Regulatory Compliance

21 CFR Part 11 Compliance Guide: Electronic Records and Signatures

Everything you need to know about FDA 21 CFR Part 11 compliance for electronic records and electronic signatures.

Regulatory Compliance

21 CFR Part 11 Compliance Guide: Electronic Records and Signatures

Voyantix Team Aug 1, 2025 9 min read

What is 21 CFR Part 11?

21 CFR Part 11 is a federal regulation issued by the U.S. Food and Drug Administration (FDA) that establishes criteria under which electronic records and electronic signatures are considered trustworthy, reliable, and equivalent to paper records and handwritten signatures. Enacted in 1997, Part 11 was designed to encourage the adoption of electronic systems by life sciences organizations while maintaining the integrity, authenticity, and confidentiality of regulated records.

The regulation applies to records in any form that are created, modified, maintained, archived, retrieved, or transmitted under any records requirements set forth in FDA regulations, including predicate rules related to drugs, biologics, medical devices, food, and tobacco products. Part 11 does not create new record-keeping requirements — rather, it establishes the criteria that electronic systems must meet when they are used to satisfy existing record-keeping requirements under other FDA regulations.

Part 11 is organized into three subparts: General Provisions (including scope and implementation), Electronic Records (covering closed systems, open systems, and record retention), and Electronic Signatures (including general requirements, components and controls, and identification codes/passwords). Understanding each subpart is essential for organizations seeking to implement compliant electronic systems in GxP-regulated environments.

Who Must Comply with 21 CFR Part 11?

Any FDA-regulated organization that uses electronic systems to create, modify, maintain, or transmit records subject to FDA requirements must comply with Part 11. This includes pharmaceutical manufacturers, biotechnology companies, medical device manufacturers, contract research organizations (CROs), contract manufacturing organizations (CMOs), clinical laboratories, blood banks, and tobacco product manufacturers. The regulation applies regardless of company size — from small biotech startups to large multinational pharmaceutical corporations.

The types of systems subject to Part 11 compliance include Quality Management Systems (QMS), Laboratory Information Management Systems (LIMS), Electronic Batch Records (EBR), Computerized Maintenance Management Systems (CMMS), Environmental Monitoring Systems (EMS), Training Management Systems, Document Management Systems (DMS), and any other computerized system that creates, modifies, or stores electronic records subject to FDA regulatory requirements. Even systems that are not primarily quality-focused, such as ERP systems that generate regulated records, may fall under Part 11 scope.

It is important to note that Part 11 compliance is not optional for organizations subject to FDA jurisdiction. While the FDA has exercised enforcement discretion in certain areas, the underlying requirements remain in effect, and organizations that fail to comply may face regulatory action including Warning Letters, consent decrees, import alerts, and product approval delays.

Key Requirements: Electronic Records, Electronic Signatures, Audit Trails

Electronic Records: Part 11 distinguishes between closed systems and open systems. A closed system is an environment in which system access is controlled by persons who are responsible for the content of electronic records. An open system is an environment in which system access is not controlled by persons who are responsible for the content of electronic records. For closed systems, Part 11 requires procedures and controls that include: system validation to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records; the ability to generate accurate and complete copies of records; protection of records to enable their accurate and ready retrieval; limiting system access to authorized individuals; secure, computer-generated, time-stamped audit trails; operational system checks; authority checks; device checks; controls for open systems including additional measures such as encryption; and documentation of system and procedural controls.

Electronic Signatures: Part 11 requires that electronic signatures be unique to one individual and not reused or reassigned. Electronic signatures must be linked to their respective electronic records to ensure that signatures cannot be excised, copied, or otherwise transferred to falsify a record. Each electronic signature must include the printed name of the signer, the date and time when the signature was executed, and the meaning associated with the signature (such as review, approval, responsibility, or authorship). For non-biometric signatures, at least two distinct identification components are required, such as an identification code and password. For biometric signatures, a unique biometric identifier must be used.

Audit Trails: Audit trails are among the most critical Part 11 controls. The regulation requires secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records. Audit trails must be generated and maintained by the system independently of the operator, include the identity of the operator who made the change, record the date and time of the change, capture what was changed, and preserve the original record content. Audit trails must be available for copying and review by the FDA during inspections, and must be protected from unauthorized modification or deletion.

