Indelio
AI-native quality management · 21 CFR Part 11 / GAMP 5
Start free trialSign in
← Resources

The 21 CFR Part 11 Compliance Checklist (2026)

August 11, 2026 · 7 min read

The moment you keep an FDA-required record electronically — a signed SOP, a released design output, a closed complaint — instead of on paper, 21 CFR Part 11 applies. It's the FDA's rule for when electronic records and electronic signatures are trustworthy enough to stand in for paper and ink. And a point that trips up a lot of small teams: the QMSR shift in February 2026 changed Part 820, but it did not touch Part 11. Part 11 still applies, unchanged, to every electronic record and signature in your quality system.

This is a practical checklist — not the regulation reprinted, but the things an investigator actually looks for, grouped the way you'd verify them.

First: does Part 11 even apply to you?

Part 11 applies when you use electronic records or electronic signatures in place of paper for records the FDA requires. If your SOPs, training records, CAPAs, design history, or complaint files live in software and you rely on them instead of a paper original, you're in scope. Keeping a Word file on a shared drive and printing/wet-signing the "real" copy is not an electronic-record system — it's paper with an electronic draft, and it comes with its own problems (version control, lost signatures, no audit trail). Most teams are better served getting Part 11 right than trying to stay out of scope.

The checklist

System controls (closed systems — §11.10)

  • The system is validated. You have documented evidence it does what it's supposed to and that records are accurate and reliable (IQ/OQ/PQ, or a risk-based CSA equivalent). A vendor's validation of their software doesn't fully cover your installed instance — some validation is yours.
  • Records can be produced in human-readable and electronic form for inspection and copying. An investigator can get a complete, accurate copy.
  • Records are protected and retained for their full required retention period, and remain retrievable and readable the whole time.
  • Access is limited to authorized individuals — role-based, so people can only do what their role permits.
  • There is a secure, computer-generated, time-stamped audit trail that records who did what and when, and — critically — that does not overwrite prior entries. The audit trail must be as durable as the record itself and available for review and copying.
  • Operational and authority checks enforce the correct sequence of steps and ensure only authorized people take a given action (e.g., only an approver can approve).
  • The people who administer and use the system are qualified to do so (training records).

Electronic signatures (§11.50, §11.70, §11.100)

  • Each signature shows its manifestations (§11.50): the printed name of the signer, the date and time of signing, and the meaning of the signature (authored, reviewed, approved, etc.). All three, visible on the record and any copy.
  • Signatures are linked to their records (§11.70) so a signature can't be cut, copied, or transferred to falsify another record.
  • Each electronic signature is unique to one individual and is never reused or reassigned (§11.100).
  • The organization verified the identity of the individual before issuing their signing credentials.

Signature components & password controls (§11.200, §11.300)

  • A non-biometric electronic signature uses two components — typically a user ID and a private password. When signing several records in a continuous session, both components are used for the first signing and at least one for each subsequent one; if the session breaks, both are required again.
  • Signing is genuinely re-authenticated at the moment of signing — not just "you're logged in, so it counts." The password (or second factor) is entered to sign.
  • Identification codes and passwords are controlled (§11.300): uniqueness (no two people share credentials), periodic password aging/revision, a procedure to deauthorize lost or compromised credentials, and safeguards against unauthorized use (e.g., lockout after failed attempts, transaction monitoring).

Procedures & people (often the real gap)

  • You have SOPs for system use, security, e-signatures, and record retention — and people are trained on them.
  • There is a policy holding individuals accountable for actions taken under their electronic signature (deterrence of falsification).
  • Change control governs changes to the validated system, so it stays validated.

The gaps that actually get cited

  • An "audit trail" that can be edited or deleted. If a superuser or the database admin can quietly alter history, it isn't an audit trail. It has to be tamper-evident and append-only.
  • Signatures without a meaning. A name and a timestamp aren't enough — the record has to say what the signature attests to.
  • Shared logins. One account used by the whole team destroys attributability and fails §11.100 and §11.300 outright.
  • "Log in once, sign all day." If the system doesn't re-verify identity at the moment of signing, the signatures are weak.
  • Validation that stops at the vendor. Assuming the vendor's validation covers everything, with no qualification of your own configured, installed instance.

How a modern eQMS closes it

Part 11 is very achievable with the right system — most of the checklist becomes built-in rather than something you police. A purpose-built eQMS enforces role-based access and segregation of duties server-side; captures a tamper-evident, append-only audit trail (a hash-chained trail makes any alteration detectable); applies two-component electronic signatures that re-verify identity at the moment of signing and bind the signature to the exact record content and its meaning; and manages retention and change control as part of how it works, not as a manual chore. Combined with an independent validation approach against your own instance, that turns Part 11 from a scramble into a non-event.

Indelio is built to be Part 11–ready out of the box for small device, biotech, and SaMD teams — append-only hash-chained audit trail, two-component e-signatures bound to the signed record, enforced segregation of duties, and a validation package you execute against your own tenant. If your electronic records live in general-purpose tools today, this is the checklist to run before an inspector runs it for you.

See if Indelio fits your quality system
A right-sized, AI-native 21 CFR Part 11 eQMS for small device and biotech teams. Three founding-partner spots open now — or start a 30-day free trial.
Book a 20-minute lookSee pricing
← More resources