21 CFR Part 11 in Pharma: Requirements, Audit Trails & Electronic Signatures
21 CFR Part 11 is one of the most important FDA regulations for electronic records and electronic signatures. In pharmaceutical environments, it matters when regulated records are maintained electronically and fall within Part 11's scope.
21 CFR Part 11 is the FDA regulation that establishes criteria for certain electronic records and electronic signatures so they can be considered trustworthy, reliable, and generally equivalent to paper records and handwritten signatures. It works together with the underlying FDA recordkeeping requirements, often called predicate rules.
Not every electronic file in a pharmaceutical company is automatically a Part 11 record. FDA's current guidance interprets Part 11 scope narrowly and focuses on electronic records required by predicate rules or submitted to FDA under applicable statutes and regulations.
What Is 21 CFR Part 11?
21 CFR Part 11 is the FDA regulation titled Electronic Records; Electronic Signatures. It applies to certain records maintained electronically under FDA recordkeeping requirements and to certain electronic records submitted to FDA.
The regulation establishes criteria under which FDA considers electronic records and electronic signatures trustworthy, reliable, and generally equivalent to paper records and handwritten signatures.
Part 11 is not simply an “IT regulation.” It is a quality and record-integrity framework for regulated electronic records and signatures.
When Does 21 CFR Part 11 Apply?
FDA's Scope and Application guidance explains that Part 11 applies to electronic records created, modified, maintained, archived, retrieved, or transmitted under FDA record requirements, and to certain electronic records submitted to FDA.
A useful screening sequence is:
- Is the record required by an FDA predicate rule or submitted to FDA?
- Is the record being maintained or used electronically?
- Is the electronic record relied on to perform a regulated activity or make a regulated decision?
- If yes, what Part 11 and predicate-rule controls apply?
The answer should be based on the specific record, intended use, applicable FDA requirement, system design, and documented risk assessment-not simply on whether a computer is involved.
What Are Predicate Rules?
Predicate rules are the underlying FDA regulations that require a company to create, maintain, review, or retain particular records. Part 11 does not replace those requirements.
In pharmaceutical manufacturing, predicate-rule requirements may come from 21 CFR Part 211, including batch production records, laboratory records, investigations, and other CGMP documentation.
Predicate rule: tells you what regulated record or control is required.
Part 11: adds requirements when that record is maintained or used electronically within Part 11's scope.
Key 21 CFR Part 11 Requirements
| Control Area | What It Supports |
|---|---|
| System validation | Confidence that the system performs as intended for its regulated use. |
| Accurate and complete copies | Records can be inspected, reviewed, and reproduced appropriately. |
| Record protection | Records remain available and retrievable throughout required retention. |
| Access control | Only authorized individuals can use the system or perform defined actions. |
| Operational and authority checks | Helps enforce permitted sequencing and authorized actions where applicable. |
| Audit trails | Supports traceability of record creation, modification, and deletion where appropriate. |
| Training and accountability | Users understand responsibilities and electronic-signature accountability. |
| Electronic signature controls | Links the signature to the signer and the associated electronic record. |
Audit Trails Under 21 CFR Part 11
Audit trails are one of the most discussed Part 11 topics. Part 11 includes requirements for secure, computer-generated, time-stamped audit trails in certain contexts, but FDA's current Scope and Application guidance states that the agency is exercising enforcement discretion regarding some specific Part 11 audit-trail provisions.
That does not mean audit trails are unimportant. FDA recommends considering audit trails or other physical, logical, or procedural controls based on predicate-rule requirements, documented risk assessment, product quality and safety impact, and record integrity.
Audit trails are especially valuable where users can create, modify, reprocess, or delete regulated electronic records during normal operation.
A useful review asks: Who performed the action? What changed? When did it happen? What was the original information? Was the action authorized and scientifically justified?
Electronic Signatures in Pharma
Part 11 establishes requirements for electronic signatures used within its scope. Electronic signatures should be unique to an individual and designed so the signature cannot be readily repudiated or transferred to another person.
For signed electronic records, signature manifestation should include information such as the signer's printed name, the date and time of signing, and the meaning associated with the signature-such as review, approval, responsibility, or authorship-when required.
