Written and maintained by CASRAI Editorial Board
Last updated
Scope of this page: this covers computerised system validation (CSV) as EU GMP actually frames it — EudraLex Volume 4 Annex 15 (Qualification and Validation), revision deadline 1 October 2015, plus Annex 11 (Computerised Systems), revision 1, deadline 30 June 2011. Most CSV content online defaults to a US framing — GAMP 5 plus 21 CFR Part 11 plus, more recently, FDA’s Computer Software Assurance guidance — and treats the EU requirements as a footnote. This page reverses that: the lifecycle below is built from Annex 15 and Annex 11 text directly, with the FDA-centric framing addressed as a separate comparison further down. As of 2026-08-26 a draft revision of Annex 11 is in progress but not yet in force — see the callout near the end before citing draft clause numbers.
Which regulation governs what: Annex 15 sets the lifecycle, Annex 11 sets the computer-specific controls
The two annexes do different jobs, and EU GMP guidance keeps them separate on purpose.
Annex 15 (Qualification and Validation) is the general framework that applies to every qualified/validated thing on a GMP site — equipment, facilities, processes, and computerised systems alike. It sets the programme-level rules: a validation master plan (VMP) should clearly define the qualification/validation programme (Annex 15 §1.4), and §1.5 lists exactly seven things a VMP should include or reference — policy, organisational roles, a summary of facilities/equipment/systems/processes and their qualification status, change control and deviation handling for qualification and validation, guidance on acceptance criteria, references to existing documents, and the qualification/validation strategy including requalification. Annex 15 also sets rules that apply throughout the lifecycle: a mid-execution change to a protocol (including its acceptance criteria) must be handled as a documented, scientifically justified deviation (§2.7); a failed acceptance criterion is a deviation requiring full investigation (§2.8); and conditional approval to proceed to the next qualification stage is explicitly permitted, but only with a documented assessment that the open item has no significant impact (§2.10). One general-section line is worth quoting exactly because it forecloses a shortcut some sites still try: “Retrospective validation is no longer considered an acceptable approach.”
Annex 11 (Computerised Systems) is narrower and more specific: it governs what a computerised system itself must be able to demonstrate, on top of whatever Annex 15 requires of the qualification programme around it. It names four roles — Process Owner, System Owner, Qualified Persons and IT (§2) — and sets requirements for supplier and third-party management: formal agreements with clear statements of responsibility, with IT departments treated as analogous to a third party (§3.1); a supplier audit based on risk assessment (§3.2); documentation review of commercial off-the-shelf (COTS) software against user requirements (§3.3); and supplier quality-system/audit information available to inspectors on request (§3.4).
Put simply: Annex 15 tells you when and why to validate, and what the governing document looks like. Annex 11 tells you what the computerised system specifically has to be able to show. A CSV programme under EU GMP has to satisfy both at once, which is exactly what most FDA-centric CSV guidance doesn’t model, since 21 CFR Part 11 has no equivalent split between a programme-level annex and a systems-level annex.
The lifecycle end to end: from system inventory to retirement
Reading Annex 15 and Annex 11 together produces a working lifecycle, not just a list of clauses. Here is what it looks like in the order a system actually moves through it.
- Inventory and GMP-functionality assessment. Annex 11 §4.3 requires “an up to date listing of all relevant systems and their GMP functionality” to be available, and for systems assessed as critical, a current system description covering physical/logical arrangements, data flows, interfaces, hardware/software prerequisites and security measures. This is the entry point: nothing downstream (risk classification, validation depth, periodic review) can happen for a system that isn’t on the inventory.
- User requirements and risk assessment. Annex 11 §4.4 requires user requirements specifications (URS) based on a documented risk assessment and the system’s GMP impact, and that traceability be maintained through the rest of the lifecycle. This is where GAMP 5’s software-category framework typically gets applied in practice — Annex 11 doesn’t name GAMP 5, but nothing in it conflicts with using GAMP categories to scale validation effort to risk, which is why the two are used together almost everywhere despite GAMP 5 being industry guidance (ISPE), not EU or FDA regulatory text.
- Supplier assessment. For anything not built entirely in-house, §3.2’s risk-based supplier audit and §3.3’s COTS documentation review happen here, before qualification protocols are written.
