QAreMed
MenuClose

Standard

FDA 21 CFR Part 11 validation testing

Part 11 never decides whether a record must be kept. A predicate rule does that, and Part 11 then sets the conditions under which that record may exist electronically and be signed electronically. Validation testing under 11.10(a) shows the system is accurate, reliable, consistent in its intended performance, and able to discern invalid or altered records.

Issued by
U.S. Food and Drug Administration
Edition
Codified regulation in force. Final rule 62 FR 13464 of 20 March 1997, effective 20 August 1997, most recently amended by 88 FR 13018 of 2 March 2023.
Applies in
United States
Source
Publisher catalogue entry, checked 2 September 2026

What does Part 11 require you to do?

By itself, nothing. Part 11 never rules that a record has to exist. section 11.1(b) applies the part to records in electronic form that are "created, modified, maintained, archived, retrieved, or transmitted under any records requirements set forth in agency regulations", and to electronic records submitted to FDA under the Federal Food, Drug, and Cosmetic Act and the Public Health Service Act. Another regulation makes the record mandatory. Part 11 then sets the conditions under which the electronic version of it counts, which section 11.1(a) frames as the criteria for treating electronic records and signatures as "trustworthy, reliable, and generally equivalent" to paper.

FDA calls that other regulation a predicate rule. The term appears nowhere in the regulation and is not among the nine terms defined at section 11.3(b); it comes from the 2003 Scope and Application guidance, which defines predicate rules as "the underlying requirements set forth in the Act, PHS Act, and FDA regulations (other than part 11)". Footnote 3 of that guidance names three of them: 21 CFR Part 211 for current good manufacturing practice, 21 CFR Part 820 for the quality system regulation, and 21 CFR Part 58 for good laboratory practice.

That mechanism decides what you are buying. A record you keep electronically because it suits you, and that no predicate rule obliges you to retain, is not a Part 11 record; the 2003 guidance says so in terms. A validation programme scoped without that question answered spends the same effort on a document store as on the system holding the records a regulator will actually ask for.

Every requirement Part 11 makes sits in three subparts, and the numbering inside them is sparse on purpose: there is no 11.20, no 11.40 and no 11.60.

Sections of 21 CFR Part 11, from 11.1 Scope to 11.300 controls for identification codes and passwords, with the subject of each.
SectionSubject
11.1Scope
11.2Implementation
11.3Definitions
11.10Controls for closed systems
11.30Controls for open systems
11.50Signature manifestations
11.70Signature/record linking
11.100General requirements for electronic signatures
11.200Electronic signature components and controls
11.300Controls for identification codes/passwords

Whether a system answers to section 11.10 or additionally to section 11.30 turns on the definitions at 11.3(b)(4) and 11.3(b)(9), which separate closed from open systems by who controls access and by nothing else.

One section bites earlier than the rest for a company planning a submission. section 11.2(b) permits electronic records in place of paper for submitted documents only where the requirements of the part are met and the document type has been identified in public docket No. 92S-0251 as one the agency accepts electronically. A document sent to a receiving unit not named in that docket is not considered official in electronic form.

Which parts of Part 11 does FDA say it will enforce?

FDA narrowed the part in 2003 and named the sections it would leave alone. The guidance is "Part 11, Electronic Records; Electronic Signatures, Scope and Application", a final guidance under docket FDA-2003-D-0143. Its cover page dates it August 2003, and FDA's guidance catalogue records the issue date as September 2003.

It rests on three stated elements: the part will be interpreted narrowly so fewer records fall under it; for records that remain, FDA intends to exercise enforcement discretion over the requirements for validation, audit trails, record retention and record copying, and over all of Part 11 for systems operational before the effective date; and, in FDA's own sentence, "We will enforce all predicate rule requirements, including predicate rule record and recordkeeping requirements."

