Humanize Health

21 CFR Part 11Electronic Records & Signatures

21 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures. It defines the conditions under which the agency accepts them as equivalent to paper records and handwritten signatures — principally validation of the system, secure computer-generated audit trails, controlled access, and signature manifestations permanently linked to the record they sign.

Full title
21 CFR Part 11 — Electronic Records; Electronic Signatures
Issued by
US Food and Drug Administration
Applies
United States, to records kept under a predicate rule

What it covers

In practice

Part 11 applies to records you keep because a predicate rule requires them. It does not sweep in every database you operate, and establishing that boundary is the first task — it usually narrows the scope considerably.

Where it does apply, the requirement most often underestimated is the audit trail. It must be computer-generated rather than user-entered, it must not be alterable by the people whose actions it records, and it must survive as long as the record itself.

FDA’s current enforcement posture, set out in its 2003 scope-and-application guidance, is risk-based and narrower than the regulation’s plain text. But guidance is discretion, not amendment, and vendors routinely overstate what it relieves.

Where teams get it wrong

Buying “Part 11 compliant” software and stopping there

The tool supplies capability. Compliance also requires validation in your context, plus the procedures and training that govern its use.

Audit trails the record owner can edit

If the people being recorded can alter the record of their own actions, the trail evidences nothing.

Applying it to everything

Scoping Part 11 across systems that hold no predicate-rule records adds cost and slows the organisation without improving any inspection outcome.

Common questions

Does Part 11 apply to our system?

Only to electronic records you keep because a predicate rule requires them, and to electronic signatures applied to those records. It does not sweep in every database you operate. Establishing that boundary is the first task and usually narrows the scope considerably — applying it everywhere adds cost without improving any inspection outcome.

Is vendor “Part 11 compliant” software enough?

No. A vendor can supply the capability — audit trails, access control, signature binding — but validation for your intended use, and the procedures and training that govern how your people use it, remain yours. Compliance is a property of your implementation, not a feature you can purchase.

What makes an audit trail compliant?

It must be computer-generated rather than user-entered, time-stamped, and record who changed what and when — and where relevant, why. Critically it must not be alterable by the people whose actions it records, and it must be retained at least as long as the record itself and be available for FDA review.

Working out how 21 CFR Part 11 applies to what you are building is usually the first conversation.

Get in touch →