EU GMP readiness assessment and roadmap for Chapter 4, Annex 11 and Annex 22 - QFINITY
QFINITY · GMP drafts 2025

Readiness Assessment and RoadmapChapter 4, Annex 11 & 22

The readiness assessment is a gap assessment of your control architecture against the three draft texts of the EU GMP Guide (EudraLex Volume 4), read alongside current good practice. How well prepared you will be when the texts take effect is decided now, because experience shows that only months pass between publication and the effective date.

What you receive

Four deliverables at the end of the assessment.

The four results build on one another. Each module you book contributes its control map and its findings.

  1. 1Control map

    Your controls per module, with gaps and priorities against the draft and current good practice.

  2. 2Prioritized gap list

    Every gap ranked by risk and effort, with contested consultation points flagged.

  3. 3Roadmap to the effective date

    Steps, sequence and time windows. Your team carries them out, with our support if you wish.

  4. 4Management briefing

    One session: what is changing, where you stand and what comes first.

The central artifact

The control map.

The control map is one sheet per module. Every control in the framework appears on it with its status, every gap with its priority. The management briefing starts from this sheet.

Control map with prioritized gaps and roadmap: result of the readiness assessment for Chapter 4, Annex 11 and Annex 22 - QFINITY
Scope of service

Three modules, individually or as a package.

You choose the modules that fit. The point-by-point comparison is the basis, but the emphasis lies on interpretation. We clarify which expectation and which intent sit behind a requirement, which aspects are essential for you and how you can implement them in your processes and systems. That interpretation draws on client projects and our work in the ISPE GAMP committees.

Chapter 4 · 2025 draftData
What we examine
  • Data governance framework and ownership across the data lifecycle
  • Data criticality and data risk as the measure, ALCOA++
  • Play-through of two or three critical record chains
You receive
  • Control map of the framework with gaps and priorities
  • Findings for each record chain examined
Annex 11 · revision, 2025 draftSystems
What we examine
  • Process framework for validation, changes, access rights and audit trails
  • Security, periodic review and supplier oversight
  • Play-through of two or three selected systems
You receive
  • Control map of the framework, findings for each system examined
  • Action plan to strengthen your system controls, including the extended periodic review
Annex 22 · 2025 draftAI
What we examine
  • Inventory of your AI models and classification of their use as critical or non-critical
  • Intended use, acceptance criteria, test data, Human-in-the-Loop (HITL) and monitoring
  • Play-through of selected models, including generative AI outside critical applications
You receive
  • Control map for the governance of your AI models
  • Classification per application, findings for each model examined

Per module we assess your process framework and play it through on selected examples. The examples stand for your system landscape.

Also for clinical trials

For sponsors and CROs we run the same readiness assessment against ICH E6(R3) including its Annex 2, which takes effect in the EU on 15 January 2027. Alongside ICH E6(R3), the second reference is the 2023 EMA guideline on computerized systems and electronic data in clinical trials. Our page on the data integrity of GCP-relevant systems sets out the regulatory context.

In the intro call we settle which modules cover your situation.

Book an intro call
What is changing

Where the three drafts point.

In July 2025 the European Commission put Chapter 4, the Annex 11 revision and the new Annex 22 out for consultation. The texts interlock and none is final. We read the drafts in light of current good practice, meaning the 2011 Annex 11, PIC/S PI 041, GAMP 5 2nd Edition and the ISPE GAMP Guide on artificial intelligence, and gauge where the final texts are heading.

  • Chapter 4: data and documentation

    The draft provides for a data governance system as part of the pharmaceutical quality system, covering the entire data lifecycle. A documented risk assessment based on data criticality and data risk should justify the extent of data integrity measures. ALCOA++ applies to paper and electronic records alike.

  • Annex 11: computerized systems

    At 19 pages, the draft goes into far more detail than the 2011 text. The main additions are a dedicated security section with 20 requirements, rules for identity and access management, mandatory audit trails and a periodic review with a defined scope. Full responsibility for these requirements stays with the regulated company, even where suppliers or cloud services provide and operate the system.

  • Annex 22: AI models

    The Annex 22 draft is designed as the first standalone AI annex to EudraLex Volume 4 and builds on Annex 11 for the lifecycle of computerized systems. Its core themes are a documented intended use, acceptance criteria, independent test data and monitoring in operation. For generative AI the draft draws tight limits. Outside critical applications, qualified staff are to ensure that outputs are suitable for the intended use. The draft calls this Human-in-the-Loop.