FDA's 2003 enforcement position on each 21 CFR Part 11 requirement, set against the predicate rule or section text that still binds.
RequirementFDA's 2003 positionWhat still binds
11.10(a), validationdiscretionpredicate rule validation requirements, for example 21 CFR 820.70(i)
11.10(b), copies of recordsdiscretioninspection of all records under predicate rules, for example 211.180(c) and (d)
11.10(c), protection and retrievaldiscretionpredicate rule retention and availability, for example 211.180(c) and (d), 108.25(g), 108.35(h)
11.10(e) and 11.10(k)(2), audit trailsdiscretionpredicate rule documentation of date, time or sequencing, for example 58.130(e), and any requirement that changes do not obscure previous entries
11.10(d), (f), (g), (h), (i), (j), (k)enforcedthe section text as written
11.30, open systemsenforced, apart from the correspondences abovethe section text as written
11.50, 11.70, 11.100, 11.200, 11.300enforcedthe section text as written
any system operational before 20 August 1997discretion over all Part 11 requirements, on four conditionspredicate rules, then and now

FDA's 2003 guidance withdraws no part of the regulation: each requirement placed under enforcement discretion is replaced by a predicate rule requirement rather than removed.

The legacy carve-out is the narrowest entry on that table, because all four of its conditions have to hold for the specific system: it was operational before 20 August 1997; it met all applicable predicate rule requirements before that date; it meets all applicable predicate rule requirements now; and you hold documented evidence and justification that it is fit for its intended use, including an acceptable level of record security and integrity where that applies. A change made since 1997 that would stop the system meeting a predicate rule puts Part 11 controls back on its records and signatures.

Two limits sit inside the same guidance. It states that "part 11 remains in effect and that this exercise of enforcement discretion applies only as identified in this guidance", and it repeats FDA's standard position that a guidance establishes no legally enforceable responsibility and that "should" means recommended. section 11.1(e) is untouched by any of it: computer systems, controls and attendant documentation maintained under the part are readily available for, and subject to, FDA inspection.

The common misreading is that discretion over 11.10(a) removes validation. It moves the citation. The depth of the work becomes a risk based judgement you have to justify and document, which is the direction computer software assurance takes further, and it is the variable behind most of the spread in what FDA software validation costs.

What does validation testing have to demonstrate?

section 11.10(a) is one sentence: "Validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records." The regulation names no method, no document set, no test types and no lifecycle model. The fourth objective is the one that reshapes a test plan, because a suite that only proves the features work has not touched it.

section 11.10 opens by requiring procedures and controls designed to ensure authenticity, integrity and, when appropriate, confidentiality of electronic records, and to ensure that a signer cannot readily repudiate the signed record as not genuine. Eleven lettered controls follow, and each one turns into something a test has to show.

Controls 11.10(a) to 11.10(k) of 21 CFR Part 11, with what validation testing has to demonstrate for each one.
SectionWhat the test has to demonstrate
11.10(a)An altered or invalid record is discerned by the system, rather than only that valid input is accepted
11.10(b)A copy exports in human readable and in electronic form, and the copy carries the same content and meaning as the original
11.10(c)A record restored from archive is retrieved accurately and readily at the far end of its retention period
11.10(d)An unauthorised individual is refused system access
11.10(e)Entries and actions that create, modify or delete a record are recorded with date and time, independently of the operator, and the previous value stays readable
11.10(f)A step attempted out of the permitted sequence is refused
11.10(g)Each of the five privileges is checked separately: use the system, sign a record, access an input or output device, alter a record, perform the operation at hand
11.10(h)Input arriving from an unexpected device or source is rejected as invalid
11.10(i)Developers, maintainers and users hold the education, training and experience for their assigned tasks, with records to show it
11.10(j)The accountability policy exists and people follow it, since the section requires establishment and adherence
11.10(k)(1) and (k)(2)Access to system documentation is controlled, and its revisions are recorded in time sequence

A Part 11 suite is mostly negative testing, and 11.10(g) is where that shows. Confirming that an authorised user can sign is one test. The section names five privileges, so the suite also needs a user who can open the record and is refused the signature, and a user who can sign and is refused the change to a locked field.

What an audit trail test has to do

  1. Create a record as one user.
  2. Change one field as a second user.
  3. Open the trail. Confirm the date, the time and the acting operator for both actions.
  4. Confirm the previous value is still readable after the change.
  5. Delete the record. Confirm the trail keeps the deletion entry.
  6. Read the recorded time against the time zone reference the system documentation states.
  7. Export the trail. Compare its retention setting against the retention period of the subject record.

Step 7 is the one that fails in practice. section 11.10(e) requires the audit trail documentation to be retained for at least as long as the subject records and to be available for agency review and copying, and trails are frequently rotated on a database schedule that nobody mapped to a retention rule. Testing an audit trail covers the evidence each of those steps has to leave behind.

