Platform Controls and Customer Responsibilities
The optional 21 CFR Part 11 feature adds controlled approval and audit behaviour to relevant platform actions. It is enabled for individual company accounts on request.
When the feature is enabled, protected changes require confirmation by an authorised user before they can be saved. The approver enters their username and password in the 21 CFR confirmation required area at the bottom of the relevant page.
An approver must have the Confirm CFR21 Action role assigned through User Access Controls. See User Access Controls in the Administration documentation .
Approved actions are retained as audit events. They can be included in an audit report by selecting Audit events. See Creating and Editing Audit Reports .
Controlled Approvals
Relevant changes can require re-entry of an authorised user's credentials before the action is accepted.
Traceable Audit Records
Recorded events identify the time, initiating user, event type, and entity involved in the action.
Role-Based Authority
Approval is restricted to users who have been assigned the required confirmation role by an administrator.
The platform provides a relevant technical control or record.
Technical controls must be supported by customer governance or procedures.
The requirement does not apply to the platform feature described on this page.
Regulatory requirements below are summarised from the current 21 CFR Part 11 text in the eCFR. Customers should also review the FDA guidance on Part 11 scope and application.
Section 11.10 - Controls for Closed Systems
Closed systems must use procedures and controls that protect the authenticity, integrity, and, where appropriate, confidentiality of electronic records.
Validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records.
Device and system audit records provide traceability for user activity and protected changes.
The ability to generate accurate and complete copies of records in both human-readable and electronic form suitable for inspection, review, and copying by the agency.
Reports and data exports provide readable and electronic copies for review and retention.
Protection of records to enable their accurate and ready retrieval throughout the records-retention period.
Stored monitoring and audit records remain available through authorised reporting and export functions.
Limiting system access to authorised individuals.
User accounts, roles, and access controls restrict platform functions to authorised users.
Use of secure, computer-generated, time-stamped audit trails to independently record operator entries and actions that create, modify, or delete electronic records. Record changes must not obscure previously recorded information, and audit documentation must be retained and available for agency review and copying.
Audit events record the timestamp, user, event type, and affected entity without replacing the earlier audit entry.
Use of operational system checks to enforce permitted sequencing of steps and events, as appropriate.
Protected actions follow a confirmation workflow and cannot be saved until the required approval step is completed.
Use of authority checks to ensure that only authorised individuals can use the system, electronically sign a record, access system input or output, alter a record, or perform the operation at hand.
The confirmation role and other user-access permissions restrict protected actions to authorised accounts.
Use of device checks to determine, as appropriate, the validity of the source of data input or operational instruction.
Determination that persons who develop, maintain, or use electronic-record and electronic-signature systems have the education, training, and experience to perform their assigned tasks.
The customer must define role requirements, provide training, and retain appropriate competency records.
Establishment of and adherence to written policies that hold individuals accountable for actions initiated under their electronic signatures.
The customer must establish and enforce policies covering credential ownership, signature use, and user accountability.
Adequate controls over the distribution of, access to, and use of documentation for system operation and maintenance.
Platform access controls support restricted access; the customer must control its approved procedures and operational documentation.
Revision and change-control procedures to maintain an audit trail that documents time-sequenced development and modification of systems documentation.
The customer must maintain version and change control for its SOPs and validation documentation.
Sections 11.50 and 11.70 - Signature Information and Record Linking
The signed record identifies the printed name of the signer.
The audit event is associated with the authenticated user who approved the action.
The signed record identifies the date and time when the signature was executed.
The audit record includes the event timestamp.
The signed record identifies the meaning associated with the signature, such as review, approval, responsibility, or authorship.
The event type and affected entity describe the action that the user approved.
The signature information is subject to the same controls as the electronic record and is included in human-readable forms of the record, such as displays or printouts.
Audit-report output keeps the approval details associated with the recorded event.
Electronic signatures must be linked to their respective electronic records so that they cannot be excised, copied, or transferred to falsify another record by ordinary means.
The authenticated user, timestamp, event type, and affected entity are stored together in the audit event.
