Pharma & life sciences
GxP document management for life sciences
GxP document management is governed by FDA 21 CFR Part 11 and EU GMP Annex 11, which require validated systems, attributable and unalterable audit trails, controlled electronic signatures, and copies that remain readable for the record’s full retention period — commonly the product lifetime plus one year.
Why documents are difficult in pharma & life sciences
Life sciences is the sector with the strictest electronic records requirements of any we work with, and the one where a document system itself becomes an object of inspection. Under FDA 21 CFR Part 11 and EU GMP Annex 11, the system holding your batch records is not neutral infrastructure — it must be validated, its audit trail must be computer-generated and unalterable, and its electronic signatures must be provably linked to the records they apply to.
The practical consequence is that "we will configure it later" is not available. A GxP configuration has to be specified, tested and documented before it holds a regulated record, and changes to it are themselves controlled. That front-loads work most organisations prefer to defer, and it is the single biggest reason life sciences document projects run longer than the equivalent project in another sector.
Regulatory pressure
Three regulatory pressures that shape the configuration
FDA 21 CFR Part 11 (electronic records; electronic signatures)
What it requires. Validated systems, secure computer-generated time-stamped audit trails recording operator entries and actions that create, modify or delete records, retention of audit trails for at least as long as the records themselves, limited system access, and electronic signatures linked to their records so they cannot be excised, copied or transferred.
What it means for a document system. The audit trail must be generated by the system rather than maintained by a person, must be unalterable, and must outlive the record. It also means signature and record are inseparable: a signed batch record whose signature could be detached and reapplied elsewhere fails the rule.
EU GMP Annex 11 (computerised systems)
What it requires. Risk-based validation, an up-to-date system description, supplier assessment, controls over data changes with reason recorded, and the ability to obtain readable printed copies of electronically stored data throughout the retention period.
What it means for a document system. Supplier assessment makes the vendor part of your inspection scope, so the availability of validation documentation and a quality agreement is a procurement requirement rather than a nicety. "Reason for change" also has to be captured, which most general-purpose systems do not prompt for.
ALCOA+ data integrity expectations
What it requires. Records must be Attributable, Legible, Contemporaneous, Original and Accurate, with the additional expectations that they are Complete, Consistent, Enduring and Available.
What it means for a document system. Attributable rules out shared accounts absolutely. Contemporaneous rules out batch data entry after the fact. Enduring and Available shape retention and export: a record you cannot render in fifteen years is not available, whatever your storage says.
Capability mapping
Five capabilities mapped to GxP requirements
Computer-generated, unalterable audit trail
Every action is recorded by the system with the operator, a server-side timestamp and the document version, in an append-only log that no role can edit. Part 11 §11.10(e) requires exactly this, and requires the trail to be retained at least as long as the record — which is why the trail outlives disposed documents.
Signatures bound to a specific version
A signature applies to one version of one document and is filed with it, so it cannot be detached and reapplied. The signing history records the signer, the time and what was signed — the linkage Part 11 §11.70 demands.
Approval before issue for controlled SOPs
Workflow enforces that only an approved version is current, marks superseded versions unambiguously, and records the approver and date. The failure this prevents — an operator working to a superseded SOP — is among the most commonly cited GMP observations.
Attributable access with no shared accounts
Unique user identification with two-factor authentication enforceable per role, and OIDC single sign-on so identity is governed centrally. Attributability is not a permission feature; it is the precondition for every other Part 11 control.
Retention that outlasts the product
Batch documentation retention is expressed relative to expiry or release rather than creation, and disposition raises a review rather than deleting. Legal holds suspend disposal where an investigation or claim is live.
Taxonomy
A starting folder taxonomy
Quality management system
- Standard operating procedures (controlled)
- Work instructions and forms
- Quality manual and policies
- Change controls
- Deviations and CAPA
Manufacturing (GMP)
- Master batch records
- Executed batch records
- Equipment logs and calibration
- Cleaning validation
- Environmental monitoring
Laboratory (GLP)
- Analytical methods and validation
- Certificates of analysis
- Stability study data
- Out-of-specification investigations
Clinical (GCP)
- Trial master file sections
- Protocols and amendments
- Informed consent forms
- Investigator site files
Regulatory and validation
- Submissions and correspondence
- Computerised system validation packages
- Supplier assessments and quality agreements
- Training records and competency
Keeping computerised system validation in its own branch matters because it is the documentation an inspector asks for about the document system itself — including the validation of the DocumentMS configuration you are using to hold everything else.
