Claude

IntuitionLabs is now a member of the Claude Partner Network – AI training and upskilling with Claude for pharma and biotech. Book a call.

IntuitionLabs
Back to Articles
IntuitionLabs

21 cfr part 11 · data integrity

21 CFR Part 11: IT Guide to Electronic Records & Signatures

October 12, 2025
Updated August 7, 2026
50 min read

Updated 2026 guide for IT on 21 CFR Part 11. Covers FDA CSA guidance, AI compliance, electronic records & signatures, system validation, audit trails & data integrity

21 CFR Part 11: IT Guide to Electronic Records & Signatures
Summary
  1. 01Part 11 remains fully in effect; FDA's enforcement discretion applies only to specified validation, audit-trail, record-retention, and record-copying provisions, not to predicate rules.
  2. 02IT teams must classify each system as open or closed under Sec 11.3 based on who controls access, then apply 11.10 controls or add encryption and digital-signature measures under 11.30 for open systems.
  3. 03Data integrity remains the top inspection focus: roughly 80% of FDA warning letters cited data governance failures by 2016, and warning letters rose 73% in the second half of 2025 versus 2024.
  4. 04The September 2025 Computer Software Assurance (CSA) guidance replaces the legacy GPSV framework with a risk-based validation approach, changing how IT teams approach Part 11 system validation.
  5. 05Electronic signatures must be permanently linked to their records and use at least two distinct identification components for non-biometric signing to prevent falsification.
  6. 06FDA's October 2024 guidance clarifies that data from wearables and EHRs is not subject to Part 11 until it enters the sponsor's system, such as an EDC or LIMS.

Executive Summary

21 CFR Part 11 is the FDA’s regulation governing electronic records and electronic signatures in FDA-regulated industries. It was enacted in 1997 to allow firms to use digital systems in place of paper records while ensuring data integrity and security. Key requirements include strict system validation, secure audit trails, user access controls, and electronic signature controls (unique ID/password or biometrics) ([1]) ([2]). For IT teams, compliance means determining which predicate-rule and Part 11 controls apply to each regulated-record use case, then designing and maintaining systems accordingly. Part 11 remains in effect, but FDA’s current guidance exercises enforcement discretion, in the circumstances it describes, for specified Part 11 requirements concerning validation, audit trails, record retention, and record copying; applicable predicate rules still apply. Electronic signatures must be linked to their records so they cannot be excised, copied, or otherwise transferred to falsify a record, and non-biometric signatures must use at least two distinct identification components, such as an identification code and password ([1]) ([2]). Over the years, FDA has clarified that Part 11's applicability is limited to regulated records (predicated on other GMP rules) ([3]) and has offered enforcement discretion on some requirements (validation, audit trails, etc.) ([4]), but the regulation itself remains in effect. Data-integrity issues remain an important inspection concern. A 2026 journal article, published online in October 2025, analyzing 1,766 FDA warning letters from 2016–2023 found no statistically significant pre-/post-pandemic differences; it reported patterns consistent with risk-based data-integrity oversight but stated that causality cannot be inferred. In the second half of 2025 alone, FDA issued 327 warning letters – a 73% increase over the same period in 2024 – with data integrity and quality-system failures remaining top citations. This report provides an in-depth technical guide for IT professionals, covering Part 11's history and background, its detailed requirements (closed/open systems controls, audit trails, e-signatures, record retention, etc.), implementation strategies (system validation, security, data integrity practices), case examples, and future trends (global harmonization with Annex 11, digital health, AI). All claims are supported by regulatory texts, FDA guidance, industry analyses, and expert sources.

01

Introduction and Background

In the 1990s, as pharmaceutical, biotech and medical-device firms began using computerized systems extensively, FDA sought to ensure that electronic records and signatures would be as reliable as traditional paper records. In March 1997 the FDA finalized 21 CFR Part 11 (“Electronic Records; Electronic Signatures”) ([4]). Its purpose was to permit the “widest possible use of electronic technology” while protecting public health ([5]). Part 11 applies to “records in electronic form that are created, modified, maintained, archived, retrieved, or transmitted under any records requirements set forth in [FDA’s] regulations” ([3]). In practice, a company falls under Part 11 if it chooses electronic recordkeeping or signature in lieu of paper for any regulated activity. For example, clinical trial data in an EDC system, manufacturing batch records in a LIMS, or submission of regulatory documents electronically will all trigger Part 11 ([3]). (Records submitted to FDA under the FD&C Act or PHS Act are covered even if not explicitly identified in regs ([3]).) The rest of Part 11’s rules (Subpart B and C) then impose strict controls on such systems.

Part 11’s introduction was controversial. Industry groups argued that rigid requirements (validation, audit trails, etc.) would be costly and hamper innovation with little health benefit ([6]). In response, FDA in 2003 issued guidance stating it would narrowly interpret Part 11 and use enforcement discretion on certain provisions ([4]) ([7]). Specifically, for active systems, FDA announced it would not enforce the validation, audit trail, record retention, and record copying rules of Part 11 for the time being ([4]). (However, underlying GMP rules still applied, and old “legacy” systems (pre-1997) were largely excused under specified conditions ([4]).) Significantly, FDA stressed that Part 11 remains in effect ([7]). Thus companies must still ensure predicate rules (e.g. CGMP 21 CFR Parts 210/211 for drugs, GLP, GMP for devices, etc.) are met.

Over time, the emphasis has shifted toward data integrity. In recent years, regulators worldwide have prioritized ensuring records remain complete, accurate, and retrievable. Barbara Unger reports that in 2015–2016 roughly 80% of FDA warning letters cited failures of data governance/data integrity, across both electronic and paper records ([8]) ([9]). Data integrity is defined as records being ALCOA (Attributable, Legible, Contemporaneous, Original, Accurate) ([10]). Thus even if FDA eased enforcement on some technicalities of Part 11, the core principle remains: regulated data must be secure, traceable, and untampered with. FDA's October 2024 final guidance on electronic systems in clinical investigations – a Q&A document addressing 29 questions on electronic records, digital health technologies, and e-signatures – reiterates that Part 11 compliance is expected in any system once data are captured into a sponsor's records ([11]). Additionally, in September 2025, FDA finalized its Computer Software Assurance (CSA) guidance, which introduces a modern risk-based approach to software validation that supersedes the legacy General Principles of Software Validation (GPSV) framework – significantly impacting how IT teams approach Part 11 system validation.

Given this background, IT teams in life-science organizations must recognize that computerized system compliance is not optional. Whether designing new software or upgrading legacy systems, IT must embed Part 11 controls into networks, applications, and procedures. This report details those requirements and their technical implications.

327

FDA warning letters issued in the second half of 2025

73%

Increase in FDA warning letters versus the same period in 2024

~80%

Share of FDA warning letters citing data integrity failures by 2016

1,766

FDA warning letters analyzed in the 2016-2023 journal study

F.01
FDA's Part 11 Guidance Has Evolved From Strict Rule to Risk-Based Enforcement
  1. 199721 CFR Part 11 Finalized

    FDA issued Part 11 as a binding federal regulation under Title 21 CFR governing electronic records and signatures.

  2. 2003FDA Scope and Application Guidance

    FDA guidance said it would narrowly interpret Part 11 and exercise enforcement discretion on certain provisions.

