Home / Blog Center / Part 11 Electronic Signature and Record-Linking Rules

21 CFR Part 11 Electronic Signature Identity and Record-Linking Requirements

Shunfang
2026-07-31
7min
Twitter Facebook Linkedin

Electronic signature identity and record linking

21 CFR Part 11 treats an electronic signature as more than a visual mark on a document. The signature must be attributable to a verified individual, display required signing information, and remain linked to the electronic record so that it cannot be transferred by ordinary means to falsify another record.

For the wider regulatory context, use the FDA 21 CFR Part 11 electronic signatures guide.

Verify identity before assigning a signature

Section 11.100 requires each electronic signature to be unique to one individual and not reused or reassigned. Before establishing or sanctioning an individual’s electronic signature, the organisation must verify that person’s identity.

Identity proofing should be proportionate to the role and risk. Document:

  • how identity is verified;
  • who approves account creation;
  • which identity evidence is retained;
  • how duplicate or shared identities are prevented;
  • how contractors and external participants are handled;
  • how access is removed when a role ends.

Identity verification at enrolment must connect to authentication at signing. A well-verified account provides little assurance if credentials are later shared.

Use appropriate signature components

For non-biometric electronic signatures, § 11.200 requires at least two distinct identification components, such as an identification code and password.

During a single continuous period of controlled system access, the first signing uses all components; subsequent signings use at least one component that is executable only by the individual. Outside a continuous controlled session, each signing uses all components.

Controls should also ensure that signatures are used only by their genuine owners and that attempted use by another person would require collaboration by two or more individuals.

Protect identification codes and passwords

Section 11.300 addresses uniqueness, periodic checking or revision, loss management, transaction safeguards, and testing of devices that generate or carry credentials.

Operational controls commonly include:

  • unique user accounts;
  • password and authentication policies;
  • multi-factor authentication where appropriate;
  • immediate deactivation of compromised credentials;
  • detection and escalation of unauthorised attempts;
  • periodic access review;
  • controlled recovery and reset processes;
  • testing of tokens or devices where used.

Shared accounts undermine attribution and should not be used for regulated signing.

Display the signature manifestation

Under § 11.50, the signed electronic record must clearly show:

  • the printed name of the signer;
  • the date and time of signature execution;
  • the meaning of the signature, such as review, approval, responsibility, or authorship.

This information must be subject to the same controls as the electronic record and appear in a human-readable display or printout. Configure signing reasons deliberately rather than relying on a generic “completed” status.

Keep the signature linked to the record

Section 11.70 requires electronic and handwritten signatures executed to electronic records to remain linked to their respective records. The purpose is to prevent a signature from being excised, copied, or transferred to falsify another electronic record by ordinary means.

The implementation should preserve:

  • a stable record or transaction identifier;
  • the exact version or hash associated with signing;
  • signer and authentication context;
  • signature date, time, and meaning;
  • workflow and status events;
  • completed document and evidence package.

Test what happens when a document is amended, replaced, downloaded, archived, restored, or migrated.

Link identity, intent, and evidence

A defensible signature workflow answers three different questions:

  1. Identity: Who was authorised and authenticated?
  2. Intent: What action did the signer intentionally take, and what did it mean?
  3. Integrity: Which record was signed, and has the signed version remained protected?

The signature display, audit trail, and retained completion evidence should tell one consistent story. For audit-event design, see 21 CFR Part 11 audit trail requirements.

How eSign.AI supports electronic signatures

eSign.AI supports electronic and digital signatures, configurable signer authentication, signing reasons, time-stamped signer events, completed-document evidence, and business-system integration. These capabilities help organisations connect signer identity, signing intent, and the signed record.

The organisation remains responsible for identity-verification procedures, account governance, intended-use validation, training, credential controls, and assessment against applicable predicate rules. Clinical research teams can apply these same controls to clinical trial and eConsent workflows, with the additional responsibilities of the protocol and consent process.

Sources and further reading

FAQs

What information must appear with a Part 11 signature?
The signed record must show the signer's printed name, the date and time of signing, and the meaning of the signature.
Why must a signature remain linked to its record?
The link is intended to prevent a signature from being excised, copied, or transferred by ordinary means to falsify another record.
Can regulated users share a signing account?
No. Part 11 requires each electronic signature to be unique to one individual and not reused or reassigned.
avatar
Shunfang
Head of Product Management at eSign.AI, a seasoned leader with extensive international experience in the e-signature industry. Follow me on LinkedIn