Skip to content
Entourage

Do your electronic records and signatures pass an FDA data integrity review under 21 CFR Part 11?

21 CFR Part 11 is the FDA regulation for electronic records and electronic signatures in GxP environments, requiring tamper-evident audit trails, unambiguous user authentication and ALCOA+ compliant data integrity. In the EU, EU GMP Guide Annex 11 applies in parallel. The weak point is rarely the signature itself, but the audit trail: anyone who only reviews it at inspection time, rather than checking it regularly during routine operation, discovers the gap at the same moment as the inspector.

  • Pharma
  • Biotech
  • MedTech
  • IVD

Overview

What requirements do 21 CFR Part 11 and data integrity place on your systems?

Part 11 hardening across pharma, biotech, MedTech & IVD · 21 CFR Part 11, EU GMP Guide Annex 11, GAMP 5

Last updated: 2026-06-13

Data integrity does not mean filing documents as PDFs. 21 CFR Part 11 requires provable, immutable system histories from the moment data is created. The four points at which GxP systems most often draw findings during inspection:

  • Tamper-evident audit trail: Do the audit trails run continuously at the system level, are they enabled and protected against subsequent alteration, including by administrators? 21 CFR Part 11 and Annex 11 require a traceable record of every relevant change.
  • Unambiguous authentication and e-signature: Shared logins, lack of attributability and weak access rights are among the most common data integrity findings. Electronic signatures under 21 CFR Part 11 must be individually attributable, linked to name, date and the meaning of the signature, and non-transferable.
  • ALCOA+ across the entire data lifecycle: From creation through long-term archiving, data must remain attributable, legible, contemporaneous, original and accurate, supplemented by complete, consistent, enduring and available, grounded in the MHRA and FDA data integrity guidance.
  • Hybrid systems and suppliers: The media break between a paper signature and an electronic record, as well as GxP data outsourced to SaaS and cloud infrastructure, must be safeguarded against 21 CFR Part 11, Annex 11 and EU GMP Guide Chapter 4.

Services

How we support you

Part 11 gap analysis

Systematic review of all GxP-critical electronic systems against 21 CFR Part 11. Deliverable: a prioritized remediation plan with identified gaps in access controls, e-signature mechanisms, audit trail configuration and backup concepts.

ALCOA+ data integrity audit

Review of your processes along the ALCOA+ dimensions in line with the MHRA and FDA data integrity guidance. Deliverable: an audit report covering exposed data silos and inconsistencies together with corrective actions, before an authority finds them.

Audit trail & e-signature design

Architecture and configuration of tamper-evident audit trails and Part 11 compliant e-signature processes with individual attribution, signature meaning and time stamp. Deliverable: a documented configuration specification and an audit trail review SOP.

GxP IT supplier assessment

Vendor assessment of your software suppliers and cloud providers against 21 CFR Part 11, Annex 11 and EU GMP Guide Chapter 4. Deliverable: a supplier audit report assessing the outsourced electronic records.

Validation in line with GAMP 5

Risk-based computer system validation in line with GAMP 5, covering Part 11 and Annex 11 requirements. Deliverable: validation documentation for the system concerned.

Learn more

Inspection readiness for GxP IT

Preparation of your IT systems for FDA and EU inspections, including audit trail review routines and provision of system log files. Deliverable: an inspection readiness assessment of the GxP system landscape.

Learn more

What it comes down to

Data integrity under 21 CFR Part 11 is not decided at the electronic signature, but on three strands that have to fit together in the right order: Unambiguous authentication establishes who is accountable for a record. The audit trail must capture every change to that record at the system level and in a tamper-evident way. And the ALCOA+ review must demonstrate that the data remains attributable, complete and unchanged across its entire lifecycle. Anyone who hardens the signature processes but leaves the audit trail switched off or never reviews it has the most expensive gap precisely where the inspector looks first.

