21 CFR Part 11 when you have no compliance department
Some Part 11 clauses are met by software. Others can only be met by procedures you write. Buying the first does not give you the second.
21 CFR Part 11 sets the conditions under which the FDA accepts electronic records and electronic signatures instead of paper.
It splits into two halves. Some clauses are met by software. Others can only be met by procedures the company writes and follows. A vendor can supply the first half. No vendor can supply the second.
Companies without a compliance department usually buy good software and stop there. The gap is in the second half.
What the software has to do
These clauses are met by the system, and you should ask a vendor to show each one.
| Clause | Requirement |
|---|---|
| §11.10(b) | Produce accurate and complete copies of records, for inspection |
| §11.10(c) | Protect records for their whole retention period |
| §11.10(d) | Limit access to authorized individuals |
| §11.10(e) | A secure, computer-generated, time-stamped audit trail |
| §11.10(g) | Authority checks, so only permitted people can act |
| §11.50 | Every signature shows the printed name, the date and time, and the meaning |
| §11.70 | Each signature is linked to its record and cannot be transferred |
| §11.200 | A signature uses two distinct components, and only its genuine owner can use it |
Ask for a demonstration of §11.10(b) in particular. A system that exports a record without its audit trail and its signatures has not produced a complete copy.
What only you can do
These clauses describe people and procedures. Software cannot satisfy them.
- §11.10(a). Validation. The system must be validated for your intended use. Responsibility stays with you.
- §11.10(i). Training. The people who use, develop or maintain the system must have the education, training and experience to do so. You keep the records.
- §11.10(j). A written accountability policy. You must hold individuals accountable for actions taken under their electronic signature, in writing. This is a short SOP, and it is frequently missing.
- §11.300. Password and account procedures. The software enforces the rules. You write the procedure for issuing accounts, handling a lost password and reviewing access.
- §11.10(k). Document controls. Your own procedures for the documentation of the system.
The certification letter
§11.100(c) requires something that is not software and not an SOP.
Before or at the time you first use electronic signatures, you must certify to the FDA that the electronic signatures in your system are intended to be the legally binding equivalent of handwritten signatures.
Three details matter:
- The certification must be signed with a traditional handwritten signature. That requirement has not changed.
- It may be submitted in electronic or paper form. FDA publishes the current route on its page for Letters of Non-Repudiation Agreement. Check it, because the submission method has changed since the regulation was written.
- It is submitted once, for the organization, rather than once per system.
It is one letter. It is also the Part 11 requirement small companies most often miss, because it is the only one that does not look like software or like a procedure.
A practical order
- Confirm the software meets the §11.10 and §11.50 clauses above. Ask for demonstrations, not statements.
- Write the accountability policy required by §11.10(j).
- Write the account and password procedure required by §11.300.
- Send the §11.100(c) certification before first use.
- Train the users, and keep the training records.
- Validate the system for your intended use.
Only step one is bought. The rest is written, and none of it is long.
What Hemeralis provides
- An append-only, hash-chained audit trail, enforced by the database rather than by an application check.
- Electronic signatures with two authentication factors, each bound to one record and one action, and usable once.
- Printed name, date, time and meaning rendered on every signed record.
- A compliance export containing the record, its audit trail, its signatures and a list of every attached file with its checksum, including files that were removed.
- Five levels of access control, all enforced on the server.
- Identity, passwords and multi-factor authentication managed by Amazon Cognito.
A clause-by-clause mapping is available on request.
What Hemeralis does not provide
Hemeralis does not write your accountability policy, your account procedure or your training records. It does not send the §11.100(c) certification. It does not validate your instance.
Those are the second half of Part 11, and they stay with the company that uses the system.
What validation involves, and who is responsible. What a QMS costs.