21 CFR Part 11 Compliance: Audit Trails, E-Signatures, and Validation

Complying with 21 CFR Part 11 means running your electronic recordkeeping and electronic signature systems so the FDA treats their outputs as equivalent to paper records and handwritten signatures. That requires validated software, secure audit trails, enforced access controls, signatures that are permanently bound to the records they authenticate, and a written certification to the FDA that your electronic signatures are intended as the legal equivalent of ink. The rule has been in effect since August 20, 1997, and it reaches any organization that keeps FDA-regulated records digitally: pharmaceutical and device manufacturers, biotech firms, food processors, blood banks, clinical research organizations, and contract labs.1eCFR. 21 CFR 11.1 – Scope

When Part 11 Actually Applies

Part 11 does not create recordkeeping obligations on its own. It attaches whenever some other FDA regulation, called a predicate rule, already requires you to keep a record or capture a signature, and you satisfy that requirement electronically. Predicate rules include current good manufacturing practice for finished pharmaceuticals, the quality system regulation for medical devices, and the rules governing investigational new drug applications and clinical trials. The predicate rule tells you what to record and how long to keep it. Part 11 tells you how to keep it in electronic form so the FDA considers it trustworthy.2Food and Drug Administration. Part 11, Electronic Records; Electronic Signatures – Scope and Application

Two boundaries save a lot of confusion. Paper records that happen to travel by email, such as a scanned PDF of a hand-signed form, are outside Part 11. And if your organization keeps paper as the official record and only scans copies for convenience, the scans are treated as copies, not regulated electronic records, and Part 11’s audit trail, access, and validation requirements do not apply to them.1eCFR. 21 CFR 11.1 – Scope2Food and Drug Administration. Part 11, Electronic Records; Electronic Signatures – Scope and Application

Closed Systems and Open Systems

The regulation splits electronic environments into two categories, and the split changes what you have to build.

A closed system is one where the people responsible for the record content also control access to the system. A validated laboratory information management system running on internal servers reached through managed workstations is a closed system, and the technical requirements in Section 11.10 are written for that setting.3eCFR. 21 CFR 11.10 – Controls for Closed Systems

An open system is one where the record creator does not fully control access, such as records moving across the public internet or sitting on infrastructure a third party manages. Open systems must meet every closed-system control and add protections like document encryption and digital signature standards to preserve authenticity and confidentiality in transit and at rest.4eCFR. 21 CFR 11.30 – Controls for Open Systems

Technical Controls You Need in Place

Section 11.10 describes the controls every compliant closed system must have. They work together to make records accurate, changes traceable, and users accountable.

Audit Trails

The system must generate secure, computer-created, time-stamped audit trails that independently record every operator action that creates, changes, or deletes a record. Changes cannot overwrite prior data. The original entry stays visible, with the modification recorded next to it. Audit trail records must be kept at least as long as the underlying electronic records and must be available for FDA review.5eCFR. 21 CFR Part 11 – Electronic Records; Electronic Signatures

Authority, Operational, and Device Checks

Authority checks limit what each user can do based on their role. The system has to enforce those distinctions automatically rather than lean on policy. Not everyone who can view a record should be able to sign it. Not everyone who can enter data should be able to delete it.3eCFR. 21 CFR 11.10 – Controls for Closed Systems

Operational checks enforce the correct sequence of steps. If data must be reviewed before it can be approved, the system should block approval until the review is done. Device checks confirm data is coming from a legitimate source, such as a specific laboratory instrument or validated terminal.3eCFR. 21 CFR 11.10 – Controls for Closed Systems

Copies for FDA Inspection

The system must produce accurate, complete copies of records in both human-readable form (a printout or on-screen display) and electronic form the FDA can review and copy. If there is doubt about whether inspectors will be able to perform that review, the regulation directs firms to raise it with the agency in advance.3eCFR. 21 CFR 11.10 – Controls for Closed Systems

Electronic Signature Requirements

Part 11 gives electronic signatures the same legal weight as handwritten signatures when they meet specific criteria. The requirements cover what the signature displays, how identity is verified, and how the signature stays attached to the record.

What Each Signature Must Show

Every signed electronic record must clearly display the printed name of the signer, the date and time of execution, and the meaning of the signature, such as review, approval, responsibility, or authorship. This information has to appear in any human-readable rendering of the record, on screen or in print.6eCFR. 21 CFR 11.50 – Signature Manifestations

Verifying Identity

Two approaches are recognized. Biometric signatures use a measurable physical characteristic like a fingerprint or retinal scan and must be designed so no one but the owner can execute them.7eCFR. 21 CFR 11.200 – Electronic Signature Components and Controls

Non-biometric signatures need at least two distinct identification components, typically a user ID and a password. In a single continuous login session, the first signing requires both components, and later signings within that session require at least one component that only the signer can execute. If the session breaks and the user signs again later, both components are required again for every signing.7eCFR. 21 CFR 11.200 – Electronic Signature Components and Controls

Whichever method you use, each signature must be unique to one person and can never be reused or reassigned. Before issuing a signature, the organization must verify the individual’s identity.8eCFR. 21 CFR 11.100 – General Requirements

Binding the Signature to the Record

Electronic signatures must be permanently linked to their records so the signature cannot be cut out, copied, or moved to another record. This is the non-repudiation principle. Once you sign, the system has to make it impossible for you to credibly deny the action or for anyone to transfer your signature onto a falsified record.5eCFR. 21 CFR Part 11 – Electronic Records; Electronic Signatures

The Certification Letter to the FDA

Before using electronic signatures, or at the time you start using them, your organization must submit a certification to the FDA stating that the electronic signatures in your system are intended to be the legally binding equivalent of handwritten signatures. The certification itself must be signed by hand and can be submitted on paper or electronically. The FDA can also request additional certification that a specific electronic signature is equivalent to a signer’s handwritten signature. Skipping this step undermines the legal standing of every electronic signature in your system.8eCFR. 21 CFR 11.100 – General Requirements

Password and Credential Controls

Section 11.300 sets rules for systems that use user ID and password combinations rather than biometrics, and they go past typical IT policy.

No two people can share the same user ID and password combination. Credentials must be periodically reviewed, recalled, or updated to handle events like password aging. If a token, card, or other credential-generating device is lost or stolen, procedures have to deactivate it right away and issue a replacement under controlled conditions.9eCFR. 21 CFR 11.300 – Controls for Identification Codes/Passwords

The system must guard against unauthorized password use and detect and report unauthorized access attempts immediately. “Immediately” rules out satisfying the requirement through a weekly security log review.9eCFR. 21 CFR 11.300 – Controls for Identification Codes/Passwords

Validation and Documentation

Having the right features installed is not compliance. A compliant system has been formally tested and documented to show it works as intended. Validation generally moves through three phases: installation qualification, which confirms hardware and software are correctly installed and configured; operational qualification, which tests whether the system functions correctly within specified parameters under working conditions; and performance qualification, which shows the system performs reliably in actual production with real personnel, materials, and settings. Failures at any phase have to be documented and resolved before the next.

Around the validation record, you need standard operating procedures that cover how the environment is managed day to day: user roles, system limitations, data backup, and security protocols. Personnel records have to show every user has been trained on both the technical operation of the system and the regulatory requirements it must satisfy. Records of who holds administrative access, along with validation test results, have to be kept current and available for inspection.

How the 2003 FDA Guidance Changes the Picture

In 2003 the FDA issued guidance narrowing enforcement of Part 11 while it reexamined the rule. The regulation still stands as written, but the agency said it would exercise enforcement discretion in specific areas.2Food and Drug Administration. Part 11, Electronic Records; Electronic Signatures – Scope and Application

  • Validation: the agency will not enforce Part 11’s validation requirements beyond what the predicate rule already requires.
  • Audit trails: the agency will not enforce Part 11’s audit trail provisions, though predicate rule requirements to document dates, times, and changes still apply.
  • Record retention: the agency will not enforce Part 11’s specific protections for retrieval throughout the retention period.
  • Record copies: the agency will not enforce Part 11’s specific requirements for generating copies of electronic records.

This is not a pass. Predicate rule requirements for validation, documentation, and record integrity remain fully enforceable, and firms that treat the 2003 guidance as a blanket exemption tend to discover during inspections that the predicate rules demanded most of the same controls. The practical effect is that the FDA evaluates your system primarily against the substantive requirements of the underlying regulation rather than the technical text of Part 11 standing alone.2Food and Drug Administration. Part 11, Electronic Records; Electronic Signatures – Scope and Application

Cloud and SaaS Deployments

When regulated records sit on infrastructure a cloud service provider manages, compliance does not transfer to the vendor. The regulated company remains responsible for meeting Part 11. Cloud environments typically qualify as open systems, so they must satisfy every closed-system control plus additional measures such as encryption.

In practice this is a shared-responsibility model. The vendor supplies the infrastructure, and your organization writes the validation plan, runs the testing, maintains the documentation, and shows the system reliably performs its intended function. Contracts should explicitly cover validation obligations, data security responsibilities, and the vendor’s duty to facilitate FDA inspections. Because cloud platforms change continuously through updates and scaling, validation is not a one-time event. Your validation program has to account for ongoing change.

Data Integrity: The ALCOA+ Lens

Part 11 supplies the regulatory framework, but the FDA judges electronic records against a broader set of data integrity expectations captured by the acronym ALCOA+. Regulated data should be attributable to the person who generated it, legible and permanently recorded, contemporaneous with the action it documents, kept as the original record or a certified true copy, and accurate. The “plus” adds completeness, consistency, endurance across the retention period, and availability. These are not a separate regulation, but they are the standard inspectors use when they assess whether your electronic records can be trusted.

What an FDA Inspection Looks For

During a site inspection, FDA investigators typically request your validation documentation, standard operating procedures, training records, and access to the live system’s audit trails. The review focuses on whether the controls described in your documentation actually work in the production environment. Inspectors check that audit trails capture the required information, that access controls prevent unauthorized actions, and that electronic signatures meet the display and linking requirements.

If investigators identify conditions that may violate FDA regulations, they document their observations on an FDA Form 483. A Form 483 is not a final agency determination that a violation occurred. It is a list of observations the agency considers alongside the full inspection report and any company response before deciding on further action.10U.S. Food and Drug Administration. FDA Form 483 Frequently Asked Questions

Unresolved issues can escalate to a warning letter, and continued noncompliance can lead to product seizures or court injunctions. Criminal penalties also apply for intentional misconduct. Under the Federal Food, Drug, and Cosmetic Act, a first-time violation of FDA recordkeeping requirements carries up to one year in prison and a $1,000 fine. Violations committed with intent to defraud carry up to three years and a $10,000 fine.11Office of the Law Revision Counsel. 21 USC 333 – Penalties