“Approved by QA” is not only a visual name on a screen. The system should maintain a reliable link between the individual, the signature event, and the electronic record being approved.
System Validation and Part 11
Part 11 includes validation requirements for systems used to create, modify, maintain, or transmit electronic records. FDA's current guidance describes enforcement discretion regarding certain Part 11 validation provisions while making clear that predicate-rule requirements remain applicable.
A modern risk-based validation approach typically focuses on intended use, critical functions and data, access and security, data flow, audit-trail behavior where relevant, testing evidence proportional to risk, and change control throughout the lifecycle.
Related guide: Change Control in Pharmaceutical Industry.
Electronic Records, Copies, and Retention
A major mistake is assuming that printing an electronic record automatically converts it into a complete paper record. FDA's CGMP records guidance explains that printed chromatograms may not contain all information needed to satisfy underlying record requirements when the electronic system contains additional raw data and metadata.
Depending on the system, important electronic context can include raw data, metadata, audit-trail information, method and processing parameters, sequence information, reprocessing history, user identification, and date/time information.
Records should remain protected, retrievable, and understandable for the required retention period.
Practical Example: HPLC System in a QC Laboratory
System: Chromatography Data System used to acquire and process assay results.
Regulated use: Results support batch-release decisions under CGMP.
Important controls: unique user accounts, appropriate privileges, controlled methods, complete raw data, metadata, audit trails where appropriate, secure retention, review of relevant processing changes, and validated operation for intended use.
Risk: If analysts can delete failed injections, modify processing parameters without traceability, or share accounts, the reliability and attribution of the laboratory record can be compromised.
This is why Part 11, data integrity, GDocP, and OOS investigation are closely connected in the QC laboratory.
Related guides: OOS in Pharmaceutical Industry, Data Integrity in Pharmaceutical Industry, and Good Documentation Practices in Pharma.
21 CFR Part 11 vs Data Integrity
| Concept | Main Focus |
|---|---|
| 21 CFR Part 11 | FDA requirements and controls for certain electronic records and electronic signatures. |
| Data Integrity | Whether data remain complete, consistent, accurate, attributable, and trustworthy throughout the lifecycle. |
| GDocP | How regulated records are created, completed, corrected, reviewed, controlled, and retained. |
These concepts overlap, but they are not interchangeable. A system can have sophisticated electronic-signature controls and still have poor data integrity if users share accounts, records are incomplete, or review practices are weak.
Common 21 CFR Part 11 Compliance Mistakes
21 CFR Part 11 Knowledge for Pharma Interviews
“21 CFR Part 11 establishes FDA requirements for certain electronic records and electronic signatures. I would first determine whether the record is in scope based on the applicable predicate rule and intended electronic use. Then I would expect appropriate controls for validation, access, record protection, audit trails based on risk and requirements, accurate copies, retention, and electronic signatures.”
Frequently Asked Questions
What is 21 CFR Part 11 in simple terms?
It is the FDA regulation governing certain electronic records and electronic signatures used to meet FDA requirements.
Does Part 11 apply to every computer system in pharma?
No. Applicability depends on whether the electronic records are subject to FDA predicate-rule requirements or are submitted to FDA within Part 11's scope.
Is an audit trail always required?
Part 11 contains audit-trail provisions, but FDA's current guidance applies enforcement discretion to certain specific Part 11 requirements. Firms should still consider audit trails and other controls based on predicate rules, risk, product quality, safety, and record integrity.
Is a PDF or printout always enough?
No. A static copy may omit raw data, metadata, audit history, or other context needed to reconstruct and review the regulated electronic record.
Is Part 11 the same as data integrity?
No. Part 11 is a specific FDA regulation. Data integrity is a broader quality concept covering the reliability and trustworthiness of data throughout their lifecycle.
Official and Authoritative Sources
- Electronic Code of Federal Regulations — 21 CFR Part 11
- FDA — Part 11, Electronic Records; Electronic Signatures — Scope and Application
- FDA — CGMP Questions and Answers: Records and Reports
21 CFR Part 11 is not a checklist to apply blindly to every computer. The strongest compliance approach starts with scope, predicate rules, intended use, and data risk-then applies electronic-record and signature controls that keep regulated records trustworthy, reviewable, attributable, and available.




Comments
Post a Comment