How can life sciences companies demonstrate gap-free QA compliance of their GxP-relevant IT systems to inspectors?
We audit GxP-relevant IT systems from a QA perspective: validation status, IT vendor suitability, change control and the inspection readiness of the system portfolio. The real hurdle is rarely the individual system, but rather the missing link between IT operations and QA oversight. As long as patches and configuration changes run without QA review, the gap only surfaces in the audit trail, that is, precisely when the authority is standing in front of it.
Overview
Which QA compliance gaps arise in IT systems in life sciences?
QA audits for GxP IT systems in accordance with EU GMP Guide Annex 11, 21 CFR Part 11 and GAMP 5
Last updated: June 13, 2026
GxP-relevant IT systems such as LIMS, eQMS and MES must meet the same quality standards as physical processes. In practice, however, IT compliance is often treated as a purely IT task, without QA exercising the same oversight that it applies to equipment and procedures. The gaps that inspections most frequently target:
- Validation documentation for GMP systems is incomplete or outdated; the lifecycle validation required under EU GMP Guide Annex 11 is not consistently evidenced.
- IT vendor audits are neglected, even though GMP-critical data is processed at the service provider and EU GMP Guide Annex 11 requires an assessment of the supplier and service provider.
- Change control and incident management for IT systems are not adequately monitored from a quality standpoint; software updates and patches run without proper QA review.
- The audit trail required under 21 CFR Part 11 and Annex 11 is not enabled, not reviewed, or configuration changes have been left without a traceable history.
Services
How we support you
IT vendor assessment & QA requirements
Auditing of IT service providers and software vendors against GMP-relevant quality requirements: software development lifecycle, change and incident management, access controls and data integrity. The deliverable is an audit report with findings, classification by GAMP 5 software category and a draft quality agreement.
How we work together
What it comes down to
A QA audit for IT systems does not check the system against a requirements specification, but rather the quality oversight of the system. The EU GMP Guide Annex 11 and 21 CFR Part 11 require that computerized systems remain validated across their lifecycle, that the audit trail secures the traceability of every data change, and that suppliers and service providers are formally assessed. The sequence determines the effort: first the system inventory must be in place and every system must carry a GAMP 5 category, because only the categorization governs, on a risk basis, how deep validation, vendor assessment and audit trail review need to reach. Anyone who audits without this inventory over-validates standard software unnecessarily and at the same time overlooks the custom category 5 systems to which the critical findings attach.
The pressure point almost always lies at the interface between IT operations and QA. Patches, configuration changes and vendor updates run within IT operations, while QA involvement in change control is missing. As long as this gap persists, an affected validation status only becomes visible once an inspector opens the audit trail and finds an undocumented change. We therefore start with change control and audit trail review before releasing the portfolio for inspection: corrections are cheap where they are planned as a CAPA, and expensive when they appear as an observation in the inspection report.
Our approach
Our approach
Step
Result
Scoping & system inventory
A confirmed list of GxP-relevant IT systems with GAMP 5 categorization and risk classification as the audit scope.
Document & on-site review
Findings on validation documentation, change control and audit trail, evidenced against Annex 11 and 21 CFR Part 11.
Vendor assessment
Audited IT service providers with findings, assessment of the software development lifecycle and the status of quality agreements.
Findings report & prioritization
An audit report with classified findings, risk classification and a prioritization matrix for remediation.
CAPA support
Defined corrective and preventive actions, traceable through to evidence of effectiveness.
Inspection readiness
Critical gaps closed and an IT and CSV portfolio that can be presented to a regulatory inspection.
Common pitfalls
Where projects commonly fail
The audit trail is configurable, but was never enabled or never reviewed.
21 CFR Part 11 and EU GMP Guide Annex 11 require not only the technical capability, but documented periodic audit trail review; an empty or unreviewed trail is a classic inspection finding.
IT patches and security updates are deployed by IT operations without going through QA change control.
This means the assessment of whether the system's validation status under Annex 11 is affected is missing, and a revalidation decision was never made.
Cloud and SaaS providers are treated as pure IT suppliers and not audited as GMP-relevant service providers.
If the provider processes GMP-critical data, EU GMP Guide Annex 11 requires a formal assessment and a quality agreement, which in practice is often missing.
GAMP 5 categorization is skipped, so that standard software and configurable or custom systems receive the same blanket validation effort.
This leads either to under-validated category 5 systems or to unnecessary effort for simple standard software.
Responsibility between IT and QA is not delineated in writing.
The audit reveals that no one owns the oversight of validation and compliance, because IT points to QA and QA points to IT; QA's overarching GMP responsibility remains formally unevidenced.
Quality Management & Compliance
Do any of these pitfalls apply to you?
In a first call we assess your situation and say what needs clarifying first in your case. Without obligation, reply usually within one working day.
FAQ
Frequently asked questions
Sources
- EU GMP Guide Annex 11 (Computerised Systems) and Annex 15 (Qualification and Validation) - primary text
- 21 CFR Part 11 (Electronic Records; Electronic Signatures) and Part 211 - primary text
- GAMP 5 - A Risk-Based Approach to Compliant GxP Computerised Systems (ISPE)
- ISO 13485:2016; IEC 62304
Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Case Studies
What this looks like in practice
Latest insights
All insights →Regulations & standards considered
- EU GMP Guide Annex 11 (Computerised Systems)
- EU GMP Guide Annex 15 (Qualification and Validation)
- 21 CFR Part 11 (Electronic Records; Electronic Signatures)
- 21 CFR Part 211 (cGMP for Finished Pharmaceuticals)
- GAMP 5 (Good Automated Manufacturing Practice, ISPE)
- ISO 13485:2016 (QMS for Medical Devices)
- IEC 62304 (Medical Device Software Lifecycle)
Related topics
Computer System Validation (CSV) →
CSV as the foundation of the validation status examined in the audit
IT Audits & ISO 27001 →
IT security audits complementing the GMP QA perspective
Inspection Readiness →
Inspection preparation beyond the IT area
Data Integrity Assurance →
Audit trail and ALCOA in accordance with Annex 11 and 21 CFR Part 11
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +49 89 4161170-0
info@theentourage.de
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences


