eSign.AIeSign.AI

Industry Insights

FDA 21 CFR Part 11 Electronic Signatures: A Practical Guide

Understand when FDA 21 CFR Part 11 applies and how to evaluate electronic signature controls, audit trails, validation, access, and record retention.

eSign.AI Regulatory & Industry Research Team12 min read

Part 11 starts with the record, not the signature

21 CFR Part 11 does not turn every electronic approval used by a life-sciences company into a regulated record. The first question is whether a predicate rule requires the record to be maintained or submitted to FDA and whether the organisation relies on the electronic version to perform the regulated activity. If it does, the electronic record and its associated signature may fall within Part 11. That scope decision should be documented before teams choose authentication methods, configure signing fields, or validate a platform. Part 11 also does not make software alone compliant: the regulated organisation remains responsible for intended use, procedures, training, access governance, validation decisions, and ongoing control.

What Part 11 is designed to protect

The rule focuses on whether electronic records and signatures remain trustworthy, reliable, attributable, and available throughout their required lifecycle.

01

Scope: identify records required by an FDA predicate rule and determine whether the electronic or paper version is relied on.

02

Record integrity: protect regulated records against unauthorised access, alteration, loss, or incomplete reconstruction.

03

Signature accountability: connect a unique, verified signer to the signed record, time, and meaning of the signing action.

04

Inspection readiness: retain records and produce accurate, complete, human-readable and electronic copies when required.

A practical scope test before implementation

Start with the applicable predicate rule and actual operating practice. The same technology can support both Part 11 and non-Part 11 workflows.

Part 11 is more likely to apply when

  • A predicate rule requires the record to be maintained and the electronic record replaces paper.
  • A required record exists in both formats, but the electronic version is relied on for the regulated activity.
  • A record is submitted electronically to FDA under an accepted submission route.
  • An electronic signature is used as the equivalent of a handwritten signature, initial, approval, review, or verification required by a predicate rule.

Part 11 may not be triggered when

  • The electronic information is not required to be retained under an FDA predicate rule.
  • A computer only generates a paper record and the compliant paper record is the version actually relied on.
  • The workflow falls within a specific exclusion stated in 21 CFR 11.1.
  • The record is purely operational and does not support a regulated activity, submission, or required recordkeeping obligation.

Translate Part 11 requirements into evidence you can review

A feature checklist is not enough. For each control, confirm how it works in the intended workflow and what evidence can be produced during validation, audit, or inspection.

System validation

Accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records.

Documented intended use, risk assessment, requirements, testing, deviations, approvals, and change control proportionate to record risk.

Accurate copies

Complete copies must be available in human-readable and electronic form for review and copying.

Export the signed record and associated evidence without losing content, meaning, signature data, or relevant event history.

Retention and retrieval

Records must remain protected and readily retrievable for the required retention period.

Confirm retention ownership, search and retrieval, backup, migration, deletion controls, and access after a contract or account changes.

Access and authority

Access, signing, alteration, and regulated actions must be limited to authorised individuals.

Review account provisioning, role permissions, approval authority, segregation of duties, deactivation, and periodic access review.

Audit trail

Secure, computer-generated, time-stamped records should reconstruct actions that create, modify, or delete regulated records.

Check event coverage, time reference, actor attribution, previous-value preservation, exportability, retention, and protection from ordinary user alteration.

Signature manifestation

The signed record must show the signer's printed name, signing date and time, and the meaning of the signature.

Verify that review, approval, responsibility, or authorship is captured clearly and remains visible in human-readable output.

Signature-record linking

A signature must be linked to its record so it cannot be copied or transferred to falsify another record by ordinary means.

Test document integrity controls and confirm the evidence package binds the signer, action, time, and final record together.

Identity and signature controls

Each signature must be unique to one person, identity must be verified, and non-biometric signatures require controlled identification components.

Map identity proofing, authentication, credential ownership, password or token controls, recovery, and misuse detection to the workflow's risk.

How eSign.AI can support a Part 11 signing workflow

eSign.AI provides electronic-signature and evidence capabilities that can be configured as part of a regulated process. Suitability still depends on the customer's intended use, applicable predicate rules, procedures, validation approach, identity method, and retained evidence.

