21 CFR Part 11 Electronic Records and Signatures

Review how the optional Telemetry2U approval and audit controls support regulated electronic-record workflows, and where customer procedures remain required.

Platform Controls and Customer Responsibilities

The optional 21 CFR Part 11 feature adds controlled approval and audit behaviour to relevant platform actions. It is enabled for individual company accounts on request.

When the feature is enabled, protected changes require confirmation by an authorised user before they can be saved. The approver enters their username and password in the 21 CFR confirmation required area at the bottom of the relevant page.

An approver must have the Confirm CFR21 Action role assigned through User Access Controls. See User Access Controls in the Administration documentation .

Approved actions are retained as audit events. They can be included in an audit report by selecting Audit events. See Creating and Editing Audit Reports .

Controlled Approvals

Relevant changes can require re-entry of an authorised user's credentials before the action is accepted.

Traceable Audit Records

Recorded events identify the time, initiating user, event type, and entity involved in the action.

Role-Based Authority

Approval is restricted to users who have been assigned the required confirmation role by an administrator.

Platform control

The platform provides a relevant technical control or record.

Platform + customer SOP

Technical controls must be supported by customer governance or procedures.

Not applicable

The requirement does not apply to the platform feature described on this page.

Regulatory requirements below are summarised from the current 21 CFR Part 11 text in the eCFR. Customers should also review the FDA guidance on Part 11 scope and application.

Section 11.10 - Controls for Closed Systems

Closed systems must use procedures and controls that protect the authenticity, integrity, and, where appropriate, confidentiality of electronic records.

11.10(a) Platform control

Validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records.

Platform alignment

Device and system audit records provide traceability for user activity and protected changes.

11.10(b) Platform control

The ability to generate accurate and complete copies of records in both human-readable and electronic form suitable for inspection, review, and copying by the agency.

Platform alignment

Reports and data exports provide readable and electronic copies for review and retention.

11.10(c) Platform control

Protection of records to enable their accurate and ready retrieval throughout the records-retention period.

Platform alignment

Stored monitoring and audit records remain available through authorised reporting and export functions.

11.10(d) Platform control

Limiting system access to authorised individuals.

Platform alignment

User accounts, roles, and access controls restrict platform functions to authorised users.

11.10(e) Platform control

Use of secure, computer-generated, time-stamped audit trails to independently record operator entries and actions that create, modify, or delete electronic records. Record changes must not obscure previously recorded information, and audit documentation must be retained and available for agency review and copying.

Platform alignment

Audit events record the timestamp, user, event type, and affected entity without replacing the earlier audit entry.

11.10(f) Platform control

Use of operational system checks to enforce permitted sequencing of steps and events, as appropriate.

Platform alignment

Protected actions follow a confirmation workflow and cannot be saved until the required approval step is completed.

11.10(g) Platform control

Use of authority checks to ensure that only authorised individuals can use the system, electronically sign a record, access system input or output, alter a record, or perform the operation at hand.

Platform alignment

The confirmation role and other user-access permissions restrict protected actions to authorised accounts.

11.10(h) Not applicable

Use of device checks to determine, as appropriate, the validity of the source of data input or operational instruction.

11.10(i) Platform + customer SOP

Determination that persons who develop, maintain, or use electronic-record and electronic-signature systems have the education, training, and experience to perform their assigned tasks.

Customer responsibility

The customer must define role requirements, provide training, and retain appropriate competency records.

11.10(j) Platform + customer SOP

Establishment of and adherence to written policies that hold individuals accountable for actions initiated under their electronic signatures.

Customer responsibility

The customer must establish and enforce policies covering credential ownership, signature use, and user accountability.

11.10(k)(1) Platform + customer SOP

Adequate controls over the distribution of, access to, and use of documentation for system operation and maintenance.

Shared responsibility

Platform access controls support restricted access; the customer must control its approved procedures and operational documentation.

11.10(k)(2) Platform + customer SOP

Revision and change-control procedures to maintain an audit trail that documents time-sequenced development and modification of systems documentation.

Shared responsibility

The customer must maintain version and change control for its SOPs and validation documentation.

Sections 11.50 and 11.70 - Signature Information and Record Linking

11.50(a)(1) Platform control

The signed record identifies the printed name of the signer.

Platform alignment

The audit event is associated with the authenticated user who approved the action.

11.50(a)(2) Platform control

The signed record identifies the date and time when the signature was executed.

Platform alignment

The audit record includes the event timestamp.

11.50(a)(3) Platform control

The signed record identifies the meaning associated with the signature, such as review, approval, responsibility, or authorship.

Platform alignment

The event type and affected entity describe the action that the user approved.

11.50(b) Platform control

The signature information is subject to the same controls as the electronic record and is included in human-readable forms of the record, such as displays or printouts.

Platform alignment

Audit-report output keeps the approval details associated with the recorded event.

11.70 Platform control

Electronic signatures must be linked to their respective electronic records so that they cannot be excised, copied, or transferred to falsify another record by ordinary means.

