Guides

21 CFR Part 11 when you have no compliance department

Some Part 11 clauses are met by software. Others can only be met by procedures you write. Buying the first does not give you the second.

Updated · 6 min read

21 CFR Part 11 sets the conditions under which the FDA accepts electronic records and electronic signatures instead of paper.

It splits into two halves. Some clauses are met by software. Others can only be met by procedures the company writes and follows. A vendor can supply the first half. No vendor can supply the second.

Companies without a compliance department usually buy good software and stop there. The gap is in the second half.

What the software has to do

These clauses are met by the system, and you should ask a vendor to show each one.

ClauseRequirement
§11.10(b)Produce accurate and complete copies of records, for inspection
§11.10(c)Protect records for their whole retention period
§11.10(d)Limit access to authorized individuals
§11.10(e)A secure, computer-generated, time-stamped audit trail
§11.10(g)Authority checks, so only permitted people can act
§11.50Every signature shows the printed name, the date and time, and the meaning
§11.70Each signature is linked to its record and cannot be transferred
§11.200A signature uses two distinct components, and only its genuine owner can use it

Ask for a demonstration of §11.10(b) in particular. A system that exports a record without its audit trail and its signatures has not produced a complete copy.

What only you can do

These clauses describe people and procedures. Software cannot satisfy them.

The certification letter

§11.100(c) requires something that is not software and not an SOP.

Before or at the time you first use electronic signatures, you must certify to the FDA that the electronic signatures in your system are intended to be the legally binding equivalent of handwritten signatures.

Three details matter:

It is one letter. It is also the Part 11 requirement small companies most often miss, because it is the only one that does not look like software or like a procedure.

A practical order

  1. Confirm the software meets the §11.10 and §11.50 clauses above. Ask for demonstrations, not statements.
  2. Write the accountability policy required by §11.10(j).
  3. Write the account and password procedure required by §11.300.
  4. Send the §11.100(c) certification before first use.
  5. Train the users, and keep the training records.
  6. Validate the system for your intended use.

Only step one is bought. The rest is written, and none of it is long.

What Hemeralis provides

A clause-by-clause mapping is available on request.

What Hemeralis does not provide

Hemeralis does not write your accountability policy, your account procedure or your training records. It does not send the §11.100(c) certification. It does not validate your instance.

Those are the second half of Part 11, and they stay with the company that uses the system.

What validation involves, and who is responsible. What a QMS costs.