21 CFR Part 11 Compliance Guide
Electronic records and electronic signatures compliance for FDA-regulated systems.
Table of Contents
Part 11 Overview
Scope and Applicability
21 CFR Part 11 applies to electronic records and signatures used to meet FDA predicate rule requirements.
| Applies To |
Does Not Apply To |
| Records required by FDA regulations |
Paper records |
| Records submitted to FDA |
Internal documents not required by regulation |
| Electronic signatures on required records |
Digital communication (email) for general purposes |
| Systems creating/maintaining regulated records |
Non-regulated systems |
Key Terms
| Term |
Definition |
| Electronic Record |
Any combination of text, graphics, data in digital form |
| Electronic Signature |
Computer data compilation intended as legally binding signature |
| Digital Signature |
Electronic signature based on cryptographic methods |
| Closed System |
Environment with controlled access by responsible persons |
| Open System |
Environment with uncontrolled access |
| Audit Trail |
Secure, computer-generated, time-stamped record |
Predicate Rules
Part 11 does not create new record requirements. It governs HOW records are maintained when electronic:
| Predicate Rule |
Record Type |
| 21 CFR 820 (QSR) |
Device Master Records, Device History Records |
| 21 CFR 211 (cGMP) |
Batch records, laboratory records |
| 21 CFR 58 (GLP) |
Study records, raw data |
| 21 CFR 11.10(e) |
Records required to be maintained |
Electronic Record Requirements
General Requirements (§11.10)
Closed systems must implement controls including:
- System Validation - Accuracy, reliability, consistent intended performance
- Record Generation - Accurate and complete copies in human-readable form
- Record Protection - Throughout retention period
- Access Control - Limit system access to authorized individuals
- Audit Trail - Secure, computer-generated, time-stamped record
- Operational Checks - Enforce permitted sequencing of steps
- Authority Checks - Restrict functions to authorized individuals
- Device Checks - Determine validity of input/output devices
- Training - Personnel education and experience
- Documentation - Written policies and accountability
Audit Trail Requirements
| Requirement |
Implementation |
| Secure |
Cannot be modified or deleted by users |
| Computer-generated |
System creates automatically, not manually entered |
| Time-stamped |
Date and time of each action recorded |
| Independent |
Stored separately from application data |
| Original values |
Previous values retained when modified |
| Who, what, when |
User identity, action taken, date/time |
| Reason for change |
Where required by predicate rule |
Audit Trail Entries
| Event Type |
Data Captured |
| Record Creation |
User, date/time, initial values |
| Record Modification |
User, date/time, old value, new value, reason |
| Record Deletion |
User, date/time, reason (if permitted) |
| Login/Logout |
User, date/time, success/failure |
| Signature Application |
User, date/time, signature meaning |
| Failed Access |
User attempted, date/time, reason |
Record Copy Requirements
Must be able to generate accurate and complete copies:
| Format |
Requirement |
| Electronic |
Export in standard format (PDF, XML) |
| Paper |
Human-readable printout |
| FDA Inspection |
Provide copies upon request |
| Audit Trail |
Include with record or separately |
Electronic Signature Requirements
General Requirements (§11.50, 11.100)
| Requirement |
Implementation |
| Unique to individual |
Not shared between persons |
| Not reused |
Identifier not assigned to another person |
| Identity verification |
Verify identity before assignment |
| Certification |
Certify to FDA that signatures are binding |
Signature Components (§11.200)
| Type |
Components Required |
| Non-biometric |
At least two distinct identification components |
| - First signing |
Both components (user ID + password) |
| - Subsequent signings |
At least one component within controlled session |
| Biometric |
Biometric designed for individual identification |
Signature Manifestations (§11.50)
Electronic signatures must include:
| Element |
Requirement |
| Printed name |
Full name of signer |
| Date and time |
When signature was applied |
| Meaning |
Purpose of signature (e.g., review, approval, responsibility) |
Signature/Record Linking (§11.70)
| Requirement |
Implementation |
| Linked to record |
Signature cannot be excised, copied, or transferred |
| Cannot falsify |
Technical controls prevent counterfeiting |
| Cannot repudiate |
Signer cannot deny signing |
Signature Certification
Organizations must submit certification to FDA (§11.100(c)):
SAMPLE CERTIFICATION LETTER
[Date]
Food and Drug Administration
[Appropriate Center Address]
Subject: Electronic Signature Certification
[Company Name] hereby certifies that all electronic signatures
used in our FDA-regulated systems are the legally binding
equivalent of traditional handwritten signatures.
