Skip to content
Assyro AI
21 CFR Part 11 Compliance: EDMS Applicability and Evidence
21 cfr part 11
21 cfr part 11 compliance
electronic records electronic signatures

21 CFR Part 11 Compliance: EDMS Applicability and Evidence

Guide

Determine which EDMS records fall under 21 CFR Part 11, then map record, access and signature controls to evidence. Includes boundary cases and a practical assessment matrix.

Assyro Team
16 min read

21 CFR Part 11 establishes FDA criteria for trustworthy electronic records and signatures within its scope. Start with the record and its regulated use, then assess the system controls. A document-management product does not become compliant for every use because its website lists audit trails, electronic signatures or a “Part 11-ready” label.

For an EDMS assessment, establish the underlying record obligation, which version is relied on, how access is controlled and whether an electronic signature is being used. An electronic record can be in scope without an electronic signature. A scanned document can be the maintained regulated record. A cloud service can require a more careful control assessment than the words “public” or “private” convey.

This guide preserves the distinction between binding regulation, FDA guidance and suggested assessment methods. It focuses on US pharmaceutical document workflows, with separate clinical and device scope reminders. Regulatory text and guidance revisions were checked on October 6, 2026. The matrices are practical assessment aids, not a certification of any organization or product.

Establish Part 11 applicability before buying features

Section 11.1 covers electronic records maintained under FDA record requirements and electronic records submitted under the Federal Food, Drug, and Cosmetic Act or Public Health Service Act, including submissions not specifically identified in a regulation. It also identifies exclusions, including paper records transmitted electronically and particular sector-specific records. Read the actual scope provision in current Part 11; an EDMS file extension does not decide the answer.

Use a record-level assessment before a system-level conclusion. Record the document class; process; responsible organization; underlying requirement; maintained original or true copy; electronic/paper reliance; submission use; signature purpose; repository; and unresolved facts. One application may hold regulated SOPs, ordinary business documents and convenience copies with different assessments.

For each class, answer these questions in order:

  1. What requires the record to be maintained or submitted, and by whom?
  2. Which record does the organization actually rely on when performing that activity?
  3. Is the electronic version that maintained or submitted record, a supporting component, or only a convenience copy?
  4. Does a specific exclusion or FDA enforcement policy affect the analysis?
  5. Is an electronic signature used as a legally binding equivalent, and what does it signify?

If the first two answers are unknown, the assessment is Unresolved. Do not select “not applicable” merely because the supplier cannot answer questions about the customer's process.

Apply the decision to different records

Comparison table with columns Situation, Initial assessment, Fact or evidence needed
SituationInitial assessmentFact or evidence needed
Electronic procedure maintained to meet an applicable drug-CGMP documentation requirementIn scope, subject to the specific applicability assessmentIdentify the requirement, authoritative revision and maintained record
Team lunch invitation, with no FDA record or submission obligation in the stated useOutside Part 11 for that stated useDocument why the content has no regulated-record role
Paper original retained and used; scan supplied only for convenienceDo not decide from “scan” aloneConfirm actual reliance, completeness of the paper record and whether the scan has acquired a regulated use
Paper original replaced by an electronic maintained copyAssess the electronic record and copying processIdentify authority for the copy, preserved meaning and relevant metadata
Unsigned electronic record required by an applicable FDA ruleRecord controls may apply without signature controls being triggeredSeparate the record obligation from whether signing is required or used
Old electronic file imported into a new EDMSNo automatic age exemptionAssess current maintained use and system; file creation date is insufficient

These are conditional applications of the scope analysis, not six universal classifications. FDA's August 2003 scope guidance discusses actual electronic reliance, paper/electronic arrangements and enforcement policy. In drug CGMP, FDA's December 2018 data-integrity guidance, Q9–Q10 addresses electronic copies and preservation of record meaning, including relevant metadata and static/dynamic characteristics.

Read the regulation and enforcement policy together

Part 11 remains in effect. FDA's 2003 guidance states specified enforcement discretion for validation, audit trails, record copying and retention, while continuing predicate-rule enforcement and other Part 11 controls. This is not a repeal, a blanket exemption or permission to make required records unreliable. Apply the policy to the actual situation rather than deleting whole control categories from a procurement checklist. See FDA's scope guidance, sections III.A and III.C.

