Innotec — Equipment for particulate systems and bioprocess analysis
Standard

21 CFR Part 11: Electronic Records and Electronic Signatures Under FDA Regulation

Active site.norm_type_Regulamento federal Estados Unidos FDA (U.S. Food and Drug Administration)

21 CFR Part 11 is the FDA regulation setting the criteria under which electronic records and electronic signatures are considered trustworthy and equivalent to paper records and handwritten signatures. It applies to records required by other FDA regulations (predicate rules) when kept in electronic form.

What the FDA requires of computerized systems, and where most operations fail

What 21 CFR Part 11 is

21 CFR Part 11 is the part of the U.S. Code of Federal Regulations defining when the FDA accepts electronic records and electronic signatures as equivalent to paper records and handwritten signatures.

Issued as a final rule by the U.S. Food and Drug Administration (FDA) in March 1997 and effective from August that year, the regulation is organized in three subparts: scope and definitions, electronic records, and electronic signatures.

A critical and widely misunderstood point: Part 11 does not create new recordkeeping obligations. It defines the conditions under which records you are already required to keep may exist in electronic form.

Predicate rules: what determines whether Part 11 applies

Part 11 only reaches records required by so-called predicate rules, meaning the requirements set out in the Federal Food, Drug, and Cosmetic Act, the Public Health Service Act and other FDA regulations that mandate creating, maintaining or submitting records.

The practical logic is sequential:

  • Is there a predicate rule requiring that record? If not, Part 11 does not apply.
  • Have you chosen to keep that record electronically instead of on paper? If yes, Part 11 applies.
  • Do you use an electronic signature in place of a handwritten one? If yes, Subpart C applies as well.

Paper records merely transmitted by electronic means (a PDF attached to an email, for instance) do not automatically fall within scope.

Core requirements of 21 CFR Part 11

The required controls combine technology, procedure and organizational accountability. The main ones are:

  • System validation, with documented evidence that the system consistently performs as intended, including detection of invalid or altered records.
  • Audit trail, a secure, computer generated, time stamped record documenting creation, modification and deletion of records without obscuring previously recorded information.
  • Access control, limiting system access to authorized individuals with unique, non shared credentials.
  • Readable copies, with the ability to generate accurate and complete copies of records in both human readable and electronic form for inspection.
  • Retention, protecting records throughout the required retention period, with reliable retrieval.
  • Operational and device checks, enforcing correct sequencing of steps and validating the source of data input.
  • Training, with personnel having the education, training and experience to perform their assigned tasks.

None of these controls is optional once a record falls in scope. A missing or non functional audit trail is among the most recurrent inspection observations.

Electronic signatures: what the FDA requires

A Part 11 compliant electronic signature must contain, linked to the signed record:

  • The printed name of the signer.
  • The date and time the signature was executed.
  • The meaning of the signature, whether review, approval, responsibility or authorship.

Non biometric signatures must employ at least two distinct identification components, such as an identification code and a password. Biometric signatures must be designed so that no one other than the genuine individual can execute them.

The FDA does not consider signatures drawn with a finger or an electronic stylus to be equivalent to handwritten signatures.

Open and closed systems

The regulation distinguishes closed systems, where access is controlled by the people responsible for the record content, from open systems, where that control does not exist.

Open systems require additional measures to ensure authenticity, integrity and, where applicable, confidentiality, typically through encryption and digital signature. With growing adoption of cloud platforms and outsourced IT services, this distinction has returned to the centre of compliance discussions.

The 2024 update: FDA guidance on electronic systems

In October 2024 the FDA finalized the guidance Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers, announced in the Federal Register on 2 October 2024. It finalizes the March 2023 draft and supersedes the 2007 guidance Computerized Systems Used in Clinical Investigations.

The final version is organized around 29 questions covering electronic records, systems deployed by regulated entities, IT service providers, digital health technologies (DHTs) and electronic signatures. One notable clarification: the FDA stated it does not intend to require Part 11 compliance from electronic health record systems serving as sources of real world data.

The regulation itself has not changed since 1997. What changed is the agency's expectation of how compliance is demonstrated in digital, distributed and cloud based environments.

The risk based approach

The 2003 guidance, Part 11, Electronic Records; Electronic Signatures, Scope and Application, introduced the risk based approach that remains the practical basis for implementation. Rather than applying the same rigour to every system, the organization assesses:

  • The record's impact on product quality and patient safety.
  • The criticality of the decision that depends on that data.
  • The complexity and maturity of the system involved.

That assessment drives validation depth, audit trail scope and the level of procedural control applied. Documenting the rationale behind the decision matters as much as the decision itself.

Part 11 in the laboratory environment

In laboratories, Part 11 reaches systems generating or storing data under predicate rules: chromatographs and their acquisition software, LIMS, purified water monitoring systems, temperature loggers, balances with digital output and document management platforms.

The common failure points are predictable:

  • Instruments with audit trail disabled or user configurable.
  • Shared logins among analysts.
  • Raw data stored only locally on the instrument PC, without validated backup.
  • No change control over analytical methods.
  • Missing documented qualification (IQ/OQ/PQ) of the computerized system.

Fixing this means treating the instrument and its software as a single qualified system, not as hardware with an accessory program attached.