What does a signature have to carry?

Three items, named at section 11.50(a): the printed name of the signer, the date and time the signature was executed, and the meaning associated with the signature, such as review, approval, responsibility or authorship. Under 11.50(b) all three are subject to the same controls as the record itself and have to appear in any human readable form of it, on screen and on the printout.

section 11.70 then requires the signature to be linked to its record so that it cannot be excised, copied or otherwise transferred to falsify a record "by ordinary means". The standard is ordinary means rather than absolute cryptographic proof, which is why the test is an attempt to move a signature between two records through the application and through its exports.

Subpart C sets the credential itself. section 11.100(a) requires each electronic signature to be unique to one individual and never reused or reassigned. section 11.100(b) requires the organisation to verify the individual's identity before it assigns or sanctions the signature. section 11.100(c) requires a certification to FDA, signed with a traditional handwritten signature, that the electronic signatures in the system are intended to be the legally binding equivalent of handwritten ones; the 2023 amendment replaced the printed mailing address in 11.100(c)(1) with a pointer to FDA's web page on Letters of Non-Repudiation Agreement.

section 11.200(a) requires a signature not based on biometrics to employ at least two distinct identification components, an identification code and a password being the example in the text. Within a single continuous period of controlled system access the first signing uses all components and later signings use at least one component executable only by that individual; signings outside such a period each use all components. A signature based on biometrics is exempt from the two component rule under 11.200(b), and the definition at 11.3(b)(3) reaches repeatable actions as well as physical features.

section 11.300 adds five controls where the signature is an identification code combined with a password, and 11.300(e) is the unusual one: it requires initial and periodic testing of tokens or cards that bear or generate identification code or password information, to confirm they still function and have not been altered without authorisation. That is a recurring testing obligation written into the regulation itself, and the 2003 guidance places no discretion over it. Electronic signature testing under Part 11 sets out the cases for the session rule and for the linking requirement.

Which artefacts will an FDA investigator ask for?

section 11.1(e) answers that at the top level: the computer systems including hardware and software, the controls, and the attendant documentation have to be readily available for and subject to inspection. Nothing in the 2003 guidance narrows that section.

For clinical investigations FDA published a more specific list, and what a trial platform has to prove about its records and its signatures is built around it. The guidance "Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers" is final, dated October 2024, docket FDA-2017-D-1105, and it expands on the 2003 guidance rather than replacing it, stating that FDA continues to apply a narrow and practical interpretation of Part 11. Question 8 names what an inspection of the sponsor looks at, including the data collection, handling, security and management plans; the life cycle of the system from design through decommissioning; the procedures that keep the records needed to reconstruct the investigation unaltered in value or meaning, including during transfer to a durable repository; the procedures that give appropriate access only to authorised individuals; the change control procedures and the changes actually made; the contracts with IT service providers setting out their functions and responsibilities; and the corrective and preventive actions taken on errors affecting data integrity or participant protection.

Question 9 covers an inspection of the clinical investigator and asks for the training records of the staff who use the system, the procedures and controls for system access and for data creation, modification and maintenance, evidence that users hold their own accounts, evidence that sponsors are told when personnel change so that access rights can be revoked, and any use of backup, recovery or contingency plans for source records.

Where the system is operated by a vendor, that guidance still puts the documentation obligation on the regulated entity, and recommends reviewing the provider's development and management processes, validation processes, functional testing and change control tracking logs. If the same system holds PHI, the vendor relationship needs a business associate agreement as well, which is a separate instrument from the validation evidence and a separate negotiation, raised at how we work with protected health information.

Where do Part 11 findings come from?

  • No record of which records on the system are Part 11 records, and no predicate rule cited against any of them, so the scope of validation cannot be defended.
  • The audit trail logs the change and overwrites the previous value, which 11.10(e) forbids in the same sentence that requires the trail.
  • Authority checks are tested as login only, and no test exists for a user who can read a record and has to be refused the signature under 11.10(g).
  • The signature block on the printout shows a user identifier and a timestamp with no meaning of the signing, so 11.50(a)(3) is missing from the human readable form.
  • Password ageing is configured in the system, and no record exists of the periodic check, recall or revision of issuances that 11.300(b) asks for.
  • Tokens are tested once at issue, against an 11.300(e) obligation that is initial and periodic.
  • The 11.100(c) certification is never sent, or is sent and no copy can be produced during the inspection.
  • System documentation is version controlled in a wiki with no time sequenced record of its development and modification, which is what 11.10(k)(2) requires.
  • The vendor holds the only validation package, and the sponsor cannot produce it on the day of the inspection.