Its legacy-system policy concerns systems operational before August 20, 1997, with qualifying past/current predicate compliance and documented fitness for intended use. It is not a blanket exemption for records created before that date. Changes and current compliance matter; “legacy” is not a substitute for the required assessment. See section III.C.3.

For the assessment below, retain two separate fields: regulatory provision and applicable interpretation/predicate basis. This prevents a reviewer from mistaking a recommendation for regulatory text, or a policy of discretion for proof that no assurance is needed.

Define the system boundary: closed, open and cloud

The definitions in section 11.3 turn on whether system access is controlled by the people responsible for the electronic-record content. Hosting location alone is insufficient. An electronic signature is a legally meaningful signing act; a digital signature is a cryptographic type of electronic signature. A typed name in ordinary correspondence is not automatically the same workflow. See Part 11 definitions.

For a proposed SaaS EDMS, identify who grants access, who removes it, how supplier support access works, which external parties can enter, and which controls protect transfers. A service agreement documents responsibilities; it does not prove that access actually follows those responsibilities.

For open systems, section 11.30 calls for applicable section 11.10 controls and additional measures as necessary to protect authenticity, integrity and appropriate confidentiality. It gives encryption and suitable digital-signature standards as examples. Do not turn that conditional language into a universal claim that every cloud document must carry a digital signature.

Document the boundary of the workflow being assessed. A controlled internal repository and its external transfer route may need different analyses. If the supplier's privileged access or an external recipient's role is unclear, leave the affected assessment unresolved and obtain the missing control description.

Map electronic-record controls to evidence

The following matrix groups section 11.10(a)–(k) for a closed-system EDMS assessment. The provision column summarizes regulatory subjects. The evidence column is a suggested way to investigate the configured use; it is not a claim that the regulation mandates a particular screenshot, report name or software architecture. Apply the enforcement-policy and predicate analysis above.

Comparison table with columns Provision and control subject, Suggested EDMS evidence, Negative or unresolved case
Provision and control subjectSuggested EDMS evidenceNegative or unresolved case
11.10(a): fitness and reliable intended operationApproved intended use, risk rationale and executed requirement-linked checksSupplier brochure supplied instead of evidence for the configured workflow
11.10(b): accurate, complete readable/electronic copiesReconcile a record export to source content and required contextPDF opens but required history or signature information is absent
11.10(c): protected retrieval over retentionRetention mapping, retrieval demonstration and recovery evidenceBackup job succeeds but a retained revision cannot be retrieved
11.10(d), (g): authorized access and actionsRole assignments plus denied-user and wrong-role execution checksRemoved user remains able to approve through an active session
11.10(e): secure history of record changesInspect create/change/delete history and preservation of earlier informationA meaningful change leaves no reconstructable trace
11.10(f): appropriate sequence controlsChallenge the specified review/approval transition rulesA later revision inherits approval contrary to the approved process
11.10(h): appropriate source/device checksIdentify relevant inputs and challenge an unauthorized sourceInterface can write records without the intended source verification
11.10(i), (j): personnel suitability and signing accountabilityRole competence evidence and applicable written accountability policySigning access assigned before identity/role preparation is established
11.10(k): controlled system documentationApproved procedures/configuration documentation and change historyOperators rely on instructions for a superseded workflow

Turn each applicable row into an assessment record with record class, trigger, authority, interpretation, requirement, configuration, owner, evidence ID, result and gap disposition. Keep Pass, Fail, Unresolved and justified Not applicable distinct. A document listing planned tests is not execution evidence. A successful demonstration as an administrator does not establish what an ordinary approver can do.

Ask the process owner to identify what would make the record untrustworthy, then choose representative challenges. For example, a disabled approver should not retain authority simply because their browser remains open. A copied SOP should not appear to carry approval for a different revision. These are concrete acceptance scenarios to investigate, not reported defects in any named product.

Assess signatures separately from login

Signature controls span Subpart B and Subpart C. Sections 11.50 and 11.70 address manifestations and record linkage; sections 11.100, 11.200 and 11.300 address general signing requirements, components and credential controls. An EDMS login test does not cover all of them.

For signature manifestations, inspect the signer's printed name, signing time/date and meaning in the human-readable record. For linkage, challenge whether a signature can be moved to falsify a different record. Preserve the exact revision being signed. These checks derive from sections 11.50 and 11.70; they do not require that every later authorized revision erase the prior signed version.

