1. Decide which records and signatures are in scope

Start with the applicable FDA recordkeeping requirement—the predicate rule. For each required record, document whether the organization maintains or relies on the electronic record instead of paper to perform the regulated activity. Include records submitted electronically and electronic signatures intended to replace required handwritten signatures.

Do not infer scope from the presence of a computer or PDF. Name the record, its predicate requirement, its official form, the regulated activity that relies on it, retention period, and the reason Part 11 applies or does not apply.

2. Trace each in-scope record across the implemented workflow

Map where the record is created, modified, reviewed, signed, maintained, archived, retrieved, transmitted, and retired. Identify the system responsible at each stage, the interfaces between systems, and any paper and electronic components that together preserve the complete content and meaning.

For a routine assay analysis, trace the original plate-reader record, approved method, analysis inputs and results, retained report, any review or signature, and downstream laboratory filing. A transfer of custody or format is a control point, not the end of the record.

Minimum record-scope decision
Record questionDocumented answer
Why is it required?Predicate rule or submission requirement
Which form is relied on?Electronic, paper, or defined hybrid
Where is it controlled?System of record and responsible process owner
What preserves its meaning?Data, metadata, context, signatures, and linked records
How long must it remain available?Approved retention and retrieval requirement

3. Map applicable controls to the record and its risks

Evaluate the implemented technical and procedural controls that make each in-scope record trustworthy, reliable, and retrievable. Size the evidence using the record’s effect on product quality, safety, and data integrity; document why a control applies and how it is provided.

For a closed system, § 11.10 organizes the review around validation, complete copies, protection and retrieval, authorized access, audit trails, operational and authority checks, device or input checks where appropriate, trained personnel and accountability, and documentation controls. Open systems add measures appropriate to their additional risk.

Control areaEvidence to inspect
Accuracy and intended performanceApproved requirements, risk assessment, configuration, verification, customer tests, deviations, and release conclusion
Copies and retentionComplete human-readable and electronic output, preserved content and meaning, protection, retrieval, and archive tests
Access and checksUnique accounts, approved roles, authorization changes, enforced sequence, authority decisions, and input-source controls
Recorded changesOriginal and changed values, actor, time, reason where required, protection, retention, and review procedure
People and documentsTraining, signature-accountability policy, controlled procedures, system documentation, and change control

4. Evaluate electronic signatures only where they are used

For each in-scope signature, identify the record signed, signer, date and time, and meaning such as review, approval, responsibility, or authorship. Confirm the readable manifestation required by § 11.50 and the record linkage required by § 11.70 so the signature cannot be excised, copied, or transferred to falsify another record.

Also assess uniqueness, identity verification, credential controls, loss management, and the organization’s policy holding individuals accountable for actions under their electronic signatures. A button labeled “Approve” is not enough evidence.

5. Resolve technical and procedural gaps

Record every unmet or partially met requirement, the affected record and risk, compensating control if justified, owner, due date, verification evidence, and residual risk. A procedure can govern human behavior; it should not be used to claim that an absent application control is technically enforced.

Test representative normal and failure paths in the approved configuration, including unauthorized actions, invalid sequence, record change, retrieval, copy generation, signature linkage, interface failure, and recovery as applicable. Preserve protocol deviations and their approved disposition.

6. Approve a record-by-record conclusion

The assessment should state which records and signatures are in scope, which controls apply, the evidence reviewed, executed tests, unresolved gaps, residual risk, and whether the implemented workflow is authorized for the defined use. Avoid a free-standing conclusion that software is universally “Part 11 certified.”

Reassess the conclusion when predicate-rule use, electronic reliance, configuration, interfaces, procedures, records, suppliers, or software releases change. The approved scope and evidence identify what must be revisited.

Limits and where a controlled workflow helps

Provenarium's controlled routine workflow is not currently claimed to be 21 CFR Part 11 compliant. FDA does not certify software, and each customer must validate or qualify its configured workflow for intended use. Provenarium can preserve source and configuration identity, method lineage, locked execution, result history, reports, and exact-record method-approval signatures.

Responsibility remains with the regulated organization: each customer determines applicability and validates or qualifies the configured workflow—including procedures, users, interfaces, retention, audit-trail review, downstream filing, and release decisions—for intended use.

Frequently asked questions

Can software be “Part 11 certified”?

FDA does not certify a software product for every use. A defensible conclusion addresses the applicable electronic records and signatures in the implemented system, its procedures, and the evidence for the defined use.

Is an audit log the same as a compliant audit trail?

Not automatically. Evaluate whether it covers the regulated changes and required metadata, protects prior information, remains retained and available, and is reviewed under an appropriate procedure.

Does Part 11 require electronic signatures?

Part 11 governs electronic signatures when they are used as the equivalent of required handwritten signatures or general signings. The predicate rule and actual process determine which signatures are required.

Primary references