This certification is made in accordance with 21 CFR Part 11,
Section 11.100(c).
Sincerely,
[Authorized Representative]
[Title]
System Controls
Administrative Controls
| Control |
Implementation |
| Written policies |
SOPs for electronic records and signatures |
| Roles and responsibilities |
Defined system access roles |
| Training program |
Initial and periodic training |
| Periodic review |
Regular assessment of controls |
| Accountability |
Individual responsibility for actions |
Operational Controls
| Control |
Implementation |
| Sequence enforcement |
System enforces step order |
| Time limits |
Session timeout after inactivity |
| Event logging |
All significant events recorded |
| Error handling |
System prevents invalid operations |
| Backup/recovery |
Regular backup and tested recovery |
Technical Controls
| Control |
Implementation |
| User authentication |
Unique ID + password minimum |
| Password complexity |
Minimum length, character requirements |
| Password expiration |
Periodic change requirement |
| Account lockout |
Lock after failed attempts |
| Access control |
Role-based permissions |
| Encryption |
Data in transit and at rest |
Password Requirements
| Requirement |
Specification |
| Minimum length |
8 characters minimum |
| Complexity |
Upper, lower, number, special character |
| History |
Cannot reuse last 12 passwords |
| Expiration |
Maximum 90 days |
| Lockout |
5 failed attempts, 30-minute lockout |
| Initial password |
Must change on first login |
Session Controls
| Control |
Specification |
| Inactivity timeout |
Maximum 15 minutes |
| Session duration |
Maximum 8 hours |
| Concurrent sessions |
Limit or prevent |
| Re-authentication |
Required for sensitive operations |
Validation Requirements
Validation Approach
| Phase |
Activities |
| Planning |
Validation plan, requirements, risk assessment |
| Specification |
User requirements, functional specifications |
| Configuration |
System setup, security configuration |
| Testing |
IQ, OQ, PQ protocols and execution |
| Release |
Validation summary report, release approval |
| Maintenance |
Change control, periodic review |
Validation Documentation
| Document |
Purpose |
| Validation Plan |
Scope, approach, responsibilities, schedule |
| User Requirements |
What system must do (business requirements) |
| Functional Specification |
How system will meet requirements |
| Design Specification |
Technical implementation details |
| Test Protocols |
IQ, OQ, PQ test procedures |
| Test Results |
Executed protocols with evidence |
| Traceability Matrix |
Requirements to test coverage |
| Validation Summary Report |
Overall validation conclusion |
Testing Categories
Installation Qualification (IQ):
- System installed per specifications
- Hardware and software inventory
- Configuration documentation
Operational Qualification (OQ):
- Functions operate as specified
- Audit trail verification
- Security control testing
- Error handling verification
Performance Qualification (PQ):
- System performs in production environment
- User acceptance testing
- Integration testing
- Load/stress testing (if applicable)
Part 11 Specific Testing
| Test Area |
Verification |
| Audit trail |
All CRUD operations recorded correctly |
| Access control |
Role permissions enforced |
| Electronic signatures |
Signature components and linking |
| Record integrity |
Data cannot be altered without detection |
| Backup/restore |
Records restored accurately |
| Session controls |
Timeout and lockout function |
| Password controls |
Complexity and expiration enforced |
Compliance Checklist
System Assessment Checklist
Administrative Controls:
Access Controls:
Audit Trail:
Electronic Signatures:
Record Management:
System Controls:
Validation:
Gap Assessment Template
PART 11 GAP ASSESSMENT
System: [System Name]
Assessment Date: [Date]
Assessor: [Name]
| Requirement | §11 Reference | Current State | Gap | Remediation | Priority |
|-------------|---------------|---------------|-----|-------------|----------|
| Audit trail | 11.10(e) | [Description] | [Y/N] | [Action] | [H/M/L] |
| Access control | 11.10(d) | [Description] | [Y/N] | [Action] | [H/M/L] |
| E-signatures | 11.50 | [Description] | [Y/N] | [Action] | [H/M/L] |
Summary:
- Total requirements assessed: [Number]
- Requirements met: [Number]
- Gaps identified: [Number]
- Remediation timeline: [Date]
Periodic Review Schedule
| Review Type |
Frequency |
Scope |
| Access review |
Quarterly |
User access appropriateness |
| Audit trail review |
Monthly |
Sample review of audit entries |
| Security review |
Annually |
Controls effectiveness |
| Validation review |
Annually or on change |
System still validated |
| Policy review |
Annually |
SOPs current and followed |
Common Deficiencies
FDA Warning Letter Themes
| Deficiency |
Root Cause |
Prevention |
| Shared user accounts |
Convenience over compliance |
Enforce unique accounts |
| Inadequate audit trail |