  3. Oct 2024Clinical Investigations Q&A Guidance

    FDA's guidance clarified Part 11's role in modern contexts such as clinical trial digital technologies.

  4. Sept 2025Computer Software Assurance (CSA) Guidance

    FDA finalized a risk-based validation approach that supersedes the legacy GPSV framework for software validation.

02

Regulatory Scope and Key Definitions

Applicability: 21 CFR Part 11 covers all FDA-regulated electronic records and electronic signatures when used in place of paper. As FDA explains, it “applies to records in electronic form that are created, modified, maintained, archived, retrieved, or transmitted under any records requirement” ([3]). This means any electronic method of meeting a statutory or regulatory requirement – e.g. manufacturing logs, analytical test results, clinical trial data, etc. – is subject to Part 11. Notably, records submitted electronically to FDA (NDAs, 510(k)s, etc.) are automatically under Part 11, even if the underlying FDA regulation did not explicitly call out Part 11 ([3]). In short, if your company is subject to FDA regulations, then any designated records kept in a computer system must comply with Part 11.

Predicate Rules: Part 11 itself does not list specific record-keeping requirements; it references underlying (predicate) rules such as CGMPs. Compliance means satisfying both the predicate (e.g., 21 CFR Part 211 for drug production) and Part 11. FDA’s guidance repeatedly emphasizes that underlying rules still apply ([4]). For instance, even if a computer spreadsheet falls under Part 11, the lab or production record it maintains is also subject to CGMP documentation standards ([3]) ([4]).

Definitions: Part 11 Subpart A (Sec. 11.3) defines key terms. A closed system is one where “system access is controlled by persons who are responsible for the content of electronic records on the system” (i.e., behind the company’s firewall). By contrast, an open system is one “in which system access is not controlled by persons who are responsible for the content of electronic records” ([12]) – for example, cloud or remote systems. These definitions matter because security expectations differ (see Controls). Other terms (electronic signature, digital signature, handwritten sign, etc.) are defined but we focus below on controls rather than detailed definitions.

Relationship to Other Laws: Part 11 only applies where a regulated activity requires record-keeping. For example, ordinary business emails or records unrelated to FDA regulations are outside its scope. However, if electronic records eventually feed into FDA-submitted documents (e.g. lab equipment logs), those records cannot use exempt shortcuts. It’s also worth noting that Part 11 is a Federal Rule in Title 21 CFR; its legal force is equivalent to regulation (it was issued via Notice-and-Comment in 1997). In contrast, EU GMP Annex 11 is a guidance document (Part of Eudralex) which serves a similar purpose in Europe. Both aim to ensure data integrity in computerized systems, but there are differences in emphasis (Table 2). For example, Annex 11 places more explicit emphasis on risk assessment and systems life cycle, whereas Part 11 is more prescriptive about specific technical controls ([1]) ([13]). (Annex 11 is discussed further in Section 6.)

data integrity is owned by every person in the firm who develops or completes an official GxP record

03

Part 11 Requirements in Detail

Part 11 Subparts B and C lay out the technical and procedural controls required. Below we organize these by major function: system controls (Sec.11.10/11.30), audit trails (11.10(e)), e-signatures (11.50, 11.100–11.300), and auxiliary requirements (training, paperwork, etc.). For each, we quote the regulation or guidance and interpret IT implications.

Controls for Closed Systems (21 CFR 11.10)

Section 11.10 lists the controls closed systems must have. In brief, a system where your organization controls access must still be rigorously secured to ensure record authenticity and integrity ([14]) ([15]). Key requirements include:

  • Validation (11.10(a)): “Validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records” ([1]). Interpretation: Section 11.10(a) states a validation requirement, but FDA’s current guidance exercises enforcement discretion for that Part 11 provision in the circumstances described in the guidance. Applicable predicate-rule validation requirements still apply. IT teams should use a justified, documented risk assessment to determine and document the appropriate assurance activities for systems that affect required records, signatures, product quality, or patient safety. For example, if a database application calculates an assay result, validation tests must show it never miscalculates or silently alters data. Risk-based validation (per GAMP5 principles) is now common: critical features (data capture, audit trails, signature) get thorough testing ([16]), while low-risk functions may get lighter checks.

  • Record Copies (11.10(b)): “Ability to generate accurate and complete copies of records in both human readable and electronic form suitable for inspection…” ([17]). Interpretation: Systems must allow exporting or printing of data exactly as entered. IT should ensure that all stored electronic records can be reproduced. This often means having printing features, export to PDF or CSV, and audit trails that persist in the printed/viewed form. Often regulators will ask for “Batch Record Reports” or audit trail reports: these must exist and be validated.

  • Record Protection (11.10(c)): “Protection of records to enable their accurate and ready retrieval throughout the records retention period” ([18]). Interpretation: Implement secure, redundant storage. Data must be regularly backed up and archived per policy. IT should design reliable backup procedures (with periodic restoration testing) so that no data are lost. Access controls must ensure only authorized archival processes occur. For example, database write-once-read-many (WORM) storage or secure cloud vaults can help ensure records aren’t tampered.

  • Access Controls (11.10(d) and 11.10(g)): “Limiting system access to authorized individuals” ([15]), and “authority checks to ensure only authorized individuals can use the system, electronically sign a record, …, or alter a record” ([19]). Interpretation: Implement strong user authentication (unique user IDs, passwords or tokens, multifactor where possible). Use role-based access controls so that, e.g., production staff can enter results but only quality staff can approve. Disable shared accounts. Centralized identity management (Azure AD, LDAP, IAM) is often used so passwords can be enforced enterprise-wide. IT should also use transaction safeguards to detect and promptly report attempted unauthorized use of identification codes or passwords, as required by Sec. 11.300(d). For production systems, file and database permissions must restrict who can view/modify records (e.g. Windows/Linux ACLs, DB roles).

  • Audit Trails (11.10(e)): “Use of secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records. Record changes shall not obscure previously recorded information.… Audit trail documentation shall be retained… and available for agency review” ([20]). Interpretation: Where audit trails are required by an applicable predicate rule, or are selected based on a documented risk assessment, systems should automatically record the relevant operator actions and timing. FDA currently exercises enforcement discretion for specified Part 11 audit-trail provisions in the circumstances described in its guidance, while continuing to enforce applicable predicate rules. For instance, if a lab instrument’s software allows editing of a calibration, the system must log the original value, the new value, the user ID, and date/time. Audit logs must be append-only and secured (so no one can erase or modify past entries). Each audit entry should capture: username, timestamp, action type, old value, new value, reason for change (if applicable). The regulations don’t explicitly mandate “reason” for change, but best practice (per guidance) is to prompt users for a comment on purpose ([21]). IT teams should verify that commercial systems have audit-trail features activated (some off-the-shelf apps disable them by default; FDA expects them turned on).

Where audit trails are required, they should be retained with the associated records for the applicable predicate-rule retention period. For example, drug CGMP production, control, and distribution records specifically associated with a batch generally must be retained for at least one year after that batch’s expiration date; separate rules and exceptions apply to other records and products ([20]). Systems should be validated to ensure audit entries are tamper-proof and synchronized (time stamps usually centralized via NTP). A recent analysis notes that regulators now expect audit trails to capture “specific type of action, the data element affected, and the previous and new values” ([22]), be immutable, and archived in a secure searchable form.

