FDA 21 CFR Part 11
Evidence request list. 13 controls, 13 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
21 CFR Part 11 - Implementation, Guidance, Risk-Based Approach and Status
21 CFR Part 11 has been in force since 20 August 1997 (Final Rule published 20 March 1997 + effective 20 August 1997). The 2003 FDA Scope and Application Guidance significantly narrowed enforcement scope using a risk-based approach + announced enforcement discretion regarding certain Part 11 requirements (legacy systems + validation + audit trails for non-critical records). FDA enforcement focus areas: (a) data integrity - the FDA Data Integrity Guidance (2018 + 2021 update) + Warning Letters citing inadequate audit trail review + missing accountability + paper-vs-electronic discrepancies + post-hoc record creation; (b) clinical trial data per Bioresearch Monitoring (BIMO); (c) GMP manufacturing records per the 'Data Integrity ALCOA+' framework (Attributable + Legible + Contemporaneous + Original + Accurate + Complete + Consistent + Enduring + Available); (d) medical device per QMSR (21
- Data integrity assessment using ALCOA+ framework
- CSV-to-CSA transition plan
- SBOM + AI/ML model governance
- International coordination with EU Annex 11 + EMA
- Compliance program treating Part 11 as static (no CSA transition + no SBOM + no AI/ML governance)
- ALCOA+ data integrity gaps not addressed
- Annex 11 + EMA coordination absent for dual-validated systems
21 CFR Part 11 - Validation, Audit Trail, Operational Controls (§11.10(a) + (e) + (f))
Section 11.10 access + control elements: (d) LIMITING SYSTEM ACCESS TO AUTHORISED INDIVIDUALS - role-based access control (RBAC) + least-privilege + provisioning + de-provisioning lifecycle + periodic access reviews + segregation of duties; (f) USE OF OPERATIONAL SYSTEM CHECKS TO ENFORCE PERMITTED SEQUENCING OF STEPS AND EVENTS AS APPROPRIATE - workflow + step-by-step controls preventing out-of-order execution (e.g. release approval before product release; review before submission); (g) USE OF AUTHORITY CHECKS to ensure that only authorised individuals can use the system + electronically sign a record + access the operation or computer system input or output device + alter a record or perform the operation at hand - the authority check is the just-in-time verification at the moment of action that the user has the right to perform the specific action; (h) USE OF DEVICE (e.g. TERMINAL) CHE
- Access control matrix + RBAC + access reviews
- Workflow design + sequencing test cases
- Authority check evidence at sensitive actions
- Device / terminal registration + validation
- Shared accounts in Part 11 systems
- Workflow allowing out-of-order execution
- Authority checks only at login without per-action verification
- Device checks absent allowing data input from unregistered terminals
Section 11.10(e) audit trail requirement: USE OF SECURE + COMPUTER-GENERATED + TIME-STAMPED AUDIT TRAILS to independently record the date and time of operator entries and actions that create + modify + or delete electronic records. Record changes must not obscure previously recorded information. Audit trails must be maintained for as long as required for the subject records (typically following the underlying record-retention requirement which can be 2 years (clinical) + 5 years (medical device) + or longer depending on the regulated activity) + must be AVAILABLE FOR AGENCY REVIEW AND COPYING. Audit trails must include: WHO (user identity); WHAT (action - create + modify + delete + view as appropriate); WHEN (computer-generated time stamp - server-side clock + synchronized to authoritative time source NTP); WHERE (system + module + record); BEFORE / AFTER VALUES (for modification audit);
- Audit trail design specification + DQ-OQ-PQ test evidence
- Tamper-evidence verification + integrity controls
- Audit trail retention aligned with subject-record retention
- Agency-review export capability test
- Audit trail enabled at vendor default without site-specific configuration
- Tamper-evident only at filesystem layer + database-level inserts not detected
- Audit trail retention shorter than subject-record retention
- Time-source not synchronized to authoritative NTP creating inconsistent time-stamps
