EU Annex 11 vs 21 CFR Part 11: What Software Must Do to Satisfy Both

Any laboratory software sold to, or used by, a company that supplies both the United States and the European Union has to satisfy two rulebooks for computerized systems. 21 CFR Part 11 is the FDA’s regulation on electronic records and electronic signatures. Annex 11 is the EU GMP guideline on computerized systems. They overlap heavily, they are not the same, and the differences decide what a software product must contain and what a regulated user must do around it. This article compares them section by section, explains where each is stricter, sets out what a single system built for both markets has to provide, and covers the draft revision of Annex 11 and the new Annex 22 on artificial intelligence that were published for consultation in 2025.

What each regulation governs

21 CFR Part 11 was issued by the FDA in 1997. It applies to records in electronic form that are created, modified, maintained, archived, retrieved or transmitted under any records requirement in FDA regulations, and to electronic signatures on those records. It is a regulation, with the force of law, and it is narrow by design: it says what makes an electronic record and an electronic signature trustworthy, and little else. Its structure is Subpart A (scope and definitions, including the distinction between closed and open systems), Subpart B (electronic records: §11.10 controls for closed systems, §11.30 for open systems, §11.50 signature manifestations, §11.70 signature and record linking) and Subpart C (electronic signatures: §11.100 general requirements, §11.200 components and controls, §11.300 controls for identification codes and passwords). FDA’s 2003 guidance on scope and application narrowed how the agency interprets and enforces it.

EU GMP Annex 11 is part of EudraLex Volume 4, the EU’s Good Manufacturing Practice guidelines, and applies to all forms of computerized systems used as part of GMP-regulated activities. The current version took effect in 2011. It is a guideline that interprets the legal requirements of the GMP directives, and inspectors treat it as the standard. It covers the whole system across its lifecycle in seventeen sections: risk management, personnel, suppliers and service providers, validation, data, accuracy checks, data storage, printouts, audit trails, change and configuration management, periodic evaluation, security, incident management, electronic signature, batch release, business continuity and archiving.

The shortest summary is that Part 11 tells you what a trustworthy record and signature look like, and Annex 11 tells you how to run a computerized system so that its records can be trusted.

Side-by-side comparison

Topic21 CFR Part 11EU Annex 11 (2011)
Legal statusFDA regulation; bindingEU GMP guideline interpreting the directives; applied by inspectors as the standard
ScopeElectronic records and electronic signatures under FDA records requirementsAll computerized systems used in GMP activities, across their lifecycle
Risk managementImplied; addressed by the 2003 guidanceExplicit: §1 requires risk management throughout the lifecycle
PersonnelTraining implied (§11.10(i))§2 requires cooperation between process owners, system owners, QA and IT, with appropriate training
SuppliersNot addressed§3 requires supplier assessment, formal agreements, and allows supplier documentation to support validation
Validation§11.10(a): validation to ensure accuracy, reliability, consistent performance and detection of invalid or altered records§4: validation covering the lifecycle, with documentation, requirements, supplier assessment and test methods appropriate to risk
Access control§11.10(d) limited access; §11.10(g) authority checks; §11.300 passwords§12: physical and logical controls, individual access, recorded creation and change of authorizations
Audit trail§11.10(e): secure, computer-generated, time-stamped, independent of operator, retained with the record§9: system-generated record of GMP-relevant changes and deletions, based on risk; reason documented; available, intelligible and regularly reviewed
Electronic signaturesDetailed: §11.50 manifestations, §11.70 linking, §11.100 to §11.300 uniqueness, two components, password controls, certification to FDA§14: same impact as handwritten, permanently linked to the record, including time and date
Accurate copies§11.10(b): accurate and complete copies in human-readable and electronic form§8: clear printed copies; for records supporting batch release, printouts showing whether data were changed
Data accuracy checksNot explicit§6: built-in checks for critical data entered manually
Data storage and backup§11.10(c): protection for accurate and ready retrieval§7: protection from damage; accessibility, readability and accuracy checked; regular backups tested
Change and configuration management§11.10(k): change control for system documentation§10: all changes controlled, documented and, where appropriate, validated
Periodic evaluationNot addressed§11: systems periodically evaluated to confirm validated state
Incident managementNot addressed§13: incidents reported, assessed and their root cause identified
Business continuityNot addressed§16: provisions for continued support of critical processes on failure
ArchivingRetention implied by §11.10(c)§17: data checked for accessibility, readability and integrity; migration verified
Open systems§11.30: additional measures such as encryption and digital signaturesNot distinguished
Venn diagram of EU Annex 11 vs 21 CFR Part 11 showing shared controls and where each regulation goes further

Build signatures to Part 11, the lifecycle to Annex 11 and the audit trail to the union of both, and one system satisfies both markets.