Signing meaning and manifestation

Workflows can capture the reason for signing together with signer and signing-event information, helping teams represent actions such as review, approval, or responsibility.

Signer verification and account controls

Configurable signer-verification and account-security options can support identity and access requirements. The selected method should be assessed against the workflow and the organisation's risk model.

Audit evidence

Signing events, completion information, and supporting evidence can help teams reconstruct who acted, what was signed, and when the event occurred.

Workflow and system integration

API and workflow integration can connect signing steps with quality, clinical, document-management, or business systems, while the organisation defines system boundaries and validation responsibilities.

What this does not mean

Using eSign.AI does not by itself make an organisation or process Part 11 compliant. Compliance depends on the complete system, configuration, procedures, people, training, records, and ongoing governance.

A six-step implementation path

Treat Part 11 as a controlled business process, not a feature toggle.

01

Inventory regulated records

Identify the predicate rule, record owner, required signature, retention period, submission route, and the version actually relied on.

02

Define intended use and system boundaries

Document what the eSignature platform will do, which connected systems remain authoritative, and where records and evidence are retained.

03

Set identity, access, and signing controls

Configure signer verification, authentication, roles, signing meaning, authority checks, credential recovery, and account deactivation.

04

Design the evidence package

Confirm the final record, signer name, time, signing meaning, event history, integrity evidence, and export format required for review.

05

Validate against risk and intended use

Test critical requirements, negative paths, permissions, signature linking, audit events, exports, integrations, and failure recovery.

06

Operate under controlled procedures

Maintain SOPs, training, periodic access reviews, incident handling, change control, vendor oversight, and revalidation triggers.

21 CFR Part 11 requirements vs eSign.AI implementation

Mapping FDA regulatory requirements to specific platform capabilities.

Part 11.50: signature manifestations

Requirement: printed copies must show signature name, date/time, and meaning. eSign.AI implementation: every signed PDF includes a signature manifest page listing all signers, timestamps (UTC + local), and signing purpose. This is auto-generated and tamper-evident.

Part 11.70: signature/record linking

Requirement: electronic signatures must be linked to their electronic records so they cannot be excised, copied, or transferred. eSign.AI implementation: signatures are cryptographically bound to the document hash. Any modification after signing invalidates the signature. The audit trail records the document hash at signing time.

Part 11.200: non-biometric signatures

Requirement: two distinct identification components (e.g., user ID + password). eSign.AI implementation: supports dual-factor signing (email/password + SMS OTP, or SSO + KBA). For closed systems, the platform enforces session-based authentication combined with per-signature confirmation.

21 CFR Part 11 requirements mapped to platform capabilities

How eSign.AI addresses each major Part 11 subsection.

Part 11.10: closed system controls

Part 11.10 requires validation, audit trails, system documentation, and access controls. eSign.AI provides: validated workflow templates, complete audit logs (60-80 events per signature), ISO 27001 certified infrastructure, role-based access control with custom roles and permissions, screen watermarking, and session management. The platform's audit log records who performed each action, when (with UTC timestamp), from where (IP and geolocation), and how (authentication method).

Part 11.50, 11.70, 11.200: signature controls

11.50 requires signature manifestations (name, date/time, meaning). 11.70 requires signatures to be linked to their records. 11.200 requires two identification components for non-biometric signatures. eSign.AI generates a signed signature manifest for every document, cryptographically binds signatures to document hashes, and supports dual-factor signing (SSO + per-signature OTP, or password + KBA).

Industry adoption: pharma and medical devices

In life sciences, Part 11 compliance is essential for clinical trial documents, batch records, laboratory data, and regulatory submissions. eSign.AI's FDA Part 11 module includes signing reason capture, hand-drawn signature styling, timestamp recording, and face recognition for signer identity verification — features specifically designed to meet FDA inspection requirements.

COMMON QUESTIONS

Questions teams ask about Part 11 electronic signatures

No. Scope depends on the applicable predicate rule, whether the record is required to be maintained or submitted, and whether the organisation relies on the electronic record for a regulated activity. Document the scope decision for each record type.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.