Who this is for: quality professionals evaluating systems, and anyone who has been told a product is "Part 11 compliant" and wants to know what that must mean before signing.
What Part 11 covers — and the predicate rule trap
Part 11 applies when records required by other FDA regulations — the predicate rules: 210/211 for drugs, 820 for devices, 606 for blood — are kept electronically. It does not create record requirements; it sets the conditions under which electronic versions are trustworthy. First question in any assessment: which predicate rules require the records you keep?
Subpart B: the record requirements
Validated systems (11.10a). Records protected and retrievable through the retention period (11.10c). Access limited to authorized individuals (11.10d). And the one that fails most audits: secure, computer-generated, time-stamped audit trails that record changes without obscuring prior values (11.10e). A system that overwrites a corrected value — even with a log entry — fails that clause by design.
Subpart C: what makes an e-signature real
A signature must be unique to one individual (11.100), carry two identification components with re-authentication during a session (11.200), display its meaning — author, review, approval — and be bound to its record such that it cannot be excised or transferred (11.70). A checkbox that stamps a name is not a signature under any of those tests.
"Part 11 compliant" — the three questions that test the claim
One: can the audit trail be disabled, and by whom? If an administrator can turn it off, an inspector assumes it was. Two: what happens to the prior value when a record is corrected? Three: does signing require re-authentication, and is the meaning recorded? Architecture answers these; configuration hopes about them.
Note also that compliance is never the vendor’s alone — validation of your use, your procedures, and your access control stays with you. What a vendor owes you is an architecture that cannot silently fail, plus documentation that makes your validation tractable.
Data integrity: where Part 11 enforcement actually lives
Modern FDA citations rarely name Part 11 directly — they arrive as data integrity findings under the predicate rules: shared logins, batch-signed records, unreviewed audit trails. FDA’s data integrity guidance expects routine audit trail review, which is only survivable if the system surfaces exceptions instead of demanding a manual read of everything.