No EDC is Annex 11 compliant out of the box. Compliance comes from the system plus your risk assessment, validation and procedures. Here is how the Annex 11 clauses map to an EDC, which controls Capture builds in, and which parts stay with your quality team.
Free sandbox · No credit card · 21 CFR Part 11 aligned
Hosting
EU
Audit trail
Per field
Sponsor tasks
4 open
The short answer
The requirement
Annex 11 sits in Volume 4 of EudraLex, the EU guidelines for good manufacturing practice, and PIC/S carries an equivalent annex in its own GMP guide. It has a short principle and 17 clauses grouped into general requirements (risk management, personnel, suppliers and service providers), the project phase (validation) and the operational phase (data, accuracy checks, storage, printouts, audit trails, change management, periodic evaluation, security, incident management, electronic signatures, batch release, business continuity and archiving). The core idea is that replacing a manual process with a computerised one must not reduce product quality, process control or quality assurance.
Strictly, Annex 11 is a GMP text. An EDC that holds trial data is inspected under GCP, and the EMA's 2023 computerised systems guideline is the document EU GCP inspectors apply to eCRFs, ePRO, IRT and the cloud services behind them. Buyers still ask for an "Annex 11 compliant EDC" for good reasons: many QA teams come from GMP, PIC/S member inspectorates use Annex 11 vocabulary, and vendor questionnaires often use its clauses as the checklist. The two documents ask for similar evidence, so mapping an EDC against Annex 11 is a sensible exercise as long as you also read the GCP guideline. If you need the US side as well, see Annex 11 vs 21 CFR Part 11.
Clause by clause
The clauses that matter most for a clinical data system. The middle column describes Capture as built today; the right column is work no vendor can do for you.
| Annex 11 clause | What it expects | What Capture provides | What stays with you |
|---|---|---|---|
| 1. Risk management | Risk-based decisions on validation and data integrity controls | A documented, fixed set of controls to assess | Your risk assessment for the study's intended use |
| 3. Suppliers and service providers | Formal agreements; supplier competence assessed | Validation-support documentation for Enterprise customers | Supplier assessment, audit decision, written agreement |
| 4. Validation | Evidence the system is fit for intended use | A free sandbox with every feature to run your test scripts | Validation plan, UAT execution and report |
| 6. Accuracy checks | Checks on manually entered critical data | Range and custom edit checks that raise auto-queries; calculated fields | Defining checks in your data validation plan |
| 7. Data storage | Data secured, accessible and readable; backups | EU (Frankfurt) or US hosting; AES-256 at rest, TLS in transit | Request backup and restore evidence during supplier assessment |
| 9. Audit trails | Record of GMP-relevant changes, with the reason; regularly reviewed | Field-level, append-only trail with old value, new value, user, time and reason | Audit trail review in your data management plan |
| 10. Change management | Changes made in a controlled way | Draft to approved form lifecycle; approved forms locked for live use | Change control for amendments and re-testing |
| 11. Periodic evaluation | Systems reviewed to confirm they stay valid | Exportable audit trail and by-site exports for the review | Scheduling and documenting the review |
| 12. Security | Access limited to authorised people | Role-based access, row-level security, PII segregation, optional TOTP two-factor | User access requests, reviews and removal |
| 14. Electronic signature | Same impact as handwritten, permanently linked, dated | Password re-authentication, meaning statement, signature hashed to the content | Defining who signs what, and what it means |
| 17. Archiving | Archived data readable for the retention period | CSV/Excel with data dictionary, SDTM XPT with Define-XML, signed consent PDFs | Archiving to your retention rules |
Clauses 2, 8, 13, 15 and 16 (personnel, printouts, incidents, batch release, business continuity) are mainly about the regulated user's organisation or do not apply to an EDC.
