
The Annex 11 Revision.
The draft of the new EU GMP Annex 11 (2025 consultation) replaces the 2011 version and brings the requirements for computerized systems into line with today's IT reality. Four pages become nineteen; security, identity and access management, alarms and operation in the cloud now take center stage. The draft is not final yet, and its level of detail in particular is under intense discussion in the industry. Its impact, however, is already noticeable in inspections.
Not a maintenance update: a complete overhaul.
The EMA's GMP/GDP Inspectors Working Group and the PIC/S Committee rewrote Annex 11 together; the draft replaces the 2011 version for the EU and the PIC/S authorities alike. It codifies what inspectors have expected for years: much of it previously lived only in Q&As and data integrity guidance.
The draft prescribes what control has to look like, down to MFA, virus scanners and password rules. At the same time, detailed rules age faster than the annex they sit in: the prescribed password complexity reflects a position that NIST Special Publication 800-63B has now explicitly moved away from. In our view, specifics of this kind belong in referenced standards.
Five documents, one direction.
Read the revision in context and the pattern emerges. Within two years, EMA and PIC/S have set five initiatives on the same course, from concept paper to adopted recommendation:
| Document | Level | The common thread |
|---|---|---|
| Concept Paper on the Annex 15 revision (2026) | Production level: processes | qualification and validation as a continuous task across the lifecycle |
| PIC/S PI 006-4 (in force from 10/2026) | Production level: practice | retrospective validation removed, Ongoing Process Verification replaces periodic revalidation |
| Annex 11 draft (2025 consultation) | System level | a validated state across the entire lifecycle, periodic review as a chapter of its own |
| Annex 22 draft (2025 consultation) | System level: AI models | continuous performance and drift monitoring, building on the initial test evidence |
| Chapter 4 draft (2025 consultation) | Data level: documentation | Data Governance across the entire data lifecycle |
In our view, this sequence is no coincidence: Annex 11 modernizes the system level, Chapter 4 the data level; only on that foundation can the EU GMP Annex 22 regulate AI models whose evidence relies just as much on continuous monitoring. The 2022 concept paper still wanted to regulate AI within Annex 11 itself; that it became an annex of its own keeps the AI rules flexible for a fast-moving field, and underlines how solid the foundation has to be. Our analysis of PIC/S recommendation PI 006-4 shows how the same movement reaches the production level.
Where the text stands today.
The revision has been running to a published plan since 2021, with delays but without a change of direction:
- 1
Concept Paper
In 2022, the EMA's GMP/GDP Inspectors Working Group and the PIC/S Committee decide on the revision together. The concept paper lists 33 reasons, including cloud services, audit trails and IT security, and set publication by the European Commission for June 2026.
- 2
Draft and Consultation
July to October 2025: the 19-page draft goes out for comments, alongside Chapter 4 (documentation) and the new Annex 22 in the consultation on the EudraLex Volume 4 revision.
- 3
Evaluation
The drafting group evaluates the consultation comments. We do not expect another consultation round with the industry.
- 4
Finalization
The working group's workplan aims to hand the final text to the European Commission toward the end of 2026, roughly half a year later than originally planned. We expect publication no earlier than that, not least because Annex 11 and Annex 22 have to fit together in the end.
- 5
Entry into Force
A transition period follows publication. Until then, the 2011 Annex 11 applies; inspectors' expectations, however, are already aligning with the draft.
Does the new Annex 11 conflict with CSA?
In 2025, with its final guidance on Computer Software Assurance, the FDA streamlined how evidence is produced. The Annex 11 draft demands executed test scripts and makes traceability a hard pass-or-fail criterion. A contradiction?
Annex 11: formalizes the evidence
Executed test scripts as evidence, traceability to requirements as a hard pass-or-fail criterion, conditional approval only with a documented assessment.
CSA: the thinking that comes first
Test depth follows risk and Intended Use; unscripted testing is permitted where the risk supports it.
On a close reading, there is no contradiction: both frameworks scale the extent of testing on a risk basis, and the draft opens the door to alternatives that demonstrably provide "the same or higher level of control". The drafting group had CSA on the table as early as 2022; the concept paper explicitly commits to taking account of the FDA guidance, at the time newly published as a draft. Test on a risk basis and trace the evidence cleanly back to requirements, and you serve both worlds with one approach.
The validated state becomes a permanent task.
The new Chapter 14 turns the periodic evaluation into a review program in its own right: the review verifies that the system remains "fit for intended use" and in a validated state; a final review closes out decommissioning.
"Computerised systems should be validated before use and maintained in a validated state throughout their lifecycle."
EU GMP Annex 11 (Computerised Systems), draft for the 2025 consultation, section 2.1 "Lifecycle management".
The validated state is therefore no longer a project deliverable but an operational task across the entire lifecycle. Anyone who only starts assembling the evidence when the inspection comes does not have it.
QFINITY has worked on computerized systems since the ERES programs of the Part 11 era - on the core team of GAMP 5 Second Edition and in day-to-day validation practice. We read the drafts before they become the rule, so our clients are prepared when others are only starting to look.
What you can establish today.
We do not have a crystal ball either: the new Annex 11 may turn out strict, in line with the current draft, or milder, allowing more flexibility. If it turns out strict: who walks through your system inventory and checks every system against the new requirements, on top of day-to-day business? If it turns out mild: who decides what 'appropriate' means for you? Either way, sensible requirements can already be introduced today, with justification:
Frequent questions.
The text is a draft; the consultation ran until October 2025. The working group's workplan aims to hand the text to the European Commission toward the end of 2026, followed by a transition period. Until entry into force, the 2011 version applies.
Formally, no. But many of its requirements come from Q&As, data integrity guidance and everyday inspection practice; they describe the expectation inspectors are already working to. Close the gaps only after finalization and you will be working under time pressure.
Audit trail functionality becomes mandatory wherever users can change data, settings or access. The review becomes targeted rather than across-the-board: it follows the risk, concentrates on the integrity of manual changes and sits with people not involved in the activity. It must be completed before batch release, unless a later point in time is justified.
For remote access to critical systems from outside controlled perimeters, the draft provides for MFA. Behind that lies a fundamental shift: the draft treats IT security as a GMP topic; password rules, patching and penetration tests now sit in the annex itself.
The 2022 concept paper still wanted to regulate acceptance criteria for AI models within Annex 11 itself. That became an annex of its own: the EU GMP Annex 22 governs AI models in critical GMP applications, while the surrounding computerized system is validated under Annex 11.
Bring your systems to the state the draft expects.
The new Annex 11 is not final yet; your systems run today, and the next inspection will not wait for Brussels. We mirror your system landscape against the draft, from access management and audit trail review to the periodic review plan, and prioritize the gaps by risk. What gets implemented is what makes sense for your systems, not every provision for its own sake. The starting point: a free initial consultation (about 30 minutes) in which we assess your position.
Book an initial consultation