Section 11.10(a) requires VALIDATION of closed systems to ensure accuracy + reliability + consistent intended performance + the ability to discern invalid or altered records. Validation is operationalised through: (a) Computer System Validation (CSV) lifecycle including URS (User Requirements Specification) + FS (Functional Specification) + DS (Design Specification) + IQ (Installation Qualification) + OQ (Operational Qualification) + PQ (Performance Qualification) + risk assessment + traceability matrix + validation summary report + ongoing validation maintenance; (b) GAMP 5 framework (ISPE Good Automated Manufacturing Practice) categorising systems as Category 1 (infrastructure software) through Category 5 (custom software) with proportionate validation rigour; (c) ICH Q9 (Quality Risk Management) + ICH Q10 (Pharmaceutical Quality System) risk-based approaches; (d) FDA 2003 SCOPE AND AP
- CSV file per system - URS + FS + DS + IQ + OQ + PQ + risk + traceability + summary
- GAMP 5 category determination
- Risk-based testing rationale documentation
- CSA transition plan
- SBOM for production / medical device software
- CSV applied uniformly without risk-based scope
- GAMP 5 categorisation absent
- 2003 enforcement-discretion guidance invoked as blanket exemption
- CSA transition not planned
Section 11.10(b) + (c) record protection + retention + inspection requirements: (b) THE ABILITY TO GENERATE ACCURATE AND COMPLETE COPIES OF RECORDS IN BOTH HUMAN READABLE AND ELECTRONIC FORM SUITABLE FOR INSPECTION + REVIEW + AND COPYING BY THE AGENCY - records must be exportable in both human-readable (PDF + print) + electronic (XML + JSON + CSV + native format) forms; copies must be ACCURATE (faithful to original) + COMPLETE (no omissions or summarisation); FDA inspectors expect to receive copies on request typically within minutes for routine inspection + hours for complex queries. (c) PROTECTION OF RECORDS TO ENABLE THEIR ACCURATE AND READY RETRIEVAL THROUGHOUT THE RECORDS RETENTION PERIOD - retention periods derive from underlying agency-regulation requirements (typically 2 years post-clinical-trial-close for clinical; 5+ years for medical-device QMSR records; longer for biologics +
- Copy-export capability + format support
- Records retention schedule per agency-regulation requirement
- Migration / archival procedure + obsolescence plan
- Destruction procedure + authorisation records
- Records exportable only in proprietary format
- Retention period shorter than agency regulation
- Migration losing audit trails or signature linkages
- Destruction without documented authorisation
21 CFR Part 11 Subpart A - General Provisions (Scope, Implementation, Definitions)
Section 11.3 establishes the Part 11 definitions: (a) ACT = the Federal Food + Drug + and Cosmetic Act. (b) AGENCY = the Food and Drug Administration. (c) BIOMETRICS = a method of verifying an individual's identity based on measurement of the individual's physical feature(s) or repeatable action(s) where those features and/or actions are both unique to that individual and measurable. (d) CLOSED SYSTEM = an environment in which system access is controlled by persons who are responsible for the content of electronic records that are on the system. (e) DIGITAL SIGNATURE = an electronic signature based upon cryptographic methods of originator authentication, computed by using a set of rules and a set of parameters such that the identity of the signer and the integrity of the data can be verified. (f) ELECTRONIC RECORD = any combination of text + graphics + data + audio + pictorial + or other
- Internal classification of systems as closed or open per §11.3(d)/(i)
- Electronic record + signature inventory
- Biometric / digital signature deployment register
- System classification not documented + risk-based controls applied without clarity on closed vs open
- Definitional drift between §11.3 + internal procedure language
Section 11.1 (Scope): the rules in this part set forth the criteria under which the agency considers electronic records + electronic signatures + handwritten signatures executed to electronic records to be trustworthy + reliable + equivalent to paper records + handwritten signatures executed on paper. Section 11.1 applies to records in electronic form that are created + modified + maintained + archived + retrieved + transmitted under any records requirement set forth in agency regulations. Section 11.2 (Implementation): for records required to be maintained but not submitted to the agency, persons may use electronic records in lieu of paper records or electronic signatures in lieu of traditional signatures provided that the requirements of Part 11 are met. Section 11.2(b) for records submitted to the agency, persons may use electronic records in lieu of paper records provided that the re
- Internal scope memo identifying which agency-regulation records the entity maintains in electronic form
