21 CFR Part 11 establishes FDA criteria for trustworthy electronic records and signatures within its scope. Start with the record and its regulated use, then assess the system controls. A document-management product does not become compliant for every use because its website lists audit trails, electronic signatures or a “Part 11-ready” label.
For an EDMS assessment, establish the underlying record obligation, which version is relied on, how access is controlled and whether an electronic signature is being used. An electronic record can be in scope without an electronic signature. A scanned document can be the maintained regulated record. A cloud service can require a more careful control assessment than the words “public” or “private” convey.
This guide preserves the distinction between binding regulation, FDA guidance and suggested assessment methods. It focuses on US pharmaceutical document workflows, with separate clinical and device scope reminders. Regulatory text and guidance revisions were checked on October 6, 2026. The matrices are practical assessment aids, not a certification of any organization or product.
Establish Part 11 applicability before buying features
Section 11.1 covers electronic records maintained under FDA record requirements and electronic records submitted under the Federal Food, Drug, and Cosmetic Act or Public Health Service Act, including submissions not specifically identified in a regulation. It also identifies exclusions, including paper records transmitted electronically and particular sector-specific records. Read the actual scope provision in current Part 11; an EDMS file extension does not decide the answer.
Use a record-level assessment before a system-level conclusion. Record the document class; process; responsible organization; underlying requirement; maintained original or true copy; electronic/paper reliance; submission use; signature purpose; repository; and unresolved facts. One application may hold regulated SOPs, ordinary business documents and convenience copies with different assessments.
For each class, answer these questions in order:
- What requires the record to be maintained or submitted, and by whom?
- Which record does the organization actually rely on when performing that activity?
- Is the electronic version that maintained or submitted record, a supporting component, or only a convenience copy?
- Does a specific exclusion or FDA enforcement policy affect the analysis?
- Is an electronic signature used as a legally binding equivalent, and what does it signify?
If the first two answers are unknown, the assessment is Unresolved. Do not select “not applicable” merely because the supplier cannot answer questions about the customer's process.
Apply the decision to different records
| Situation | Initial assessment | Fact or evidence needed |
|---|---|---|
| Electronic procedure maintained to meet an applicable drug-CGMP documentation requirement | In scope, subject to the specific applicability assessment | Identify the requirement, authoritative revision and maintained record |
| Team lunch invitation, with no FDA record or submission obligation in the stated use | Outside Part 11 for that stated use | Document why the content has no regulated-record role |
| Paper original retained and used; scan supplied only for convenience | Do not decide from “scan” alone | Confirm actual reliance, completeness of the paper record and whether the scan has acquired a regulated use |
| Paper original replaced by an electronic maintained copy | Assess the electronic record and copying process | Identify authority for the copy, preserved meaning and relevant metadata |
| Unsigned electronic record required by an applicable FDA rule | Record controls may apply without signature controls being triggered | Separate the record obligation from whether signing is required or used |
| Old electronic file imported into a new EDMS | No automatic age exemption | Assess current maintained use and system; file creation date is insufficient |
These are conditional applications of the scope analysis, not six universal classifications. FDA's August 2003 scope guidance discusses actual electronic reliance, paper/electronic arrangements and enforcement policy. In drug CGMP, FDA's December 2018 data-integrity guidance, Q9–Q10 addresses electronic copies and preservation of record meaning, including relevant metadata and static/dynamic characteristics.
Read the regulation and enforcement policy together
Part 11 remains in effect. FDA's 2003 guidance states specified enforcement discretion for validation, audit trails, record copying and retention, while continuing predicate-rule enforcement and other Part 11 controls. This is not a repeal, a blanket exemption or permission to make required records unreliable. Apply the policy to the actual situation rather than deleting whole control categories from a procurement checklist. See FDA's scope guidance, sections III.A and III.C.
Its legacy-system policy concerns systems operational before August 20, 1997, with qualifying past/current predicate compliance and documented fitness for intended use. It is not a blanket exemption for records created before that date. Changes and current compliance matter; “legacy” is not a substitute for the required assessment. See section III.C.3.
For the assessment below, retain two separate fields: regulatory provision and applicable interpretation/predicate basis. This prevents a reviewer from mistaking a recommendation for regulatory text, or a policy of discretion for proof that no assurance is needed.
