Chapter 4, Annex 11, Annex 22: Three Drafts, One Control System

Oliver Herrmann at the lectern of the main conference of the Biopharmaceutical Bioprocess Development Summit in Shanghai

One conference day in Shanghai, packed and inspiring in equal measure: a keynote and a panel at the Biopharmaceutical Bioprocess Development Summit, plus the deep-dive AI session at the AI for Pharma 2026 running in parallel. The question raised on the panel is one we currently meet in projects and committees alike: how do the three European drafts Chapter 4, Annex 11 and Annex 22 work together? This article shares the reading we gave on stage and looks into the background of shifting responsibilities, authority cases and criticality – as a working hypothesis based on the drafts and our observations.

Oliver Herrmann and Martin Heitmann under the entrance arch of AI for Pharma 2026 in Shanghai
TWO INVITATIONSInvited independently, on stage together: Oliver Herrmann and Martin Heitmann at the venue in Shanghai.

The occasion was unusual enough to be worth telling: a CMC and bioprocess summit put EU GMP regulation on its keynote program, and the AI for Pharma 2026 running in parallel booked the matching AI deep dive. Martin Heitmann and I had been invited independently of each other and only discovered it during preparation. Companies there want to know the criteria while there is still time to design for them. One day on site, tightly scheduled, and on the main conference panel the question that carries this article: how do all these data integrity requirements actually fit together?

The order behind the three drafts

Keynote slide: One Delivery, Three Rule Books - delivery, cargo, truck, autopilot and driver as an image for Chapter 4, Annex 11 and Annex 22
KEYNOTE SLIDEOne picture, three rule books: the cargo is the data (Chapter 4), the truck is the application and the road the qualified infrastructure (Annex 11), autopilot and guardrails belong to Annex 22, and a human stays at the wheel, carrying responsibility.

Our answer on the panel starts with where the legal act sits. Chapter 4 lives in the main part of the EU GMP Guide, and that is also where batch certification takes place: the Qualified Person certifies the batch on the basis of the records. That is not a system function but a legal act, and it is now meant to rest entirely on records – beyond documents in the traditional sense. This is why Chapter 4 addresses the data and its governance.

Annex 11 is the technical implementation. Its job is to give this legal act technical and functional trust: the computerized system in which the records are created, validated against its intended use and operated in a validated state. Annex 22, finally, inherits from both. It governs AI in critical GMP applications and presupposes the data and system control that Chapter 4 and Annex 11 have built. In the end, the three texts have to add up to a coherent control system, or one of them has not done its job.

One caveat belongs to every one of these statements: all three texts are drafts from the consultation. What will finally be published is open. Until then, this reading is a working hypothesis, based on our observations in the industry and on the EMA’s communication.

As early as 2022, the EMA concept paper on the Annex 11 revision announced that the FDA guidance on Computer Software Assurance, then available as a draft, would be examined: "This guidance and any implication will be considered with regards to aspects of potential regulatory relevance for GMP Annex 11." A guidance from the medical device world, written for production and quality system software and final in the meantime, is thus explicitly on the radar of the pharma revision. The convergence reaches across the Atlantic.

Exhibit 1: The person who moved

To test the ordering formula, follow the Qualified Person through the texts. The Annex 11 of 2011 named them explicitly: "…only Qualified Persons [to] certify the release of the batches". In the 2025 draft, they no longer appear. Instead, they now stand in the Chapter 4 draft: "All records should be available to the Qualified Person at the time of the release decision."

The move confirms the order: certification rests on the records, so the Qualified Person belongs in the chapter that governs the records. The system-side execution, meaning the signature in the system and the workflow behind it, remains a matter for Annex 11. On stage, we made the point in a single sentence:

The QP did not leave. The annex stopped being about them.

Exhibit 2: The numbers

The second test is quantitative. We measured the drafts against the 2011 versions, on the primary texts themselves:

1
Annex 11 grows from 5 to 19 pages. A statement of principles becomes a catalog of requirements that increasingly describes what control has to look like.
2
Chapter 4 grows from 9 to 17 pages and from 32 to 85 clauses. Both clause series are numbered without gaps; the chapter is still called "Documentation".
3
Four terms that appeared exactly zero times in 2011 now carry the chapter. Counted in the text: "governance" 19 times, "data integrity" more than twenty times, "lifecycle" 15 times, "criticality" 7 times.

The unassailable core of this measurement is the zero: a documentation chapter builds its foundation on terms it did not even know in 2011. The numbers show the direction, away from the document as a container, toward the data and its lifecycle as the object of control.

The test question both drafts ask: how strongly do these data influence the decision resting on them, and would you even notice an error?

Exhibit 3: Criticality has three readings and two axes

"Critical" appears several times across the drafts and does not mean the same thing three times over. The Chapter 4 draft defines data criticality in its glossary as "the degree of influence that data have on product safety as well as the regulatory compliance of processes, decisions and product quality". The same draft adds a second axis, detectability: would you see it if the data were wrong? The Annex 22 draft, in turn, calls applications critical when they have a "direct impact on patient safety, product quality or data integrity".

The third reading we took from a conference presentation: at the ISPE Pharma 4.0 conference in Barcelona in 2025, the EMA rapporteur explained the intention behind the critical-application concept along two axes, direct impact and detectability of the error. Detectability thus stands in both drafts, in Chapter 4 as in Annex 11 ("the likelihood of detection"), and additionally in the explained intention behind Annex 22; a single find becomes a pattern.

In practice, both converge on ALCOA++: criticality drives the rigor with which the ten attributes are demonstrated. And the second plus, Traceable, is the attribute-side counterpart of the detectability axis: it makes an error findable after the fact.

Exhibit 4: Existing requirements already apply to the use of AI

Anyone who considers the drafts a distant prospect should read two authority cases from this year. In April 2026, the FDA charged a manufacturer in a warning letter with "overreliance on artificial intelligence for your drug manufacturing operations". And in June 2026, the MHRA described AI-written inspection responses in its Inspectorate blog with "references to MHRA guidance that doesn’t exist", and drew the line that matters: "our concern isn’t whether you use AI; it’s whether your submissions are accurate, verifiable, and prepared under appropriate oversight".

Both authorities check the same thing: whether the evidence is accurate, verifiable and produced under appropriate oversight. The use of AI as such is not in question in either case. That is exactly the logic of the three drafts, applied before their finalization.

What follows from this

Oliver Herrmann at the microphone on the main conference panel in Shanghai
THE PANELThe question about the interplay of the requirements came from the main conference panel. This article’s answer is the worked-out version.

The consequence of our observations: the culture these drafts presuppose can be built today, with a data inventory, assigned criticality and a governance that puts the cross-cutting questions where they belong. Someone has to start, and what the first one builds sets the measure for every system that follows. That is exactly why these foundations belong at the overarching QA level: laid out once there, they carry across all systems instead of emerging by chance in whichever project comes first. QFINITY has supported this build-up since the ERES programs of the Part 11 era and from the core team of GAMP 5 Second Edition; we read the drafts before they become the rule.

And the sentence that drew the strongest reaction in Shanghai belongs at the end, because it explains why this control architecture exists in the first place:

Our industry is not machines serving patients. It is people serving people. The colleague who runs the bioreactor today may be the patient waiting for the vial tomorrow.

More on the foundation of this reading: our pages on the Annex 11 revision and the EU GMP Annex 22 track the state of the two drafts, and our analysis of PIC/S recommendation PI 006-4 shows how the same movement reaches the production level.