Citations: EU GMP Annex 11

No citations match the current filters.
Risk Management
Mapping
Reference: 1. Risk Management
Risk management should be applied throughout the lifecycle of the computerised system taking into account patient safety, data integrity and product quality. As part of a risk management system, decisions on the extent of validation and data integrity controls should be based on a justified and docu
Validation Approach
Mapping
Reference: 1. Risk Management
As part of a risk management system, decisions on the extent of validation and data integrity controls should be based on a justified and documented risk assessment of the computerised system.
Change Management
Mapping
Reference: 10. Change and Configuration Management
Any changes to a computerised system including system configurations should only be made in a controlled manner in accordance with a defined procedure.
Periodic Review
Mapping
Reference: 11. Periodic Evaluation
Computerised systems should be periodically evaluated to confirm that they remain in a valid state and are compliant with GMP. Such evaluations should include, where appropriate, the current range of functionality, deviation records, incidents, problems, upgrade history, performance, reliability, se
System Authorization
Mapping
Reference: 12.1 Security
Physical and/or logical controls should be in place to restrict access to computerised system to authorised persons. Suitable methods of preventing unauthorised entry to the system may include the use of keys, pass cards, personal codes with passwords, biometrics, restricted access to computer equip
Security Controls
Mapping
Reference: 12.2 Security
The extent of security controls depends on the criticality of the computerised system.
Access Management
Mapping
Reference: 12.3 Security
Creation, change, and cancellation of access authorisations should be recorded.
Audit Trail
Mapping
Reference: 12.4 Security
Management systems for data and for documents should be designed to record the identity of operators entering, changing, confirming or deleting data including date and time.
Incident Management
Mapping
Reference: 13. Incident Management
All incidents, not only system failures and data errors, should be reported and assessed. The root cause of a critical incident should be identified and should form the basis of corrective and preventive actions.
Electronic Signature
Mapping
Reference: 14. Electronic Signature
Electronic records may be signed electronically. Electronic signatures are expected to: a. have the same impact as hand-written signatures within the boundaries of the company, b. be permanently linked to their respective record, c. include the time and date that they were applied.
Electronic Signature (Qualifiied Person)
Mapping
Reference: 15. Batch Release
When a computerised system is used for recording certification and batch release, the system should allow only Qualified Persons to certify the release of the batches and it should clearly identify and record the person releasing or certifying the batches. This should be performed using an electroni
Business Continuity
Mapping
Reference: 16. Business Continuity
For the availability of computerised systems supporting critical processes, provisions should be made to ensure continuity of support for those processes in the event of a system breakdown (e.g. a manual or alternative system). The time required to bring the alternative arrangements into use should
Archiving
Mapping
Reference: 17. Archiving
Data may be archived. This data should be checked for accessibility, readability and integrity. If relevant changes are to be made to the system (e.g. computer equipment or programs), then the ability to retrieve the data should be ensured and tested.
Roles and Responsibilties
Mapping
Reference: 2. Personnel
All personnel should have appropriate qualifications, level of access and defined responsibilities to carry out their assigned duties.
Training of Personnel
Mapping
Reference: 2. Personnel
There should be close cooperation between all relevant personnel such as Process Owner, System Owner, Qualified Persons and IT.
IT Supplier Audit Reports
Mapping
Reference: 3. Suppliers and Service Providers
Quality system and audit information relating to suppliers or developers of software and implemented systems should be made available to inspectors on request.
IT Supplier Audits
Mapping
Reference: 3. Suppliers and Service Providers
The competence and reliability of a supplier are key factors when selecting a product or service provider. The need for an audit should be based on a risk assessment.
Quality Agreements with IT Supplier
Mapping
Reference: 3. Suppliers and Service Providers
When third parties (e.g. suppliers, service providers) are used e.g. to provide, install, configure, integrate, validate, maintain (e.g. via remote access), modify or retain a computerised system or related service or for data processing, formal agreements must exist between the manufacturer and any
Vendor Documentation
Mapping
Reference: 3. Suppliers and Service Providers
Documentation supplied with commercial off-the-shelf products should be reviewed by regulated users to check that user requirements are fulfilled.
Validation Documentation (Planning and Reporting)
Mapping
Reference: 4.1 Validation
The validation documentation and reports should cover the relevant steps of the life cycle. Manufacturers should be able to justify their standards, protocols, acceptance criteria, procedures and records based on their risk assessment.
Validation Documentation (Change control and Deviations)
Mapping
Reference: 4.2 Validation
Validation documentation should include change control records (if applicable) and reports on any deviations observed during the validation process.
CS Inventory
Mapping
Reference: 4.3 Validation
An up to date listing of all relevant systems and their GMP functionality (inventory) should be available.
System Description
Mapping
Reference: 4.3 Validation
For critical systems an up to date system description detailing the physical and logical arrangements, data flows and interfaces with other systems or processes, any hardware and software pre-requisites, and security measures should be available.
Traceability
Mapping
Reference: 4.4 Validation
User requirements should be traceable throughout the life-cycle.
User requirement specifications
Mapping
Reference: 4.4 Validation
User Requirements Specifications should describe the required functions of the computerised system and be based on documented risk assessment and GMP impact
Quality Management System (in house)
Mapping
Reference: 4.5 Validation
The regulated user should take all reasonable steps, to ensure that the system has been developed in accordance with an appropriate quality management system.
Quality Management System (supplier)
Mapping
Reference: 4.5 Validation
The regulated user should take all reasonable steps, to ensure that the system has been developed in accordance with an appropriate quality management system. The supplier should be assessed appropriately.
System Performance
Mapping
Reference: 4.6 Validation
For the validation of bespoke or customised computerised systems there should be a process in place that ensures the formal assessment and reporting of quality and performance measures for all the life-cycle stages of the system.
Qualified Test Environment
Mapping
Reference: 4.7 Validation
Automated testing tools and test environments should have documented assessments for their adequacy.
Test Evidences
Mapping
Reference: 4.7 Validation
Evidence of appropriate test methods and test scenarios should be demonstrated. Particularly, system (process) parameter limits, data limits and error handling should be considered.
Testing Tools Validation
Mapping
Reference: 4.7 Validation
Automated testing tools and test environments should have documented assessments for their adequacy.
Electronic Records (Data Integrity)
Mapping
Reference: 4.8 Validation
If data are transferred to another data format or system, validation should include checks that data are not altered in value and/or meaning during this migration process.
Electronic Records (Data Review)
Mapping
Reference: 6. Accuracy checks
For critical data entered manually, there should be an additional check on the accuracy of the data. This check may be done by a second operator or by validated electronic means. The criticality and the potential consequences of erroneous or incorrectly entered data to a system should be covered by
Electronic Records (Security and Access Management)
Mapping
Reference: 7.1 Data Storage
Data should be secured by both physical and electronic means against damage. Stored data should be checked for accessibility, readability and accuracy. Access to data should be ensured throughout the retention period.
Backup and Restore
Mapping
Reference: 7.2 Data Storage
Regular back-ups of all relevant data should be done. Integrity and accuracy of backup data and the ability to restore the data should be checked during validation and monitored periodically.
Electronic Records (Data availbility in human readable format)
Mapping
Reference: 8.1 Printouts
It should be possible to obtain clear printed copies of electronically stored data.
Electronic Records (Audit trail in human readable format)
Mapping
Reference: 8.2 Printouts
For records supporting batch release it should be possible to generate printouts indicating if any of the data has been changed since the original entry.
Electronic Records (Audit trail)
Mapping
Reference: 9. Audit Trails
Consideration should be given, based on a risk assessment, to building into the system the creation of a record of all GMP-relevant changes and deletions (a system generated "audit trail"). For change or deletion of GMP-relevant data the reason should be documented. Audit trails need to be available
Infrastructure Qualification
Mapping
Reference: Principle
The application should be validated; IT infrastructure should be qualified.
Validation
Mapping
Reference: Principle
This annex applies to all forms of computerised systems used as part of a GMP regulated activities. A computerised system is a set of software and hardware components which together fulfill certain functionalities. The application should be validated; IT infrastructure should be qualified. Where a
Graph Explorer