- eCTD / eMDR / eSubmissions readiness file
- Public-docket 92S-0251 cross-reference for FDA-submitted records
- Electronic records used in lieu of paper without meeting Part 11 requirements
- FDA-submitted records not identified in public docket 92S-0251 (or successor list) as agency-accepted electronic forms
21 CFR Part 11 Subpart B - Electronic Records (§11.10 Closed Systems)
Section 11.10 establishes the 11 control requirements for CLOSED SYSTEMS used to create + modify + maintain + transmit electronic records. Persons who use closed systems must employ procedures + controls designed to ensure the authenticity + integrity + when appropriate the confidentiality of electronic records + to ensure that the signer cannot readily repudiate the signed record as not genuine. Such procedures + controls must include: (a) VALIDATION of systems to ensure accuracy + reliability + consistent intended performance + the ability to discern invalid or altered records; (b) the ability to generate ACCURATE + COMPLETE COPIES of records in both human readable and electronic form suitable for inspection + review + and copying by the agency; (c) PROTECTION of records to enable their accurate + ready retrieval throughout the records retention period; (d) LIMITING SYSTEM ACCESS to au
- §11.10 control inventory mapping each (a)-(k) requirement
- Validation lifecycle file (URS + FS + DS + IQ + OQ + PQ + risk assessment + summary report)
- Audit-trail design + review evidence + retention policy aligned with subject-record retention
- Access control + authority + device check evidence
- Personnel training records + accountability policies + documentation control / change-management records
- Validation limited to vendor IQ/OQ without site-specific OQ/PQ + risk-based testing
- Audit trail not computer-generated + time-stamped + tamper-evident
- Access limiting based on shared accounts (violates §11.10(d) + §11.10(g))
- Personnel qualifications + accountability policy missing or stale
21 CFR Part 11 Subpart B - Electronic Records (§11.30 Open Systems, §11.50 + §11.70 Signature Manifestations and Linking)
Section 11.30 establishes the controls for OPEN SYSTEMS. Persons who use open systems to create + modify + maintain + transmit electronic records must employ procedures + controls designed to ensure the authenticity + integrity + as appropriate the confidentiality of electronic records from the point of their creation to the point of their receipt. Such procedures + controls must include those identified in §11.10 (closed system controls) AS APPROPRIATE + ADDITIONAL MEASURES such as: (a) DOCUMENT ENCRYPTION + (b) USE OF APPROPRIATE DIGITAL SIGNATURE STANDARDS to ensure record authenticity + integrity + confidentiality. Open systems are those where access is not controlled by the persons responsible for the content of electronic records on the system - typically systems where multiple organisations or external parties have access (e.g. cloud-hosted multi-tenant systems + EDC platforms sha
- Open system classification + risk assessment
- Encryption-at-rest + in-transit + key management
- Digital signature standards adoption + certificate management
- Open system using only §11.10 closed-system controls without §11.30 additional measures
- Encryption not applied to records traversing untrusted intermediaries
- Digital signatures absent or not following recognised standards
Section 11.50 (Signature Manifestations): (a) signed electronic records must contain information associated with the signing that clearly indicates all of the following: (1) the printed name of the signer; (2) the date and time when the signature was executed; (3) the meaning (such as review + approval + responsibility + or authorship) associated with the signature. (b) the items identified in §11.50(a) must be subject to the same controls as for electronic records + must be included as part of any human readable form of the electronic record (such as electronic display or printout). Section 11.70 (Signature / Record Linking): electronic signatures + handwritten signatures executed to electronic records must be linked to their respective electronic records to ensure that the signatures cannot be excised + copied + or otherwise transferred to falsify an electronic record by ordinary means
- Signature manifestation evidence in record output (PDF + print + display)
- Signature-record linking cryptographic or system-enforced binding
- Tamper-evident binding test results
- Signature manifestation missing meaning (only name + date)
