“Is your software actually GxP-compliant?” This question arises in almost every life sciences project. At first, it may sound like a technical question, but it touches on an entire regulatory framework of authorities, legislation, guidelines, and standards that has evolved over decades. From a regulatory perspective, the focus is not on software in general, but on computerised systems and their validation in CSV projects. Viewing this regulatory framework as simply a collection of abbreviations makes it difficult to derive specific requirements from it.
This article explains which authorities are responsible for what, how legislation and guidelines fit together, and why a single outdated document can result in a product being taken off the market.
When a document becomes a quality risk – two typical scenarios
Discussions about computerised systems in regulated environments often focus on individual functions. Is a task reliably delivered? Does a user role have overly broad permissions? These questions are justified, but they only scratch the surface. Two scenarios that regularly occur in practice illustrate the potential consequences:
- Outdated standard operating procedure (SOP) for production parameters: An SOP is updated, but the previous version remains accessible in the production system. Employees continue to work according to the outdated version. The active ingredient content falls outside the specification, potentially resulting in an insufficient dose. In addition to the batch recall, the document management system must be revised.
- Incorrect manufacturing instructions for sterile medicinal products: A GMP inspection finds that an older version of the manufacturing instructions containing outdated process parameters has been used. The risk of sterility failure, and therefore of microbial contamination, increases. The consequences are a batch recall and a production shutdown until the cause has been identified.
In both cases, the issue ultimately is not a discussion about a feature, but whether a product can remain on the market at all. This is exactly why it pays to understand how the regulatory framework fits together.
The rule-makers – which authority is responsible for what
In Germany, two federal authorities share responsibility for different product categories. The Federal Institute for Drugs and Medical Devices (BfArM) is responsible for conventional medicinal products and a large proportion of medical devices, including authorisation, control, and monitoring. The Paul-Ehrlich-Institut (PEI) is responsible for vaccines, blood products, advanced therapy medicinal products (ATMPs), allergens, and antibodies. The two authorities work closely together, for example on clinical trials and regulatory advice.
At European level, the EMA (European Medicines Agency) coordinates the assessment and monitoring of medicinal products and helps ensure their safety, thereby facilitating access to the European market. In the United States, the Food and Drug Administration (FDA) has a much wider scope of responsibility: It is responsible for the safety, efficacy and quality of medicinal products, medical devices and food, both during authorisation and in post-market surveillance.
Two additional authorities are relevant and regularly feature in our projects. Swissmedic combines responsibility for the authorisation, regulation, and monitoring of medicinal products and medical devices in Switzerland. Since Brexit, responsibility for the United Kingdom has shifted from the European Medicines Agency to the Medicines and Healthcare products Regulatory Agency (MHRA). Its requirements largely mirror EU regulations, so significant differences are unlikely. However, specific areas may have their own forms and detailed requirements.
The referees – how regulatory oversight is organised in Germany
One authority sets the rules, while another enforces them. In Germany, day-to-day regulatory oversight of the industry lies almost entirely with the federal states and is coordinated by the Central Authority of the Länder for Health Protection with regard to Medicinal Products and Medical Devices (ZLG), based in Bonn. Typical responsibilities include:
- GMP inspections of manufacturers
- GDP inspections of wholesalers
- Pharmacy supervision, including pharmacies that manufacture medicinal products
- Monitoring of clinical trial sites in accordance with GCP
- Market surveillance and recalls
Key to understanding the division of responsibilities: The inspectors work for the state authorities, not for BfArM or PEI. Responsibility therefore extends from the EU and the German Federal Ministry of Health through the federal authorities to the state authorities that conduct inspections on site. This structure remains unchanged, whether the focus is on GMP, GDP or GCP.
The rules for medicinal products – from the EU GMP Guidelines to 21 CFR
For medicinal products, the EU GMP Guidelines (EudraLex Volume 4) provide the regulatory foundation. They set out mandatory requirements for quality management, manufacturing processes, documentation, and controls. Three sections are particularly relevant to electronic quality management systems:
- Chapter 4 – Documentation: governs the management of documents and is the source of numerous requirements for document control.
