Skip to content
ComeplyComeply

The draft Annex 11: what changes, and why we wouldn't wait for the final text

Christian Hyltoft·Founder·September 30, 2026·5 min read

The draft Annex 11 read against an existing quality system

Still a draft, but one that lands in SOPs you already own.

In July 2025 the European Commission and PIC/S put a revised EU GMP Annex 11 out for consultation, along with a revised Chapter 4 on documentation and a new Annex 22 on artificial intelligence. Comments closed in October 2025. More than a year later, none of the three is final, and nobody can tell you the date the new Annex 11 will start to apply. We still think now is the time to read it. The direction is clear, and the SOPs it touches take a while to change, so it's better to plan that work before an inspector starts asking about it.

Where it stands

The draft came out on 7 July 2025 as a joint EU and PIC/S consultation, and comments closed on 7 October 2025. If you open EudraLex Volume 4 today, the current Annex 11 is still the one from January 2011. The EMA inspectors' working group now aims to give the Commission a final text for Annex 11, Chapter 4 and Annex 22 together in Q4 2026, which is later than it first planned. Until that final version is published there's no coming-into-operation date, and the wording can still change. So read everything below as the direction of travel. It isn't settled yet.

A much longer document

The 2011 annex is short and leans on principles. The draft has 17 sections and a glossary, and it adds headings the old one never had: the pharmaceutical quality system, alarms, identity and access management, and backup. Quality risk management runs through the whole lifecycle, with ICH Q9(R1) named as the place to look for methods and tools. You can still use alternative practices, as long as you can show, and document, that they give the same or a higher level of control. In practice there's less room for interpretation. A lot of what the 2011 text left to your judgement is now written down.

Audit trails become the default

This is the change most QA teams will feel first. The 2011 text, in section 9, only asked you to consider building an audit trail into a system, based on a risk assessment. Draft section 12 says a system where users create, modify or delete data should have an audit trail that automatically logs every manual user interaction. It should record who made the change, what changed (the old value and the new one), when (with the time zone) and why, and the system should prompt the user for the reason. It should also stay switched on and locked at all times. Reviewing audit trails isn't new, since the 2011 text already expected it. What the draft adds is detail. Each system needs a documented review procedure, and the review should be done by someone who wasn't involved in the activity. It should be targeted and risk-based rather than covering every entry, and it should happen before batch release unless you can justify catching problems later.

Signatures and access

Draft section 13 wants an electronic signature to involve full re-authentication. A smart card, a PIN or the fact that you're already logged in isn't enough on its own. The signature has to record what it means, and if a record changes after it was signed, it has to show as unsigned. Section 11, on identity and access management, is blunter still: shared accounts, apart from read-only ones, are called a violation of data integrity. Remote access to critical systems from outside controlled networks should use multi-factor authentication. People doing GMP work shouldn't hold administrator rights, and access should be reviewed on a recurring basis.

Suppliers, cloud and who is responsible

The draft is clear on one point: the regulated user stays fully responsible for a system, whoever built it and whoever runs it. You assess a supplier by audit or by a thorough assessment, depending on risk. You oversee them through service-level agreements and KPIs, and your contract needs an exit strategy so you keep control of your data if you part ways. Your own IT department is treated the same way as an outside provider, which will surprise some organisations. You won't find a separate chapter on cloud. Software as a service comes up in the sections on requirements and suppliers, and expectations for data centres sit under security, which now runs to 20 subsections.

Periodic review, backup and security

What used to be periodic evaluation becomes periodic review, with twelve things it has to cover. They include checking the configuration for changes nobody approved, following up on audit trail and access reviews, service levels, backup and restore tests, and changes in regulation. Backups have to be kept physically and logically apart from the original data, and restore tests should be documented and based on risk. On security, the draft expects an information security management system, security awareness training, timely patching, network segmentation, and penetration testing for critical systems that face the internet.

What we'd do now

It's tempting to wait for the final text. We'd advise against it, because rewriting these SOPs, training people on them and getting them approved all takes time. Start by listing the procedures the draft touches: computerised system validation, audit trail review, user and access management, electronic signatures, backup and restore, supplier qualification and periodic review. Read each one against the draft section that covers it and write down where it falls short. Keep your notes tied to the draft's section numbers. When the final text arrives, you'll see which findings still apply instead of starting from scratch.

Where Comeply comes in

We built Comeply for changes like this one. Monitoring picks up drafts like this when they're published. The requirement database splits the text into individual requirements and marks how binding each one is, and Crosswalk, which is still in beta, lines the draft up against the 2011 text clause by clause. Reports then check those requirements against your own SOPs and quote your documents back to you, with the quotes verified, so the list of affected procedures comes from what you've actually written. When the final version comes out, you run the same comparison again.

Annex 11 revision

See the draft Annex 11 read against your own SOPs.

We can show you how Comeply compares the draft with the 2011 text, and which of your procedures it affects.

Book a walkthrough