\1.
It should demonstrate who signed, what they signed, when they signed, why they signed where required, and how the signature stays linked to the record.
Define the signature event
Start by identifying the regulated record and the decision the signature represents. Approval, review, authorship, verification, and acknowledgement are not always the same event. The requirement should state which meaning applies.
Define the status change that follows the signature, the role allowed to sign, whether a reason is required, and what happens if the record is changed later.
Test identity and authority
Test account creation, unique identity, authentication, role assignment, lockout or reset controls, and removal of access. The test should show that the signer is the person associated with the credential and that the role is permitted for that record and step.
Do not treat an email address alone as proof of signature identity. Review the organisation's account and identity procedures alongside system controls.
Test manifestation and linkage
The signed record should display or expose the signer identity, date and time, and signature meaning as required by the approved specification. Test that the signature is linked to the record so it cannot be copied to a different record or silently detached.
Challenge edits after signing. The system should either prevent the change, require a new controlled action, or preserve the history and signature state according to the approved design.
Cover administration and interfaces
Test administrative actions that could affect signature control, including role changes, password resets, time settings, imports, exports, and integrations. The scope depends on the intended use and risk.
Keep the Part 11 regulation and FDA scope guidance in the source set, then document how the system-specific controls meet the applicable requirements.
Retain evidence
Keep the test record, configuration, user and role evidence, signature manifestation, audit trail, and deviation disposition. A signature is one part of a controlled record lifecycle, not the entire control system.
| Control area | Evidence to look for |
|---|---|
| Identity | Unique account, authentication, role and access record |
| Meaning | Signature manifestation and defined signing purpose |
| Linkage | Record history showing signature remains connected |
| Change response | Controlled behaviour when signed data is edited |
| Administration | Reviewed evidence for privileged actions |
FAQ
Does Part 11 apply to every electronic signature?
Applicability depends on whether the electronic record and signature are used in the scope of the regulation and applicable predicate rules. Document the assessment.
Can a shared account sign a regulated record?
Shared accounts make individual attribution difficult and generally conflict with the need to link a signature to one person. Follow the approved identity policy.
Must a signature include a reason?
A reason may be required by the process or configuration. Define it in the requirements rather than assuming one universal option.
What if the record changes after signing?
The approved design should specify the response, such as invalidating the signature, creating a new revision, or requiring reapproval.
Decision rule: choose evidence from the consequence of failure, the control being relied on, and the ability to detect a problem. A larger document set is not automatically stronger. Clear scope, reproducible evidence, and an approved conclusion are what make the decision defensible.
Keep the rationale with the controlled record. Future reviewers should be able to see what was considered, what was tested or reviewed, what remains uncertain, and who accepted the residual risk.
During review, compare the approved requirement with observed use, current configuration, and retained evidence. That simple comparison often finds drift before an auditor does.
For related work, read our validation traceability matrix guide.
Primary sources
Bring validation work under control
VLMS Software helps healthcare teams organise validation, evidence, and audit readiness around the work that matters.
Talk to VLMS Software