The GMP Annex 11 Revision: Computerised Systems, Data Integrity and the New AI Annex

EU GMP Annex 11, the rulebook for computerised systems in pharmaceutical manufacturing, dates from 2011 — before cloud computing, software-as-a-service and machine learning were part of daily operations. That is about to change. In July 2025 the European Commission opened a consultation on a substantially revised Annex 11, an updated Chapter 4 and an entirely new Annex 22 on artificial intelligence. Together they represent the biggest shift in EU data-governance expectations in over a decade.

Why the 2011 text ran out of road

The current Annex 11 is a short, principles-based guideline that has served for years but plainly predates modern IT. A concept paper published in November 2022 by the EMA and PIC/S set out the drivers for revision: data both “in motion” and “at rest,” the digital transformation of manufacturing, the rise of AI and machine learning, and the near-universal reliance on external cloud and software service providers. None of these are meaningfully addressed by the existing annex.

What is on the table

On 7 July 2025 the Commission opened a stakeholder consultation on three linked EudraLex Volume 4 documents — a revised Chapter 4 (Documentation), a revised Annex 11 (Computerised Systems) and a new Annex 22 (Artificial Intelligence) — drafted by the EMA GMDP Inspectors Working Group together with PIC/S. The consultation closed in October 2025, and the sector is now in the post-consultation review window. No confirmed effective date has been published; adoption is widely expected during 2026, but firms should plan against direction rather than a fixed deadline.

How Annex 11 is changing

Based on the Commission’s own summary of the draft, the revised Annex 11 raises expectations across the board:

  • Lifecycle management of computerised systems as an explicit, continuous obligation rather than a one-off validation event.
  • Quality risk management applied across every stage of the system lifecycle.
  • Stronger requirements on the definition and maintenance of system requirements.
  • Much stronger oversight of suppliers and external service providers — the reality of cloud and SaaS is written into the text.
  • Reinforced controls on data integrity, audit trails, electronic signatures and system security.

The practical direction is clear: cybersecurity, identity and access management, and supplier governance move from good practice to core GMP expectations, and audit-trail review becomes a more demanding, more explicit discipline.

Annex 22: the first dedicated EU GMP rules on AI

Annex 22 is the genuinely new element. It addresses the use of AI and machine-learning models in the manufacture of active substances and finished products, with an emphasis on intended-use definition, model selection, training, validation, performance metrics and the quality of training and test data, backed by continuous oversight through change control, performance monitoring and human review.

The draft takes a notably conservative line on the type of AI permitted in critical GMP applications, with commentary across the sector reading it as restricting critical use to static, deterministic models that produce the same output for the same input, and keeping continuously-learning and generative models out of critical applications. The precise scope wording is exactly the kind of detail that can shift between draft and final text, so the sensible course is to track the enacted version closely before committing to a validation approach for any AI tool touching product quality.

It builds on a familiar data-integrity foundation

None of this arrives in a vacuum. The revision sits within EudraLex Volume 4 and rests on the established data-integrity lineage — the ALCOA and ALCOA+ principles, the PIC/S data-integrity guidance, and long-standing regulator expectations that records be attributable, legible, contemporaneous, original and accurate. Because the documents were co-drafted with PIC/S, the changes will ripple across the many authorities that participate in that scheme, not just the EU.

What manufacturers should do now

The consultation window has closed, but the preparation window has not. Sensible early steps include reassessing computerised-system validation against a lifecycle and risk-management model, mapping and tightening contracts and oversight for cloud and SaaS suppliers, reviewing audit-trail and access-control practices against the raised bar, and taking an inventory of any AI or machine-learning tools already influencing GMP decisions so their governance can be brought up to the expected standard.

How PQRA helps

PQRA helps manufacturers and their suppliers prepare for the revised Annex 11 and Annex 22: gap-assessing computerised systems and data-integrity practices against the draft expectations, strengthening supplier qualification and cloud governance, upgrading audit-trail and validation frameworks, and building defensible controls around AI tools used in GMP environments. We help sites treat this as a managed transition rather than a last-minute scramble when the final text lands.

To assess your readiness for the revised EU GMP computerised-systems and AI requirements, get in touch with the PQRA team.

CATEGORIES:

Uncategorized

Tags:

No responses yet

Αφήστε μια απάντηση

Η ηλ. διεύθυνση σας δεν δημοσιεύεται. Τα υποχρεωτικά πεδία σημειώνονται με *