Computerised systems in GxP environments must meet strict documentation and validation requirements. Manage critical Annex 11 terminology with version control, approval workflows, and audit trails — directly in Confluence.
EudraLex Volume 4, Annex 11 is the EU GMP standard governing computerised systems used in medicinal product manufacturing. Published by the European Commission, revised in 2011, it requires validation, audit trails, access controls, supplier assessment, and business continuity for any computerised system processing GMP-relevant data. It applies alongside — and is broader than — FDA 21 CFR Part 11.
EudraLex Volume 4, Annex 11 “Computerised Systems” is the EU’s regulatory framework for computerised systems used in GMP (Good Manufacturing Practice) environments. Published by the European Commission and last revised in 2011, it applies to all medicinal product manufacturing in the EU/EEA.
Annex 11 is the EU counterpart to FDA 21 CFR Part 11. Where Part 11 focuses on electronic records and electronic signatures, Annex 11 takes a broader approach — covering the entire computerised system lifecycle from specification through retirement.
The key principle: a computerised system must not reduce product quality, process control, or quality assurance. Every system that creates, modifies, stores, or retrieves GMP-relevant data must be validated and controlled.
For regulated organisations, consistent terminology across validation documents, SOPs, and qualification protocols is not optional — it is an audit expectation. When your validation plan says “operational qualification” but your test script says “operational acceptance testing,” an inspector will question your validation approach.
Both regulations govern electronic records and computerised systems, but they differ in scope and emphasis. Teams operating in both EU and US markets need to understand where they overlap and where they diverge.
| Requirement Area | EU Annex 11 (official text) | FDA 21 CFR Part 11 (eCFR) |
|---|---|---|
| Audit trails | Required (§9) | Required (§11.10(e)) |
| Access controls | Required (§12) | Required (§11.10(d)) |
| Electronic records integrity | Required (§§7, 9, 17) | Required (§11.10) |
| Electronic signatures | Required (§14) — same impact as hand-written signatures within the boundaries of the company, permanently linked to record, time- and date-stamped | Detailed requirements (Subpart C: §§11.100, 11.200, 11.300); signature/record linking at §11.70; manifestations at §11.50 |
| System validation | Explicit lifecycle requirements (§4) | Required (§11.10(a)) |
| Personnel & training | Explicit requirement (§2) | Personnel qualifications (§11.10(i)) |
| Supplier assessment | Required (§3.2) | Not specifically addressed |
| Incident management | Required (§13) | Not specifically addressed |
| Business continuity | Required (§16) | Not specifically addressed |
| Periodic evaluation | Required (§11) | Not specifically addressed |
| Data migration | Explicit requirements (§4.8) | Not specifically addressed |
Key takeaway: Annex 11 is broader than Part 11. If you comply with Annex 11’s full scope — validation, suppliers, incident management, periodic review — you cover most of Part 11’s requirements as well. EU GMP Annex 11 §14 covers electronic signatures directly: they “shall have the same impact as hand-written signatures within the boundaries of the company,” be permanently linked to their respective record, and include the time and date applied. Part 11 elaborates the same area in much greater operational detail across Subpart C (signature components, identification codes, controls). For teams managing both, see our FDA terminology page.
The Annex 11 terminology landscape, organized by domain:
| Category | Terms | Examples |
|---|---|---|
| System Lifecycle | 6 | Computerised System, Validation, URS, Functional Spec, Configuration, Customisation |
| Data Integrity | 5 | Audit Trail, Electronic Record, Data Migration, Archiving, Backup |
| Access & Security | 4 | Access Control, Logical Security, Physical Security, System Administrator |
| Operation | 5 | Incident Management, Change Control, Periodic Review, Business Continuity, Disaster Recovery |
| Quality | 5 | Qualification, Operational Acceptance, GxP Assessment, Supplier Assessment, SLA |
A pre-built Annex 11 CSV isn’t available yet. The AI Act, FDA, and SOC 2 templates are available now and provide a structure you can adapt to Annex 11 — same column format, same one-click import.
EudraLex Volume 4, Annex 11 is the EU GMP standard governing computerised systems used in medicinal product manufacturing. Published by the European Commission and last revised in 2011, it requires validation, audit trails, access controls, supplier assessment, and business continuity for any computerised system processing GMP-relevant data.
Annex 11 is broader than Part 11. Annex 11 covers the entire computerised system lifecycle — validation, supplier assessment, periodic review, incident management, and business continuity — while 21 CFR Part 11 focuses on electronic records (Subpart B) and electronic signatures (Subpart C). Part 11 elaborates e-signature rules across Subpart C (§§11.100, 11.200, 11.300); Annex 11 §14 addresses electronic signatures directly — they “shall have the same impact as hand-written signatures within the boundaries of the company,” be permanently linked to the record, and carry the time and date applied.
Annex 11 applies to any computerised system used in GMP-regulated activities: LIMS, ERP, MES, SCADA, chromatography data systems, electronic batch records, document management systems, and any tool (including terminology or glossary tools) that creates, modifies, stores, or retrieves GMP-relevant data.
Annex 11 §9 (Audit Trails) requires consideration, based on a risk assessment, of building into the system a record of all GMP-relevant changes and deletions. For change or deletion of GMP-relevant data the reason should be documented. Audit trails need to be available, convertible to a generally intelligible form, and regularly reviewed.
Stop managing computerised system definitions in spreadsheets without audit trails. Build your term set in the app, approve, scan your validation documentation. Need help getting started? See the installation guide and documentation.
Evaluate in Confluence Browse Available TemplatesCompliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence
FDA Terminology Management — 43 FDA terms with 21 CFR Part 11 alignment
GxP Documentation Guide — GxP compliance overview for pharma, biotech, and medtech
ALCOA+ Documentation Principles — data integrity framework for audit trail requirements
ISO 13485 Terminology — medical device quality management terminology guide
Security & Privacy Whitepaper — Forge architecture, SOC2, DORA, NIS2, GDPR, FDA 21 CFR Part 11 coverage
EU AI Act Terminology Governance — non-pharma regulatory hub for AI Act Article 3 definitions