- Annex 11 – Computerised Systems: sets out in detail the requirements for validated systems, including audit trails and data management. The Annex is currently under revision.
- Annex 22 – Artificial Intelligence: as a new draft, addresses the use of artificial intelligence in the pharmaceutical sector and the resulting requirements.
At national level, the German Medicinal Products Act (AMG) provides the legal framework for the development, manufacture, authorisation, supply, and monitoring of medicinal products. The Ordinance on the Manufacture of Medicinal Products and Active Substances (AMWHV) provides more detailed requirements for manufacture, testing, storage, and distribution and explicitly refers to the EU GMP Guidelines. It therefore provides the link that makes the EU GMP Guidelines binding for manufacturing in Germany.
In the United States, this role is fulfilled by Title 21 of the Code of Federal Regulations (21 CFR) . Parts 210 and 211 govern medicinal product manufacturing in accordance with current Good Manufacturing Practice, Part 820 sets out requirements for quality management systems, and Part 11 covers electronic records and electronic signatures. In our day-to-day work with customers, Part 11 compliance is particularly relevant because it provides the basis for electronic releases and signature processes. However, one responsibility always remains with the company itself: determining which records are subject to record-keeping requirements.
The rules for medical devices – MDR, IVDR, and ISO 13485
A parallel regulatory structure applies to medical devices. The MDR (Medical Device Regulation, Regulation 2017/745) governs safety, performance, clinical evaluation, traceability and post-market surveillance throughout Europe. The latter goes further than you might initially expect: Manufacturers must monitor their products on the market and respond to relevant information, including observations from social media channels. For in vitro diagnostic medical devices, which analyse samples outside the human body, the IVDR (Regulation 2017/746) covers performance evaluation, risk classification and conformity assessment. Both regulations are implemented in German law through the Medical Device Law Implementation Act (MPDG), which also governs responsibilities, monitoring and market surveillance.
Additionally, two standards are particularly relevant: ISO 13485 for quality management systems in medical device manufacturing, and ISO 14971 for risk management. There is no direct legal requirement to apply these standards, but both are recognised as reflecting the state of the art and are referenced in regulatory requirements. In the United States, the FDA QMSR (Quality Management System Regulation) formalised this approach in 2025, aligning quality management system requirements for medical device manufacturers more closely with ISO 13485.
From requirements to practice – the guidelines that bridge the gap
Legislation defines what is required, not how it should be implemented. Harmonisation organisations and practical guidelines bridge this gap.
PIC/S (Pharmaceutical Inspection Co-operation Scheme) is an international association of GMP inspectorates with currently 56 participating authorities. The published guides cover areas ranging from manufacturing processes, storage, and raw material selection to the validation of computerised systems. The International Council for Harmonisation (ICH) works closely with PIC/S. We frequently encounter ICH Q9 on quality risk management and ICH Q10 on pharmaceutical quality systems, including elements such as monitoring, CAPA, change management, and management review.
For computerised systems, ISPE plays a key role. In addition to the established ISPE GAMP® 5, 2nd Edition, the GAMP Good Practice Guide: Data Integrity by Design, the ALCOA+ principles, the Good Practice Guide: Digital Validation, and the new GAMP AI Guide for AI-supported GxP systems are also relevant. These guidelines are regularly updated to reflect changes in legislation. They do not replace binding requirements, but provide a risk-based, transparent, and practical approach to implementation.
Back to the original scenario – which requirements apply?
What requirements would have applied in the case of the outdated manufacturing instructions for sterile medicinal products? A look at the regulations reveals a striking degree of consistency across jurisdictions:
Across all major regulatory frameworks, the same basic principle applies: Medicinal products must be manufactured strictly in accordance with the approved manufacturing instructions. If an outdated version is used, the manufacturing process is considered uncontrolled from a regulatory perspective.
A closer look at the responsibilities is particularly revealing. The AMWHV explicitly assigns responsibility for the approval to the Head of Production. In projects, we are regularly asked who needs to approve a document and where a signature is required. The regulations also provide the answer to this question.
What this means for an electronic quality management system
The hierarchy described above translates directly into requirements for computerised systems in regulated environments:
- Document control: The system must ensure that an outdated version can no longer be accessed or used at the point of work.
