Document Management for Life Sciences: FDA 21 CFR Part 11 & GMP Records
FDA 21 CFR Part 11 sets the criteria under which the FDA treats electronic records and electronic signatures as trustworthy and equivalent to paper. For life sciences firms it requires validated systems, secure time-stamped audit trails, and controlled electronic signatures, layered on top of the underlying GMP, GLP, and GCP predicate rules that mandate the records in the first place.
FDA 21 CFR Part 11 is the regulation that decides when an electronic record or electronic signature is good enough to stand in for paper and ink in an FDA-regulated environment. The FDA published the final rule on March 20, 1997, and it became effective on August 20, 1997, establishing the criteria under which the agency considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and generally equivalent to paper records and handwritten signatures on paper. For a pharmaceutical or biotech organization, that single sentence has enormous consequences: it is what allows a batch record, a stability dataset, a deviation, or a validation protocol to exist legitimately in a computer system rather than in a binder.
Part 11 is widely misunderstood as a standalone records mandate. It is not. The records that must be created, the data captured, and the retention periods that apply all come from other FDA regulations — the predicate rules — such as current Good Manufacturing Practice for drugs (21 CFR Part 211), Good Laboratory Practice (21 CFR Part 58), and the clinical regulations under Part 312. Part 11 governs only how those records and signatures behave once an organization keeps them electronically, adding controls for validation, audit trails, system access, signature integrity, and record copying on top of obligations that already exist.
This guide explains what Part 11 requires in depth, how the predicate rules and FDA's 2003 scope guidance frame it, how the ALCOA+ data-integrity framework and computer system validation operationalize it, what GxP retention periods apply, and where organizations most often fail in ways that surface as FDA Form 483 observations and warning letters. Reynolds Business Systems, a records and document-management firm based in Emmaus, Pennsylvania, works with these requirements across the Lehigh Valley and the Mid-Atlantic, and the Pennsylvania life-sciences context appears throughout.
What 21 CFR Part 11 is — electronic records and signatures
21 CFR Part 11 is the section of FDA regulation titled "Electronic Records; Electronic Signatures." Its purpose is narrow and specific: to set the conditions under which the FDA will accept electronic records and electronic signatures in place of their paper equivalents. When those conditions are met, the FDA considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and generally equivalent to paper records and handwritten signatures on paper. When they are not met, an electronic record that a predicate rule requires is effectively not a valid record at all — which is why Part 11 deficiencies routinely escalate into data-integrity findings rather than mere paperwork observations.
The rule has applied since August 20, 1997, and it reaches almost every system a modern life-sciences organization runs — LIMS, chromatography data systems, electronic batch record and manufacturing execution systems, electronic quality and document management systems, and the spreadsheets and instrument software in between. The test is functional: if a system creates, modifies, maintains, archives, retrieves, or transmits a record that an FDA predicate rule requires, Part 11 is in scope for that record.
Part 11 distinguishes between closed and open systems, and the distinction drives which controls apply. A closed system is one where access is controlled by the people responsible for the content of the electronic records — the typical case for a validated system running inside a company's own controlled network. An open system is one where system access is not controlled by those responsible for the records, such as records exchanged with or hosted by an outside party over an uncontrolled channel. Open systems must apply the same closed-system controls plus additional measures — including document encryption and the use of appropriate digital signature standards — to assure record authenticity, integrity, and confidentiality.
| Dimension | Closed system (11.10) | Open system (11.30) |
|---|---|---|
| Access control | Controlled by the persons responsible for record content | Not controlled by the persons responsible for record content |
| Typical example | Validated LIMS, CDS, or eQMS on a company-controlled network | Records exchanged with or hosted by an outside party over an uncontrolled channel |
| Controls required | Validation, audit trails, access controls, signature integrity, and the rest of 11.10 | All 11.10 controls plus additional measures such as document encryption and digital signature standards |
| Goal | Authentic, intact, attributable records | Authenticity, integrity, and confidentiality across an uncontrolled boundary |
Predicate rules: why Part 11 never stands alone
The most consequential concept for anyone implementing Part 11 is the predicate rule. FDA's 2003 guidance, "Part 11, Electronic Records; Electronic Signatures — Scope and Application," defines predicate rules as the underlying requirements set forth in the Federal Food, Drug, and Cosmetic Act, the Public Health Service Act, and FDA regulations other than Part 11 itself. In plain terms, the predicate rules say what records you must keep and what they must contain; Part 11 says how those records must behave if you keep them electronically.
