Part 11 is cited constantly in discussions about electronic batch records. It is also, in our experience, one of the most selectively read regulations in pharmaceutical manufacturing. Vendors claim their products are Part 11 compliant as if that phrase settles the matter. Quality teams accept or challenge the claim without always being sure what it specifically requires. The result is that compliance gets treated as a binary vendor certification rather than a documented technical and procedural state that the regulated party owns and must defend at inspection.
Reading the regulation itself, which is 21 CFR Part 11 Subpart A through Subpart C, is the right starting point. It is short. The core technical and procedural requirements are stated directly. What it says and what it is commonly understood to require are not always the same thing.
What the rule actually requires
21 CFR Part 11 establishes criteria under which FDA considers electronic records to be trustworthy, reliable, and equivalent to paper records. It applies when electronic records are used in place of paper records, or when electronic signatures are used in place of handwritten signatures, in contexts governed by FDA regulations under Parts 210, 211, 820, and other applicable regulations.
The core technical controls Part 11 requires are: audit trails that capture the date and time of operator entries and actions that create, modify, or delete electronic records, and that record both the original and changed values when records are altered; system access controls including user identification codes and passwords with procedures for limiting system access to authorized individuals; sequential computer-generated timestamps for audit trail entries; and secure, computer-generated audit trail records that are retained for a period at least as long as the records they cover and are available for agency review and copying.
For electronic signatures, the rule requires that they be unique to the individual, that individuals not reuse signatures, and that signature records include the printed name of the signer, the date and time when the signature was executed, and the meaning of the signature (such as review, approval, or responsibility). Linked signatures, where a signature binds to a specific version of a specific record, are required under 11.70.
What is procedural, not just technical
Part 11 compliance is not achieved solely through software features. Sections 11.10(j) and 11.10(k) require training of individuals who use electronic record or signature systems, and documentation of that training. Section 11.10(g) requires authority checks to ensure that only authorized individuals can use the system, access the operation or computer system input or output device, alter a record, or perform an operation. These requirements call for written procedures governing system use, documented training records, and periodic access reviews.
Regulated companies are responsible for establishing and maintaining controls over electronic systems used to create, modify, maintain, or transmit electronic records. A vendor can deliver a system with the right technical architecture; the regulated party must implement and maintain the procedural controls that make the system compliant in practice. When an FDA investigator asks for your Part 11 assessment, they want to see both the technical controls and the SOPs, training records, and audit trail reviews that demonstrate the controls are being operated as designed.
The hybrid system complication
Many pharmaceutical manufacturers operate hybrid systems: paper records and electronic records in parallel, with some data captured electronically and some on paper. FDA issued guidance in 2003 clarifying that Part 11 applies to electronic records that are required under predicate rules or that are used to fulfill regulatory obligations, even when a paper counterpart exists. A common misreading is that maintaining a paper backup removes an electronic record from Part 11 scope. It does not, if the electronic record is the record being used to fulfill a regulatory requirement.
The practical implication for batch record systems is that scanned paper records and electronic data captured in an EBR or LIMS may both fall within Part 11 scope, depending on which records are being used to support release decisions and comply with 21 CFR Part 211 documentation requirements. A system architecture that stores some records as PDF scans with electronic review does not escape Part 11 by virtue of originating on paper.
What vendors frequently overstate
The claim "our system is 21 CFR Part 11 compliant" carries exactly as much regulatory weight as the vendor's validation documentation supports. A vendor can build a system with all the right technical features and still deliver a product that requires significant customer-side validation effort before it meets the operational definition of Part 11 compliance for a specific application.
We are not saying vendor compliance claims are dishonest. We are saying that compliance for a specific batch record application in a specific manufacturing environment is determined by how the system is configured, how access controls are implemented, how audit trails are reviewed and retained, and how the procedural framework is maintained by the quality team. A vendor audit certificate or a self-certification statement is an input to that determination, not a conclusion.
In practice, quality teams should ask vendors for their IQ/OQ/PQ documentation packages, their audit trail specification, their approach to electronic signature binding, and evidence from prior customer validation work. Vendors who have actually been through multiple pharmaceutical manufacturing validations will have this documentation organized and will not be surprised by the question.
Audit trail review as an ongoing practice
One of the requirements quality teams most often underweight is the expectation that audit trails are periodically reviewed, not just generated. FDA 483 observations and warning letters on electronic batch records frequently cite failure to review audit trails as a CGMP deficiency. The audit trail exists to ensure that any change to a record can be reconstructed and explained; if it is never reviewed in practice, it is not functioning as a control.
Establishing a periodic audit trail review procedure, specifying frequency, scope, and what review findings trigger investigation, is a straightforward control to implement. The harder part is sustaining it when review volume is high. For operations using automated systems to capture electronic batch records across multiple batches per day, the volume of audit trail entries can make manual review impractical. Tooling that supports audit trail review by exception, flagging entries that involve record modification or deletion, makes the practice manageable.
A scenario worth walking through
Consider a solid-dose manufacturer in New England transitioning from paper batch records to an EBR system. They have completed IQ and OQ with the vendor. During PQ, their quality team discovers that the system's audit trail captures record creation and modification timestamps, but does not capture the original value before a field is edited by a production operator. This means the audit trail cannot demonstrate what value was recorded first and what it was changed to, which is a direct gap against the 11.10(e) requirement for audit trail entries that capture the original and changed data.
This is not a validation failure that causes the project to collapse; it is exactly what PQ is designed to catch. The question at that point is whether the gap can be remediated through configuration, through a vendor software update, or whether it is a fundamental architectural limitation that makes the system unsuitable for this application. All three outcomes occur in the field. Catching it in PQ rather than at an FDA inspection is the entire point of the validation process.
How to read a vendor's Part 11 documentation
When evaluating a batch record system for Part 11 compliance, the most useful documents are the system's Part 11 assessment matrix, which should cross-reference each Part 11 requirement against a specific system feature and the configuration or procedure that satisfies it; the audit trail specification; the electronic signature binding specification; and any customer-facing validation guide that documents which requirements are satisfied by vendor-supplied documentation versus customer-executed qualification activities. Gap analysis against these documents, before contract execution, surfaces the questions that matter for your specific implementation.
See how Katalyze AI performs on your documentation
Talk to the team about your batch records and deviation history. We will show you a working demo configured to your product type.
Request a Demo