Non-biometric and biometric signing have different conditions

Section 11.200 distinguishes the following situations. “Components” does not mean that a screenshot containing two text boxes establishes compliance.

Comparison table with columns Signing situation, Component rule to assess, Useful challenge
Signing situationComponent rule to assessUseful challenge
First non-biometric signing in a continuous period of controlled accessAll required signature components, with at least two distinct identification components in the designSign after authentication and verify what actually constitutes the signing act
Subsequent signing in that same controlled periodAt least one component executable only by the individualConfirm session continuity and that another person cannot reuse the signing action
Signing outside one continuous controlled periodAll components for each signingEnd the controlled session, then attempt another signature
Biometric signingDesign ensures use only by the genuine ownerEvaluate the biometric signing implementation; do not apply the non-biometric component table blindly

Single sign-on, multifactor authentication and signature-component design are related but different questions. Establish what the identity provider, application and signing workflow each do. If session continuity cannot be demonstrated, the reduced subsequent-signing path is not established. Ask for the intended control design and execution evidence instead of assuming any SSO product makes the answer yes or no.

Section 11.300 addresses code/password uniqueness, maintenance, compromised credentials, safeguards and relevant device checks. It does not supply a universal password-expiry day count. For procurement, have the supplier show the implemented policy, revocation path and alerts relevant to the proposed use. Include a lost-token or departed-user scenario; successful enrollment alone is incomplete evidence.

Identity and certification are organizational work

Section 11.100 requires individual uniqueness, no signature reuse or reassignment, and identity verification before electronic-signature assignment, along with certification of legally binding intent before or at use. Current paragraph (c)(1) permits the traditionally hand-signed certification to be submitted electronically or on paper. The certification is not FDA product approval. See current section 11.100 within Part 11.

FDA's current ESG NextGen non-repudiation-letter instructions describe electronic generation/upload through the Unified Submission Portal for registration and make physical mailing optional. They distinguish individual and company-wide letters and specify additional arrangements for agents/CROs. Those are current gateway instructions; do not infer that every internal EDMS implementation must create an ESG account. Follow the applicable FDA instructions for the certification and retain its scope and submission evidence.

The assessment owner should be able to answer which people/legal entity are covered, where the certification evidence is held and how the organization verifies signers. A vendor's assertion that its software supports electronic signatures does not establish those customer actions.

Audit trails, review frequency and record integrity

The text of 11.10(e) specifies secure, computer-generated, timestamped history, preservation of earlier information and trail retention at least as long as the subject records. Read it with the enforcement-policy analysis above.

For an EDMS, inspect a real sequence in the proposed configuration: draft creation, content change, rejection, resubmission, approval and supersession. Identify the required history at each stage. Establish whether earlier information remains available and whether exported evidence retains enough context to understand the sequence.

Do not confuse a file activity feed with the evidence needed for the regulated record. A log saying “updated” may be inadequate for a particular requirement even if it is technically an audit event. Conversely, Part 11 does not prescribe one named database technology or a universal write-once storage product. Define the required result and assess the protection and reconstruction controls.

In drug CGMP, FDA's December 2018 data-integrity guidance, Q7–Q8, connects audit-trail review to review of the associated records. Where CGMP specifies the data-review frequency, apply that frequency; otherwise determine an appropriate approach using process knowledge and risk. A universal monthly schedule is not the guidance's rule. Q1 also explains the importance of data and associated metadata. See the FDA guidance.

For your SOP workflow, record who reviews which history, when that review occurs, what exceptions are escalated and where the review evidence is kept. Do not borrow a laboratory-data schedule without establishing that it fits the document process. For a more focused discussion, use our audit-trail guide.

Integrity is a lifecycle question: can the organization understand who acted, what record they acted on and how the record reached its current state? A beautiful exported PDF may answer none of those questions if required context is missing. Evaluate both routine use and later retrieval after staff, software or service arrangements change.

Worked assessment: one EDMS, three document uses

Fictional Harbor Pharma is evaluating an EDMS. It proposes to maintain production SOPs electronically, keep courtesy scans of certain paper-held records and store ordinary internal announcements. The examples below illustrate assessment logic, not a completed compliance determination for a real company.

For the SOP workflow, Harbor identifies the applicable written-procedure obligation and the maintained electronic revision. 21 CFR 211.100 is a relevant starting point for production/process-control procedures within its scope. Harbor separately documents its approval process and how the electronic signatures implement it.