- Human-readable form not generated or unrepresentative
- Signature linking by side-table reference allowing excision + copying
21 CFR Part 11 Subpart C - Electronic Signatures (§11.100 General Requirements)
Section 11.100 establishes the general requirements for electronic signatures: (a) UNIQUENESS - each electronic signature must be UNIQUE TO ONE INDIVIDUAL + must not be reused by + or reassigned to anyone else. (b) IDENTITY VERIFICATION - before an organisation establishes + assigns + certifies + or otherwise sanctions an individual's electronic signature + or any element of such electronic signature + the organisation must verify the identity of the individual. (c) FDA CERTIFICATION - persons using electronic signatures must, prior to + or at the time of + such use, certify to the agency that the electronic signatures in their system, used on or after August 20 1997, are intended to be the legally binding equivalent of traditional handwritten signatures. The CERTIFICATION must be SUBMITTED IN PAPER FORM SIGNED WITH A TRADITIONAL HANDWRITTEN SIGNATURE to: Food and Drug Administration, Of
- Electronic signature uniqueness verification at issuance + revocation
- Identity verification records (in-person + remote + KYC)
- FDA paper certification on file (one-time submission)
- Additional-certification readiness
- Electronic signature reused or reassigned
- Identity verification limited to email verification without stronger authentication
- FDA certification missing or not submitted in paper form with handwritten signature (this is a frequent inspection finding)
- No additional-certification readiness
21 CFR Part 11 Subpart C - Electronic Signatures (§11.200 + §11.300 Components, Controls, ID Codes and Passwords)
Section 11.200 establishes electronic signature components + controls: (a) ELECTRONIC SIGNATURES THAT ARE NOT BASED UPON BIOMETRICS must: (1) EMPLOY AT LEAST TWO DISTINCT IDENTIFICATION COMPONENTS such as an identification code + password (the FDA's two-factor electronic signature requirement); (i) when an individual executes a series of signings during a single + continuous period of controlled system access + the first signing must be executed using all electronic signature components + subsequent signings must be executed using at least one electronic signature component that is only executable by + and designed to be used only by the individual; (ii) when an individual executes one or more signings not performed during a single + continuous period of controlled system access + each signing must be executed using all of the electronic signature components. (2) be used only by their ge
- Two-component signature design (ID code + password) + continuous-session policy
- Biometric signature controls evidence
- Anti-shared-signature monitoring
- Single-component signature (e.g. password only) treated as Part 11 compliant
- Continuous-session policy missing or inconsistent across systems
- Biometric signature without anti-spoofing controls
Section 11.300 establishes the controls for identification codes + passwords used as electronic signature components: (a) MAINTAINING THE UNIQUENESS of each combined identification code + password such that no two individuals have the same combination of identification code + password; (b) ENSURING that identification code + password issuances are periodically checked + recalled + or revised (e.g. to cover such events as password aging); (c) FOLLOWING LOSS MANAGEMENT PROCEDURES TO ELECTRONICALLY DEAUTHORIZE LOST + STOLEN + MISSING + or otherwise potentially compromised tokens + cards + and other devices that bear or generate identification code or password information + to issue temporary or permanent replacements using suitable + rigorous controls; (d) USE OF TRANSACTION SAFEGUARDS to prevent unauthorised use of passwords and / or identification codes + to detect and report in an immedi
- ID + password uniqueness verification
- Password aging + rotation policy + records
- Loss management procedure + token + card deauthorisation + replacement
- Transaction safeguard + unauthorised-use detection + alerting
- Token / card initial + periodic testing
- ID + password combinations reused across users
- Password aging not enforced or password manager allowing identical passwords across systems
- Lost tokens deauthorised slowly or via informal process
- Transaction safeguards limited to logging without alerting
- Token / card initial + periodic testing absent
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FDA 21 CFR Part 11 framework page.