Home / Blog Center / 21 CFR Part 11 for Clinical Trials and eConsent

21 CFR Part 11 for Clinical Trials and eConsent

Shunfang
2026-07-31
7min
Twitter Facebook Linkedin

eConsent and electronic signatures in clinical trials

Electronic informed consent can improve access and documentation in clinical trials, but replacing paper with an electronic workflow does not remove the responsibilities of sponsors, investigators, institutional review boards, and other regulated parties.

The relevant requirements depend on the record, the applicable predicate rules, and whether electronic records and signatures are relied on for regulated activities. For a structured overview, see the FDA 21 CFR Part 11 electronic signatures guide.

Start with the clinical process

Map the full consent journey:

  • delivery of approved information;
  • participant review and questions;
  • identity and eligibility checks;
  • signature by the participant or legally authorised representative;
  • investigator or witness signature where required;
  • provision of a copy to the participant;
  • amendment and re-consent;
  • retention and inspection access.

The electronic system should support the approved process rather than change it silently. Confirm requirements with the study protocol, IRB or ethics approval, applicable FDA regulations, and local law.

Determine which records are in scope

Identify the official consent record and related evidence. This may include the approved consent version, participant acknowledgements, signature manifestations, timestamps, authentication events, delivery evidence, audit trail, and records of re-consent.

FDA’s October 2024 guidance on electronic systems, records, and signatures in clinical investigations emphasises risk-based evaluation, appropriate controls, record availability, and clear responsibilities when sponsors, clinical investigators, and service providers use electronic systems.

Verify identity and authority

The workflow must distinguish the participant, a legally authorised representative, the investigator, and any witness. Define how identity and authority are verified for each role, especially in remote consent.

Controls may include account-based authentication, one-time verification, identity-document checks, or higher-assurance methods appropriate to the risk and jurisdiction. Record the method used without collecting more personal data than necessary.

For Part 11 electronic signatures, the organisation should address uniqueness, identity verification before assignment, signature components, and credential controls. See electronic signature identity and record-linking requirements.

Capture intent and signature meaning

The participant should understand that the electronic action represents consent. The interface should distinguish acknowledgment, consent, witness confirmation, investigator approval, and other meanings.

The signed record should clearly show the signer’s printed name, signing date and time, and signature meaning. The signature must remain linked to the consent version that was presented and signed.

Preserve the approved version

Consent forms can change during a study. The system should prevent an obsolete or unapproved version from being sent and should preserve the exact version associated with each signature.

Test:

  • version approval and release;
  • assignment of the correct version by site and participant;
  • withdrawal or replacement of obsolete versions;
  • re-consent triggers;
  • amendment history;
  • retrieval of the signed version and evidence.

Provide a copy and support accessibility

The process should provide the participant with a copy of the informed-consent information and completed record as required. Confirm delivery methods, accessibility, language, device support, and alternatives for participants who cannot or do not wish to use the electronic process.

Remote technology should not reduce the participant’s opportunity to ask questions or make a voluntary decision.

Validate and oversee the electronic system

Regulated parties should define intended use, assess risk, and retain evidence that the system is fit for its role in the clinical investigation. Vendor qualification may contribute evidence, but sponsors and sites must understand their own configuration, integrations, procedures, and responsibilities. The implementation can be documented through a Part 11 software validation checklist tailored to the study and its regulated records.

Assess:

  • access and role controls;
  • signature and authentication configuration;
  • audit-trail coverage;
  • record export and retention;
  • availability and recovery;
  • integration accuracy;
  • change notifications and release management;
  • incident handling;
  • data privacy and security;
  • subcontractors and data locations.

How eSign.AI supports clinical eConsent workflows

eSign.AI supports configurable electronic and digital signature workflows, participant and staff authentication options, controlled signing sequences, signature-event evidence, completed records, and integration with clinical or document systems.

These capabilities can support an eConsent implementation, but the sponsor, investigator, and other responsible parties must determine applicable requirements, obtain the necessary approvals, validate intended use, govern participant communications, and maintain required records.

Sources and further reading

FAQs

Does every eConsent workflow fall under Part 11?
Applicability depends on the records, the governing predicate rules, and how the electronic records and signatures are relied on.
What should an eConsent signature record preserve?
It should preserve the approved consent version, signer identity and role, signing date and time, signature meaning, and associated workflow and audit evidence.
Does using a vendor transfer the sponsor's responsibilities?
No. Vendor evidence can support oversight, but regulated parties remain responsible for intended use, approvals, validation, procedures, and required records.
avatar
Shunfang
Head of Product Management at eSign.AI, a seasoned leader with extensive international experience in the e-signature industry. Follow me on LinkedIn