Skip to content
Entourage

How do life sciences companies validate computerised systems in a GMP-compliant manner under GAMP 5 and EU GMP Annex 11?

We support pharma, biotech, MedTech and IVD companies in validating computerised systems under GAMP 5 and EU GMP Annex 11 - from system classification and the validation plan through URS, IQ, OQ and PQ to the validation report and lifecycle maintenance. The critical fork is rarely the testing itself, but the risk classification at the outset: validating a standard system as if it were a custom-developed one burns effort that is then missing elsewhere for data integrity.

  • Pharma
  • Biotech
  • MedTech
  • IVD

Overview

What do Annex 11 and 21 CFR Part 11 require of computerised systems?

CSV across all industries · GAMP 5, EU GMP Annex 11, FDA 21 CFR Part 11

Last updated: 2026-06-13

The EU GMP Guide Annex 11 and FDA 21 CFR Part 11 require every GMP-relevant IT system to be demonstrably fit for its intended use and to keep its data integral across the entire lifecycle. The points where CSV projects most often get stuck:

  • Risk-based validation scope instead of a one-size-fits-all approach: GAMP 5 classifies systems from standard software to custom development; without this classification, either too much is tested or a critical system is under-validated - both an inspection finding.
  • A complete, traceable validation package: URS, functional specification, traceability matrix, IQ, OQ and PQ must be seamlessly linked so that every requirement points to a test record - Annex 11 requires an end-to-end specification and testing chain.
  • Data integrity according to ALCOA principles: audit trail, access control and electronic signatures under Annex 11 and 21 CFR Part 11 must be technically implemented and configured, not merely described in an SOP.
  • Change control and revalidation in operation: software updates, operating system upgrades and configuration changes without an impact assessment invalidate the validated state - the validated state is a lifecycle, not a one-off project closure.

Services

How we support you

Risk-based validation strategy under GAMP 5

Classification of your systems into the GAMP 5 categories and derivation of the validation scope per system. Deliverable: a validation master plan with a justified risk and GxP-criticality assessment for each system.

Complete validation package from URS to PQ

Preparation of the user requirement specification, functional specification, traceability matrix as well as IQ, OQ and PQ protocols with test scripts. Deliverable: a validation dossier ready for inspection against Annex 11, including the validation report.

Data integrity & audit trail assessment

Review and implementation of the requirements for audit trail, access permissions and electronic signatures under Annex 11 and 21 CFR Part 11. Deliverable: a data integrity assessment with a gap list and concrete configuration measures.

Learn more

Change control & revalidation

Impact assessment for updates, upgrades and hardware changes, plus definition of the revalidation scope. Deliverable: an assessed change record with a decision on the extent of requalification and a documented rationale.

Learn more

CSV lifecycle & periodic review

Establishing the periodic system review, maintaining the validated state and preparing for inspections. Deliverable: a periodic review procedure with criteria that evidence the validated state across the system's lifetime.

What it comes down to

Computer system validation is at its core a question of sequence, not of test volume. The EU GMP Guide Annex 11 and FDA 21 CFR Part 11 do not require maximum effort, but an effort that matches the risk of the system. That is why the GAMP 5 classification at the outset determines the whole project: a standard system essentially needs a supplier assessment and a PQ under real conditions, while a configured or bespoke system needs the full chain of URS, functional specification, traceability matrix, IQ, OQ and PQ. Skip this classification and you validate non-critical systems too deeply and GxP-critical ones too shallowly - and it is exactly this imbalance that an inspector finds first.

The second bottleneck comes after release. A validation report proves the state as at a cut-off date, not for the system's lifetime. Change control and periodic review keep the validated state in force: every update and every upgrade needs an impact assessment that defines the revalidation scope before it goes live. In parallel, data integrity must take hold technically in line with the ALCOA principles - an enabled, tamper-proof audit trail and role-based access control under Annex 11 and 21 CFR Part 11, not just as SOP text. Companies that plan for these two strands, lifecycle and data integrity, from the start shift the effort to where corrections are cheap, rather than into the inspection, where they become expensive.

Our approach

Our approach

01

System assessment & classification

System inventory with GxP criticality and GAMP 5 category per system, with the validation scope derived from it.

02

Validation plan

Validation plan with roles, acceptance criteria, risk assessment and test scope, aligned with QA.

03

Specification & qualification

URS, functional specification and traceability matrix as well as executed IQ, OQ and PQ protocols with documented results.

04

Validation report

Final report with an assessment of deviations, releasing the system for GMP use.

05

Lifecycle & change control

Periodic review, change control integration and revalidation logic established in ongoing operation.

Common pitfalls

Where projects commonly fail

Every system is validated to the same depth.

Standard software with no configuration receives the same test scope as a custom development under GAMP 5. The result is excessive effort on non-critical systems while GxP-critical systems are tested too sparingly - the most common finding from an incorrect risk classification.

The traceability matrix is missing or not end-to-end.

Annex 11 requires every requirement from the URS to be traceable through to a test record. If the linkage is reconstructed only at project close, requirements without test coverage surface and are treated as a gap in the audit.

The audit trail is assumed but not verified.

Many systems technically provide an audit trail, but it is switched off, not tamper-proof or configured in a way that is not reviewable. Annex 11 and 21 CFR Part 11 require an effective, enabled and regularly reviewed audit trail.

Software updates go in without an impact assessment.

A patch or operating system upgrade is applied without assessing the validated state. The validation status is thereby formally invalidated - an inspector spots this from a version discrepancy between the validation report and the production system.

Supplier documentation is adopted unchecked.

The software vendor's test documentation does not replace your own qualification. Without a supplier assessment and your own PQ under real process conditions, it remains open whether the system performs as intended in the specific use case.

FAQ

Frequently asked questions

GAMP 5 (ISPE Good Automated Manufacturing Practice) is the industry reference for validating computerised systems in regulated GxP environments. It provides a risk-based approach: systems are categorised by their degree of standardisation, and the validation scope follows from GxP criticality and risk - less effort for standard systems, more for configured and bespoke systems.

Sources
  • EU-GMP-Leitfaden Annex 11 (Computerised Systems) - primary text
  • FDA 21 CFR Part 11 (Electronic Records; Electronic Signatures) - primary text
  • GAMP 5 (ISPE Good Automated Manufacturing Practice, A Risk-Based Approach to Compliant GxP Computerized Systems)
  • EMA Q&A: Good Manufacturing Practice - Data Integrity; PIC/S PI 041 (Data Management and Integrity)
  • Entourage website writer source material - Computer System Validation expertise page
  • https://theentourage.de/expertise/computer-system-validierung/ (existing page content, revised)

Life Science Journal

Regulatory updates, straight to your inbox.

New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.

Regulations & standards considered

  • EU-GMP-Leitfaden Annex 11 (Computerised Systems)
  • FDA 21 CFR Part 11 (Electronic Records; Electronic Signatures)
  • GAMP 5 (ISPE Good Automated Manufacturing Practice, A Risk-Based Approach to Compliant GxP Computerized Systems)
  • EMA Q&A: Good Manufacturing Practice - Data Integrity
  • PIC/S PI 041 (Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments)

Have a concrete project?

Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.

Prefer direct? +49 89 4161170-0
info@theentourage.de

  • Reply usually within one working day
  • 4 offices: DE · CH · IT · US
  • 100% life sciences