Skip to main content
v2026.11,610 entries · CC-BY 4.0

Direct comparison

EU Annex 11 vs. 21 CFR Part 11

How EU GMP Annex 11 and US 21 CFR Part 11 differ on audit trails, e-signatures, supplier oversight, risk management, and periodic review, clause by clause.

Ask about EU Annex 11 vs. 21 CFR Part 11

Answers are drawn from this comparison and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

How do EU GMP Annex 11, 21 CFR Part 11 compare side by side?

The table below compares EU GMP Annex 11, 21 CFR Part 11 across 12 procurement-relevant dimensions, from legal character through enforcement route.

Side-by-side comparison

DimensionEU GMP Annex 1121 CFR Part 11
Legal characterEU GMP guidance under EudraLex Volume 4 — not a standalone statute, but the operative inspection standard across the EU/EEA and PIC/S member statesUS federal regulation (21 CFR Part 11), in force since 20 August 1997
Practical scopeApplies to any computerised system with GMP relevance on a site governed by EU GMPNarrowed by FDA's 2003 scope-and-application guidance to records a predicate rule (GMP/GCP/GLP) actually requires to be kept or submitted, and that are maintained electronically in place of paper
Risk-based approachRisk management is a named, opening principle (§1): validation effort and the rigor of data-integrity controls should be commensurate with the system's assessed GMP riskNo standalone risk-management clause — the regulation applies its controls uniformly once a record is in scope; risk-based scaling comes from separate FDA guidance (e.g. Computer Software Assurance), not Part 11 itself
System inventory§4.3 requires an up-to-date listing of all relevant systems and their GMP functionality, with a fuller system description required for systems assessed as criticalNo inventory requirement in the regulatory text
Suppliers & service providers§3 requires formal agreements with clear statements of responsibility (IT treated as a third party for this purpose), plus a risk-based supplier audit (§3.2) and documented review of COTS software (§3.3)No explicit supplier or vendor-assessment provision
Audit trails§9: audit trail scope itself is risk-based — built per a documented risk assessment to capture GMP-relevant changes and deletions, convertible to a generally intelligible form, and reviewed regularly§11.10(e): secure, computer-generated, time-stamped audit trails independently recording the date and time of operator entries and actions that create, modify, or delete an electronic record, without obscuring previously recorded information — required for every closed system in scope, not risk-scaled by the rule itself
Electronic signatures§14: an electronic signature must carry the same effect as a handwritten signature within the company, be permanently linked to its record, and include the date and time applied — stated at a principle level, without prescribing the signature's displayed components§11.50/11.70/11.100-11.300: a signed record must show the signer's printed name, the date and time of signing, and the meaning associated with the signature (e.g. review, approval, responsibility, authorship); signing sessions distinguish a first component (unique ID + password/biometric) from subsequent components within the same session
Data entry accuracy checks§6: critical data entered manually requires an additional accuracy check, by a second operator or by validated electronic means§11.10(f)-(h): operational system checks, authority checks, and device checks, but no manual-entry second-check requirement stated as such
Periodic evaluation§11 requires periodic evaluation confirming a live system remains in a valid, GMP-compliant state, with a near-checklist of what to cover (functionality, deviations, incidents, upgrade history, performance, security, validation status)No periodic-review clause in the regulation itself; ongoing review is addressed only through the site's own quality system under the applicable predicate rule
Business continuity§16 expects provisions for continuity of support for critical processes if a computerised system breaks down (e.g. a defined manual or alternative fallback)No business-continuity clause — addressed, if at all, through the predicate rule's own quality-system expectations, not Part 11
Archiving§17 sets expectations for the protection and accessibility of archived data across the required retention period, including on system or vendor change§11.10(c): record protection and ready retrievability throughout the retention period, without a dedicated archiving clause
Enforcement routeEU/EEA national competent authorities and PIC/S member-state GMP inspectors, citing Annex 11 as inspection guidanceFDA, citing 21 CFR Part 11 as a codified federal regulation, backed by the applicable predicate rule (GMP/GCP/GLP)

Common questions

Common questions about EU GMP Annex 11 vs 21 CFR Part 11

Does complying with 21 CFR Part 11 automatically satisfy Annex 11, or vice versa?

+

No. The two overlap heavily on audit trails and electronic signatures but diverge on supplier oversight, system inventory, periodic evaluation, and business continuity, all of which Annex 11 names explicitly and Part 11 does not. A lab under both regimes has to build a control set that satisfies whichever requirement is stricter on each point, not assume one framework's compliance covers the other.

Which is stricter overall?

+

Neither is uniformly stricter. Annex 11 goes further on programme-level obligations — risk management as a stated principle, supplier/service-provider audits, a mandatory system inventory, periodic evaluation, and business continuity planning. Part 11 is more prescriptive on one specific point: the exact components (printed name, date/time, meaning, session-based identification) an electronic signature manifestation must display.

Do I need GAMP 5 to comply with either one?

+

No — GAMP 5 (ISPE) is industry guidance, not EU or FDA regulatory text on either side. It sits outside both regimes formally, but functions as a shared, widely-adopted risk-based methodology for scaling validation effort by software category, and is used to structure compliance with both Annex 11 and Part 11 in practice.

Is Annex 11 legally binding the way Part 11 is?

+

Not in the same sense. Part 11 is codified US federal regulation. Annex 11 is EU GMP guidance issued under the EudraLex framework — it doesn't carry independent statutory force, but it is the operative standard EU/EEA and PIC/S member-state inspectors apply, so in practice it functions as a hard compliance requirement for any GMP site under their jurisdiction.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.