ขอบเขต: ระบุหลักฐานที่ต้องการตามกฎหมายของ FDA และตรวจสอบว่าเอกสารหรือสำเนากระดาษที่ใช้เป็นหลักฐาน
Part 11 เริ่มต้นด้วยบันทึก ไม่ใช่ลายมือชื่อ
21 CFR Part 11 ไม่ทำให้แต่ละการอนุมัติอิเล็กทรอนิกที่ใช้โดยบริษัทสาขาวิทยาศาสตร์มีฐานะเป็นบันทึกที่ถูกควบคุม. คำถามแรกคือว่าข้อกำหนดกฎหมายที่เป็นต้นกำเนิดต้องการให้บันทึกถูกเก็บรักษาหรือยื่นเสนอแก่ FDA และว่าองค์กรนับเชื่อในเวอร์ชันอิเล็กทรอนิกเพื่อทำกิจกรรมที่ถูกควบคุม. ถ้ามีการเช่นนั้น บันทึกอิเล็กทรอนิกและลายมือชื่อที่เกี่ยวข้องอาจตกอยู่ในขอบเขต Part 11. การตัดสินใจขอบเขตดังกล่าวควรถูกบันทึกก่อนทีทีมเลือกวิธีการยืนยันตัวตน, ปรับแต่งฟิลด์การลงลายมือชื่อ หรือตรวจสอบการปรับแต่งของแผนกายุทาง
ที่มุ่งมั่นในการปกป้องของ Part 11
กฎนี้มุ่งเน้นที่ว่าหลักฐานเอกสารและลายมือชื่อได้รับความเชื่อถือ น่าเชื่อถือ สามารถเชื่อถือได้ และสามารถเข้าถึงได้ตลอดช่วงชีวิตที่ต้องการของมัน
การปกป้องความบริสุทธิ์ของหลักฐาน: ปกป้องหลักฐานที่ถูกควบคุมต่อการเข้าถึงที่ไม่ถูกต้อง การแก้ไข การสูญเสีย หรือการสร้างคืนที่ไม่สมบูรณ์
ความรับผิดชอบของลายมือชื่อ: เชื่อมโยงลายมือชื่อที่เป็นเดียวกันและได้รับการยืนยันกับหลักฐานที่ลงลายมือชื่อ รวมถึงเวลาและความหมายของการลงลายมือชื่อ
ความพร้อมสำหรับการตรวจสอบ: รักษาหลักฐานและผลิตสำเนาที่เป็นที่เข้าถึงง่ายและเป็นที่เชื่อถือเมื่อมีความต้องการ
การทดสอบขอบเขตที่มีประโยชน์ก่อนการปฏิบัติการ
เริ่มด้วยกฎหมายที่มีผลกระทบและการปฏิบัติงานที่เป็นจริง เทคโนโลยีเดียวกันสามารถสนับสนุนทั้ง Part 11 และกระบวนการที่ไม่ใช่ Part 11
Part 11 มีแนวโน้มที่จะถูกใช้เมื่อ
- กฎหมายที่มีผลกระทบต้องการให้รักษาหลักฐานและหลักฐานทางเอกสารทางไฟฟ้าแทนหลักฐานกระดาษ
- หลักฐานที่มีรูปแบบทั้งสอง แต่หลักฐานทางเอกสารทางไฟฟ้าที่ใช้เป็นหลักฐานสำหรับกิจกรรมที่ถูกควบคุม
- หลักฐานที่ส่งเข้าไปยัง FDA ด้วยทางส่งเข้าที่ได้รับการยอมรับ
- ลายมือชื่อทางเอกสารที่ใช้เป็นเทียบกับลายมือชื่อหลักฐานที่เขียนด้วยมือ ลายมือชื่อเริ่มต้น การอนุมัติ การตรวจสอบ หรือการยืนยันที่ต้องการตามกฎหมายที่มีผลกระทบ
Part 11 อาจไม่ถูกกระตุ้นเมื่อ
- ข้อมูลทางเอกสารทางไฟฟ้าไม่ต้องการรักษาตามกฎหมายของ FDA ที่มีผลกระทบ
- คอมพิวเตอร์สร้างหลักฐานกระดาษเท่านั้น และหลักฐานกระดาษที่ปฏิบัติตามกฎหมายเป็นหลักฐานที่ใช้เป็นหลักฐานที่เชื่อถือ
- กระบวนการที่อยู่ในขอบเขตของการยกเว้นที่ระบุใน 21 CFR 11.1
- หลักฐานนี้เป็นหลักฐานที่เพียงการปฏิบัติงานเท่านั้นและไม่สนับสนุนกิจกรรมที่ถูกควบคุม การส่งเข้าหรือหน้าที่ที่ต้องการรักษาหลักฐาน
แปลความต้องการของ Part 11 ให้เป็นหลักฐานที่สามารถตรวจสอบได้
รายการความสามารถไม่เพียงพอ สำหรับแต่ละการควบคุม ยืนยันว่ามันทำงานอย่างไรในกระบวนการที่มีเป้าหมายและหลักฐานที่สามารถผลิตขึ้นในระหว่างการตรวจสอบ การตรวจประกัน หรือการตรวจสอบ
การประมวลผลระบบ
ความเหมาะสม ความเชื่อถือ การประสบความสำเร็จตามที่วางแผน และความสามารถในการตรวจสอบหลักฐานที่ผิดปกติหรือถูกแก้ไข
การบันทึกการใช้ที่มีเอกสาร การประเมินความเสี่ยง ความต้องการ การทดสอบ การเกิดความแตกต่าง การอนุมัติ และการควบคุมการเปลี่ยนแปลงที่เหมาะสมต่อความเสี่ยงของหลักฐาน
สำเนาที่เหมาะสม
สำเนาที่สมบูรณ์ต้องสามารถใช้เป็นที่เข้าถึงง่ายและทางเอกสารทางไฟฟ้าสำหรับการตรวจสอบและสำเนา
Export the signed record and associated evidence without losing content, meaning, signature data, or relevant event history.
