{"id":98},"_6-data-integrity","6. Data integrity",[11,101,102],{},"Data integrity asks whether people can trust the record throughout its lifecycle. Consider\nwhether data is attributable, legible, contemporaneous, original, accurate, complete, consistent,\nenduring, and available when needed.",[11,104,105],{},"The practical questions include:",[107,108,109,113,116,119],"ul",{},[110,111,112],"li",{},"Who created or changed the record?",[110,114,115],{},"Can the organisation tell what changed and why?",[110,117,118],{},"Are records protected from inappropriate alteration or deletion?",[110,120,121],{},"Can the information be retrieved and understood for the required retention period?",[11,123,79,124,128],{},[81,125,127],{"href":126},"\u002Fproduct\u002Fevidence-and-traceability-for-gmp-ai","evidence and traceability guide for GMP AI","\napplies these questions to AI-assisted work as well.",[21,130,132],{"id":131},"_7-interfaces-and-integrations","7. Interfaces and integrations",[11,134,135],{},"Whenever systems exchange information, the transfer becomes part of the controlled process. The\norganisation should know what data moves, where it goes, how errors are handled, and how it can\nshow that the receiving system received the correct information.",[11,137,138],{},"Examples may include an ERP to eQMS transfer, a LIMS to MES interface, SharePoint to Power\nAutomate, or an electronic balance to a spreadsheet. The technology changes, but the questions\nabout completeness, accuracy, reconciliation, and exception handling remain.",[21,140,142],{"id":141},"_8-backups-and-storage","8. Backups and storage",[11,144,145],{},"A backup that has never been restored is an assumption, not evidence of recovery capability.",[11,147,148],{},"Document where data is stored, how often it is backed up, how long it is retained, who can access\nit, and how restoration is tested. Frequency and recovery objectives should reflect the process\nand the consequences of data loss.",[21,150,152],{"id":151},"_9-audit-trails","9. Audit trails",[11,154,155],{},"When a GMP-relevant record changes, the organisation should be able to understand who changed it,\nwhen it changed, what changed, and why. Audit trails are part of the evidence that makes a record\ntrustworthy.",[11,157,158],{},"They should be reviewed in a way that is meaningful for the process, with findings assessed and\nescalated where the change could affect quality, data integrity, or a regulated decision.",[21,160,162],{"id":161},"_10-change-control","10. Change control",[11,164,165],{},"Change itself is not the problem. Uncontrolled change is.",[11,167,168],{},"Assess changes to workflows, configuration, software versions, integrations, reports, permissions,\nand surrounding procedures for their potential effect on GMP functionality and validated state.\nThe change record should explain the impact assessment, testing, approval, implementation, and\nany required follow-up.",[11,170,171,172,176],{},"See ",[81,173,175],{"href":174},"\u002Fproduct\u002Fcontrolled-change-for-gmp-ai-workflows","controlled change for GMP AI workflows"," for\nthe corresponding questions when models, prompts, retrieval, tools, or AI workflows change.",[21,178,180],{"id":179},"_11-periodic-review","11. Periodic review",[11,182,183],{},"Validation is not a one-time declaration that remains sufficient forever. Periodic review asks\nwhether the organisation still has justified confidence in the system based on what has changed\nand what has been learned.",[11,185,186],{},"Review the process, risks, users, access, supplier, incidents, deviations, upgrades, interfaces,\nand performance evidence. The outcome should be a documented decision about continued use,\nremediation, requalification, or retirement.",[21,188,190],{"id":189},"_12-security","12. Security",[11,192,193],{},"Access should be restricted according to role and need. The organisation should know who has\nprivileged access, who approves it, how access is reviewed, and how leavers or role changes are\nhandled.",[11,195,196],{},"Security protects more than confidentiality. In a GMP system, inappropriate access can affect\ndata integrity, records, approvals, audit trails, and the reliability of quality decisions.",[11,198,79,199,203],{},[81,200,202],{"href":201},"\u002Fproduct\u002Fsharepoint-governance","SharePoint governance pathway"," provides related guidance for\ncontrolled