FDA 21 CFR Part 11 Compliance
Term 42 of 68 in the ERPStack technical glossary
What is FDA 21 CFR Part 11 Compliance?
FDA 21 CFR Part 11 is a United States Food and Drug Administration regulation establishing criteria under which electronic records and electronic signatures are considered trustworthy and equivalent to paper records.
FDA 21 CFR Part 11 Compliance at a glance
- Regulation
- 21 CFR Part 11, Electronic Records; Electronic Signatures, published at 62 FR 13464 on 20 March 1997
- Authority
- 21 U.S.C. 321-393 and 42 U.S.C. 262, as recorded in the Code of Federal Regulations
- Core demands
- Validated systems, secure audit trails, record retention and controlled electronic signatures
- Signature rule
- Each signature linked to its record so it cannot be transplanted onto another one
- Built with
- Append-only PostgreSQL 18 records through Drizzle ORM 0.45, signature binding in Next.js 16, WORM storage on AWS, validation evidence from Vitest 4 and Playwright 1.59 in GitHub Actions
- Numbers that matter
- 21 CFR Part 11; 62 FR 13464, 20 March 1997; authority 21 U.S.C. 321-393 and 42 U.S.C. 262; audit trails retained at least as long as the record
- Adjacent regimes
- HIPAA, SOC 2, ISO 27001 and AS9100 Aerospace Standard in regulated manufacturing
- Commonly paired with
- WORM storage on AWS, an Immutable Audit Trail in PostgreSQL 18, RBAC and SSO on signing, Certified Timesheet Tracking, Drizzle ORM 0.45 append-only writes, and Vitest 4 and Playwright 1.59 validation evidence
- Sectors it governs
- biotech and healthcare manufacturers, plus the manufacturing and logistics systems feeding them — all reading 1 audit trail in PostgreSQL 18 under RBAC and SSO.
How FDA 21 CFR Part 11 Compliance works in production
The ERPStack approach to FDA 21 CFR Part 11 Compliance
We build clinical trial software with dual-signature validation flows, MFA confirmations, and tamper-evident audit logs to satisfy FDA auditors.
Frequently asked questions about FDA 21 CFR Part 11 Compliance
What does 21 CFR Part 11 Compliance cover?
Electronic records and electronic signatures used in FDA-regulated processes. Part Compliance rests on 21 CFR Part 11, published at 62 FR 13464 on 20 March 1997, which requires validated systems, secure computer-generated time-stamped audit trails, protection of records across their retention period, and electronic signatures that are verifiably linked to the records they approve.
What does a Part 11 audit trail have to record?
Operator entries and actions that create, modify or delete a record, with a computer-generated timestamp, retained for at least as long as the record itself and available for review. Part Compliance also requires that the trail not obscure previously recorded information — so corrections are appended, never overwritten. That single requirement rules out the update-in-place pattern most applications default to.
What does system validation mean here?
Documented evidence that the system does what it is specified to do, consistently. Part Compliance treats validation as an ongoing property rather than a one-off exercise, which maps well onto an automated test suite plus a controlled change process: requirements traced to tests, tests executed on every change, and results retained. Manual validation of a system that then changes weekly satisfies nobody.
How are electronic signatures kept trustworthy?
By binding them to the record and to a verified identity. Part Compliance requires that a signature include the signer, the date and time, and the meaning of the signing, and that it cannot be excised and reused elsewhere. Implementations therefore store the signature with a cryptographic reference to the exact record version, alongside re-authentication at the moment of signing.