  • Operational Checks (11.10(f)): “Operational system checks to enforce permitted sequencing of steps and events, as appropriate.” ([23]). Interpretation: Where workflow order matters (e.g. enter results only after calibration), the system should enforce it. This might mean configuring software so certain fields unlock only after prerequisite fields are completed, or using transaction sequences in databases. IT can use form logic or middleware to enforce such business rules.

  • Device Checks (11.10(h)): “Use of device (e.g., terminal) checks to determine the validity of the source of data input or operational instruction.” ([24]). Interpretation: This refers to making sure data come from authorized equipment. For instance, if a barcode scanner or instrument is supposed to feed data, the system could verify the device ID or certificate. A common example is PLCs in a plant: data from a certified PLC should be accepted, but manual entries should be flagged. IT solutions may include using digital certificates or secure channels (TLS) from devices.

  • Personnel Training (11.10(i)): “Determination that persons who develop, maintain, or use electronic record/electronic signature systems have the education, training, and experience to perform their tasks.” ([24]). Interpretation: IT must help ensure that all personnel (developers, system admins, and end-users) are properly trained on Part 11 requirements and the specific system SOPs. This is often satisfied by training logs and competency records in the QMS. IT’s role is to provide user manuals, validate training tracking in the LMS, and sometimes configure software to require completion of training before access.

  • Documentation Control (11.10(k)): “Appropriate controls over system documentation… adequate controls over distribution of, access to, and use of documentation for system operation and maintenance; (2) Revision and change control procedures… to maintain an audit trail...” ([25]). Interpretation: All system documentation (user manuals, SOPs, specs) must itself be controlled. This means only authorized individuals can alter SOPs, and all revisions are logged. IT can support this via electronic document management (EDMS) that enforces versioning and approvals. For example, upgrade notes and design documents should be stored in controlled archives.

In summary, Section 11.10 lists controls for closed systems, but FDA’s scope guidance exercises enforcement discretion in specified circumstances for its validation, audit-trail, record-retention, and record-copying provisions. For IT teams, this means identifying applicable predicate-rule requirements, documenting a risk assessment, and implementing appropriate controls while maintaining access restrictions, workflow checks, training, documentation controls, and electronic-signature requirements that FDA continues to enforce. A concise summary appears in Table 1 below.

T.02
Part 11 SectionKey Requirement (Closed Systems)
11.10(a)Validation: Systems must be validated for accuracy, reliability, consistent performance ([1]).
11.10(b)Record Copies: Must produce accurate, complete human-readable/electronic copies for inspection ([17]).
11.10(c)Records Protection: Secure storage/backup so records are retrievable for full retention period ([15]).
11.10(d),(g)Access Control: System access limited to authorized users; enforce user authentication and privileges ([15]) ([19]).
11.10(e)Audit Trails: Computer-generated, time-stamped audit logs for all data creation/change/deletion, immutable and archived ([20]).
11.10(f)Operational Checks: Enforce correct sequencing of steps/events (workflow logic) ([23]).
11.10(h)Device Checks: Verify validity of data sources/instruments (e.g. authenticated devices) ([24]).
11.10(i)Training: Ensure personnel are qualified (training and competence) for system roles ([24]).
11.10(j)Policies: Written policies hold individuals accountable under their electronic signature, preventing falsification ([24]) ([26]).
11.10(k)Documentation Control: Manage distribution and revision of system documentation with traceability ([25]).

IT Implementation: In practice, achieving these controls requires robust IT processes. For example, to satisfy 11.10(e) the system administrator should configure applications (LIMS, MES, databases) to log every user action on GxP data fields. Many commercial life-science software packages offer built-in “audit trail” modules; IT must ensure these are enabled. Centralized logging (e.g. SIEM) may be used to aggregate logs across multiple systems. Regular reviews of audit logs for unauthorized attempts (as per 11.300(d)) should be in SOPs. Access control is typically handled via corporate identity systems (unified sign-on), with periodic password changes and access reviews (see Sec 11.300 below).

Controls for Open Systems (21 CFR 11.30)

If a system is open under § 11.3—meaning persons responsible for the electronic-record content do not control system access—then § 11.30 applies. It states that open systems must employ all of the 11.10 controls as appropriate, plus additional measures such as encryption and digital signatures ([27]). Specifically, Sec. 11.30 adds: “procedures and controls… including those identified in §11.10…and additional measures such as document encryption and use of appropriate digital signature standards to ensure, as necessary, record authenticity, integrity, and confidentiality” ([27]).

For IT teams, this means assessing each SaaS or cloud implementation against the regulatory definition of an open or closed system: whether persons responsible for record content control system access. Cloud hosting alone does not make a system open. Apply the controls appropriate to that determination, the applicable predicate rules, and a documented risk assessment. For an open system, § 11.30 calls for procedures and controls appropriate to ensure record authenticity, integrity, and confidentiality, including additional measures such as document encryption and appropriate digital-signature standards as necessary. Use of strong digital signature algorithms (PKI) is recommended when records move between systems. For example, if lab results are sent via email or file transfer, an encrypted, signed PDF or XML with PKI can fulfill this clause. Many regulated companies also require encrypting mobile devices or USBs as part of open-system controls.

The AWS GxP Guidance illustrates this “shared responsibility” model: infrastructure providers handle the underlying platform, but the customer is ultimately responsible for meeting Part 11 requirements ([28]). For instance, AWS notes that applicability of Part 11 is the customer’s responsibility, and AWS maps which controls it can assist with ([28]). In practice, IT teams working with cloud software should work closely with vendors to confirm how applicable controls are implemented or supported, document the access-control classification, and determine whether encryption, digital-signature standards, or other measures are necessary for the particular open-system use case.

Electronic Signatures (Subpart C – §§11.50, 11.70, 11.100–11.300)

Part 11 treats electronic signatures (e-signatures) as equivalent to handwritten signatures under predicate regulations. The requirements are detailed in Subpart C:

  • Signature Manifestation (11.50): Each signed electronic record must clearly show (a) the printed name of the signer, (b) date/time of the signature, and (c) the meaning of the signature (reviewed, approved, etc.). These items must be part of the digital record and subject to the same controls as the record itself ([29]). IT implication: Configure forms and reports (or e-signature software) to automatically append the user name, timestamp, and role for each e-signature event. For example, whenever a user approves a document in a QMS, the PDF report must display “Jane Doe – 2024-10-10 14:35 – Approved”. Ensuring the signature history prints in reports is critical for audit purposes.

  • Signature/Record Linking (11.70): Electronic (and handwritten) signatures must be linked to their records so they cannot be excised, copied, or otherwise transferred ([30]). IT implication: The database should maintain each version of a signed record bound to that signature. If a document or record is exported or printed, the system should include the signature metadata in a tamper-evident way. Avoid printing just the record without the audit trail. Some systems use digital signatures (as per PKI) to cryptographically bind signature and data.

