A document management system (DMS) for pharma compliance is a validated system that controls how GMP documents are created, reviewed, approved, distributed and retired. It enforces version control, audit trails, electronic signatures and role-based access, so that you can show an inspector that every document is current, approved and traceable. In the EU, the key requirements come from EU GMP Chapter 4 and Annex 11. If you export to the US, FDA 21 CFR Part 11 also applies. Medtech companies additionally follow ISO 13485 and MDR/IVDR.
This guide covers what the regulations require, how the EU GMP rules for computerized systems are changing, and how to evaluate and implement a DMS in a Nordic life science organization.
A pharma DMS is a platform that controls the full lifecycle of regulated documents, from draft through review, approval, distribution, periodic review and archiving. It is not file storage. It is a governing system that ensures only approved versions are in use and that every action is logged.
In a GMP environment, documents carry regulatory weight. SOPs, work instructions, specifications, validation protocols and risk assessments determine how work is actually done. If an outdated SOP is still circulating, that is not just an administrative problem. It is a potential product quality risk and an inspection finding.
General file-sharing tools, such as SharePoint, can store documents, but they don't enforce controlled workflows, compliant electronic signatures or complete audit trails out of the box. Making them GMP-compliant usually requires extensive configuration, add-ons and validation work. That often costs more than a purpose-built system.
The practical test is simple. If an inspector asks for the complete version history of a specific SOP (who changed what, when, why, and who approved it), can you produce it in minutes? With a purpose-built DMS the answer is yes, because the system records it automatically. With shared folders and email approvals, the answer is usually a manual reconstruction.
The requirements depend on your products and markets. This table summarizes the most important frameworks:
| Framework | Applies to | What it requires of your DMS |
|---|---|---|
| EU GMP Chapter 4 | Medicinal product manufacturers in the EU/EEA | Good documentation practice, document control, data integrity (ALCOA+/ALCOA++) |
| EU GMP Annex 11 | Computerized systems used in GMP activities | Validation, audit trails, access control, electronic signatures, supplier oversight |
| ICH Q10 | Pharmaceutical quality systems | Document control as part of a lifecycle-based quality system |
| FDA 21 CFR Part 11 | Electronic records and signatures for the US market | Audit trails, e-signatures linked to a verified identity, system validation |
| ISO 13485 (clauses 4.2.4–4.2.5) | Medical device manufacturers | Control of documents and records |
| EU MDR / IVDR (Article 10) | Medical device and IVD manufacturers in the EU | A quality management system including documentation and change control |
Chapter 4 sets the rules for GMP documentation in general. Annex 11 covers the computerized systems that manage it. Together they require that electronic records are accurate and protected, that access is limited to authorized users, that every change is captured in an audit trail, and that the system is validated for its intended use.
ICH Q10 describes the pharmaceutical quality system that document control is part of. ICH Q9(R1) describes quality risk management. That is why regulators expect your validation and review efforts to be risk-based, not uniform.
If your products or data reach the US market, Part 11 governs electronic records and signatures. It requires audit trails, controls for system access, validation, and electronic signatures that are uniquely linked to one individual and show the meaning of the signature, such as "reviewed" or "approved".
For medical device manufacturers, ISO 13485 sets the requirements for document and record control. EN ISO 13485 is harmonized under MDR, but it does not cover every MDR or IVDR obligation. Your system therefore needs to support requirements beyond the standard, for example around technical documentation and post-market surveillance.
The current Annex 11 dates from 2011, long before cloud services and AI were part of everyday GMP work. The European Commission, EMA and PIC/S have therefore revised Chapter 4 and Annex 11 and introduced a new Annex 22 on artificial intelligence.
The changes that matter most for document management:
In practice, the direction is clear: regulators expect data integrity, supplier oversight and audit trail review to be built into the system and your routines, not handled afterwards. A gap assessment of your current document control against the revised texts is a good starting point.
