logo
arrow-right All Blogs

What Is 21 CFR Part 11? A Complete Guide to Electronic Records and Signatures

AC

Adrta Compliance Team

9 min read

What Is 21 CFR Part 11? A Complete Guide to Electronic Records and Signatures

21 CFR Part 11 is an FDA regulation that establishes requirements for electronic records and electronic signatures used in FDA-regulated activities, helping ensure that electronic information is trustworthy, reliable, and appropriately controlled.

As pharmaceutical, biotechnology, medical device, clinical research, and laboratory organizations move from paper-based processes to digital systems, 21 CFR Part 11 compliance has become an important consideration when selecting, implementing, and managing computerized systems.

From electronic documents and laboratory records to quality management systems and electronic approvals, regulated organizations increasingly depend on digital records throughout their operations. This shift brings significant advantages in accessibility, efficiency, traceability, and collaboration, but it also creates the need for appropriate controls over how electronic information is created, modified, reviewed, approved, stored, and retrieved.

Understanding 21 CFR Part 11 is therefore not simply a matter of understanding a software feature. It requires understanding how electronic records and signatures are used within a regulated environment.

THE BASICS

What Does 21 CFR Part 11 Mean?

11
At a glance

21 CFR Part 11, formally titled Electronic Records; Electronic Signatures, establishes criteria under which electronic records and electronic signatures may be considered trustworthy, reliable, and generally equivalent to paper records and handwritten signatures, where applicable.

01
Regulatory Framework

Provides a framework for using electronic technology in FDA-regulated environments without compromising the integrity and reliability of regulated information.

02
Record Lifecycle

Addresses how organizations control electronic records and signatures throughout their lifecycle, including access, audit trails, protection, retention, and retrieval.

03
Applicability

Its applicability depends on the nature of the record, applicable FDA requirements, and how the organization uses and relies on that electronic record.

!
Important: Part 11 does not apply to every electronic document.

Applicability depends on the nature of the record, the applicable FDA requirements, and how the organization uses and relies on that electronic record.

When Does 21 CFR Part 11 Apply?

Part 11 applies to certain electronic records that are created, modified, maintained, archived, retrieved, or transmitted under requirements established by FDA regulations. It also applies to certain electronic records submitted to the FDA.

This is where predicate rules become important. Predicate rules are the underlying FDA regulations that establish requirements for particular records or activities. For example, regulations governing drug manufacturing, laboratory practices, or clinical investigations may require organizations to create and maintain specific records.

When an organization chooses to maintain such records electronically and relies on those electronic records to perform regulated activities, Part 11 may become applicable. Therefore, determining whether Part 11 applies should begin with understanding the regulatory purpose of the record rather than simply asking whether a particular file exists electronically.

KEY REQUIREMENTS

What Are the Main Requirements of 21 CFR Part 11?

Part 11 focuses on controls that help ensure electronic records and electronic signatures remain trustworthy, traceable, and appropriately controlled.

01
Access Control

Ensure only authorized individuals can access regulated systems and perform permitted activities through authentication, unique accounts, authorization, and role-based permissions.

02
Audit Trails

Maintain a traceable history of relevant electronic-record activity, including who performed an action, when it occurred, and what information was changed.

03
Electronic Signatures

Ensure electronic signatures are appropriately linked to the individual performing the signing action and associated with the relevant electronic record.

!
Why audit trails matter

Audit trails help organizations investigate discrepancies, understand record history, and demonstrate traceability during quality reviews or regulatory inspections. They should not, however, be treated as a standalone feature that automatically makes a system compliant.

21 CFR Part 11 and Data Integrity

Data integrity is closely connected to 21 CFR Part 11 because regulated organizations need confidence that their electronic records remain accurate, complete, and trustworthy throughout their lifecycle.

A record should not only be correct when it is first created. Organizations also need appropriate controls around subsequent activities such as modification, review, approval, retention, and retrieval. This is why concepts such as attribution, traceability, security, accuracy, completeness, and availability are so important when implementing electronic systems in GxP environments.

Part 11 should therefore be considered as part of a broader framework involving data integrity, GxP requirements, computerized system controls, risk management, and applicable predicate rules.

CLOUD & VALIDATION

Cloud Systems & Computer System Validation (CSV)

The use of cloud technology does not, by itself, remove the potential applicability of 21 CFR Part 11. When cloud-based software is used to create, maintain, modify, approve, or store electronic records that fall within the applicable regulatory scope, organizations still need to consider appropriate controls.

11
21 CFR Part 11
Electronic Records & Signatures
Primary Focus
Establishes requirements and controls for applicable electronic records and electronic signatures.
Core Scope

Focuses on trustworthiness, auditability, e-signatures, and record integrity.

CSV
Computer System Validation
System Performance & Intended Use
Primary Focus
Concerned with providing documented assurance that a computerized system performs as intended for its specified use.
Core Scope

Focuses on system consistency, specification alignment, vendor control, and operational testing.

Both need to be considered.

Having a validated system does not automatically mean every aspect of Part 11 has been addressed, and having Part 11 functionality does not eliminate the need to appropriately assess and assure a computerized system. Both need to be considered within the context of the organization's intended use, regulatory obligations, and risk.

Is "21 CFR Part 11 Compliant" Software Automatic?

There is no software feature that, by itself, makes an entire organization compliant with 21 CFR Part 11.

A software platform can provide technical controls such as audit trails, electronic signatures, access management, and record retention. However, compliance also depends on how the system is configured, implemented, validated or otherwise assured, and used.

Organizations also need appropriate procedures, trained personnel, access controls, system governance, and controls for managing changes throughout the system lifecycle. For this reason, organizations evaluating software should look beyond a vendor's claim that a product is "Part 11 compliant." They should evaluate whether the system's functionality supports their specific intended use and regulatory requirements.

Digital Transformation & Implementation Roadmap

The move toward digital quality and operational systems has made Part 11 increasingly relevant. Paper-based processes can make it difficult to maintain consistent version control, monitor approvals, track changes, and retrieve historical records. Digital systems can address many of these challenges by connecting workflows, records, users, and approvals within a controlled environment.

However, digital transformation in a regulated organization cannot be based on efficiency alone. The system must also preserve the integrity and reliability of the information generated through those processes.

STEP 1
Identify Scope & Predicate Rules

First identify which electronic records and signatures are relevant to regulated activities. Determine the applicable predicate rules and assess how those records are created, modified, reviewed, approved, stored, and retrieved.

STEP 2
Evaluate Technical Capabilities

Evaluate the computerized system supporting those activities. This includes understanding its access controls, audit trail capabilities, electronic signature functionality, record retention, security controls, and ability to generate accurate and complete records.

STEP 3
Establish Procedures & Governance

Establish the procedures and responsibilities surrounding the system. Users need to understand how regulated records and signatures should be handled, while system owners need processes for managing changes, access, incidents, and the system lifecycle.

This approach helps shift the focus from simply asking "Is this software Part 11 compliant?" to a more useful question:

"Does this system, together with our processes and controls, adequately support the regulated activities for which we rely on it?"