FDA Electronic Records and Electronic Signatures
FDA regulation establishing criteria for electronic records and signatures to be considered trustworthy and equivalent to paper records. Required for any company manufacturing or distributing FDA-regulated products.
What 21 CFR Part 11 draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Audit Trail
Systems MUST use secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Authority Checks
REQUIRES use of authority checks to ensure only authorized individuals can use the system, access operations, or sign records.
Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.
Operational System Checks
Systems MUST enforce permitted sequencing of steps and events, as appropriate.
Framework audits do not ask whether you own a tool; they ask you to demonstrate that a named control operated over a period. Access reviews, privileged activity, change monitoring, and audit-log integrity are produced from the activity already being captured and mapped to the control they satisfy, with dashboards showing posture over the audit window rather than at a single point. Our evidence-pack engagement formats it the way assessors expect and answers the database-controls questions on the call.
Signature Manifestations
Electronic signatures MUST be linked to their respective electronic records to ensure signatures cannot be removed or transferred.
A requirement like this is about the record surviving the person who would rather it did not, which means the audit trail has to be protected as carefully as the data. File activity monitoring hashes the datafiles, the transaction logs, the backups, and the audit trail itself with XXH3, then baselines them — so an alteration or a deletion is evident rather than inferred, and it is attributed to the session and OS user behind it. Because the same platform holds the query trail, a destructive statement and the file-level change it produced are two views of one event rather than two investigations.
What 21 CFR Part 11 covers
21 CFR 11.3(b)(6) and (b)(7) — electronic record and electronic signature
Records in electronic form that are created, modified, maintained, archived, retrieved or transmitted under any FDA predicate rule.
In scope
- Any combination of text, graphics, data, audio or pictorial information in digital form
- Electronic signatures intended as the legally binding equivalent of a handwritten signature
- Audit trails required by 11.10(e)
What falls outside
Records kept only on paper, and records not required by a predicate rule. The predicate rule is what pulls a record into Part 11 — Part 11 does not create record-keeping obligations of its own.
Scope is defined by the OTHER regulation. That is why "are we a Part 11 system?" is unanswerable without first naming the predicate rule the record supports.
21 CFR Part 11 · as at 2026-08
How 21 CFR Part 11 is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The FDA, through inspection findings, warning letters, and referral to the Department of Justice.
Part 11 has no penalty table. Failure shows up as a data integrity observation, and data integrity is the single most cited category in drug GMP warning letters. If the electronic records are unreliable, every batch they support becomes suspect. Consent decrees in this area have routinely cost hundreds of millions.
The Park doctrine is used sparingly and is controversial, but it is settled law and it reaches officers who did not personally participate.
Who is personally on the hook
- Who can be charged
- Responsible corporate officers, under the Park doctrine — liability attaches by position, without proof that the officer knew or intended the violation
- For what
- shipping adulterated or misbranded product — liability attaches by position, without proof the officer knew
- Maximum
- A misdemeanour on strict liability, rising to a felony with imprisonment where there is intent to defraud or mislead, or a repeat offence
- Brought by
- The US Department of Justice, on referral from the FDA
Uncapped exposure that sits outside this instrument
These come from company law rather than from 21 CFR Part 11, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Responsible corporate officer
United States, under the Federal Food, Drug, and Cosmetic Act. It does not travel outside FDA-regulated activity.
Triggered by. A violation occurring in an operation the officer was in a position to prevent. There is no requirement to show the officer knew about it or intended it.
Who. Officers with authority over the operation, by virtue of their position rather than their acts.
A criminal conviction is not indemnifiable, and a misdemeanour conviction here carries debarment from the industry, which ends a career rather than costing a sum.
United States v. Dotterweich (1943); United States v. Park (1975).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for 21 CFR Part 11,
not configured for it afterwards
GxP Data Integrity Monitoring
Track all access to validation data, batch records, and quality systems
21 CFR Part 11 Audit Trail Report
Timestamped audit trail with operator identification for FDA inspections
Unauthorized Access Detection
Real-time alerts when users attempt unauthorized system access
GxP Data Patterns
Identify batch records, COAs, validation data, and LIMS entries
Other Healthcare frameworks
Walk into the 21 CFR Part 11 audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.