  • Unique ID and Verification (11.100): Each e-signature must be unique to one individual (not reused/reassigned) ([31]). Before assigning an e-signature, the organization must verify the identity of the person ([31]). Under 11.100(c), users had to submit a signed “nonrepudiation” letter to FDA certifying their e-signature equals their handwritten signature (and provide further proof on request) ([32]). (In practice, this “letter of nonrepudiation” still exists, though some users wonder how strictly it is enforced.) IT implication: Maintain a user registry with one-to-one mapping: for example, each user’s credentials in the system are never shared. Identity proofing (typically done by QA at onboarding) must be documented (e.g., copy of ID). IT should ensure user records reflect the person’s “signed name” (e.g. Jane Doe). The system should forbid reuse of credentials. (Again, the underlying rule behind 11.100 is that any e-signing act is attributable to a unique person.)

  • Signature Components (11.200): Non-biometric signatures must use at least two distinct identification components (commonly, an identification code and password) ([2]). If a user performs multiple signatures in one continuous session, the first signature uses both components, and subsequent ones must use at least one (to balance security with convenience). If signings are not contiguous, each signature uses full credentials. The signature must be used only by its genuine owner; any attempt by someone else requires multi-person collaboration (for high assurance) ([2]). Biometric signatures (like fingerprint) must be designed so only the genuine owner can use them ([33]). IT implication: Configure signing so it executes the required signature components, not merely a confirmation click. During one continuous period of controlled system access, the first non-biometric signing must execute all components and each subsequent signing must execute at least one component that only the signer can execute; signings outside that continuous period must execute all components. Do not allow reuse of old passwords.

  • Password Controls (11.300): If ID/password combos are used, controls must ensure their security ([34]). This includes: unique ID/password per person (no two users share a combo); periodic expiration and forced changes; a process to deauthorize lost/stolen tokens (e.g. if a user’s laptop is stolen); transaction safeguards to detect unauthorized use of credentials (e.g. an alert on repeated failed logins); and initial/periodic testing of tokens to ensure they haven’t been tampered ([34]). IT implication: Implement enterprise password policies (expiration, length, history). Integrate with mobile device management if tokens or authenticator apps are used. Ensure procedures exist for quickly disabling a user’s account if their credentials are compromised. Real-time intrusion detection (locking out after X bad attempts) can help.

Importantly, Part 11 does not mandate a specific e-signature technology ([35]). FDA allows username/password, biometric, digital certificates, etc., as long as they meet 11.200/11.300. (For example, biometrics must be unique and non-reusable ([33]).) A 2024 FDA guidance notes that methods like ID cards, biometrics, and digital signatures are all acceptable ways to meet Part 11 signature standards ([35]). In short, IT can choose the technology, but must enforce the rules above.

Finally, Part 11 contains no § 11.100(f). In practice, organizations should support reliable attribution through the applicable identity-verification, unique-signature, signature-component, access-control, signature-manifestation, linking, and accountability-policy requirements. Audit trails and administrative controls can help investigate a disputed signature, but they do not create a standalone Part 11 burden to disprove every denial.

Data Integrity Principles

Though not a section of Part 11 itself, data integrity underlies the entire regulation. Every control above supports keeping records ALCOA+ (Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, Available). As Ludwig Huber explains: “Protecting the integrity of data is a challenge of 21 CFR Part 11 compliance. Integrity requires records to be complete, intact, and maintained in their original context – associated with the procedures which were used to create the data” ([36]). In practice, companies often develop Data Integrity policies (or follow industry guidelines, e.g. MHRA’s guide) that complement Part 11.

For IT teams, data integrity means ensuring source data cannot be falsified or lost. This includes: disabling or monitoring features like “auto-save” or “undo history” in office software that might overwrite original entries; controlling who can edit audit trails; ensuring databases prevent gaps in sequences; etc. It also means checking that all regulated data (including metadata such as audit trails) is backed up and stored so it cannot be invisibly changed. Educating users is part of this — staff must not try to override or delete audit logs to “hide” problems. IT should implement logs of audit: for example, when audit trail entries are written, make a separate system log to ensure they happened.

Case in Point: Industry analysis shows regulators are focusing heavily on data integrity. Climet Inc. notes that in recent years “infractions related to data integrity have been noted in several FDA Warning Letters” and that since 2017 it has been a “major audit concern” for regulators ([37]). Barbara Unger reports that “data integrity and data governance continue to be addressed in approximately 80% of FDA warning letters” ([8]) ([9]). A modern Part 11 enforcement is often about demonstrating, via audit trails and documentation, that data have remained intact. In FDA inspections today, reviewers expect audit trails to capture why each change was made and to preserve history ([21]) ([22]).

System Validation and Quality Management

21 CFR 11.10(a) explicitly calls for system validation ([1]), and FDA guidance emphasizes a life-cycle approach. A major shift occurred in September 2025 when FDA finalized its Computer Software Assurance (CSA) guidance, which formally endorses a risk-based, least-burdensome approach to software validation – including scripted testing, unscripted/exploratory testing, continuous monitoring, and leveraging supplier evidence where appropriate ([38]). This supersedes the legacy GPSV Section 6 guidance and aligns with ISPE's GAMP 5 Second Edition (published July 2022), which similarly promotes critical thinking by subject matter experts over rigid documentation checklists ([39]). In practice, IT must establish a Computer Software Assurance process (formerly CSV). Key points:

  • User Requirements and Risk Assessment: Before implementing any system, IT should define what GxP requirements it must meet (functional requirements) and perform a risk assessment. This assessment, as explained in a Beckman example, identifies where most errors or data integrity risks lie (e.g. data entry fields, calculations) ([16]). Validation effort is proportional to risk.

  • Test Planning and Execution: For each major system (ERP, LIMS, QMS, etc.), develop OQ/PQ test scripts that demonstrate controls (e.g. an audit trail entry is created when changing a record; only the new value appears as current while old value is in log). Include “challenge tests” for key controls. Document all testing results.

  • Ongoing Change Control: Any changes (software upgrades, patches, database migrations) require re-validation or impact analysis. IT should implement a Change Control procedure (as required by 11.10(k)), logging all modifications to systems and re-testing where needed.

  • Governance: IT Quality Assurance should periodically audit the validation program. Part 11 § 11.10(i) requires that persons who develop, maintain, or use electronic-record/electronic-signature systems have appropriate education, training, and experience. Support staff should be trained on the organization’s applicable assurance and validation procedures. CSA terminology and methods may be relevant for medical-device production or quality-management-system software, while other systems require an approach based on their applicable predicate rules and documented risk assessment. The GAMP 5 Second Edition also explicitly supports agile and iterative development methodologies and expanded coverage for cloud computing, AI/ML, and open-source software.

Proper validation is often the foundation of Part 11 compliance: it ensures the system does what it is supposed to do (preserving data integrity) and that IT documentation (e.g. design specs) exists for audits. IT should keep validation records (plans, scripts, reports) readily available – these themselves become regulated documents.

Implementation for IT Teams: Infrastructure and Software

Access Control and Cybersecurity

While Part 11 does not explicitly address cybersecurity, in modern context security and Part 11 overlap heavily. IT teams must treat GxP systems with high security: apply enterprise best practices (firewalls, encryption, malware protection) in addition to Part 11 controls. Often, regulators expect that GxP networks are segmented and secured similarly to other quality systems. For example, any workstation that signs off records should have strong login credentials (complex passwords, periodic change, screened for breaches). Antivirus scanning and OS patching should be rigorous, but documented as part of CSV and not disruptive to record integrity.