Where Part 11 is more specific

Part 11 is far more prescriptive about electronic signatures and identity. It requires each signature to be unique to one individual and never reused or reassigned (§11.100(a)), requires the organization to verify the identity of the individual before establishing a signature (§11.100(b)), and requires a certification to the FDA that electronic signatures are intended to be the legally binding equivalent of handwritten ones (§11.100(c)). Signatures not based on biometrics must use at least two distinct identification components (§11.200(a)(1)), with both used at the first signing of a session and at least one thereafter, and must be usable only by their genuine owner. §11.300 adds password controls: uniqueness of the ID and password combination, periodic checking and revision, loss management procedures and safeguards against unauthorized use.

Part 11 is also specific about what a signature must show: the printed name of the signer, the date and time, and the meaning of the signature (§11.50), and that the signature must be linked to its record so that it cannot be excised, copied or transferred to falsify another record (§11.70).

Software built to Annex 11 alone can meet its §14 in ways that would not satisfy §11.200. A system for both markets therefore builds signatures to Part 11.

Where Annex 11 is broader

Annex 11 asks for things Part 11 never mentions. Supplier assessment (§3): the regulated user must assess the competence and reliability of a software supplier, formalize the relationship, and may audit it. Risk management (§1): applied throughout the lifecycle, and used to decide the extent of validation and data integrity controls. Periodic evaluation (§11): the system is reviewed at intervals to confirm it remains valid and compliant. Incident management (§13). Business continuity (§16). Accuracy checks on critical manually entered data (§6). Archiving with checks on migration (§17).

These are obligations on the regulated user rather than features of the software, but they shape what a software supplier must provide: documentation that can be assessed, a lifecycle that can be audited, support for periodic review, and an incident process. A supplier who has only ever been asked Part 11 questions will not have these ready. Our article on validating custom software lists what to ask for.

Validating custom software

Audit trails under both

Part 11 §11.10(e) requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions that create, modify or delete electronic records, without obscuring previously recorded information, and retained for at least as long as the record and available for review and copying.

Annex 11 §9 says that, based on a risk assessment, consideration should be given to building into the system a record of all GMP-relevant changes and deletions, that the reason for a change or deletion of GMP-relevant data should be documented, and that audit trails should be available, convertible to a generally intelligible form and regularly reviewed.

The union of the two is what software should provide: a system-generated trail that cannot be switched off by users, capturing who, what, when, old value, new value and reason, retained with the record, exportable in readable form, and reviewable. The reason-for-change field is an Annex 11 expectation that Part 11 does not state; the independence from operator action is a Part 11 expectation that Annex 11 does not state. Build both in. The draft Annex 11 revision expands audit trail requirements into ten subsections covering technical setup and timely review, which points where inspection practice is going.

Electronic signatures under both

Annex 11 §14 states that electronic records may be signed electronically and that the signature must have the same impact as a handwritten signature within the company, be permanently linked to its record, and include the time and date it was applied. Part 11 adds everything described above: uniqueness, identity verification, two components, session rules, name and meaning displayed, password controls, and certification to the FDA.

A system built to Part 11’s signature requirements satisfies Annex 11’s. The reverse is not true. In a software product this means a signing dialog that requires user ID and password at the point of signing, a signature record showing name, time, date and meaning, permanent binding to the record, and administrative controls over password lifecycle.

Validation and suppliers

Part 11 §11.10(a) requires validation but says nothing about how. Annex 11 §4 requires validation documentation and reports covering the relevant lifecycle steps, a justified change to the process based on risk, an inventory of systems, user requirements traceable through the lifecycle, an assessment of suppliers, and evidence of appropriate test methods and scenarios. Annex 11 also explicitly allows the regulated user to use documentation from a supplier who has been assessed.