What do we run against Part 11?

We start from the scope question, because it decides everything downstream: which records the predicate rules require, whether you rely on the electronic or the paper version of each, and which systems therefore carry Part 11 controls. From that list the test suite is built section by section across 11.10, 11.30 and subpart C, weighted towards the refusals rather than the accepted paths, with the evidence recorded in the artefact set above.

What that produces is an inspection file: the validation package tied to the four objectives of 11.10(a), the negative test results behind the authority and device checks, the audit trail and signature evidence, and the traceability that lets an investigator move from a section to the test that covered it. The regulatory position stays with the organisation that holds the records. The work is described in FDA software validation, and the record side of it in validation documentation.

Section numbers and quoted text on this page were checked against the eCFR text of 21 CFR Part 11, current as of 31 August 2026, and against the 2003 Scope and Application guidance and the October 2024 clinical investigations questions and answers.

What do you receive?

Part 11 record scope decision, per predicate rule
Shows an investigator which records on the system are Part 11 records, which predicate rule requires each one, and whether you rely on the electronic record or on a paper printout
Validation package against the four objectives of 11.10(a)
Lets an investigator trace each of accuracy, reliability, consistent intended performance and the detection of altered records to the test that exercised it
Record copy demonstration in human readable and electronic form
Lets an investigator take away an accurate and complete copy under 11.10(b) and confirm the copy preserves the content and meaning of the original
Audit trail test evidence with the retention setting attached
Shows the trail is computer generated and time stamped, that a change does not obscure the previous value, and that the trail is retained for at least as long as the records it covers under 11.10(e)
Authority check matrix, role against privilege
Lets an investigator pick one role and see which of the five privileges named in 11.10(g) it holds and which negative test proved the refusal
Signature manifestation and linking evidence
Shows the printed name, the date and time and the meaning of the signing appear in the human readable record under 11.50, and that a signature cannot be moved to another record by ordinary means under 11.70
Identification code and password control records
Covers the five controls in 11.300, including the initial and periodic testing of tokens or cards that 11.300(e) requires on a recurring basis
Systems documentation change control log
Answers 11.10(k)(2) with a time sequenced record of how the system documentation itself was developed and modified

What do buyers ask about this?

Does Part 11 apply if we print everything to paper?
Not if the printout satisfies every applicable predicate rule requirement and you actually rely on the paper to perform the regulated activity. The 2003 guidance states that using computers to generate such printouts would not trigger Part 11. Business practice overrides stated intent, so where staff work from the screen rather than from the printout, FDA may treat the electronic record as the one in use.
FDA said it would not enforce 11.10(a). Do we still have to validate?
Yes, under a different citation. The 2003 guidance places 11.10(a) under enforcement discretion and says in the same passage that persons must still comply with all applicable predicate rule requirements for validation, naming 21 CFR 820.70(i) as an example. What changes is that the extent of validation becomes a risk based decision you justify and document rather than a fixed list read off Part 11.
Is a cloud hosted system an open system under Part 11?
That turns on who controls access. 11.3(b)(4) defines a closed system as one where system access is controlled by the persons responsible for the content of the records, and 11.3(b)(9) defines an open system as one where it is not. Hosting, internet exposure and tenancy are absent from both definitions. Where the system is open, 11.30 adds document encryption and appropriate digital signature standards from the point of record creation to the point of receipt.
Our SaaS vendor validated the system. Is that enough for an inspection?
FDA may request documentation of system validation during an inspection, and the 2024 clinical investigations guidance puts the responsibility for making it available on the regulated entity, including documentation created and maintained by the IT service provider. That guidance suggests reviewing the provider's processes for developing and managing the system, its validation processes, its functional testing and its change control procedures and tracking logs.

Which product types does this apply to?

Which of our services test it?

What does validating your product actually involve?

Answer four questions about your markets, your product type and its integrations. You get the standards that reach you, the artefacts each one asks you to produce, and which of them a test supplier delivers.