What the FDA requires of computerized systems, and where most operations fail
What 21 CFR Part 11 is
21 CFR Part 11 is the part of the U.S. Code of Federal Regulations defining when the FDA accepts electronic records and electronic signatures as equivalent to paper records and handwritten signatures.
Issued as a final rule by the U.S. Food and Drug Administration (FDA) in March 1997 and effective from August that year, the regulation is organized in three subparts: scope and definitions, electronic records, and electronic signatures.
A critical and widely misunderstood point: Part 11 does not create new recordkeeping obligations. It defines the conditions under which records you are already required to keep may exist in electronic form.
Predicate rules: what determines whether Part 11 applies
Part 11 only reaches records required by so-called predicate rules, meaning the requirements set out in the Federal Food, Drug, and Cosmetic Act, the Public Health Service Act and other FDA regulations that mandate creating, maintaining or submitting records.
The practical logic is sequential:
- Is there a predicate rule requiring that record? If not, Part 11 does not apply.
- Have you chosen to keep that record electronically instead of on paper? If yes, Part 11 applies.
- Do you use an electronic signature in place of a handwritten one? If yes, Subpart C applies as well.
Paper records merely transmitted by electronic means (a PDF attached to an email, for instance) do not automatically fall within scope.
Core requirements of 21 CFR Part 11
The required controls combine technology, procedure and organizational accountability. The main ones are:
- System validation, with documented evidence that the system consistently performs as intended, including detection of invalid or altered records.
- Audit trail, a secure, computer generated, time stamped record documenting creation, modification and deletion of records without obscuring previously recorded information.
- Access control, limiting system access to authorized individuals with unique, non shared credentials.
- Readable copies, with the ability to generate accurate and complete copies of records in both human readable and electronic form for inspection.
- Retention, protecting records throughout the required retention period, with reliable retrieval.
- Operational and device checks, enforcing correct sequencing of steps and validating the source of data input.
- Training, with personnel having the education, training and experience to perform their assigned tasks.
None of these controls is optional once a record falls in scope. A missing or non functional audit trail is among the most recurrent inspection observations.
Electronic signatures: what the FDA requires
A Part 11 compliant electronic signature must contain, linked to the signed record:
- The printed name of the signer.
- The date and time the signature was executed.
- The meaning of the signature, whether review, approval, responsibility or authorship.
Non biometric signatures must employ at least two distinct identification components, such as an identification code and a password. Biometric signatures must be designed so that no one other than the genuine individual can execute them.
The FDA does not consider signatures drawn with a finger or an electronic stylus to be equivalent to handwritten signatures.
Open and closed systems
The regulation distinguishes closed systems, where access is controlled by the people responsible for the record content, from open systems, where that control does not exist.
Open systems require additional measures to ensure authenticity, integrity and, where applicable, confidentiality, typically through encryption and digital signature. With growing adoption of cloud platforms and outsourced IT services, this distinction has returned to the centre of compliance discussions.
The 2024 update: FDA guidance on electronic systems
In October 2024 the FDA finalized the guidance Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers, announced in the Federal Register on 2 October 2024. It finalizes the March 2023 draft and supersedes the 2007 guidance Computerized Systems Used in Clinical Investigations.
The final version is organized around 29 questions covering electronic records, systems deployed by regulated entities, IT service providers, digital health technologies (DHTs) and electronic signatures. One notable clarification: the FDA stated it does not intend to require Part 11 compliance from electronic health record systems serving as sources of real world data.
The regulation itself has not changed since 1997. What changed is the agency's expectation of how compliance is demonstrated in digital, distributed and cloud based environments.
The risk based approach
The 2003 guidance, Part 11, Electronic Records; Electronic Signatures, Scope and Application, introduced the risk based approach that remains the practical basis for implementation. Rather than applying the same rigour to every system, the organization assesses:
- The record's impact on product quality and patient safety.
- The criticality of the decision that depends on that data.
- The complexity and maturity of the system involved.
That assessment drives validation depth, audit trail scope and the level of procedural control applied. Documenting the rationale behind the decision matters as much as the decision itself.
Part 11 in the laboratory environment
In laboratories, Part 11 reaches systems generating or storing data under predicate rules: chromatographs and their acquisition software, LIMS, purified water monitoring systems, temperature loggers, balances with digital output and document management platforms.
The common failure points are predictable:
- Instruments with audit trail disabled or user configurable.
- Shared logins among analysts.
- Raw data stored only locally on the instrument PC, without validated backup.
- No change control over analytical methods.
- Missing documented qualification (IQ/OQ/PQ) of the computerized system.
Fixing this means treating the instrument and its software as a single qualified system, not as hardware with an accessory program attached.
21 CFR Part 11 and EU Annex 11
The European counterpart is Annex 11 of the EU GMP Guide, covering computerized systems. Both converge on validation, audit trail, access control and data integrity, but differ in structure and emphasis: Part 11 details electronic signature requirements far more deeply, while Annex 11 leans more heavily on quality risk management.
Operations exporting to both markets typically build a single control system meeting the stricter requirement on each topic.
Demonstrating compliance
Compliance rests on three layers that must exist simultaneously:
- Technology, with a validated system, secure audit trail, role based access and reliable retention.
- Procedure, with SOPs for validation, change control, access management, backup and recovery.
- Accountability, with recorded training, clear ownership of each system and an electronic signature policy.
One clarification the FDA itself makes is worth recording: the agency does not certify systems. There is no "Part 11 certified" software. There is only a system configured, validated and operated so as to meet the regulation, and that responsibility sits with the regulated entity, not the vendor.