Define the system boundary: closed, open and cloud
The definitions in section 11.3 turn on whether system access is controlled by the people responsible for the electronic-record content. Hosting location alone is insufficient. An electronic signature is a legally meaningful signing act; a digital signature is a cryptographic type of electronic signature. A typed name in ordinary correspondence is not automatically the same workflow. See Part 11 definitions.
For a proposed SaaS EDMS, identify who grants access, who removes it, how supplier support access works, which external parties can enter, and which controls protect transfers. A service agreement documents responsibilities; it does not prove that access actually follows those responsibilities.
For open systems, section 11.30 calls for applicable section 11.10 controls and additional measures as necessary to protect authenticity, integrity and appropriate confidentiality. It gives encryption and suitable digital-signature standards as examples. Do not turn that conditional language into a universal claim that every cloud document must carry a digital signature.
Document the boundary of the workflow being assessed. A controlled internal repository and its external transfer route may need different analyses. If the supplier's privileged access or an external recipient's role is unclear, leave the affected assessment unresolved and obtain the missing control description.
Map electronic-record controls to evidence
The following matrix groups section 11.10(a)–(k) for a closed-system EDMS assessment. The provision column summarizes regulatory subjects. The evidence column is a suggested way to investigate the configured use; it is not a claim that the regulation mandates a particular screenshot, report name or software architecture. Apply the enforcement-policy and predicate analysis above.
| Provision and control subject | Suggested EDMS evidence | Negative or unresolved case |
|---|---|---|
| 11.10(a): fitness and reliable intended operation | Approved intended use, risk rationale and executed requirement-linked checks | Supplier brochure supplied instead of evidence for the configured workflow |
| 11.10(b): accurate, complete readable/electronic copies | Reconcile a record export to source content and required context | PDF opens but required history or signature information is absent |
| 11.10(c): protected retrieval over retention | Retention mapping, retrieval demonstration and recovery evidence | Backup job succeeds but a retained revision cannot be retrieved |
| 11.10(d), (g): authorized access and actions | Role assignments plus denied-user and wrong-role execution checks | Removed user remains able to approve through an active session |
| 11.10(e): secure history of record changes | Inspect create/change/delete history and preservation of earlier information | A meaningful change leaves no reconstructable trace |
| 11.10(f): appropriate sequence controls | Challenge the specified review/approval transition rules | A later revision inherits approval contrary to the approved process |
| 11.10(h): appropriate source/device checks | Identify relevant inputs and challenge an unauthorized source | Interface can write records without the intended source verification |
| 11.10(i), (j): personnel suitability and signing accountability | Role competence evidence and applicable written accountability policy | Signing access assigned before identity/role preparation is established |
| 11.10(k): controlled system documentation | Approved procedures/configuration documentation and change history | Operators rely on instructions for a superseded workflow |
Turn each applicable row into an assessment record with record class, trigger, authority, interpretation, requirement, configuration, owner, evidence ID, result and gap disposition. Keep Pass, Fail, Unresolved and justified Not applicable distinct. A document listing planned tests is not execution evidence. A successful demonstration as an administrator does not establish what an ordinary approver can do.
Ask the process owner to identify what would make the record untrustworthy, then choose representative challenges. For example, a disabled approver should not retain authority simply because their browser remains open. A copied SOP should not appear to carry approval for a different revision. These are concrete acceptance scenarios to investigate, not reported defects in any named product.
Assess signatures separately from login
Signature controls span Subpart B and Subpart C. Sections 11.50 and 11.70 address manifestations and record linkage; sections 11.100, 11.200 and 11.300 address general signing requirements, components and credential controls. An EDMS login test does not cover all of them.
For signature manifestations, inspect the signer's printed name, signing time/date and meaning in the human-readable record. For linkage, challenge whether a signature can be moved to falsify a different record. Preserve the exact revision being signed. These checks derive from sections 11.50 and 11.70; they do not require that every later authorized revision erase the prior signed version.
