21 CFR Part 11: Electronic Records and Electronic Signatures Explained

Understand 21 CFR Part 11, when it applies, what it requires, how FDA interprets its scope, and how organisations implement electronic records and electronic signatures in regulated pharmacovigilance systems.

Audio Lesson 12 min
Knowledge Assessment Test your understanding of this article. Take the assessment →

21 CFR Part 11: Electronic Records and Electronic Signatures Explained

Introduction

Electronic records and electronic signatures are fundamental components of modern regulated operations. Pharmacovigilance organisations routinely create, modify, review, approve, transmit and retain safety information using computerised systems. Safety databases, regulatory reporting systems, document management platforms, signal management systems and other applications may therefore contain records that contribute directly to regulated pharmacovigilance activities.

21 CFR Part 11 establishes criteria under which the United States Food and Drug Administration (FDA) considers electronic records, electronic signatures and handwritten signatures executed to electronic records to be trustworthy, reliable and generally equivalent to paper records and handwritten signatures executed on paper.

Part 11 does not operate as an independent substitute for the underlying regulatory requirements governing a regulated activity. Instead, it operates alongside the applicable predicate rules. Determining whether a particular electronic record is subject to Part 11 therefore requires understanding both the record itself and the underlying regulatory requirement for creating, maintaining or submitting that record.

This distinction is essential in pharmacovigilance. A safety database may contain thousands of electronic data elements, but not every electronic data element automatically becomes a Part 11 record merely because it exists in a computerised system.

The FDA's current Part 11 guidance describes a relatively narrow interpretation of the regulation's scope and explains enforcement discretion for certain Part 11 provisions. At the same time, the guidance makes clear that Part 11 remains in effect and that FDA continues to expect compliance with specified controls and with applicable predicate rules. 1

Understanding this distinction is therefore more useful than treating Part 11 as a checklist of technical controls.

For pharmacovigilance professionals, Part 11 should be understood as part of a broader control framework involving:

The objective is not simply to make a system "Part 11 compliant". The objective is to establish and maintain trustworthy and reliable electronic records and signatures that support the regulated activity throughout the system lifecycle.


Learning Objectives

After reading this article, you should be able to:


What Is 21 CFR Part 11?

21 CFR Part 11 is the section of Title 21 of the Code of Federal Regulations that establishes criteria for electronic records and electronic signatures used in FDA-regulated activities.

The regulation addresses circumstances in which electronic records and electronic signatures may be used in place of paper records and handwritten signatures.

The regulation is therefore concerned with the reliability, trustworthiness and integrity of electronic information used within regulated processes.

Part 11 contains requirements relating to areas including:

The regulation must, however, be interpreted in its regulatory context.

Part 11 does not define whether a record must exist in the first place. That requirement generally comes from another FDA regulation, commonly referred to as a predicate rule.

Part 11 addresses the controls applicable when regulated records are maintained or submitted electronically under the circumstances described in the regulation.


Why Was Part 11 Introduced?

Part 11 was introduced to establish criteria under which FDA would accept electronic records and electronic signatures as equivalent to traditional paper records and handwritten signatures under specified circumstances.

The regulation was finalised in 1997.

Its introduction reflected the increasing use of electronic technologies within regulated industries and the need for a regulatory framework that could accommodate electronic information while maintaining confidence in the integrity and reliability of regulated records.

The regulation was intended to permit broad use of electronic technology while protecting the public health.

Since its introduction, interpretation and implementation of Part 11 have generated substantial discussion regarding its scope, validation, audit trails, record retention and other controls.

In 2003, FDA issued its guidance for industry Part 11, Electronic Records; Electronic Signatures — Scope and Application. The guidance describes FDA's then-current interpretation of the scope of Part 11 and explains enforcement discretion concerning certain requirements. FDA states that Part 11 itself remains in effect. 2

This history is important because many descriptions of Part 11 encountered in industry materials combine the regulation itself with the 2003 guidance. They should be distinguished.


Part 11 Regulation Versus FDA Guidance

A fundamental principle when interpreting Part 11 is to distinguish between the regulation and FDA guidance.

The regulation establishes legally binding requirements within its scope.

FDA guidance describes the Agency's current thinking and recommendations. FDA explicitly states that guidance documents do not establish legally enforceable responsibilities unless specific statutory or regulatory requirements are cited. 3

The distinction can be summarised as follows:

Source Function
21 CFR Part 11 Regulation establishing requirements for electronic records and electronic signatures within its scope
FDA Part 11 Guidance Explains FDA's interpretation and enforcement approach
Predicate rules Establish the underlying regulated record, activity or requirement
Company procedures Define how the organisation implements applicable requirements
Validation / assurance evidence Provides objective evidence that the implemented system and controls are appropriate

This distinction becomes particularly important when discussing FDA's enforcement discretion.

The 2003 guidance states that FDA intends to exercise enforcement discretion with respect to certain Part 11 requirements concerning validation, audit trails, record copying and record retention, as described in the guidance. However, it also states that FDA intends to enforce other specified Part 11 controls and applicable predicate-rule requirements. 4

Therefore, it is incorrect to interpret the guidance as meaning that Part 11 is optional.


The Relationship Between Part 11 and Predicate Rules

The concept of the predicate rule is central to understanding Part 11.