Retention and retrieval
Records must remain protected and readily retrievable for the required retention period.
Confirm retention ownership, search and retrieval, backup, migration, deletion controls, and access after a contract or account changes.
Access and authority
Access, signing, alteration, and regulated actions must be limited to authorised individuals.
Review account provisioning, role permissions, approval authority, segregation of duties, deactivation, and periodic access review.
Audit trail
Secure, computer-generated, time-stamped records should reconstruct actions that create, modify, or delete regulated records.
Check event coverage, time reference, actor attribution, previous-value preservation, exportability, retention, and protection from ordinary user alteration.
Signature manifestation
The signed record must show the signer's printed name, signing date and time, and the meaning of the signature.
Verify that review, approval, responsibility, or authorship is captured clearly and remains visible in human-readable output.
Signature-record linking
A signature must be linked to its record so it cannot be copied or transferred to falsify another record by ordinary means.
Test document integrity controls and confirm the evidence package binds the signer, action, time, and final record together.
Identity and signature controls
Each signature must be unique to one person, identity must be verified, and non-biometric signatures require controlled identification components.
Map identity proofing, authentication, credential ownership, password or token controls, recovery, and misuse detection to the workflow's risk.
How eSign.AI can support a Part 11 signing workflow
eSign.AI provides electronic-signature and evidence capabilities that can be configured as part of a regulated process. Suitability still depends on the customer's intended use, applicable predicate rules, procedures, validation approach, identity method, and retained evidence.
Signing meaning and manifestation
Workflows can capture the reason for signing together with signer and signing-event information, helping teams represent actions such as review, approval, or responsibility.
Signer verification and account controls
Configurable signer-verification and account-security options can support identity and access requirements. The selected method should be assessed against the workflow and the organisation's risk model.
Audit evidence
Signing events, completion information, and supporting evidence can help teams reconstruct who acted, what was signed, and when the event occurred.
Workflow and system integration
API and workflow integration can connect signing steps with quality, clinical, document-management, or business systems, while the organisation defines system boundaries and validation responsibilities.
What this does not mean
Using eSign.AI does not by itself make an organisation or process Part 11 compliant. Compliance depends on the complete system, configuration, procedures, people, training, records, and ongoing governance.
A six-step implementation path
Treat Part 11 as a controlled business process, not a feature toggle.
Inventory regulated records
Identify the predicate rule, record owner, required signature, retention period, submission route, and the version actually relied on.
Define intended use and system boundaries
Document what the eSignature platform will do, which connected systems remain authoritative, and where records and evidence are retained.
Set identity, access, and signing controls
Configure signer verification, authentication, roles, signing meaning, authority checks, credential recovery, and account deactivation.
Design the evidence package
Confirm the final record, signer name, time, signing meaning, event history, integrity evidence, and export format required for review.
Validate against risk and intended use
Test critical requirements, negative paths, permissions, signature linking, audit events, exports, integrations, and failure recovery.
Operate under controlled procedures
Maintain SOPs, training, periodic access reviews, incident handling, change control, vendor oversight, and revalidation triggers.
21 CFR Part 11 requirements vs eSign.AI implementation
Mapping FDA regulatory requirements to specific platform capabilities.
Part 11.50: signature manifestations
Requirement: printed copies must show signature name, date/time, and meaning. eSign.AI implementation: every signed PDF includes a signature manifest page listing all signers, timestamps (UTC + local), and signing purpose. This is auto-generated and tamper-evident.
Part 11.70: signature/record linking
Requirement: electronic signatures must be linked to their electronic records so they cannot be excised, copied, or transferred. eSign.AI implementation: signatures are cryptographically bound to the document hash. Any modification after signing invalidates the signature. The audit trail records the document hash at signing time.
Part 11.200: non-biometric signatures
Requirement: two distinct identification components (e.g., user ID + password). eSign.AI implementation: supports dual-factor signing (email/password + SMS OTP, or SSO + KBA). For closed systems, the platform enforces session-based authentication combined with per-signature confirmation.
21 CFR Part 11 requirements mapped to platform capabilities
How eSign.AI addresses each major Part 11 subsection.
Part 11.10: closed system controls
Part 11.10 requires validation, audit trails, system documentation, and access controls. eSign.AI provides: validated workflow templates, complete audit logs (60-80 events per signature), ISO 27001 certified infrastructure, role-based access control with custom roles and permissions, screen watermarking, and session management. The platform's audit log records who performed each action, when (with UTC timestamp), from where (IP and geolocation), and how (authentication method).
Part 11.50, 11.70, 11.200: signature controls
11.50 requires signature manifestations (name, date/time, meaning). 11.70 requires signatures to be linked to their records. 11.200 requires two identification components for non-biometric signatures. eSign.AI generates a signed signature manifest for every document, cryptographically binds signatures to document hashes, and supports dual-factor signing (SSO + per-signature OTP, or password + KBA).
Industry adoption: pharma and medical devices
In life sciences, Part 11 compliance is essential for clinical trial documents, batch records, laboratory data, and regulatory submissions. eSign.AI's FDA Part 11 module includes signing reason capture, hand-drawn signature styling, timestamp recording, and face recognition for signer identity verification — features specifically designed to meet FDA inspection requirements.
คำถามที่ยังไม่ได้รับการตอบ
Questions teams ask about Part 11 electronic signatures
No. Scope depends on the applicable predicate rule, whether the record is required to be maintained or submitted, and whether the organisation relies on the electronic record for a regulated activity. Document the scope decision for each record type.