Access management is crucial. For instance, implementing multi-factor authentication (e.g., smartcard+PIN) for critical systems enhances compliance with unique signatures rules ([2]). Also, audit logs of access events (login/logout, failed attempts) help prove who accessed what when. Some regulated companies integrate identity providers (IdP) and Single-Sign-On (SSO) solutions, but must ensure they meet Part 11 criteria (no sharing of accounts, strong password policies).

Data Storage and Backup

Part 11 requires “accurate and ready retrieval” (11.10(c)) ([15]). Therefore, IT must enforce robust backup/archival procedures. This often means daily (or even intra-day) backups of critical databases, with at least two independent copies (onsite and offsite). Backup processes should be validated to ensure they capture audit trails as well as records. Test restores regularly. For cloud-based data, ensure the cloud provider has geo-redundant storage and provides proof of backups. Retention schedules must align with regulatory requirements (e.g. drug CGMP often requires 1 year beyond expiration, investigational studies often 2+ years). Automate retention enforcement if possible.

Software Systems and GxP Tools

IT teams typically manage a suite of regulated software: LIMS (Laboratory Information Mgmt), ELN (Electronic Lab Notebooks), MES (Manufacturing Execution), QMS (Document Control, CAPA, etc.), eTMF (trial master file), EDC (electronic data capture), etc. Each must be Part 11-compliant or configured to be. Some products are “21 CFR Part 11 certified” by vendors, but IT should still verify each installation, upgrade, or customization. Key actions include:

  • Enabling audit trail features (and configuring them to log all required fields). For example, one vendor notes their system “provides 21 CFR Part 11 compliant audit trails allowing you to monitor and record all document-related actions for accountability, traceability” ([40]).
  • Locking down configuration screens so that only administrators can change due process.
  • Integrating with e-signature modules. Some systems have built-in signature workflows (like a built-in “sign” button in a QMS), others rely on external PKI. IT should set up any required digital certificates or secure hashing.
  • Documenting any system interconnections. If two systems exchange data (e.g. LIMS → ERP), the transfer mechanism must be validated (does it preserve integrity?). Interfaces should be secured (API keys protected, TLS encryption).

Cloud and SaaS Considerations

Many companies now use cloud or SaaS for GxP systems. IT should determine whether each implementation is closed or open under Part 11 by assessing whether persons responsible for record content control system access. Hosting location, a vendor’s role, a VPC, or internet access alone does not decide the classification. The regulated company remains accountable for meeting applicable requirements on cloud platforms ([28]). In practical terms, IT should perform due diligence, obtain relevant vendor documentation, document the access-control determination, and ensure contracts and system configuration support required records and inspections.

Training and SOPs

Part 11 requires written policies and trained personnel ([24]). IT teams must often help author and maintain the Standard Operating Procedures (SOPs) for system use. For example, SOPs should cover “User Administration” (how to create/disable accounts, manage passwords), “System Backups”, “Change Control”, etc. Training records should show that IT staff were trained on these Part 11 SOPs, and that end-users were trained on how to properly use the systems (e.g., not to share logins, how to apply e-signatures correctly). Ensuring that updated system procedures follow each software change is critical.

Audit Trails and Monitoring

Since audit trails are a cornerstone of Part 11, IT must also work with Quality to routinely review them. For example, monthly or quarterly audits of log reports should check for unauthorized deletions or unusual access patterns. Alerts can be set so that high-severity issues (like someone logging in at 3 AM or deleting an audit log entry) trigger immediate review. Systems should time-synchronize logs to make it obvious if someone “re-enters history.” We note that software providers often highlight audit trail features: SimplerQMS advertises that its audit logs “automatically capture all necessary information as outlined in 21 CFR Part 11” and can “show evidence of who did the change, to what, when, and why” ([41]). IT teams should strive to provide that level of traceability.

Additionally, IT is responsible for maintaining “system logs” beyond just data audit trails. For example, Windows/Linux event logs, database logs, and application server logs should be preserved and available. While Part 11 focuses on data records, during an FDA inspection an entire set of logs may be requested to prove system integrity.

Electronic Signatures – Operational Workflow

From a practical perspective, Part 11 means replacing paper signature stamps with digital ones. Typical implementation: a user logs into the system (gaining at least two-factor auth); when they need to sign a record (e.g. release a batch or approve a protocol), the system either requests a re-entry of password or uses a connected token to generate a digital signature. That signature event must be recorded in the audit trail with the signer’s ID and timestamp. Some organizations require dual signatures (concurrent or sequential) for high-risk actions (multi-user_signatures per some specs), which is also allowed by 11.200: no single person may hijack another’s signature without collusion. ([42]).

One nuance: for continuous workflow (“session”), the system may allow multiple signings without full re-login each time, as long as each signature event is captured. ([2]). This is common: a QC manager might log in once and then sign 10 test results in a row. The rule says: full credentials on the first signature, then at least one factor (usually password) on subsequent ones. IT should ensure the system enforces this correctly – e.g. a user must not be able to “rubber-stamp” multiple sign-offs without affirmation.

Letters of Nonrepudiation: While 21 CFR 11 required users to send FDA a signed letter asserting their e-signature as binding in the 1990s, this has become a formal compliance step. In 2024 guidance, FDA still mentions that each e-signature user must send a letter to FDA and provide it upon request ([35]). In practice, most firms have users sign a global ITS SOP that includes that assertion, or maintain template letters. IT should ensure any such commitment is documented (e.g. in personnel files).

Record Retention and Copies (Subpart B)

Part 11 record-retention expectations must be read with the applicable predicate rules. For example, drug CGMP production, control, and distribution records specifically associated with a batch generally must be retained for at least one year after the batch expiration date; other records, products, and clinical-investigation contexts can have different requirements ([15]). The system must protect against premature deletion. IT should implement archival processes that lock records until retention lapses. Before deleting, some systems can automatically flag or require a manager’s override with justification (to align with 11.10(k)’s revision controls).

Generation of accurate copies (Sec.11.10(b) above) means IT must also ensure the system can export or print records on demand. For example, FDA-inspectors often ask for PDFs of data with audit trails. Ensure reporting tools can produce binding copies. Sometimes IT provides “read-only” export accounts or captured snapshots in EDMS.

Open vs. Closed System Determination

IT must consciously determine whether each implementation is a closed or open system under § 11.3. The test is whether persons responsible for the content of the electronic records control system access; on-premises deployment, cloud hosting, internet access, contractors, and vendor-operated authentication are not individually dispositive. If the system is open, § 11.30 requires procedures and controls appropriate to ensure authenticity, integrity, and confidentiality, including additional measures such as encryption and appropriate digital-signature standards as necessary. Document the access-control determination and the resulting controls ([43]).

Illustration: Consider a supplier-managed cloud ERP. Determine whether persons responsible for the electronic-record content control access to that implementation, then document the result. If it is an open system, apply § 11.30 controls as necessary to ensure record authenticity, integrity, and confidentiality; encryption and appropriate digital-signature standards are examples of measures the regulation identifies.