This is why the work begins with the gap analysis and not with configuration: it reveals which system is the critical one before audit trail routines are written and suppliers are assessed. Validation in line with GAMP 5 provides the technical foundation, but it only covers Part 11 once audit trail review and access control are explicitly part of routine operation. Data integrity is a continuous process, not a one-time filed record, and for the EU, EU GMP Guide Annex 11 requires the same end-to-end rigor that the FDA requires for the United States.

Our approach

Our approach

01

System inventory & scoping

A list of GxP-critical electronic systems with risk classification and a defined review scope.

02

Part 11 gap analysis

A prioritized remediation plan: identified gaps in audit trail, access control and e-signature against 21 CFR Part 11.

03

ALCOA+ data integrity audit

A report on exposed data silos and inconsistencies along the ALCOA+ dimensions, with corrective actions.

04

Audit trail & signature design

Documented configuration of tamper-evident audit trails and Part 11 compliant e-signatures, including a review SOP.

05

Supplier & cloud assessment

Vendor audit reports for SaaS and cloud providers against 21 CFR Part 11 and Annex 11.

06

Inspection readiness

An established audit trail review routine and system log files available on demand for FDA and EU inspections.

Common pitfalls

Where projects commonly fail

Shared logins and excessive administrator rights.

Multiple users on the same account, or administrator rights for regular users, destroy attributability under ALCOA+ and are among the most common data integrity findings. 21 CFR Part 11 requires individual, non-transferable authentication.

The audit trail is not enabled or is never reviewed.

An audit trail that exists at the system level but is switched off or never reviewed satisfies neither 21 CFR Part 11 nor Annex 11. Without a documented audit trail review routine, the gap remains undetected until inspection.

Raw data can be overwritten or deleted without a trace after the fact.

If original data can be altered without a trace in the audit trail, data integrity under ALCOA+ is not in place. A finding of this kind quickly escalates from a single system to the entire quality system.

Hybrid systems without a defined original.

With a paper-plus-electronic record, there is often no determination of which medium is the original, nor synchronization of the paper signature with the digital metadata. Annex 11 and 21 CFR Part 11 require a validated, clearly governed media break.

Cloud and SaaS data without a supplier assessment.

GxP data is hosted on outsourced infrastructure without the provider being assessed against 21 CFR Part 11, Annex 11 and EU GMP Guide Chapter 4. Responsibility for the outsourced records remains with the regulated company.

FAQ

Frequently asked questions

ALCOA+ is the reference framework for data integrity: attributable, legible, contemporaneous, original and accurate, supplemented by complete, consistent, enduring and available. 21 CFR Part 11 and the MHRA and FDA data integrity guidance presuppose these principles for electronic records.

Sources
  • 21 CFR Part 11 (FDA, Electronic Records; Electronic Signatures), primary text
  • EU-GMP-Leitfaden Annex 11 (Computerised Systems) and Kapitel 4 (Documentation), primary text
  • GAMP 5 (ISPE), MHRA 'GXP' Data Integrity Guidance, FDA Guidance for Industry: Data Integrity and Compliance With Drug CGMP
  • Entourage writer material (Briefing 21-cfr-part-11-datenintegritaet, as of 2026-05-11)
  • https://theentourage.de/regulatory-compliance/21-cfr-part-11-datenintegritaet/ (existing page content, revised)

Life Science Journal

Regulatory updates, straight to your inbox.

New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.

Regulations & standards considered

  • 21 CFR Part 11 (FDA, Electronic Records; Electronic Signatures)
  • EU-GMP-Leitfaden Annex 11 (Computerised Systems)
  • EU-GMP-Leitfaden Kapitel 4 (Documentation)
  • GAMP 5 (ISPE, A Risk-Based Approach to Compliant GxP Computerized Systems)
  • ICH Q9 (Quality Risk Management)
  • MHRA 'GXP' Data Integrity Guidance and Definitions
  • FDA Guidance for Industry: Data Integrity and Compliance With Drug CGMP

Have a concrete project?

Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.

Prefer direct? +49 89 4161170-0
info@theentourage.de

  • Reply usually within one working day
  • 4 offices: DE · CH · IT · US
  • 100% life sciences