How can life sciences companies demonstrate gap-free QA compliance of their GxP-relevant IT systems to inspectors?
We audit GxP-relevant IT systems from a QA perspective: validation status, IT vendor suitability, change control and the inspection readiness of the system portfolio. The real hurdle is rarely the individual system, but rather the missing link between IT operations and QA oversight. As long as patches and configuration changes run without QA review, the gap only surfaces in the audit trail, that is, precisely when the authority is standing in front of it.
- Pharma
- Biotech
- MedTech
- IVD
Overview
Which QA compliance gaps arise in IT systems in life sciences?
QA audits for GxP IT systems in accordance with EU GMP Guide Annex 11, 21 CFR Part 11 and GAMP 5
Last updated: 2026-06-13
GxP-relevant IT systems such as LIMS, eQMS and MES must meet the same quality standards as physical processes. In practice, however, IT compliance is often treated as a purely IT task, without QA exercising the same oversight that it applies to equipment and procedures. The gaps that inspections most frequently target:
- Validation documentation for GMP systems is incomplete or outdated; the lifecycle validation required under EU GMP Guide Annex 11 is not consistently evidenced.
- IT vendor audits are neglected, even though GMP-critical data is processed at the service provider and EU GMP Guide Annex 11 requires an assessment of the supplier and service provider.
- Change control and incident management for IT systems are not adequately monitored from a quality standpoint; software updates and patches run without proper QA review.
- The audit trail required under 21 CFR Part 11 and Annex 11 is not enabled, not reviewed, or configuration changes have been left without a traceable history.
Services
How we support you
CSV quality audit of the system portfolio
A complete review of the validation status of all GxP-relevant IT systems: completeness and currency of the validation documentation, quality of the IQ/OQ/PQ packages in accordance with EU GMP Guide Annex 15, traceability gaps and validation backlog. The deliverable is a list of findings with risk classification and a prioritization matrix per system.
Learn more →IT vendor assessment & QA requirements
Auditing of IT service providers and software vendors against GMP-relevant quality requirements: software development lifecycle, change and incident management, access controls and data integrity. The deliverable is an audit report with findings, classification by GAMP 5 software category and a draft quality agreement.
QA review of IT change control
Review and optimization of the IT change control process from a QA perspective: quality of the impact assessment, QA review involvement, revalidation decisions and documentation of patches. The deliverable is an assessment of the as-is process against EU GMP Guide Annex 11 with concrete corrective actions.
Learn more →Inspection preparation IT & CSV
Preparation for regulatory inspections in the IT area: verification of the completeness of the system portfolio, review of all CSV documents and a mock inspection with IT-focused inspection questions. The deliverable is an action plan with gaps closed ahead of the inspection date.
Learn more →Audit trail & data integrity review
Examination of audit trail configuration and audit trail review practice against 21 CFR Part 11 and EU GMP Guide Annex 11: activation, protection against manipulation, access roles and traceability of configuration changes. The deliverable is a gap report per system with an assessment against the ALCOA principles.
Learn more →How we work together
What it comes down to
A QA audit for IT systems does not check the system against a requirements specification, but rather the quality oversight of the system. The EU GMP Guide Annex 11 and 21 CFR Part 11 require that computerized systems remain validated across their lifecycle, that the audit trail secures the traceability of every data change, and that suppliers and service providers are formally assessed. The sequence determines the effort: first the system inventory must be in place and every system must carry a GAMP 5 category, because only the categorization governs, on a risk basis, how deep validation, vendor assessment and audit trail review need to reach. Anyone who audits without this inventory over-validates standard software unnecessarily and at the same time overlooks the custom category 5 systems to which the critical findings attach.
The pressure point almost always lies at the interface between IT operations and QA. Patches, configuration changes and vendor updates run within IT operations, while QA involvement in change control is missing. As long as this gap persists, an affected validation status only becomes visible once an inspector opens the audit trail and finds an undocumented change. We therefore start with change control and audit trail review before releasing the portfolio for inspection: corrections are cheap where they are planned as a CAPA, and expensive when they appear as an observation in the inspection report.
Our approach
Our approach
Step
Result
Scoping & system inventory
A confirmed list of GxP-relevant IT systems with GAMP 5 categorization and risk classification as the audit scope.
Document & on-site review
Findings on validation documentation, change control and audit trail, evidenced against Annex 11 and 21 CFR Part 11.
Vendor assessment
Audited IT service providers with findings, assessment of the software development lifecycle and the status of quality agreements.
Findings report & prioritization
An audit report with classified findings, risk classification and a prioritization matrix for remediation.
CAPA support
Defined corrective and preventive actions, traceable through to evidence of effectiveness.
Inspection readiness
Critical gaps closed and an IT and CSV portfolio that can be presented to a regulatory inspection.
Common pitfalls
Where projects commonly fail
The audit trail is configurable, but was never enabled or never reviewed.
21 CFR Part 11 and EU GMP Guide Annex 11 require not only the technical capability, but documented periodic audit trail review; an empty or unreviewed trail is a classic inspection finding.
IT patches and security updates are deployed by IT operations without going through QA change control.
This means the assessment of whether the system's validation status under Annex 11 is affected is missing, and a revalidation decision was never made.
Cloud and SaaS providers are treated as pure IT suppliers and not audited as GMP-relevant service providers.
If the provider processes GMP-critical data, EU GMP Guide Annex 11 requires a formal assessment and a quality agreement, which in practice is often missing.
GAMP 5 categorization is skipped, so that standard software and configurable or custom systems receive the same blanket validation effort.
This leads either to under-validated category 5 systems or to unnecessary effort for simple standard software.
Responsibility between IT and QA is not delineated in writing.
The audit reveals that no one owns the oversight of validation and compliance, because IT points to QA and QA points to IT; QA's overarching GMP responsibility remains formally unevidenced.
FAQ
Frequently asked questions
Sources
- EU GMP Guide Annex 11 (Computerised Systems) and Annex 15 (Qualification and Validation) - primary text
- 21 CFR Part 11 (Electronic Records; Electronic Signatures) and Part 211 - primary text
- GAMP 5 - A Risk-Based Approach to Compliant GxP Computerized Systems (ISPE)
- ISO 13485:2016; IEC 62304
- https://theentourage.de/expertise/audits-and-qa-services-for-it-systems/ (existing page content, revised)
Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Case Studies
What this looks like in practice
Related insights
All insights →Regulations & standards considered
- EU GMP Guide Annex 11 (Computerised Systems)
- EU GMP Guide Annex 15 (Qualification and Validation)
- 21 CFR Part 11 (Electronic Records; Electronic Signatures)
- 21 CFR Part 211 (cGMP for Finished Pharmaceuticals)
- GAMP 5 (Good Automated Manufacturing Practice, ISPE)
- ISO 13485:2016 (QMS for Medical Devices)
- IEC 62304 (Medical Device Software Lifecycle)
Related topics
Computer System Validation →
CSV as the foundation of the validation status examined in the audit
IT Audits & ISO 27001 →
IT security audits complementing the GMP QA perspective
Inspection Readiness →
Inspection preparation beyond the IT area
Data Integrity Assurance →
Audit trail and ALCOA in accordance with Annex 11 and 21 CFR Part 11
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +49 89 4161170-0
info@theentourage.de
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences


