Skip to main content

> 21_cfr_part_11

21 CFR Part 11

Electronic Records; Electronic Signatures (Part 11)

SPEC // INSPECT: 21 CFR Part 11REVIEWED: 2026-09-16
CATEGORYMedical Device Regulations
JURISDICTIONUNITED_STATES
REGULATORY AUTHORITYUnited States Food and Drug Administration (FDA)
LIFECYCLE STATUSCURRENT
EXECUTIVE BRIEF SPECIFICATION PDFDISTRIBUTION LOCKED
Fail-Closed Distribution Policy: Download control is visibly disabled until Cloudflare R2 CDN upload and remote SHA-256 verification complete.
[AI // ARCHITECTURAL SUMMARY]

FDA 21 CFR Part 11 establishes criteria for software systems generating electronic records and electronic signatures submitted to the FDA. It requires strict computerized system validation, tamper-evident audit trails, authority checks, dual-factor signature controls, record retention, and operational controls ensuring clinical and GxP data integrity.

Scope & Applicability

Applies to electronic records that are created, modified, maintained, archived, retrieved, or transmitted under any FDA records requirement.

Non-Coverage Boundaries

Does not apply to paper records transmitted electronically or raw unstructured research data not subject to formal GxP submission requirements.

Key Clauses & Control Requirements

sec-11-10-e

Computer-Generated Audit Trails

Mandates secure, computer-generated, time-stamped audit trails that independently record date, time, operator, and action without obscuring earlier entries.

[AUDIT // VERIFIABLE EVIDENCE CHECKLIST]

Required Regulatory & Audit Evidence Artifacts

  • [✓]Computer System Validation (CSV / CSA) package with IQ/OQ/PQ protocols
  • [✓]Tamper-resistant audit trail export logs showing before-and-after values
  • [✓]Role-Based Access Control (RBAC) matrix and unique credential assignment logs
[LEADERSHIP TAKEAWAY // CTO & VP OF ENGINEERING DIRECTIVE]
Audit trails are not an engineering afterthought. In Part 11, mutating an electronic record without an immutable, attributable timestamped audit log is an immediate regulatory violation.
PRIMARY SOURCES & AUTHORITY

Frequently Asked Questions

Can two people share credentials for an electronic signature under Part 11?

Never. Part 11 strictly requires that each electronic signature is attributable to a single unique individual and that credentials must never be shared.