How do life sciences companies validate computerised systems in a GMP-compliant manner under GAMP 5 and EU GMP Annex 11?
We support pharma, biotech, MedTech and IVD companies in validating computerised systems under GAMP 5 and EU GMP Annex 11 - from system classification and the validation plan through URS, IQ, OQ and PQ to the validation report and lifecycle maintenance. The critical fork is rarely the testing itself, but the risk classification at the outset: validating a standard system as if it were a custom-developed one burns effort that is then missing elsewhere for data integrity.
- Pharma
- Biotech
- MedTech
- IVD
Overview
What do Annex 11 and 21 CFR Part 11 require of computerised systems?
CSV across all industries · GAMP 5, EU GMP Annex 11, FDA 21 CFR Part 11
Last updated: 2026-06-13
The EU GMP Guide Annex 11 and FDA 21 CFR Part 11 require every GMP-relevant IT system to be demonstrably fit for its intended use and to keep its data integral across the entire lifecycle. The points where CSV projects most often get stuck:
- Risk-based validation scope instead of a one-size-fits-all approach: GAMP 5 classifies systems from standard software to custom development; without this classification, either too much is tested or a critical system is under-validated - both an inspection finding.
- A complete, traceable validation package: URS, functional specification, traceability matrix, IQ, OQ and PQ must be seamlessly linked so that every requirement points to a test record - Annex 11 requires an end-to-end specification and testing chain.
- Data integrity according to ALCOA principles: audit trail, access control and electronic signatures under Annex 11 and 21 CFR Part 11 must be technically implemented and configured, not merely described in an SOP.
- Change control and revalidation in operation: software updates, operating system upgrades and configuration changes without an impact assessment invalidate the validated state - the validated state is a lifecycle, not a one-off project closure.
Services
How we support you
Risk-based validation strategy under GAMP 5
Classification of your systems into the GAMP 5 categories and derivation of the validation scope per system. Deliverable: a validation master plan with a justified risk and GxP-criticality assessment for each system.
Complete validation package from URS to PQ
Preparation of the user requirement specification, functional specification, traceability matrix as well as IQ, OQ and PQ protocols with test scripts. Deliverable: a validation dossier ready for inspection against Annex 11, including the validation report.
Data integrity & audit trail assessment
Review and implementation of the requirements for audit trail, access permissions and electronic signatures under Annex 11 and 21 CFR Part 11. Deliverable: a data integrity assessment with a gap list and concrete configuration measures.
Learn more →Change control & revalidation
Impact assessment for updates, upgrades and hardware changes, plus definition of the revalidation scope. Deliverable: an assessed change record with a decision on the extent of requalification and a documented rationale.
Learn more →CSV lifecycle & periodic review
Establishing the periodic system review, maintaining the validated state and preparing for inspections. Deliverable: a periodic review procedure with criteria that evidence the validated state across the system's lifetime.
How we work together
What it comes down to
Computer system validation is at its core a question of sequence, not of test volume. The EU GMP Guide Annex 11 and FDA 21 CFR Part 11 do not require maximum effort, but an effort that matches the risk of the system. That is why the GAMP 5 classification at the outset determines the whole project: a standard system essentially needs a supplier assessment and a PQ under real conditions, while a configured or bespoke system needs the full chain of URS, functional specification, traceability matrix, IQ, OQ and PQ. Skip this classification and you validate non-critical systems too deeply and GxP-critical ones too shallowly - and it is exactly this imbalance that an inspector finds first.
The second bottleneck comes after release. A validation report proves the state as at a cut-off date, not for the system's lifetime. Change control and periodic review keep the validated state in force: every update and every upgrade needs an impact assessment that defines the revalidation scope before it goes live. In parallel, data integrity must take hold technically in line with the ALCOA principles - an enabled, tamper-proof audit trail and role-based access control under Annex 11 and 21 CFR Part 11, not just as SOP text. Companies that plan for these two strands, lifecycle and data integrity, from the start shift the effort to where corrections are cheap, rather than into the inspection, where they become expensive.
Our approach
Our approach
Step
Result
System assessment & classification
System inventory with GxP criticality and GAMP 5 category per system, with the validation scope derived from it.
Validation plan
Validation plan with roles, acceptance criteria, risk assessment and test scope, aligned with QA.
Specification & qualification
URS, functional specification and traceability matrix as well as executed IQ, OQ and PQ protocols with documented results.
Validation report
Final report with an assessment of deviations, releasing the system for GMP use.
Lifecycle & change control
Periodic review, change control integration and revalidation logic established in ongoing operation.
Common pitfalls
Where projects commonly fail
Every system is validated to the same depth.
Standard software with no configuration receives the same test scope as a custom development under GAMP 5. The result is excessive effort on non-critical systems while GxP-critical systems are tested too sparingly - the most common finding from an incorrect risk classification.
The traceability matrix is missing or not end-to-end.
Annex 11 requires every requirement from the URS to be traceable through to a test record. If the linkage is reconstructed only at project close, requirements without test coverage surface and are treated as a gap in the audit.
The audit trail is assumed but not verified.
Many systems technically provide an audit trail, but it is switched off, not tamper-proof or configured in a way that is not reviewable. Annex 11 and 21 CFR Part 11 require an effective, enabled and regularly reviewed audit trail.
Software updates go in without an impact assessment.
A patch or operating system upgrade is applied without assessing the validated state. The validation status is thereby formally invalidated - an inspector spots this from a version discrepancy between the validation report and the production system.
Supplier documentation is adopted unchecked.
The software vendor's test documentation does not replace your own qualification. Without a supplier assessment and your own PQ under real process conditions, it remains open whether the system performs as intended in the specific use case.
FAQ
Frequently asked questions
Sources
- EU-GMP-Leitfaden Annex 11 (Computerised Systems) - primary text
- FDA 21 CFR Part 11 (Electronic Records; Electronic Signatures) - primary text
- GAMP 5 (ISPE Good Automated Manufacturing Practice, A Risk-Based Approach to Compliant GxP Computerized Systems)
- EMA Q&A: Good Manufacturing Practice - Data Integrity; PIC/S PI 041 (Data Management and Integrity)
- Entourage website writer source material - Computer System Validation expertise page
- https://theentourage.de/expertise/computer-system-validierung/ (existing page content, revised)
Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Case Studies
What this looks like in practice
Related insights
All insights →Regulations & standards considered
- EU-GMP-Leitfaden Annex 11 (Computerised Systems)
- FDA 21 CFR Part 11 (Electronic Records; Electronic Signatures)
- GAMP 5 (ISPE Good Automated Manufacturing Practice, A Risk-Based Approach to Compliant GxP Computerized Systems)
- EMA Q&A: Good Manufacturing Practice - Data Integrity
- PIC/S PI 041 (Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments)
Related topics
21 CFR Part 11 & Data Integrity →
Electronic records, audit trail and ALCOA in detail
Good Manufacturing Practice (GMP) →
GMP fundamentals within which CSV is embedded
Change Management →
Impact assessment and revalidation across the lifecycle
Process Validation →
Validation of manufacturing processes alongside system validation
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +49 89 4161170-0
info@theentourage.de
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences

