EU GMP Annex 11 clause 11 requires that computerised systems are periodically evaluated to confirm they remain in a valid state and compliant. It is a short clause. It is also, in our experience, the single most commonly overdue obligation in the whole annex.
The reason is structural rather than negligent: periodic review is a lifecycle duty with no project attached to it, no go-live date driving it, and no sponsor whose bonus depends on it.
What a periodic review is
A structured assessment of whether a system is still what its documentation says it is. It looks at the change history since the last review, incidents and deviations, operational performance, user access, calibration status where relevant, and whether current regulatory expectations have moved.
It produces a conclusion — the system remains validated, or it does not and here is what must happen — with findings that become tracked actions.
What it is not
It is not a revalidation. This confusion is the main reason reviews get deferred: someone scopes it as a full re-execution of IQ/OQ/PQ, costs it accordingly, and the whole thing becomes a project that cannot be funded this quarter.
It is also not a tick-box. A review that concludes "no issues" on a system with eleven uncontrolled changes and an overdue supplier assessment is worse than no review, because it documents that you looked and did not see.
How often
The annex does not fix an interval. You set it based on the system's criticality, its change history and its incident record, and you justify the choice. Annually is common for critical systems; a stable, low-risk system may reasonably be reviewed less often.
What matters is that the interval is defined, justified, and actually met. An undefined interval is a finding by itself, and a defined interval that is routinely missed is worse than a longer one that is kept.
Catching up when you are behind
If several systems are overdue, resist the instinct to do them all properly and in parallel. That is how the backlog becomes permanent.
- Triage by criticality and by change volume. A system with forty changes since its last review is a different proposition from one with none.
- Do the highest-risk system properly and completely. It establishes the template and tells you how long one actually takes.
- For low-change, low-risk systems, a short review that honestly concludes little has changed is legitimate and fast.
- Schedule the next round before closing the current one. The backlog rebuilt itself last time because nobody did this.
Our EU Annex 11 & Annex 22 compliance work usually starts with this triage, and GxP Copilot reports change history, incidents and calibration status against each system so the review is an assessment rather than an archaeology exercise.
Why inspectors go here early
Because it is a fast, reliable signal. A validation package tells an inspector how you behaved during a project, when attention was high and budget existed. A periodic review record tells them how you behave the rest of the time.
An estate with current reviews and documented findings reads as controlled. An estate with an immaculate original package and no review since go-live reads as one where validation was an event rather than a state — and that shapes everything they look at next.
Where to go next
Explore GxP Copilot for AI-native validation, TraceDraft for source-traceable clinical documentation, or book a demo to see either on your own data.
