The original Annex 11 was written for computerised systems installed inside a company's own data centre. A decade of SaaS adoption later, the revision addresses the questions practitioners have been answering by analogy: who validates what, how supplier oversight works when you cannot audit the infrastructure yourself, and what continuous delivery means for a validated state.
What the revision clarifies
- Cloud and SaaS deployment models are explicitly in scope rather than an exception.
- Accountability for compliance cannot be transferred to the supplier under any contract.
- Supplier assessment must be risk-based, documented and periodically refreshed.
- Audit trails must be secure, reviewable and outside the reach of ordinary users.
- Data must remain retrievable in a readable form for the full retention period.
The shared responsibility model
Every cloud QMS engagement should be accompanied by a written responsibility matrix agreed with the supplier and referenced in the validation plan. Ambiguity in this document is where most inspection findings originate.
| Activity | Supplier | Regulated company |
|---|---|---|
| Infrastructure qualification | Owns | Reviews evidence |
| Platform release testing | Owns | Assesses impact |
| Configuration and workflows | Supports | Owns |
| User access and periodic review | Provides tooling | Owns |
| Process validation and UAT | Supports | Owns |
| Backup and disaster recovery | Owns | Verifies and tests restore |
| Audit trail review | Provides tooling | Owns |
| Data retention and archive | Owns storage | Owns policy and evidence |
Supplier assessment done properly
- 1Assess the supplier's quality management system and development lifecycle, not just certifications.
- 2Review actual validation deliverables from a recent platform release.
- 3Test the escalation and incident notification path before you need it.
- 4Confirm data residency, sub-processor list and exit provisions in writing.
- 5Schedule periodic reassessment tied to risk, typically annually for GxP-critical platforms.
Validation in a continuous release world
SaaS platforms update continuously. Annual revalidation is therefore both wasteful and ineffective. The workable model is a standing impact assessment process supported by automated regression evidence from the supplier and targeted verification of your own configured processes.
Continuous validation cycle
Release notice
Supplier provides advance notice with change classification.
Impact assessment
Quality assesses GxP relevance against configured processes.
Targeted testing
Risk-based verification of affected workflows only.
Evidence capture
Results filed against the validation package automatically.
Periodic review
Cumulative assessment confirms the validated state holds.
Validation is a state you maintain, not a project you finish.
Practical readiness checklist
- Signed responsibility matrix referenced in the validation plan.
- Current supplier assessment with evidence, not just a completed questionnaire.
- Documented data residency, retention and retrieval demonstration.
- Audit trail review procedure with defined critical events and frequency.
- Tested restore from backup within the last twelve months.
- Change impact assessment records for every platform release since go-live.