Inside Capture
The audit trail is written by database triggers, one row per changed field, with the user, timestamp, old value, new value and reason for change. The database blocks updates and deletes on audit rows, and each row carries a SHA-256 hash chained to the previous row for that study, so a gap or an edit breaks the chain. The server records the IP address, and technical events go to a separate system log so the GCP trail holds only regulated actions. Clinical data is soft-deleted only; hard deletes are blocked. More detail is on the audit trail software page.
Staff signatures ask for the password again and store a meaning statement. On eConsent, the participant's signature is confirmed with an emailed one-time code, the investigator countersigns, and each signature is hashed to the exact document content at signing. Access follows study roles, with personal data segregated so researchers see coded IDs while site coordinators see names, enforced by row-level security in the database rather than only in the interface. Staff can turn on two-factor authentication with an authenticator app, and sessions end after inactivity with a countdown warning first. See role-based access control and electronic signatures.
Capture hosts studies in the EU (Frankfurt) or the USA (N. Virginia). For an EU sponsor, Frankfurt hosting keeps trial data inside the EU, which simplifies the data storage and supplier sections of your assessment and your GDPR transfer analysis. GDPR is a separate obligation from Annex 11; the GDPR compliant clinical trial software page covers it.
Change a value, read the audit trail, sign a form and test role access in the free sandbox. No credit card, and you pay only when you go live.
Shared responsibility
Annex 11 speaks to the regulated user throughout. Clause 3 asks you to assess your supplier and put the arrangement in a formal agreement. Clause 4 asks for validation evidence that fits your intended use, which a vendor can support but not replace. Clause 11 asks you to come back and review the system periodically. The EMA clinical guideline makes the same point for trials: the sponsor and investigator stay responsible even when a service provider runs the system, and inspectors expect to see the documentation the sponsor relied on.
Treat the vendor's controls as inputs to your own file. A good starting point is the computer system validation guide, followed by the vendor security questionnaire for the supplier assessment.
Ask in writing and file the answers with your supplier assessment.
Before first participant
Which data, which decisions and which submissions the EDC supports.
Covers data integrity and participant safety, and sets the depth of validation.
Questionnaire or audit, plus an agreement that names responsibilities.
UAT scripts run against your configured study, deviations closed, report signed.
Who reviews what, how often, recorded in the data management plan.
Account requests, role assignment, periodic review and prompt removal.
Which roles sign which records, and what each signature attests.
Release notes, incidents and changes reviewed against the validated state.
No software is Annex 11 compliant on its own, because the annex covers risk management, validation, suppliers and procedures as well as features. Capture provides the system controls: field-level append-only audit trail with reason for change, re-authenticated electronic signatures, role-based access and EU hosting. You complete the picture with your own validation and SOPs.
Annex 11 is part of the EU GMP guidelines, so it is written for GMP-regulated systems. For clinical trial systems, EU GCP inspectors apply the EMA guideline on computerised systems and electronic data in clinical trials (2023). Many sponsors map their EDC against both because the expectations overlap.
Not as of 8 October 2026. A draft revision was consulted on from 7 July to 7 October 2025, and the European Commission's EudraLex page still lists the January 2011 revision. Check the Commission's page for the current status.
Capture hosts data in the EU (Frankfurt) or the USA (N. Virginia). EU sponsors can keep study data in Frankfurt.
Enterprise customers receive documentation and implementation assistance to support sponsor validation and user acceptance testing. You still validate for your own intended use, and you can run your test scripts in the free sandbox first.
Annex 11 expects regular, tested backups. This page does not describe Capture's backup arrangements; ask us for them as part of your supplier assessment, as you should with any vendor.
Keep exploring
Annex 11 vs 21 CFR Part 11
Side-by-side comparison of the EU and US rules.
EMA computerised systems guideline
The GCP guideline EU inspectors apply to trial systems.
21 CFR Part 11 compliant EDC
The US counterpart to this page.
Computer system validation
Validating an EDC for its intended use.
Audit trail software
How the hash-chained audit trail works.
Security at Capture
Sign-in, audit, deletion and review practices.
Build a study in the free sandbox and test the audit trail, signatures and access roles. No credit card, and you pay only when you go live.