WebOfPharma · Pharmaceutical Computerized System Validation
21 CFR Part 11 Validation Requirements
A practical, risk-based guide to validating electronic records and electronic signatures used in pharmaceutical quality, laboratory, manufacturing, and regulatory processes.
Quick answer
21 CFR Part 11 validation is documented evidence that a computerized system reliably creates, modifies, maintains, retrieves, and transmits regulated electronic records and applies trustworthy electronic signatures. A defensible program verifies intended use, record integrity, access control, audit trails, system checks, signatures, retention, and ongoing change control. Part 11 is not satisfied by a single test script; it is a lifecycle control supported by predicate rules, risk assessment, procedures, training, and approved evidence.
Scope
What is regulated?
Electronic records and signatures relied on to meet FDA requirements or support regulated decisions.
Evidence
What must be shown?
The system performs its intended use consistently and preserves complete, trustworthy records.
Controls
What is tested?
Access, audit trails, signatures, copies, retention, interfaces, workflow checks, and recovery.
Lifecycle
What continues?
Periodic review, security, backup, change control, incident response, training, and decommissioning.
What Is 21 CFR Part 11?
21 CFR Part 11 is the U.S. FDA regulation that establishes criteria for when electronic records and electronic signatures may be considered trustworthy, reliable, and generally equivalent to paper records and handwritten signatures.
In pharmaceutical operations, Part 11 becomes relevant when an electronic record is created or retained to satisfy an FDA predicate rule, or when an electronic signature is used to sign a record required by that regulated activity. Examples include laboratory results, batch records, deviation approvals, change-control decisions, stability records, training records, release approvals, and quality-system investigations.
For a broader quality foundation, connect the validation strategy to cGMP requirements and the site pharmaceutical quality system.
Part 11, Predicate Rules, and Validation: How They Fit Together
Part 11 provides electronic-record and electronic-signature controls, but it does not replace the underlying GMP, laboratory, manufacturing, clinical, or submission requirements that make a record necessary. Validation connects the two: it demonstrates that the system can produce and protect the record required by the predicate rule.
| Layer | Question to answer | Validation implication |
|---|---|---|
| Predicate rule | What regulated activity or record must be controlled? | Define the business process, critical data, approvals, retention, and quality decision. |
| Part 11 | How will the electronic record or signature remain trustworthy? | Test security, audit trails, copies, signatures, system checks, and record linkage. |
| GMP quality system | How will people operate, review, maintain, and change the system? | Approve procedures, roles, training, incident handling, change control, and periodic review. |
| Validation evidence | What objective evidence supports the release decision? | Maintain traceability from intended use and risks to protocols, results, deviations, and approval. |
Core 21 CFR Part 11 Validation Requirements
For a closed system, §11.10 describes controls that support trustworthy records. The validation package should convert each applicable control into a clear requirement, test, review, or procedural control.
| Control area | What the validation should demonstrate | Typical evidence |
|---|---|---|
| System validation | The system is accurate, reliable, performs its intended functions, and can identify invalid or altered records where appropriate. | Approved plan, risk assessment, URS, traceability matrix, executed tests, deviation assessment, and validation summary. |
| Accurate and complete copies | Records can be generated in human-readable and electronic form for review, inspection, and retention. | Export tests, report comparison, metadata check, print/PDF review, file-format and retrieval evidence. |
| Record protection | Records remain protected from accidental or unauthorized alteration, deletion, or loss throughout their retention period. | Access tests, retention configuration, backup/restore challenge, archive retrieval, and security procedures. |
| Limited system access | Only authorized, trained users can access functions and records appropriate to their roles. | Role matrix, user-provisioning test, segregation-of-duties review, lockout test, and periodic access review. |
| Time-stamped audit trails | Creation, modification, and deletion events are recorded with a secure time stamp and preserve the prior information. | Audit-trail challenge, time-zone review, old/new value comparison, reason-for-change test, review SOP, and sample report. |
| Operational and authority checks | The system enforces required steps, approvals, sequence, limits, and role-based decision rights. | Workflow test, blocked-step test, approval test, limit challenge, exception handling, and negative test results. |
| Device and data-input checks | Input sources, instruments, interfaces, and devices are identified and controlled where they affect record accuracy. | Interface mapping, device challenge, checksum or reconciliation test, instrument identity, and error-handling evidence. |
| Training and written policies | People who develop, maintain, or use the system have appropriate training and follow approved data-management policies. | Training records, role descriptions, SOPs, policy acknowledgements, and competency checks. |
| Documentation controls | System documentation is controlled, current, accessible, and protected from unauthorized modification. | Version history, approval workflow, configuration baseline, release notes, and controlled document repository. |
Open systems require the applicable closed-system controls plus additional safeguards appropriate to the environment, such as stronger authentication, encryption, digital-signature controls, secure transmission, or other measures that protect authenticity, integrity, and confidentiality.
