21 CFR Part 11 Compliance Requirements: Controls and Signatures

Complying with 21 CFR Part 11 means putting specific technical and procedural controls around any electronic record or electronic signature you use in place of paper to satisfy an FDA recordkeeping requirement. The rule sits on top of other FDA regulations rather than replacing them, so the compliance requirements of 21 CFR Part 11 only activate when an underlying regulation — a predicate rule — already requires you to keep or submit the record. Get that scoping question right, then work through the controls, signatures, validation, and documentation the regulation demands.

When Part 11 Actually Applies

Part 11 applies to records in electronic form that are created, modified, maintained, archived, retrieved, or transmitted under any records requirement set forth in FDA regulations, and to electronic records submitted to the agency under the Federal Food, Drug, and Cosmetic Act or the Public Health Service Act.1eCFR. 21 CFR 11.1 – Scope

The predicate rules are the existing FDA regulations that require you to maintain or submit those records in the first place. Good Manufacturing Practice regulations (21 CFR Parts 210 and 211), clinical trial recordkeeping under 21 CFR Part 312, and medical device quality system regulations under 21 CFR Part 820 are common examples. When a company keeps those required records electronically instead of on paper, Part 11 kicks in.2Food and Drug Administration. Part 11, Electronic Records; Electronic Signatures – Scope and Application

Records that no predicate rule requires you to keep are not Part 11 records, even if you store them electronically. Paper records transmitted electronically — a faxed signed document, for instance — also fall outside the scope.1eCFR. 21 CFR 11.1 – Scope Compliance work should start by inventorying which of your electronic records are actually subject to predicate rules.

Controls for Closed Systems

A closed system is one where the people responsible for the electronic records also control who can access the system.3eCFR. 21 CFR 11.3 – Definitions Most regulated organizations operate closed systems, and Section 11.10 sets out the controls those systems must have:

  • Systems must be validated to ensure accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records.
  • The system must generate accurate, complete copies of records in both human-readable and electronic form so FDA investigators can review them without proprietary software.
  • Records must be protected to allow accurate and ready retrieval throughout the retention period.
  • System access must be limited to authorized individuals.
  • Secure, computer-generated, time-stamped audit trails must independently record when operators create, modify, or delete records, and changes cannot obscure previously recorded information.
  • The system must enforce the correct sequencing of steps and events where appropriate.
  • Authority checks must ensure only authorized individuals use the system, sign records, alter records, or perform specific operations.
  • Device checks must verify the validity of data input sources or operational instructions.
  • Everyone who develops, maintains, or uses the system must have the education, training, and experience for their assigned tasks.
  • Written policies must hold individuals accountable for actions taken under their electronic signatures, specifically to deter falsification.
  • Documentation for system operation and maintenance must be controlled, including revision and change controls.
4eCFR. 21 CFR 11.10 – Controls for Closed Systems

That last item on systems documentation trips up companies that focus only on data integrity. You need version histories for the operating procedures and system configurations themselves, not just the records inside the system.

Extra Controls for Open Systems

An open system is one where the people responsible for the electronic records do not control who can access the system.3eCFR. 21 CFR 11.3 – Definitions Cloud-hosted platforms where access extends beyond internal company control can fall into this category. Open systems must include all the closed-system controls above, plus additional measures such as document encryption and appropriate digital signature standards to ensure record authenticity, integrity, and confidentiality from creation through receipt.5eCFR. 21 CFR 11.30 – Controls for Open Systems

If your system qualifies as open, encryption and digital signature technology become regulatory requirements rather than optional security upgrades. Any company moving regulated records to a cloud platform should evaluate the open-versus-closed question before configuring controls.

Audit Trail Expectations

Audit trails draw more scrutiny during FDA inspections than almost any other Part 11 control because they are the primary way inspectors detect data manipulation. Section 11.10(e) requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and any actions that create, modify, or delete records. Changes cannot obscure the original information, and the audit trail must be retained at least as long as the underlying record and be available for FDA review.4eCFR. 21 CFR 11.10 – Controls for Closed Systems

FDA guidance on data integrity goes further than the regulation text. The agency expects audit trails to be reviewed with each record and before that record is approved, not just during periodic audits. The reviewer must have the knowledge and authority to evaluate the audit trail for changes, deletions, or modifications, and to confirm the record is complete, accurate, and reliable. Frequency and depth of review should reflect the complexity and risk of the data.6Food and Drug Administration. Data Integrity and Compliance With Drug CGMP – Questions and Answers

An audit trail that exists but nobody reviews before approving records is a common finding. Inspectors look at whether audit trail review is built into routine workflows, not merely available on request.

Electronic Signature Requirements

Part 11 treats electronic signatures as legally equivalent to handwritten signatures when specific conditions are met. The requirements cover what appears with the signature, how it links to the record, what components it uses, and general controls over identity.

Display and Meaning

Every signed electronic record must clearly display the printed name of the signer, the date and time of signing, and the meaning associated with the signature — such as review, approval, responsibility, or authorship. This information must appear in any human-readable version of the record, on screen and in print.7eCFR. 21 CFR Part 11 – Section 11.50

Linking Signatures to Records

Electronic signatures must be linked to their records so that signatures cannot be cut out, copied, or transferred to a different record to falsify information.8eCFR. 21 CFR Part 11 – Section 11.70 If an approval could be detached from one batch record and reattached to another, accountability collapses. Validation testing should include this linkage.

Signature Components

Non-biometric electronic signatures must use at least two distinct identification components, typically a user ID and password. During a single, continuous session of controlled system access, only the first signing requires both components; later signings in that same session need at least one component unique to the individual. Outside a continuous session, every signing requires all components.9eCFR. 21 CFR 11.200 – Electronic Signature Components and Controls

Non-biometric signatures must be used only by their genuine owners, and the system must be designed so that using someone else’s signature would require collaboration of at least two people. Biometric signatures — based on unique physical characteristics — must be designed so that no one other than the genuine owner can use them.9eCFR. 21 CFR 11.200 – Electronic Signature Components and Controls

Uniqueness and Identity Verification

Each electronic signature must be unique to one individual and cannot be reused or reassigned. Before assigning a signature, the organization must verify the individual’s identity.10eCFR. 21 CFR 11.100 – General Requirements Sharing login credentials violates this requirement directly and is one of the most common findings in FDA data integrity investigations.

Filing the Signature Certification With the FDA

Before using electronic signatures — or at the time you begin using them — your organization must certify to the FDA that the electronic signatures in your system are intended to be the legally binding equivalent of handwritten signatures. The certification itself must be signed with a traditional handwritten signature and may be submitted electronically or on paper.10eCFR. 21 CFR 11.100 – General Requirements

The FDA’s page on Letters of Non-Repudiation Agreement provides current submission instructions, and electronic submission through the FDA’s Unified Submission Portal is available.11Food and Drug Administration. Letters of Non-Repudiation Agreement Keep a copy of the certification in your regulatory files. On request, you may also need to provide additional testimony that a specific electronic signature is the legally binding equivalent of the signer’s handwritten signature.

Validation, Procedures, and Training

Validation is the first control listed under Section 11.10 because without it you have no documented evidence that the system works as intended. Validation is not a one-time event: after significant changes such as software updates, hardware replacements, or configuration changes, revalidation is needed to confirm the system still meets its specifications. Periodic reviews should assess whether the validated state has been maintained, and both initial validation and ongoing reviews should be documented.

Standard Operating Procedures should cover system maintenance, data backup, user access management, and the audit trail review process. Version control on those SOPs lets inspectors see what procedures were in effect at any point in time.

Training records deserve particular attention because Section 11.10(i) requires that people who develop, maintain, or use electronic record systems have adequate education, training, and experience.4eCFR. 21 CFR 11.10 – Controls for Closed Systems Training records should show who was trained, when, on what topics, and whether they demonstrated competency. If those records live in an electronic system, that system is itself subject to Part 11.

