Foundation guide

Electronic records, audit trails, and signatures

Identify which information is needed to reconstruct the regulated activity: data, metadata, relationships, approvals, and relevant history. Then identify the applicable record obligations. FDA’s Part 11 scope guidance explains the relationship between electronic records and underlying record requirements, often called predicate rules. Applicability requires evaluation of the actual record and use. FDA Part 11 scope guidance

Editorial previewTechnical review and author byline approval pending

Start with the record and its purpose

Identify which information is needed to reconstruct the regulated activity: data, metadata, relationships, approvals, and relevant history. Then identify the applicable record obligations. FDA’s Part 11 scope guidance explains the relationship between electronic records and underlying record requirements, often called predicate rules. Applicability requires evaluation of the actual record and use. FDA Part 11 scope guidance

Example 1: A result without its context

A migrated result says “Pass,” but the unit, method revision, original measurement, and approval context are missing. The migration preserved a label, not necessarily enough information to understand the decision. Define the complete record before designing the export.

Example 2: An audit trail that is difficult to review

The system captures every technical event but cannot easily distinguish a changed acceptance limit from routine session activity. Reviewers may struggle to find meaningful changes. Design review around relevant events, responsible roles, access to underlying records, and timely handling of exceptions.

Example 3: A signature copied into a PDF

A picture of a signature on an exported report does not by itself demonstrate who signed, what they signed, or how the signature remains associated with the record. Examine the original approval information, record version, signing meaning, identity controls, and export behavior.

Useful challenges

Change a controlled value through each authorized path. Try an unauthorized path. Check whether the history identifies the event and preserves the information required by the applicable process. Retrieve the record after an update. Confirm a reviewer can determine what version was approved. Check whether privileged administration can undermine the intended controls.

Completed review note — fictional: “The export contains the approved record, version identifier, approval identities, approval times, and signing meanings. The relationship between the export and source record was checked using the retained record identifier. Detailed change history remains accessible in the controlled archive and is included in the retention plan.”

Whether that arrangement is adequate depends on the applicable obligations, retrieval needs, and verified system behavior. A feature called “Part 11 mode” does not complete that assessment.