QMS & PQS Implementation · 4 min read
Computerised System Validation: Annex 11 and GAMP 5
How to validate computerised systems under EU GMP Annex 11 and GAMP 5: risk-based scope, the V-model lifecycle, data integrity and audit-trail review.
By Balasubramanian Ramaiah · 19 June 2026 · Updated 1 October 2026
Almost every modern quality failure has a computerised system somewhere behind it. A spreadsheet nobody validated, an audit trail nobody reviewed, a shared login nobody questioned. Computerised system validation is how you prove those systems are fit for their GxP purpose and keep your data trustworthy. This guide explains what EU GMP Annex 11 and GAMP 5 expect, and how to scope validation by risk rather than by reflex.
What is computerised system validation (CSV)?
Computerised system validation is documented evidence that a computerised system consistently performs its intended function, with controlled, accurate and secure data. It applies to any system that creates, processes or stores GxP data, from a laboratory instrument and its software to a manufacturing execution system, an eQMS or even a validated spreadsheet. The aim is confidence that the system is reliable and that the records it holds can be trusted.
What do Annex 11 and GAMP 5 require?
Two reference points govern the field. EU GMP Annex 11 is the regulation. GAMP 5 is the practical framework most companies use to meet it.
- EU GMP Annex 11 sets the regulatory expectations for computerised systems used in GMP, covering risk management, validation, data integrity, audit trails, access control, electronic signatures and supplier oversight.
- GAMP 5, the ISPE Good Automated Manufacturing Practice guide, gives a risk-based, lifecycle method for delivering and maintaining validated systems, scaling the effort to the system's risk and complexity.
- 21 CFR Part 11 is the parallel FDA regulation for electronic records and signatures, relevant if you supply the US market.
Annex 11 and data integrity are closely linked, which is why audit-trail review and access control feature heavily in our guide to a data integrity programme.
How does the GAMP 5 risk-based approach work?
GAMP 5 sorts software into categories so you do not validate a configured commercial tool as if you had built it from scratch. The category guides the rigour.
| GAMP category | Example | Validation effort |
|---|---|---|
| Category 1, infrastructure | Operating systems, databases | Qualified as infrastructure, not separately validated |
| Category 3, non-configured | Off-the-shelf software used as supplied | Lighter, focused on intended use |
| Category 4, configured | Configured LIMS, eQMS, MES | Moderate, covering the configuration |
| Category 5, custom | Bespoke or custom-coded software | Highest, full lifecycle with design review |
Effort follows risk and category, so your documentation is proportionate rather than uniform.
What does the CSV lifecycle look like?
Validation follows a V-model that pairs each specification with a matching test.
- User Requirements Specification (URS). What the system must do, written before selection.
- Functional and Design Specifications. How the system and its configuration meet the URS.
- Installation Qualification (IQ). Evidence the system is installed correctly.
- Operational Qualification (OQ). Evidence it functions across its operating range.
- Performance Qualification (PQ). Evidence it performs in the real process with real users.
- Traceability matrix. A thread linking each requirement to its test, so nothing is missed.
How does CSV protect data integrity?
A validated system is the foundation of trustworthy data. Validation confirms that records stay Attributable, Legible, Contemporaneous, Original and Accurate (ALCOA+), that audit trails capture changes, that access is unique and role-based, and that electronic signatures are controlled. A system that has never been validated cannot give you that assurance, which is why unvalidated spreadsheets holding GxP data are a frequent and avoidable finding. Reviewing the audit trail is part of routine use, as covered in our note on audit-trail review.
What are the most common CSV and Annex 11 findings?
Inspectors return to the same weak points. Address these before they do.
- GxP spreadsheets and standalone systems used without any validation.
- Audit trails switched off, or present but never reviewed.
- Shared or generic logins that break attributability.
- No supplier assessment for a critical software vendor.
- A URS that was written after the system was bought, if at all.
An independent GMP audit that examines your systems and audit trails end to end is the most reliable way to find these gaps early.
Key takeaways
- CSV is documented proof a GxP system works reliably and keeps data trustworthy.
- Annex 11 is the regulation, GAMP 5 is the risk-based method to meet it.
- Scale validation to the GAMP category and risk, not uniformly.
- Unvalidated spreadsheets and unreviewed audit trails are the findings most often raised.
If you need your computerised systems validated or audited against Annex 11 and GAMP 5, book a discovery call with a senior Qualified Person and GMP auditor.
Frequently asked questions
What is the difference between Annex 11 and GAMP 5?+
EU GMP Annex 11 is the regulation that sets the expectations for computerised systems used in GMP, covering validation, data integrity, audit trails and access control. GAMP 5 is the ISPE good-practice framework that gives a risk-based, lifecycle method for meeting those expectations. In short, Annex 11 says what is required and GAMP 5 shows a practical way to deliver it.
Do I need to validate a spreadsheet?+
If a spreadsheet creates, processes or stores GxP data, such as a calculation that supports batch release or a stability result, then yes, it needs validation proportionate to its risk. Unvalidated GxP spreadsheets are one of the most common inspection findings, because the calculations and data they hold cannot otherwise be trusted.
What are the GAMP 5 software categories?+
GAMP 5 groups software as Category 1 infrastructure, Category 3 non-configured off-the-shelf software, Category 4 configured products such as a LIMS or eQMS, and Category 5 custom or bespoke software. The category guides how much validation effort is appropriate, so a configured commercial tool is not validated as heavily as custom-coded software.
What does Annex 11 say about audit trails?+
Annex 11 expects GMP-relevant changes and deletions to be recorded in a secure, time-stamped audit trail, and it expects those audit trails to be reviewed. A system that can record an audit trail but where nobody reviews it is a frequent finding, because the control only works if the review actually happens.
Is CSV the same as data integrity?+
They are closely linked but not identical. Computerised system validation proves a system works reliably and is the foundation that makes trustworthy data possible. Data integrity is the broader discipline of keeping records ALCOA+ across their lifecycle, through access control, audit-trail review, and good practice, on top of a validated system.