Record Retention

Part 11 requires that records be protected for accurate and ready retrieval throughout the retention period, and audit trail documentation must be kept at least as long as the underlying records.4eCFR. 21 CFR 11.10 – Controls for Closed Systems Part 11 itself does not set specific retention timeframes; those come from the predicate rules that govern each type of record. Identifying the applicable predicate rule for each record type is essential for setting accurate retention schedules.

Cloud Platforms and Third-Party Vendors

Moving regulated systems to a cloud platform does not transfer compliance responsibility. The regulated company remains accountable for Part 11 compliance regardless of where the system is hosted, and the shared responsibilities need to be defined in writing before implementation.

Contracts with cloud service providers should clearly assign responsibility for system validation, data security, and audit facilitation. When evaluating vendors, look for established security certifications such as ISO 27001 and SOC 2, and confirm the provider supports the access controls, audit trail capabilities, and data integrity protections Part 11 demands. Data ownership needs explicit contractual treatment so you retain access to your data and audit trails if you change providers.

Cloud environments raise one issue on-premise systems do not. The provider may update infrastructure or configurations without your direct involvement, so validation cannot be treated as static. Regulated companies need mechanisms to monitor changes in the cloud environment and revalidate when those changes could affect the system’s validated state.

The FDA’s Enforcement Discretion

In a 2003 guidance document that remains in effect, the FDA announced it would exercise enforcement discretion for certain Part 11 requirements while it re-examined the regulation. The agency said it would not take enforcement action for the validation, audit trail, record retention, and record copying requirements of Part 11 as standalone Part 11 obligations.12Food and Drug Administration. Part 11, Electronic Records; Electronic Signatures – Scope and Application

Those controls are not optional. The FDA continues to enforce all predicate rule requirements, so if a predicate rule requires validated systems, complete records, or data integrity controls, those obligations still apply under the predicate rule. Most companies implement the full Part 11 controls anyway because the predicate rule requirements largely overlap.

The FDA does actively enforce other Part 11 provisions, including access controls, operational system checks, authority checks, device checks, training requirements, accountability policies, systems documentation controls, and all electronic signature requirements under Sections 11.50, 11.70, 11.100, 11.200, and 11.300.12Food and Drug Administration. Part 11, Electronic Records; Electronic Signatures – Scope and Application

Enforcement discretion also covers systems that were operational before August 20, 1997, the effective date of Part 11. Those legacy systems are not held to Part 11’s technical requirements, though the underlying predicate rule obligations apply in full.12Food and Drug Administration. Part 11, Electronic Records; Electronic Signatures – Scope and Application

What Non-Compliance Costs

FDA enforcement escalates. Inspections typically end with a Form 483 listing observations the investigator identified as possible violations. A Form 483 is not a final agency determination, and the company can respond.13Food and Drug Administration. FDA Form 483 Frequently Asked Questions A weak response or failure to correct the issues can lead to a Warning Letter, which puts the company on public record for regulatory deficiencies.

Beyond Warning Letters, the FDA can pursue injunctions, consent decrees, import bans, and debarment. Consent decrees for data integrity failures have historically cost companies hundreds of millions of dollars in remediation, third-party auditing, and operational disruption. The agency can also debar individuals and firms from participating in FDA-regulated activities under 21 U.S.C. § 335a.14Food and Drug Administration. FDA Debarment List (Drug Product Applications)

Criminal penalties reach further. Violating the FD&C Act’s prohibited acts, which include failing to maintain required records and submitting false reports, carries up to one year of imprisonment and a $1,000 fine for a first offense. If the violation involves intent to defraud or mislead, or follows a prior conviction, penalties rise to up to three years and $10,000. Specific violations such as knowingly adulterating drugs with a reasonable probability of causing serious harm reach up to 20 years and $1,000,000.15Office of the Law Revision Counsel. 21 USC 333 – Penalties

Reputational damage compounds the direct costs. Warning Letters and enforcement actions are public. Inspection findings are shared among global regulators through mutual recognition agreements, so a data integrity failure discovered by the FDA can trigger heightened scrutiny from European, Canadian, and other regulatory authorities at the same time. For contract research and manufacturing organizations, a single enforcement action can trigger client departures that dwarf the direct regulatory costs.