21 CFR Part 11, Explained in Plain Language | Kintavo
← FIELD NOTES

21 CFR Part 11, Explained in Plain Language

Kintavo Quality Team · Updated August 2026

Who this is for: quality professionals evaluating systems, and anyone who has been told a product is "Part 11 compliant" and wants to know what that must mean before signing.

What Part 11 covers — and the predicate rule trap

Part 11 applies when records required by other FDA regulations — the predicate rules: 210/211 for drugs, 820 for devices, 606 for blood — are kept electronically. It does not create record requirements; it sets the conditions under which electronic versions are trustworthy. First question in any assessment: which predicate rules require the records you keep?

Subpart B: the record requirements

Validated systems (11.10a). Records protected and retrievable through the retention period (11.10c). Access limited to authorized individuals (11.10d). And the one that fails most audits: secure, computer-generated, time-stamped audit trails that record changes without obscuring prior values (11.10e). A system that overwrites a corrected value — even with a log entry — fails that clause by design.

Subpart C: what makes an e-signature real

A signature must be unique to one individual (11.100), carry two identification components with re-authentication during a session (11.200), display its meaning — author, review, approval — and be bound to its record such that it cannot be excised or transferred (11.70). A checkbox that stamps a name is not a signature under any of those tests.

"Part 11 compliant" — the three questions that test the claim

One: can the audit trail be disabled, and by whom? If an administrator can turn it off, an inspector assumes it was. Two: what happens to the prior value when a record is corrected? Three: does signing require re-authentication, and is the meaning recorded? Architecture answers these; configuration hopes about them.

Note also that compliance is never the vendor’s alone — validation of your use, your procedures, and your access control stays with you. What a vendor owes you is an architecture that cannot silently fail, plus documentation that makes your validation tractable.

Data integrity: where Part 11 enforcement actually lives

Modern FDA citations rarely name Part 11 directly — they arrive as data integrity findings under the predicate rules: shared logins, batch-signed records, unreviewed audit trails. FDA’s data integrity guidance expects routine audit trail review, which is only survivable if the system surfaces exceptions instead of demanding a manual read of everything.

Where would you be cited tomorrow?

Eight questions, scored instantly across the areas inspectors sample. No email required to see your result.

Take the Free Assessment
← All field notes Book a personalized demo → RELATED: Part 11 compliance → Document Control module →
KEEP READING
COMPLIANCE The Part 11 compliance hub Read → FIELD NOTES Data integrity: ALCOA+, explained Read → FIELD NOTES QMS validation: IQ/OQ/PQ Read →