A pharma DMS must, at minimum, enforce these six capabilities through the system itself, not through manual routines:
| Capability | What to look for |
|---|---|
| Version control | Only the approved version is available; earlier versions are retained and comparable |
| Audit trail | Automatic and tamper-proof; captures who, what, when and why, and can be reviewed |
| Electronic signatures | Linked to a verified identity, with timestamp and meaning; compliant with Annex 11 and, where relevant, Part 11 |
| Role-based access | Permissions to draft, review, approve and read, governed by role, unit and competence |
| Workflow automation | Configurable review and approval routes, reminders and escalation |
| Lifecycle management | Periodic review, retention and disposal rules, and archiving that preserves the audit trail |
A strong audit trail records more than the change itself. It captures the context: which workflow step triggered the change, who approved it and what justification was given. Manual logging is neither reliable nor acceptable.
Email-based review cycles create delays and gaps. Look for a system where your quality team can configure workflows without a consultant. Otherwise, every regulatory change becomes a vendor project.
Evaluate a DMS in five steps: map your requirements, define your document types and workflows, assess validation support, check integrations, and test configurability with your own documents.
A cloud-based DMS moves infrastructure, security patching and release testing to the vendor. That frees your team to focus on quality work. It doesn't move regulatory responsibility. The revised Annex 11 makes it clear that you must oversee your supplier, assess each update and retain access to the documentation you need.
What to look for:
Nordic companies face the same EU regulations as the rest of Europe, with a few practical differences.
Document control and risk management depend on each other. When a risk is identified, the SOPs and work instructions it affects must be reviewed. When a document changes, the linked risks should be reassessed. ICH Q9(R1) expects this link to be systematic.
The practical consequence is that the DMS should not stand alone. When deviations, CAPA, risk assessments and document changes live in the same system, you can trace a deviation to its root cause, the corrective action and the updated governing document, without searching across tools. Read more about moving from document management to governance that works in practice.
A structured implementation follows four phases:
Choosing a DMS for pharma compliance is a governance decision as much as a technology decision. Start with your regulatory requirements, including the revised Chapter 4 and Annex 11. Map your document types and workflows. Then evaluate vendors on concrete criteria: validation support, audit trails, configurability and how well document control connects to deviations, risk and training.
Done right, document control stops being an administrative burden. Every document is current, every change is traced, and every approval can be verified.
Centuri is a modern, user-friendly and configurable quality management system used by Nordic life science organizations. Document management is connected with case management, risk management, competence management and process mapping in one platform. Each release is tested and validated by Centuri, and the electronic signature function meets the requirements of FDA 21 CFR Part 11. Learn more about Centuri for life science.
Book a demo – see how your SOP approval flow would work in Centuri.
A GxP-compliant DMS enforces version control, tamper-proof audit trails, compliant electronic signatures and role-based access. It must also be validated for its intended use following a risk-based approach such as GAMP 5. No system is compliant on its own. Compliance also depends on how you configure, validate and use it.
It is possible, but it requires significant configuration, add-ons and validation to provide controlled approval workflows, compliant electronic signatures and complete audit trails. Many life science companies find that a purpose-built system is faster and cheaper to validate and maintain.
A DMS handles document control. An eQMS (electronic quality management system) also covers deviations, CAPA, change control, risk management, audits and training. In a regulated environment, the benefit of an eQMS is that document changes can be linked directly to the deviations and risks that triggered them.
The revision strengthens requirements on data integrity, audit trail review, electronic signatures, identity and access management, and oversight of cloud and SaaS suppliers. It comes together with a revised Chapter 4 and a new Annex 22 on AI, and reflects how GMP work is increasingly done in digital and cloud-based systems.
Yes. Centuri's electronic signature function meets the requirements of FDA 21 CFR Part 11, including password management. Each release is tested and validated against requirements such as Part 11, MDR, ISO 13485 and GMP.
Yes. The vendor's release testing reduces your effort, but you are responsible for validating your configuration and intended use, and for assessing each update through change control. Ask the vendor for release notes and validation documentation.
Use a risk-based approach following GAMP 5, typically with installation, operational and performance qualification (IQ, OQ, PQ). Focus on high-risk functions such as electronic signatures, audit trails and access control. Centuri supplies function specifications and supports IQ/OQ/PQ during implementation.
It depends on the number of document types, sites and integrations, and on how much existing content needs to be migrated.