FDA

21 CFR Part 11 GxP Compliance: What It Requires, What It Looks Like, and How to Get There

A practical guide to 21 CFR Part 11 for GxP teams — what the regulation actually requires, what compliant electronic records and signatures look like in a validated system, and the ten failure modes inspectors find most often.

2026-08-07Cybroscape Technologies14 min read
Key takeaway

A practical guide to 21 CFR Part 11 for GxP teams — what the regulation actually requires, what compliant electronic records and signatures look like in a validated system, and the ten failure modes inspectors find most often.

21 CFR Part 11 is the FDA regulation that governs electronic records and electronic signatures in regulated life sciences environments. Issued in 1997 and still the authoritative US standard for GxP electronic systems, it sets the minimum requirements that any computer system must meet before electronic records can substitute for paper records in an FDA-regulated context. Understanding what Part 11 actually requires — and what a compliant system looks like in practice — is essential for every validation lead, QA director, and compliance team working in pharma, biotech, medical devices, or CROs.

What 21 CFR Part 11 Actually Covers

Part 11 applies to electronic records that are created, modified, maintained, archived, retrieved, or transmitted under FDA GxP requirements — including 21 CFR Parts 210, 211 (GMP), 820 (device QSR), and GCP regulations. If a regulation requires a record, and you keep that record electronically, Part 11 applies. The regulation has two main components: requirements for the electronic records themselves (Subpart B) and requirements for electronic signatures applied to those records (Subpart C). Predicate rule records kept only on paper, or hybrid systems where electronic records are printed and signed on paper, still exist but carry their own compliance burden.

A critical point the FDA has repeatedly clarified: Part 11 does not require organisations to use electronic signatures or electronic records. It sets the standards those systems must meet if you choose to use them. Many organisations still use paper in certain contexts because the validation and compliance burden of a Part 11-compliant electronic system outweighs the benefit for that record type.

The Seven Core Requirements for Electronic Records

  • System validation. Any system that creates or manages Part 11 records must be validated under GAMP 5 or equivalent — documented evidence that it consistently does what it is intended to do. See GxP Copilot for the validation package.
  • Audit trail. The system must generate a computer-generated, time-stamped audit trail that records the date and time of operator entries and actions that create, modify, or delete electronic records. The audit trail must be available for review and must not be modifiable by the user whose actions are being recorded.
  • Access controls. System access must be limited to authorised individuals. User IDs must be unique. Shared logins are a direct Part 11 violation. Access logs must be maintained.
  • Operational system checks. The system must enforce the sequencing of steps and events where required — for example, preventing a document from moving to Approved status unless all required review steps have been completed.
  • Authority checks. The system must ensure that only authorised individuals can use the system, electronically sign a record, access the operation, or enter or modify a record.
  • Device checks. Where appropriate, the system must check the validity of data sources — for example, the source of a computer terminal or scanner.
  • Training. Personnel using Part 11 systems must be trained, and that training must be documented in the personnel training records.

What a Compliant Audit Trail Looks Like

The audit trail requirement is the most commonly inspected Part 11 control and the one most organisations fail to implement correctly. A compliant audit trail captures: who took the action (unique user identifier, not a shared login), what the action was (creation, modification, deletion, retrieval, signature), when it happened (timestamp in a controlled time zone, not client-local time), and what changed (for modifications, the old value and the new value). The audit trail must be computer-generated — not a manually maintained log — and must be retained for at least as long as the records it documents.

Common failures: audit trails stored in the same table as the records they document (making them deletable alongside the records); audit trails that only log who approved a document, not who edited it; timestamps from client browsers rather than the server; and no integrity check to detect whether audit trail entries have been modified after the fact. Audit Readiness in GxP Copilot uses a tamper-evident, append-only structure with a hash-chain integrity check that flags any retrospective modification.

What Compliant Electronic Signatures Require

Part 11 Subpart C governs electronic signatures. The requirements are specific and non-negotiable. Each electronic signature must be unique to one individual and must not be reused by or reassigned to anyone else. Organisations must verify the identity of each individual before assigning them an electronic signature. Signatures applied to records must contain the signer's printed name, the date and time when the signature was executed, and the meaning of the signature (for example: reviewed, approved, witnessed).

