Ready to fix validation chaos? Book Review
Electronic Records

Electronic-Signature Controls: What Part 11 Validation Should Show

\1.

It should demonstrate who signed, what they signed, when they signed, why they signed where required, and how the signature stays linked to the record.

Define the signature event

Start by identifying the regulated record and the decision the signature represents. Approval, review, authorship, verification, and acknowledgement are not always the same event. The requirement should state which meaning applies.

Define the status change that follows the signature, the role allowed to sign, whether a reason is required, and what happens if the record is changed later.

Test identity and authority

Test account creation, unique identity, authentication, role assignment, lockout or reset controls, and removal of access. The test should show that the signer is the person associated with the credential and that the role is permitted for that record and step.

Do not treat an email address alone as proof of signature identity. Review the organisation's account and identity procedures alongside system controls.

Test manifestation and linkage

The signed record should display or expose the signer identity, date and time, and signature meaning as required by the approved specification. Test that the signature is linked to the record so it cannot be copied to a different record or silently detached.

Challenge edits after signing. The system should either prevent the change, require a new controlled action, or preserve the history and signature state according to the approved design.

Cover administration and interfaces

Test administrative actions that could affect signature control, including role changes, password resets, time settings, imports, exports, and integrations. The scope depends on the intended use and risk.

Keep the Part 11 regulation and FDA scope guidance in the source set, then document how the system-specific controls meet the applicable requirements.

Retain evidence

Keep the test record, configuration, user and role evidence, signature manifestation, audit trail, and deviation disposition. A signature is one part of a controlled record lifecycle, not the entire control system.

Control areaEvidence to look for
IdentityUnique account, authentication, role and access record
MeaningSignature manifestation and defined signing purpose
LinkageRecord history showing signature remains connected
Change responseControlled behaviour when signed data is edited
AdministrationReviewed evidence for privileged actions

FAQ

Does Part 11 apply to every electronic signature?

Applicability depends on whether the electronic record and signature are used in the scope of the regulation and applicable predicate rules. Document the assessment.

Can a shared account sign a regulated record?

Shared accounts make individual attribution difficult and generally conflict with the need to link a signature to one person. Follow the approved identity policy.

Must a signature include a reason?

A reason may be required by the process or configuration. Define it in the requirements rather than assuming one universal option.

What if the record changes after signing?

The approved design should specify the response, such as invalidating the signature, creating a new revision, or requiring reapproval.

Decision rule: choose evidence from the consequence of failure, the control being relied on, and the ability to detect a problem. A larger document set is not automatically stronger. Clear scope, reproducible evidence, and an approved conclusion are what make the decision defensible.

Keep the rationale with the controlled record. Future reviewers should be able to see what was considered, what was tested or reviewed, what remains uncertain, and who accepted the residual risk.

During review, compare the approved requirement with observed use, current configuration, and retained evidence. That simple comparison often finds drift before an auditor does.

For related work, read our validation traceability matrix guide.

Bring validation work under control

VLMS Software helps healthcare teams organise validation, evidence, and audit readiness around the work that matters.

Talk to VLMS Software