Orientation in eight questions

Annex 11 Check for computerised systems

In a few minutes, assess how robustly risk management, validation, supplier control, audit trails and access controls are organised. The evaluation identifies initial priorities without collecting personal data.

A transparent quick check, not an audit

The check follows the sections of EU GMP Annex 11 (2011 revision) and the publicly available ZLG Aide-Mémoire 071212 on inspecting computerised systems: the question catalogue used by German GMP inspectors. Scoring is explicit: Yes = 3, Partly = 2, Unknown = 1, No = 0. The result provides orientation and is neither an audit nor legal advice.

Evidence Review · 8 questions
Step 1 of 2
Step 1: Governance and validation
01 · Risk managementDoes a documented risk assessment drive the extent of validation and data-integrity controls throughout the system lifecycle?

Requirement from EU GMP Annex 11, section 1: Risk Management.

02 · ValidationIs the computerised system validated on a risk basis before GxP use, with traceable requirements and qualification evidence (URS, IQ, OQ, PQ)?

Requirement from EU GMP Annex 11, section 4: Validation.

03 · SuppliersAre suppliers and service providers, including hosting, formally assessed, and are quality agreements in place?

Requirement from EU GMP Annex 11, section 3: Suppliers and Service Providers.

04 · Data and accuracyDo data-integrity controls apply to all GMP data, and is critical manually entered data independently verified?

Requirement from EU GMP Annex 11, sections 5 and 6: Data and Accuracy Checks.

Step 2: Operation and monitoring
05 · Audit trailAre GMP-relevant audit trails enabled, protected, time-stamped and reviewed on a documented, risk-based schedule?

Requirement from EU GMP Annex 11, section 9: Audit Trails.

06 · SecurityDo all persons use individual accounts with role-based rights, and are administrator privileges segregated from routine use?

Requirement from EU GMP Annex 11, section 12: Security.

07 · Change controlAre software and configuration changes assessed for GMP impact, approved and documented before implementation?

Requirement from EU GMP Annex 11, section 10: Change and Configuration Management.

08 · Periodic evaluationIs the system periodically evaluated on a risk basis, including functionality, deviations, incidents, upgrades, security and validation status?

Requirement from EU GMP Annex 11, section 11: Periodic Evaluation.

Regulatory context and target groups

For operators

Pharmaceutical and manufacturing organisations gain an initial view of validation, supplier control, audit trails and access controls before inspection.

For ERP and system owners

The check helps prioritise CSV gaps on manufacturing ERP, MES and connected GxP systems, before the audit calendar tightens.

Develop Annex 11 with robust evidence

Discuss CSV, a GAP analysis or validation of a manufacturing ERP with our advisory team.

Contact us