This course provides a comprehensive examination of 21 CFR Part 11
the FDA regulation governing electronic records and electronic
signatures in all FDA-regulated industries. Originally published in
1997 and last amended in March 2023, Part 11 establishes the criteria
under which FDA considers electronic records and electronic signatures
to be trustworthy, reliable, and legally equivalent to paper records
and handwritten signatures.
The course covers the scope of Part 11 and when it applies including
the critical distinction between open and closed systems. All key
definitions in §11.3 are examined: electronic record, electronic
signature, digital signature, biometrics, open system and closed
system.
The 11 mandatory controls for closed systems under §11.10 are covered
in full including system validation, the generation of accurate
copies, record protection, access limitation, audit trails, operational
and authority checks, device checks, personnel qualification, written
accountability policies, and system documentation controls. Particular
emphasis is placed on §11.10(e) audit trail requirements the most
frequently cited Part 11 finding in FDA warning letters including
what must be captured, what must not happen to original data, retention
requirements, and FDA inspection access rights.
Additional controls required for open systems under §11.30 are
addressed, including document encryption and digital signature
standards. Signature manifestation requirements (§11.50) and
signature/record linking (§11.70) are examined in full, along with
the three core electronic signature requirements of §11.100
uniqueness, identity verification, and non-repudiation certification
to FDA. The two-component authentication requirements and biometric
signature controls of §11.200, and the five password management
controls of §11.300, are covered in detail.
The course concludes with a dedicated slide mapping Part 11
requirements to their corresponding 21 CFR §211.68 CGMP counterparts
demonstrating how violations of Part 11 frequently constitute
simultaneous data integrity violations under CGMP.
Suitable for: IT and CSV teams, QA managers, regulatory affairs,
laboratory personnel, manufacturing operations, and all personnel
involved in implementing, validating, or using computerized systems
for FDA-regulated records and signatures.
Approx. 35 minutes | 5 assessment questions | Certificate on completion
Source: 21 CFR Part 11, eCFR, last amended 2 March 2023 |
ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11