Skip to content

Audit trails for 21 CFR Part 11: what to record and how

On the software side, FDA's 21 CFR Part 11 requirements for electronic records and signatures show up most in the audit trail. What to record, immutability, retention and a short checklist for electronic signatures.

2 min read21 CFR Part 11 · GMP · Audit trail · Validation

The U.S. Food and Drug Administration's 21 CFR Part 11 covers electronic records and electronic signatures subject to FDA requirements. Manufacturers and contract laboratories supplying the U.S. market meet these requirements in customer audits too. On the software side, their most visible part is the audit trail.

This article summarizes a software team's perspective; it is not legal or regulatory advice. Whether a system complies is assessed within the organization's own validation process.

What should the audit trail record?

Section 11.10(e) of Part 11 requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions that create, modify or delete electronic records. In practice, each event stores:

  • who: a unique user identity
  • when: server time, with the time zone stated
  • what: create, modify or delete
  • which record and which field
  • the old value and the new value
  • the reason for the change (expected in GMP processes, e.g. by EU GMP Annex 11)

Earlier information must not be obscured

The same section requires that record changes do not obscure previously recorded information. In design this becomes two decisions: records are never physically deleted but flagged as deleted (soft delete), and changes are not overwritten but added as new versions. The audit trail itself must be immutable: no application user, administrators included, should be able to edit an audit entry.

Retention and access

The audit trail must be retained at least as long as the electronic record it covers and be available for review and copying during an inspection. That means tying audit records to the same backup and archive policy as the primary data and providing a readable export (PDF or CSV).

Access control and electronic signatures

An audit trail loses its meaning in a system with weak authentication. Part 11 requires limiting system access to authorized individuals (11.10(d)), showing the signer's name, the date and time and the meaning of the signature (such as "approved" or "reviewed") in electronic signatures (11.50), and linking signatures to their records (11.70). Each electronic signature must belong to one individual only (11.100), which is why shared accounts are not acceptable.

A checklist for the software side

  • A unique account per user, role-based permissions
  • Audit entries generated server-side and not editable from within the application
  • Old and new value, a reason field
  • Soft delete and record versioning
  • Name, date-time and meaning in electronic signatures
  • Audit trail backed up with the records and exportable
  • Traceable requirement–test mapping for validation documents

We build this structure into the design of our serialization and laboratory software from the start. If you would like to review the audit trail of an existing system together, get in touch.

Let's discuss this for your plant