Guide: what the draft Annex 22 requires of AI in GMPRead the guide

Regulation is not an afterthought. It is a design requirement

A system that complies because it was documented afterwards is fragile. One that complies because it was designed that way withstands a new version, a new supplier and a new inspector.

  • Control proportionate to risk
  • Documentation included in the delivery
  • Spain, Portugal and Latin America

First we decide how much control it calls for

Not every system needs the same control.

A pharmaceutical company has systems that affect product quality or patient safety, and systems that handle purchasing or meeting room bookings. Treating them the same is an expensive mistake in both directions.

The first decision in every project is which category the system belongs to and what evidence has to be produced as a result. That decision is documented and justified, because it is the first one you will be asked to explain.

Is the system part of a GxP process?

The documentation is part of the delivery

What you receive besides the software.

This is the documentation index: eleven documents in four phases, from planning to closure. Our method shows at what point in the project each one is delivered.

1. Planning

Validation plan (VP)

Scope and strategy of the validation, responsibilities, and the client's own procedures that apply.

  • Each qualification (DQ, IQ, OQ and PQ) includes its protocol, the execution with the evidence, the deviation log and its report
  • If the system includes AI, the model documentation and its monitoring plan are added
  • After go-live, the plan for maintaining the validated state says what to repeat for each change

Standards we apply

What we apply depending on the scope of the project.

Computerized systems and data integrity

FDA · 21 CFR Part 11
Electronic records and electronic signatures. It determines access control, the content of the audit trail and what signing means inside the system.
EudraLex Annex 11
Computerized systems in the European Union. Supplier management, data, business continuity and change control. Its revision is under way together with Chapter 4, on documentation.
GAMP 5 Second Edition
A risk-based lifecycle, with computer software assurance. Testing effort is concentrated where the risk to the patient justifies it.
ALCOA++
Data integrity: attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, available when needed and traceable, as defined in the EMA guideline on computerized systems and electronic data in clinical trials.
FDA · Computer Software Assurance
Final FDA guidance, from February 2026, with a risk-based approach to testing. It is aimed at medical devices; for medicines, that same approach is the one set out in GAMP 5 Second Edition.

Good practices for each activity

Good Manufacturing Practice
EudraLex Volume 4 and its annexes, for every system that touches production, release or quality control.
FDA · 21 CFR 210 and 211
FDA current Good Manufacturing Practice for medicines, when you manufacture in or export to the United States. Section 211.68 covers automatic, mechanical and electronic equipment, including computerized systems.
ICH E6(R3)
Good Clinical Practice. Data governance, proportionate validation and the sponsor's responsibilities for the trial systems.
Good Laboratory Practice
OECD principles for non-clinical safety studies, and good practice in quality control laboratories, when the system supports that work.
Good Distribution Practice
European guidelines on wholesale distribution: traceability, transport conditions and the handling of returns and falsified medicines.
Good Pharmacovigilance Practices
European Medicines Agency modules, in particular case management systems and the pharmacovigilance system master file.

Artificial intelligence and data protection

EudraLex Annex 22, draft
Artificial intelligence in critical GMP applications: intended use, acceptance criteria, independent test data, explainability, confidence and operation. As of October 1, 2026 it is still a draft. We summarize it in the Annex 22 guide.
FDA and EMA AI principles
Principles of good AI practice in medicines development, published jointly by the two agencies in January 2026. A common governance framework for the models involved in the lifecycle of a medicine.
EU AI Act
Regulation (EU) 2024/1689. Since August 2, 2026 it requires telling people that they are interacting with an AI and marking the content it generates. High-risk systems have their own requirements: from December 2, 2027 those in Annex III, such as recruitment and workforce management, and from August 2, 2028 AI in regulated products, such as medical devices. Most GxP systems are not high-risk under the Regulation, but they remain subject to GMP. When the project includes models: system classification, risk management, training data governance and human oversight.
Data protection
The General Data Protection Regulation in Spain and Portugal, with their national laws, and each country's own law in Latin America, listed in the country table. Always with particular care for health data and trial subject data.

What each country requires

In Spain and Portugal the European Union rules apply. In Latin America, each country's own regulation applies, and it is best read alongside these common references:

PIC/S
Members: Argentina, Brazil and Mexico. Paraguay has adopted its guide since 2026
RTCA
Common regulation for Costa Rica, Panama and Guatemala
FDA
If you export to the United States

Choose one or more countries. With none chosen, all of them are shown.