Comparison table with columns Assessment row, Worked input/evidence, Disposition
Assessment rowWorked input/evidenceDisposition
Scope: production SOPNamed procedure requirement; EDMS is the maintained record; electronic approval intended as signingProceed with applicable record and signature controls
Access/authorityProposed ordinary approver can sign; disabled approver is denied; role configuration retainedPass for those tested conditions, subject to the broader assessment
Signature manifestationOn-screen record has name/time/meaning, but the human-readable export omits meaningFail this acceptance check; correction and retest required
Courtesy scanTeam cannot establish whether operations rely on the scan or the retained paperUnresolved; obtain the process owner's evidence before assigning scope
Internal lunch noticeNo FDA record/submission obligation or regulated-record role identified in the stated useNot applicable for that use, with rationale retained

The decision is to hold acceptance of the proposed SOP signing/export use until the failed check is resolved. Passing access tests do not compensate for the missing manifestation. The ambiguous scan receives an owner and a specific question, not a convenient exemption.

Extend Harbor's access check across time. In this fictional exercise, approver A17 signs SOP-9 revision 2 while authorized. The access owner then removes A17's approval role under the approved procedure, while the same browser session remains open. A17 attempts to sign revision 3. The expected result is denial of the new signing action, with the earlier legitimate revision-2 signature still attributable and retrievable. Removing authority must not erase historical attribution or reassign the earlier signature to A17's replacement.

Record the role-change evidence, the action time, the active-session result and the retained historical signature. A denied fresh login alone leaves the existing-session boundary untested. If revision 3 is actually signed after the authority was removed, record Fail and investigate that authorization path; if nobody exercised it, record Unresolved. Repeat the affected path after correction and retain the original evidence. The timing and role-removal rule come from Harbor's stated design, rather than an invented universal session timeout in Part 11.

Now change one fact: Harbor decides to discard the paper originals and maintain the scans as the required records. The former “courtesy” label no longer supports the assessment. Harbor must reassess the electronic copy, preserved content/context, access, retention and applicable record controls before relying on that new arrangement. A statement in an old inventory cannot override actual use.

Change a different fact: the supplier demonstrates a biometric signature instead of Harbor's proposed non-biometric signing flow. That demonstration does not pass the planned non-biometric session checks. Update the design and applicable requirements if Harbor chooses the new method, or obtain evidence for the method it actually intends to deploy.

Complete the assessment and maintain its boundaries

Use one final record to consolidate the control evidence:

Comparison table with columns Field, What the assessor records
FieldWhat the assessor records
ScopeRecord classes, predicate/submission basis, actual reliance and exclusions
System boundaryNamed application/configuration, integrations, access-control responsibilities and transfer routes
SignaturesSigning purpose, method, identity/accountability process and certification evidence
Control evidenceApplicable matrix rows linked to actual checks, policies and retained outputs
ExceptionsEnforcement-policy analysis, justified non-applicability and unresolved questions
GapsImpact, immediate control, owner, deadline, correction and verification
DecisionAccepted scope, restricted scope or hold; reviewer/authority and date
Reassessment triggersChanged use, workflow, access model, signing design, migration or supplier service

For an existing system with gaps, distinguish immediate protection of records from the longer remediation plan. Do not promise that any compensating procedure is automatically FDA-acceptable. Assess whether it addresses the actual requirement and risk, then retain the rationale and evidence. An unresolved ability to alter approvals is different from a missing hyperlink in user help.

Validation should address the configured intended use, including procedures and interfaces. GAMP terminology or IQ/OQ/PQ document names can organize work but do not themselves determine Part 11 applicability or prove the controls. Our computerized-system-validation guide follows that lifecycle in more detail.

Keep clinical and device contexts explicit. FDA's October 2024, Revision 1 clinical electronic-systems guidance addresses clinical investigations. The February 3, 2026 CSA guidance addresses medical-device production/quality-management software. Neither makes a general pharmaceutical EDMS automatically exempt from applicable record requirements.

When comparing suppliers, ask them to populate the evidence gaps for your configuration. Keep organizational duties, record ownership and acceptance decisions visible. For an Assyro workflow discussion, bring the same assessment used for other suppliers; an article, demonstration or software feature list cannot certify your overall compliance.

About the author

Assyro Team

Expert regulatory operations consultants helping pharmaceutical companies navigate complex compliance challenges.

Related articles

Demos available this week