AWS’s GxP Appendix underscores that even on cloud, the customer is responsible for interpreting Part 11 ([28]). Cloud systems are not a separate “semi-open” category: document whether persons responsible for record content control system access, then apply the controls appropriate to the resulting classification and use case.

Data Integrity and ALCOA Principles

Beyond specific controls, IT must embrace data integrity holistically. Data integrity means records are complete, consistent, accurate, and original. Typical IT measures include:

  • Timestamp accuracy: Synchronize all system clocks (NTP) to ensure audit logs have consistent timestamps.
  • Legibility: If data are transferred to humans (printouts, reports), confirm they include all audit and metadata. For example, a printed batch record should list every revision or log entry with who changed what.
  • Contextual linkage: Maintain all relational data. If a database record has foreign keys, ensure related tables stay intact in backups.
  • No “blanking”: As FDA has emphasized, once a record is finalized, it should not be erased or overwritten without trace. IT can enforce this at the database level (e.g., no DELETE privileges for normal users; any delete triggers an audit).

One more concept: “Review, secure and archive”. Part 11 itself doesn’t say “review”, but FDA expects training records and SOPs to show that data is regularly reviewed (by QA) for integrity. IT should support this via dashboards or reporting for compliance teams to spot-check entries.

A Risk-Based Approach is advisable. As Beckman explains, a risk focus means identifying where errors are likely and building appropriate controls ([16]). For example, if a cleanroom log is typed into a Word doc, risks include typos or unauthorized edits – IT could require checkboxes in software rather than free text. If a PLC outputs values automatically, the raw signal path should be tested for integrity. The idea is to apply Part 11 rigor where the patient or product safety impact is highest.

Case Examples and Scenarios

To illustrate, consider a pharmaceutical lab implementing a new LIMS in the cloud:

  • User Management: IT assigns each analyst a unique ID and enforces password complexity. All login attempts (success or fail) are logged (11.300) ([34]). The LabVantage whitepaper notes its system “tracks logon attempts (successful and failed) including user ID, date/time… meaning of action” ([44]). This meets Part 11’s requirement to “ensure each individual has a unique identity” and to alert on unauthorized attempts.
  • Audit Trail Validation: The IT/Quality team conducts a test: a test analyst edits a record; the system automatically logs the old and new values. If the analyst tries to disable the audit log via admin menu, the system denies it or records the attempt. This demonstrates compliance with Sec.11.10(e) requiring the audit trail to be “computer-generated” and uneditable.
  • Backup/Retention: IT schedules nightly backups to secure encrypted tape and a cloud vault. The system is configured to retain records for 5 years. Every backup set also includes the database of audit trails. A restoration drill confirms data can be restored in full, satisfying 11.10(c) on retrievability.
  • Signatures: When a supervisor “releases” a batch in MES, the system pops up a prompt for that supervisor to enter password again. Once entered, the record in the database shows the supervisor’s ID, date/time, and the action “Batch Release”. This addresses the applicable 11.50 and 11.200 requirements. The printed batch protocol report includes the signature manifest as required by 11.50: “Released by John Smith – 2024-08-15 10:23 – Approved”.
  • Legacy Data Migration: The team migrates 10-year-old QC data from a deprecated system (pre-1997 era) into the new LIMS. FDA’s 2003 guidance says legacy systems may have some flexibility ([45]), but migrating data into an active system implies compliance. So IT documents the migration process and validates that all values moved correctly (ensuring no data integrity gap).

In terms of enforcement, FDA warning letters provide real-life examples: for instance, a medical clinic was cited in 2005 because its EMR system was not meeting Part 11 when maintaining patient records. The FDA reminder was blunt: using an electronic medical record "requires meeting" Part 11's "specific requirements" (the clinic had been relying on informal data controls). More recently, FDA has continued to issue warning letters for Part 11 deficiencies – including a January 2025 case where data integrity findings during a BIMO inspection led to a complete response letter, warning letter, and shareholder lawsuit. Similarly, FDA has issued warning letters to drug firms for spreadsheet misuse (e.g. formulas that allowed record history to be overwritten) – underscoring the lesson that even standard tools must be strictly configured.

Another hypothetical: a small biotech using Office 365 for GxP data. Without Part 11-focused settings, things like co-authoring or cloud syncing could break audit trails. To comply, IT might choose to disable cloud autosave on Word for regulated documents, and require that any official record be saved as a PDF through a validated export process. It might also implement DLP (data-loss prevention) to stop unapproved cloud sharing of GxP data. The key is that no electronic “shortcut” is allowed to bypass the controls above.

Data Analysis, Enforcement and Compliance Trends

FDA's visible stance on Part 11 compliance has varied. After the 2003 enforcement guidance, Part 11 citations dipped for a time, but data integrity issues remained prominent. Unger's analysis found ~80% of warning letters by 2016 involved data integrity ([8]) ([9]). A 2026 journal article, published online in October 2025, analyzing 1,766 FDA warning letters from 2016–2023 found no statistically significant pre-/post-pandemic differences. It identified year-over-year increases in selected categories after 2020 and patterns consistent with risk-based data-integrity oversight, but cautioned that causality cannot be inferred. Notably, many warning letters cite predicate rules (CGMP 211) for unmaintained data, but the underlying cause can include weak electronic controls.

Enforcement accelerated sharply in 2025: FDA issued 327 warning letters between July and December 2025, a 73% increase over the same period in 2024. Data integrity, incomplete production records, and deficient access controls were among the most common citations. FDA has also signaled heightened rigor and data-driven targeting in its inspection strategy, meaning firms with prior Part 11 deficiencies face elevated scrutiny.

A key trend is harmonization and modernization: FDA's Oct 2024 final guidance clarifies Part 11's role in modern contexts (e.g., clinical trial digital technologies) ([11]), and the September 2025 CSA guidance fundamentally shifts how validation is approached. For IT, this means staying alert to new guidance: e.g. handling data from wearables (digital health) under Part 11, adopting risk-based validation via CSA, or vetting AI/ML tools that process records ([46]).

The key takeaway is proactive compliance: do not assume FDA will ignore Part 11. Indeed, DocuSign and Adobe have published guides showing how e-signature platforms can be configured to meet Part 11, signaling industry demand for compliant solutions.

Global Context and Annex 11 Comparison

While 21 CFR Part 11 is U.S.-focused, the pharmaceutical and biotech industries are global. In the EU, GMP Annex 11 (Part 11’s counterpart) sets out rules for computerized systems under EU Good Manufacturing Practice. Both regulations share goals: data integrity, secure records, audit trails, and controlled e-signatures. However, they differ in scope and approach. Table 2 highlights major differences:

