EU GMP Annex 11: Computerised Systems
EU GMP Annex 11 (revised 2022) provides guidance on the application of Good Manufacturing Practice (GMP) to computerised systems used in the pharmaceutical industry, including manufacturing, testing, and distribution. Published by the European Commission as part of EudraLex Volume 4, it covers the entire lifecycle of computerised systems, data integrity, risk management, and compliance requirements for regulated operations.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (20)
Audit Trail
| Code | Title |
|---|---|
| GMP11-10 | Audit Trails |
Change
| Code | Title |
|---|---|
| GMP11-17 | Change and Configuration Management |
Compliance
| Code | Title |
|---|---|
| GMP11-25 | Inspection Readiness |
Data Integrity
| Code | Title |
|---|---|
| GMP11-07 | Data Integrity ALCOA Plus |
| GMP11-08 | Data Input Accuracy Checks |
| GMP11-09 | Accuracy and Range Checks at Interfaces |
| GMP11-22 | Time Stamp and System Clock |
E-Signatures
| Code | Title |
|---|---|
| GMP11-11 | Electronic Signatures |
General Requirements
Six general requirements that apply across all four pillars
| Code | Title |
|---|---|
| Clause 1 | Risk management |
| Clause 2 | Personnel |
| Clause 3 | Suppliers and service providers |
| TNFD-GR-1 | Materiality |
| TNFD-GR-2 | Scope of Disclosures |
| TNFD-GR-3 | Location of Nature-related Issues |
| TNFD-GR-4 | Integration with Other Sustainability Disclosures |
| TNFD-GR-5 | Time Horizons |
| TNFD-GR-6 | Engagement with Affected Stakeholders |
Governance
| Code | Title |
|---|---|
| GMP11-02 | Personnel and Responsibilities |
Lifecycle
| Code | Title |
|---|---|
| GMP11-18 | Periodic Evaluation |
| GMP11-24 | Decommissioning and Data Migration |
Operational Phase — Change and Configuration
| Code | Title |
|---|---|
| Clause 10 | Change and configuration management |
| Clause 11 | Periodic evaluation |
Operational Phase — Data Management
| Code | Title |
|---|---|
| Clause 5 | Data |
| Clause 6 | Accuracy checks |
| Clause 7 | Data storage |
| Clause 8 | Printouts |
| Clause 9 | Audit trails |
Operational Phase — Release and Continuity
| Code | Title |
|---|---|
| Clause 15 | Batch release |
| Clause 16 | Business continuity |
| Clause 17 | Archiving |
Operational Phase — Security and Access
| Code | Title |
|---|---|
| Clause 12 | Security |
| Clause 13 | Incident management |
| Clause 14 | Electronic signatures |
Operations
| Code | Title |
|---|---|
| GMP11-19 | Incident Management |
| GMP11-20 | Batch Release Using Electronic Records |
Project Phase
| Code | Title |
|---|---|
| Clause 4 | Validation |
Records
| Code | Title |
|---|---|
| GMP11-16 | Archiving |
| GMP11-21 | Printouts and Verification |
Resilience
| Code | Title |
|---|---|
| GMP11-14 | Backups |
| GMP11-15 | Business Continuity |
Risk
| Code | Title |
|---|---|
| GMP11-01 | Risk Management Approach |
Security
| Code | Title |
|---|---|
| GMP11-12 | Access Control and Identity Management |
| GMP11-13 | Periodic Access Review |
| GMP11-23 | Security and Cybersecurity Safeguards |
Supplier
| Code | Title |
|---|---|
| GMP11-03 | Suppliers and Service Providers |
Validation
| Code | Title |
|---|---|
| GMP11-04 | Validation Lifecycle |
| GMP11-05 | User Requirements Specification (URS) |
| GMP11-06 | Configuration Management |
Your Compliance Coverage
If you comply with EU GMP Annex 11: Computerised Systems, you already cover:
AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
17%
8 controls mapped
Compare →CFTC System Safeguards (17 CFR 37, 38, 39, 49)
17%
8 controls mapped
Compare →ASIC Cyber Resilience Good Practices
17%
8 controls mapped
Compare →+ 648 more: CSA STAR (Security, Trust, Assurance, and Risk) (17%), FTC GLBA Safeguards Rule (16 CFR Part 314) (17%)
See all 651 mapped frameworks ↓Maps to 651 other frameworks
Frequently Asked Questions
What is EU GMP Annex 11: Computerised Systems?
EU GMP Annex 11: Computerised Systems is a compliance framework from European Union (EMA/EC) with 20 domains and 48 controls. EU GMP Annex 11 (revised 2022) provides guidance on the application of Good Manufacturing Practice (GMP) to computerised systems used in the pharmaceutical industry, including manufacturing, testing, and distribution. Published by the European Commission as part of EudraLex Volume 4, it covers the entire lifecycle of computerised systems, data integrity, risk management, and compliance requirements for regulated operations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does EU GMP Annex 11: Computerised Systems have?
EU GMP Annex 11: Computerised Systems has 48 controls organised across 20 domains. The largest domains are General Requirements (9 controls), Operational Phase — Data Management (5 controls), Data Integrity (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does EU GMP Annex 11: Computerised Systems map to?
EU GMP Annex 11: Computerised Systems maps to 651 other compliance frameworks. The top mapping partners are AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (17% coverage), CFTC System Safeguards (17 CFR 37, 38, 39, 49) (17% coverage), ASIC Cyber Resilience Good Practices (17% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with EU GMP Annex 11: Computerised Systems compliance?
Start your EU GMP Annex 11: Computerised Systems compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU GMP Annex 11: Computerised Systems requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 48 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required