For a drug manufacturer the predicate rules live mostly in 21 CFR Part 211 (cGMP) — the batch production and control records required by 211.188, the laboratory records required by 211.194, and the general records and reports requirements of 211.180. For a nonclinical laboratory they live in Part 58 (GLP); for clinical research, in Parts 312 and 812 and the GCP framework. Part 11 attaches to each of those records the moment it exists in electronic form, which is why a Part 11 program cannot be designed in the abstract: map the predicate-rule records first, then apply Part 11 controls to the systems that hold them.
FDA's 2003 guidance also narrowed how aggressively the agency interprets Part 11. Under that guidance the FDA reads the rule narrowly and exercises enforcement discretion over four requirement areas — validation, audit trails, record retention, and record copying — meaning it does not generally take enforcement action on those four under Part 11 alone, provided the predicate-rule requirements are met. Crucially, enforcement discretion is not an exemption: Part 11 otherwise remains in full effect, and every underlying predicate-rule requirement is still enforced. An organization that reads "enforcement discretion" as permission to skip validation or audit trails has misread the guidance, because the predicate rules independently demand both.
Enforcement discretion over validation, audit trails, record retention, and record copying applies to Part 11 — not to the predicate rules. Current GMP at 211.68 still requires validated computer systems and protected backup data, and 211.194 still requires complete, accurate laboratory records. The predicate rule is almost always the stronger obligation.
Retention depends on the record
Record retention by GxP record type (years)
The controls Part 11 actually requires, section by section
The operative requirements for closed systems sit in 21 CFR 11.10, which lists the controls an organization must employ to protect electronic records and ensure their authenticity, integrity, and — where appropriate — confidentiality. Two of those controls dominate inspections. Section 11.10(a) requires validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records. Section 11.10(e) requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions that create, modify, or delete electronic records — and record changes must not obscure previously recorded information.
The electronic-signature requirements are equally specific. Under 11.50, every signed electronic record must display three elements: the printed name of the signer, the date and time the signature was executed, and the meaning associated with the signature — such as review, approval, responsibility, or authorship. Under 11.70, electronic and handwritten signatures executed to electronic records must be linked to their respective records so the signatures cannot be excised, copied, or otherwise transferred to falsify a record by ordinary means. A signature that can be detached from its record and reapplied elsewhere fails this test.
The general signature controls follow in the 11.100 through 11.300 series. Section 11.100(a) requires that each electronic signature be unique to one individual and never reused by, or reassigned to, anyone else. Section 11.200 requires non-biometric electronic signatures to employ at least two distinct identification components — for example, an identification code and a password. And 11.300 requires controls over identification codes and passwords, including maintaining the uniqueness of each combined ID and password so that no two individuals share the same combination, and periodically checking, recalling, or revising issuances, which is the regulatory basis for password aging and de-provisioning. Together these sections make an electronic signature a controlled, attributable act rather than a checkbox.
| Section | Requirement | Practical control |
|---|---|---|
| 11.10(a) | Validation for accuracy, reliability, consistent performance, and discerning altered records | Risk-based computer system validation with documented evidence |
| 11.10(e) | Secure, computer-generated, time-stamped audit trail; changes must not obscure prior data | Enabled, locked audit trail covering create, modify, delete; periodic review |
| 11.30 | Open systems apply 11.10 controls plus encryption and digital signature standards | Encryption and validated digital signatures for records crossing uncontrolled boundaries |
| 11.50 | Signed records display printed name, date and time, and meaning of the signature | Three signature elements rendered on screen and in copies |
| 11.70 | Signatures linked to records and not transferable to falsify a record | Cryptographic or database linkage between signature and record |
| 11.100(a) | Each signature unique to one individual, never reused or reassigned | Identity-verified, individually issued accounts; no shared logins |
| 11.200 | Non-biometric signatures use at least two distinct identification components | ID code plus password (or equivalent two-component scheme) |
| 11.300 | Controls over ID codes and passwords, including uniqueness and periodic revision | Unique credentials, password aging, prompt de-provisioning |
ALCOA and ALCOA+: the data-integrity backbone
Part 11 is the regulation; ALCOA+ is the framework FDA and other regulators use to judge whether the data inside a Part 11 system can be trusted. In its December 2018 guidance, "Data Integrity and Compliance With Drug CGMP," the FDA defines data integrity as the completeness, consistency, and accuracy of data, and states that complete, consistent, and accurate data should be Attributable, Legible, Contemporaneously recorded, Original or a true copy, and Accurate — the acronym ALCOA. These five attributes are the criteria an investigator applies to a raw chromatogram, a weighing record, or an electronic signature when deciding whether the record reflects what actually happened.
ALCOA comprises five core attributes — Attributable, Legible, Contemporaneous, Original, and Accurate. The widely adopted ALCOA+ extension, articulated in the MHRA's 2018 'GXP' Data Integrity Guidance, adds four further attributes — Complete, Consistent, Enduring, and Available — for nine data-integrity attributes in total. The MHRA defines the additions precisely: Complete means the data must be a whole, complete set; Consistent means the data are self-consistent; Enduring means they are durable and lasting throughout the data lifecycle; and Available means they are readily available for review or inspection. The 'plus' attributes are where many electronic systems quietly fail — a record can be attributable and accurate yet incomplete because a failing test result was deleted, or non-enduring because it lives only on a temporary instrument buffer.
| Attribute | Meaning | What it requires in an electronic system |
|---|---|---|
| Attributable | Who created or changed the data, and when | Unique user accounts and a complete audit trail |
| Legible | Readable and permanent | Human-readable rendering preserved for the full retention period |
| Contemporaneous | Recorded at the time of the activity | Synchronized, trusted system clocks; no back-dating |
| Original | The first capture, or a verified true copy | Source records retained; true-copy verification documented |
| Accurate | Correct, valid, and error-free | Validated calculations, controlled changes, second-person checks |
| Complete | A whole, complete set including repeats and reanalyses | No selective deletion; all data and metadata retained |
| Consistent | Self-consistent across the record | Chronological, sequential entries with consistent date and time stamps |
| Enduring | Durable throughout the data lifecycle | Secure, backed-up storage resistant to alteration or loss |
| Available | Retrievable for review or inspection | Readable and producible on request for the full retention period |
A Part 11 system can pass every technical control and still fail data integrity if the data it holds are not complete, consistent, enduring, and available.
Computer system validation: proving the system is trustworthy
Validation is where Part 11 and the predicate rules converge most directly. Section 11.10(a) requires validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records, and current GMP at 211.68 independently requires that automated, mechanical, and electronic equipment be suitable for its intended use and routinely verified. Computer system validation (CSV) is the documented program that satisfies both: it demonstrates, with evidence, that a system does what it is supposed to do and nothing it is not supposed to do.
FDA's data-integrity guidance frames validation in risk-based terms. The agency expects each CGMP workflow on a computer system — for example, creating an electronic master production and control record — to be validated for its intended use, with the extent of validation commensurate with the risk the automated system poses to product quality and data integrity. A simple, low-risk system requires proportionally less validation effort than a configurable MES that releases batches. This risk-based posture is the principle behind FDA's more recent Computer Software Assurance (CSA) thinking, which directs effort toward the functions that matter rather than toward generating documentation for its own sake.
In practice, CSV follows a lifecycle: requirements are defined, the system is qualified through installation, operational, and performance qualification (IQ/OQ/PQ) against those requirements, the Part 11 functions — audit trail, access control, electronic signatures, record copying — are tested explicitly, and the validated state is maintained through change control, periodic review, and revalidation when the system changes materially. The deliverable is a traceable evidence package an inspector can follow from requirement to test to result.
Validate the Part 11 functions, not just the business functions. Inspectors specifically test whether the audit trail can be disabled, whether deleted data are recoverable, whether a signature can be detached from its record, and whether two users can share a login. Build those negative tests into the validation protocol from the start.
Audit trails: the most-cited control in inspections
The audit trail is the single control inspectors examine most closely, because it is the mechanism that makes electronic data attributable and tamper-evident. Section 11.10(e) requires a secure, computer-generated, time-stamped audit trail that independently records the date and time of operator entries and actions that create, modify, or delete electronic records, and it specifies that record changes must not obscure previously recorded information. FDA's 2018 guidance reinforces the concept with a working definition: an audit trail is a secure, computer-generated, time-stamped electronic record that allows reconstruction of the course of events relating to the creation, modification, or deletion of an electronic record.