System Validation Requirements (IQ, OQ, PQ)

Part 11 requires that electronic systems be validated to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records. System validation follows a lifecycle approach that typically includes Installation Qualification (IQ), Operational Qualification (OQ), and Performance Qualification (PQ).

Installation Qualification (IQ) verifies that the system hardware, software, and network infrastructure are installed correctly according to vendor specifications and organizational requirements. IQ documentation includes verification of system configuration, database setup, network connectivity, security settings, and installation of all required components.

Operational Qualification (OQ) verifies that the system functions as intended under normal operating conditions. OQ testing includes functional testing of all system features, verification of user access controls, audit trail functionality, electronic signature workflows, data integrity controls, backup and recovery procedures, and system security measures.

Performance Qualification (PQ) verifies that the system performs consistently and reliably under real-world operating conditions over time. PQ testing typically includes extended operational testing, load testing, stress testing, and verification that the system maintains data integrity under sustained use.

Beyond initial validation, Part 11 compliance requires ongoing periodic review of system controls, change management for system modifications, revalidation when significant changes are made, and continued monitoring of system performance and security. The level of validation documentation should be proportional to the risk and complexity of the system and the criticality of the records it manages.

Common 21 CFR Part 11 Violations and How to Avoid Them

FDA inspections and Warning Letters have identified several recurring patterns of Part 11 non-compliance. Understanding these common violations helps organizations focus their compliance efforts effectively:

  • Inadequate Audit Trail Controls: Systems that do not generate audit trails, generate incomplete audit trails, or do not record operator identity and timestamps fail to meet Part 11 requirements. Ensure all regulated electronic systems generate comprehensive audit trails covering record creation, modification, and deletion.
  • Insufficient Access Controls: Shared login credentials, lack of unique user identification, and inadequate password policies undermine the link between electronic signatures and individual accountability. Implement role-based access controls with unique user IDs, strong password requirements, and session management.
  • Lack of System Validation: Deploying electronic systems without completing appropriate validation activities, or performing validation that does not adequately test Part 11 controls. Develop and execute comprehensive validation protocols that specifically address Part 11 requirements.
  • Inadequate Record Retention: Electronic records that cannot be accurately and completely retrieved, or that are lost or corrupted during storage or transfer. Implement robust backup, archival, and disaster recovery procedures to ensure record integrity and availability.
  • Weak Electronic Signature Controls: Electronic signatures that are not linked to records, that do not include required signature manifestations, or that do not use appropriate identification components. Configure electronic signature workflows to capture all Part 11-required information and enforce identity verification.
  • Insufficient Documentation: Lack of written policies, procedures, or documentation describing Part 11 controls and their operation. Develop and maintain comprehensive SOPs, system descriptions, and control documentation for all Part 11-relevant systems.

How Software Helps Achieve Part 11 Compliance

Modern life sciences software platforms are designed with Part 11 compliance as a foundational requirement rather than an afterthought. Purpose-built eQMS, LIMS, and other GxP software solutions incorporate Part 11 controls natively, significantly reducing the burden of demonstrating compliance.

Key Part 11 compliance features in modern software include: comprehensive, tamper-evident audit trails that automatically record all record creation, modification, and deletion events with user identity, timestamp, old value, and new value; role-based access controls with unique user identification, multi-factor authentication, and configurable password policies; electronic signature workflows with biometric and non-biometric options, signature manifestations, and signature-meaning capture; validated system architecture with vendor qualification documentation, installation and operation qualification protocols, and ongoing periodic review capabilities; data integrity controls including input validation, range checks, and data encryption at rest and in transit; and complete record lifecycle management with version control, archival, and retention policy enforcement.

Cloud-based Part 11-compliant software offers additional advantages including automatic compliance updates as regulations evolve, built-in disaster recovery and business continuity, reduced IT infrastructure burden, and the ability to scale compliant operations without additional validation overhead. When evaluating software for Part 11 compliance, organizations should request vendor compliance documentation, including SOC 2 Type II reports, validation documentation, and evidence of ongoing compliance monitoring.

Frequently Asked Questions

Achieve 21 CFR Part 11 Compliance

Voyantix QMS provides a fully validated, 21 CFR Part 11 compliant platform with built-in audit trails, electronic signatures, and access controls designed specifically for life sciences organizations.

Explore Our QMS