For custom software this is the section that decides the cost. A developer who works to a documented lifecycle and can be assessed as a supplier lets the customer use the developer’s evidence; a developer who cannot leaves the customer to generate it. GAMP 5 second edition and the FDA’s 2025 computer software assurance guidance both support a risk-based, proportionate approach, and both markets accept it.

The 2025 draft revision of Annex 11, and Annex 22

On 7 July 2025 the European Commission opened a stakeholder consultation on a revised Chapter 4 (documentation), a revised Annex 11 and a new Annex 22 on artificial intelligence. The consultation closed on 7 October 2025, and final publication is expected from 2026. Until the final text is published the 2011 Annex 11 remains in force, but the draft shows the direction.

Area2011 Annex 112025 draft revision
Audit trailsOne section, risk-based, reason documented, regularly reviewedExpanded to ten subsections covering technical setup and timely review
IT securityOne section on physical and logical accessExpanded: firewalls, disaster recovery objectives, patching, malware protection, penetration testing for critical systems
Periodic reviewOne sentence on periodic evaluationA section of twelve subsections on review expectations
Suppliers and service providersAssessment and formal agreementsDetailed requirements for IT service providers: audit, contract and documentation, with nine contractual subsections
ArchivingBriefAligned with OECD GLP archiving expectations
ValidationLifecycle documentationLimited-scope use permitted before full validation if explicitly stated in the validation report
Access controlIndividual access; recorded authorizationsEmphasis on segregation of duties and limits of shared credentials
Artificial intelligenceNot addressedNew Annex 22: expectations for AI and machine learning in manufacturing, including model validation, training data quality and continuing oversight

The practical message for software buyers and builders is that audit trail review, security hardening, supplier documentation and periodic review will be asked about in more detail, and that AI components will have their own expectations. Software built now should be designed so that its audit trail can be reviewed efficiently, its security can be evidenced, and its supplier documentation is ready to hand over. Our GMP compliant software article lists the controls to expect.

GMP compliant software article

Building one system for both markets

The economical approach is to build to the stricter rule in each area, so that one design, one audit trail and one signature model satisfy both.

Signatures to Part 11: two components, session rules, name, date, time and meaning displayed, permanent linking, password lifecycle controls.

Audit trail to the union: system-generated, independent of the operator, cannot be disabled, records who, what, when, old and new values and reason, retained with the record, exportable and reviewable.

Lifecycle to Annex 11: documented risk management, requirements, supplier evidence, validation documentation, change control, periodic review, incident handling, backup and archiving, with the FDA’s risk-based assurance model used to size the testing.

Copies and printouts to both: complete, human-readable and electronic copies that show whether data were changed.

Security to the draft Annex 11: individual accounts, role-based permissions, directory integration, encryption, patch management and a way to evidence all of it.

TotalLab’s AuditSafe was built to this union. It provides audit trails, electronic signatures, granular user permissions and image authenticity verification that support FDA 21 CFR Part 11 and EU Annex 11, it runs inside TotalLab’s own analysis products and inside instrument software from OEM partners, and it has been through the regulatory departments of some of the largest pharmaceutical companies. For a manufacturer who needs a compliant edition of existing software, the OEM integration route adds those controls without a rebuild; for a new tool, the same components are designed in from the specification.

AuditSafe

OEM integration route

Frequently asked questions

Q: What is the difference between EU Annex 11 and 21 CFR Part 11?
A: 21 CFR Part 11 is a binding FDA regulation on electronic records and electronic signatures. Annex 11 is the EU GMP guideline on computerized systems and covers the whole system lifecycle: risk management, suppliers, validation, data, audit trails, security, change control, periodic review, incidents, business continuity and archiving. Part 11 is more specific about signatures; Annex 11 is broader in scope.

Q: Do I need to comply with both Annex 11 and Part 11?
A: If your products or records are subject to both FDA and EU GMP requirements, yes. Most companies supplying both markets build systems to satisfy both, taking the stricter rule in each area.

