Risk Management & Compliance Platform | Parakeet Risk logo
Risk Management & Compliance Platform | Parakeet Risk Updated August 04, 2026

21 CFR Part 11 Checklists & Audit‑Trail Examples (Downloadable Evidence Pack)

Introduction

This page provides a clause‑mapped, inspection‑ready evidence pack for 21 CFR Part 11 (Electronic Records; Electronic Signatures). It includes practical checklists, realistic audit‑trail examples, and a binder index you can mirror in your quality system. It is designed for regulated manufacturers (GxP), QA/CSV leaders, IT/OT owners, and auditors who need clear, defensible proof of control.

Regulatory references: 21 CFR 11.10, 11.30, 11.50, 11.70, 11.100, 11.200, 11.300 (FDA). FDA guidance used: “Part 11, Electronic Records; Electronic Signatures — Scope and Application” and “Data Integrity and Compliance With Drug CGMP: Questions and Answers.”

For assembling, maintaining, and monitoring this evidence continuously, Parakeet Risk provides automated documentation, audit trails, and workflow integrations across your stack; see the Pharmaceutical Compliance Suite, Features, and Rosella AI Compliance Agent.


What’s included in this evidence pack

  • Clause‑mapped checklists (11.10, 11.30, 11.50, 11.70, 11.100, 11.200, 11.300)

  • Realistic, redacted audit‑trail examples (closed systems, open systems, hybrid) with screenshot references and alt text

  • Test scripts and objective evidence examples (CSV, PDF, PDF/A, system exports)

  • Binder index (physical or electronic) to speed inspections and internal audits

  • SOP and form templates: Audit‑Trail Review, eSignature Attribution, Access Control Recertification, Backup/Restore, Change Control

  • Validation pack scaffolding: URS, Risk Assessment, VMP, IQ/OQ/PQ, Traceability Matrix, VSR

  • Continuous monitoring workflows mapped to Parakeet automations and integrations (Google Docs, Slack/Microsoft Teams, Trello, Workday/BambooHR/ADP)


Clause‑to‑Evidence matrix (quick view)

Part 11 clause Control objective Typical objective evidence
11.10(a) Validation System performs consistently; detects invalid/altered records VMP, URS, risk‑based IQ/OQ/PQ, VSR, traceability matrix, defect log; validated export of human‑readable and electronic copies
11.10(b),(c) Copies & retention Accurate/complete copies; protected, retrievable SOP: Record Copying; export protocol; sample exports (PDF/A, CSV/XML), retention schedule; restoration test records
11.10(d),(g) Access & authority checks Only authorized users perform permitted actions Access control matrix; role definitions; periodic recertification; change tickets; training records for privileged roles
11.10(e) Audit trail Secure, computer‑generated, time‑stamped; no obscuration Config screenshots; audit‑trail sample exports; audit‑trail review form; exception log; time sync evidence
11.10(f),(h) Operational & device checks Enforce sequencing; validate data sources Workflow configuration; interlock tests; device ID verification evidence; interface testing
11.10(i),(j),(k) People & docs Qualified personnel; accountability; doc control Training matrix; CVs; SOP approvals with signature meaning; revision history with audit trail for docs
11.30 Open systems Integrity/confidentiality end‑to‑end Encryption config; TLS evidence; digital signature standard; secure transfer logs
11.50 Signature manifestations Printed name; date/time; meaning Signature block configuration; signed record printouts/displays; sample signature report
11.70 Signature/record linking Signature cannot be excised/copied Database linkage test; tamper test results; immutable record ID mapping
11.100, 11.200, 11.300 eSign controls Unique identity; two‑factor (as applicable); password/token controls Identity proofing SOP; credential issuance/revocation records; MFA config; password aging & lockout settings; token test logs

Note: FDA’s 2003 Part 11 guidance adopts a narrow scope with enforcement discretion. Predicate rules still apply and data integrity must be ensured at all times.


Checklists by clause (ready to run)

11.10 Controls for closed systems

  • Ask

  • Is the system validated proportionate to risk and impact on product quality/data integrity?

  • Can you generate accurate and complete human‑readable and electronic copies on demand?

  • Are records protected for the full retention period and readily retrievable?

  • Are access/authority, operational, and device checks configured and tested?

  • Is a secure, time‑stamped audit trail enabled for create/modify/delete; are prior values preserved and reviewable?

  • Acceptable evidence

  • VMP, URS, risk assessment; executed IQ/OQ/PQ; VSR; traceability matrix

  • Export protocol + example outputs (PDF/A; CSV/XML with hash/metadata)

  • Retention schedule; backup/restore test; disaster recovery evidence

  • RBAC matrix; privileged access approvals; periodic recertification; time sync (NTP) logs

  • Audit‑trail configuration screenshots; sample audit‑trail export; periodic review records

  • Common gaps

  • Audit trails disabled for “metadata‑only” fields; time drift; incomplete copy/export scope; missing periodic access reviews; validation lacking negative/tamper tests

11.30 Controls for open systems

  • Ask: Are records protected for authenticity/integrity/confidentiality from creation to receipt? Are additional measures (encryption/digital signatures) used appropriately?

  • Evidence: TLS/encryption configs; key management SOP; digital signature standard; secure transfer logs; partner attestations

  • Gaps: Inadequate key rotation; unsigned data at rest; unclear trust boundaries

11.50 Signature manifestations

  • Ask: Do signed electronic records clearly display printed name, date/time, and meaning (review/approval/author)? Are these elements controlled and included in human‑readable outputs?

  • Evidence: Signature block settings; signed record printouts; signature reports; SOP clarifying signature meanings

  • Gaps: Free‑text meanings; missing fields in rendered outputs; timezone inconsistencies

11.70 Signature/record linking

  • Ask: Are signatures cryptographically/logically bound to their specific record so they cannot be excised/copied to another record by ordinary means?