- Audit trail: Changes to GxP-relevant data must be fully traceable and protected against alteration, as required by Annex 11.
- Electronic signatures: Releases must comply with the requirements of 21 CFR Part 11 and reflect the responsibilities defined by the applicable regulations.
- Data integrity: The ALCOA+ principles must be embedded in the system itself, not merely documented in accompanying process instructions.
- Controlled processes: The system must support the recording, evaluation, and documentation of deviations.
- Validation: The system must be capable of being validated in CSV projects using recognised approaches such as ISPE GAMP® 5 and of remaining in a validated state when changes are made.
With engamp®, we address precisely these requirements, combining document control, release processes and traceability in a secure, efficient, and transparent way.
Conclusion: Understanding regulations as a hierarchy
At first glance, the regulatory landscape in the life sciences sector can seem complex. However, viewing it as a hierarchy makes it easier to navigate: Authorities establish and oversee the regulatory framework, laws and regulations set out binding requirements, and harmonisation organisations and guidelines translate these requirements into practical guidance. Medicinal products and medical devices are subject to different but interconnected regulatory frameworks.
The two scenarios described at the beginning show how quickly an uncontrolled document can become a quality and patient safety risk. A consistently controlled and validated quality management system is therefore not merely an administrative tool, but a key element of product safety. With Annex 22 on artificial intelligence, the next chapter is already taking shape, one that operators and providers of computerised systems will need to address together.
We can help you determine which regulatory requirements apply to your processes and how to incorporate them into an electronic quality management system.
Frequently asked questions (FAQs)
- Which authorities are responsible for life sciences in Germany?
In Germany, BfArM and the Paul-Ehrlich-Institut share responsibilities according to product category. BfArM is responsible for conventional medicinal products and a large proportion of medical devices, while the PEI is responsible for vaccines, blood products, advanced therapy medicinal products, allergens and antibodies. Inspections and day-to-day regulatory oversight are carried out by the state authorities and coordinated by the ZLG.
- What do the EU GMP Guidelines cover, and why are they relevant to computerised systems?
The EU GMP Guidelines (EudraLex Volume 4) set out requirements for quality management, manufacturing processes, documentation and controls. For electronic quality management systems, the most relevant sections are Chapter 4 (Documentation), Annex 11 (Computerised Systems), and the new Annex 22 (Artificial Intelligence).
- What is the difference between the AMG and the AMWHV?
The German Medicinal Products Act (AMG) provides the overarching legal framework for the development, manufacture, authorisation, supply, and monitoring of medicinal products. The Ordinance on the Manufacture of Medicinal Products and Active Substances (AMWHV) provides more detailed requirements for manufacture, testing, storage, and distribution. It explicitly refers to the EU GMP Guidelines, making them binding for manufacturing in Germany.
- Are ISO 13485 and ISO 14971 legally mandatory?
There is no direct legal requirement to apply these standards. However, both are recognised as reflecting the state of the art and are referenced in regulatory requirements. The obligation therefore arises indirectly, and in practice, their application is virtually unavoidable.
- What is the difference between legislation and guidelines?
Laws and regulations are legally binding and define what is required. Guidelines issued by organisations such as PIC/S, ICH or ISPE describe how these requirements can be implemented using a risk-based and practical approach. They do not replace binding requirements, but complement them.
- What does 21 CFR Part 11 mean for electronic signatures?
21 CFR Part 11 sets out the FDA requirements for electronic records and electronic signatures. Companies determine which records are subject to GxP requirements. The system used must then ensure that signatures are uniquely attributable, traceable, and protected against alteration.
- Why is an outdated document version a regulatory problem?
Because manufacturing must only be carried out in accordance with the approved, current instructions. If an outdated version is used, the manufacturing process is considered uncontrolled from a regulatory perspective. This can result in deviations from specifications, batch recalls and, in extreme cases, a production shutdown.
- What requirements does this create for an eQMS?
An electronic quality management system must provide document control that prevents outdated versions from continuing to be used. It must also provide a complete audit trail, electronic signatures compliant with Part 11, embedded ALCOA+ principles for data integrity, and validation based on recognised approaches such as ISPE GAMP® 5.

