30+ Data Points on What Changes and Why It Matters
Annex 11 of the EU GMP guidelines has governed how pharmaceutical manufacturers must design, validate, and operate computerised systems since its last revision in 2011. In June 2025 the European Commission published a draft revision open for industry consultation until October 2025, with the final version expected in mid-2026. The draft expands the document from 5 to 19 pages, adds seven new sections, and introduces explicit requirements for cloud systems, cybersecurity, artificial intelligence, and senior management accountability – none of which appeared in the 2011 version.
The context for this revision is significant. According to Zamann Pharma analysis of critical GMP inspection findings from 2024, more than 70 percent were directly related to computerised systems, with data integrity, audit trail management, and access control as the most frequently cited categories. The 2025 draft is a regulatory catch-up to what inspectors have been expecting for years.
Below we have compiled 30+ data points on the 2025 Annex 11 draft revision: what changed, what is new, how the new requirements compare to the 2011 standard, what the inspection data shows about current compliance gaps, and what the timeline means for manufacturers.
1. What Changed: 2011 vs 2025 Draft - Side-by-Side Comparison
- The 2011 version of Annex 11 was 5 pages covering 17 numbered sections. The 2025 draft is 19 pages covering 24 sections – 7 of which are entirely new. (EMA; European Commission June 2025)
- The 14-year gap between revisions is the longest in any major EU GMP annexe. In that period, pharmaceutical IT infrastructure moved from predominantly on-premise to predominantly cloud-hosted, and AI began entering GMP-relevant applications including process analytical technology and quality decision support. (EMA)
- The companion Annex 22, published alongside the Annex 11 draft, creates the first EU GMP-specific framework for AI and machine learning systems in pharmaceutical manufacturing and quality. (EMA June 2025)
2. GMP Inspection Data: Why This Revision Is Overdue
- More than 70% of critical GMP inspection findings in 2024 were directly related to computerised systems, with data integrity, audit trail management, and access control as the most frequently cited categories. (Zamann Pharma Analysis 2024)
- Data integrity deficiencies – including audit trails that exist but are not regularly reviewed, backdated entries, and electronic records that do not meet ALCOA principles – have been the leading cause of FDA Warning Letters and EMA non-compliance statements for the past decade. (FDA Warning Letter Database; EMA Inspection Reports)
- Access control deficiencies most commonly cited include shared login credentials, administrator accounts used for routine GMP operations, and failure to remove access for departed employees on a timely basis. All three are addressed explicitly in the 2025 Annex 11 draft. (EMA; FDA 21 CFR Part 11)
- Computerised system validation gaps frequently involve legacy systems validated under older methodologies that do not meet current GAMP 5 (second edition, 2022) expectations for risk-based validation and ongoing system lifecycle management. (ISPE GAMP 5 Second Edition 2022)
3. Cybersecurity: The Most Significant New Requirement
- The 2011 Annex 11 contained no mention of cybersecurity. The 2025 draft introduces cybersecurity as a first-class GMP requirement – the first time it has appeared in the core EU GMP computerised systems document. (EMA Annex 11 2025 Draft)
- Pharmaceutical sector ransomware attacks increased significantly in the 2020s. The 2021 attack on Ireland’s Health Service Executive – one of the largest healthcare ransomware incidents – disrupted pharmaceutical supply chains and highlighted the GMP integrity consequences of cybersecurity failures. (HSE Cyber Attack Report 2021)
- A cybersecurity incident affecting a GMP system creates a data integrity assessment obligation – the manufacturer must determine whether GMP records were compromised, altered, or destroyed during the incident, and must document that assessment as a deviation. (EMA Data Integrity Guidance; 2025 Annex 11 Draft)
- The cybersecurity risk assessment required by the draft must categorise GMP systems by their impact on product quality and patient safety – not solely by IT risk criteria. A system that controls critical process parameters or holds batch release records carries a higher GMP cybersecurity risk rating than a system used for internal reporting. (EMA Annex 11 Draft 2025)
- EMA inspectors are expected to assess cybersecurity controls as part of GMP inspections from the effective date of the final rule. Manufacturers who have not integrated cybersecurity into their computerised system validation and change control programmes will face inspection findings in this area. (EMA Inspection Expectations)
4. Cloud and SaaS Systems: Explicit Scope and Vendor Obligations
- The 2025 draft explicitly brings cloud-hosted and SaaS systems into Annex 11 scope – a question that the 2011 version left unanswered, creating significant ambiguity for the decade-plus in which pharmaceutical companies moved quality and manufacturing systems to cloud platforms. (EMA Annex 11 Draft 2025)
- The draft confirms that validation responsibility remains with the pharmaceutical manufacturer, not the cloud vendor, regardless of whether the system is hosted on-premise or in a cloud environment. The vendor’s IQOQ documentation and SOC 2 reports are inputs to, not substitutes for, the manufacturer’s validation. (EMA Annex 11 Draft 2025)
- Quality Technical Agreements (QTAs) with cloud and SaaS vendors must now explicitly address Annex 11 requirements – including audit trail availability, data backup and recovery, change notification procedures, and the vendor’s obligation to provide access to system records for regulatory inspections. (EMA Annex 11 Draft; EU GMP Chapter 7)
- The draft requires manufacturers to assess data sovereignty and residency for cloud-hosted GMP systems – specifically whether the data storage location creates regulatory access issues or conflicts with EU data protection requirements. (EMA Annex 11 Draft 2025)
- Approximately 60-70% of pharmaceutical quality management systems are now cloud-hosted or SaaS-delivered, based on industry surveys. The explicit cloud scope in the 2025 draft affects the majority of manufacturers’ current system landscapes. (ISPE/PDA Industry Survey 2023)
- The draft’s cloud provisions align with FDA’s 2023 Computer Software Assurance guidance, which also addressed cloud and SaaS systems and similarly confirmed that manufacturers cannot delegate validation responsibility to vendors. (FDA CSA Guidance 2023)
5. AI and Machine Learning: Annex 22 as Companion Framework
- Annex 22 – a new EU GMP annexe with no predecessor – was published alongside the Annex 11 draft in June 2025. It provides the first dedicated EU GMP framework for AI and ML systems in pharmaceutical manufacturing. (EMA June 2025)
- The key principle of Annex 22 is that AI systems must be validated for their specific intended purpose in the GMP context, with ongoing performance monitoring throughout the operational lifecycle – not validated once and assumed to remain valid. (EMA Annex 22 Draft 2025)
- Model drift – the gradual degradation in AI model performance as real-world data diverges from training data – is identified as a primary GMP risk in Annex 22. Manufacturers must define metrics for detecting drift and establish thresholds that trigger revalidation or human override. (EMA Annex 22 Draft 2025)
- Annex 22 explicitly requires human oversight for AI-assisted decisions in safety-critical GMP processes. Fully automated AI decisions affecting batch release, critical process parameters, or product quality specifications are not currently envisaged as compliant without human review. (EMA Annex 22 Draft 2025)
6. Data Integrity: ALCOA++ and Audit Trail Review Requirements
- The 2025 draft formalises ALCOA++ as the required data integrity framework for all electronic GMP records. The four additions to original ALCOA – Complete, Consistent, Enduring, and Available – have been used in EMA data integrity guidance since 2016 but are now written into Annex 11 itself. (EMA Annex 11 Draft 2025; EMA Data Integrity Guidance 2016)
- The Enduring attribute requires that electronic records be retained in a format that remains readable throughout the retention period, including after system upgrades, software version changes, or vendor discontinuation – a requirement that has significant implications for legacy system archiving. (EMA Annex 11 Draft 2025)
- The draft introduces a specific requirement that audit trails must be reviewed regularly, not merely available. Review frequency must be documented, risk-based, and evidence of review must be retained. An audit trail that exists but is never reviewed does not satisfy the 2025 draft requirement. (EMA Annex 11 Draft 2025)
- The Available attribute requires that GMP records be accessible to regulatory authorities on request within a reasonable timeframe. Cloud-hosted records that require vendor cooperation to access, or records held in formats requiring proprietary software that is no longer available, potentially fail this requirement. (EMA Annex 11 Draft 2025)
7. Senior Management Accountability: What the Draft Explicitly Requires
- The 2025 draft introduces explicit senior management accountability for GMP computerised system compliance – a requirement that was implied by the broader EU GMP framework in 2011 but not stated in Annex 11 itself. (EMA Annex 11 Draft 2025)
- Senior management must ensure that adequate resources – personnel, infrastructure, and budget – are allocated to computerised system validation, data integrity programmes, and cybersecurity controls. Resource adequacy is now an inspectable Annex 11 element. (EMA Annex 11 Draft 2025)
- The accountability cannot be fully delegated to IT or Quality teams. Senior management must demonstrate awareness of the computerised system landscape at their site and the significant risks to GMP compliance – particularly for cloud-hosted systems and high-risk GMP applications. (EMA Annex 11 Draft 2025)
- In practice, this requirement means that inspection responses to Annex 11 findings will need to demonstrate senior management engagement, not only technical remediation. Root cause analyses that identify resource constraints as a contributing factor to computerised system deficiencies now carry regulatory risk at the management level. (EMA Inspection Practice)
- EMA inspections have increasingly cited management review inadequacy as a contributing factor in quality system failures over the past five years. The explicit senior management accountability clause in the 2025 draft formalises this inspection practice. (EMA Annual Report on Inspections)
8. Timeline and Implementation: What Manufacturers Need to Plan For
- Manufacturers who wait for the final rule before beginning gap assessment are likely to face a compressed implementation timeline. Cybersecurity programme development, cloud vendor QTA updates, and audit trail review procedure implementation each require 6-12 months at minimum. (Industry Implementation Benchmarks)
- The consultation period closing October 2025 provides an opportunity for industry to submit comments on provisions that are ambiguous or operationally challenging. EMA consultation responses historically influence the final text of annexe revisions. (European Commission Consultation Process)
- GAMP 5 Second Edition (2022) already incorporates most of the risk-based validation principles formalised in the 2025 Annex 11 draft. Manufacturers who have updated their validation programmes to GAMP 5 Second Edition will require fewer structural changes than those still operating under GAMP 5 First Edition (2008) frameworks. (ISPE GAMP 5 Second Edition 2022)
- The highest-priority gap assessments are for cloud-hosted GMP systems without current QTAs addressing Annex 11 requirements, systems with audit trails that are generated but not reviewed, and GMP environments without documented cybersecurity risk assessments. These are the three areas most likely to generate immediate inspection findings. (EMA Inspection Practice; 2025 Draft)
Key Takeaways for Pharmaceutical QA and IT Compliance Teams
Sources
Regulatory Documents
- European Commission: EudraLex Volume 4 – EU GMP Guidelines (Annex 11 current and draft)
- EMA: Good Manufacturing Practice Annexes (Annex 11 and Annex 22 Draft 2025)
- EMA: Current Annex 11 (2011 version) for comparison
Industry and Research Sources
- ISPE: GAMP 5 Second Edition (2022) – Risk-Based Approach to Compliant GxP Computerized Systems
- Zamann Pharma: Critical GMP Inspection Findings Analysis 2024 (70% computerised systems figure)
- FDA: Computer Software Assurance (CSA) Guidance 2023 (cloud/SaaS parallel)
- WHO: Data Integrity and Compliance With GMP Guidelines (ALCOA++ framework reference)