Platform alignment

The authenticated user, timestamp, event type, and affected entity are stored together in the audit event.

Section 11.100 - General Requirements for Electronic Signatures

11.100(a) Platform control

Each electronic signature must be unique to one individual and must not be reused by, or reassigned to, anyone else.

Platform alignment

Approval is associated with the authenticated user's individual account and credentials.

11.100(b) Platform + customer SOP

Before assigning or sanctioning an individual's electronic signature, the organisation must verify the identity of the individual.

Customer responsibility

The customer must verify user identity before granting access and assigning signature authority.

11.100(c) Platform + customer SOP

Persons using electronic signatures must certify to the agency that the signatures are intended to be the legally binding equivalent of traditional handwritten signatures.

Customer responsibility

The customer is responsible for any required certification, supporting testimony, and internal procedures.

11.100(c)(1)-(2) Platform + customer SOP

Required certification must be submitted in the prescribed form, and additional certification or testimony must be provided when requested by the agency.

Customer responsibility

The customer must determine and complete the current agency submission process applicable to its regulated use.

Section 11.200 - Electronic Signature Components and Controls

11.200(a)(1) Platform control

Non-biometric electronic signatures must employ at least two distinct identification components, such as an identification code and password.

Platform alignment

The approval workflow requires the authorised user's username and password.

11.200(a)(1)(i) Platform control

During a continuous period of controlled system access, the first signing must use all signature components; subsequent signings must use at least one component executable only by the individual.

Platform alignment

Protected approvals require confirmation within the authenticated user's controlled session.

11.200(a)(1)(ii) Platform control

Signings performed outside a single continuous period of controlled access must use all electronic-signature components.

Platform alignment

A new authenticated session and protected approval require the applicable identification components.

11.200(a)(2) Platform + customer SOP

Electronic signatures must be used only by their genuine owners.

Shared responsibility

Individual accounts support ownership; the customer must prohibit credential sharing and enforce account security.

11.200(a)(3) Platform + customer SOP

The system must be administered and executed so that attempted use of an individual's signature by another person requires the collaboration of two or more individuals.

Shared responsibility

Individual credentials and administrative access controls must be supported by customer procedures for account recovery and reassignment.

11.200(b) Not applicable

Requirements for electronic signatures based on biometrics do not apply to this username-and-password approval feature.

Section 11.300 - Controls for Identification Codes and Passwords

11.300(a) Platform control

Each combined identification code and password must be unique so that no two individuals have the same combination.

Platform alignment

Each user signs in with an individual account and private password.

11.300(b) Platform control

Identification-code and password issuances must be periodically checked, recalled, or revised, including controls such as password ageing where appropriate.

Platform alignment

Administrators can manage user access, while users can update their account credentials through the available security controls.

11.300(c) Platform + customer SOP

Loss-management procedures must deauthorise lost, stolen, missing, or compromised tokens or devices and provide controlled replacement where applicable.

Shared responsibility

The customer must promptly remove or restrict compromised access and follow its approved account-recovery procedure.

11.300(d) Platform control

Transaction safeguards must prevent unauthorised use of passwords or identification codes and detect and report attempted unauthorised use as appropriate.

Platform alignment

Authentication and access-control safeguards restrict protected actions to valid authorised accounts.

11.300(e) Platform + customer SOP

Devices that bear or generate identification-code or password information must be initially and periodically tested to ensure they function properly and have not been altered without authorisation.

Customer responsibility

The customer must maintain procedures for any external authentication devices used in its regulated workflow.

Recorded Audit Events

When the feature is enabled, the following event types can be included in the audit record. Each record identifies the timestamp, initiating user, event type, and entity involved.

  • Action added
  • Action deleted
  • Action modified
  • Action step added
  • Action step deleted
  • Action step modified
  • Alert added
  • Alert condition added
  • Alert condition deleted
  • Alert condition modified
  • Alert deleted
  • Alert modified
  • Alert notification group added
  • Alert notification group removed
  • Annotation added
  • Annotation deleted
  • Annotation modified
  • Certificate added
  • Certificate deleted
  • Confirm action failed - invalid e-mail or password
  • Confirm action failed - not authorised
  • Document electronically signed
  • Login failure - account locked out
  • Login failure - incorrect password
  • New user account created
  • Node access granted to user
  • Node access revoked from user
  • Node added
  • Node calibration performed
  • Node command sent
  • Node deleted
  • Node input label added
  • Node input label deleted
  • Node input label modified
  • Node modified
  • Notification group added
  • Notification group deleted
  • Notification group member added
  • Notification group member changed
  • Notification group member removed
  • Notification group modified
  • Roles granted to user
  • Roles revoked from user
  • Scheduled job added
  • Scheduled job deleted
  • Scheduled job modified
  • User confirmed action with password
  • User details added
  • User details deleted
  • User details modified
  • User has asked for resend of e-mail confirmation
  • User has changed password
  • User has confirmed e-mail
  • User has confirmed e-mail change
  • User has initiated forgotten password request
  • User has logged in
  • User has logged out