HomeQuality Guide

21 CFR Part 11 in Pharma: Requirements, Audit Trails & Electronic Signatures

 

21 CFR Part 11 in pharma showing electronic records electronic signatures audit trails and data integrity controls

Published by: Pharma Quality System Editorial Team Editorial basis: 21 CFR Part 11, FDA Part 11 Scope and Application guidance, and FDA CGMP records guidance
ELECTRONIC RECORDS • ELECTRONIC SIGNATURES • DATA INTEGRITY

21 CFR Part 11 is one of the most important FDA regulations for electronic records and electronic signatures. In pharmaceutical environments, it matters when regulated records are maintained electronically and fall within Part 11's scope.

Quick answer

21 CFR Part 11 is the FDA regulation that establishes criteria for certain electronic records and electronic signatures so they can be considered trustworthy, reliable, and generally equivalent to paper records and handwritten signatures. It works together with the underlying FDA recordkeeping requirements, often called predicate rules.

Important scope note:
Not every electronic file in a pharmaceutical company is automatically a Part 11 record. FDA's current guidance interprets Part 11 scope narrowly and focuses on electronic records required by predicate rules or submitted to FDA under applicable statutes and regulations.

What Is 21 CFR Part 11?

21 CFR Part 11 is the FDA regulation titled Electronic Records; Electronic Signatures. It applies to certain records maintained electronically under FDA recordkeeping requirements and to certain electronic records submitted to FDA.

The regulation establishes criteria under which FDA considers electronic records and electronic signatures trustworthy, reliable, and generally equivalent to paper records and handwritten signatures.

Core idea:
Part 11 is not simply an “IT regulation.” It is a quality and record-integrity framework for regulated electronic records and signatures.

When Does 21 CFR Part 11 Apply?

Decision guide for determining when 21 CFR Part 11 applies to regulated electronic records in pharmaceutical systems

FDA's Scope and Application guidance explains that Part 11 applies to electronic records created, modified, maintained, archived, retrieved, or transmitted under FDA record requirements, and to certain electronic records submitted to FDA.

A useful screening sequence is:

  1. Is the record required by an FDA predicate rule or submitted to FDA?
  2. Is the record being maintained or used electronically?
  3. Is the electronic record relied on to perform a regulated activity or make a regulated decision?
  4. If yes, what Part 11 and predicate-rule controls apply?

The answer should be based on the specific record, intended use, applicable FDA requirement, system design, and documented risk assessment-not simply on whether a computer is involved.

What Are Predicate Rules?

Predicate rules are the underlying FDA regulations that require a company to create, maintain, review, or retain particular records. Part 11 does not replace those requirements.

In pharmaceutical manufacturing, predicate-rule requirements may come from 21 CFR Part 211, including batch production records, laboratory records, investigations, and other CGMP documentation.

Simple relationship:

Predicate rule: tells you what regulated record or control is required.
Part 11: adds requirements when that record is maintained or used electronically within Part 11's scope.

Key 21 CFR Part 11 Requirements

Control AreaWhat It Supports
System validationConfidence that the system performs as intended for its regulated use.
Accurate and complete copiesRecords can be inspected, reviewed, and reproduced appropriately.
Record protectionRecords remain available and retrievable throughout required retention.
Access controlOnly authorized individuals can use the system or perform defined actions.
Operational and authority checksHelps enforce permitted sequencing and authorized actions where applicable.
Audit trailsSupports traceability of record creation, modification, and deletion where appropriate.
Training and accountabilityUsers understand responsibilities and electronic-signature accountability.
Electronic signature controlsLinks the signature to the signer and the associated electronic record.

Audit Trails Under 21 CFR Part 11

Audit trails are one of the most discussed Part 11 topics. Part 11 includes requirements for secure, computer-generated, time-stamped audit trails in certain contexts, but FDA's current Scope and Application guidance states that the agency is exercising enforcement discretion regarding some specific Part 11 audit-trail provisions.

That does not mean audit trails are unimportant. FDA recommends considering audit trails or other physical, logical, or procedural controls based on predicate-rule requirements, documented risk assessment, product quality and safety impact, and record integrity.

Practical point:
Audit trails are especially valuable where users can create, modify, reprocess, or delete regulated electronic records during normal operation.

A useful review asks: Who performed the action? What changed? When did it happen? What was the original information? Was the action authorized and scientifically justified?

Electronic Signatures in Pharma

Part 11 establishes requirements for electronic signatures used within its scope. Electronic signatures should be unique to an individual and designed so the signature cannot be readily repudiated or transferred to another person.

For signed electronic records, signature manifestation should include information such as the signer's printed name, the date and time of signing, and the meaning associated with the signature-such as review, approval, responsibility, or authorship-when required.

Example:
“Approved by QA” is not only a visual name on a screen. The system should maintain a reliable link between the individual, the signature event, and the electronic record being approved.