System limitation |
Validate audit trail |
| Missing signatures |
Process gap |
Enforce signature workflow |
| Incomplete validation |
Time/resource constraints |
Plan adequate resources |
| No change control |
Process not followed |
Enforce change control |
| Password sharing |
Culture issue |
Training and enforcement |
Remediation Priorities
| Priority |
Deficiency Type |
Timeline |
| Critical |
Audit trail missing/modifiable |
Immediate |
| Critical |
Signatures can be falsified |
Immediate |
| High |
Shared accounts in production |
30 days |
| High |
Validation gaps |
60 days |
| Medium |
Training gaps |
90 days |
| Low |
Documentation gaps |
120 days |
1---2name: 001-electronic-56bc72303description: 21 CFR Part 11 Compliance Guide4---5# 21 CFR Part 11 Compliance Guide67Electronic records and electronic signatures compliance for FDA-regulated systems.89---1011## Table of Contents1213- [Part 11 Overview](#part-11-overview)14- [Electronic Record Requirements](#electronic-record-requirements)15- [Electronic Signature Requirements](#electronic-signature-requirements)16- [System Controls](#system-controls)17- [Validation Requirements](#validation-requirements)18- [Compliance Checklist](#compliance-checklist)1920---2122## Part 11 Overview2324### Scope and Applicability252621 CFR Part 11 applies to electronic records and signatures used to meet FDA predicate rule requirements.2728| Applies To | Does Not Apply To |29|------------|-------------------|30| Records required by FDA regulations | Paper records |31| Records submitted to FDA | Internal documents not required by regulation |32| Electronic signatures on required records | Digital communication (email) for general purposes |33| Systems creating/maintaining regulated records | Non-regulated systems |3435### Key Terms3637| Term | Definition |38|------|------------|39| Electronic Record | Any combination of text, graphics, data in digital form |40| Electronic Signature | Computer data compilation intended as legally binding signature |41| Digital Signature | Electronic signature based on cryptographic methods |42| Closed System | Environment with controlled access by responsible persons |43| Open System | Environment with uncontrolled access |44| Audit Trail | Secure, computer-generated, time-stamped record |4546### Predicate Rules4748Part 11 does not create new record requirements. It governs HOW records are maintained when electronic:4950| Predicate Rule | Record Type |51|----------------|-------------|52| 21 CFR 820 (QSR) | Device Master Records, Device History Records |53| 21 CFR 211 (cGMP) | Batch records, laboratory records |54| 21 CFR 58 (GLP) | Study records, raw data |55| 21 CFR 11.10(e) | Records required to be maintained |5657---5859## Electronic Record Requirements6061### General Requirements (§11.10)6263Closed systems must implement controls including:64651. **System Validation** - Accuracy, reliability, consistent intended performance662. **Record Generation** - Accurate and complete copies in human-readable form673. **Record Protection** - Throughout retention period684. **Access Control** - Limit system access to authorized individuals695. **Audit Trail** - Secure, computer-generated, time-stamped record706. **Operational Checks** - Enforce permitted sequencing of steps717. **Authority Checks** - Restrict functions to authorized individuals728. **Device Checks** - Determine validity of input/output devices739. **Training** - Personnel education and experience7410. **Documentation** - Written policies and accountability7576### Audit Trail Requirements7778| Requirement | Implementation |79|-------------|----------------|80| Secure | Cannot be modified or deleted by users |81| Computer-generated | System creates automatically, not manually entered |82| Time-stamped | Date and time of each action recorded |83| Independent | Stored separately from application data |84| Original values | Previous values retained when modified |85| Who, what, when | User identity, action taken, date/time |86| Reason for change | Where required by predicate rule |8788### Audit Trail Entries8990| Event Type | Data Captured |91|------------|---------------|92| Record Creation | User, date/time, initial values |93| Record Modification | User, date/time, old value, new value, reason |94| Record Deletion | User, date/time, reason (if permitted) |95| Login/Logout | User, date/time, success/failure |96| Signature Application | User, date/time, signature meaning |97| Failed Access | User attempted, date/time, reason |9899### Record Copy Requirements100101Must be able to generate accurate and complete copies:102103| Format | Requirement |104|--------|-------------|105| Electronic | Export in standard format (PDF, XML) |106| Paper | Human-readable printout |107| FDA Inspection | Provide copies upon request |108| Audit Trail | Include with record or separately |109110---111112## Electronic Signature Requirements113114### General