EU GMP

EU GMP Annex 11 - Computerised Systems

Plain-language explanation, inspection context and common violation patterns.

What it says

Computerised systems used in GMP-regulated activities must be validated as appropriate for their intended purpose, with risk management applied throughout the system lifecycle, audit trails enabled for critical data, and specific requirements for electronic signatures, data storage and business continuity in the event of system failure.

Paraphrased for plain-language clarity. Always verify against the current published regulation text.

What it means in practice

What inspectors look for

Most common violation

Computerised systems with no documented periodic review since initial validation, leaving open the question of whether the system remains appropriately validated after years of patches, configuration changes or expanded use.

Related regulations

Want a deeper, interactive breakdown?

GMPify's Regulation Explainer tool gives subscribers an AI-powered analysis of any 21 CFR, EU GMP, USP or ICH reference, with live inspection context.

Try the Regulation Explainer →