A predicate rule is an underlying FDA requirement that establishes an obligation concerning a regulated activity or record.

Part 11 operates alongside those underlying requirements.

For example, if an FDA regulation requires an organisation to maintain a particular record and the organisation chooses to maintain that record electronically, Part 11 may apply to that electronic record depending on the circumstances described in Part 11 and FDA's interpretation of its scope.

The predicate rule determines the underlying regulatory obligation.

Part 11 establishes additional criteria concerning the electronic form of the record or signature.

This relationship can be represented as:

Predicate rule

Requirement to create, maintain or submit a regulated record

Organisation chooses electronic record

Assessment of Part 11 applicability

Appropriate technical, procedural and organisational controls

This distinction prevents one of the most common misunderstandings about Part 11: that every electronic record generated by a computerised system is automatically a Part 11 record.


Why This Matters in Pharmacovigilance

Pharmacovigilance systems generate and maintain extensive electronic information.

Examples include:

The fact that information exists electronically does not, by itself, determine whether every element falls within Part 11.

The organisation must understand:

  1. what regulatory record is required;
  2. which electronic record is relied upon;
  3. what predicate rule applies;
  4. whether the electronic record falls within Part 11;
  5. what controls are appropriate;
  6. how the decision has been documented.

This is why Part 11 assessment should be integrated with business-process analysis rather than performed solely as a technical system checklist.


Part 11 Is Not a Stand-Alone Validation Standard

Another common misunderstanding is to treat Part 11 as a complete Computerised System Validation methodology.

It is not.

Part 11 contains requirements relating to validation of systems within its scope, but validation strategy must also consider the applicable predicate rules, intended use, risks, data integrity and the nature of the computerised system.

FDA's 2003 guidance specifically states that organisations should consider the impact of computerised systems on their ability to meet predicate-rule requirements and on the accuracy, reliability, integrity, availability and authenticity of required records and signatures. It recommends a justified and documented risk-based approach. 5

This aligns naturally with modern risk-based Computerised System Validation and Computer Software Assurance approaches.


Part 11 and Pharmacovigilance Computerised Systems

For a pharmacovigilance system, Part 11 should be considered within the complete regulated process rather than as an isolated software attribute.

For example, an electronic case record may support:

The organisation should therefore understand which records and signatures are relied upon for regulated activities and ensure that appropriate controls protect their integrity throughout the lifecycle.

This requires coordination between:

Part 11 compliance is consequently a business-process and governance issue, not simply an IT configuration exercise.


Scope and Applicability of 21 CFR Part 11

Determining whether 21 CFR Part 11 applies to a particular computerised system or record requires more than asking whether the organisation uses electronic technology.

The critical question is whether the organisation is using electronic records or electronic signatures within the circumstances covered by Part 11 and applicable predicate rules.

FDA's 2003 guidance describes a narrow interpretation of Part 11 scope. Under this interpretation, Part 11 applies principally when records required to be maintained under predicate rules, or records submitted to FDA electronically, are maintained or used in electronic form within the circumstances described by the regulation and guidance. 1

This makes the assessment of applicability a business and regulatory question rather than simply a technical one.


Records Covered by Part 11

21 CFR Part 11 applies to records in electronic form that are created, modified, maintained, archived, retrieved or transmitted under records requirements established by FDA regulations.

It also applies to certain electronic records submitted to FDA under the Federal Food, Drug, and Cosmetic Act or the Public Health Service Act, even when the particular record is not specifically identified in an FDA regulation. 2

The practical implication is that organisations should first identify the underlying regulatory obligation and then determine how the associated record is created, maintained, used and submitted.


The Role of Predicate Rules

Part 11 should be evaluated together with the applicable predicate rules.

The predicate rule establishes the underlying regulatory requirement for an activity or record.

Part 11 addresses the use of electronic records and electronic signatures in satisfying that requirement.

For example, an organisation may have a regulatory obligation to maintain a record. If the organisation chooses to maintain that record electronically and relies upon the electronic record for the regulated activity, Part 11 may become applicable.

The analysis therefore follows the regulatory requirement rather than the technology.


Electronic Records Used Instead of Paper

One of the clearest situations covered by Part 11 is where an organisation chooses to maintain a required record electronically instead of maintaining the required record in paper form.

In such circumstances, the electronic record becomes the record relied upon for the regulated activity.

The organisation should therefore determine:

FDA recommends documenting decisions concerning whether particular records are Part 11 records. 3


Electronic Records Maintained in Addition to Paper

A more complicated situation occurs when an organisation maintains both paper and electronic versions of a required record.

The existence of a paper copy does not automatically mean that Part 11 is irrelevant.

FDA's guidance explains that where a required record is maintained electronically in addition to paper and the electronic record is relied upon to perform regulated activities, FDA may consider the electronic record to fall within Part 11. 4

This makes the organisation's actual business practice important.

The key question is therefore:

Which record does the organisation actually rely upon?


Electronic Records Used to Generate Paper Records

A different situation exists when a computerised system is used to generate a paper record and the organisation relies upon the paper record for its regulated activity.

FDA's narrow interpretation states that, where the resulting paper record satisfies the applicable predicate-rule requirements and the organisation relies upon the paper record, FDA would generally not consider the organisation to be using the electronic record in lieu of the paper record solely because a computer system was used to generate it. 5

This distinction is important because the mere presence of a computer does not automatically make every resulting record a Part 11 record.


Records Submitted Electronically to FDA

Part 11 also applies to certain electronic records submitted to FDA.

The relevant question is whether the record is submitted electronically under the applicable statutory or regulatory framework.

A record that is merely used internally to generate a submission is not automatically a Part 11 record solely because it contributes information to a submission. FDA's guidance explains that such a record may nevertheless fall within Part 11 if it is independently required to be maintained under a predicate rule and is maintained electronically. 6

This distinction is particularly important when designing regulatory submission workflows.


Electronic Signatures Within Scope

Part 11 applies to electronic signatures that are intended to have the same significance as handwritten signatures, initials or other required signings associated with regulated records.

Examples may include electronic actions representing:

The organisation should establish the regulatory significance of the signature rather than treating every electronic acknowledgement or user interaction as a Part 11 electronic signature.


Closed Systems

Part 11 distinguishes between closed systems and open systems.

A closed system is one in which access to the system is controlled by persons responsible for the content of the electronic records contained within the system.

Many controlled pharmacovigilance applications can operate as closed systems because access is restricted through organisational identity and access-management controls.

For closed systems, §11.10 establishes controls addressing areas such as:

The exact implementation should be based upon the intended use, risk and applicable requirements.


Open Systems

An open system is one in which system access and control are not limited in the manner described for a closed system.

Part 11 therefore establishes additional requirements for open systems.

Section 11.30 requires controls designed to ensure, as appropriate, the authenticity, integrity and confidentiality of electronic records from the point of creation through receipt.

These controls may include measures such as:

The organisation should therefore determine whether its operating environment is genuinely a closed system before relying upon the controls applicable to closed systems alone.


Hybrid Records

Regulated processes may involve combinations of paper and electronic records.

Examples include:

FDA's guidance recognises that paper and electronic record or signature components can coexist in a hybrid environment provided that applicable predicate-rule requirements are satisfied and the content and meaning of the records are preserved. 7

Hybrid environments require particularly clear procedures defining which record is authoritative and how the relationship between the paper and electronic components is controlled.


Part 11 Applicability Assessment

A practical Part 11 applicability assessment can therefore follow a structured sequence.

Question Assessment
Is there an underlying FDA regulatory or statutory requirement for the record or submission? Identify the predicate rule
Is the record maintained electronically? Determine the authoritative record
Is the electronic record used instead of paper? Assess Part 11 applicability
Is electronic and paper information both maintained? Determine which record is relied upon
Is the electronic record submitted to FDA? Assess submission requirements
Is an electronic signature used as the equivalent of a required handwritten signature? Assess Part 11 signature requirements
Is the system closed or open? Determine the applicable system controls
What risks affect record integrity? Perform and document risk assessment

FDA specifically recommends that organisations document decisions regarding which records are Part 11 records. 8


Applying the Scope Assessment to Pharmacovigilance

Pharmacovigilance provides many examples where careful scope assessment is necessary.

Consider an electronic Individual Case Safety Report.

The organisation should determine:

  1. Which regulatory obligations require the underlying information?
  2. Which electronic record constitutes the official case record?
  3. Is the electronic record relied upon for regulated pharmacovigilance activities?
  4. Are paper copies also maintained?
  5. Which users may create, modify, review or approve information?
  6. Which electronic signatures represent regulated approvals or certifications?
  7. Which records are transmitted electronically to regulatory authorities?
  8. What controls are necessary to protect the integrity of the record?

The answer should be documented rather than assumed.

This approach prevents organisations from applying Part 11 mechanically to every field in a safety database while also preventing them from overlooking electronic records that are genuinely relied upon for regulated activities.


Scope Is a Documented Regulatory Decision

Part 11 applicability should not be determined solely by an IT department, software supplier or generic compliance checklist.

The assessment requires understanding of:

For important pharmacovigilance systems, the resulting determination should be documented and maintained as part of the system's controlled lifecycle documentation.

Professional Insight

The most reliable way to determine whether 21 CFR Part 11 applies is to begin with the regulated activity and the underlying predicate rule, then trace how the required record or signature is created, maintained, used and submitted. Starting with the software alone can produce both over-application and under-application of Part 11.


Electronic Records Under 21 CFR Part 11

The concept of the electronic record is central to 21 CFR Part 11. Before determining which technical controls are required, an organisation must understand what information constitutes a regulated record, which electronic version is authoritative and how that record is created, modified, reviewed, transmitted and retained.

This distinction is particularly important in pharmacovigilance because modern safety systems contain large quantities of information. A safety database may contain individual data fields, system-generated information, audit trail entries, workflow states, derived reports, attachments and regulatory transmission records. Not every item necessarily has the same regulatory status.

The organisation must therefore understand the relationship between the business process, the regulatory requirement and the electronic record that supports that requirement.


What Is an Electronic Record?

21 CFR §11.3 defines an electronic record as a combination of text, graphics, data, audio, pictorial or other information represented in digital form that is created, modified, maintained, archived, retrieved or distributed by a computer system.

The definition is deliberately broad.

An electronic record may therefore include information that is:

However, the presence of digital information alone does not determine whether it is a regulated record within the scope of Part 11.

The regulatory context and the organisation's use of the information must also be considered.


Record Versus Data

The terms data and record are often used interchangeably in everyday practice, but they should not automatically be treated as equivalent.

Data may represent individual values or observations.

A record represents information maintained as evidence of a regulated activity or required by an applicable regulatory framework.

For example, a safety database may contain:

These individual data elements contribute to a case record, but the regulatory significance of the complete record depends upon how the organisation uses and maintains that information.

This distinction is important when performing Part 11 assessments.


The Authoritative Electronic Record

An organisation should clearly identify which electronic record is considered authoritative for a regulated process.

This is particularly important when multiple representations of the same information exist.

Examples include:

The organisation should establish which representation constitutes the official record and which representations are merely copies or working outputs.

This decision should be documented in procedures and, where appropriate, system validation documentation.


The Record Lifecycle

An electronic record should be considered throughout its complete lifecycle.

This may include:

  1. creation;
  2. modification;
  3. review;
  4. approval;
  5. transmission;
  6. retrieval;
  7. archival;
  8. retention;
  9. eventual disposition.

Controls applied at one stage should not compromise the integrity of the record at another.

For example, a safety record may be created in one system, modified during medical review, transmitted through an electronic reporting interface and subsequently archived. The organisation must understand how the record remains attributable, reliable and retrievable throughout these transitions.


Creation of Electronic Records

Electronic records may originate from multiple sources.

In pharmacovigilance, information may be received through:

The organisation should understand how information enters the computerised system and which controls protect its integrity at the point of creation.

Where information is imported automatically, validation and interface controls may be particularly important.


Modification of Electronic Records

Regulated records may require modification as new information becomes available.

For an Individual Case Safety Report, for example, additional follow-up information may result in changes to:

The system should preserve appropriate evidence of significant modifications in accordance with applicable requirements and organisational procedures.

The objective is not necessarily to prevent every modification.

The objective is to ensure that authorised modifications remain controlled and that the history and integrity of the regulated record can be appropriately reconstructed.


Metadata and Context

Electronic information may depend upon associated metadata to retain its meaning.

Metadata can include information such as:

Metadata may therefore contribute materially to the meaning, integrity or reconstruction of an electronic record.

Organisations should determine which metadata are necessary to support the reliability and interpretation of records and ensure that relevant information is appropriately controlled and retained.


System-Generated Information

Not all information within a regulated system is entered directly by a human user.

Computerised systems may automatically generate:

Such information may form part of the evidence supporting a regulated process.

Validation should therefore consider not only user-entered data but also critical system-generated information.


Derived Records and Calculated Information

Some electronic records contain values derived from other data.

Examples include:

Where derived information contributes to a regulated decision or record, the organisation should understand:

The level of control should be proportionate to the risk and regulatory significance of the derived information.


Electronic Copies

Electronic copies may be created for operational, review, transmission or archival purposes.

Examples include:

A copy should not automatically be assumed to have the same regulatory status as the original electronic record.

The organisation should establish whether the copy is:

FDA's Part 11 guidance discusses the importance of providing copies of electronic records in both human-readable and electronic form when requested by FDA, where applicable.


Electronic Records and Printed Copies

Printing an electronic record does not necessarily eliminate the regulatory significance of the electronic record.

The organisation should determine which form is relied upon for the regulated activity.

For example, if a pharmacovigilance team maintains a safety record electronically and routinely relies upon the electronic record for processing, review and reporting, simply printing a report does not necessarily transform the underlying electronic record into an irrelevant technical artifact.

The actual business process and applicable regulatory requirements must be considered.


Electronic Records and Regulatory Reporting

Pharmacovigilance systems frequently create electronic information that is transmitted to regulatory authorities.

Examples include:

The organisation should understand the relationship between:

These may represent related but distinct electronic records within the overall reporting process.


Electronic Records in Safety Databases

A pharmacovigilance safety database may contain multiple layers of information supporting an individual case.

A simplified model is:

Source safety information
         |
         v
     Case record
         |
         v
  Medical assessment
         |
         v
 Coding and classification
         |
         v
    Quality review
         |
         v
 Regulatory reporting
         |
         v

Transmission acknowledgement | v Follow-up and lifecycle management

Each stage may generate information that contributes to the overall evidence associated with the case.

Validation and data-integrity controls should therefore consider the complete process rather than a single database screen.


Electronic Records and Data Integrity

Part 11 should not be considered separately from data integrity.

For regulated electronic records, organisations should consider whether information remains:

These principles are often expressed through ALCOA and ALCOA+ concepts and are particularly relevant when assessing pharmacovigilance systems.

Data integrity principles will be examined in greater detail in the dedicated Data Integrity cluster.


Electronic Records During System Migration

Migration presents a significant risk to electronic records.

When information is transferred between systems, organisations should assess whether:

A successful migration should preserve the integrity and meaning of regulated records rather than simply transfer database fields.


Electronic Records and System Retirement

Electronic records may remain subject to retention requirements after the computerised system that created them has been retired.

Retirement planning should therefore address:

System retirement does not necessarily terminate the organisation's obligation to maintain regulated records.


Determining Whether an Electronic Record Is in Scope

A practical assessment should consider the following questions:

Question Purpose
What regulated activity does the information support? Establish the business context
Which predicate rule applies? Establish the regulatory obligation
What record is required? Define the regulated record
Is the record maintained electronically? Assess electronic-record applicability
Which version is authoritative? Establish record ownership
Is the electronic record relied upon? Assess practical significance
What metadata are necessary to interpret it? Protect meaning and context
How is it modified? Assess lifecycle controls
How is it retained and retrieved? Assess long-term availability
Is it transmitted to FDA? Assess submission requirements

This assessment should be based upon actual organisational practice rather than merely the capabilities of the software.


Electronic Records Require Context

The most important principle is that an electronic record cannot be assessed solely by looking at its file format, database structure or software application.

The organisation must understand the relationship between:

This contextual approach allows Part 11 requirements to be applied appropriately without either extending them indiscriminately to every piece of digital information or overlooking records that are genuinely relied upon for regulated activities.

Professional Insight

The correct Part 11 question is not simply "Is this data electronic?" The more meaningful question is "What regulated record does this electronic information represent, what regulatory requirement creates the obligation for that record, and how does the organisation rely upon and control it throughout its lifecycle?" This distinction is fundamental to effective Part 11 assessment in pharmacovigilance.


Core Requirements of 21 CFR Part 11

Once the scope of Part 11 has been established, the next question is how an organisation controls the electronic records and electronic signatures that fall within its scope.

Part 11 contains requirements addressing the technical and procedural controls used to ensure that electronic records and signatures remain trustworthy and reliable.

For closed systems, §11.10 establishes controls relating to areas including:

Part 11 also establishes specific requirements for electronic signatures and controls relating to signature components and identification codes.

These requirements should not be implemented as isolated technical features. They should be interpreted in the context of the intended use, regulated process, risk and lifecycle of the computerised system.


Validation of Systems

Section 11.10(a) requires closed systems to be validated to ensure accuracy, reliability, consistent intended performance and the ability to discern invalid or altered records.

Validation therefore forms a fundamental Part 11 control.

The purpose is not simply to demonstrate that software functions correctly.

The organisation should demonstrate that the implemented system is capable of supporting its intended regulated use and that controls affecting electronic records operate as intended.

For a pharmacovigilance system, validation may therefore consider:

Validation activities should be proportionate to the risks associated with the intended use.


Part 11 Validation and Modern CSV

Part 11 validation should be integrated with the organisation's broader Computerised System Validation or Computer Software Assurance strategy.

The validation approach should consider:

This prevents the common mistake of creating a separate "Part 11 validation" programme that is disconnected from the actual business process.

The same objective evidence may support multiple regulatory expectations when appropriately designed.


Accurate and Complete Copies

Section 11.10(b) requires the ability to generate accurate and complete copies of records in both human-readable and electronic form suitable for FDA inspection, review and copying.

This requirement has practical consequences for system design and lifecycle management.

The organisation should be able to determine:

A screenshot is not automatically an adequate electronic copy of a regulated record.

Depending upon the record, an appropriate copy may require structured data, associated metadata or other information necessary to preserve the meaning and context of the record.


Record Protection

Section 11.10(c) requires protection of records to enable accurate and ready retrieval throughout the required retention period.

Record protection therefore extends beyond cybersecurity.

It includes protection against:

For pharmacovigilance systems, retention controls should be considered alongside regulatory requirements governing safety information and the organisation's documented retention policies.


Limiting System Access

Section 11.10(d) requires limiting system access to authorised individuals.

Access control is therefore both a Part 11 requirement and a fundamental data-integrity control.

A pharmacovigilance system should typically distinguish between different levels of access according to job responsibilities.

Examples may include:

Access should be granted according to defined roles and should be reviewed periodically.


Role-Based Access

Role-based access provides a structured way of controlling system permissions.

A role should represent a legitimate business responsibility rather than simply a collection of convenient technical permissions.

For example, a user responsible for case processing may require permission to enter and modify case information but should not necessarily have unrestricted system-administration privileges.

Separating business roles from technical privileges helps reduce the risk of inappropriate access.


Access Provisioning and Deprovisioning

Access control must operate throughout the user lifecycle.

The organisation should control:

When an employee or contractor leaves an organisation, access should be removed or disabled in accordance with established procedures.

Failure to remove unnecessary access can create significant data-integrity and security risks.


Operational Checks

Section 11.10(f) requires the use of operational system checks where appropriate to enforce permitted sequencing of steps and events.

The objective is to prevent users from performing activities in an inappropriate sequence when sequence is important to the validity of the regulated process.

Pharmacovigilance examples may include workflows in which:

Operational checks should reflect actual business requirements rather than arbitrary technical restrictions.


Authority Checks

Section 11.10(g) requires authority checks to ensure that only authorised individuals can use a system, electronically sign a record, access an operation or alter a record.

Authority checks therefore operate at a more specific level than basic login authentication.

Authentication answers:

Who are you?

Authorisation answers:

What are you permitted to do?

A robust pharmacovigilance system should distinguish these concepts.

For example, a user may be authorised to review a case but not authorised to approve a system configuration change.


Device Checks

Section 11.10(h) addresses device checks, where appropriate, to determine the validity of the source of data input or operational instruction.

