V5 Ultimate
EU GMP Annex 11 · EMA · MHRA · GAMP 5

EU Annex 11 software — computerised systems that pass an EMA inspection.

Annex 11 is Europe's Part 11 — plus risk-based validation, formal supplier assessment, periodic review, and incident management. V5 ships every Annex 11 control in the platform, including the supplier audit pack EMA and MHRA inspectors ask for on day one.

The problem

What breaks without this.

Part 11 alone doesn't satisfy an EMA inspection

Annex 11 adds supplier assessment, risk-based validation, periodic review, incident management and explicit business-continuity expectations. US-only vendors often can't produce the evidence.

The supplier audit pack is what fails first

Annex 11 §3 makes you formally assess the software supplier. Without a vendor-supplied audit pack (validation evidence, dev lifecycle, security, change control), the buyer has to audit you on-site — and that turns into a months-long blocker.

Periodic review is not a one-time activity

Annex 11 §11 requires periodic review of the computerised system — risk, security, user access, audit trail integrity. Spreadsheet-based reviews fail under scrutiny.

Bilingual / multi-region operations multiply the burden

EU-headquartered manufacturers with US sites (or vice versa) need one platform that satisfies both regimes simultaneously, without parallel evidence systems.

How V5 solves it

Records-by-execution. Compliance, by design.

01

Risk-based validation aligned to GAMP 5

V5 is categorised as a GAMP 5 Category 4 configured product, with a vendor validation package (IQ/OQ/PQ, traceability, FRA / FMEA) you map to your URS — exactly what Annex 11 §4 expects.

02

Supplier audit pack on demand

A pre-built Annex 11 §3 supplier-assessment pack: SDLC evidence, code-review and test policy, security controls, incident response, change-control records, sub-processor list. Hand it to QA on day one.

03

Audit trail you can actually review

Annex 11 §9 demands the audit trail be reviewed, not just captured. V5 surfaces audit-trail review queues — GMP-relevant changes flagged for QA, signed off as part of batch release.

04

Periodic review queue

Annex 11 §11 periodic review is a scheduled workflow in V5 — user access, role drift, security events, audit-trail anomalies, incident summary — produced as a signed periodic-review report.

05

Incident & business continuity covered

Annex 11 §13 and §16 incident management, BCDR plans, RTO/RPO targets and DR test evidence are produced from the live system, not maintained on the side.

Buyer's guide

What to look for when you're buying.

Annex 11 (revision under consultation) tightens data-integrity, AI and third-party clauses. Criteria below are what to check.

Data-integrity by architecture

What it tests: Are ALCOA+ properties structural, not procedural?

Why it matters: Procedural DI drifts.

V5: Append-only, attributable, contemporaneous by design.

Third-party clause coverage

What it tests: Are vendor obligations documented per §4?

Why it matters: Regulators audit the vendor chain.

V5: Vendor QMS documented; SDLC evidence shared under MSA.

Data lifecycle

What it tests: Is data lifecycle (create → archive → destroy) governed and evidenced?

Why it matters: New §17-style expectations demand it.

V5: Lifecycle policies configurable and enforced.

AI/ML transparency

What it tests: Where AI is used, is training data, versioning and human oversight documented?

Why it matters: Draft-Annex-11 AI expectations.

V5: Model versioning, training data provenance and human-in-loop gates documented in-system.

Periodic review

What it tests: Is periodic review of the computerised system supported and evidenced?

Why it matters: §11 requires it.

V5: Periodic review is a first-class record type.

Compared

Spreadsheet vs legacy QMS vs V5.

Annex 11 alignment.

CapabilitySpreadsheetLegacy QMSV5 Ultimate
ALCOA+ by architectureNoProceduralStructural
Third-party evidenceN/AOn requestUnder MSA, standing
AI transparencyN/ANoneDocumented
Periodic reviewN/AManualNative
Regulatory deep-dive

The clauses, verbatim — and how V5 answers each.

Key Annex 11 clauses and V5's answer.

Annex 11 §1
Risk management should be applied throughout the lifecycle of the computerised system...

V5: Risk assessment is a first-class artefact per system and per change.

Annex 11 §4
The regulated user should take all reasonable steps to ensure that the system has been developed in accordance with an appropriate quality management system.

V5: V5 SDLC shared under MSA; evidence per release.

Annex 11 §9
Consideration should be given, based on a risk assessment, to building into the system the creation of a record...

V5: Audit trail is native, unconditional, tamper-evident.

Annex 11 §11
Periodic evaluations of computerised systems should be conducted...

V5: Periodic review scheduled and enforced.

How it works in V5

Step by step on the floor.

Annex 11 delivered as architecture.

  1. 1
    Deploy

    Validation pack applied

    IQ/OQ/PQ delivered.

  2. 2
    Operate

    ALCOA+ enforced

    Structural DI at every write.

  3. 3
    Change

    Change control with validation delta

    Delta reviewed; no full re-do.

  4. 4
    Review

    Periodic review

    Native record type with cadence per risk tier.

ROI & cost of failure

The math, with the assumptions visible.

Annex 11 ROI is compliance risk reduction primarily.

DI-related findings

Before
Trending up EU-wide
With V5
Structurally reduced

Architecture removes the class.

Periodic review labour

Before
Manual
With V5
Derived

Live evidence.

Sites see the biggest ROI in avoided remediation projects.

Customer scenario

What changed on the floor.

Setting

A multi-site EU sterile manufacturer.

Before

Two consecutive Annex 11 inspections cited DI gaps in the legacy QMS.

After

Post-cutover: DI findings closed; periodic review runs as scheduled record type.

What you get

Proof points

  • GAMP 5 Category 4 configured product — vendor validation package included
  • Annex 11 §3 supplier-assessment pack ready for buyer QA
  • Audit-trail review queue with GMP-relevance flagging
  • Scheduled Annex 11 §11 periodic review with signed report
  • Dual Part 11 + Annex 11 e-signature semantics for global sites
  • MHRA-style data integrity (ALCOA+) controls applied by default
Regulatory anchors

Built to satisfy

  • EU GMP Annex 11 (Computerised systems)
  • EU GMP Annex 15 (Qualification & validation)
  • EU GMP Annex 16 (QP certification & batch release)
  • 21 CFR Part 11 (parallel US regime)
  • MHRA GxP Data Integrity Guidance
  • GAMP 5 (validation lifecycle)

Frequently asked questions

How is Annex 11 different from 21 CFR Part 11?+

Annex 11 is broader. Part 11 is about electronic records and signatures. Annex 11 adds risk-based validation, formal supplier assessment (§3), periodic review (§11), explicit incident management (§13) and business continuity (§16). A Part-11-only system is necessary but not sufficient for EMA inspection.

Do you provide a supplier-assessment pack?+

Yes — a pre-built Annex 11 §3 audit pack covering SDLC, code-review and test policy, security controls, incident response, sub-processor list and change-control records. Buyers' QA teams use it directly without on-site supplier audit in most cases.

How does V5 handle audit-trail review?+

Annex 11 §9 requires the audit trail to be reviewed, not just captured. V5 surfaces a review queue with GMP-relevance flagging and ties review sign-off to batch release — so the trail is actually inspected before product moves.

Can the same V5 tenant satisfy both Annex 11 and Part 11?+

Yes. E-signature semantics, audit-trail rules and validation evidence cover both regimes simultaneously. Global manufacturers run one platform across EU and US sites without parallel evidence systems.

See V5 on your own line.

Free trial, no card. Live in 7 days with guided onboarding.