· ERES COMPLIANCE

21 CFR Part 11 — Electronic Records and Signatures

21 CFR Part 11 establishes the conditions under which FDA will accept electronic records and electronic signatures as equivalent to paper records and handwritten signatures for regulated activities. It applies broadly across FDA-regulated GxP domains and sets expectations for system controls — validation, audit trails, access controls, and signature manifestations — that recur throughout modern GxP computerised-system practice.

What an explainer is not

A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 22 LINKS

Part 11 does not decide which records you must keep — a predicate rule does that. It decides what must be true of a record once you keep it electronically, which is why scoping it wrongly is the commonest failure.

06 · QUALITY MATURITY — 21 CFR PART 11 — ELECTRONIC RECORDS AND SIGNATURES, REACTIVE TO ADAPTIVE

L1
Reactive

Compliance is asserted from a vendor statement. Nobody at the site has listed which records are in scope or why.

L2
Defined

A scope assessment exists per system, but it was answered system by system rather than record by record, so it says "yes" or "no" to things that are partly both.

L3
Controlled

Scope derives from the predicate rules that require the records, audit trails are configured and actually reviewed, and signature manifestations carry meaning as well as identity.

L4
Predictive

Audit-trail review is risk-targeted rather than exhaustive, and what it finds feeds investigations rather than being filed as evidence of review.

L5
Adaptive

The record’s integrity is a property of how the system is designed and operated, so compliance is demonstrated by running the process rather than assembled for an inspection.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 3

Derived from the 3 standards SPEQ maps to this subject, across 3 regulatory bodies: FDA, EMA, MHRA.

RECORDS & OBJECTIVE EVIDENCE

  • The record inventory, with the predicate rule that requires each record
  • Audit-trail configuration, and evidence of review with what the review examined
  • Signature manifestations showing name, date, time and the meaning of the signing
  • Access control records tying each account to one identified individual
  • Copy and retention arrangements demonstrating records remain readable and complete

COMMON INSPECTION FINDINGS

  • Scope asserted at system level, leaving in-scope records inside an out-of-scope system
  • Audit trails enabled but never reviewed, or reviewed with no record of what was looked at
  • Shared or generic accounts on systems producing regulated records
  • Signature meaning absent, so the record shows who but not what they were attesting
  • Compliance resting on a vendor claim with no site assessment behind it
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

Scope and Applicability

Part 11 applies to records that are created, modified, maintained, archived, retrieved, or transmitted electronically in place of a paper record, and to electronic signatures intended to be the legally binding equivalent of a handwritten signature, for records required to be maintained under any predicate FDA regulation (such as 21 CFR 211 for drug GMP). It is a controls rule layered on top of predicate requirements, not a standalone recordkeeping obligation.

A 2003 FDA guidance narrowed enforcement discretion in practice — focusing primarily on audit trail, record retention and copying, and legacy-system considerations — but the regulation’s text and its scope remain in force; the guidance describes enforcement approach, not a reduction of the rule.

Core System Controls

For closed systems, Part 11 expects validation demonstrating accuracy, reliability, and consistent intended performance; the ability to generate accurate and complete copies of records; protection of records to enable their accurate and ready retrieval; limiting system access to authorised individuals; and computer-generated, time-stamped audit trails that independently record operator entries and actions creating, modifying, or deleting electronic records, without obscuring previously recorded information.

Additional controls include operational system checks that enforce permitted sequencing of steps, authority checks confirming an individual’s authorisation to perform a given operation, and device checks that validate the source of data input where appropriate.

Electronic Signatures

Electronic signatures under Part 11 must be unique to one individual, never reused or reassigned, and verified before assignment. Each signed record must clearly show the printed name of the signer, the date and time of signing, and the meaning of the signature (such as review, approval, or authorship). Signature manifestations must be linked to their respective record such that the signature cannot be excised, copied, or transferred to falsify another record.

Part 11 vs. EU Annex 11

EU GMP Annex 11 covers similar ground for computerised systems in the EU/EEA — validation, data integrity, audit trails, access control — but is structured as a GMP annex rather than a records-equivalence rule, and its specific control language differs from Part 11’s. Multinational organisations typically design a single computerised-system control framework broad enough to satisfy both, rather than maintaining two parallel compliance programs.

SPEQ interpretation: audit trail review is where Part 11 compliance is most often tested in practice — having an audit trail configured is necessary but not sufficient; the organisation must also be able to demonstrate it is periodically reviewed as part of routine data-integrity oversight, which is where paper-only compliance programs tend to fall short.

FREQUENTLY ASKED

Does Part 11 require every FDA-regulated record to be electronic?

No. Part 11 sets conditions for when electronic records and signatures are acceptable as equivalents; organisations may still use paper records, and a hybrid paper/electronic approach is common, though it introduces its own data-integrity risks that must be managed.

Is a scanned handwritten signature on a PDF an “electronic signature” under Part 11?

Generally no in the intended Part 11 sense — the rule contemplates signatures generated and controlled within an electronic signing system meeting its specific criteria (uniqueness, non-repudiation, linkage to the record), not a static image of a wet signature pasted into a document.

What is the difference between an audit trail and a signature manifestation?

An audit trail is the system-level, time-stamped record of who did what and when across the record’s lifecycle; a signature manifestation is the specific displayed element on a signed record showing who signed, when, and with what meaning. Part 11 requires both, and they serve different verification purposes.

PROFESSIONAL · INSPECTION PLAYBOOK · SPEQ SYNTHESIS

The inspection-readiness playbook for this topic

CHECKING ACCESS

Checking your Professional access…