Table 2: Key Differences Between 21 CFR Part 11 and EU GMP Annex 11

T.03
Aspect21 CFR Part 11 (US)EU GMP Annex 11
Legal StatusFederal regulation, Part of Title 21 CFR ([13]); binding on FDA-regulated firms.Annex 11 is European Commission guidance within the EU GMP Guide. It informs the application of GMP obligations that rest on binding EU legal acts and is used in GMP inspections; it should not be characterized simply as non-binding.
ScopeApplies to any electronic records/signatures for FDA submissions or GMP/GCP/GLP compliance ([3]). Even covers clinical systems if data may support FDA applications.Applies to all computerized systems used in GMP-regulated manufacturing/testing in the EU. (Does not by itself address clinical trial systems).
ValidationRequires system validation (Sec. 11.10(a)) ([1]); FDA’s approach has historically been risk-sensitive.Emphasizes risk-based validation explicitly: Annex 11 §1 states computerized system lifecycle must be managed (validation, change control, etc.) using risk management.
Audit TrailsMandatory in closed systems (Sec.11.10(e)) ([20]). Must record date/time, user, activity.Also mandatory; Annex 11 §3.10 mandates audit trails/notes for GMP record changes. Emphasizes audit trail review as part of QMS.
Electronic SignaturesMust be unique to one individual ([47]); Part 11 requires non-repudiation letter (Sec.11.100) and dual-components for signatures ([2]).Also requires unique signatures; does not require FDA non-repudiation letter. Annex 11 emphasizes procedures for e-sign use but is less prescriptive on components (focus on equivalent to paper).
Infrastructure (Open/Closed)Specifies separate rules for open vs closed (11.10 vs 11.30) ([27]); e.g. open systems need encryption.Does not use “open/closed” terminology; implicitly assumes all data must be protected. Specifically requires data encryption for data in transit or published outside system boundary.
Records CopyMust produce accurate copies (Sec.11.10(b)) ([48]). Digital copies need to be inspectable.Requires ability to produce hard/electronic copies. Annex 11 §3.4 covers backup and retrieval similarly.
Scope of ApplicabilityApplies according to § 11.1 and FDA’s record-by-record scope guidance, including qualifying predicate-rule records maintained or relied on electronically, electronic submissions to FDA, and qualifying electronic signatures.Applies to GMP (drugs/devices) in EU. Clinical only if related to manufacturing (ICH/GCP has separate guidance).
Future OutlookFDA finalized clinical-investigation guidance in October 2024 and revised Computer Software Assurance guidance in February 2026. The CSA guidance concerns medical-device production and quality-management-system software under 21 CFR Part 820. FDA’s AI guidance for drug and biological products remains draft. Part 11 text is unchanged.Annex 11 was last updated in 2011. It remains part of the EU GMP Guide and informs the application of underlying GMP obligations.
SourceUS FDA Title 21 Code of Federal Regulations ([1]).EU GMP Guide Annex 11 (Volume 4 of EudraLex).

In practice, companies selling products in both markets often design systems to the stricter standard of the two. Generally, Part 11 is seen as more prescriptive on certain technical points (e.g. the “two-component” requirement for e-sigs), whereas Annex 11 is more risk- and lifecycle-focused. IT can leverage similarities: for example, ensuring a system has a validated audit trail, strong security, and user authentication covers the main points of both regulations ([20]) ([27]).

Current Practices and Data Insights

Audit Findings: Surveys of FDA 483 inspection observations show that Part 11 alone is rarely cited by number – inspectors usually cite predicate rules (e.g. 21 CFR 211.68 for cleaning records) when data control fails. But the underlying issues often trace to Part 11 problems (missing audit trail, unauthorized signers, etc.). Common deficiencies include absent or incomplete audit trails, poor system validation, and insufficient e-signature controls. In 2025, FDA inspection strategy shifted toward heightened rigor and data-driven targeting, meaning companies with prior data integrity findings face increased surveillance.

Vendor Solutions: The vendor and academic community offer many compliance tools. For example, AWS provides a Part 11 Audit Manager framework to help customers audit their environments ([49]). LIMS and QMS providers highlight compliance features: SimplerQMS claims its system “automatically captures all necessary information as outlined in 21 CFR Part 11” in its time-stamped audit trail ([41]), and emphasizes training users to meet requirements ([50]). DocuSign and Adobe publish white papers on configuring e-signature platforms for Part 11 (adding password/password+OTP modes, encryption, audit logs).

Training and Culture: Even with the right tech, user behavior matters. Instances of “workarounds” (e.g., sharing logins or writing signatures on paper then scanning) are strictly against Part 11. Modern compliance programs stress that Part 11 is “not an IT project alone” but a quality project. Responsibility spans IT, Quality, and business. FDA guidance itself notes that computerized system compliance used to be viewed as “the IT department’s responsibility”, but now “data integrity is owned by every person in the firm who develops or completes an official GxP record” ([51]).

Emerging Topics and Future Directions

  • Digital Health and Real-World Data: FDA's Oct 2024 guidance on Part 11 in clinical investigations clarifies new terrain ([11]). It notes that data from electronic health records and wearable devices will not be held to Part 11 until that data enters the sponsor's system. This has implications for IT: eSource data (e.g. EHR feeds) can be considered outside Part 11, but once ingested into an EDC or LIMS, Part 11 controls kick in. IT teams working on data integrations should therefore clearly map where Part 11 begins.

  • Computer Software Assurance (CSA): The September 2025 CSA final guidance represents the most significant shift in Part 11 validation practice in decades. It explicitly endorses a least-burdensome, risk-based approach that can include unscripted/exploratory testing, continuous monitoring, and leveraging supplier evidence – moving away from the exhaustive scripted-testing paradigm. For IT teams, this means validation efforts can now be proportional to the risk each software function poses to product quality and patient safety, reducing unnecessary documentation while maintaining regulatory rigor.

  • Artificial Intelligence: FDA's engagement with AI in regulated settings has accelerated significantly. In January 2025, FDA issued a draft guidance on AI in drug development, proposing a risk-based credibility assessment framework for AI models used in regulatory submissions. In January 2026, FDA and EMA jointly released "Guiding Principles of Good AI Practice in Drug Development", emphasizing human-centric design, fitness for purpose, and robust data governance. For Part 11, this means any AI that processes GxP data (analytics, predictive models, facial recognition for identity verification, etc.) must be validated with audit trails of algorithmic decisions. Documentation requirements are tiered by risk level – high-risk AI applications require full transparency, prospective validation, and ongoing monitoring. IT should proceed cautiously: FDA reminds that human oversight and traceability remain key.

  • Data Integrity Guidance: FDA and global agencies continue to strengthen data integrity expectations. PIC/S published its Good Practices for Data Management and Data Integrity guidance (PI 041-1, effective July 2021), and in February 2026 EMA and PIC/S launched a joint public consultation on a revised data management and integrity concept paper. These do not change Part 11 per se, but they reinforce global expectations around ALCOA+ principles and harmonize requirements across regulatory jurisdictions.

  • Part 11 Rulemaking: To date, no new final rule has amended the text of Part 11 itself. However, the surrounding guidance landscape has changed substantially: the CSA guidance (Sept 2025), the clinical investigations Q&A guidance (Oct 2024), and the AI framework guidance (Jan 2025/2026) all reinterpret how Part 11 principles apply to modern technologies. IT organizations should watch for any official changes in CFR or guidance, and should also monitor the ISPE GAMP 5 Second Edition for evolving industry best practices on cloud computing, AI/ML validation, and agile development in GxP contexts.

Key Takeaway

Part 11 compliance is a complex but essential consideration for computerized systems that create, maintain, or support electronic records and signatures within Part 11’s applicable scope in life-science environments. IT teams must integrate regulatory controls into all aspects of system design, implementation, and operation. Key focus areas are system validation, robust security and access control, comprehensive audit trails, and properly managed electronic signatures – all underpinned by rigorous documentation and training. As regulations evolve, especially with the rise of digital and remote technologies, IT must work closely with Quality and Regulatory Affairs to adapt processes. Ultimately, a well-implemented Part 11 framework not only satisfies FDA, but also strengthens the integrity and reliability of data that underpin patient safety and product quality.

