2.2 Electronic Records & Signatures (21 CFR Part 11)

Key Takeaways

  • 21 CFR Part 11 applies to electronic records, electronic signatures, and handwritten signatures executed to electronic records required by the FDA.
  • Closed systems are controlled by those responsible for content, while open systems are not and require extra encryption and digital signature standards.
  • Audit trails must be secure, computer-generated, time-stamped, retain old/new values, not obscure previous data, and be kept for the same duration as the main records.
  • To use electronic signatures, firms must submit a physical, handwritten non-repudiation certification letter on paper to the FDA's Office of Regional Operations.
Last updated: July 2026

2.2 Electronic Records & Signatures (21 CFR Part 11)

Regulatory Purpose and Scope of Part 11

In 1997, the Food and Drug Administration (FDA) implemented 21 CFR Part 11, a regulation establishing the criteria under which the agency considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and generally equivalent to paper records and handwritten signatures executed on paper. This regulation applies to any electronic record that is created, modified, maintained, archived, retrieved, or transmitted under any records requirement set forth in FDA regulations.

As clinical trials transitioned from paper case report forms (CRFs) and physical investigator site files to electronic data capture (EDC) systems, electronic source (eSource) documents, and electronic trial master files (eTMFs), compliance with 21 CFR Part 11 became a cornerstone of clinical research operations. If a system is not compliant with Part 11, the FDA can reject the clinical trial data submitted in support of a marketing application.

Closed vs. Open Systems

21 CFR Part 11 makes a fundamental distinction between closed and open systems, applying different administrative and technical controls to each:

  • Closed Systems: Defined under 21 CFR 11.3(b)(4) as an environment in which system access is controlled by persons who are responsible for the content of electronic records that are on the system. In clinical research, most EDC systems, eTMFs, and electronic institutional review board (eIRB) portals operate as closed systems because the sponsor, contract research organization (CRO), or institution directly manages user accounts, passwords, and permissions.
  • Open Systems: Defined under 21 CFR 11.3(b)(9) as an environment in which system access is not controlled by persons who are responsible for the content of electronic records that are on the system. A common example is the transmission of clinical data over the public internet or submission of electronic records through a portal open to external, non-authenticated networks.

Controls for Closed Systems

To maintain a compliant closed system, organizations must implement a series of controls defined in 21 CFR 11.10. These include:

  1. System Validation: Validating systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records.
  2. Record Generation: The ability to generate accurate and complete copies of records in both human-readable and electronic form for inspection and review.
  3. Protection of Records: Protecting records to enable their accurate and ready retrieval throughout the records retention period.
  4. Limiting System Access: Restricting system access to authorized individuals.
  5. Audit Trails: Use of secure, computer-generated, time-stamped audit trails (see detailed section below).
  6. Operational System Checks: Enforcing permitted sequencing of steps and events, such as preventing data entry before a subject is registered or preventing a signature before all required fields are complete.
  7. Authority Checks: Ensuring that only authorized individuals can use the system, sign a record, access inputs or outputs, or perform a given operation.
  8. Device Checks: Verifying the validity of the source of data input or operational instruction (e.g., ensuring a remote diagnostic device is calibrated and authorized to transmit data to the EDC).
  9. Education and Training: Determining that persons who develop, maintain, or use electronic record/signature systems have the necessary education, training, and experience.
  10. Written Policies: Establishing and adhering to written policies that hold individuals accountable for actions initiated under their electronic signatures to prevent non-repudiation.

Additional Controls for Open Systems

For open systems, 21 CFR 11.30 mandates that organizations implement all the closed system controls plus additional measures to ensure record authenticity, integrity, and confidentiality. These additional controls include:

  • Document Encryption: Protecting data in transit and at rest using cryptographic standards.
  • Digital Signature Standards: Implementing digital signatures that employ public-key cryptography to verify the identity of the sender and ensure that the document has not been altered since it was signed.

Audit Trail Requirements

One of the most critical components of 21 CFR Part 11 compliance is the audit trail (21 CFR 11.10(e)). An audit trail is a secure, computer-generated, time-stamped electronic record that independently records the date and time of operator entries and actions that create, modify, or delete electronic records.

Key regulatory characteristics of an audit trail include:

  • Non-obscuring changes: When a record is modified or deleted, the audit trail must record the change without obscuring the previously recorded information. For example, if a clinical coordinator changes a subject’s baseline systolic blood pressure entry from 120 mmHg to 140 mmHg, the system must retain the original "120" and show the change to "140."
  • Content: The audit trail must record the identity of the operator making the entry, the exact date and time of the entry or change, the old value, the new value, and the reason for the change.
  • Retention: Audit trail records must be retained for a period at least as long as that required for the subject electronic records.
  • Inspection availability: The audit trail must be readily available for FDA review and copying during inspections.

Electronic Signature Requirements and Execution

An electronic signature is defined as a computer data compilation of any symbol or series of symbols executed, adopted, or authorized by an individual to be the legally binding equivalent of the individual's handwritten signature.

Signature Components and Linkage

Every electronic signature executed within a system must contain three distinct visible components:

  1. The printed name of the signer.
  2. The date and time when the signature was executed.
  3. The meaning associated with the signature (such as review, approval, authorship, or responsibility).

These components must be electronically linked to their respective records to ensure that the signature cannot be excised, copied, or otherwise transferred to falsify another electronic record.

Execution Controls (Single vs. Continuous Sessions)

Under 21 CFR 11.200, electronic signatures that are not based on biometrics must employ at least two distinct identification components, such as an identification code (username) and a password.

  • Non-continuous sessions: When an individual executes a series of signings that are not performed during a single, continuous system access session, each signature must require the entry of both the identification code and the password.
  • Continuous sessions: When an individual executes a series of signings during a single, continuous session (e.g., signing multiple case report forms in one sitting), the first signature must require both components (username and password). Subsequent signatures within that continuous session require only the password.

Non-Repudiation and FDA Certification

To prevent individuals from denying that they executed an electronic signature (non-repudiation), 21 CFR 11.100(c) requires that organizations submit a formal certification to the FDA.

  • The certification must be submitted in writing, on paper, with a traditional physical handwritten signature.
  • It must certify that the electronic signatures in their systems are the legally binding equivalent of traditional handwritten signatures.
  • This certification must be submitted to the FDA's Office of Regional Operations prior to or at the time of the system's first use.
Loading diagram...
Electronic Signature Execution Workflow (21 CFR Part 11)
Test Your Knowledge

According to 21 CFR Part 11, what is the regulatory distinction between a closed system and an open system?

A
B
C
D
Test Your Knowledge

When an investigator signs multiple electronic case report forms (eCRFs) in a single, continuous system access session, what are the requirements for entering signature credentials under 21 CFR Part 11?

A
B
C
D
Test Your Knowledge

To comply with 21 CFR Part 11, what must an organization do before or at the time of first using electronic signatures in a system?

A
B
C
D