What are the IT requirements of 21 CFR Part 11?

Short answer

21 CFR Part 11 requires that electronic records and signatures used for FDA-required records be trustworthy and equivalent to paper. For IT, that means validated systems, access limited to authorized people, secure time-stamped audit trails, records retrievable for the full retention period, and electronic signatures unique to one person that show name, date, time and meaning. It applies where FDA predicate rules require the record.

When Part 11 applies

Part 11 covers records in electronic form that are created, modified, maintained, archived, retrieved or transmitted under any records requirement in FDA regulations, plus electronic records submitted to FDA. Those underlying requirements, such as GMP, GLP and GCP rules, are called predicate rules.

FDA's 2003 Scope and Application guidance narrowed how the agency applies the rule: if a predicate rule does not require the record, Part 11 generally does not apply to it. Research notes that will never support a submission or a regulated decision are usually outside it.

Controls for closed systems (11.10)

  • Validation for accuracy, reliability, consistent intended performance and the ability to detect invalid or altered records.
  • Accurate, complete copies in human-readable and electronic form for FDA inspection.
  • Protection of records so they can be retrieved throughout the retention period.
  • System access limited to authorized individuals, with authority checks on who can sign, alter records or run operations.
  • Secure, computer-generated, time-stamped audit trails that do not obscure earlier entries and are kept as long as the records.
  • Operational and device checks, trained users, written accountability policies, and change control over system documentation.

Electronic signature rules

Each signed record must show the signer's printed name, the date and time, and the meaning, such as review or approval (11.50), and the signature must be linked so it cannot be copied to another record (11.70). Each signature must be unique to one person and never reassigned, identity must be verified first, and your company must certify to FDA that its electronic signatures are legally binding (11.100). Non-biometric signatures need at least two distinct components, such as an ID and password (11.200), with controls on uniqueness, periodic review and lost credentials (11.300).

What FDA enforces today

Under the 2003 guidance, FDA exercises enforcement discretion on Part 11's specific validation, audit trail, record retention and record copying provisions, and on legacy systems in operation before August 20, 1997. It continues to enforce access controls, authority and device checks, training and accountability, and all electronic signature provisions.

Discretion is not exemption. Predicate rules still require records to be accurate and retained, and FDA's 2018 data integrity guidance expects audit trails to be reviewed as part of record review. FDA recommends a documented, justified risk assessment to decide how much validation each system needs.

Common follow-up questions

Does Part 11 apply to Microsoft 365 or SharePoint?

Only when you use them to create or keep records required by a predicate rule or submitted to FDA. If you run controlled documents or batch records there, that use needs Part 11 controls such as audit trails, access control and compliant signatures; general email and drafts usually do not.

Does Part 11 require multifactor authentication?

Part 11 does not name MFA. It requires limited access and, for non-biometric signatures, at least two distinct identification components such as an ID and password. MFA is a sound way to strengthen the access controls FDA continues to enforce.

Does Part 11 cover clinical trial systems?

Yes. FDA's October 2024 final guidance on electronic systems, records and signatures in clinical investigations applies Part 11 expectations to sponsors, investigators, IRBs and CROs using electronic systems for clinical investigation records.

Need help with this?

LAN Service Group provides GxP-regulated IT for life-science companies, implementing the access controls, audit trail configuration, identity management and system documentation that Part 11 compliance depends on.

Talk to LAN Service Group (888) 281-7243

Sources