System Validation and Part 11

Part 11 includes validation requirements for systems used to create, modify, maintain, or transmit electronic records. FDA's current guidance describes enforcement discretion regarding certain Part 11 validation provisions while making clear that predicate-rule requirements remain applicable.

A modern risk-based validation approach typically focuses on intended use, critical functions and data, access and security, data flow, audit-trail behavior where relevant, testing evidence proportional to risk, and change control throughout the lifecycle.

Related guide: Change Control in Pharmaceutical Industry.

Electronic Records, Copies, and Retention

A major mistake is assuming that printing an electronic record automatically converts it into a complete paper record. FDA's CGMP records guidance explains that printed chromatograms may not contain all information needed to satisfy underlying record requirements when the electronic system contains additional raw data and metadata.

Depending on the system, important electronic context can include raw data, metadata, audit-trail information, method and processing parameters, sequence information, reprocessing history, user identification, and date/time information.

Records should remain protected, retrievable, and understandable for the required retention period.

Practical Example: HPLC System in a QC Laboratory

21 CFR Part 11 controls for HPLC chromatography data systems in pharmaceutical quality control laboratories

System: Chromatography Data System used to acquire and process assay results.

Regulated use: Results support batch-release decisions under CGMP.

Important controls: unique user accounts, appropriate privileges, controlled methods, complete raw data, metadata, audit trails where appropriate, secure retention, review of relevant processing changes, and validated operation for intended use.

Risk: If analysts can delete failed injections, modify processing parameters without traceability, or share accounts, the reliability and attribution of the laboratory record can be compromised.

This is why Part 11, data integrity, GDocP, and OOS investigation are closely connected in the QC laboratory.

Related guides: OOS in Pharmaceutical Industry, Data Integrity in Pharmaceutical Industry, and Good Documentation Practices in Pharma.

21 CFR Part 11 vs Data Integrity

Comparison of 21 CFR Part 11 data integrity and Good Documentation Practices in pharmaceutical quality systems

ConceptMain Focus
21 CFR Part 11FDA requirements and controls for certain electronic records and electronic signatures.
Data IntegrityWhether data remain complete, consistent, accurate, attributable, and trustworthy throughout the lifecycle.
GDocPHow regulated records are created, completed, corrected, reviewed, controlled, and retained.

These concepts overlap, but they are not interchangeable. A system can have sophisticated electronic-signature controls and still have poor data integrity if users share accounts, records are incomplete, or review practices are weak.

Common 21 CFR Part 11 Compliance Mistakes

Assuming every electronic file is Part 11Scope should be determined from regulatory use and predicate-rule requirements.
Shared user accountsWeakens attribution and electronic-record accountability.
Keeping only printoutsMay lose critical raw data, metadata, or system history.
Weak access controlUsers may have privileges beyond their responsibilities.
Ignoring audit-trail riskCritical changes or processing events may not receive adequate review.
Treating validation as paperworkValidation should demonstrate fitness for intended regulated use and focus on meaningful risk.

21 CFR Part 11 Knowledge for Pharma Interviews

Strong interview answer:

“21 CFR Part 11 establishes FDA requirements for certain electronic records and electronic signatures. I would first determine whether the record is in scope based on the applicable predicate rule and intended electronic use. Then I would expect appropriate controls for validation, access, record protection, audit trails based on risk and requirements, accurate copies, retention, and electronic signatures.”

Frequently Asked Questions

What is 21 CFR Part 11 in simple terms?

It is the FDA regulation governing certain electronic records and electronic signatures used to meet FDA requirements.

Does Part 11 apply to every computer system in pharma?

No. Applicability depends on whether the electronic records are subject to FDA predicate-rule requirements or are submitted to FDA within Part 11's scope.

Is an audit trail always required?

Part 11 contains audit-trail provisions, but FDA's current guidance applies enforcement discretion to certain specific Part 11 requirements. Firms should still consider audit trails and other controls based on predicate rules, risk, product quality, safety, and record integrity.

Is a PDF or printout always enough?

No. A static copy may omit raw data, metadata, audit history, or other context needed to reconstruct and review the regulated electronic record.

Is Part 11 the same as data integrity?

No. Part 11 is a specific FDA regulation. Data integrity is a broader quality concept covering the reliability and trustworthiness of data throughout their lifecycle.

Official and Authoritative Sources

Key takeaway
21 CFR Part 11 is not a checklist to apply blindly to every computer. The strongest compliance approach starts with scope, predicate rules, intended use, and data risk-then applies electronic-record and signature controls that keep regulated records trustworthy, reviewable, attributable, and available.

Comments

Popular posts from this blog

CAPA in Pharmaceutical Industry: Process, Examples & Root Cause Analysis

Good Documentation Practices (GDocP) in Pharma: Rules, ALCOA+ & Examples