The requirement is global, not only American. EU GMP Annex 11 (Computerised Systems) requires, based on a risk assessment, building a system-generated audit trail that records all GMP-relevant changes and deletions together with the reasons for them, available and convertible to an intelligible form, and regularly reviewed. The phrase "regularly reviewed" is the part organizations underestimate: an enabled audit trail that no one reviews provides little assurance. Audit-trail review should be part of the routine review of the underlying record — for laboratory data, that aligns with the 211.194(a)(8) requirement for the initials or signature of a second person showing that original laboratory records have been reviewed for accuracy, completeness, and compliance with established standards. A defensible program closes the three common gaps at once: the audit trail must be enabled and impossible for an ordinary user to disable, change-preserving so original values are never overwritten, and routinely reviewed against the record it supports.
Building a Part 11 and GMP compliance program
A defensible electronic-records program is built deliberately, predicate rule first, then layering Part 11 controls onto the systems that hold those records. The sequence below moves from inventory to sustained operation.
- Map the predicate-rule records. Identify every record an FDA regulation requires — batch records under 211.188, laboratory records under 211.194, nonclinical data under Part 58, clinical records under Part 312 — and the systems that create, hold, or transmit each one. Part 11 scope follows this map.
- Classify systems as closed or open, and by risk. Determine which systems are closed (company-controlled access) and which are open (records crossing an uncontrolled boundary), and rank each by the risk it poses to product quality and data integrity, since both scope and validation effort follow risk.
- Validate each system for its intended use. Run risk-based computer system validation that satisfies 11.10(a) and 211.68, explicitly testing the audit trail, access controls, electronic signatures, and record-copying functions, and produce a traceable evidence package.
- Enable, lock, and configure audit trails. Turn on the 11.10(e) audit trail across create, modify, and delete actions, ensure it preserves original values, prevent ordinary users from disabling it, and confirm date and time stamps come from a trusted, synchronized clock.
- Control electronic signatures end to end. Issue unique individual credentials (11.100(a)), require at least two identification components for non-biometric signatures (11.200), render the three signature elements (11.50), link signatures to their records (11.70), and enforce password uniqueness and aging (11.300).
- Operationalize ALCOA+. Confirm that data captured in each system are attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available — and that procedures prohibit selective deletion of results.
- Establish audit-trail and second-person review. Make audit-trail review part of routine record review, and apply the 211.194(a)(8) second-person review to original laboratory records for accuracy, completeness, and compliance.
- Define retention and backup. Set retention periods from the governing predicate rules (cGMP, GLP, IND/GCP), and meet 211.68(b) by maintaining backup data that are exact, complete, and secure from alteration, inadvertent erasure, or loss.
- Govern with SOPs, training, and change control. Document procedures for system use, access management, data review, and disposition; train users to a verifiable standard; and maintain the validated state through change control and periodic review.
- Inspect yourself before the FDA does. Run internal data-integrity audits and mock inspections that probe the same controls an investigator will — disablement of audit trails, recoverability of deleted data, shared logins, and signature integrity.
Worked example: a Lehigh Valley biotech QC laboratory
Consider a hypothetical biotech quality-control laboratory in the Lehigh Valley running a chromatography data system to test drug-product release samples. The figures below combine the cited requirements with clearly illustrative inputs to show how the obligations stack up; the illustrative numbers are labeled as such.
The CDS holds laboratory records required by predicate rule 211.194, so Part 11 attaches. To comply, the lab validates the system for its intended use (11.10(a)); enables a locked, change-preserving audit trail across create, modify, and delete (11.10(e)); issues each analyst a unique account (11.100(a)) secured by two identification components (11.200); and renders the three signature elements — printed name, date and time, and meaning such as 'reviewed' or 'approved' — on every signed result (11.50). Suppose an analyst runs a sample, the result fails specification, and a second injection passes. ALCOA+ requires that both injections be retained: the complete data set, self-consistent and enduring, with the audit trail showing every action. Deleting the failing injection would violate the rule against obscuring previously recorded information and render the record incomplete. A second reviewer then signs under 211.194(a)(8), confirming the original records were reviewed for accuracy, completeness, and compliance — including a review of the audit trail.