The appropriate implementation depends upon the system and risk.

Potential controls may include:

The requirement should not be interpreted as requiring the same technical mechanism in every system.

The appropriate control should be justified by the intended use and risk.


Determining Appropriate User Qualifications

Section 11.10(i) requires determination that persons who develop, maintain or use electronic record systems have the education, training and experience necessary to perform their assigned tasks.

This requirement extends beyond initial system training.

The organisation should consider whether users understand:

Training should be appropriate to the person's role.


Training Records

Training itself may generate regulated records.

The organisation should therefore consider how training records are:

Where electronic training systems are used to maintain regulated training records, the Part 11 applicability and appropriate controls should be assessed.


Written Policies Establishing Accountability

Section 11.10(j) requires written policies that hold individuals accountable and responsible for actions initiated under their electronic signatures.

The purpose is to establish clear accountability for electronic actions.

In practical terms, personnel should understand that an electronic signature is not merely a button or user-interface event.

It represents an accountable action associated with a specific individual.

Organisational procedures should therefore define:


Documentation Controls

Section 11.10(k) requires controls over system documentation, including controls governing the distribution of, access to and use of system documentation for operation and maintenance.

Documentation may include:

The organisation should ensure that controlled documentation remains current and that obsolete versions are appropriately managed.


Audit Trails

Section 11.10(e) requires use of secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify or delete electronic records.

Audit trails are among the most important Part 11 controls for regulated pharmacovigilance systems.

A meaningful audit trail should allow authorised reviewers to understand relevant changes to regulated records, including:

The exact information required depends upon the system, record and risk.

Audit trails should not be treated simply as a technical log that exists somewhere in the database.

They are part of the evidence supporting the integrity and reconstructability of regulated electronic records.


Audit Trail Review

The existence of an audit trail does not by itself demonstrate effective control.

Organisations should establish appropriate procedures for determining:

A risk-based approach should determine the extent and frequency of audit trail review.

For critical pharmacovigilance processes, audit trail review may be particularly important when investigating:


Electronic Signatures

Part 11 establishes specific requirements for electronic signatures.

An electronic signature is defined in §11.3 as a computer data compilation of any symbol or series of symbols executed, adopted or authorised by an individual to be legally binding as the equivalent of the individual's handwritten signature.

The important concept is therefore not simply that a user clicks a button.

An electronic signature represents an individual's accountable action associated with an electronic record.

The organisation should understand:


Signature Components

Part 11 requires electronic signatures to employ at least two distinct identification components, such as an identification code and password, subject to the specific provisions of the regulation.

Controls also apply to identification-code and password combinations.

These controls are intended to prevent fraudulent use and maintain individual accountability.

Shared accounts and shared credentials are therefore fundamentally inconsistent with the objective of individual electronic-signature accountability.


Linking the Signature to the Record

An electronic signature should remain associated with the electronic record to which it applies.

The organisation should be able to determine:

A signature that can be separated from its associated record without appropriate controls can weaken the evidentiary value of the electronic approval.


Signature Meaning

Part 11 requires signed electronic records to contain information associated with the signature, including:

The meaning may include actions such as:

This ensures that an electronic signature communicates more than the identity of the person who performed it.


Signature Controls and Pharmacovigilance

Electronic signatures may be used in pharmacovigilance for activities such as:

The organisation should define the significance of each electronic signature and ensure that the underlying business process supports appropriate accountability.


Part 11 Controls Are Interdependent

Part 11 controls should not be implemented independently.

For example:

Together, these mechanisms provide a control framework for trustworthy electronic records and signatures.


A Risk-Based Implementation Approach

Not every technical feature of a computerised system has the same significance.

Implementation decisions should therefore consider:

A risk-based approach prevents organisations from treating Part 11 as a simple checklist while ensuring that important controls receive appropriate attention.

Professional Insight

Part 11 controls are most effective when viewed as an integrated system of technical, procedural and organisational safeguards. Validation, access control, audit trails, authority checks, training and electronic signatures are not independent compliance features; together they establish the conditions under which electronic records can remain trustworthy, attributable, reliable and reconstructable throughout their lifecycle.


Electronic Signature Controls in Detail

Electronic signatures are one of the most important elements of 21 CFR Part 11 because they establish individual accountability for actions performed on regulated electronic records.

Part 11 does not treat an electronic signature simply as a graphical representation of a person's name. The regulation establishes requirements intended to ensure that an electronic signature is attributable to the individual who executed it, remains associated with the relevant electronic record and has the same intended significance as the individual's handwritten signature where the applicable requirements are satisfied.

Sections 11.50, 11.70, 11.100, 11.200 and 11.300 establish the principal electronic-signature requirements.

FDA's Part 11 guidance specifically identifies these electronic-signature provisions among the Part 11 requirements that FDA intends to continue enforcing. 1


What Is an Electronic Signature?

Under §11.3, an electronic signature is a computer data compilation of any symbol or series of symbols that is executed, adopted or authorised by an individual to be the legally binding equivalent of the individual's handwritten signature.

The important elements are therefore:

A user clicking a general navigation button is not automatically executing a Part 11 electronic signature.

The organisation must determine whether the electronic action is intended to represent a signature required for a regulated activity.


