Audit trails for 21 CFR Part 11: what to record and how
On the software side, FDA's 21 CFR Part 11 requirements for electronic records and signatures show up most in the audit trail. What to record, immutability, retention and a short checklist for electronic signatures.
The U.S. Food and Drug Administration's 21 CFR Part 11 covers electronic records and electronic signatures subject to FDA requirements. Manufacturers and contract laboratories supplying the U.S. market meet these requirements in customer audits too. On the software side, their most visible part is the audit trail.
This article summarizes a software team's perspective; it is not legal or regulatory advice. Whether a system complies is assessed within the organization's own validation process.
What should the audit trail record?
Section 11.10(e) of Part 11 requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions that create, modify or delete electronic records. In practice, each event stores:
- who: a unique user identity
- when: server time, with the time zone stated
- what: create, modify or delete
- which record and which field
- the old value and the new value
- the reason for the change (expected in GMP processes, e.g. by EU GMP Annex 11)
Earlier information must not be obscured
The same section requires that record changes do not obscure previously recorded information. In design this becomes two decisions: records are never physically deleted but flagged as deleted (soft delete), and changes are not overwritten but added as new versions. The audit trail itself must be immutable: no application user, administrators included, should be able to edit an audit entry.
Retention and access
The audit trail must be retained at least as long as the electronic record it covers and be available for review and copying during an inspection. That means tying audit records to the same backup and archive policy as the primary data and providing a readable export (PDF or CSV).
Access control and electronic signatures
An audit trail loses its meaning in a system with weak authentication. Part 11 requires limiting system access to authorized individuals (11.10(d)), showing the signer's name, the date and time and the meaning of the signature (such as "approved" or "reviewed") in electronic signatures (11.50), and linking signatures to their records (11.70). Each electronic signature must belong to one individual only (11.100), which is why shared accounts are not acceptable.
A checklist for the software side
- A unique account per user, role-based permissions
- Audit entries generated server-side and not editable from within the application
- Old and new value, a reason field
- Soft delete and record versioning
- Name, date-time and meaning in electronic signatures
- Audit trail backed up with the records and exportable
- Traceable requirement–test mapping for validation documents
We build this structure into the design of our serialization and laboratory software from the start. If you would like to review the audit trail of an existing system together, get in touch.
Let's discuss this for your plant
More notes
All notes →- 3 min readFive common errors in pharma serialization codes and how to catch them on the lineMissing separators, wrong check digits, date format mix-ups, duplicate serial numbers and disallowed characters: the most frequent errors in pharma DataMatrix codes and how to prevent each one on the line.
- 2 min readStarting predictive maintenance without labeled failure dataPredictive maintenance does not need a dataset of labeled past failures. Learning normal behavior, linking alarms to a physical fault class and collecting labels along the way is a sound start.