Service · Part 11 / Annex 11

21 CFR Part 11 &
EU Annex 11.

These regulations require clear applicability decisions, controlled operation and defensible evidence for electronic records and signatures. We design the control model and evidence narrative that stands up under inspection.

Applicability decisions
that are defensible.

In cloud and SaaS environments, the regulated organisation remains accountable regardless of who manages the infrastructure. Governance succeeds when responsibilities and evidence are explicit.

01
Applicability and rationaleRecords, signatures, retention, and where controls genuinely apply, with documented decision rationale.
02
Audit trail governanceGeneration, protection, review expectations, and role accountability, aligned to intended use and risk.
03
Access and privilege governanceRBAC, admin controls, periodic review and deprovisioning, with evidence that controls operate in BAU.
04
Supplier oversightChange governance, shared responsibility boundaries and evidence for SaaS, cloud and managed services.

Frequently asked.

What is 21 CFR Part 11?
FDA regulation for electronic records
Part 11 governs electronic records and signatures in regulated industries. It requires validated systems, secure audit trails, controlled access and reliable record retention.
What is EU Annex 11?
GMP requirements for computerised systems
Annex 11 covers validation, data integrity, security, change control and supplier oversight for computerised systems used in GMP environments across the EU.
Does Part 11 apply to cloud systems?
Yes, the organisation remains responsible
If a cloud or SaaS platform stores GxP electronic records, Part 11 and Annex 11 apply. The regulated organisation remains responsible for validation and governance decisions, even where infrastructure is supplier-managed.

Applicability, resolved.
Not just discussed.

Based on a genuine engagement. Details are anonymised, and in some cases composited, to protect client confidentiality.

Situation

A global CRO migrating to a new electronic data capture platform needed to confirm that the system's electronic signature and audit trail configuration met both 21 CFR Part 11 and EU Annex 11 requirements across a multiregional clinical trial programme. The migration timeline was fixed and the compliance assessment had not been scoped.

Challenge

The vendor's compliance documentation was written generically and did not address the organisation's specific configuration, defined user roles or intended use. There was no clear mapping between regulatory requirements and implemented controls, leaving an unresolved compliance gap that QA and regulatory affairs were not in a position to close internally.

Approach

A Part 11 and Annex 11 applicability assessment was conducted against the organisation's specific configuration and intended use. Vendor documentation was reviewed, annotated and supplemented. A configuration-specific compliance matrix was produced, covering audit trail, electronic signatures, access controls and record retention, together with a validated signature workflow record.

Outcome

The compliance package was accepted by QA and regulatory affairs without revision. The platform was released to production with a complete, auditable electronic records governance record in place and no outstanding compliance questions.

Navigating Part 11
or Annex 11?

Book a call to discuss your applicability position and what a proportionate evidence pack needs to look like.

Book a Call