Annex 11 checklist for a cannabis ERP
Which version applies
The Annex 11 in force is the revision published in EudraLex Volume 4 in January 2011, which came into operation on 30 June 2011. In 2025 the European Commission consulted stakeholders on a revised Annex 11, a revised Chapter 4 on documentation and a new Annex 22 on artificial intelligence; at the time of writing the 2011 text is still the one listed in EudraLex Volume 4. Check the Commission's page before an inspection, because a new version will change what inspectors ask for.
The principle of the annex is short. The application should be validated and the IT infrastructure qualified. Where a computerised system replaces a manual operation, there should be no decrease in product quality, process control or quality assurance, and no increase in the overall risk of the process.
When your ERP is in scope
Annex 11 applies to all forms of computerised systems used as part of GMP-regulated activities. For a licensed medical cannabis operator that usually includes the ERP: it holds the executed batch record, the stock status of each lot (quarantine or released), QC results against specifications and, in many cases, the QP's certification. EU-GMP Annex 16 (section 4.2) accepts validated computerised systems as the safeguard that stops uncertified batches reaching saleable stock, which only works if the system itself meets Annex 11. Chapter 4 adds that for electronic records the regulated user must define which data are raw data, at least all data on which quality decisions are based.
The checklist, clause by clause
Each row gives the Annex 11 section, what an inspector will look for, what 365Phyta supports according to this website, and what stays with you. Where this site does not describe a function, the row says so rather than guessing: cover those points in your supplier assessment and your qualification tests.
| Annex 11 section | What the inspector looks for | What 365Phyta supports | What stays with you |
|---|---|---|---|
| 1 Risk management | A documented risk assessment behind the extent of validation and the data-integrity controls. | Not a software function. | Your risk assessment of the system and its GMP impact. |
| 2 Personnel | Defined roles for process owner, system owner, QPs and IT, with access matched to duties. | Role-based access. | Role definitions, qualifications and training records. |
| 3 Suppliers and service providers | Formal agreements with suppliers and service providers, a risk-based decision on auditing them, and supplied documentation reviewed against user requirements. | Qualification documentation (IQ/OQ scripts and a requirements traceability matrix) for your review. | The agreements, the supplier assessment or audit, and the documentation review. |
| 4 Validation | Life-cycle validation records, a system inventory and description, user requirements traceable through the life cycle, tests covering limits and error handling, and checks that migrated data are unchanged. | IQ/OQ scripts and a traceability matrix from functions to tests, updated for each major version. | User requirements, risk assessment, performance qualification, migration checks and the validation report. |
| 5 Data | Built-in checks on data exchanged electronically with other systems. | Not described on this site. | Interface specifications and tests. |
| 6 Accuracy checks | A second check of critical data entered manually, by a second person or validated electronic means. | Not described on this site. | Deciding which data are critical and how they are checked. |
| 7 Data storage | Data protected against damage, readable throughout the retention period, with regular back-ups whose restore is checked. | Not described on this site. | Confirming back-up and restore arrangements and testing them in validation. |
| 8 Printouts | Clear printed copies; for batch-release records, printouts that show whether data changed after entry. | Not described on this site. | Verifying printouts in your OQ and PQ. |
| 9 Audit trails | A risk-based, system-generated record of GMP-relevant changes and deletions, with the reason documented, readable and regularly reviewed. | GMP-relevant events appended to an immutable event ledger with the user, date and time. | Regular audit-trail review and your reason-for-change procedure. |
| 10 Change and configuration management | Changes, including configuration, made only under a defined procedure. | Updated protocols and traceability matrix for each major version. | Your change control for configuration and upgrades. |
| 11 Periodic evaluation | Periodic confirmation that the system remains validated and GMP-compliant. | An annual computerised-system review report. | Performing and approving the review. |
| 12 Security | Access restricted to authorised people, grants and removals recorded, and the identity, date and time recorded for every entry, change, confirmation or deletion. | Role-based access; every entry and signature tied to a named user. | Access procedures and periodic access reviews. |
| 13 Incident management | All incidents reported and assessed, with root causes of critical incidents feeding corrective and preventive action. | Not a system-incident function; product CAPA records in Phyta GMP can hold root-cause actions. | Your incident procedure for the system itself. |
| 14 Electronic signature | Signatures with the same impact as handwritten ones, permanently linked to their record, with time and date. | Signatures linked to the signed record, showing who signed, when and with what meaning. | Your policy that electronic signatures are binding within the company. |
| 15 Batch release | Only Qualified Persons certify; the system identifies and records the certifying person; certification by electronic signature. | QP certification by electronic signature; release blocked while a deviation is open or a test is missing. | Assigning QP rights and keeping the certification register current. |
| 16 Business continuity | Documented, tested alternative arrangements if a system supporting critical processes breaks down. | Not described on this site. | A business continuity plan, tested. |
| 17 Archiving | Archived data checked for accessibility, readability and integrity, and retrieval tested before system changes. | Not described on this site. | An archiving procedure and retrieval tests. |
Evidence to have ready for the inspection
- A system inventory and description.Section 4.3 expects an up-to-date list of systems and their GMP functions and, for critical systems, a description of data flows, interfaces and security measures.
