Cloud-hosted GxP systems have become standard infrastructure across pharmaceutical manufacturing — but EU GMP Annex 11 compliance for cloud deployments remains inconsistently implemented. EMA inspection activity in 2025 and 2026 has demonstrated increasing scrutiny of cloud-specific compliance gaps that were previously overlooked or accepted with minimal documentation.

The Four Areas Generating the Most Observations

1. Supplier Qualification — Annex 11 requires formal assessment of computerised system suppliers and service providers. For cloud systems, this means documented qualification of the cloud provider (AWS, Azure, GCP) at both the infrastructure and application level. A vendor's SOC 2 report or ISO 27001 certificate is a starting point — not a complete qualification. EMA inspectors expect to see a risk-based supplier assessment specific to the GxP use case.

2. Data Sovereignty and Location — GxP data must be accessible to EU competent authorities upon request. Cloud deployments that store data in non-EU jurisdictions require documented risk assessment and contractual guarantees of data accessibility. Organizations cannot assume that a global cloud provider's standard terms satisfy this requirement.

3. Audit Trail Accessibility — For cloud-hosted systems, the audit trail must be accessible to the marketing authorization holder — not just the vendor. Situations where only the SaaS vendor can produce audit trail exports create a fundamental Annex 11 compliance gap. Contracts must specify audit trail ownership, format, and export capability.

4. Disaster Recovery and Business Continuity — Annex 11 requires documented backup procedures with validated restoration capability. For cloud systems, this means formally validating that backup and restoration processes work as documented — not assuming the cloud provider's infrastructure guarantees are sufficient. Tested recovery procedures with documented results are the standard inspectors apply.

Practical Compliance Approach

For each cloud-hosted GxP system, document a cloud-specific risk assessment addressing the four areas above. Supplement standard CSV documentation with cloud addenda covering data location, supplier qualification rationale, and business continuity testing evidence. Organizations that treat cloud systems identically to on-premise systems in their validation programs are creating inspection risk that is straightforward to remediate with the right documentation framework.