Part 11 is about trustworthy records, not a logo on a software page
21 CFR Part 11 sets requirements for electronic records and electronic signatures in FDA-regulated contexts. The rule addresses controls that help ensure authenticity, integrity, and, when appropriate, confidentiality. FDA’s scope and application guidance also explains how the agency thinks about Part 11 in relation to predicate rules. It is therefore a mistake to treat Part 11 as a generic product badge. The correct question is whether the system, its use, and its procedures together produce reliable records for the regulated activity.
Start with the record and the predicate requirement
List the records the system creates, changes, approves, transmits, or retains. For each record, identify the business process and the underlying predicate requirement. This prevents a common failure mode: testing a feature in isolation while never proving that the complete record remains usable and trustworthy through its lifecycle.
Control areas to review
- Validation and intended use: show that the system performs consistently for its defined use and that the validation record is maintained.
- Access control: restrict system access to authorised people and apply role permissions to create, change, approve, or export records.
- Operational checks: use appropriate checks for data input, processing, and output where errors could affect the record or decision.
- Audit trails: capture relevant changes, retain the original information where required, and make the history reviewable.
- Authority checks: prevent unauthorised use of the system, signature, or controlled operation.
- Record copies: produce accurate and complete copies in human-readable and, where appropriate, electronic form.
- Retention and availability: protect records for the required retention period and keep them available for inspection.
- Electronic signatures: make signatures unique to one individual, link them to the record, and show the signer, time, and signing meaning.
The procedure is part of the control
A technically capable system can still fail in practice if account provisioning, access review, audit-trail review, backup, incident handling, and signature management are undefined. Write the operating procedures, train the people who perform them, and retain evidence that the procedures are followed. A control with no owner is merely a wish wearing a password.
Questions for a focused review
- Can the team identify every regulated record and its retention requirement?
- Can an auditor reconstruct who changed a record, what changed, when, and why?
- Are shared accounts prohibited where individual attribution is required?
- Does an electronic signature remain linked to the exact record and signing meaning?
- Can the organisation retrieve a complete, readable record without relying on the vendor’s goodwill?
Use the VLMS validation lifecycle approach to connect these questions to requirements, risks, tests, approvals, and periodic review. Part 11 compliance is an outcome of the complete control environment, not of one checkbox.
Review your electronic-record controls
Start with the system, process, and evidence questions that matter to your team.
Talk with VLMS about your validation programme →