Skip to content
Entourage

How can life sciences companies demonstrate gap-free QA compliance of their GxP-relevant IT systems to inspectors?

We audit GxP-relevant IT systems from a QA perspective: validation status, IT vendor suitability, change control and the inspection readiness of the system portfolio. The real hurdle is rarely the individual system, but rather the missing link between IT operations and QA oversight. As long as patches and configuration changes run without QA review, the gap only surfaces in the audit trail, that is, precisely when the authority is standing in front of it.

  • Pharma
  • Biotech
  • MedTech
  • IVD

Overview

Which QA compliance gaps arise in IT systems in life sciences?

QA audits for GxP IT systems in accordance with EU GMP Guide Annex 11, 21 CFR Part 11 and GAMP 5

Last updated: 2026-06-13

GxP-relevant IT systems such as LIMS, eQMS and MES must meet the same quality standards as physical processes. In practice, however, IT compliance is often treated as a purely IT task, without QA exercising the same oversight that it applies to equipment and procedures. The gaps that inspections most frequently target:

  • Validation documentation for GMP systems is incomplete or outdated; the lifecycle validation required under EU GMP Guide Annex 11 is not consistently evidenced.
  • IT vendor audits are neglected, even though GMP-critical data is processed at the service provider and EU GMP Guide Annex 11 requires an assessment of the supplier and service provider.
  • Change control and incident management for IT systems are not adequately monitored from a quality standpoint; software updates and patches run without proper QA review.
  • The audit trail required under 21 CFR Part 11 and Annex 11 is not enabled, not reviewed, or configuration changes have been left without a traceable history.

Services

How we support you

CSV quality audit of the system portfolio

A complete review of the validation status of all GxP-relevant IT systems: completeness and currency of the validation documentation, quality of the IQ/OQ/PQ packages in accordance with EU GMP Guide Annex 15, traceability gaps and validation backlog. The deliverable is a list of findings with risk classification and a prioritization matrix per system.

Learn more

IT vendor assessment & QA requirements

Auditing of IT service providers and software vendors against GMP-relevant quality requirements: software development lifecycle, change and incident management, access controls and data integrity. The deliverable is an audit report with findings, classification by GAMP 5 software category and a draft quality agreement.

QA review of IT change control

Review and optimization of the IT change control process from a QA perspective: quality of the impact assessment, QA review involvement, revalidation decisions and documentation of patches. The deliverable is an assessment of the as-is process against EU GMP Guide Annex 11 with concrete corrective actions.

Learn more

Inspection preparation IT & CSV

Preparation for regulatory inspections in the IT area: verification of the completeness of the system portfolio, review of all CSV documents and a mock inspection with IT-focused inspection questions. The deliverable is an action plan with gaps closed ahead of the inspection date.

Learn more

Audit trail & data integrity review

Examination of audit trail configuration and audit trail review practice against 21 CFR Part 11 and EU GMP Guide Annex 11: activation, protection against manipulation, access roles and traceability of configuration changes. The deliverable is a gap report per system with an assessment against the ALCOA principles.

Learn more

What it comes down to

A QA audit for IT systems does not check the system against a requirements specification, but rather the quality oversight of the system. The EU GMP Guide Annex 11 and 21 CFR Part 11 require that computerized systems remain validated across their lifecycle, that the audit trail secures the traceability of every data change, and that suppliers and service providers are formally assessed. The sequence determines the effort: first the system inventory must be in place and every system must carry a GAMP 5 category, because only the categorization governs, on a risk basis, how deep validation, vendor assessment and audit trail review need to reach. Anyone who audits without this inventory over-validates standard software unnecessarily and at the same time overlooks the custom category 5 systems to which the critical findings attach.

The pressure point almost always lies at the interface between IT operations and QA. Patches, configuration changes and vendor updates run within IT operations, while QA involvement in change control is missing. As long as this gap persists, an affected validation status only becomes visible once an inspector opens the audit trail and finds an undocumented change. We therefore start with change control and audit trail review before releasing the portfolio for inspection: corrections are cheap where they are planned as a CAPA, and expensive when they appear as an observation in the inspection report.

Our approach

Our approach

01

Scoping & system inventory

A confirmed list of GxP-relevant IT systems with GAMP 5 categorization and risk classification as the audit scope.

02

Document & on-site review

Findings on validation documentation, change control and audit trail, evidenced against Annex 11 and 21 CFR Part 11.

03

Vendor assessment

Audited IT service providers with findings, assessment of the software development lifecycle and the status of quality agreements.

04

Findings report & prioritization

An audit report with classified findings, risk classification and a prioritization matrix for remediation.

05

CAPA support

Defined corrective and preventive actions, traceable through to evidence of effectiveness.

06

Inspection readiness

Critical gaps closed and an IT and CSV portfolio that can be presented to a regulatory inspection.

Common pitfalls

Where projects commonly fail

The audit trail is configurable, but was never enabled or never reviewed.

21 CFR Part 11 and EU GMP Guide Annex 11 require not only the technical capability, but documented periodic audit trail review; an empty or unreviewed trail is a classic inspection finding.

IT patches and security updates are deployed by IT operations without going through QA change control.

This means the assessment of whether the system's validation status under Annex 11 is affected is missing, and a revalidation decision was never made.

Cloud and SaaS providers are treated as pure IT suppliers and not audited as GMP-relevant service providers.

If the provider processes GMP-critical data, EU GMP Guide Annex 11 requires a formal assessment and a quality agreement, which in practice is often missing.

GAMP 5 categorization is skipped, so that standard software and configurable or custom systems receive the same blanket validation effort.

This leads either to under-validated category 5 systems or to unnecessary effort for simple standard software.

Responsibility between IT and QA is not delineated in writing.

The audit reveals that no one owns the oversight of validation and compliance, because IT points to QA and QA points to IT; QA's overarching GMP responsibility remains formally unevidenced.

FAQ

Frequently asked questions

The QA department holds the overarching responsibility for GMP compliance, including computerized systems under EU GMP Guide Annex 11. In practice, the division of tasks is decisive: IT provides and operates systems, QA owns validation oversight and compliance. This delineation should be set out in writing, because inspectors deliberately probe accountability.

Sources
  • EU GMP Guide Annex 11 (Computerised Systems) and Annex 15 (Qualification and Validation) - primary text
  • 21 CFR Part 11 (Electronic Records; Electronic Signatures) and Part 211 - primary text
  • GAMP 5 - A Risk-Based Approach to Compliant GxP Computerized Systems (ISPE)
  • ISO 13485:2016; IEC 62304
  • https://theentourage.de/expertise/audits-and-qa-services-for-it-systems/ (existing page content, revised)

Life Science Journal

Regulatory updates, straight to your inbox.

New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.

Regulations & standards considered

  • EU GMP Guide Annex 11 (Computerised Systems)
  • EU GMP Guide Annex 15 (Qualification and Validation)
  • 21 CFR Part 11 (Electronic Records; Electronic Signatures)
  • 21 CFR Part 211 (cGMP for Finished Pharmaceuticals)
  • GAMP 5 (Good Automated Manufacturing Practice, ISPE)
  • ISO 13485:2016 (QMS for Medical Devices)
  • IEC 62304 (Medical Device Software Lifecycle)

Have a concrete project?

Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.

Prefer direct? +49 89 4161170-0
info@theentourage.de

  • Reply usually within one working day
  • 4 offices: DE · CH · IT · US
  • 100% life sciences