Annex 11 to EU GMP - Computerised Systems
Operational Phase - Data Management

Annex 11 to EU GMP - Computerised Systems Clause 5: Data

Built-in checks must ensure correct and secure entry and processing of electronically exchanged data.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 14 controls across 6 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 42001:2023 · 5 controls

  • 8.4 AI system impact assessment
  • A.4.3 Data resources
  • A.7 Data for AI systems
  • A.7.5 Data provenance
  • A.7.6 Data preparation

ISO/IEC TR 24028:2020 · 4 controls

  • 8.2.2 Data poisoning
  • 8.3.2 Data acquisition
  • 8.3.3 Data pre-processing and modelling
  • 8.8.1 Data acquisition and preparation

ISO 27002:2022 · 2 controls

  • 8.11 Data masking
  • 8.12 Data leakage prevention

FDA 21 CFR Part 11 · 1 control

ISO/IEC 23894:2023 · 1 control

  • 23894-A.7 Data Quality and Provenance

ISO/IEC 38500:2024 · 1 control

  • 5.9 Data and decisions

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operational Phase - Data Management

Query this from an agent

The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.