- Qualification stages (DQ/IQ/OQ/PQ). Annex 15’s general qualification model applies: protocols define the critical systems, attributes and parameters to be tested, plus acceptance criteria (§2.4); third-party or vendor-supplied protocols must still be confirmed suitable by site personnel and may need supplementing, not accepted as-is (§2.6). For bespoke or customised systems specifically, Annex 11 §4.6 requires a formal assessment and report on quality and performance measures covering all lifecycle stages — a heavier bar than for configured COTS software. See IQ/OQ/PQ and Computer System Validation (CSV): GAMP 5, IQ/OQ/PQ, and 21 CFR Part 11 for the mechanics of the qualification stages themselves — this page doesn’t repeat that detail.
- Data migration, where applicable. Annex 11 §4.8 requires verification that data migrated into a system are not altered in value and/or meaning — a distinct, documented check, not an assumption that a successful transfer implies fidelity.
- Go-live and periodic evaluation. Once live, Annex 11 §11 requires periodic evaluation to confirm a system remains in a valid state and GMP-compliant. The clause lists, almost as a ready-made agenda, what that evaluation should cover where appropriate: current range of functionality, deviation records, incidents, problems, upgrade history, performance, reliability, security and validation status reports. Annex 15 §4.1–4.2 adds the general requalification rule underneath this: evaluate at an appropriate frequency, and where a fixed period is used, that period must be justified with defined evaluation criteria — a blanket “revalidate every three years” policy with no stated justification doesn’t satisfy this on its own.
- Change control through the system’s life. Annex 15 §11.2/11.4/11.7 governs change control for qualified/validated systems generally; nothing in the lifecycle above is a one-time event once a system is live.
One clause is easy to misread and worth flagging on its own: Annex 15 §1.3 says validation personnel do not need to report into QA or quality management — but “there should be appropriate quality oversight over the whole validation life cycle.” That is a narrower requirement than the reporting-line assumption a lot of training material makes.
What EU GMP expects a live computerised system to demonstrate
Separate from the validation lifecycle itself, Annex 11 sets ongoing operational requirements for any GMP-relevant computerised system:
- Accuracy checks (§6): for critical data entered manually, there must be an additional accuracy check — by a second operator or by validated electronic means.
- Printouts (§8.1/8.2): clear printed copies must be obtainable, and for records supporting batch release, it must be possible to generate printouts indicating whether any data has been changed since the original entry.
- Audit trails (§9): the audit trail requirement is itself risk-based — systems should be built, based on a risk assessment, to record GMP-relevant changes and deletions, and that record must be available, convertible to a generally intelligible form, and regularly reviewed.
- Operator identity (§12.4): systems should record the identity of operators entering, changing, confirming or deleting data, including date and time.
- Incident management (§13): all incidents — not only system failures and data errors — should be reported and assessed, with the root cause of a critical incident identified and used as the basis for corrective and preventive action.
- Electronic signatures (§14): expected to carry the same effect as a handwritten signature within the company, be permanently linked to their record, and include the time and date applied.
The general pattern across these clauses: EU GMP asks for a documented, risk-based justification of how much control is enough, rather than prescribing one fixed mechanism for every system regardless of criticality.
How this differs from the FDA-centric CSV framing most guidance defaults to
Search results and vendor whitepapers on “computer system validation” overwhelmingly default to a US framing: GAMP 5, 21 CFR Part 11, and increasingly FDA’s Computer Software Assurance (CSA) approach. That framing isn’t wrong, but it isn’t the same regulatory structure as EU GMP, and treating them as interchangeable causes real gaps. The concrete differences:
- Different legal character. 21 CFR Part 11 is US federal regulation (electronic records and electronic signatures). Annex 11 is EU GMP guidance issued under the EudraLex framework — not a directly binding regulation in the same sense, but the operative GMP inspection standard across the EU/EEA and PIC/S member states. Both drive toward similar controls (audit trails, access control, electronic signature integrity), but through structurally different documents with different legal weight.
- No EU equivalent to FDA’s Computer Software Assurance guidance. FDA’s “Computer Software Assurance for Production and Quality System Software” guidance was finalised 24 September 2025, and it is scoped specifically to production and quality-system software under the Quality System Regulation (21 CFR Part 820, the medical-device context) — it is not a Part 11 replacement, and it has no EU GMP counterpart. There is no analogous EU document that formally licenses “critical thinking replaces scripted testing” for GMP computerised systems the way CSA does for US medical-device production software. Under EU GMP, validation rigor is scaled to risk directly through Annex 11/15’s own risk-assessment language, not through a separate assurance-philosophy guidance document.
- Annex 11 requires a documented system inventory; Part 11 doesn’t name one. The §4.3 requirement for an up-to-date listing of all relevant systems and their GMP functionality is an EU GMP-specific obligation with no direct Part 11 equivalent.
