The 21 CFR Part 11 Compliance Checklist: A Practical Guide for Regulated Teams
A practical, downloadable-style checklist for FDA 21 CFR Part 11 compliance — covering validation, audit trails, electronic signatures, access controls, and recordkeeping.
21 CFR Part 11 is the FDA regulation that governs electronic records and electronic signatures in regulated industries — pharma, biotech, medical devices, CROs, and academic medical centers running FDA-regulated work. It's been on the books since 1997, and yet it remains one of the most consistent sources of Form 483 observations and warning letters. The reason is simple: most teams treat Part 11 as a vendor checkbox rather than an operational discipline. This checklist is designed to fix that. Work through it once a quarter and you will know — before an inspector tells you — exactly where your gaps are.
Use this as a working document. Each item maps to a specific Part 11 subsection. For each item, your goal is a yes-or-no answer backed by evidence: a validated configuration, a signed SOP, an exported audit trail, or a screenshot of the enforced control. 'We think so' is a no.
Section A — System validation (§11.10(a))
☐ Do you have a signed Installation Qualification (IQ) for every Part 11 system in current use?
☐ Do you have a signed Operational Qualification (OQ) that tests configured roles, workflows, and approvals as you actually use them — not the vendor's defaults?
☐ Has any change to the system since the last validation been captured in a change-control record with a regression-test summary?
☐ Do you maintain a current Validation Summary Report that ties IQ/OQ/PQ together and is signed by the validation lead and quality head?
Section B — Audit trail integrity (§11.10(e))
☐ Is the audit trail automatically generated for every create, update, delete, approve, and signature event — without operator action?
☐ Does the audit trail capture user identity, role, IP address, server timestamp, and before/after values?
☐ Have you confirmed (in a sandbox) that a system administrator cannot edit or delete audit-trail rows?
☐ Does the audit trail use the server clock, not the workstation clock, so a user cannot back-date entries by changing their local time?
☐ Can the audit trail be exported in a human-readable format with before/after snapshots, and is the export reproducible on demand?
☐ Is the audit trail retained for at least as long as the underlying record's retention requirement?
Section C — Electronic signatures (§11.50 and §11.70)
☐ Does every signed record render the printed name of the signer, the date and time, and the meaning of the signature (authored, reviewed, approved)?
☐ Is the signature meaning configurable per workflow, and does it appear on the rendered record — not buried in a separate audit log?
☐ Is the signature cryptographically linked to the record so that any modification invalidates the signature?
☐ Have signed records been spot-checked (pull 10 recent signatures) to confirm all three elements are present?
Section D — Authentication and identity (§11.10(d), §11.200, §11.300)
☐ Is every user account unique to one individual — no shared logins, no generic 'admin' accounts, no operator-uses-supervisor-credentials patterns?
☐ Is two-component authentication enforced for every signature event (unique user ID plus password, passkey, or SSO with MFA)?
☐ Are password policies enforced (minimum length, complexity, expiration, no reuse)?
☐ Does the system lock accounts after a configurable number of failed attempts?
☐ Is session timeout enforced for inactive users?
Section E — User lifecycle and access reviews (§11.10(d))
☐ Do you run a periodic (at least annual, ideally quarterly) user-access review reconciling active employees against active Part 11 system accounts?
☐ Is account provisioning tied to a documented joiner workflow with role assignment approved by a manager?
☐ Is account deactivation tied to the HR leaver process within one business day of termination?
☐ Are role changes (mover events) documented in a change-control record with re-training where required?
Section F — Record protection and recovery (§11.10(c))
☐ Are electronic records backed up daily, with backups tested for restoration on a documented schedule?
☐ Are records stored in a manner that protects against accidental or malicious alteration during their retention period?
☐ Is disaster recovery documented with a recovery time objective (RTO) and recovery point objective (RPO) appropriate to the criticality of the system?
Section G — Record availability for inspection (§11.10(b))
☐ Can complete, accurate copies of any electronic record be produced in both human-readable and electronic form for FDA review?
☐ Can a specific record (deviation, batch record, training record) be retrieved within 15 minutes of an inspector's request?
☐ Is the export format suitable for the inspector's review — typically PDF for human review and CSV or XML for electronic analysis?
Section H — Operational procedures (§11.10(i), §11.10(j), §11.10(k))
☐ Is every operator trained on the system before being granted access, with training documented and a competency check completed?
☐ Is there a written policy that holds individuals accountable for actions performed under their electronic signature?
☐ Is there a documented procedure for system administration, change control, and incident response?
Section I — Vendor and supplier qualification
☐ Has your Part 11 system vendor been qualified as a critical supplier with a documented audit (on-site or remote)?
☐ Do you have a Quality Agreement with the vendor covering change notification, security incident reporting, and audit rights?
☐ Do you maintain copies of the vendor's SOC 2 or equivalent certifications, and review them on renewal?
How BioTrace automates this checklist
BioTrace was designed around this checklist rather than retrofitted into it. The audit trail is append-only and cryptographically chained — there is no administrator path to edit or delete a row. Electronic signatures capture printed name, timestamp, role, IP, and explicit meaning on the rendered record. Two-component authentication is enforced through SSO with MFA. The user-access review is a one-click export reconciled against your identity provider. Records can be exported in PDF and CSV in seconds, and IQ/OQ packages plus a Validation Summary Report ship with every tenant.
None of this absolves you of running the checklist above — Part 11 is your responsibility, not your vendor's — but it dramatically shrinks the surface area of manual work each quarter, and it means the answer to most checklist items can be verified with a screenshot rather than a multi-day investigation.
Start a 14-day Professional trial to see the audit trail, electronic signatures, and validation package operating on your own configured tenant.