Electronic Signatures
What is Electronic Signatures?
Digital methods of indicating agreement or approval on electronic documents, with legal validity defined by regulations such as eIDAS and ESIGN.
Terms that appear alongside electronic signatures
Each of these is named in at least one of the same controls as electronic signatures. The number is how many controls name both.
- integrity 5 shared controls
- audit trail 5 shared controls
- audit 5 shared controls
- cybersecurity 4 shared controls
- data integrity 3 shared controls
- certification 3 shared controls
- fda 21 cfr part 11 3 shared controls
- authentication 3 shared controls
Frameworks that govern electronic signatures
What the standards actually require on electronic signatures
Requirements naming electronic signatures across 6 standards, quoted from the control text.
Sets the requirements for validating a qualified electronic signature (confirming the certificate validity, integrity of the signed data, and signatory identity at signing time), and provides for qualified validation services (Art 33).
EIDAS-Art.32 · Validation of qualified electronic signatures →Section 11.100 establishes the general requirements for electronic signatures: (a) UNIQUENESS - each electronic signature must be UNIQUE TO ONE INDIVIDUAL + must not be reused by + or reassigned to anyone else.
Part11.100 · Electronic signatures - general requirements (21 CFR §11.100) →Requirements for securing electronic transactions, including qualified electronic signatures.
MALABO-Art7 · Security of Electronic Transactions and Electronic Signatures →Electronic signatures must be equivalent to handwritten ones, permanently linked to records with date and time stamps.
Clause 14 · Electronic signatures →Parties may not deny the legal validity of an electronic signature solely on the basis that it is in electronic form and must permit parties to electronic transactions to mutually determine appropriate authentication technologies and methods.
USMCA-19.6 · Electronic Authentication and Electronic Signatures →Section 820.35 establishes FDA-specific record-control requirements that supplement ISO 13485:2016 Section 4.2.5. SPECIFIC REQUIREMENTS: (a) RECORD RETENTION - records must be retained for a period of time equivalent to the design + expected life of the device...
QMSR-820.35 · Control of records - record retention, audit trail, UDI, medical-device reporting (§820.35) →Questions people ask about electronic signatures
What is Electronic Signatures?
Why is Electronic Signatures important for compliance?
Which compliance frameworks address Electronic Signatures?
Where can I learn more about Electronic Signatures?
See how Electronic Signatures applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.