Electronic Signature Versus Electronic Approval

An electronic approval may be implemented through different technologies and workflows.

The organisation should distinguish between:

These actions may have different regulatory significance.

For example, a pharmacovigilance medical reviewer may review an ICSR without formally approving it. A subsequent electronic signature may represent the formal approval of the medical assessment.

The system and procedures should make this distinction clear.


Signature Manifestations

Section 11.50 requires signed electronic records to clearly display information associated with the signing.

This includes:

The signature manifestation should therefore communicate not only who performed the signature but also when it occurred and what the signature represents.

Examples of signature meaning may include:


Example of a Pharmacovigilance Signature

Consider an electronic approval of a controlled pharmacovigilance document.

The electronic record might display:

Name: Jane Smith
Date and time: 10 August 2026, 14:32 IST
Meaning: Approved

The important point is not the visual appearance of the signature.

The system must maintain the appropriate association between:


Signature and Record Linking

Section 11.70 requires electronic signatures and handwritten signatures executed to electronic records to be linked to their respective records so that the signatures cannot be excised, copied or otherwise transferred to falsify an electronic record by ordinary means.

This requirement is fundamental to electronic-signature integrity.

A signature should not exist as an independent object that can simply be detached from one record and attached to another without appropriate controls.

The system should preserve the relationship between the signature and the record throughout the record lifecycle.


Why Signature Linking Matters

Consider a pharmacovigilance workflow in which a medical reviewer approves a case assessment.

If the signature can be copied independently from the approved case and attached to another case, the signature no longer provides reliable evidence of the original approval.

The integrity of the signature therefore depends upon the integrity of its relationship with the record.

This relationship should be considered during:


Uniqueness of Electronic Signatures

Section 11.100(a) requires each electronic signature to be unique to one individual.

An electronic signature must therefore not be shared between users.

This requirement supports individual accountability.

Shared electronic-signature credentials create ambiguity regarding who actually performed an action and undermine the evidentiary value of the signature.


Verification of Identity

Section 11.100(b) requires the identity of an individual to be verified before or at the time of assignment of an electronic signature.

The organisation should therefore have a controlled process for establishing the identity of individuals before issuing electronic-signature credentials.

Identity verification may be governed by organisational processes involving:

The precise mechanism may vary according to the organisation and technology.


Certification of Legal Equivalence

Section 11.100(c) requires persons using electronic signatures to certify to FDA that the electronic signatures are intended to be the legally binding equivalent of traditional handwritten signatures.

This requirement is distinct from the technical implementation of the signature itself.

An organisation should therefore have an appropriate controlled process for fulfilling the applicable certification requirement.

FDA provides information and example language concerning electronic-signature certification and non-repudiation agreements. 2


Signature Components

Section 11.200 establishes controls for electronic-signature components.

For electronic signatures that are not based solely on biometric methods, the regulation requires at least two distinct identification components, such as:

The purpose is to establish a controlled mechanism through which the signature can be uniquely associated with the individual.

The components must be used in accordance with the requirements applicable to their use.


First Signature During a Controlled Session

Section 11.200(a)(1) addresses execution of an individual's first signing during a continuous period of controlled system access.

The identification components must be used in the manner specified by the regulation so that the system can establish the identity of the signer.

The implementation should prevent another individual from simply using an already authenticated session to execute a signature under someone else's identity.

This is particularly important in shared working environments.


Subsequent Signatures

Section 11.200(a)(1) also permits the subsequent signings of the same individual during a single continuous period of controlled system access to use one or more components of the signature, provided the applicable requirements are satisfied.

The precise implementation should therefore be evaluated against the system architecture and the regulatory requirements rather than assumed from generic software functionality.


Preventing Another Person From Using the Signature

Section 11.200(a)(2) requires controls designed to ensure that an electronic signature cannot be used by another individual.

This creates an important operational responsibility for users.

Personnel should not:

Organisational procedures should establish clear expectations and accountability.


Identification Codes and Passwords

Section 11.300 establishes controls for identification codes and passwords used with electronic signatures.

Controls address areas including:

These requirements should be implemented through the organisation's identity and access-management processes.


Credential Uniqueness

An identification code should uniquely identify the individual to whom it is assigned.

This means that two users should not share the same identity for regulated activities requiring individual accountability.

Generic accounts may therefore present significant problems when they are used for actions requiring attribution to an individual.

Where technical or operational reasons require a service account, its use should be distinguished from individual electronic-signature activity.


Lost or Compromised Credentials

Organisations should have procedures for responding when identification codes or passwords are:

The response should prevent continued unauthorised use and should preserve appropriate evidence where a compromise may have affected regulated records.

Potential responses may include:


Detecting Unauthorised Attempts

Section 11.300 includes controls relating to detection of unauthorised attempts to use identification codes or passwords.

The implementation may involve mechanisms such as:

The appropriate implementation should reflect the system architecture and risk.


Periodic Credential Checks

Part 11 includes provisions concerning periodic checking of identification codes and passwords.

Modern identity-management systems may implement credential controls through centralised security mechanisms rather than through individual application functions.

The organisation should nevertheless demonstrate that the resulting control environment satisfies applicable requirements.

Part 11 compliance should therefore be assessed across the complete technical environment rather than by looking only at one application's login screen.


