Identify the electronic records and applicable requirements
Begin with the electronic records that applicable FDA requirements—often called predicate rules—require your organization to keep. Document how those records are created, changed, maintained, archived, retrieved, transmitted, or signed. Source files, plate maps, calculations, settings, reviews, reports, and dispositions may play different roles.
Document where each record is created and controlled, including transfers between systems. Copying a result to a LIMS does not remove the need to retain its source data and analysis settings, and a PDF alone may not contain every record needed to reconstruct the work.
Evaluate controls in the implemented workflow
Consider validation for intended use, record accuracy and retrieval, access authorization, operational and authority checks, audit trails where applicable, device or input checks where appropriate, training and accountability, documentation controls, retention, and change control.
Electronic signatures introduce additional identity, linking, manifestation, and policy questions. Do not advertise signatures merely because a UI has an “Approve” button.
| Area | Questions to ask |
|---|---|
| Identity and access | Are users unique, authorized, reviewed, and removed appropriately? |
| Records | Can complete, accurate, human-readable and electronic copies be retrieved? |
| Audit trail | Which regulated changes are captured, with who/what/when/why? |
| Signatures | How are identity, intent, meaning, and record linkage maintained? |
| Validation/change | How is intended use tested and release impact assessed? |
Evaluate the complete assay record, not the PDF alone
Trace one analysis from the original plate-reader file through the selected sheet or channel, plate map, concentration calculations, model and settings version, exclusions, diagnostics, suitability outcomes, result, report, review, and any approval or signature. The required controls must protect the relevant records throughout that path.
Provenarium connects the source data, analysis configuration, results, exclusions, software version, and report. Your Part 11 assessment should place those records within the implemented access, review, audit-trail, signature, retention, backup, validation, and operating procedures used by your organization.
Frequently asked questions
Can software be “Part 11 certified”?
Treat broad certification language cautiously. Compliance applies to regulated use of electronic records and signatures within an implemented system and procedures, not to a software binary in every context.
Is an audit log the same as a compliant audit trail?
Not automatically. Evaluate coverage, metadata, security, retention, review, time, meaning, and relationship to regulated records and applicable requirements.
Does Part 11 require electronic signatures?
Part 11 addresses electronic signatures when they are used for applicable records. Determine record and signature requirements from predicate rules and the organization’s process with qualified experts.