Automation Glossary • 21 CFR Part 11

What Is 21 CFR Part 11 (Electronic Records and Signatures)?

Merobix Engineering • • 6 min read

When a pharmaceutical, food, or beverage operation replaces paper records with electronic ones, a regulator has to be able to trust the electronic record as much as it trusted ink on a page. In the United States the rule that establishes when it can is the FDA's 21 CFR Part 11. This guide defines Part 11 itself - what it requires of electronic records and electronic signatures for them to be trustworthy - and explains how a validated SCADA system and historian meet those requirements, complementing the batch-record and pharma-compliance topics that assume Part 11 without defining it.

Back to Blog

21 CFR Part 11 in one line: 21 CFR Part 11 is the FDA regulation that defines the conditions under which electronic records and electronic signatures are considered trustworthy and equivalent to paper records and handwritten signatures. It requires controls such as secure audit trails, access restrictions, record integrity, and signatures bound to their records, so that regulated electronic data can be relied upon. Meeting it depends on both a capable, validated system and the procedures around it.

What Part 11 Requires of an Electronic Record

Part 11 sets out what has to be true for an electronic record to stand in for a paper one in an FDA-regulated context. Central to it is the secure, computer-generated audit trail: any creation, modification, or deletion of a regulated record must be captured automatically, with the time, the change, and the identity of the person who made it, and the original value must not be obscured. Access controls limit who can view or change records to authorized users, so that authorship and accountability are enforced by the system rather than by trust. The records must be protected so they remain accurate and retrievable throughout their retention period, and the system must be able to generate accurate, complete copies for inspection.

These requirements exist to close the gap that electronic records could otherwise open. A paper record is hard to alter invisibly; a database row is not, unless the system is built to prevent it. Part 11's controls are what make an electronic record as resistant to silent, untraceable change as a paper one - arguably more so, because the audit trail records every touch. The rule does not prescribe a specific technology; it describes the properties the record and the system must have. Meeting it is therefore partly a matter of the software's capabilities and partly a matter of the validated procedures the operation wraps around them.

Electronic Signatures and ALCOA+ Data Integrity

Part 11 also governs electronic signatures - the electronic equivalent of a handwritten signoff. To be trustworthy, an electronic signature must be uniquely attributable to one individual, must not be reusable by or transferable to anyone else, and must be permanently bound to the record it signs so it cannot be cut from one record and pasted onto another. The signing event carries the signer's identity, the time, and the meaning of the signature - review, approval, responsibility. This is what lets an electronic approval on a batch record or a report carry the same weight a wet-ink signature would, with the same accountability behind it.

Underlying all of this is the data integrity principle often summarized as ALCOA+: records should be Attributable, Legible, Contemporaneous, Original, and Accurate, with the plus adding complete, consistent, enduring, and available. Part 11's audit trails, access controls, and signature binding are, in effect, the technical means of achieving ALCOA+ for electronic data. Attributable comes from user accounts and audit trails; contemporaneous from time-stamping at the moment of action; original and enduring from protected, retained storage; available from the ability to retrieve and produce the record on demand. A system that embodies these properties is one whose data an auditor can trust, which is the whole point of the rule.

How a Validated SCADA and Historian Satisfy Part 11

A SCADA system with a historian is naturally positioned to meet many of Part 11's requirements, because the properties the rule demands - time-stamped records, captured actions, retained history - are close to what a SCADA system does anyway. The parts that make it Part 11 capable are the ones aimed squarely at trustworthiness: user accounts and role-based access so actions are attributable, a computer-generated audit trail that records every configuration change, setpoint change, acknowledgment, and record edit with who and when, electronic signature support for regulated approvals, and protected, retained storage so the record endures unaltered for its retention period. These are the same mechanisms that appear in the audit-trail and shift-log topics, applied here to satisfy a specific legal standard.

Capability alone is not compliance, though - Part 11 lives in the pairing of a capable system with validation. Validation is the documented evidence that the system does what it is supposed to and that the controls actually work, and a Part 11 environment requires it. A cloud SCADA platform such as Merobix contributes the technical foundation: attributable, time-stamped records with an audit trail, access controls, retained and retrievable history, and the ability to produce accurate copies for inspection. The regulated operation supplies the validation and the procedures around it - the qualified accounts, the signing conventions, the change control. Together the validated platform and the operation's practices are what make the electronic records and signatures trustworthy in the sense Part 11 demands.

Frequently Asked Questions

What is 21 CFR Part 11 in simple terms?

It is the FDA rule that says when electronic records and electronic signatures can be trusted as much as paper records and handwritten signatures. It requires controls like secure audit trails, access restrictions, protected records, and signatures firmly bound to what they sign. The point is to make electronic data in regulated industries as reliable and tamper-evident as the paper it replaces.

What does ALCOA+ mean and how does it relate to Part 11?

ALCOA+ is a data integrity principle: records should be Attributable, Legible, Contemporaneous, Original, and Accurate, plus complete, consistent, enduring, and available. Part 11's requirements - audit trails, access controls, time-stamping, protected storage, and signature binding - are essentially the technical means of achieving ALCOA+ for electronic data. A system that embodies ALCOA+ is producing the kind of trustworthy record Part 11 requires.

Does using a Part 11 capable SCADA system make you compliant?

Not by itself. A capable system provides the necessary controls - attributable records, audit trails, access restrictions, e-signatures, and retained storage - but Part 11 compliance also requires validation and the procedures the operation puts around the system. Compliance is the pairing of a validated, capable platform with qualified user accounts, defined signing conventions, and change control, not just the software's features.

Sources & Further Reading

Primary references from the standards bodies and regulators that define this topic:

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
SCADA Audit Report & Audit Log  •  Measurement Reconciliation Report  •  Exception-Based Surveillance  •  Methane Monitoring Compliance Report  •  Sparkline  •  Analog bar graph  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →