Computer System Validation: Pharma Requirements & EU GMP Annex 11

Computer System Validation Annex 11 lifecycle and EU GMP requirements

Many pharma firms use software to make or store GMP data. For example, LIMS, QMS, eBMR, or ERP. Once software supports GMP, you must prove it fits its purpose. You must also control risks. You must keep it under control for its whole life. This work is called Computer System Validation, or CSV. This Computer System Validation Annex 11 guide covers the lifecycle, data integrity, and cloud steps.

Computer System Validation Annex 11: What Is CSV?

CSV is a clear process. It shows that a system fits its planned use. It also shows that it works in real life.

CSV is more than a screen check. Therefore, you must know how you use the system. You must know what GMP step it supports. You must know what data it holds. You must know what risk occurs if it fails.

As a result, Computer System Validation Annex 11 links four items:

  • Planned use and GMP impact
  • User needs and requirements
  • Risk check per ICH Q9
  • Test proof and lifecycle control

Common systems include LIMS, MES, eBMR, QMS, CAPA, and ERP. In addition, cloud tools now fall in scope. However, your use and risk set the scope. Not every IT tool needs the same proof. The official text is listed in EudraLex Volume 4.

EU GMP Annex 11 Requirements for Computerised Systems

Annex 11 is the main EU guide for computer systems in GMP. The live version is from Jan 2011. It covers risk, validation, data, audit trails, access, e-signs, and backup.

Is Annex 11 Changing?

Yes. The 2011 text is old. Therefore, EMA wrote a concept paper in 2022.

Subsequently, the EU and PIC/S shared a new draft on 7 July 2025. The draft closed for comments on 7 Oct 2025 and is now under review.

The draft is much bigger. For example, it adds clear rules for cloud, SaaS, vendor checks, and AI. A new Annex 22 will cover AI systems. The 2011 version is still the binding text. However, inspectors already ask about topics from the draft. Therefore, you should align your Computer System Validation Annex 11 plan with the draft now.

How Should You Manage Risk?

Annex 11 wants a risk-based plan. You must check risks to patient, product, and data.

Moreover, ICH Q9(R1) says your work should match the risk. Therefore, low-risk tools need less proof. High-risk tools need more proof. For example, a LIMS that releases batches needs more tests than a training log.

What Are User Requirements?

User needs state what the system must do. They form the base for tests.

Consequently, you must map each key need to a test. This map proves you tested each need. In addition, you must approve needs before tests. This step is key for Computer System Validation Annex 11 compliance.

How to Handle Data Integrity and Audit Trails?

Annex 11 covers data, audit trails, access, e-signs, and backup. In addition, many firms use ALCOA+.

ALCOA+ means data must be clear, on time, and correct. Also, you must know who made it.

Access is key. For example, an analyst can enter a result. But the analyst cannot manage users. Therefore, you must test this block. You must show that audit trails log all changes with old value, new value, user, and reason.

What About Change Control and Periodic Review?

A valid system does not stay valid alone. For instance, patches and updates can change it.

Consequently, you need change control. You also need logs and periodic checks. These steps keep the system valid after go-live. As a result, you can show that the system stayed under control.

Do You Need a Backup and Business Continuity Plan?

Yes. For key steps, you need a backup plan. You must state what to do if the system fails.

Moreover, you should test the backup if risk is high. You must also log all events. For key events, you must find the root cause.

Computer System Validation Annex 11 Lifecycle: 7 Steps

The exact steps depend on system and risk. However, a typical lifecycle for Computer System Validation Annex 11 includes:

Step 1: Define Use and Scope

First, list process, users, and data. Therefore, you know what is in scope.

Step 2: Write User Needs

Write clear needs. For example, “System must block future dates.” You must validate each key need.

Step 3: Check Risks

Check risks for each need. As a result, you know what to test first. High risk means more proof.

Step 4: Plan Tests

Define docs, test methods, and pass criteria. Moreover, define who will review.

Step 5: Run Tests

Test against approved needs. Moreover, save all proof. Therefore, you can show evidence later.

Step 6: Review and Approve

Review results and gaps. Then approve the system for use.

Step 7: Keep It Validated

After go-live, use change control. Do periodic reviews. Re-test if needed. This step keeps your Computer System Validation Annex 11 status valid.

CSV, Data Integrity and Risk: A Simple LIMS Example

Think of a LIMS that holds lab data. It is not enough to show the right number on screen.

In addition, you must show who can change data. You must show how the audit trail logs it. You must show how data moves to other tools. And you must show how you keep records.

Therefore, Computer System Validation Annex 11 is not just about code. It is about system, process, people, and rules together.

Data Migration and Interfaces

Annex 11 says you must validate data moves. You must prove that data keeps its value and meaning.

Similarly, system links need checks. A good system can still fail if it sends wrong or duplicate data. Consequently, you must test interfaces with real data cases.

Computer System Validation Annex 11 for Cloud and SaaS

Today many systems run in the cloud. A vendor may host the tech. However, you still own GMP compliance. You own how you use it. You cannot outsource this duty.

Supplier docs can help. For example, they can reduce double work. But they do not prove that your setup fits your intended use. Therefore, you must still review needs. You must approve them. You must check your own config and user roles.

In short, the vendor controls the server and uptime. You control roles, config, and process. So your Computer System Validation Annex 11 plan must show where this line sits. GAMP 5 gives a useful guide here. But it does not replace GMP rules.

Do You Need IQ OQ PQ for Computer System Validation Annex 11?

Many teams use IQ OQ PQ:

  • IQ: Shows you installed the system as per needs.
  • OQ: Shows key functions work under set rules.
  • PQ: Shows it works well in daily use.

However, you should not use the same IQ OQ PQ plan for every system. The right plan depends on system type, use, and risk. Annex 11 wants a justified lifecycle plan. It does not force one fixed template. Therefore, your approach for Computer System Validation Annex 11 must be risk-based.

Next Steps

To prepare, review your system list. Check GMP impact and risk. Update your Computer System Validation Annex 11 files for cloud and audit trails. For more help, see our Computer System Validation services and GAMP 5 guide.

What is Computer System Validation in pharma?

 Computer System Validation (CSV) is a documented process to demonstrate that a computerised system supporting regulated activities is suitable for its intended use and remains under appropriate control throughout its lifecycle, including requirements, risk assessment, testing and lifecycle control.

What is EU GMP Annex 11?

 EU GMP Annex 11 is the European GMP guidance for computerised systems used as part of GMP-regulated activities. The current binding version is the January 2011 revision listed in EudraLex Volume 4, covering risk management, validation, data integrity, audit trails and lifecycle oversight.

 Is EU GMP Annex 11 being revised in 2025?

Yes. EMA published a concept paper in 2022 and the European Commission and PIC/S published a draft revised Annex 11 on 7 July 2025 for consultation until 7 October 2025. The draft expands requirements for cloud, SaaS, supplier oversight and AI. A new Annex 22 for AI is also proposed. The 2011 version remains binding until finalization.

Is IQ/OQ/PQ required for every computerised system?

Not necessarily in identical form. The appropriate qualification approach depends on the system, its intended use, GMP impact and risk. Annex 11 focuses on a justified lifecycle approach rather than prescribing one fixed IQ/OQ/PQ template.

How does Annex 11 apply to cloud and SaaS systems?

You still own responsibility for how you use a cloud or SaaS system in your GMP process, even if a supplier hosts it. You must review and approve requirements for your intended use, assess supplier documentation, control your configuration and user roles, and maintain the validated state through change control.

Estimated reading time: 7 minutes