Non-biometric and biometric signing have different conditions
Section 11.200 distinguishes the following situations. “Components” does not mean that a screenshot containing two text boxes establishes compliance.
| Signing situation | Component rule to assess | Useful challenge |
|---|---|---|
| First non-biometric signing in a continuous period of controlled access | All required signature components, with at least two distinct identification components in the design | Sign after authentication and verify what actually constitutes the signing act |
| Subsequent signing in that same controlled period | At least one component executable only by the individual | Confirm session continuity and that another person cannot reuse the signing action |
| Signing outside one continuous controlled period | All components for each signing | End the controlled session, then attempt another signature |
| Biometric signing | Design ensures use only by the genuine owner | Evaluate the biometric signing implementation; do not apply the non-biometric component table blindly |
Single sign-on, multifactor authentication and signature-component design are related but different questions. Establish what the identity provider, application and signing workflow each do. If session continuity cannot be demonstrated, the reduced subsequent-signing path is not established. Ask for the intended control design and execution evidence instead of assuming any SSO product makes the answer yes or no.
Section 11.300 addresses code/password uniqueness, maintenance, compromised credentials, safeguards and relevant device checks. It does not supply a universal password-expiry day count. For procurement, have the supplier show the implemented policy, revocation path and alerts relevant to the proposed use. Include a lost-token or departed-user scenario; successful enrollment alone is incomplete evidence.
Identity and certification are organizational work
Section 11.100 requires individual uniqueness, no signature reuse or reassignment, and identity verification before electronic-signature assignment, along with certification of legally binding intent before or at use. Current paragraph (c)(1) permits the traditionally hand-signed certification to be submitted electronically or on paper. The certification is not FDA product approval. See current section 11.100 within Part 11.
FDA's current ESG NextGen non-repudiation-letter instructions describe electronic generation/upload through the Unified Submission Portal for registration and make physical mailing optional. They distinguish individual and company-wide letters and specify additional arrangements for agents/CROs. Those are current gateway instructions; do not infer that every internal EDMS implementation must create an ESG account. Follow the applicable FDA instructions for the certification and retain its scope and submission evidence.
The assessment owner should be able to answer which people/legal entity are covered, where the certification evidence is held and how the organization verifies signers. A vendor's assertion that its software supports electronic signatures does not establish those customer actions.
Audit trails, review frequency and record integrity
The text of 11.10(e) specifies secure, computer-generated, timestamped history, preservation of earlier information and trail retention at least as long as the subject records. Read it with the enforcement-policy analysis above.
For an EDMS, inspect a real sequence in the proposed configuration: draft creation, content change, rejection, resubmission, approval and supersession. Identify the required history at each stage. Establish whether earlier information remains available and whether exported evidence retains enough context to understand the sequence.
Do not confuse a file activity feed with the evidence needed for the regulated record. A log saying “updated” may be inadequate for a particular requirement even if it is technically an audit event. Conversely, Part 11 does not prescribe one named database technology or a universal write-once storage product. Define the required result and assess the protection and reconstruction controls.
In drug CGMP, FDA's December 2018 data-integrity guidance, Q7–Q8, connects audit-trail review to review of the associated records. Where CGMP specifies the data-review frequency, apply that frequency; otherwise determine an appropriate approach using process knowledge and risk. A universal monthly schedule is not the guidance's rule. Q1 also explains the importance of data and associated metadata. See the FDA guidance.
For your SOP workflow, record who reviews which history, when that review occurs, what exceptions are escalated and where the review evidence is kept. Do not borrow a laboratory-data schedule without establishing that it fits the document process. For a more focused discussion, use our audit-trail guide.
Integrity is a lifecycle question: can the organization understand who acted, what record they acted on and how the record reached its current state? A beautiful exported PDF may answer none of those questions if required context is missing. Evaluate both routine use and later retrieval after staff, software or service arrangements change.
Worked assessment: one EDMS, three document uses
Fictional Harbor Pharma is evaluating an EDMS. It proposes to maintain production SOPs electronically, keep courtesy scans of certain paper-held records and store ordinary internal announcements. The examples below illustrate assessment logic, not a completed compliance determination for a real company.
For the SOP workflow, Harbor identifies the applicable written-procedure obligation and the maintained electronic revision. 21 CFR 211.100 is a relevant starting point for production/process-control procedures within its scope. Harbor separately documents its approval process and how the electronic signatures implement it.
| Assessment row | Worked input/evidence | Disposition |
|---|---|---|
| Scope: production SOP | Named procedure requirement; EDMS is the maintained record; electronic approval intended as signing | Proceed with applicable record and signature controls |
| Access/authority | Proposed ordinary approver can sign; disabled approver is denied; role configuration retained | Pass for those tested conditions, subject to the broader assessment |
| Signature manifestation | On-screen record has name/time/meaning, but the human-readable export omits meaning | Fail this acceptance check; correction and retest required |
| Courtesy scan | Team cannot establish whether operations rely on the scan or the retained paper | Unresolved; obtain the process owner's evidence before assigning scope |
| Internal lunch notice | No FDA record/submission obligation or regulated-record role identified in the stated use | Not applicable for that use, with rationale retained |
The decision is to hold acceptance of the proposed SOP signing/export use until the failed check is resolved. Passing access tests do not compensate for the missing manifestation. The ambiguous scan receives an owner and a specific question, not a convenient exemption.
Extend Harbor's access check across time. In this fictional exercise, approver A17 signs SOP-9 revision 2 while authorized. The access owner then removes A17's approval role under the approved procedure, while the same browser session remains open. A17 attempts to sign revision 3. The expected result is denial of the new signing action, with the earlier legitimate revision-2 signature still attributable and retrievable. Removing authority must not erase historical attribution or reassign the earlier signature to A17's replacement.
Record the role-change evidence, the action time, the active-session result and the retained historical signature. A denied fresh login alone leaves the existing-session boundary untested. If revision 3 is actually signed after the authority was removed, record Fail and investigate that authorization path; if nobody exercised it, record Unresolved. Repeat the affected path after correction and retain the original evidence. The timing and role-removal rule come from Harbor's stated design, rather than an invented universal session timeout in Part 11.
Now change one fact: Harbor decides to discard the paper originals and maintain the scans as the required records. The former “courtesy” label no longer supports the assessment. Harbor must reassess the electronic copy, preserved content/context, access, retention and applicable record controls before relying on that new arrangement. A statement in an old inventory cannot override actual use.
Change a different fact: the supplier demonstrates a biometric signature instead of Harbor's proposed non-biometric signing flow. That demonstration does not pass the planned non-biometric session checks. Update the design and applicable requirements if Harbor chooses the new method, or obtain evidence for the method it actually intends to deploy.
Complete the assessment and maintain its boundaries
Use one final record to consolidate the control evidence:
| Field | What the assessor records |
|---|---|
| Scope | Record classes, predicate/submission basis, actual reliance and exclusions |
| System boundary | Named application/configuration, integrations, access-control responsibilities and transfer routes |
| Signatures | Signing purpose, method, identity/accountability process and certification evidence |
| Control evidence | Applicable matrix rows linked to actual checks, policies and retained outputs |
| Exceptions | Enforcement-policy analysis, justified non-applicability and unresolved questions |
| Gaps | Impact, immediate control, owner, deadline, correction and verification |
| Decision | Accepted scope, restricted scope or hold; reviewer/authority and date |
| Reassessment triggers | Changed use, workflow, access model, signing design, migration or supplier service |
For an existing system with gaps, distinguish immediate protection of records from the longer remediation plan. Do not promise that any compensating procedure is automatically FDA-acceptable. Assess whether it addresses the actual requirement and risk, then retain the rationale and evidence. An unresolved ability to alter approvals is different from a missing hyperlink in user help.
Validation should address the configured intended use, including procedures and interfaces. GAMP terminology or IQ/OQ/PQ document names can organize work but do not themselves determine Part 11 applicability or prove the controls. Our computerized-system-validation guide follows that lifecycle in more detail.
Keep clinical and device contexts explicit. FDA's October 2024, Revision 1 clinical electronic-systems guidance addresses clinical investigations. The February 3, 2026 CSA guidance addresses medical-device production/quality-management software. Neither makes a general pharmaceutical EDMS automatically exempt from applicable record requirements.
When comparing suppliers, ask them to populate the evidence gaps for your configuration. Keep organizational duties, record ownership and acceptance decisions visible. For an Assyro workflow discussion, bring the same assessment used for other suppliers; an article, demonstration or software feature list cannot certify your overall compliance.
About the author
Assyro Team
Expert regulatory operations consultants helping pharmaceutical companies navigate complex compliance challenges.