The example illustrates the central discipline of Part 11: compliance is a property of the validated system plus the procedures around it, not a feature you buy. The same CDS, configured to allow a shared analyst login or a disable-able audit trail, would be non-compliant on identical hardware.
Retention across the GxP landscape
Part 11 governs how electronic records behave, but the predicate rules set how long they must be kept — and the periods differ sharply by GxP domain. Getting retention wrong is a predicate-rule violation regardless of how well the system is validated. Under cGMP, any production, control, or distribution record associated with a drug-product batch must be retained for at least one year after the batch's expiration date — or three years after distribution for certain over-the-counter drug products that lack expiration dating. Under FDA Good Laboratory Practice, nonclinical-study documentation, raw data, and specimens submitted to FDA in support of a research or marketing permit must generally be retained for at least five years following the submission date, with at least two years required in other circumstances, whichever applicable period is shortest.
Clinical research follows yet another clock. Clinical investigators under an Investigational New Drug application must retain study records for two years after a marketing application is approved for the investigated indication, or for two years after the investigation is discontinued and FDA is notified if no application is approved. Because these periods are tied to events — expiration, submission, approval, discontinuation — rather than to a fixed calendar, an electronic records system has to capture the triggering event and hold the record until the correct clock runs out, which is far harder to manage in spreadsheets than in a controlled records system.
| Record type | Governing rule | Minimum retention |
|---|---|---|
| Drug-product batch production, control, and distribution records | 21 CFR 211.180 (cGMP) | At least 1 year after the batch expiration date |
| Certain OTC drug products lacking expiration dating | 21 CFR 211.180 (cGMP) | 3 years after distribution |
| Nonclinical study documentation, raw data, and specimens (submitted to FDA) | 21 CFR 58.195 (GLP) | At least 5 years after submission (at least 2 years in other circumstances) |
| Clinical investigator records under an IND | 21 CFR 312.62 (IND/GCP) | 2 years after marketing approval, or 2 years after discontinuation and FDA notification |
Retention also requires protected backups and complete underlying records. Section 211.68(b) requires that a backup file of data entered into a computer or related system be maintained, with hard copy or alternative systems ensuring the backup data are exact, complete, and secure from alteration, inadvertent erasure, or loss. The batch record itself must be complete: 211.188 requires batch production and control records that include complete information, an accurate reproduction of the master record (checked, dated, and signed), and identification of the persons performing and checking each significant step. An incomplete backup, or a batch record missing a step's attribution, fails the predicate rule even if Part 11's electronic controls are flawless.
Audit, enforcement, and the 483 and warning-letter trail
FDA inspections test Part 11 and data integrity directly, and the consequences run on an escalating path. During an inspection, observations of objectionable conditions are documented on an FDA Form 483. The firm responds; if the agency judges the response or the underlying conditions inadequate, it can issue a warning letter, and persistent or serious data-integrity failures can lead to import alerts, consent decrees, application-approval delays, and withholding of approvals. Data-integrity findings are treated with particular seriousness because they call into question not one record but the reliability of an entire dataset.
The patterns in FDA's data-integrity enforcement are consistent enough that the 2018 guidance was written as questions and answers addressing them: audit trails that were disabled or not reviewed (11.10(e)), shared login credentials that defeat attributability (11.100(a)), original data deleted or overwritten (the ALCOA+ 'Complete' attribute), and systems used in production before validation (11.10(a)). An organization that has genuinely implemented the controls in this guide has, by construction, addressed the most common findings.
Enforcement discretion over validation, audit trails, record retention, and record copying applies only to Part 11 as such. The predicate rules — 211.68's validated systems and secure backups, 211.188's complete batch records, 211.194's reviewed laboratory records — carry no such discretion, and the most damaging inspection findings are usually written against them, with Part 11 cited alongside. Preparing for an inspection therefore means preparing the predicate-rule records first and the Part 11 controls that protect them second.
Where organizations get this wrong
The failures in this area are predictable, and most come from treating Part 11 as a software-purchasing decision rather than as a validated-system-plus-procedures discipline.
