Data Integrity & CSV

21 CFR Part 11 Compliance Checklist: Audit-Ready Guide

A practical 21 CFR Part 11 compliance checklist: how to establish applicability, which controls apply to electronic records and signatures, and which evidence to prepare for your next audit. With a practical comparison between Part 11 and EU GMP Annex 11.

G GuideGxP 5 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Illustrazione editoriale GuideGxP a colori sul tema GMP: 21 CFR Part 11, registrazioni e firme elettroniche.

A 21 CFR Part 11 compliance checklist is the most effective tool to turn a 1997 FDA regulation into concrete, inspection-defensible evidence. Part 11 applies when records required by FDA predicate rules are created, modified, maintained, archived, retrieved or transmitted electronically, and when electronic signatures are used as the equivalent of handwritten ones. This article gives you a complete, point-by-point operational checklist covering applicability, electronic record controls, signatures and hybrid processes — plus a practical comparison with EU GMP Annex 11.

21 CFR Part 11 compliance checklist: where to start

The first mistake to avoid is applying every control to every system indiscriminately. A defensible scope decision starts from the regulated process, not the technology label: a cloud application, a spreadsheet or a lab instrument is not automatically in scope just because of its format. The FDA guidance Part 11 — Scope and Application (2003) describes a narrow interpretation of scope and announces enforcement discretion for specific requirements (validation, audit trails, record retention and copying), but it does not repeal Part 11 nor remove the obligations arising from predicate rules.

Applicability assessment, in six steps:

  1. Identify the predicate rule. Is the information a record required by an applicable FDA requirement (GMP, laboratory, clinical)?
  2. Map the electronic lifecycle. Is the record created, modified, maintained, archived, retrieved or transmitted electronically? Identify the authoritative record, not every convenience copy.
  3. Establish reliance. Does the electronic record replace paper, or is it used to perform a regulated activity? Document the rationale against the Scope and Application guidance.
  4. Assess signatures separately. Is the electronic signature intended to be the legally binding equivalent of a handwritten one?
  5. Define the system boundary. Include interfaces, instrument data, metadata, reports, archiving and identity management.
  6. Record the outcome. Approve a scope assessment stating predicate rule, record set, system of record, signature use and applicable controls.

Electronic record controls checklist (11.10 and 11.30)

For in-scope systems, Part 11 distinguishes between closed systems (access controlled by the persons responsible for the record content, § 11.10) and open systems (§ 11.30, which requires additional measures for authenticity, integrity and confidentiality). The table summarises the control areas and the evidence an inspector expects to see.

Control areaPart 11 requirementAudit-ready evidence
Validation (§ 11.10(a))Systems validated for accuracy, reliability and the ability to discern invalid or altered records.Approved intended use, risk-based lifecycle documentation, testing and change management.
Copies for FDA (§ 11.10(b))Accurate and complete copies in both human-readable and electronic form.Tested export procedure, including metadata and audit trails.
Protection and retention (§ 11.10(c))Records protected and retrievable throughout the required retention period.Retention plan, restore tests, format readable over time.
Access and authority checks (§ 11.10(d)(g))Access limited to authorised individuals, with authority checks on operations.Role matrix, joiner/mover/leaver management, periodic access review.
Audit trail (§ 11.10(e))Secure, computer-generated, time-stamped audit trails; changes must not obscure previous data.Documented configuration, audit trail review procedure and samples.
Operational checks (§ 11.10(f))Enforced sequencing of steps and events, where applicable.Configured workflow, exception handling, testing of critical steps.
Open systems (§ 11.30)Additional measures (e.g. encryption) for authenticity, integrity, confidentiality.Documented threat assessment and implemented safeguards.

Checklists like this one land every week in the inboxes of The Pragmatic GMP subscribers — GuideGxP's free newsletter: source-based regulatory analysis, no fluff, ready to use on the shop floor. Subscribe now.

Electronic signatures checklist (11.50–11.300)

An electronic signature is more than a login. Signed records must show the signer's printed name, the date and time, and the meaning of the signature (review, approval, responsibility, § 11.50); the signature must be linked to its record so that it cannot be excised, copied or transferred to falsify a record (§ 11.70). Also verify that:

  • each signature is unique to one individual and is not reused or reassigned (§ 11.100);
  • the signer's identity was verified before credentials were activated;
  • non-biometric signatures use at least two distinct components (e.g. ID and password, § 11.200);
  • written policies hold individuals accountable for actions initiated under their signatures;
  • ID and password controls cover uniqueness, periodic expiry and loss management (§ 11.300).

Hybrid processes: the paper printout trap

Hybrid processes (paper + electronic) require an explicit designation of the official record. Printing a result from an instrument does not make the dynamic electronic data, metadata or audit trail irrelevant when they are needed to reconstruct what happened. For each flow, define: the source record, transcription verification, correction handling and retention of the source. An electronic approval followed by a paper copy does not authorise discarding the original signed record.

Part 11 vs EU GMP Annex 11: align without confusing them

Part 11 and Annex 11 overlap in topics but are not interchangeable: the former is an FDA regulation on electronic records and signatures; the latter, published in EudraLex Volume 4, governs computerised systems in EU GMP activities. The Annex 11 revision (draft under consultation since 2025, together with the new Annex 22 on artificial intelligence) will significantly expand European expectations: do not implement consultation text as if it were already a final requirement — monitor the final publication. The most robust practical approach is a single set of controlled evidence (scope, risks, testing, periodic review), then mapped onto each applicable framework.

GuideGxP recommendation

Never declare a system "Part 11 compliant" without stating intended use, record scope, configurations and supporting evidence: in an inspection, that claim will be dismantled with a single question. Instead, build a traceable requirement→control→evidence map, approved by quality governance before configuring workflows, and subject it to audit trail review and periodic review. Start with the highest-risk records (batch release, QC data, electronic batch records) and document enforcement discretion wherever you invoke it.

To set up the whole lifecycle — from scope decision to validation to audit — the GuideGxP Operational Guide to Computer System Validation (CSV) in GxP includes 175 operational pages and 12 ready-to-use tools, already aligned with the new Annex 11.

Frequently asked questions

Has FDA repealed 21 CFR Part 11?

No. Part 11 is in force and available in the eCFR. The Scope and Application guidance narrows its interpretation and declares enforcement discretion on some provisions, but it does not remove the obligation to comply with predicate rules.

Does every electronic GMP system need Part 11 controls?

No. Assess the predicate-rule record, the reliance on the electronic record and the use of electronic signatures; document the decision and review it when the intended use changes.

Is Annex 11 the European version of Part 11?

No. They cover overlapping topics but belong to different regulatory frameworks and must be assessed separately, each in its own legal and inspection context.

Official sources

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP →