electronic records and signatures under 21 CFR Part 11 - sealed record - QFINITY
QFINITY · Service Areas · Electronic Records / Signatures

Electronic Records and Signatures.

In the GxP environment, electronic records replace paper-based documentation. Electronic signatures bind these records to a person, a point in time and a meaning - and wherever the regulations require a signature, they must carry the same evidentiary weight as a handwritten one. 21 CFR Part 11 and EU GMP Annex 11 define the requirements for both - records and signatures alike. QFINITY assesses your systems and records, determines where which signature is required - and delivers the controlled documents and training to match.

Electronic Records / Signatures

What do 21 CFR Part 11 and Annex 11 govern?

21 CFR Part 11 and EU GMP Annex 11 define the conditions under which electronic records and signatures carry the same standing as paper records and handwritten signatures.

Electronic records deliver accurate, traceable GxP documentation and make audits and inspections easier; electronic signatures bind them uniquely to a person. Together they are the mechanism that makes data integrity concrete.

GMP GLP GCP Electronic Records Electronic Signatures Data Integrity
Since 2003, the FDA has deliberately construed Part 11 narrowly: which records are relevant and which must carry a signature is determined by the underlying predicate rules - not by the technology.
Raw Data & Provenance

Which data belong in the record?

Raw data are a deliberate designation: out of everything available, the data needed to reconstruct and evaluate the quality-relevant results - defined with care and with restraint, because calculated values can replace thousands of individual readings without any loss of quality, provided the process is understood.

  • Provenance is part of the record

    The chain of input, processing and output determines where the raw data sit - differently in a chromatography system than in an MES or a clinical database. Without documented origin, no result can be reconstructed.

  • Decisions on data at rest

    The record comes into being with durable storage, at the time of the activity. Transient buffer and display values are not a record - quality-relevant decisions must not rely on them.

  • The same discipline for AI

    The draft of Annex 22 requires documented selection, documented pre-processing and justified exclusions for AI data - provenance discipline under a new name.

Electronic Signatures

What makes a valid signature.

In 21 CFR Part 11 and EU GMP Annex 11, an electronic signature is more than a click - it has to carry the same weight as a handwritten one. Four properties decide whether it is valid under the regulations - and together they deliver the ALCOA++ criteria Attributable and Traceable.

  • Uniquely linked to one person

    Every signature belongs to exactly one person, is non-transferable and non-reusable - this is what makes the record attributable.

  • Name, time and meaning

    The signature carries the signer's name, the date and time, and the meaning of the action - authored, reviewed or approved.

  • Permanently bound to the record

    The signature is linked to the record such that it cannot be copied, removed or transferred to another record.

  • Non-repudiable

    Non-repudiation: the signer cannot later deny having signed - the basis of its legal weight.

Signature types & requirements

Use the right signature type in the right way.

Once a rule requires a signature, the question becomes one of form: which type fits depends on criticality and regulatory requirements - underpinned by the demands on authentication, integrity and traceability.

  • Handwritten or electronic

    A handwritten signature on an electronic record (hybrid) or a fully electronic signature - the transition has to be controlled to an equivalent standard.

  • Biometric or ID plus password

    Non-biometric signatures rely on at least two components such as a user ID and password; biometric ones on a unique physical trait.

  • Closed or open system

    In closed systems the record owners control access; open systems require additional measures such as encryption and digital signatures.

  • Audit trail

    Every change to the record's data stays fully traceable - the signature makes it defensible and attributable to a person.

Signature Requirements

When is an electronic signature actually required?

Only where a governing rule requires a signature or an approval: Part 11 and Annex 11 themselves do not require a single signature - they define the electronic form of what GxP rules such as 21 CFR 211 or Chapter 4 of the EU GMP Guide demand. And those rules grade the requirement deliberately:

LevelUS (predicate rules)EU
Approval / releaseApproval by the quality unitInstructions and specifications approved, signed and dated; batch certification by the QP - electronically signed in the system
Full signatureMaster and batch records: dated and fully signedBatch processing record: date and signature
Initials / countersigningEquipment log: initials or signatureAlteration of an entry: initialed and dated
Identification onlyPerson performing and checking each stepe.g. maintenance: date and name of the person
From Practice

Frequent questions about records and signatures.

Four questions decide scope and effort in practice:

Only if it reproduces the record in full. For dynamic records - chromatography data, for instance, which can be reprocessed and re-evaluated - the static copy is incomplete: the electronic original with its metadata and audit trail remains the record. The printout is then a working copy, not a substitute.

For as long as the GxP regulations require - the retention period comes from those rules, not from Part 11 or Annex 11. What matters is the form: throughout the entire period, the records must remain readable, evaluable and protected - system retirements and archiving need to be designed for that before they happen.

The key question before any signature requirement: a technical confirmation needs identification and an audit trail - only a regulatorily required signature needs the full signature apparatus. Treating the two as equal pulls records into the scope of Part 11 without need; and FDA's 2003 enforcement discretion covers a lot, but explicitly not the signature requirements.

In day-to-day GxP work, practically never: GxP signatures are internal signatures between employee and company, not contract signatures. The qualified signature and its trust service remain reserved for cases where the law demands the written form.

What We Deliver

What we handle for you.

Electronic records and signatures only hold up when process, technology and controlled documents line up. Four service phases lead from the initial assessment to organization-wide adoption - also available individually, for instance as a focused assessment ahead of an inspection or as remediation after a deficiency.

  1. 1

    Analysis

    We take stock across business areas, systems and data: which records are created, which of them are raw data - and which call for which signature. The result: an inventory of your records with assessed signature requirements.

  2. 2

    Concept

    We define the signature type for each record and the organizational framework around it. The result: a records-and-signatures concept that fits your existing systems, risk profile and maturity.

  3. 3

    Implementation

    Controlled documents, SOPs and templates as a company standard - and support for implementing them in your systems within the validation framework.

  4. 4

    Training

    Awareness sessions, in-depth training, workshops and coaching - so the standards are lived in daily work and hold up in an inspection.

For Suppliers

Your product, ready for regulated customers.

If you supply software, AI-enabled products, or platform and infrastructure services into the GxP world, you will be measured against Part 11 and Annex 11 before the first regulated customer signs - three building blocks get your product and your evidence ready. The dividing line stays clear: the supplier owns the technical implementation; application, Intended Use and regulatory responsibility remain with the regulated customer. The requirements profile differs by layer - the application directly, the AI function through its behavior, the infrastructure indirectly as the foundation beneath; everything takes effect through the process and its Intended Use.

  • Product readiness

    Signature manifestation, audit trail, unique user binding: the capabilities your product needs before regulated customers are allowed to deploy it - technically sound rather than cosmetic.

  • Evidence from your lifecycle

    What regulated customers expect to see, and how your own development process becomes the evidence - the core of our software validation from the supplier's perspective.

  • Start with a preparatory audit

    The same format your regulated customers will use to audit you - just on your side of the table, as part of our IT supplier audits. It finds the gaps before a customer does.

First-Hand

We helped write the key concepts of data integrity.

The ISPE GAMP series on records and data integrity sets the industry benchmark for sound records - QFINITY served on the core team of the Data Integrity - Key Concepts volume. That practice runs through every engagement: every record knows its origin, rests on sound data and carries a signature exactly where the rules require one - turning records into evidence, not ballast.

21 CFR Part 11 EU GMP Annex 11 Audit Trail Review ALCOA++ Electronic Records Electronic Signatures
More from our service areas

Records need a foundation.

Make your records and signatures audit-ready.

We start by analyzing your systems and data and determine which signature type each process requires - the result is a clear roadmap to 21 CFR Part 11, Annex 11 and ALCOA++ compliance. Suppliers are welcome too: we get your product ready for exactly these requirements. The first consultation is free.

Book an intro call