Compliance software · EU Annex 11Updated October 8, 2026

Annex 11 compliant EDC: what to check, and what Capture covers

No EDC is Annex 11 compliant out of the box. Compliance comes from the system plus your risk assessment, validation and procedures. Here is how the Annex 11 clauses map to an EDC, which controls Capture builds in, and which parts stay with your quality team.

  • Field-level, append-only audit trail
  • Re-authenticated e-signatures
  • Hosted in the EU (Frankfurt)

Free sandbox · No credit card · 21 CFR Part 11 aligned

Annex 11 mapping, demo study

Hosting

EU

Audit trail

Per field

Sponsor tasks

4 open

  • Audit trail with reason for changeBuilt in
  • E-signature linked to the recordBuilt in
  • Unique users and role-based accessBuilt in
  • Data stored in the EUFrankfurt
  • Risk assessment for intended useSponsor
  • Validation for intended useSponsor
  • Supplier assessment and agreementSponsor
  • Backup and restore evidenceAsk supplier
Demo mapping. Annex 11 is met by the system plus your procedures, never by software alone.

The short answer

  • Annex 11 is the EU GMP annex on computerised systems (EudraLex Volume 4, January 2011 revision, in operation since 30 June 2011). It is written for GMP-regulated activities, and its principles are widely used as a reference for clinical systems too.
  • For clinical trials, EU GCP inspectors work from the EMA guideline on computerised systems and electronic data in clinical trials (EMA/INS/GCP/112288/2023, effective 9 September 2023). It covers the same ground: validation, audit trails, access, signatures and service providers.
  • An EDC supplies controls, you supply the rest. Audit trail, signatures, access control and data location are software properties. Risk assessment, validation, supplier assessment, SOPs and periodic review belong to the regulated user.
  • A revised Annex 11 is in draft. The Commission consulted on it from 7 July to 7 October 2025. As of 8 October 2026 the 2011 text is still the version in force.
  • This page is general information, not legal or regulatory advice.

The requirement

What Annex 11 is, and why EDC buyers ask about it

Annex 11 sits in Volume 4 of EudraLex, the EU guidelines for good manufacturing practice, and PIC/S carries an equivalent annex in its own GMP guide. It has a short principle and 17 clauses grouped into general requirements (risk management, personnel, suppliers and service providers), the project phase (validation) and the operational phase (data, accuracy checks, storage, printouts, audit trails, change management, periodic evaluation, security, incident management, electronic signatures, batch release, business continuity and archiving). The core idea is that replacing a manual process with a computerised one must not reduce product quality, process control or quality assurance.

Strictly, Annex 11 is a GMP text. An EDC that holds trial data is inspected under GCP, and the EMA's 2023 computerised systems guideline is the document EU GCP inspectors apply to eCRFs, ePRO, IRT and the cloud services behind them. Buyers still ask for an "Annex 11 compliant EDC" for good reasons: many QA teams come from GMP, PIC/S member inspectorates use Annex 11 vocabulary, and vendor questionnaires often use its clauses as the checklist. The two documents ask for similar evidence, so mapping an EDC against Annex 11 is a sensible exercise as long as you also read the GCP guideline. If you need the US side as well, see Annex 11 vs 21 CFR Part 11.

Clause by clause

Annex 11 clauses mapped to an EDC

The clauses that matter most for a clinical data system. The middle column describes Capture as built today; the right column is work no vendor can do for you.

Annex 11 clauseWhat it expectsWhat Capture providesWhat stays with you
1. Risk managementRisk-based decisions on validation and data integrity controlsA documented, fixed set of controls to assessYour risk assessment for the study's intended use
3. Suppliers and service providersFormal agreements; supplier competence assessedValidation-support documentation for Enterprise customersSupplier assessment, audit decision, written agreement
4. ValidationEvidence the system is fit for intended useA free sandbox with every feature to run your test scriptsValidation plan, UAT execution and report
6. Accuracy checksChecks on manually entered critical dataRange and custom edit checks that raise auto-queries; calculated fieldsDefining checks in your data validation plan
7. Data storageData secured, accessible and readable; backupsEU (Frankfurt) or US hosting; AES-256 at rest, TLS in transitRequest backup and restore evidence during supplier assessment
9. Audit trailsRecord of GMP-relevant changes, with the reason; regularly reviewedField-level, append-only trail with old value, new value, user, time and reasonAudit trail review in your data management plan
10. Change managementChanges made in a controlled wayDraft to approved form lifecycle; approved forms locked for live useChange control for amendments and re-testing
11. Periodic evaluationSystems reviewed to confirm they stay validExportable audit trail and by-site exports for the reviewScheduling and documenting the review
12. SecurityAccess limited to authorised peopleRole-based access, row-level security, PII segregation, optional TOTP two-factorUser access requests, reviews and removal
14. Electronic signatureSame impact as handwritten, permanently linked, datedPassword re-authentication, meaning statement, signature hashed to the contentDefining who signs what, and what it means
17. ArchivingArchived data readable for the retention periodCSV/Excel with data dictionary, SDTM XPT with Define-XML, signed consent PDFsArchiving to your retention rules