Q: Which is stricter, Annex 11 or Part 11?
A: Neither in general. Part 11 is stricter on electronic signatures and identity controls; Annex 11 is stricter on lifecycle management, supplier assessment, periodic review and incident handling.

Q: Is Annex 11 a law?
A: Annex 11 is a guideline within EudraLex Volume 4 that interprets the legal GMP requirements of the EU directives. Inspectors apply it as the standard, so in practice it is treated as mandatory for GMP computerized systems.

Q: What does Annex 11 require for audit trails?
A: Based on risk, a system-generated record of all GMP-relevant changes and deletions, with the reason documented, available in an intelligible form and regularly reviewed. The 2025 draft revision expands this considerably.

Q: What does Annex 11 say about electronic signatures?
A: That they must have the same impact as handwritten signatures within the company, be permanently linked to their record and include the time and date. Part 11’s signature requirements are more detailed and satisfy Annex 11 when met.

Q: What is changing in the 2025 Annex 11 revision?
A: The draft expands audit trail review, IT security, periodic review, supplier and IT service provider management and archiving, allows limited-scope use before full validation if stated in the validation report, and is accompanied by a new Annex 22 on artificial intelligence. Consultation closed on 7 October 2025 and final publication is expected from 2026.

Q: Can one software system satisfy both Annex 11 and Part 11?
A: Yes, by building signatures to Part 11, the audit trail to the union of both, and the lifecycle, supplier and review processes to Annex 11. That is how AuditSafe and TotalLab’s regulated software are designed.

References

1. U.S. Food and Drug Administration. 21 CFR Part 11, Electronic Records; Electronic Signatures. eCFR, current as of September 2026. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11
(Source for: §11.3 definitions; §11.10(a) to (k); §11.30; §11.50; §11.70; §11.100(a) to (c); §11.200(a); §11.300(a) to (e).)

2. U.S. Food and Drug Administration. Guidance for Industry: Part 11, Electronic Records; Electronic Signatures, Scope and Application. August 2003. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/part-11-electronic-records-electronic-signatures-scope-and-application
(Source for: the narrowed interpretation and enforcement discretion.)

3. European Commission. EudraLex Volume 4, Annex 11: Computerised Systems. Effective 30 June 2011. https://health.ec.europa.eu/medicinal-products/eudralex/eudralex-volume-4_en
(Source for: sections 1 to 17 as summarized in the comparison table, including §3 suppliers, §4 validation, §6 accuracy checks, §7 data storage, §8 printouts, §9 audit trails, §10 change management, §11 periodic evaluation, §12 security, §13 incident management, §14 electronic signature, §16 business continuity, §17 archiving.)

4. European Commission. Stakeholders consultation: EudraLex Volume 4, Chapter 4, Annex 11 and new Annex 22. 7 July to 7 October 2025. https://health.ec.europa.eu/consultations/stakeholders-consultation-eudralex-volume-4-good-manufacturing-practice-guidelines-chapter-4-annex_en
(Source for: the consultation dates and the scope of the three documents, including Annex 22 on AI.)

5. ECA Academy. Annex 11 Draft: First Analysis. 2025. https://www.gmp-compliance.org/gmp-news/annex-11-draft-first-analysis
(Source for: the draft’s expanded sections on audit trails, IT security, periodic review, suppliers, archiving, validation and access control, and expected publication from 2026.)

6. ISPE. GAMP 5 Second Edition. July 2022. https://ispe.org/publications/guidance-documents/gamp-5-guide-2nd-edition
(Source for: the risk-based lifecycle approach accepted in both markets.)

7. U.S. Food and Drug Administration. Computer Software Assurance for Production and Quality System Software. 24 September 2025. https://www.federalregister.gov/documents/2025/09/24/2025-18468/computer-software-assurance-for-production-and-quality-system-software-guidance-for-industry-and
(Source for: the risk-based assurance model.)

One compliance layer for both markets

AuditSafe provides the audit trails, electronic signatures, permissions and image authenticity verification that Part 11 and Annex 11 require, inside TotalLab’s software and inside instrument software from OEM partners. If your product or your lab needs to satisfy both regulators, book a free 30-minute discovery call.

Book a free 30-minute discovery call

AuditSafe for OEMs