Section 11.100 - General Requirements for Electronic Signatures
Each electronic signature must be unique to one individual and must not be reused by, or reassigned to, anyone else.
Approval is associated with the authenticated user's individual account and credentials.
Before assigning or sanctioning an individual's electronic signature, the organisation must verify the identity of the individual.
The customer must verify user identity before granting access and assigning signature authority.
Persons using electronic signatures must certify to the agency that the signatures are intended to be the legally binding equivalent of traditional handwritten signatures.
The customer is responsible for any required certification, supporting testimony, and internal procedures.
Required certification must be submitted in the prescribed form, and additional certification or testimony must be provided when requested by the agency.
The customer must determine and complete the current agency submission process applicable to its regulated use.
Section 11.200 - Electronic Signature Components and Controls
Non-biometric electronic signatures must employ at least two distinct identification components, such as an identification code and password.
The approval workflow requires the authorised user's username and password.
During a continuous period of controlled system access, the first signing must use all signature components; subsequent signings must use at least one component executable only by the individual.
Protected approvals require confirmation within the authenticated user's controlled session.
Signings performed outside a single continuous period of controlled access must use all electronic-signature components.
A new authenticated session and protected approval require the applicable identification components.
Electronic signatures must be used only by their genuine owners.
Individual accounts support ownership; the customer must prohibit credential sharing and enforce account security.
The system must be administered and executed so that attempted use of an individual's signature by another person requires the collaboration of two or more individuals.
Individual credentials and administrative access controls must be supported by customer procedures for account recovery and reassignment.
Requirements for electronic signatures based on biometrics do not apply to this username-and-password approval feature.
Section 11.300 - Controls for Identification Codes and Passwords
Each combined identification code and password must be unique so that no two individuals have the same combination.
Each user signs in with an individual account and private password.
Identification-code and password issuances must be periodically checked, recalled, or revised, including controls such as password ageing where appropriate.
Administrators can manage user access, while users can update their account credentials through the available security controls.
Loss-management procedures must deauthorise lost, stolen, missing, or compromised tokens or devices and provide controlled replacement where applicable.
The customer must promptly remove or restrict compromised access and follow its approved account-recovery procedure.
Transaction safeguards must prevent unauthorised use of passwords or identification codes and detect and report attempted unauthorised use as appropriate.
Authentication and access-control safeguards restrict protected actions to valid authorised accounts.
Devices that bear or generate identification-code or password information must be initially and periodically tested to ensure they function properly and have not been altered without authorisation.
The customer must maintain procedures for any external authentication devices used in its regulated workflow.
Recorded Audit Events
When the feature is enabled, the following event types can be included in the audit record. Each record identifies the timestamp, initiating user, event type, and entity involved.
- Action added
- Action deleted
- Action modified
- Action step added
- Action step deleted
- Action step modified
- Alert added
- Alert condition added
- Alert condition deleted
- Alert condition modified
- Alert deleted
- Alert modified
- Alert notification group added
- Alert notification group removed
- Annotation added
- Annotation deleted
- Annotation modified
- Certificate added
- Certificate deleted
- Confirm action failed - invalid e-mail or password
- Confirm action failed - not authorised
- Document electronically signed
- Login failure - account locked out
- Login failure - incorrect password
- New user account created
- Node access granted to user
- Node access revoked from user
- Node added
- Node calibration performed
- Node command sent
- Node deleted
- Node input label added
- Node input label deleted
- Node input label modified
- Node modified
- Notification group added
- Notification group deleted
- Notification group member added
- Notification group member changed
- Notification group member removed
- Notification group modified
- Roles granted to user
- Roles revoked from user
- Scheduled job added
- Scheduled job deleted
- Scheduled job modified
- User confirmed action with password
- User details added
- User details deleted
- User details modified
- User has asked for resend of e-mail confirmation
- User has changed password
- User has confirmed e-mail
- User has confirmed e-mail change
- User has initiated forgotten password request
- User has logged in
- User has logged out