- Believing software is 'Part 11 compliant' out of the box. The FDA does not certify or approve software as Part 11 compliant; compliance depends on how a system is validated, configured, and operated. A capable product configured to allow shared logins or a disable-able audit trail is non-compliant.
- Misreading enforcement discretion as exemption. The 2003 guidance applies discretion to four Part 11 areas — validation, audit trails, record retention, and record copying — but the predicate rules still require all four, so skipping them is a predicate-rule violation.
- Leaving audit trails off, disable-able, or unreviewed. Section 11.10(e) requires a secure, change-preserving audit trail, and an enabled audit trail no one reviews catches nothing.
- Sharing login credentials. Section 11.100(a) requires each signature to be unique to one individual and never reused; shared accounts destroy attributability and are a frequent data-integrity finding.
- Allowing selective deletion of data. Deleting a failing injection or an unfavorable result violates the rule against obscuring previously recorded information and breaks the ALCOA+ 'Complete' attribute.
- Skipping the negative validation tests. Validation that proves the business workflow but never tests whether the audit trail can be turned off, deleted data recovered, or a signature detached leaves the Part 11 controls unproven.
- Treating retention as one fixed period. cGMP, GLP, and IND records run on different, event-based clocks; a single calendar date causes premature destruction or indefinite, undefensible retention.
- Forgetting open-system controls. Records crossing an uncontrolled boundary need 11.30's added measures — encryption and digital signature standards — on top of the closed-system controls; cloud and partner exchanges are where this is missed.
Part 11, GMP, and the Pennsylvania life-sciences context
Pennsylvania, and the Lehigh Valley in particular, hosts a dense cluster of pharmaceutical, biotech, medical-device, and contract-development-and-manufacturing operations, alongside the academic and clinical research that feeds them. For these organizations the requirements in this guide are not abstract: every electronic batch record, stability dataset, validation protocol, and signed deviation lives or dies by whether the system holding it is validated, its audit trail is enabled and reviewed, and its signatures are controlled and attributable. The regulations are set federally by the FDA — and, for firms shipping to Europe, by EU GMP Annex 11 — but the day-to-day work of making records defensible is operational and local.
Reynolds Business Systems is a family-owned records and document-management firm based in Emmaus, Pennsylvania, serving the Lehigh Valley — Allentown, Bethlehem, and Easton — and the broader Mid-Atlantic for more than 55 years. Life-sciences organizations across the region face the same challenge this guide describes: predicate rules require the records, Part 11 governs how they must behave electronically, and ALCOA+ judges whether the data can be trusted. The operational work — digitizing legacy paper records to legible, enduring, retrievable formats, organizing retention so each record is held for the correct event-based period and disposed of defensibly, and structuring documents so an FDA inspection or partner audit goes smoothly — is where a records partner adds value. The regulations are set by the FDA; the role of a records partner is to make meeting them dependable and auditable.
Frequently asked questions
What is the 21 CFR Part 11 document?
21 CFR Part 11 is the FDA regulation titled "Electronic Records; Electronic Signatures." Published on March 20, 1997 and effective August 20, 1997, it sets the criteria under which the FDA considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and generally equivalent to paper records and handwritten signatures on paper.
Is 21 CFR Part 11 a legal requirement by the FDA?
Yes. Part 11 is an enforceable FDA regulation that applies whenever an organization keeps, in electronic form, a record that an FDA predicate rule requires. FDA's 2003 guidance narrows how the agency interprets it and applies enforcement discretion to four areas — validation, audit trails, record retention, and record copying — but Part 11 otherwise remains in effect and the underlying predicate-rule requirements are fully enforced.
What are predicate rules under 21 CFR Part 11?
FDA's 2003 scope guidance defines predicate rules as the underlying requirements in the Federal Food, Drug, and Cosmetic Act, the Public Health Service Act, and FDA regulations other than Part 11 itself — for example cGMP (Part 211), GLP (Part 58), and the clinical regulations (Part 312). The predicate rules say which records you must keep and what they contain; Part 11 governs how those records must behave electronically.
What is a 21 CFR Part 11 compliance checklist?