Requirements (§11.50, 11.100)115116| Requirement | Implementation |117|-------------|----------------|118| Unique to individual | Not shared between persons |119| Not reused | Identifier not assigned to another person |120| Identity verification | Verify identity before assignment |121| Certification | Certify to FDA that signatures are binding |122123### Signature Components (§11.200)124125| Type | Components Required |126|------|---------------------|127| Non-biometric | At least two distinct identification components |128| - First signing | Both components (user ID + password) |129| - Subsequent signings | At least one component within controlled session |130| Biometric | Biometric designed for individual identification |131132### Signature Manifestations (§11.50)133134Electronic signatures must include:135136| Element | Requirement |137|---------|-------------|138| Printed name | Full name of signer |139| Date and time | When signature was applied |140| Meaning | Purpose of signature (e.g., review, approval, responsibility) |141142### Signature/Record Linking (§11.70)143144| Requirement | Implementation |145|-------------|----------------|146| Linked to record | Signature cannot be excised, copied, or transferred |147| Cannot falsify | Technical controls prevent counterfeiting |148| Cannot repudiate | Signer cannot deny signing |149150### Signature Certification151152Organizations must submit certification to FDA (§11.100(c)):153154```155SAMPLE CERTIFICATION LETTER156157[Date]158159Food and Drug Administration160[Appropriate Center Address]161162Subject: Electronic Signature Certification163164[Company Name] hereby certifies that all electronic signatures165used in our FDA-regulated systems are the legally binding166equivalent of traditional handwritten signatures.167168This certification is made in accordance with 21 CFR Part 11,169Section 11.100(c).170171Sincerely,172[Authorized Representative]173[Title]174```175176---177178## System Controls179180### Administrative Controls181182| Control | Implementation |183|---------|----------------|184| Written policies | SOPs for electronic records and signatures |185| Roles and responsibilities | Defined system access roles |186| Training program | Initial and periodic training |187| Periodic review | Regular assessment of controls |188| Accountability | Individual responsibility for actions |189190### Operational Controls191192| Control | Implementation |193|---------|----------------|194| Sequence enforcement | System enforces step order |195| Time limits | Session timeout after inactivity |196| Event logging | All significant events recorded |197| Error handling | System prevents invalid operations |198| Backup/recovery | Regular backup and tested recovery |199200### Technical Controls201202| Control | Implementation |203|---------|----------------|204| User authentication | Unique ID + password minimum |205| Password complexity | Minimum length, character requirements |206| Password expiration | Periodic change requirement |207| Account lockout | Lock after failed attempts |208| Access control | Role-based permissions |209| Encryption | Data in transit and at rest |210211### Password Requirements212213| Requirement | Specification |214|-------------|---------------|215| Minimum length | 8 characters minimum |216| Complexity | Upper, lower, number, special character |217| History | Cannot reuse last 12 passwords |218| Expiration | Maximum 90 days |219| Lockout | 5 failed attempts, 30-minute lockout |220| Initial password | Must change on first login |221222### Session Controls223224| Control | Specification |225|---------|---------------|226| Inactivity timeout | Maximum 15 minutes |227| Session duration | Maximum 8 hours |228| Concurrent sessions | Limit or prevent |229| Re-authentication | Required for sensitive operations |230231---232233## Validation Requirements234235### Validation Approach236237| Phase | Activities |238|-------|------------|239| Planning | Validation plan, requirements, risk assessment |240| Specification | User requirements, functional specifications |241| Configuration | System setup, security configuration |242| Testing | IQ, OQ, PQ protocols and execution |243| Release | Validation summary report, release approval |244| Maintenance | Change control, periodic review |245246### Validation Documentation247248| Document | Purpose |249|----------|---------|250| Validation Plan | Scope, approach, responsibilities, schedule |251| User Requirements | What system must do (business requirements) |252| Functional Specification | How system will meet requirements |253| Design Specification | Technical implementation details |254| Test Protocols | IQ, OQ, PQ test procedures |255| Test Results | Executed protocols with evidence |256| Traceability Matrix | Requirements to test coverage |257| Validation Summary Report | Overall validation conclusion |258259### Testing