Protecting the integrity of data is a challenge of 21 CFR Part 11 compliance.

04

Tables

Table 1. Summary of 21 CFR Part 11 Controls for Closed Systems

T.01
SectionRequirementDescription / IT Implementation
11.10(a)ValidationValidate system accuracy and reliability ([1]) using risk-based CSV.
11.10(b)Record CopiesGenerate accurate, complete human/electronic copies ([17]) (e.g., validated print/export features).
11.10(c)Records ProtectionSecure storage/backup; ensure records can be retrieved for entire retention period ([15]).
11.10(d),(g)Access & Authority ChecksLimit system access and signing rights to authorized, trained individuals ([15]) ([19]).
11.10(e)Audit TrailEnable secure, time-stamped logs for all create/modify/delete actions ([20]) (unalterable, archived).
11.10(f)Operational ChecksEnforce proper sequencing of steps/events (e.g., order of data entry) ([23]).
11.10(h)Device ChecksVerify validity of data sources (e.g., ensure lab instruments are authorized) ([24]).
11.10(i)TrainingEnsure all system users and maintainers are qualified (training, experience) ([24]).
11.10(j)Signature AccountabilityWritten policy requiring individuals to be accountable for actions under their e-signature ([24]).
11.10(k)Documentation ControlControl distribution and revision of system documentation with audit trail ([25]).

Table 2. 21 CFR Part 11 vs. EU GMP Annex 11

T.04
Aspect21 CFR Part 11 (USA)EU GMP Annex 11 (EU)
Type of RuleFederal regulation (Title 21 CFR, enacted by FDA) ([13]). Mandatory for FDA submissions and GMP-regulated records.European Commission guidance in the EU GMP Guide. It informs the application of binding EU GMP obligations and is used in GMP inspections; it should not be characterized simply as non-binding.
ValidationRequires computer system validation (11.10(a)) ([1]). FDA emphasizes systems be validated to ensure accuracy.Requires risk-based validation of computer systems (Annex 1 & 2). Emphasizes lifecycle approach.
Audit TrailsMandatory in closed systems (Sec.11.10(e)) ([20]). Must log data alterations securely.Mandatory (Annex 11 §3.10): must record changes to GxP data. Requires routine review of trails.
Electronic SignaturesUnique to one person, non-reusable (11.100(a)) ([32]); requires dual factors (11.200) ([2]). FDA demands “non-repudiation” letters.Unique to one person. Requires equivalent control but no formal letter of non-repudiation.
Open/Closed SystemsExplicit rules for closed vs open (Sec.11.10 vs 11.30). Open systems need additional encryption/digital signs ([27]).All computerized systems considered; Annex 11 explicitly requires encryption for data transmission outside secure zones.
Record CopyMust produce accurate, readable copies of records ([17]) for inspection (paper or electronic).Requires ability to make exact copies; usually covered by broader GMP documentation rules.
ScopeApplies to any FDA-regulated electronic record/signature (GMP, GCP, GLP, submissions) ([3]).Applies to computerized systems in GMP-regulated manufacturing/testing.
Key EmphasisPrescriptive on specific controls (audit trails, signature controls, etc.). FDA’s focus on shifting toward data integrity.Emphasis on risk management (validation plans, risk/rule determination), as well as integrity.
Inspector FocusViolations often cited under predicate rules but based on Part 11 deficiencies. Data integrity issues predominate findings ([8]).Many findings on data integrity as well; MHRA and other authorities explicitly link to Annex 11.

Each item above aligns with reputable interpretations. For example, scilife notes that Part 11 is a U.S. regulation on electronic records/signatures ([13]), whereas EU Annex 11 is an EU GMP addendum. Both share goals (data integrity, traceability) but take somewhat different approaches.

05

Conclusion

For IT professionals, 21 CFR Part 11 demands diligence and technical rigor. Organizations should identify the predicate-rule and Part 11 requirements applicable to each regulated-record use case, apply risk-appropriate controls, and manage electronic signatures so they meet the applicable Part 11 requirements. FDA’s current guidance exercises enforcement discretion in specified circumstances for certain Part 11 validation, audit-trail, record-retention, and record-copying provisions, while predicate rules and other specified Part 11 controls remain enforceable. Success depends on integrating IT controls with company quality culture. As one QMS provider emphasizes, audit trails must be comprehensive – “who did the change, to what, when, and why” must be evident ([41]). In practical terms, this means no feature in your software or network can undermine record integrity.

Looking forward, cloud, mobile, and AI tools should be assessed against the applicable Part 11 and predicate-rule requirements. FDA’s October 2024 clinical-investigations Q&A addresses modern electronic systems in that context. FDA’s February 2026 CSA guidance is limited to medical-device production and quality-management-system software under 21 CFR Part 820, and FDA’s AI credibility framework for drugs and biological products remains draft. IT teams should use documented, risk-appropriate assurance activities within the scope of the applicable requirements, maintain vigilance on data integrity, and avoid treating a guidance document as a universal mandate. The fundamentals remain: implement applicable Part 11 controls in design and operation, keep appropriate documentation, and treat electronic records with the same seriousness as paper. In doing so, IT teams can support regulatory compliance and strengthen trust in data that underpin patient safety and product quality.

Sources: Authoritative FDA guidances, the CFR text, and industry expertise (including FDA analyses, peer-reviewed articles, and industry white papers) have been used throughout to support these conclusions ([3]) ([1]) ([4]) ([41]) ([52]) ([8]), ensuring a factual, comprehensive overview.

Sources / 52
Adrien Laurent

Need Expert Guidance on This Topic?

Let's discuss how IntuitionLabs can help you navigate the challenges covered in this article.

I'm Adrien Laurent, Founder & CEO of IntuitionLabs. With 25+ years of experience in enterprise software development, I specialize in creating custom AI solutions for the pharmaceutical and life science industries.

Disclaimer

The information contained in this document is provided for educational and informational purposes only. We make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability, or availability of the information contained herein. Any reliance you place on such information is strictly at your own risk. In no event will IntuitionLabs.ai or its representatives be liable for any loss or damage including without limitation, indirect or consequential loss or damage, or any loss or damage whatsoever arising from the use of information presented in this document. This document may contain content generated with the assistance of artificial intelligence technologies. AI-generated content may contain errors, omissions, or inaccuracies. Readers are advised to independently verify any critical information before acting upon it. All product names, logos, brands, trademarks, and registered trademarks mentioned in this document are the property of their respective owners. All company, product, and service names used in this document are for identification purposes only. Use of these names, logos, trademarks, and brands does not imply endorsement by the respective trademark holders. IntuitionLabs.ai is an AI software development company specializing in helping life-science companies implement and leverage artificial intelligence solutions. Founded in 2023 by Adrien Laurent and based in San Jose, California. This document does not constitute professional or legal advice. For specific guidance related to your business needs, please consult with appropriate qualified professionals.

Related Articles

Need help with AI?

© 2026 IntuitionLabs. All rights reserved.