information, permissions, and process structure in Microsoft 365.",[21,205,207],{"id":206},"_13-incident-management","13. Incident management",[11,209,210],{},"When a system or record fails, a quick fix is not the same as an investigation. The organisation\nshould understand what happened, why it happened, whether it could happen again, and whether the\nvalidation or control state needs to be updated.",[11,212,213],{},"Incidents, deviations, root causes, corrective actions, and follow-up evidence should connect in\na way that lets the organisation learn rather than repeatedly restore the same failure.",[21,215,217],{"id":216},"_14-and-15-electronic-signatures-and-batch-release","14 and 15. Electronic signatures and batch release",[11,219,220],{},"An electronic signature needs to be attributable and meaningful. The record should make clear\nwho signed, when they signed, and what the signature represented, such as review, approval, or\nrelease.",[11,222,223],{},"Where a computerised system supports batch release or another critical quality decision, the\norganisation should be able to explain the decision path, the evidence considered, the authority\nof the signatory, and the controls that prevent ambiguity.",[21,225,227],{"id":226},"_16-and-17-business-continuity-and-archiving","16 and 17. Business continuity and archiving",[11,229,230],{},"Ask what would happen if the system disappeared now. Could production, Quality, investigation,\nor batch release continue? Critical processes need documented fallback arrangements that are\nunderstood and tested.",[11,232,233],{},"Archiving is more than storing data. The organisation must be able to retrieve, read, understand,\nand trust the record at the end of the retention period, including the context needed to interpret\nit.",[21,235,237],{"id":236},"the-questions-to-keep-asking","The questions to keep asking",[11,239,240],{},"Across all 17 themes, Annex 11 can be translated into a small set of operating questions:",[242,243,244,247,250,253,256],"ol",{},[110,245,246],{},"Is the system fit for the intended GMP use?",[110,248,249],{},"Are risks understood and controlled in proportion to their impact?",[110,251,252],{},"Are responsibilities, permissions, and decisions attributable?",[110,254,255],{},"Are data, interfaces, audit trails, and changes trustworthy and traceable?",[110,257,258],{},"Can the organisation recover, investigate, learn, and demonstrate continued control?",[11,260,79,261,265,266,270],{},[81,262,264],{"href":263},"\u002Fproduct\u002Fregulatory-compliance","Regulatory compliance pathway"," places these questions in\nthe wider context of practical quality practice. For AI-assisted work, the ",[81,267,269],{"href":268},"\u002Fproduct\u002Fagentic-ai-governance","Practical, Governed\nAI for GMP Quality Operations"," hub adds questions about output\nboundaries, human oversight, evaluation, evidence, and controlled change.",[11,272,273],{},"Annex 11 is therefore not only a software checklist. It is a way to test whether a computerised\nsystem supports quality work without weakening control, visibility, accountability, or trust.",[11,275,276,280],{},[81,277,279],{"href":278},"\u002Fcontact","Discuss your quality-system pathway",".",{"title":282,"searchDepth":283,"depth":283,"links":284},"",2,[285,286,287,288,289,290,291,292,293,294,295,296,297,298,299,300,301],{"id":23,"depth":283,"text":24},{"id":39,"depth":283,"text":40},{"id":49,"depth":283,"text":50},{"id":59,"depth":283,"text":60},{"id":69,"depth":283,"text":70},{"id":88,"depth":283,"text":89},{"id":98,"depth":283,"text":99},{"id":131,"depth":283,"text":132},{"id":141,"depth":283,"text":142},{"id":151,"depth":283,"text":152},{"id":161,"depth":283,"text":162},{"id":179,"depth":283,"text":180},{"id":189,"depth":283,"text":190},{"id":206,"depth":283,"text":207},{"id":216,"depth":283,"text":217},{"id":226,"depth":283,"text":227},{"id":236,"depth":283,"text":237},"Compliance","2026-09-10","A practical guide to the questions GMP teams should ask about computerised systems, from risk and responsibilities to data integrity, change control, and recovery.",false,null,"md",{},true,"\u002Fblog\u002Fannex-11-in-plain-english",{"title":5,"description":304},"blog\u002Fannex-11-in-plain-english",[314,315,316,317,318],"annex-11","gmp","data-integrity","validation","quality-systems","1asnTkwBTwI3Nt4IiNvphdiua_8S3RMm_3CvsOVM9Vk",1789037363079]