A working checklist tracks the controls the rule requires: validated systems (11.10(a)); secure, time-stamped, change-preserving audit trails (11.10(e)); open-system measures such as encryption (11.30); the three signature elements of printed name, date and time, and meaning (11.50); signature-to-record linking (11.70); unique individual signatures (11.100(a)); at least two identification components (11.200); and ID/password controls including password aging (11.300) — all mapped to the predicate-rule records they protect.
What records are exempt from 21 CFR Part 11?
Part 11 applies to electronic records that an FDA predicate rule requires. Records that are not required by a predicate rule, and true paper records that an organization maintains and signs on paper, generally fall outside it. Under FDA's 2003 guidance the agency also exercises enforcement discretion over four Part 11 requirement areas — validation, audit trails, record retention, and record copying — but this is enforcement discretion, not an exemption, because the predicate rules still require those things.
How do you comply with 21 CFR Part 11?
Map the predicate-rule records first, then apply Part 11 controls to the systems holding them: validate each system for its intended use, enable and lock a change-preserving audit trail, issue unique individual credentials with at least two identification components, render and link electronic signatures, operationalize ALCOA+ so data are complete and enduring, set retention from the governing predicate rule, maintain secure backups under 211.68(b), and review audit trails and original records by a second person.
Is DocuSign 21 CFR Part 11 compliant, and can it be used for regulated documents?
The FDA does not certify or approve any software — including general e-signature tools — as "Part 11 compliant." Compliance is a property of how a system is validated, configured, and operated, not a vendor badge. An electronic-signature platform can be used in a Part 11-compliant manner only if, for the regulated record in question, it delivers the required controls: signatures unique to one individual (11.100(a)), at least two identification components (11.200), the three signature elements (11.50), signature-to-record linking (11.70), and a secure audit trail (11.10(e)) — and only if the implementation is validated for that use.
What is the difference between a closed and an open system?
A closed system is one where access is controlled by the persons responsible for the content of the electronic records — typically a validated system on a company-controlled network governed by 11.10. An open system is one where access is not controlled by those persons, such as records exchanged with or hosted by an outside party. Under 11.30, open systems must apply the closed-system controls plus additional measures, including document encryption and appropriate digital signature standards.
What is ALCOA+ and how does it relate to Part 11?
ALCOA is FDA's data-integrity framework — data should be Attributable, Legible, Contemporaneous, Original, and Accurate. ALCOA+ adds Complete, Consistent, Enduring, and Available, for nine attributes in total, as articulated in the MHRA's 2018 data-integrity guidance. Part 11 provides the technical controls (audit trails, access control, signatures); ALCOA+ is the lens regulators use to judge whether the data inside those controlled systems can actually be trusted.
What does an audit trail have to do under Part 11?
Section 11.10(e) requires a secure, computer-generated, time-stamped audit trail that independently records the date and time of operator entries and actions that create, modify, or delete electronic records, and record changes must not obscure previously recorded information. FDA defines it as a record that allows reconstruction of the course of events around a record's creation, modification, or deletion. EU GMP Annex 11 adds that the audit trail be risk-based, capture reasons for changes, and be regularly reviewed.
How long must FDA-regulated records be retained?
Retention is set by the predicate rule and is usually event-based. Under cGMP, batch production, control, and distribution records are kept at least one year after the batch's expiration date — or three years after distribution for certain OTC products lacking expiration dating. Under GLP, nonclinical study documentation submitted to FDA is generally kept at least five years after submission (at least two years in other circumstances). Clinical investigator records under an IND are kept two years after marketing approval or after the investigation is discontinued with FDA notified.
What is computer system validation (CSV) and is it required?
CSV is the documented program that demonstrates a computerized system does what it is intended to do and can discern invalid or altered records. It is required: 11.10(a) mandates validation, and cGMP 211.68 independently requires automated equipment to be suitable and verified. FDA expects each GMP workflow to be validated for its intended use, with the extent of validation commensurate with the risk the system poses — the risk-based principle behind FDA's Computer Software Assurance approach.
Sources Cited
20 REFS- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- Electronic Code of Federal Regulations (eCFR), U.S. FDA / Office of the Federal Register
- U.S. Food and Drug Administration (CDER/CBER/CDRH/CFSAN/CVM/ORA)
- U.S. Food and Drug Administration (CDER/CBER/CVM)
- Medicines & Healthcare products Regulatory Agency (MHRA), UK
- European Commission, Health and Consumers Directorate-General



