Glossary
21 CFR Part 11
Also called: Part 11, CFR Part 11
21 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences. It requires validated systems, secure computer-generated audit trails, controlled access, and signatures bound to the records they apply to so they cannot be transferred.
21 CFR Part 11 explained
What it covers
Electronic records that are created, modified, maintained, archived, retrieved or transmitted under an FDA predicate rule — and electronic signatures applied to them. If a paper record would have been required, the electronic equivalent falls in scope.
The controls inspections concentrate on
Validation. The system must be validated for its intended use, which is your validation of your configuration, not something a vendor can perform on your behalf.
Audit trails. Secure, computer-generated and time-stamped, recording operator entries and actions that create, modify or delete records. They must not obscure previously recorded information, and they must be retained at least as long as the records themselves.
Access control. Limited to authorised individuals, with unique identification. Shared accounts are excluded outright, because a record of a shared account acting is attributable to nobody.
Signature linkage. Under §11.70, signatures must be linked to their records so they cannot be excised, copied or otherwise transferred.
The European counterpart
EU GMP Annex 11 covers similar ground for computerised systems and adds explicit expectations around supplier assessment and recording the reason for a change. Organisations operating in both territories usually design to Annex 11 and satisfy Part 11 as a consequence.
What a vendor can and cannot supply
A vendor can supply the technical controls and the documentation that makes your validation feasible: a system description, functional specifications, supplier assessment material and test evidence for the platform. The validation itself, and the procedures around it, remain yours.
FAQ
21 CFR Part 11: common questions
Can software be 'Part 11 compliant'?
Not on its own. A product can provide the technical controls the rule requires; compliance depends on your validation, your procedures and how you operate it. A vendor claiming their product makes you compliant is overstating.
What is ALCOA+?
The data integrity expectations that sit alongside Part 11: Attributable, Legible, Contemporaneous, Original and Accurate, plus Complete, Consistent, Enduring and Available. Attributable is the one that rules out shared logins.
Related terms
- Business associate agreementA business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.
- Data processing addendumA data processing addendum is the contract between a controller and a processor governing how personal data is handled.
- eIDASeIDAS is the EU regulation establishing a framework for electronic identification and trust services.
- ESIGN ActThe ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.
- GDPRThe General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime.
- Golden threadThe golden thread is the requirement, introduced by the UK Building Safety Act 2022, to create and maintain accurate building safety information for higher-risk buildings throughout their life.
Last reviewed: 28 August 2026. Browse the full glossary.