Electronic Signatures in Pharmacovigilance

Electronic signatures may be used in many regulated pharmacovigilance activities.

Examples include:

The regulatory significance depends upon the underlying process and applicable requirements.


Electronic Signature Example: Safety Case Review

Consider a safety database in which a medical reviewer completes a clinical assessment.

A controlled electronic-signature workflow might involve:

  1. The reviewer authenticates using individual credentials.
  2. The system verifies that the reviewer has the appropriate authority.
  3. The reviewer completes the required assessment.
  4. The reviewer initiates the signing action.
  5. The system records the signature.
  6. The record displays the signer's identity.
  7. The system records the execution date and time.
  8. The meaning of the signature is recorded.
  9. The signature remains linked to the case record.
  10. The event is retained as part of the controlled record.

Validation should demonstrate that the workflow behaves as intended.


Electronic Signature Example: Validation Approval

A validation team may use an electronic signature to approve a Validation Summary Report.

The system should allow the organisation to determine:

This becomes particularly important when the document is subsequently revised.

A new version should not appear to have been approved by a signature associated with an earlier version.


Electronic Signatures and Version Control

Electronic signatures should be considered together with document and record version control.

When a signed record is changed, the organisation should understand:

The appropriate approach depends upon the nature of the record and applicable procedures.

The key principle is that the signature must not misleadingly imply approval of content that the signer did not actually approve.


Electronic Signatures and Audit Trails

Electronic signatures and audit trails provide complementary evidence.

The signature establishes an accountable signing action.

The audit trail may provide additional information concerning events surrounding the record.

For example, a reviewer may electronically approve a record at a particular time, while the audit trail may provide evidence of preceding changes to the record.

Neither control should be treated as a substitute for the other.


Electronic Signatures and Pharmacovigilance Vendors

Where a pharmacovigilance process is outsourced, organisations should establish who controls electronic signatures and how accountability is maintained.

This may involve:

Supplier contracts and procedures should clearly establish responsibilities for identity management, access control, signature use and record retention.

The use of a third-party platform does not eliminate the organisation's responsibility to understand how regulated electronic signatures are controlled.


Electronic Signatures During System Migration

Migration creates a particular challenge where historical records contain electronic signatures.

The organisation should determine whether migration preserves:

A migration that transfers record content while losing the evidentiary relationship between the signature and the signed record may compromise the ability to reconstruct the historical record.

Migration requirements should therefore be defined before the migration is executed.


Electronic Signatures During System Retirement

Retirement planning should address historical electronic signatures.

Where records must be retained after system retirement, the organisation should ensure that the retained records continue to provide appropriate evidence of:

The organisation should not assume that decommissioning the application automatically satisfies record-retention requirements.


Electronic Signatures Are More Than Authentication

Authentication establishes identity.

An electronic signature represents an accountable action associated with a regulated record.

These concepts should not be conflated.

A user may authenticate to a system without signing a record.

Conversely, a signing workflow may require additional controls that establish the specific significance of the action.

This distinction should be reflected in requirements, configuration, validation and procedures.


Common Electronic-Signature Failures

Common weaknesses include:

These weaknesses can undermine the reliability and accountability of electronic approvals.


Electronic Signature Control Matrix

Control area Core objective Pharmacovigilance example
Signature uniqueness Associate signature with one individual Medical reviewer
Identity verification Establish identity before signature assignment Employee onboarding
Signature manifestation Show signer, time and meaning Case approval
Signature/record linking Prevent inappropriate transfer of signature Approved safety assessment
Signature components Secure signing credentials ID and password
Credential protection Prevent unauthorised use Safety database account
Authority checks Restrict signing to authorised roles QA approval
Audit trail Provide evidence of relevant activity Case modification before approval
Version control Ensure approval applies to correct content Validation report approval
Lifecycle controls Preserve historical evidence System retirement

FDA Perspective on Electronic Signatures

FDA's Part 11 guidance specifically identifies the electronic-signature requirements as provisions that FDA intends to enforce.

This is an important distinction from the enforcement-discretion discussion concerning certain validation, audit-trail, record-copying and record-retention provisions described in the 2003 guidance. 3

Organisations should therefore avoid applying the enforcement-discretion discussion broadly to the entire Part 11 regulation.

The fact that FDA has described enforcement discretion for certain provisions does not eliminate the requirements relating to electronic signatures.


Electronic Signatures and Regulatory Submissions

Electronic signatures may also be relevant to FDA submissions.

FDA currently provides information describing accepted electronic and digital signature approaches for certain submission processes. The appropriate method depends upon the submission pathway and applicable FDA requirements. 4

Therefore, organisations should distinguish between:

The technical implementation and procedural requirements may differ.


The Experienced Professional's Approach

Experienced professionals do not begin an electronic-signature assessment by asking:

"Does the application have an e-signature feature?"

They ask:

This approach connects electronic signatures to the actual regulated process rather than treating them as a software checkbox.

Professional Insight

An effective electronic-signature control does not merely prove that a user clicked an approval button. It provides reliable evidence that an identified and authorised individual intentionally performed a defined action on a specific electronic record at a defined point in time, with the signature remaining securely associated with the record throughout its lifecycle.

Revision History