> 21_cfr_part_11
21 CFR Part 11
Electronic Records; Electronic Signatures (Part 11)
FDA 21 CFR Part 11 establishes criteria for software systems generating electronic records and electronic signatures submitted to the FDA. It requires strict computerized system validation, tamper-evident audit trails, authority checks, dual-factor signature controls, record retention, and operational controls ensuring clinical and GxP data integrity.
Scope & Applicability
Applies to electronic records that are created, modified, maintained, archived, retrieved, or transmitted under any FDA records requirement.
Non-Coverage Boundaries
Does not apply to paper records transmitted electronically or raw unstructured research data not subject to formal GxP submission requirements.
Key Clauses & Control Requirements
Computer-Generated Audit Trails
Mandates secure, computer-generated, time-stamped audit trails that independently record date, time, operator, and action without obscuring earlier entries.
Required Regulatory & Audit Evidence Artifacts
- [✓]Computer System Validation (CSV / CSA) package with IQ/OQ/PQ protocols
- [✓]Tamper-resistant audit trail export logs showing before-and-after values
- [✓]Role-Based Access Control (RBAC) matrix and unique credential assignment logs
“Audit trails are not an engineering afterthought. In Part 11, mutating an electronic record without an immutable, attributable timestamped audit log is an immediate regulatory violation.”
Cross-Surface Ecosystem Relationships
- Part 11, Electronic Records; Electronic Signatures - Scope and Application ↗(U.S. Food and Drug Administration)
Frequently Asked Questions
Can two people share credentials for an electronic signature under Part 11?
Never. Part 11 strictly requires that each electronic signature is attributable to a single unique individual and that credentials must never be shared.
