Insights
Annex 11 revision and Annex 22: what is actually in the drafts
What the 2025 consultation drafts of EU GMP Annex 11 and the new Annex 22 change for computerized systems and AI in GMP, what stays in force, and what a QA team can prepare now.
Status check, 2026-09-05: the drafts of Chapter 4, Annex 11 and Annex 22 went to public consultation from 7 July to 7 October 2025. None has been adopted. The 2011 Annex 11 remains the binding text.
The problem
Most QA teams have heard that Annex 11 is changing and that an AI annex is coming. Fewer have read the drafts, and the summaries circulating in vendor decks tend to present direction as requirement. The result is two failure modes: teams that re-validate against a draft, and teams that ignore the draft until it lands.
The risk
Re-validating to a draft wastes budget and creates records that cite a non-existent requirement, which an inspector will notice. Ignoring the draft means the gap list is written for you, on inspection day, against a text you could have read a year earlier.
What the Annex 11 draft changes
The 2011 text is five pages and seventeen clauses. The draft is seventeen sections, and several of them are new as standalone topics: alarms (§8), identity and access management (§11), and security (§15). Four changes matter most for an existing validated estate.
Audit trail review gets specific. The 2011 §9 says audit trails should be regularly reviewed. The draft (§12.5 to §12.8) expects review by personnel not directly involved in the activity, targeted rather than exhaustive review, and review before batch release unless a later detection risk is justified. If your review SOP today says "quarterly, by the system owner," that is the first line to revisit.
Periodic review becomes a section, not a paragraph. Draft §14 lists twelve items a periodic review should cover, including detection of undocumented changes, follow-up on audit trail and access reviews, and adequacy of backup and archiving, with a final review when a system is retired.
Suppliers and cloud get their own section. Draft §7 expects service agreements with KPIs, risk-based audit or assessment, and contracts that cover exit and data control. The regulated user stays fully responsible.
Data integrity is named as ALCOA+. The 2011 text never uses the term. Draft §2.4 does. Electronic signatures (§13) also tighten: full re-authentication at signing, and no signing that relies only on the earlier system login.
AI is deliberately absent from the Annex 11 draft. It is carved into Annex 22.
What the Annex 22 draft asks for
The scope is narrow on purpose. It covers static, deterministic models used in critical GMP applications with direct impact on patient safety, product quality or data integrity. Continuously learning models and probabilistic-output models are excluded from critical use, and generative AI and large language models are explicitly out of scope for critical GMP applications.
Inside that scope, the draft expects: a documented intended use with an input sample space covering common and rare variations, approved by subject-matter experts before testing (§3); acceptance criteria defined per subgroup and at least as high as the process the model replaces (§4); test data independence, so the people who train a model never see the test set, or work under a four-eyes rule if unavoidable (§6); explainability through feature attribution reviewed as part of test approval (§8); and, where a human decides on the model's output, monitoring of that human's performance like any other manual process (§3.3, §10.5). Model documentation must be reviewed by the regulated user whether the model was built in-house or supplied (§2.2).
What to prepare now
Do not re-validate. Do three things that are cheap now and expensive later: map each system's current audit trail review and periodic review against draft §12 and §14 so the gap list exists before the final text does; inventory every supplier and cloud service against draft §7 and check that the contract covers exit and data control; and, for any AI already in use, write down its intended use, its acceptance criteria, and who decides on its output. Those three documents are useful under the 2011 text today and will be the first three an inspector asks for under the new one.
Want this applied to your systems?
Book a discovery call. We will map where manual review is costing you the most, and whether CSV/CSA, AI governance, or an AI tool assessment is the right place to start.