21 CFR Part 11 Compliance Explained (And How eQMS Helps)
Complying with 21 CFR Part 11 is rarely just a matter of having the right policy in place. It comes down to whether your systems, your audit trails, and your signature workflows hold up when an FDA investigator actually looks at them.
That gap between the requirement on paper and the requirement in practice is where most companies run into trouble.
This post walks through what 21 CFR Part 11 actually says, the most common pitfalls companies hit, what an auditor is really looking for when they ask about it, and how a modern eQMS is built to address these requirements as a matter of daily operation rather than a once-a-year scramble.
What Is 21 CFR Part 11?
21 CFR Part 11 is the FDA regulation that governs electronic records and electronic signatures in FDA-regulated industries, including pharmaceutical, biotech, and medical device companies. It was first issued in 1997, in response to a straightforward question the agency needed to answer as paper systems gave way to computerized ones. Could an electronic record be considered as trustworthy, reliable, and legally binding as a paper record with a handwritten signature?
The regulation’s answer was yes, provided certain conditions are met.
Part 11 lays out the technical and procedural controls a company must have in place for electronic records and electronic signatures to be considered equivalent to their paper counterparts.
It does not tell you which software to buy or how to design your quality system. It tells you what your system, whatever it is, needs to be able to do and prove.
Who Part 11 Applies To
Part 11 applies to any FDA-regulated company that creates, modifies, maintains, archives, retrieves, or transmits records in electronic form in place of paper, where those records are required by an underlying predicate rule, such as good manufacturing practice (GMP), good laboratory practice (GLP), or good clinical practice (GCP) regulations.
This includes pharmaceutical manufacturers, medical device companies, biologics and combination product makers, contract manufacturers, and clinical research organizations.
A useful way to think about it is that Part 11 does not create new documentation requirements on its own. It applies wherever a predicate rule already requires a record or signature, and the company has chosen to keep that record electronically instead of on paper. If your quality system runs on an eQMS, spreadsheet, or any digital tool for records that GMP or GLP already require, Part 11 governs how that electronic version needs to be controlled.
Electronic Records Requirements Under Part 11
The regulation’s requirements for electronic records are meant to ensure that a record is accurate, complete, and cannot be altered without a trace. This breaks down into a handful of core expectations.
- System validation: Systems used to create, modify, or store electronic records must be validated to ensure accuracy, reliability, and the ability to detect invalid or altered records.
- Accurate, complete copies: The system must be able to generate accurate and complete copies of records in both human-readable and, where appropriate, electronic form suitable for inspection and review.
- Record protection: Records must be protected to enable their accurate and ready retrieval throughout the required retention period.
- Access limitations: Access to the system and to the records themselves must be limited to authorized individuals.
- Audit trails: The system must generate secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions that create, modify, or delete an electronic record. The original entry must not be obscured, and the audit trail must be retained for at least as long as the record it documents.
- Operational and device checks: Where appropriate, the system should enforce the correct sequence of steps and events, and confirm that only authorized devices can input data or commands.
Taken together, these requirements exist to answer one underlying question. If this record ends up in front of an investigator years from now, can the company prove exactly what it said, who touched it, and when?
Electronic Signature Requirements Under Part 11
Electronic signatures get their own set of requirements, separate from the records they are attached to, because a signature carries specific legal weight. Under Part 11, an electronic signature must be as unique to one individual as a handwritten signature, and it must never be reused or reassigned to someone else.
Key requirements include the following.
- Unique identity: Each electronic signature must be linked to one individual, and that individual’s identity must be verified before the signature is assigned.
- Signature components: Electronic signatures not based on biometrics must use at least two distinct identification components, typically an ID and a password, or an ID and a token or biometric factor.
- Continuous session controls: When an individual executes a series of signings during a single continuous session, the first signing requires both components, and subsequent signings in that same session may use just one, as long as the identity of the signer is not compromised.
- Nontransferability: Signatures cannot be shared, delegated, or reused by anyone other than the individual they belong to, even temporarily.
- Linked to the record: Each signature must be permanently linked to its corresponding record so that it cannot be excised, copied, or transferred to falsify another record.
- Signature meaning displayed: The signed record must clearly show the printed name of the signer, the date and time of signing, and the meaning associated with the signature, such as approval, review, or authorship.
This last point trips up more companies than people expect. A signature that just confirms “this action happened” is not the same as a signature that states whether the signer approved, reviewed, or authored the record. Part 11 requires that distinction to be visible on the record itself.
Common 21 CFR Part 11 Violations
Most Part 11 problems are not the result of a company ignoring the regulation outright. They tend to come from gaps that build up gradually as systems, processes, and personnel change over time. Some of the issues most frequently cited in FDA Form 483 observations and warning letters include the following.