21 CFR Part 11 Validation Lifecycle
A lifecycle approach prevents teams from treating Part 11 as a final checklist. The validation strategy should begin before configuration and continue through operation, upgrades, migration, and retirement.
Step 1: Define Intended Use and Regulated Records
Validation becomes testable only after the intended use is specific. “The system manages laboratory data” is too broad. A stronger statement identifies the laboratory process, data sources, calculations, decisions, users, records, reports, and interfaces that the system controls.
Questions for the intended-use statement
- Which product, process, laboratory, quality, clinical, or regulatory activity does the system support?
- Which electronic records are relied upon to make a GMP decision or demonstrate compliance?
- Which data are original, derived, imported, exported, or summarized?
- Which users can create, review, approve, release, change, void, or delete data?
- Where are audit trails, electronic signatures, metadata, reports, and archived copies stored?
- What would happen if the system produced an incorrect result, lost an audit trail, or allowed an unauthorized approval?
Document the intended use in the URS and connect each critical statement to a risk, control, test, and approval decision.
Step 2: Build a Part 11 Risk Assessment
A risk assessment helps determine how much validation evidence is appropriate. It does not justify ignoring a required control; it explains the depth, method, and priority of the assurance work.
| Risk question | Example high-risk condition | Possible assurance response |
|---|---|---|
| Could an error affect a release or patient-safety decision? | A calculation or result is used to release a batch. | Detailed requirements, boundary tests, independent review, audit-trail challenge, and controlled approval. |
| Could a user change data without detection? | Results can be overwritten or reprocessed without a visible history. | Role testing, audit-trail testing, reason-for-change controls, review procedure, and periodic samples. |
| Could a signature be misused? | Shared credentials or a signature not linked to the signed record. | Unique IDs, password controls, signature manifestation, record linkage, and misuse challenge. |
| Could data be lost or become unavailable? | Cloud archive or interface failure prevents retrieval of batch history. | Backup/restore tests, disaster-recovery evidence, retention review, and retrieval time objective. |
| Could an interface corrupt or omit data? | Instrument results are transferred into LIMS without reconciliation. | Interface mapping, positive/negative transfer tests, reconciliation, error queue review, and monitoring. |
Use ALCOA+ principles to evaluate whether records are attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available throughout the system lifecycle.
Step 3: Write Requirements and Traceability
Every critical Part 11 requirement should have a clear owner, an acceptance criterion, and a planned verification method. A traceability matrix makes it possible to show that no critical requirement was left untested.
| Requirement example | Verification | Acceptance evidence |
|---|---|---|
| Each user must have a unique account and role-appropriate access. | Functional and negative access tests. | Unauthorized action is blocked; user ID and role are recorded. |
| Changes to approved results must preserve original values and reason. | Audit-trail challenge and report review. | Old/new values, user, timestamp, reason, and record link are visible. |
| Electronic approval must be linked to the exact record version. | Signature and version-control test. | Signature manifestation and record linkage remain intact after retrieval. |
| Records must be retrievable in human-readable and electronic form. | Search, export, print, and archive retrieval test. | Required content and metadata are complete, readable, and usable. |
Use an approved SOP structure for requirements, testing, deviations, approvals, and controlled changes. Do not rely on screenshots alone when a system-generated report, audit trail, or electronic evidence is needed to prove behavior.
Step 4: Validate Access Controls and Security
Access control is a foundational Part 11 control because a trustworthy record depends on knowing who performed each action and preventing unauthorized functions.
- Unique user IDs are issued to individuals, never shared teams.
- Roles follow least privilege and documented segregation of duties.
- Creation, modification, disabling, and deletion of accounts are controlled.
- Password, lockout, expiration, and reset rules are configured and tested.
- Administrators cannot silently change regulated data or bypass review.
- Emergency or break-glass access is time-limited, approved, and reviewed.
- Periodic access reviews confirm that leavers and transfers are removed promptly.
- Service accounts and interfaces have named owners and documented credentials.
Include both positive tests (an authorized user can complete the intended task) and negative tests (an unauthorized user cannot view, edit, approve, or delete restricted content).
Step 5: Validate Audit Trails
An audit trail should allow a reviewer to reconstruct what happened to a regulated record. Validation should demonstrate that relevant creation, modification, deletion, approval, reprocessing, and configuration events are captured consistently.
Audit-trail test design
- Create a representative record using an authorized user.
- Perform a permitted change, such as correcting a result with a documented reason.
- Attempt an unauthorized change or deletion and record the system response.
- Review the audit trail for user identity, date/time, old and new values, reason, and record linkage.
- Check time-zone, daylight-saving, server-clock, and timestamp behavior where relevant.
- Export or print the audit-trail report and confirm that it remains readable and complete.
- Confirm that audit-trail entries cannot be edited by ordinary users and that privileged changes are controlled.
Step 6: Validate Electronic Signatures
Electronic signatures must identify the signer, show the date and time, indicate the meaning of the signature, and remain linked to the record. Validation should cover the full signature workflow rather than only the password prompt.
| Part 11 signature element | What to verify |
|---|---|
| Uniqueness | The signature belongs to one individual and is not reused or reassigned to another person. |
| Identity verification | The system verifies identity before accepting a signature and prevents use of another person's credentials. |
| Two components, where required | Identification code and password or equivalent controlled components are protected and tested for misuse. |
| Signature manifestation | Name, date/time, and signature meaning are displayed or retrievable with the signed record. |
| Record linkage | The signature remains linked to the exact electronic record and cannot be copied to falsify another record. |
| Notification and accountability | Users understand that their electronic signature is legally accountable and report suspected compromise. |
Test approval, rejection, delegation, co-signature, cancellation, correction, re-signature, and record-version scenarios. Also test what happens when the network, authentication service, or signature service is unavailable.
Step 7: Validate Records, Copies, Retention, and Retrieval
Part 11 validation must demonstrate that records remain complete and usable throughout the retention period. A record is more than the visible value: it may include metadata, audit-trail history, calculations, approvals, attachments, instrument files, templates, and linked records.
For critical systems, include restore testing, disaster-recovery exercises, checksum or reconciliation controls, and documented recovery objectives. A backup that has never been restored is an assumption, not objective evidence.
Step 8: Apply IQ, OQ, PQ, and Functional Testing Correctly
The exact qualification labels can vary by system and organization, but the evidence must show that the controlled environment is installed or configured as approved, operates as intended, and performs reliably in routine use.
| Activity | Part 11 focus | Typical question |
|---|---|---|
| DQ | Design and intended-use fit | Does the proposed architecture support required records, controls, interfaces, signatures, security, and retention? |
| IQ | Controlled installation or configuration | Are approved versions, infrastructure, integrations, settings, accounts, and documentation present? |
| OQ | Functional and security behavior | Does the system enforce roles, workflows, audit trails, signatures, limits, and error handling? |
| PQ | Routine-use performance | Can trained users complete representative processes and produce complete, reliable records under expected conditions? |
Use DQ, IQ, OQ, and PQ evidence where appropriate, but do not force an equipment-style protocol onto a low-risk application simply because the headings are familiar. The risk assessment should determine depth and method.