21 CFR Part 11 and EU Annex 11

The European counterpart is Annex 11 of the EU GMP Guide, covering computerized systems. Both converge on validation, audit trail, access control and data integrity, but differ in structure and emphasis: Part 11 details electronic signature requirements far more deeply, while Annex 11 leans more heavily on quality risk management.

Operations exporting to both markets typically build a single control system meeting the stricter requirement on each topic.

Demonstrating compliance

Compliance rests on three layers that must exist simultaneously:

  • Technology, with a validated system, secure audit trail, role based access and reliable retention.
  • Procedure, with SOPs for validation, change control, access management, backup and recovery.
  • Accountability, with recorded training, clear ownership of each system and an electronic signature policy.

One clarification the FDA itself makes is worth recording: the agency does not certify systems. There is no "Part 11 certified" software. There is only a system configured, validated and operated so as to meet the regulation, and that responsibility sits with the regulated entity, not the vendor.

Official sources & references

Primary texts and guidance published by the issuing body.

Equipment for these workflows

Instruments with features that support this standard's requirements. Compliance is achieved by the user organization, not by the equipment alone.

9 9 products
EN Particle Counters

HIAC 9703+

Contador de partículas HIAC 9703+ para control de calidad farmacéutica. Cumplimiento USP 788, 787 y 789 muestras de 1mL, precisión >95%. ¡Solicite presupuesto!

View details
EN Particle Counters

Multisizer 4e

The Multisizer 4e delivers high resolution and precision in particle counting and analysis with DPP, outperforming other technologies.

View details
EN DVS Analyzer – Dynamic Vapor Sorption

DVS Instrinsic Plus

DVS Intrinsic Plus provides dynamic water vapor sorption analysis in a compact, economical, and precise package for all your essential laboratory needs.

View details
EN Bioreactors / Biofermenters

BioLector XT

The BioLector XT Microbioreactor will optimize your process. Precise control of pH, biomass, and DO with patented microfluidic technology and optical sensors.

View details
EN Bioreactors / Biofermenters

BioLector XT & Biomek i5

BioLector XT Microbioreactor with Biomek i5: Automation of microbial cultivation with real-time measurements. Reduce errors and increase productivity.

View details
EN DVS Analyzer – Dynamic Vapor Sorption

DVS Carbon

DVS Carbon elevates your research with unmatched efficiency and reliability, providing the most advanced carbon analysis for groundbreaking discoveries in material science.

View details
EN Particle Counters

MET ONE 3400+

The innovative particle counter that eliminates workflow errors and simplifies audits. Compliance with ISO 14644, 21 CFR Part 11, and the Annex 1.

View details
EN Particle Counters

MET ONE HHPC+

Discover the MET ONE HHPC+ and its simplified operation for particle monitoring in GMP and regulated environments.

View details
EN Total Organic Carbon Analyzers (TOC)

PAT700

Discover the Beckman Coulter ANATEL PAT700 TOC Analyzer: precision and compliance for your analyses.

View details

Frequently asked questions

What is 21 CFR Part 11?

It is the FDA regulation establishing the criteria under which electronic records and electronic signatures are considered trustworthy and equivalent to paper records and handwritten signatures. Issued as a final rule in 1997, it applies to records required by other FDA regulations when kept in electronic form.

What are predicate rules?

They are requirements in the Federal Food, Drug, and Cosmetic Act, the Public Health Service Act and other FDA regulations that mandate creating, maintaining or submitting records. Part 11 applies only to records required by those rules; with no predicate rule, Part 11 does not apply.

Is there software certified for 21 CFR Part 11?

No. The FDA does not certify systems or processes. Vendors may offer features supporting compliance, but responsibility for validating, configuring and operating the system in line with the regulation always rests with the regulated entity using it.

What must a Part 11 electronic signature contain?

The signature must include the signer's printed name, the date and time of execution and the meaning of the signature, such as review, approval, responsibility or authorship. These elements must be linked to the signed record and subject to the same controls as the electronic record.

What is an audit trail under 21 CFR Part 11?

It is a secure, computer generated, time stamped record documenting creation, modification and deletion of electronic records. Previously recorded information may not be obscured, and the audit trail must be retained for the same period as the record and be available for inspection.

What is the difference between open and closed systems?

In a closed system, access is controlled by the people responsible for the record content. In an open system, that control does not exist. Open systems require additional measures for authenticity, integrity and confidentiality, typically through encryption and digital signature.

What changed with the FDA's 2024 guidance?

In October 2024 the FDA finalized a question and answer guidance on electronic systems, records and signatures in clinical investigations, superseding the 2007 document on computerized systems. The regulation text did not change; what changed is the guidance on demonstrating compliance in digital and cloud environments.

Does Part 11 apply to paper documents sent by email?

Not automatically. Records kept on paper and merely transmitted electronically do not fall in scope for that reason alone. Part 11 applies when the electronic record replaces paper as the official record required by a predicate rule.

How does 21 CFR Part 11 relate to EU Annex 11?

Annex 11 of the EU GMP Guide is the European counterpart for computerized systems. Both require validation, audit trail, access control and data integrity, but Part 11 details electronic signatures in greater depth, while Annex 11 emphasizes quality risk management.

Stay in the loop

Get updates, articles and news by email.