Clauses 2, 8, 13, 15 and 16 (personnel, printouts, incidents, batch release, business continuity) are mainly about the regulated user's organisation or do not apply to an EDC.

Inside Capture

The controls behind the table

The audit trail is written by database triggers, one row per changed field, with the user, timestamp, old value, new value and reason for change. The database blocks updates and deletes on audit rows, and each row carries a SHA-256 hash chained to the previous row for that study, so a gap or an edit breaks the chain. The server records the IP address, and technical events go to a separate system log so the GCP trail holds only regulated actions. Clinical data is soft-deleted only; hard deletes are blocked. More detail is on the audit trail software page.

Staff signatures ask for the password again and store a meaning statement. On eConsent, the participant's signature is confirmed with an emailed one-time code, the investigator countersigns, and each signature is hashed to the exact document content at signing. Access follows study roles, with personal data segregated so researchers see coded IDs while site coordinators see names, enforced by row-level security in the database rather than only in the interface. Staff can turn on two-factor authentication with an authenticator app, and sessions end after inactivity with a countdown warning first. See role-based access control and electronic signatures.

Data residency

Capture hosts studies in the EU (Frankfurt) or the USA (N. Virginia). For an EU sponsor, Frankfurt hosting keeps trial data inside the EU, which simplifies the data storage and supplier sections of your assessment and your GDPR transfer analysis. GDPR is a separate obligation from Annex 11; the GDPR compliant clinical trial software page covers it.

Run your Annex 11 checks against a real build

Change a value, read the audit trail, sign a form and test role access in the free sandbox. No credit card, and you pay only when you go live.

Test the controls free in the sandbox

Before first participant

An Annex 11 readiness checklist for your EDC

Intended use defined

Which data, which decisions and which submissions the EDC supports.

Risk assessment on file

Covers data integrity and participant safety, and sets the depth of validation.

Supplier assessed and contracted

Questionnaire or audit, plus an agreement that names responsibilities.

Validation executed

UAT scripts run against your configured study, deviations closed, report signed.

Audit trail review planned

Who reviews what, how often, recorded in the data management plan.

Access process written

Account requests, role assignment, periodic review and prompt removal.

Signature meanings defined

Which roles sign which records, and what each signature attests.

Periodic review scheduled

Release notes, incidents and changes reviewed against the validated state.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Is Capture Annex 11 compliant?

No software is Annex 11 compliant on its own, because the annex covers risk management, validation, suppliers and procedures as well as features. Capture provides the system controls: field-level append-only audit trail with reason for change, re-authenticated electronic signatures, role-based access and EU hosting. You complete the picture with your own validation and SOPs.

Does Annex 11 apply to an EDC?

Annex 11 is part of the EU GMP guidelines, so it is written for GMP-regulated systems. For clinical trial systems, EU GCP inspectors apply the EMA guideline on computerised systems and electronic data in clinical trials (2023). Many sponsors map their EDC against both because the expectations overlap.

Has the revised Annex 11 been adopted?

Not as of 8 October 2026. A draft revision was consulted on from 7 July to 7 October 2025, and the European Commission's EudraLex page still lists the January 2011 revision. Check the Commission's page for the current status.

Where is data stored?

Capture hosts data in the EU (Frankfurt) or the USA (N. Virginia). EU sponsors can keep study data in Frankfurt.

Does Capture provide validation documentation?

Enterprise customers receive documentation and implementation assistance to support sponsor validation and user acceptance testing. You still validate for your own intended use, and you can run your test scripts in the free sandbox first.

What about backups and disaster recovery?

Annex 11 expects regular, tested backups. This page does not describe Capture's backup arrangements; ask us for them as part of your supplier assessment, as you should with any vendor.

Check the Annex 11 controls yourself

Build a study in the free sandbox and test the audit trail, signatures and access roles. No credit card, and you pay only when you go live.

Test the controls free in the sandbox