Authority, good practice standard, computerized system requirement and personal data law by country
CountryAuthority and good practice standardComputerized systemsPersonal data
SpainAEMPS · EU Good Manufacturing Practice, EudraLex Volume 4Annex 11, computerized systemsGDPR and Organic Law 3/2018
PortugalINFARMED · EU Good Manufacturing Practice, EudraLex Volume 4Annex 11, computerized systemsGDPR and its national law
BrazilANVISA · RDC 658/2022IN 134/2022, complementary good practices for computerized systems. Guide 33/2020 as a referenceLGPD, Law 13.709/2018
MexicoCOFEPRIS · NOM-059-SSA1-2015, amended in 2025Section 9.13, validation of computer systemsFederal Law on the Protection of Personal Data Held by Private Parties, 2025
ArgentinaANMAT · Disposition 4159/2023, which adopts the PIC/S guideAnnex 6, computerized systemsLaw 25.326
ColombiaINVIMA · Resolution 1160 of 2016No specific annex: general requirements for electronic records and validationLaw 1581 of 2012
ChileISP · Technical Standard 127Annex 1, validation, which includes computerized systemsLaw 19.628. Law 21.719 replaces it on December 1, 2026
PeruDIGEMID · Supreme Decree 021-2018-SA, Good Manufacturing Practice ManualAssessed in each project according to the ManualLaw 29733
UruguayMSP · Decree 440/016, which adopts Mercosur GMC Resolution 15/09, based on the WHO guideRequirements of the WHO guidance on automated systems and electronic dataLaw 18.331
ParaguayDINAVISA · Resolution 183/2026, which adopts the PIC/S guidePIC/S Annex 11, computerized systems, and Annex 15Law 7593/2025, in force from November 2027
Costa RicaMinistry of Health · Central American Technical Regulation RTCA 11.03.42:07Sections 16.4 j), computer systems, and 11.1.6, electronic dataLaw 8968
PanamaNational Directorate of Pharmacy and Drugs (MINSA) · RTCA 11.03.42:07, adopted by Executive Decree 267 of 2014Sections 16.4 j) and 11.1.6 of the RTCALaw 81 of 2019
GuatemalaMSPAS, Department of Regulation and Control of Pharmaceutical Products · RTCA 11.03.42:07Sections 16.4 j) and 11.1.6 of the RTCANo specific law

13 countries

Regulatory calendar

The dates of the standards on this page, from the Annex 22 consultation to the data laws coming into force.

  1. EU

    Public consultation on the draft Annex 22

    The European Commission published it for consultation together with the revision of Annex 11 and Chapter 4.

    View the Annex 22 guide
  2. Mexico

    COFEPRIS amends NOM-059-SSA1-2015

    Its section 9.13 governs the validation of computer systems.

  3. Mexico

    Federal Law on the Protection of Personal Data Held by Private Parties

    Mexico's personal data protection law, from 2025.

  4. EU

    EU AI Act: prohibited practices and AI literacy

    The prohibited practices apply, along with the duty to promote AI literacy among the staff who use or build AI.

  5. EU and US

    FDA and EMA publish good AI practice principles

    For medicine development: a shared governance framework for the models involved in the medicine lifecycle.

  6. US

    FDA publishes the final Computer Software Assurance guidance

    It is aimed at medical devices. For drugs, the same risk-based approach is the one GAMP 5 Second Edition takes.

  7. Paraguay

    DINAVISA adopts the PIC/S guide

    Resolution 183/2026, with Annex 11, computerized systems, and Annex 15.

  8. EU

    EMA workshop on Annex 22

    Industry experts discuss the control strategy for allowing dynamic, probabilistic and generative AI models.

    View where the text is heading
  9. EU

    EU AI Act: transparency

    People must be told that they are interacting with an AI, and the content it generates must be marked. Enforcement by the authorities begins.

  10. EU

    EMA publishes the workshop report

    It points to a technology-neutral annex: the intended use, the risk and the effectiveness of the controls are what decide.

  11. EU

    Annex 22 is still a draft

    EudraLex Volume 4 contains Annexes 1 to 21. Checked against the official source.

  12. Chile

    Law 21.719 replaces Law 19.628

    Chile's personal data protection law changes.

  13. Paraguay

    Law 7593/2025 comes into force

    Paraguay's personal data protection law.

  14. EU

    EU AI Act: Annex III high-risk systems

    Requirements for high-risk systems, such as recruitment and workforce management. The Digital Omnibus package postponed them from August 2026.

  15. EU

    EU AI Act: high-risk AI in regulated products

    Requirements for AI that is part of regulated products, such as medical devices assessed by a notified body.

15 dates

What level of control does your system call for?

We work it out with you before starting, so you validate neither too much nor too little.