- User requirements traced to tests.Section 4.4 expects user requirements based on a documented risk assessment and traceable through the life cycle; a requirements traceability matrix shows the links.
- The supplier file.The agreement with your software supplier and implementation partner, your assessment or audit of them, and your review of the documentation they supplied (sections 3.1 to 3.4 and 4.5).
- The validation report, including PQ.IQ and OQ show the system is installed and works as specified; performance qualification in your environment shows it does what your process needs.
- Audit-trail review records.Section 9 expects audit trails to be reviewed regularly, so keep evidence of who reviewed what and when.
- Access records.Section 12.3 expects the creation, change and cancellation of access authorisations to be recorded; keep those records, and a periodic review of who holds QP rights, ready.
- The latest periodic evaluation.Section 11 lists what it should cover: functionality, deviations, incidents, upgrade history, performance, reliability, security and validation status.
- A tested continuity and archiving plan.Sections 16 and 17 expect the fallback and the retrieval of archived data to be documented and tested, not only written down.
What the vendor supplies and what you validate
Annex 11 places validation with the regulated company. Section 4.5 asks the regulated user to take reasonable steps to ensure the system was developed under an appropriate quality management system and to assess the supplier; section 3.3 asks for documentation supplied with commercial products to be reviewed against user requirements. The ISPE GAMP 5 guide, widely used for this work, scales the validation effort to risk.
For 365Phyta, the validation pack contains installation and operational qualification scripts, a requirements traceability matrix from functions to tests, and an annual computerised-system review report, with updated protocols and matrix for each major version. It is included with Processor and Integrated implementations for the first site; otherwise it is available for any site (€8–15k per additional site · €2k per major version). You provide the user requirements and risk assessment, performance qualification in your environment, SOPs and training, and the final validation report and release for use.
Where 365Phyta fits
365Phyta is designed to support Annex 11 alongside 21 CFR Part 11: role-based access, an immutable event ledger as the audit trail, electronic signatures that show who signed, when and with what meaning, and QP certification that is blocked while a deviation is open or a test is missing. See EU-GMP batch records, the data integrity section of the compliance page, the validation pack and 365Phyta for EU-GMP processors.
FAQ
Does Annex 11 apply to an ERP system?
Yes, when the ERP is used as part of GMP-regulated activities, for example to hold batch records, QC results, stock status or QP certification. Annex 11 applies to all forms of computerised systems used in such activities.
Can a software vendor make us Annex 11 compliant?
No. The regulated company validates the system for its intended use and remains responsible for the clauses on risk management, suppliers, validation, incidents, business continuity and archiving. A vendor can build in controls such as audit trails, access control and electronic signatures, and supply qualification documentation.
What does Annex 11 require of electronic signatures?
Section 14 expects electronic signatures to have the same impact as handwritten signatures within the company, to be permanently linked to their record, and to include the time and date they were applied. Section 15 adds that only Qualified Persons may certify batch release, using an electronic signature.
Is Annex 11 being revised?
Yes. In 2025 the European Commission consulted stakeholders on a revised Annex 11, a revised Chapter 4 and a new Annex 22 on artificial intelligence. At the time of writing, the January 2011 version listed in EudraLex Volume 4 is the one in force.
Sources
- EudraLex Volume 4, Annex 11: Computerised Systems (revision January 2011, in operation since 30 June 2011).
- European Commission, stakeholders' consultation on EudraLex Volume 4: Chapter 4, Annex 11 and new Annex 22.
- EudraLex Volume 4, EU-GMP Part I, Chapter 4: Documentation.
- EudraLex Volume 4, Annex 16: Certification by a Qualified Person and Batch Release.
- European Commission, EudraLex Volume 4 (Annex 15, qualification and validation).
- US FDA, 21 CFR Part 11: Electronic records; electronic signatures.
Walk the checklist in the system
In a 30-minute demo we show the audit trail, the access roles and a QP signature, and what the validation pack contains.