Part 11 Validation for Common Pharmaceutical Systems
Part 11 controls must be applied to the actual data flow, not just the application name. A single regulated process may include several systems and interfaces.
| System or tool | High-value validation focus | Frequent risk |
|---|---|---|
| LIMS and laboratory instruments | Raw data, processing methods, reprocessing, audit trails, integrations, result approval, and report generation. | Only the final result is retained while sequence, metadata, or rejected injections are unavailable. |
| MES and electronic batch records | Recipe/version control, operator identity, step sequencing, electronic signatures, exception handling, and batch-release data. | Manual workarounds or shared credentials bypass the approved workflow. |
| QMS, deviations, and CAPA | Workflow, investigation evidence, approvals, due dates, audit trails, attachments, and closure authorization. | Records are changed after approval without a transparent history. |
| ERP or supply-chain systems | Material status, release blocks, master data, interfaces, inventory transactions, and user authority. | Interface failure or excessive access changes a quality-relevant status. |
| Spreadsheets and local databases | Formula protection, version control, input validation, access, auditability, backup, and independent review. | Uncontrolled copies, hidden formulas, overwritten cells, or unavailable change history. |
| Cloud and SaaS systems | Tenant configuration, supplier controls, data location, service changes, backups, availability, exports, and exit plan. | Vendor evidence is accepted without testing customer-specific configuration or retrieval. |
For every system, map the complete data lifecycle: source, transformation, calculation, review, approval, report, archive, migration, and disposal.
Validation Documents and Evidence Package
A Part 11 package should be easy for Quality, system owners, inspectors, and auditors to follow. Use a controlled index and preserve the relationship between requirements, risks, tests, deviations, approvals, and production evidence.
- Computerized system inventory and Part 11 applicability assessment.
- Validation or qualification plan with roles and approval gates.
- Intended-use statement and approved URS.
- Data-flow diagram, interface inventory, and record-retention map.
- Risk assessment with rationale for test depth and controls.
- Functional, security, audit-trail, signature, migration, and recovery protocols.
- Traceability matrix linking requirements to executed evidence.
- Supplier assessment, service agreement, release notes, and vendor evidence.
- Executed test results, objective evidence, and independent review.
- Deviation assessment, investigation, and approved CAPA new where needed.
- Validation summary report, residual-risk decision, and Quality approval.
- Operating SOPs, training records, access reviews, audit-trail review, backup, and incident procedures.
Keep the evidence attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available. That is the practical connection between Part 11 validation and ALCOA+ data integrity.
Change Control, Periodic Review, and Revalidation
Validation status is not permanent. A change to software, infrastructure, configuration, interface, master data, security, workflow, supplier service, or record format can affect Part 11 controls.
Change-control questions
- Does the change alter intended use, critical data, calculations, reports, or electronic signatures?
- Does it change audit-trail behavior, timestamp logic, access roles, or record retention?
- Does it affect an interface, instrument driver, middleware, cloud service, or data migration?
- Are existing test evidence, SOPs, training, and risk assessments still valid?
- Is regression testing required, and which representative records should be challenged?
- Will the change create a new version of a report, template, method, formula, or master record?
Use the established CAPA process when a deviation, data-integrity concern, or ineffective control requires root-cause action. Periodic review should assess incidents, audit-trail findings, access reviews, performance, vendor changes, backup tests, open deviations, and emerging risks.
Common 21 CFR Part 11 Validation Findings
| Finding pattern | Why it matters | Stronger practice |
|---|---|---|
| Validation tests only the happy path. | Failures, bypasses, invalid inputs, and unauthorized actions remain unchallenged. | Add negative, boundary, exception, security, and recovery tests based on risk. |
| Audit trail is enabled but not reviewed. | Important changes may remain invisible to Quality. | Define review frequency, sample logic, escalation criteria, and documented follow-up. |
| Electronic signatures are treated as a login. | Identity, meaning, linkage, and signature accountability may not be demonstrated. | Test full signature manifestation, record linkage, misuse, delegation, and co-signature. |
| Vendor validation is accepted without customer assessment. | Customer configuration, roles, workflows, interfaces, and data retention may differ. | Use supplier evidence as input, then test intended use and customer-specific risks. |
| Exports omit metadata or rejected data. | Copies may not be complete enough for review or inspection. | Compare native records, reports, audit trails, metadata, attachments, and archive copies. |
| Access reviews are informal or late. | Former users or excessive privileges can undermine attribution and segregation of duties. | Use approved periodic review, owner sign-off, timely removal, and exception tracking. |
| Spreadsheets are outside the validation inventory. | Hidden formulas, uncontrolled copies, and overwritten values can affect regulated decisions. | Classify spreadsheet risk, lock formulas, control versions, test calculations, and retain review evidence. |
Audit-Ready 21 CFR Part 11 Checklist
Use this checklist for internal readiness reviews. Mark each item as complete, partially complete, not applicable with rationale, or requiring action.
- The system is listed in the computerized-system inventory.
- Part 11 applicability is documented against predicate-rule records.
- Intended use, critical data, users, interfaces, and retention are defined.
- Risk assessment covers product quality, patient safety, data integrity, and decisions.
- Requirements include security, audit trail, signature, copy, retention, and recovery controls.
- Requirements are traceable to approved executed test evidence.
- Unique accounts and role-based access are verified.
- Audit trails capture relevant creation, modification, deletion, and approval events.
- Electronic signatures show identity, date/time, meaning, and record linkage.
- Human-readable and electronic copies are accurate, complete, and retrievable.
- Backup, restore, disaster recovery, archive, and migration controls are tested.
- Supplier evidence and customer-specific configuration are assessed.
- SOPs, training, access review, audit-trail review, and incident processes are effective.
- Changes, deviations, data-integrity events, and CAPA are assessed for revalidation impact.
- Periodic review confirms that the system remains fit for intended use.
How 21 CFR Part 11 Supports Pharmaceutical Data Integrity
Part 11 compliance is strongest when technical controls and human practices reinforce each other. A validated system can still produce unreliable records if users share passwords, bypass workflows, fail to review audit trails, or store uncontrolled copies.
| Data-integrity objective | Part 11 and lifecycle response |
|---|---|
| Attributable | Unique accounts, role control, signature identity, audit-trail user, and controlled service accounts. |
| Contemporaneous | Validated timestamps, controlled time zones, sequence checks, and procedures that prevent backdating. |
| Original and complete | Native data, metadata, audit trails, attachments, reprocessing history, and accurate copies are preserved. |
| Accurate and consistent | Validated calculations, input checks, interface reconciliation, master-data control, and change control. |
| Enduring and available | Retention, backup, restoration, archive, migration, disaster recovery, and retrieval tests. |
When a system supports a manufacturing process, link the electronic-record strategy to Process Validation in Pharmaceuticals so process data, equipment data, laboratory results, and release decisions remain connected.
Regulatory Reference Points
Use the current primary sources when confirming applicability, interpreting a control, or updating a site validation procedure:
Use in practice: Treat external guidance as a regulatory reference, then translate it into approved site procedures, risk assessments, test protocols, training, and Quality decisions for the actual system.
Key Takeaways
- 21 CFR Part 11 validation is a lifecycle program, not a one-time software test.
- Start with predicate rules and define which electronic records are relied upon.
- Use a risk-based strategy, but do not omit controls that are applicable to the system.
- Test audit trails, electronic signatures, access, record copies, retention, interfaces, and recovery.
- Vendor documentation can support assurance, but customer-specific intended use and configuration still need evidence.
- Procedures, training, periodic review, access review, and audit-trail review are part of the control system.
- Change control, incident management, and CAPA protect the validated state after release.
Conclusion
21 CFR Part 11 validation requirements are designed to make electronic records and electronic signatures dependable evidence for regulated work. The most effective programs connect intended use, predicate rules, risk assessment, system design, testing, security, audit trails, signatures, retention, and operational procedures in one traceable lifecycle.
For pharmaceutical companies, compliance is demonstrated when a trained user can perform the approved process, the system enforces the required controls, the record can be reconstructed, and Quality can explain the evidence years later. Build the strategy around product and patient risk, preserve complete data, and keep the system under control after go-live.
Related Pharmaceutical Validation Guides
Use these WebOfPharma resources to extend your electronic-record and computerized-system validation program:
Frequently Asked Questions
What is 21 CFR Part 11 validation?
It is documented evidence that a computerized system reliably performs its intended use and protects electronic records and electronic signatures used to meet FDA requirements. It includes technical testing and operational controls such as access, audit trails, procedures, training, retention, and change control.
Does 21 CFR Part 11 require every electronic file to be validated?
No. Applicability depends on whether the electronic record is required by a predicate rule or relied upon to perform or document a regulated activity. The organization should document the scope decision and rationale for each system or record type.
What are the main Part 11 validation controls?
The main controls include system validation, accurate and complete copies, record protection, restricted access, audit trails, operational checks, authority checks, device or input checks, training, written policies, and controlled system documentation.
Are electronic signatures covered by Part 11 validation?
Yes. Validation should verify unique signer identity, controlled signature components, signature manifestation, date and time, signature meaning, and permanent linkage between the signature and the exact electronic record.
What is an audit trail under 21 CFR Part 11?
An audit trail is a secure, computer-generated, time-stamped history that records relevant creation, modification, or deletion activity while preserving prior information. The system should also support controlled review and investigation of meaningful events.
Can a vendor validation package satisfy Part 11?
Vendor evidence can reduce duplicated work, but it rarely proves the customer’s complete intended use. The customer must assess supplier controls and test its own configuration, roles, workflows, interfaces, records, signatures, retention, and risk-critical functions.
Are IQ, OQ, and PQ required for every Part 11 system?
No fixed label is required for every system. The organization must provide appropriate evidence that the controlled environment is installed or configured, functions as intended, and performs reliably in routine use. IQ, OQ, PQ, functional testing, or combined approaches may be suitable based on risk.
How should spreadsheets be handled under Part 11?
Assess each spreadsheet based on its intended use and impact. Control formulas, versions, access, inputs, review, backup, change history, and calculation accuracy. A spreadsheet that supports a GMP decision should not remain an uncontrolled personal file.
What is a Part 11 traceability matrix?
It is a controlled table linking user and functional requirements to risks, design elements, test cases, results, deviations, and approval. It demonstrates that critical requirements were addressed and that validation evidence is complete.
How often should a Part 11 system be revalidated?
There is no universal calendar interval. Revalidation or focused regression testing is triggered by changes, incidents, data-integrity concerns, major configuration updates, infrastructure changes, migrations, supplier releases, or periodic-review findings. The risk assessment should define the response.
What should be tested for an electronic signature?
Test successful signing, rejection, cancellation, re-signature, co-signature, delegation where permitted, record-version linkage, signature manifestation, unique identity, credential protection, and behavior when authentication or network services fail.
What should be included in an audit-trail review procedure?
Define the systems and events covered, reviewer responsibilities, frequency, sampling logic, review tools, escalation criteria, investigation requirements, record retention, and how recurring or suspicious activity is connected to deviation and CAPA processes.
Does Part 11 validation replace GMP procedures?
No. Part 11 validation supports electronic records and signatures; it does not replace GMP procedures for manufacturing, laboratory control, release, investigations, training, document control, or quality oversight. Both technical and procedural controls are needed.
How does Part 11 relate to ALCOA+?
Part 11 provides controls that help electronic records remain attributable, accurate, complete, secure, and available. ALCOA+ is a broader data-integrity framework used to evaluate the quality and lifecycle of records, including human practices and procedures.
What evidence should be available during an FDA inspection?
Maintain the scope assessment, intended use, risk assessment, requirements, traceability, executed protocols, objective evidence, deviations, validation summary, access records, audit-trail review records, training, SOPs, change control, backup and recovery tests, and periodic-review outputs.