The re-authentication requirement catches many systems off guard. When a person signs for the first time in a session, Part 11 requires re-authentication — the signer must re-enter their password or equivalent credentials, not simply click an "I approve" button. Where two or more signatures are applied, only the first requires a re-authentication; subsequent signatures in the same session can use one component (typically the ID or password, but not both). The signature must be linked to the specific record being signed such that it cannot be transferred to another record.

GxP Copilot enforces all of these at the data layer: re-authentication is required at signing, the ceremony records name, timestamp, and meaning, the signature is cryptographically bound to the document version being signed, and authors cannot approve their own drafts. See 21 CFR Part 11 for the full Part 11 feature detail.

What 21 CFR Part 11 Looks Like in a Validated GxP System

In practice, a Part 11-compliant system presents several visible and invisible controls. Visibly: every record shows a version history with timestamps and user identifiers; the approval workflow enforces role separation (author, reviewer, approver are distinct); signing requires a password prompt with a meaning field; and signed versions display the signature block with name, date/time, and meaning. Invisibly: the underlying records are immutable once signed — no silent edits are possible; the audit trail is stored separately from the record and verified on read; and access is governed by role-based permissions with unique, non-shared credentials for every user.

What it does not look like: a checkbox labelled "I approve" that requires no re-authentication; a signature block added to a PDF as a text annotation; an admin account shared across the QA team; a database where records and audit logs are in the same table and can be deleted together; or a system where the audit trail only activates in "GxP mode" and can be switched off.

The Ten 21 CFR Part 11 Failure Modes Inspectors Find Most Often

  • Shared user accounts. Multiple people using a single login defeats the uniqueness requirement for electronic signatures.
  • No re-authentication at signing. Clicking "approve" without re-entering credentials is not a Part 11-compliant signature.
  • Mutable audit trails. If a database administrator can delete or overwrite audit trail entries, the trail is not tamper-evident.
  • Audit trail not capturing old values. Recording that a field changed but not what it changed from leaves investigators unable to reconstruct history.
  • Client-side timestamps. Timestamps generated by the user's browser or local PC can be manipulated. The server must set the authoritative time.
  • No integrity check. Without a hash or checksum, modified records cannot be detected.
  • Author self-approval. The same person who drafted a document approving it violates the operational system check requirement for segregation of duties.
  • Inactive accounts not disabled. Departed employees whose accounts remain active represent an access control failure.
  • Signed versions editable. Any system that permits editing a record after it has been electronically signed without creating a new version under change control is non-compliant.
  • Audit trail not human-readable. If an auditor cannot read the audit trail without assistance from IT, it fails the intended purpose.

EU Annex 11 and How It Compares to Part 11

EU GMP Annex 11 is the European equivalent of 21 CFR Part 11 and covers the same core topics: validation, audit trails, access control, electronic signatures, change management, data backup, and disaster recovery. Annex 11 is generally considered more prescriptive in some areas — it explicitly requires a documented system inventory, a formal risk assessment before validation, and clear procedures for data migration. The upcoming Annex 11 revision is expected to align more closely with FDA's risk-based CSA approach and to incorporate provisions from EU GMP Annex 22 on AI in GMP. Organisations operating in both US and EU markets should build their electronic records posture to satisfy the stricter requirement on each point rather than maintaining two separate compliance postures. Annex 11 / 22 covers both Annex 11 and Annex 22 in GxP Copilot.

Getting to Part 11 Compliance Without a Remediation Project

The fastest path to Part 11 compliance is to start in a system that is architected for it — where the audit trail is structural, re-authentication is enforced by the workflow, segregation of duties is a configuration not a policy, and signed versions are frozen at the data layer. GxP Copilot is built this way. Teams that start validation in GxP Copilot are Part 11 compliant from the first sign-off cycle without a separate remediation project. Teams inheriting legacy systems that have Part 11 gaps typically need a gap assessment, a remediation plan under change control, and re-validation of affected records. audit readiness services cover both scenarios.

Where to go next

Explore GxP Copilot for AI-native validation, TraceDraft for source-traceable clinical documentation, or book a demo to see either on your own data.

21 cfr part 1121 cfr part 11 gxp21 cfr part 11 complianceelectronic records gxpelectronic signatures 21 cfr part 1121 cfr part 11 requirementsfda part 11 gxp
Next step

Bring a system. We'll show you the package.