When software supports a critical process, simply working is not enough. Intended use, impact, responsibilities, access, testing, changes and evidence must be defined and maintained throughout the lifecycle. Pharmaceutical operations make this principle particularly clear: GAMP 5 and Annex 11 provide a concrete case, not a label to attach to a product.
Pharmaceutical operations as a concrete case
During CPHI Milan 2026, discussions about AI and digital technologies brought attention back to a practical question: how can organisations innovate without adding yet another tool that is difficult to govern? This is not solely a pharmaceutical concern. Wherever an error can affect quality, safety, operational continuity or important decisions, the digital process must remain understandable, controllable and verifiable.
Digitalisation does not mean copying a paper form onto a screen. First, define who performs the activity, which decision it supports, which information constitutes the original record, which errors could affect product quality or patient safety, and which controls must remain demonstrable over time. Only then does it make sense to choose the configuration, integrations and level of automation.
GAMP 5 and Annex 11 are not the same thing
GAMP® 5 is a good-practice guide published by ISPE. It proposes a pragmatic, risk-based lifecycle approach to achieving computerised systems that are effective, reliable and fit for their intended use. ISPE makes clear that it is neither a prescriptive standard nor a single method; expressions such as “GAMP 5 certified” are therefore misleading when they suggest that a universal product certification exists.
Annex 11, by contrast, forms part of EU GMP and concerns computerised systems used in GMP-regulated activities. It does not automatically apply to every piece of software in a pharmaceutical company. When a system falls within scope, the application must be validated, the IT infrastructure qualified, and the extent of the activities must be based on a documented risk assessment.
From requirements to evidence throughout the lifecycle
The current Annex 11 requires traceable user requirements, clear roles and responsibilities, supplier assessment, appropriate testing and change control. It also requires data protection and verification, access restricted to authorised individuals, incident management, periodic evaluation and business-continuity measures. Backup and restoration are not boxes to tick: data integrity and recoverability must be verified.
Audit trails, electronic signatures and archiving must also be assessed against the actual process. A standard application log does not automatically become a GMP audit trail, and an on-screen confirmation is not necessarily equivalent to an electronic signature. Content, identity, date and time, reason for change, integrity, protection against unauthorised alteration, availability and review procedures must be defined and tested against the intended use.
The Annex 11 revision should be monitored, not anticipated
As at 10 October 2026, the official EudraLex page continues to list the January 2011 revision of Annex 11 as the current version. In 2025, the European Commission concluded a consultation on a revised Annex 11, Chapter 4 and a new Annex 22 concerning artificial intelligence. Those texts are drafts: they are useful for understanding the direction of the regulatory framework, but must not be presented as requirements that are already in force.
The draft reinforces themes that are already central: management throughout the lifecycle, requirement quality, supplier oversight, identity and access, security, audit trails, backup and data integrity. The practical implication is not to chase every formulation before it becomes final, but to design processes, responsibilities and evidence robust enough to be updated in a controlled manner.
Where ZenFactory may fit
ZenFactory organises facilities, departments and machines, connecting scheduled maintenance, service work, downtime and checklists. Checklists retain the captured version, questions and answers; dashboards, reports, exports and the activity log help teams understand the operational process within a shared context. These functions are useful when information is scattered across spreadsheets, messages and forms.
These functions do not, by themselves, demonstrate compliance with GAMP 5 or Annex 11. They may provide a foundation to assess within a path defined by intended use and risk: GMP scope, user requirements, gap analysis, configuration, traceability, access, any required signatures, audit trails, evidence-based testing, backup and restoration, procedures, training, change control and periodic review all remain part of the overall project.
Start with a tightly scoped pilot
A credible first step may cover one department, a group of machines and a clearly bounded workflow. Existing activities and data are mapped, impact and criticality are classified, observable requirements are defined, and responsibility for approving configuration, testing and release is agreed. The pilot must produce evidence, not merely an appealing demonstration.
At the end, the previous and digital processes are compared: record completeness, response times, exceptions, remaining manual activities and the ability to reconstruct what happened. The decision to extend the system follows from these results and the organisation’s Quality/GMP assessment, not from a generic promise of software that is already compliant.