Categories260261**Installation Qualification (IQ):**262- System installed per specifications263- Hardware and software inventory264- Configuration documentation265266**Operational Qualification (OQ):**267- Functions operate as specified268- Audit trail verification269- Security control testing270- Error handling verification271272**Performance Qualification (PQ):**273- System performs in production environment274- User acceptance testing275- Integration testing276- Load/stress testing (if applicable)277278### Part 11 Specific Testing279280| Test Area | Verification |281|-----------|--------------|282| Audit trail | All CRUD operations recorded correctly |283| Access control | Role permissions enforced |284| Electronic signatures | Signature components and linking |285| Record integrity | Data cannot be altered without detection |286| Backup/restore | Records restored accurately |287| Session controls | Timeout and lockout function |288| Password controls | Complexity and expiration enforced |289290---291292## Compliance Checklist293294### System Assessment Checklist295296**Administrative Controls:**297- [ ] Written policies for electronic records and signatures298- [ ] Defined roles and responsibilities299- [ ] Training program documented and executed300- [ ] Periodic review schedule established301- [ ] Accountability measures in place302303**Access Controls:**304- [ ] Unique user identification for each person305- [ ] User IDs not shared or reassigned306- [ ] Password complexity requirements enforced307- [ ] Password expiration implemented308- [ ] Account lockout after failed attempts309- [ ] Role-based access control implemented310- [ ] Access periodically reviewed311312**Audit Trail:**313- [ ] All record creation captured314- [ ] All record modifications captured315- [ ] Previous values retained316- [ ] User identity recorded317- [ ] Date/time stamp on all entries318- [ ] Audit trail secure from modification319- [ ] Audit trail available for review320321**Electronic Signatures:**322- [ ] Signatures unique to individual323- [ ] At least two identification components324- [ ] Signature manifestation includes name, date/time, meaning325- [ ] Signatures linked to records326- [ ] Certification letter submitted to FDA327328**Record Management:**329- [ ] Accurate copies can be generated330- [ ] Human-readable format available331- [ ] Records protected throughout retention332- [ ] Backup and recovery tested333334**System Controls:**335- [ ] Session timeout implemented336- [ ] Operational sequence enforcement337- [ ] Input/output device validation338- [ ] Error handling documented339340**Validation:**341- [ ] System validated for intended use342- [ ] Validation documentation complete343- [ ] Change control procedures in place344- [ ] Periodic review conducted345346### Gap Assessment Template347348```349PART 11 GAP ASSESSMENT350351System: [System Name]352Assessment Date: [Date]353Assessor: [Name]354355| Requirement | §11 Reference | Current State | Gap | Remediation | Priority |356|-------------|---------------|---------------|-----|-------------|----------|357| Audit trail | 11.10(e) | [Description] | [Y/N] | [Action] | [H/M/L] |358| Access control | 11.10(d) | [Description] | [Y/N] | [Action] | [H/M/L] |359| E-signatures | 11.50 | [Description] | [Y/N] | [Action] | [H/M/L] |360361Summary:362- Total requirements assessed: [Number]363- Requirements met: [Number]364- Gaps identified: [Number]365- Remediation timeline: [Date]366```367368### Periodic Review Schedule369370| Review Type | Frequency | Scope |371|-------------|-----------|-------|372| Access review | Quarterly | User access appropriateness |373| Audit trail review | Monthly | Sample review of audit entries |374| Security review | Annually | Controls effectiveness |375| Validation review | Annually or on change | System still validated |376| Policy review | Annually | SOPs current and followed |377378---379380## Common Deficiencies381382### FDA Warning Letter Themes383384| Deficiency | Root Cause | Prevention |385|------------|------------|------------|386| Shared user accounts | Convenience over compliance | Enforce unique accounts |387| Inadequate audit trail | System limitation | Validate audit trail |388| Missing signatures | Process gap | Enforce signature workflow |389| Incomplete validation | Time/resource constraints | Plan adequate resources |390| No change control | Process not followed | Enforce change control |391| Password sharing | Culture issue | Training and enforcement |392393### Remediation Priorities394395| Priority | Deficiency Type | Timeline |396|----------|-----------------|----------|397| Critical | Audit trail missing/modifiable | Immediate |398| Critical | Signatures can be falsified | Immediate |399| High | Shared accounts in production | 30 days |400| High | Validation gaps | 60 days |401| Medium | Training gaps | 90 days |402| Low | Documentation gaps | 120 days |