- GAMP 5 sits outside both regimes formally. GAMP 5 (ISPE, second edition, published July 2022) is industry guidance, not law or GMP text on either side of the Atlantic. It functions as a shared, informally-adopted risk-based methodology that both EU GMP and FDA-regulated CSV programmes lean on to structure software-category-based validation effort — but citing GAMP 5 as if it were an EU GMP or FDA requirement overstates its standing.
- PIC/S is the broader harmonisation layer most non-US guidance is actually built on. PIC/S PI 011-3, “Good Practices for Computerised Systems in Regulated GXP Environments” (25 September 2007), and PI 041-1, “PIC/S Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments” (1 July 2021), sit behind much of the computerised-systems and data-integrity expectations inspectors from PIC/S member authorities apply — a layer that a purely EU-vs-FDA comparison misses entirely.
For the mechanics of Part 11 itself and how GAMP 5 categorisation and the IQ/OQ/PQ sequence work in the US-centric framing, see 21 CFR Part 11: Electronic Records & Signatures and Computer System Validation (CSV): GAMP 5, IQ/OQ/PQ, and 21 CFR Part 11. For validation of electronic lab notebooks specifically under the Part 11/GxP framing, see Electronic Lab Notebook Validation Under 21 CFR Part 11 and GxP.
Where this fits in the document hierarchy
A single computerised system’s validation record doesn’t stand alone — it sits under a site’s validation master plan (VMP), which is the Annex 15 §1.4/1.5 governing document defining the whole qualification and validation programme a given system’s validation work has to satisfy. That guide covers the document hierarchy (policy → VMP → validation plan → protocol → summary report) and the lab-versus-manufacturing-site distinction in depth; this page deliberately doesn’t repeat it.
Annex 11 revision in progress — not yet in force
A draft revision of Annex 11 was published for public consultation on 7 July 2025, with the consultation closing 7 October 2025. Industry reporting on the draft (not yet independently confirmed against the final published text, since there is no final published text yet) describes a substantial expansion — from roughly five pages to around nineteen pages across seventeen chapters plus a glossary — adding coverage of cybersecurity, identity and access management, and supplier oversight, and aligning more explicitly with GAMP 5, ICH Q9/Q10 and PIC/S. A companion new Annex 22 covering artificial intelligence is also reported as part of the same package. As of the date this page was last checked, the revised Annex 11 had not been published, and the 2011 revision 1 text described above remains the operative version. Don’t cite specific draft clause numbers as current requirements — check EudraLex Volume 4 directly before relying on this for an inspection-ready programme.
Frequently asked questions
Is EU GMP Annex 11 the same thing as 21 CFR Part 11?
No. They cover overlapping ground — audit trails, electronic signatures, access control — but they are different documents with different legal character: Annex 11 is EU GMP guidance under the EudraLex framework, and 21 CFR Part 11 is US federal regulation. A system built to satisfy one is not automatically compliant with the other; each has its own specific clauses that need checking independently.
What is the difference between Annex 11 and Annex 15?
Annex 15 (Qualification and Validation) is the general programme-level framework covering equipment, facilities, processes and computerised systems alike, including the validation master plan requirement. Annex 11 (Computerised Systems) is narrower: it sets requirements specific to computerised systems — system inventory, URS, supplier management, audit trails, electronic signatures and periodic evaluation — on top of whatever Annex 15 requires of the qualification programme around it.
Does GAMP 5 apply under EU GMP, or only under FDA regulation?
Neither, formally. GAMP 5 is industry guidance published by ISPE, not EU GMP text and not FDA regulation. In practice it is used on both sides as a shared risk-based methodology for scaling validation effort to a system’s software category and GxP risk, but citing it as if it were itself a regulatory requirement overstates its actual standing.
Does FDA’s Computer Software Assurance (CSA) guidance apply to EU-regulated computerised systems?
No. FDA’s CSA guidance, finalised 24 September 2025, is scoped to production and quality-system software under the US Quality System Regulation (21 CFR Part 820) — a medical-device context. It has no formal standing under EU GMP and no EU GMP equivalent has been issued. It is, however, widely seen as philosophically aligned with GAMP 5’s second edition (2022) risk-based approach.
Has the revised version of Annex 11 been published yet?
Not as of this page’s last check. A draft went to public consultation from 7 July to 7 October 2025, but the final revised text has not been published, so the 2011 revision 1 remains the operative document. Re-check EudraLex Volume 4 directly before relying on draft-stage details for a live validation programme.