- Incomplete or disabled audit trails: Systems where audit trail functionality is turned off, not reviewed, or does not capture who made a change and why.
- Shared logins and passwords: Multiple employees using a single account, which makes it impossible to tie an action or signature to one specific individual.
- Inadequate validation documentation: Systems put into GMP use without documented evidence that they were validated for their intended purpose, or validation that was never updated after a system change.
- Password and access control weaknesses: Weak password policies, accounts that are not deactivated when an employee leaves, or access privileges broader than a role actually requires.
- Hybrid record gaps: Mixing paper and electronic records for the same process in a way that creates gaps or inconsistencies, sometimes called an uncontrolled hybrid system.
- Missing signature meaning: Electronic signatures that do not clearly indicate what the signature represents, such as approval versus review.
- Poor change control over validated systems: Software updates, configuration changes, or new integrations applied without re-evaluating the system’s validated state.
None of these are exotic failures. They are the kind of small, procedural gaps that accumulate when a company relies on manual processes, disconnected tools, or a system that was validated once and never revisited.
What Auditors and FDA Investigators Expect to See
When an FDA investigator or a third-party auditor is evaluating Part 11 compliance, they are rarely satisfied by a policy document alone. They want to see the controls working, and they want to see evidence.
This usually means an auditor will ask to see an audit trail for a specific record and expect it to show a full, unedited history of changes with timestamps and user identity, not a summary.
They may ask how access is granted, reviewed, and removed, and expect documented evidence of periodic access reviews. They typically want to see the validation package for the system in question, including test scripts, a requirements traceability matrix, and evidence that the system’s actual intended use was tested, not just its default configuration.
Auditors also tend to probe how the company handles system changes, looking for a documented change control process that shows whether a software update or configuration change triggered a revalidation assessment. And they will often ask an employee to walk through the electronic signature process for a record, to confirm that the workflow genuinely requires unique credentials and that the displayed signature meaning matches company procedure.
The common thread across all of this is traceability. An auditor is not just checking whether a policy exists. They are checking whether the system and the people using it can demonstrate, on demand, exactly what happened, who did it, and when.
How an eQMS Supports Part 11 Compliance
This is where the right electronic quality management system earns its keep. An eQMS does not replace your regulatory judgment or your quality processes, but it gives you the infrastructure to meet Part 11’s requirements consistently, rather than depending on manual discipline alone.
Audit Trails
A well-built eQMS automatically generates a time-stamped, noneditable audit trail for records as they are created, reviewed, modified, or approved. Instead of reconstructing a record’s history after the fact, quality teams can pull a complete change history for any record in minutes, which is exactly the kind of evidence an auditor expects to see immediately.
Validation
Because an eQMS is purpose-built software rather than a general-purpose tool repurposed for quality use, vendors typically provide validation documentation, including installation and operational qualification evidence, to support the customer’s own validation effort. This gives quality and IT teams a documented starting point instead of building a validation package from scratch, and it makes revalidation after updates more manageable.
Access Controls
Role-based access controls let administrators define exactly what each user can view, edit, or approve, and tie every account to one individual rather than a shared login. Access reviews, deactivation of departed employees, and permission changes can all be logged, which directly supports the access-limitation and record-protection requirements in Part 11.
Electronic Signature Workflows
An eQMS can enforce the two-component signature requirement, capture the signer’s identity, and display the meaning of the signature (approval, review, or authorship) directly on the signed record. Because the signature workflow is built into the system rather than layered on afterward, it is far harder for a signature to be applied incorrectly or without the required context.
Version Control and Record Retention
Document and record version control prevents the kind of hybrid, inconsistent record-keeping that often trips companies up in an inspection. Superseded versions are retained and clearly marked, current versions are unambiguous, and retrieval of any version, current or historical, stays straightforward throughout the retention period.
Automated Workflows
Routing records through defined review and approval steps, with reminders and escalation built in, reduces the chance that a record sits unsigned, unreviewed, or improperly routed. This supports both the operational-sequence expectations in Part 11 and the practical reality of keeping quality processes moving on schedule.
Getting Started
21 CFR Part 11 is not a checkbox you complete once. It is an ongoing standard that your systems and processes need to meet every day, through every record and every signature. Companies that treat it as a continuous operational discipline, supported by the right system architecture, tend to face far fewer surprises in an inspection than those trying to reconstruct compliance evidence after the fact.
To help you get started, download our 21 CFR Part 11 compliance checklist for a practical, at-a-glance reference to use during your next audit prep.
If your current mix of tools, spreadsheets, and manual sign-offs is making that discipline harder to maintain, it may be worth seeing what a purpose-built eQMS looks like in practice.