Worked example
A worked workflow: controlled SOP revision under change control
Step 1: Raise change control
A change control record captures the reason for the change and its assessed impact. Annex 11 expects the reason to be recorded, so it is a mandatory field rather than a free-text note.
Step 2: Draft and review
The author produces a new version. It routes to the technical reviewer and Quality Assurance, each approving in their own authenticated session with 2FA where the role requires it.
Step 3: Approve, train, effective date
QA approval locks the version and sets an effective date. Affected operators receive a training and acknowledgement task, and the SOP does not become effective until training is recorded.
Step 4: Supersede and retain
The previous version is marked superseded and retained — never deleted — and the retention rule attaches. The audit trail evidences which version was effective on any given date.
Retention
Retention expectations
| Record class | Commonly applied period | What starts the clock | Source |
|---|---|---|---|
| Executed batch records (EU GMP) | 1 year after batch expiry, or 5 years after certification — whichever is longer | Batch expiry or QP certification | EU GMP Part I, Chapter 4 |
| Batch records (US) | 1 year after batch expiry, or 3 years after distribution | Batch expiry or distribution | 21 CFR §211.180 |
| Audit trails | At least as long as the records they describe | Follows the underlying record | 21 CFR §11.10(e) |
| Trial master file / clinical trial documentation | 25 years (EU CTR); at least 2 years after last approval (ICH GCP baseline) | Trial completion or last marketing approval | EU Regulation 536/2014; ICH E6(R2) §4.9.5 |
| Validation documentation for computerised systems | Life of the system plus a defined period after decommissioning | System decommissioning | Annex 11 / organisational validation policy |
| Training records | Duration of employment plus a defined period | End of employment | GMP expectation; period set by organisational policy |
These periods are indicative and must be confirmed against the specific regulations, product types and territories you operate under before you rely on them. GxP retention differs between GMP, GCP and GLP, between the EU and US, and by product class. Nothing here is regulatory advice.
FAQ
Pharma & life sciences document management: common questions
Is DocumentMS validated for 21 CFR Part 11?
A product cannot be validated on your behalf — validation applies to your configuration, in your process, for your intended use. What we supply is the documentation that makes your validation feasible: a system description, a completed supplier assessment questionnaire, functional specifications and platform test evidence, all released under NDA on request. Ask for the pack early in an evaluation rather than late; its absence is a hard blocker for a GxP buyer, and finding out during qualification is an expensive way to discover it.
Does the audit trail meet Part 11 §11.10(e)?
It is computer-generated, time-stamped from the server, records the operator and the affected document version, cannot be edited or deleted by any role including administrators, and is retained after the underlying document is disposed of. That is the shape the rule requires. Whether your implementation satisfies an inspector is a validation question, not a feature question.
Are the electronic signatures Part 11 compliant?
Signatures are applied in an authenticated session, bound to one version of one document, and filed with it so they cannot be excised or transferred — the §11.70 linkage requirement. The signature manifestation carries all three elements §11.50 requires: the signer’s printed name, the date and time of signing, and the meaning of the signature — approved, reviewed, authored — selected by the signer at the point of signing rather than inferred from the workflow step.
Can we record a reason for change?
Yes, and for GxP configurations it should be mandatory rather than optional. Annex 11 expects the reason for a change to be recorded, and a free-text field that people can skip produces exactly the observation you were trying to avoid.
How do you prevent an operator using a superseded SOP?
Only the approved version is marked current, superseded versions are labelled unambiguously and cannot be presented as current, and the effective date is set on approval. The audit trail then evidences which version was effective on any given date — which is the question an investigation actually turns on.
Zuletzt geprüft: 2026-09-01. Compare all ten industry configurations.