Why start now

According to the 2026 to 2028 work plan of the EMA's GMP/GDP Inspectors Working Group, the final texts of Chapter 4, Annex 11 and Annex 22 are due to go to the European Commission by the end of 2026. A transition period follows, and for EU GMP annexes it has been short: the current Annex 11 took effect on 30 June 2011, a few months after publication. Annex 15 followed the same pattern in 2015. Companies that wait for the final texts must take stock, assess and implement within that window, alongside day-to-day operations.

The process

How the readiness assessment works.

In five steps we develop the roadmap with you. We contribute the method and our reading of the drafts, and your core team carries out the assessment together with us.

  1. 1

    Intro call

    The intro call takes about 30 minutes. You describe your system landscape, data flows and AI plans. Within two working days you receive a module proposal with a scope estimate and a time window.

  2. 2

    Framework and examples

    With a small core team from QA, IT and one process owner we capture your process framework and select the examples: record chains, systems and models, ranked by risk to patient safety, product quality and data integrity.

  3. 3

    Gap assessment per module

    Section by section, we check your framework against current good practice and the direction of the drafts and uncover the gaps. This includes structured interviews, a review of your process and system documentation and walkthroughs as needed. We tell you in advance how much of your core team's time we need. We calibrate the depth of evidence to the risk-based methodology of GAMP 5 and Computer Software Assurance.

  4. 4

    Prioritization

    We prioritize every gap by risk and effort. Requirements that already appear in the current texts and that the draft spells out in detail come first. Points contested in the consultation become watch items. We add recommendations drawn from our project experience.

  5. 5

    Roadmap and briefing

    You receive the four deliverables, from the control map to the management briefing. Our aim is a team that is ready to act and can carry out the roadmap.

Self-check

Six questions for a first look.

Each of the six questions addresses a core element that one of the three drafts provides for. They are no substitute for a readiness assessment, but every negative answer points to the module you should start with.

Is there a documented data governance system in which the criticality and risk of your data determine the extent of your measures?
Has responsibility for the lifecycle of critical data been assigned, from capture to destruction?
Is your periodic review set up to handle the new scope, from the validated state through access rights and audit trails to supplier contracts?
Can the people responsible in your organization explain the evidence from suppliers and cloud providers to an inspector without outside help?
Can you confidently classify the use of your AI models as critical or non-critical?
Have you defined how to measure the performance of a process step before you deploy a model there?

Questions one and two belong to the data module, three and four to systems, five and six to AI. If you answer no to at least one question in each of two or more modules, we recommend a package of those modules.

The team

Who conducts the readiness assessment.

A QFINITY team conducts the readiness assessment. Its members know Annex 11 and Annex 22 from GAMP committee work, from published articles and from exchanges with regulators. Their own audit practice has taught them what inspectors expect.

  • Committees

    On the team: the Chair of the ISPE GAMP Europe Steering Committee and the Chair of the GAMP Global Steering Committee.

  • Audit practice

    More than 17 years of audit experience, over 100 audits, more than 70 of them in the GCP environment since 2014.

  • Publications

    Member of the GAMP 5 2nd Edition core team. “How AI Will Transform Computerized System Validation”, Pharmaceutical Engineering, January/February 2026. Plus numerous articles and conference talks.

Responsibility for the evaluation, the residual risk and the release remains with your company.

Objections

Frequently asked questions about the readiness assessment.

Yes. The principles of Chapter 4 and Annex 11, such as the validated state across the lifecycle and responsibility for outsourced activities, already apply today. Annex 22 is new but builds on Annex 11. Because we compare the drafts with current good practice, the assessment holds up even if details change in the final text.

Above all, the scope of review. For the periodic review the Annex 11 draft lists twelve items, among them supplier contracts, user access and audit trails. Chapter 4 adds the documented data governance system, and Annex 22 adds governance for AI models. A working CSV is the foundation the assessment builds on.

No. Each module is a standalone gap assessment. If you are preparing to use AI, say with a draft SOP on validating AI-supported systems, the AI module tests that SOP. If your data governance is documented, the data module checks framework and record chains before the final text applies. Onboarding and inventory are shared, while classification follows each module's draft.

The effort depends on the number of modules, whether global processes are included and the number of sites. A global scope is estimated separately. The scope estimate after the intro call sets out days and a time window. Plan for three to six weeks and for your core team's participation in interviews and walkthroughs.

Your team can implement the roadmap on its own, and on request we support the implementation. A review of further data, systems and AI applications using the same method is available as a follow-up. Where you need additional capacity or expertise, we support you with GxP consulting, supplier audits or training.

Go deeper

The drafts in detail.

Preparation creates certainty.

Once the final texts are published, little time will remain for implementation, if past annexes are any guide. In a free intro call (about 30 minutes) we map your data, systems and AI plans to the modules. Within two working days you receive a scope estimate and a time window.

Discuss your assessment now