21 CFR Part 11 requirements apply when FDA-regulated predicate-rule records are created, modified, maintained, archived, retrieved or transmitted electronically, and when electronic signatures are used as the equivalent of handwritten signatures. The first task is therefore not to buy a compliance feature or apply every control indiscriminately: it is to establish the record’s predicate-rule basis, how the organisation relies on the electronic record, and whether an electronic signature is being used. Part 11 remains an FDA regulation. FDA’s Scope and Application guidance describes a narrow interpretation of scope and announced enforcement discretion for specified controls; it does not repeal Part 11 or remove predicate-rule obligations.
Start with applicability: the record, reliance and signature test
Part 11 is a codified FDA regulation governing electronic records and electronic signatures. It sits alongside the applicable FDA “predicate rules”: the underlying requirements that require records to be created, retained, submitted or signed. A defensible scope decision starts with the regulated business process rather than the technology label. A cloud application, spreadsheet, instrument or paper process is not automatically in or out of scope simply because of its format.
A practical scope decision tree
- Identify the predicate requirement. Is the information a record required by an applicable FDA regulation, such as a GMP, laboratory, clinical or other FDA-regulated requirement?
- Map the electronic lifecycle. Is that required record created, modified, maintained, archived, retrieved or transmitted in electronic form? Identify the authoritative record, not merely every temporary convenience copy.
- Establish reliance. Is the electronic record maintained instead of paper, required to be electronic, or relied upon to perform a regulated activity? Document the rationale against FDA’s Scope and Application guidance.
- Assess signatures separately. Is an electronic signature intended to be the legally binding equivalent of a handwritten signature? If so, the electronic-signature provisions are directly relevant.
- Define the system boundary. Include interfaces, instrument data, metadata, reports, archival arrangements, identity management and any manual steps needed to preserve the regulated record.
- Record the outcome. Approve a scope assessment that states the predicate rule, record set, system of record, signature use, applicable controls and any FDA enforcement-discretion rationale.
FDA’s guidance says it intends to exercise enforcement discretion for validation, audit trails, record retention and record-copying requirements in specified Part 11 provisions, while continuing to expect compliance with predicate rules. This is a regulatory enforcement policy expressed in non-binding guidance, not an exemption to protect records, retain them for the required period, or make them available for inspection. Organisations should not treat the word “discretion” as evidence that controls are unnecessary.
Core 21 CFR Part 11 requirements for electronic records
For systems within scope, Part 11 differentiates between closed systems, where system access is controlled by the people responsible for the content of electronic records, and open systems, where access is not controlled by those responsible for record content. Closed systems are addressed principally in 21 CFR 11.10; open systems require the additional measures in 11.30 necessary to ensure record authenticity, integrity and, as appropriate, confidentiality.
| Control area | Part 11 focus | Audit-ready evidence |
|---|---|---|
| Validation and intended use | Systems should be validated to ensure accuracy, reliability, consistent intended performance and the ability to discern invalid or altered records. | Approved intended-use statement, risk-based lifecycle records, testing, deviations, release and change evidence. |
| Record protection and retention | Records must be protected to enable accurate and ready retrieval throughout the required retention period. | Retention schedule, archive design, retrieval test, backup/restore evidence and readable record format. |
| Audit trails | Secure, computer-generated, time-stamped audit trails should independently record operator actions that create, modify or delete electronic records. | Configuration specification, sample trail reviews, review procedure and evidence that changes do not obscure prior information. |
| Access and authority | Access must be limited to authorised individuals; authority checks must ensure only authorised people can perform relevant operations. | Role matrix, joiner/mover/leaver records, periodic access review and segregation-of-duties rationale. |
| Operational checks | Checks should enforce permitted sequencing of steps and events, where applicable. | Workflow configuration, exception handling and test evidence for critical process sequencing. |
| Copies for FDA | Copies of records should be available in human-readable and electronic form suitable for FDA review and copying. | Inspection export procedure, representative export test and explanation of associated metadata and audit trail. |
| Open-system protection | Additional measures are required as appropriate to ensure authenticity, integrity and confidentiality. | Documented threat assessment and implemented safeguards appropriate to the system boundary. |
Part 11 also addresses procedures and controls including device checks, personnel qualifications, written policies that hold individuals accountable for actions initiated under their electronic signatures, and controls over system documentation. The appropriate implementation should be proportionate to intended use and risk, but it must still preserve the evidential value of the regulated record.
Electronic signatures are more than a login
Electronic signatures must be linked to their respective electronic records so that they cannot be excised, copied or otherwise transferred to falsify a record by ordinary means. Signed records must show the signer’s printed name, the date and time of signing, and the meaning associated with the signature, such as review, approval, responsibility or authorship. The signature controls in Part 11 also address uniqueness, identity verification, non-reuse and, depending on whether signatures are non-biometric or biometric, the relevant execution and control requirements.
A user account authenticates access; it does not automatically demonstrate that a configured action meets the organisation’s predicate-rule signature requirement. Define which actions require a signature, the signature meaning, the required signer authority and the record presentation available to a reviewer.
Hybrid processes: avoid the “paper printout” misconception
A hybrid process combines paper and electronic elements. It needs an explicit designation of the official record and a controlled relationship between source data, derived data, printouts, review evidence and archive. Printing a result from an instrument does not, by itself, make the dynamic electronic data, metadata or audit trail irrelevant where those elements are needed to reconstruct what happened.
- Instrument result printed for batch review: determine whether the electronic raw data and associated audit trail remain the authoritative evidence for the result and any changes.
- Paper form transcribed into an application: define the source record, verification of transcription where required, correction handling and retention of the source.
- Electronic approval followed by a paper copy: preserve the signed electronic record, including signature manifestation and linkage, rather than relying only on an unsigned or static printout.
GuideGxP implementation advice is to place the scope decision and record-flow map under quality governance before configuring workflows. For supplier, shared-responsibility and lifecycle considerations in hosted platforms, see the GuideGxP SaaS and cloud GxP validation roadmap.
Part 11 and EU GMP Annex 11: align controls without treating them as identical
Part 11 and Annex 11 both address controlled electronic information in regulated environments, but they arise from different frameworks and should not be represented as interchangeable. Part 11 is an FDA regulation with defined provisions for electronic records and electronic signatures. EU GMP Annex 11 is published in EudraLex Volume 4 and addresses computerised systems within EU GMP. It should be assessed with the applicable EU GMP legal and inspection context, rather than used as a substitute for a Part 11 assessment.
| Topic | 21 CFR Part 11 | EU GMP Annex 11 | Practical approach |
|---|---|---|---|
| Regulatory focus | Electronic records and electronic signatures under FDA-regulated predicate rules. | Computerised systems used in EU GMP activities. | Maintain jurisdiction- and process-specific applicability assessments. |
| System controls | Addresses validation, access, authority, operational checks, audit trails, record protection and copies. | Addresses lifecycle management and controls for GMP computerised systems. | Build one controlled evidence set, then map it to each applicable framework. |
| Signatures | Contains specific electronic-signature provisions and signature/record linkage requirements. | Assess signature and approval expectations in the EU GMP process context. | Specify meaning, identity, authority and reviewability for every regulated approval. |
| Current consultation | FDA Scope and Application guidance remains guidance, not regulation. | The Commission’s 2025 consultation on Chapter 4, Annex 11 and Annex 22 is consultation material. | Do not implement consultation text as if it were already a final requirement; monitor and assess final publications. |
A common global failure is to declare a system “Annex 11 compliant” or “Part 11 compliant” without stating the intended use, record scope, configurations and evidence that support the claim. A stronger position is a traceable requirements map, risk assessment, verification evidence and periodic review tailored to the actual regulated use.
Inspection-ready checklist
- Have we identified every applicable predicate rule and the required record, retention period and signature requirement?
- Is there an approved Part 11 applicability decision for each regulated process and system boundary?
- Have we identified the authoritative record, source data, metadata, audit trail and human-readable output?
- Is intended use defined, and is there documented lifecycle evidence appropriate to the risk and system changes?
- Are unique accounts, access authorisation, authority checks and periodic access reviews demonstrable?
- Are audit trails enabled where required, secure, retained and reviewed according to an approved procedure?
- Can the organisation retrieve complete, understandable records and suitable electronic copies throughout required retention?
- Are electronic signatures uniquely attributable, meaningfully configured and linked to their records?
- Are hybrid paper/electronic hand-offs, transcription checks and corrections controlled?
- For open-system elements, have additional safeguards been justified and evidenced?
- Can the system owner explain supplier responsibilities, incident handling, backup, restoration and archival retrieval?
- Are Part 11, Annex 11 and consultation materials clearly distinguished in procedures and training?
Frequently asked questions
Has FDA repealed 21 CFR Part 11?
No. Part 11 remains in the eCFR. FDA’s Scope and Application guidance explains its interpretation of scope and its enforcement discretion for certain provisions; it does not remove the need to comply with applicable predicate rules.
Does every electronic GMP system need Part 11 controls?
No automatic conclusion follows from the system being electronic or GMP-related. Assess the predicate-rule record, electronic reliance and electronic-signature use. Document the decision and revisit it when intended use changes.
Is Annex 11 the European version of Part 11?
No. They overlap in important control themes but belong to different regulatory frameworks, have different structures and should be assessed separately.
Primary sources
- eCFR: Title 21, Part 11, Electronic Records; Electronic Signatures
- FDA: Part 11 Electronic Records; Electronic Signatures — Scope and Application
- European Commission: EudraLex Volume 4, including Annex 11
- European Commission: 2025 consultation on Chapter 4, Annex 11 and Annex 22
Stay practical: The Pragmatic GMP
Subscribe to The Pragmatic GMP for evidence-led GMP analysis, practical checklists and regulatory updates.