PHARMA LAB · PL-06-015
Annex 11 and 21 CFR Part 11 in the laboratory: applicability

In this article
A computer does not automatically make every file a record subject to 21 CFR Part 11. Nor does a printout, by itself, exclude the system that produced the result. Defining applicability means following the work: what activity takes place, what record is required, who uses the data and for which decision.
In the pharmaceutical laboratory, the assessment must distinguish EU requirements, US requirements and interpretive guidance. This map supports a documented rationale; it neither certifies software nor replaces assessment of the process by the responsible functions.
1. Start with the process, market and record
Identify the product, activity, markets served and applicable obligations. A QC laboratory testing medicines intended for the United States may have record requirements arising, for example, from 21 CFR 211.194. These underlying requirements, often called predicate rules, establish which evidence must exist regardless of purchasing a software module.
Then follow the record from instrument data to the approved result. Consider original data, calculations, methods, necessary metadata, reviews and relationships. Distinguish required records from convenience copies and practice materials. Base that distinction on actual use: a spreadsheet described as “for information only” that determines a QC result does not fall outside the process because of its label.
2. Build a laboratory applicability matrix
This original table is an example to adapt. Each row should become a documented decision with an owner, relevant jurisdiction and verifiable evidence; an unexplained “compliant” checkbox is insufficient.
| Process or record | Requirement to assess | Control and evidence | Limit of the conclusion |
|---|---|---|---|
| QC analysis in a CDS | Complete test records, for example 211.194; EU GMP where relevant | Map of data, methods, results and history; retrieval verification | The final report alone may not represent the complete record |
| Spreadsheet calculation | Calculations and units required by the process; 211.194 and 211.68 where applicable | Verified formulas, retained version and inputs | The spreadsheet brand does not determine applicability |
| Electronic review or approval | Required act, authority and signature requirements | Identity, meaning, date/time and record linkage | Logging into a system is not automatically a signature |
| Paper linked to electronic data | Completeness and relationships between components; Chapter 4 | Shared identifier and review of the relevant complete set | Printing does not eliminate necessary electronic data |
| Isolated practice exercise | No GMP decision or required formal evidence | Fictitious data, bounded use and demonstrable separation | Formal training records need their own assessment |
| Record retained after system retirement | Applicable retention and availability obligations | Access, readability and context verified over time | Ending operational use does not cancel retention |
3. Read Part 11 alongside predicate rules
21 CFR 11.1 defines the scope of electronic records and electronic signatures. FDA’s 2003 guidance explains its narrow interpretation: the scope includes, among other things, required records maintained electronically instead of paper, or used electronically in conducting regulated activities even where a paper copy exists. What the activity relies upon matters.
The regulation remains in force. FDA’s stated enforcement discretion for certain provisions does not abolish Part 11 or predicate requirements. Do not use it to justify incomplete data, uncontrolled access or missing evidence of process fitness.
Assess the record and any signature separately: which acts are required, who is authorised and how the signature remains associated with the approved version. Controls also depend on system classification. Under Part 11 definitions, “open” and “closed” concern access control by those responsible for record content: cloud hosting or an Internet connection alone does not determine the category.
4. Connect Annex 11 to the quality system
For relevant EU GMP activities, Annex 11 requires a risk-based approach throughout the computerised system lifecycle. The assessment must translate into responsibilities, requirements, validation, security, change management, periodic evaluation and retention. Putting a feature list beside a supplier certificate is insufficient.
At verification on 2 October 2026, the official EudraLex index still lists Annex 11, January 2011 revision. The 2025 consultation must not be cited as already effective text. Annex 11 and Part 11 have different sources and scopes: a shared matrix can compare controls without declaring the frameworks interchangeable.
The same reasoning applies to legacy systems: age is not a general exemption. The FDA guidance conditions for systems operational before 20 August 1997 require specific assessment alongside predicate obligations and evidence of fitness. Developments in signature law also require contextual assessment; they do not make every possible signature technology mandatory.
5. Simulated case: the same file, two different uses
A file containing fictitious data is used in an isolated environment for an informal exercise, without generating formal training evidence. Later, an analyst proposes copying it into the QC workflow to calculate a result for review. The format is identical; its role in the process changes.
Before operational use, the owner identifies the required record, formula, inputs, version, approval and retention. They assess applicable requirements and necessary testing. Previous educational use does not demonstrate GMP fitness. Develop this assessment with spreadsheets and controls in the GMP laboratory.
6. Turn scope into verifiable decisions
Conclude the assessment with its scope and rationale, current references, existing controls, gaps, owners and acceptance criteria. Connect gaps to decisions before use or to measures authorised within the quality system. Next, link requirements and risk to validation testing and LIMS/CDS release.
Revisit applicability when use, markets, workflows, signatures or retention change. A correct assessment at implementation may no longer describe the real process following an integration or a change in the purpose of the data.
Sources and status — checked: 2 October 2026. 21 CFR Part 11, regulation, eCFR updated through 30 September 2026, §§11.1, 11.3 and 11.10–11.70; 21 CFR 211.194 and 211.68, US requirements relevant to pharmaceutical CGMP; FDA, Part 11 — Scope and Application, final nonbinding 2003 guidance (August PDF, September catalogue entry), sections III.A–C; EudraLex Volume 4, Annex 11 and Chapter 4, January 2011 revisions. The matrix and case are editorial examples, not exhaustive regulatory checklists.
Continue exploring
PL-06-018
Instrument time synchronisation: chronology and audit trails
When clocks tell different stories, identify timestamp origins and reconstruct events without changing the original records.
Read the articlePL-06-017
Laboratory electronic signatures: approvals and record linkage
A signature must make it verifiable who approved which content: workflow controls and corrections after approval.
Read the articlePL-06-016
Digital laboratory user roles: access and privileges
An operational matrix for assigning, testing and reviewing access rights while preserving accountability for actions.
Read the article


