Insight Brief · Part 11 & Annex 11

Electronic signatures:
controls and evidence under Part 11 / Annex 11.

Electronic signatures are inspected as a combination of technical controls and procedural discipline. Inspectors want to see that signatures are attributable, meaningful, and cannot be misused to mask weak governance.

What inspectors
test for.

Inspectors assess whether signatures are attributable, meaningful and properly governed, not just whether an e-signature feature is enabled in the system.

01
Unique identityEach signer has a unique account. Shared accounts are a critical weakness and a frequently cited inspection finding under both Part 11 and Annex 11.
02
Signature meaningApproval meaning is explicit (reviewed, approved, released) and linked to the business process. Meaning must be presented and permanently stored at the point of signing.
03
Authentication controlSignature requires re-authentication or an equivalent control appropriate to risk. Strength of authentication should be proportionate to the impact of the signed action.
04
Linkage and audit trailSignature is permanently linked to the signed record so it cannot be excised or reassigned. Signature events appear in audit trail records and are reviewable.

A proportionate
evidence set.

These four items typically constitute a fast-to-produce, inspection-ready evidence pack for electronic signature controls.

01
Applicability assessmentPart 11 / Annex 11 applicability determination and control mapping, with documented rationale for which requirements apply and how they are met.
02
Configured workflowsSignature workflows, role definitions and the configuration baseline showing exactly how the system is configured for e-signatures.
03
Test evidenceEvidence for signature application, invalid attempt handling and record linkage. Including negative testing where appropriate to the risk level.
04
Governing procedureSOP covering signature meaning, training requirements, account management (joiners, leavers, movers) and deviation handling.

Frequently asked.

Do we need two-factor authentication?
Proportionate to risk, not always
The requirement is for controls that ensure attribution and prevent misuse. For higher-risk processes, stronger authentication may be justified. Document the rationale for the control level chosen.
What is the most common e-signature weakness?
Weak identity governance
Shared accounts, poor leaver removal and inadequate role control around who can sign what. These are frequently cited and difficult to remediate retrospectively once an inspection has occurred.
How do we demonstrate signature meaning?
Define it, present it, store it
Define signature meanings in SOPs and ensure the system presents, and permanently stores, the meaning at the point of signing. The meaning must be retrievable alongside the signed record.

E-signature controls under scrutiny?
Let’s assess your position.

A focused review of your e-signature configuration, governance and evidence, with a clear remediation path where gaps exist.

Book a Call Part 11 / Annex 11 service →

Explore further.