FDA 21 CFR Part 11 — Electronic Records; Electronic Signatures
US federal regulation establishing criteria for acceptance of electronic records and electronic signatures by the FDA. 30 requirements across electronic records (validation, audit trails, system access controls, authority checks, device checks, education and training, documentation, open and closed system controls), electronic signatures (uniqueness, identity verification, signature manifestations, signature/record linking), and biometric and non-biometric authentication controls. Applies to all FDA-regulated industries including pharmaceuticals, medical devices, biologics, and food.
Clauses: 30
Avg Coverage: 73.0%
Publisher: U.S. Food and Drug Administration (FDA) Version: 1997 (updated guidance 2003) | Clause | Title | SP 800-53 Controls |
|---|---|---|
| §11.1 | Scope | |
| §11.2 | Implementation — Risk-Based Approach | |
| §11.3 | Definitions — Electronic Record, Electronic Signature, Digital Signature | |
| §11.10(a) | Closed Systems — Validation of Systems | |
| §11.10(b) | Closed Systems — Generating Accurate and Complete Copies | |
| §11.10(c) | Closed Systems — Protection of Records for Accurate and Ready Retrieval | |
| §11.10(d) | Closed Systems — Limiting System Access to Authorised Individuals | |
| §11.10(e) | Closed Systems — Secure, Computer-Generated, Time-Stamped Audit Trails | |
| §11.10(f) | Closed Systems — Use of Operational System Checks | |
| §11.10(g) | Closed Systems — Use of Authority Checks | |
| §11.10(h) | Closed Systems — Use of Device Checks | |
| §11.10(i) | Closed Systems — Trained Personnel | |
| §11.10(j) | Closed Systems — Written Policies for Electronic Signature Accountability | |
| §11.10(k) | Closed Systems — Controls Over Systems Documentation | |
| §11.30 | Controls for Open Systems | |
| §11.50 | Signature Manifestations | |
| §11.70 | Signature/Record Linking | |
| §11.100(a) | Electronic Signatures — Unique to One Individual | |
| §11.100(b) | Electronic Signatures — Identity Verification Before Assignment | |
| §11.100(c) | Electronic Signatures — Certification to FDA | |
| §11.200(a)(1) | Electronic Signature Components — Non-Biometric (Two Components) | |
| §11.200(a)(1)(i) | Non-Biometric Signatures — Continuous Session Controls | |
| §11.200(a)(1)(ii) | Non-Biometric Signatures — Non-Continuous Session Controls | |
| §11.200(a)(2) | Non-Biometric Signatures — Unique Identification Code/Password Pair | |
| §11.200(a)(3) | Electronic Signatures — Biometric Requirements | |
| §11.300(a) | Controls for ID Codes/Passwords — Maintaining Uniqueness | |
| §11.300(b) | Controls for ID Codes/Passwords — Periodic Revision and Recall | |
| §11.300(c) | Controls for ID Codes/Passwords — Loss Management Procedures | |
| §11.300(d) | Controls for ID Codes/Passwords — Transaction Safeguards | |
| §11.300(e) | Controls for ID Codes/Passwords — Initial and Periodic Testing |