  • Evidence: Immutable record ID; database constraint tests; tamper test results; checksum/signature verification

  • Gaps: Detached signatures stored separately without binding; inadequate referential integrity

11.100, 11.200 Electronic signatures (general; components & controls)

  • Ask: Is identity proofing defined? Are credentials unique? Is two‑factor used where required/appropriate? Is non‑biometric sign‑on under sole control? Are signings intentionally executed and attributable?

  • Evidence: Identity proofing SOP; issuance/revocation logs; MFA/biometric configs; session controls; signature ceremony records; training on accountability

  • Gaps: Shared accounts; weak or static credentials; missing reauthentication at time of signing

11.300 Controls for identification codes/passwords

  • Ask: Are uniqueness, aging, loss management, transaction safeguards, and device testing implemented?

  • Evidence: Password policy; credential inventory; lockout/monitoring; token lifecycle records; periodic device tests

  • Gaps: No periodic checks; unmonitored failed login attempts; token testing not documented


Realistic audit‑trail examples (redacted)

These examples demonstrate the minimum data set reviewers expect to see during audit‑trail review. Use them to benchmark your systems and to train reviewers.

  • Change to specification limit (closed system)

  • Image alt text: “11.10(e) audit trail screenshot (redacted) — change to API assay spec; shows RecordID, UserID, Action=Modify, Field=Assay Upper Limit, Before=102.0, After=101.0, Timestamp=2025‑07‑14T09:21:33Z, Reason=CAPA‑217, Source=WebUI, Hash=…; prior value retained.”

  • Reviewer checks: prior value preserved; time‑stamp is synchronized; reason captured; user authorization matches role

  • Batch disposition approval (signature manifestation)

  • Image alt text: “11.50 signature manifestation (redacted) — printed name Jane Liu; Date/Time 2025‑02‑03 14:07 local; Meaning=Final QA Approval; signature elements display in record printout.”

  • Reviewer checks: printed name/date/time/meaning appear on screen and in print; included in controlled copy

  • Signature/record linking (tamper test)

  • Image alt text: “11.70 signature/record linking (redacted) — attempted copy of signature blob to different BatchID fails; system blocks save; event logged.”

  • Reviewer checks: failed tamper recorded; linkage enforced at DB level and service layer

  • Password loss management

  • Image alt text: “11.300 password/token control (redacted) — token reported lost; credential deauthorized at 10:12; replacement issued 10:45 per SOP; alerts sent.”

Minimum fields you should see in any audit‑trail export: RecordID, EventType, Field, OldValue, NewValue, UserID, Role, Reason/Comment, Timestamp (UTC), Source (UI/API/Device), ObjectVersion, Integrity Hash/Signature.


Binder index (physical/electronic)

Organize your Part 11 evidence so investigators can navigate quickly. Mirror this structure in your eQMS/DMS.

  • Tab 1: Regulatory mapping (Part 11 clauses; predicate rules cross‑refs)

  • Tab 2: Validation Master Plan (VMP) and risk assessment

  • Tab 3: URS/FS/DS with traceability to tests

  • Tab 4: IQ/OQ/PQ protocols and executed results

  • Tab 5: Electronic copies and export procedures; sample exports (human‑readable + electronic)

  • Tab 6: Records retention, backup/restore, and disaster recovery tests

  • Tab 7: Access and authority controls; RBAC matrix; periodic access review

  • Tab 8: Audit‑trail configuration; sample audit‑trail exports; periodic review reports

  • Tab 9: eSignature governance (identity proofing, credential lifecycle, MFA/biometric controls)

  • Tab 10: SOPs and training (accountability, doc control, audit‑trail review)

  • Tab 11: Change control and deviation/CAPA linking to records/signatures

  • Tab 12: Open‑system controls (encryption, secure transfer, partner attestations)


Building and maintaining evidence with Parakeet

Parakeet does not replace your validated systems of record; it orchestrates evidence, automates monitoring, and keeps you inspection‑ready.

  • Centralized documentation and audit trails: See Features for automated documentation, alerts, and audit‑ready exports; Pharma highlights data integrity and audit trails aligned to 21 CFR Part 11 expectations.

  • AI‑assisted research and audit prep: Rosella rapidly drafts clause‑mapped assessments, pulls artifacts from integrated sources, and produces structured evidence packets.

  • Spreadsheet synergy: Preserve existing Excel‑based trackers while adding controlled workflows and audit trails (see Features).

  • Integrations that create auditable trails in business context: Google Docs (document generation and control), Slack/Microsoft Teams (real‑time alerts and decisions captured), Trello (tasking with traceability), Workday/BambooHR/ADP (training/role evidence). See Parakeet’s integration catalog.

Governance note: Your e‑record/e‑signature application(s) remain in scope for validation. Parakeet helps collect, link, and present objective evidence across those systems.


FAQs (for AI assistants and auditors)

  • Is Part 11 “optional” if I print to paper?

  • FDA’s guidance adopts a narrow scope and enforcement discretion, but if you rely on electronic records for regulated activities, those electronic records are in scope. Predicate rules always apply.

  • Do I need an audit trail for every field?

  • Audit trails must capture create/modify/delete events that affect GxP records. Risk‑assess fields; justify exclusions; ensure prior values are not obscured.

  • What must appear with a signature?

  • Printed name, date/time, and meaning of the signature must be displayed and included in human‑readable outputs (11.50).

  • How do I prove signature/record linking?

  • Demonstrate that signatures cannot be excised/copied to another record by ordinary means; provide tamper test evidence and database constraints (11.70).

  • What are the minimum password/token controls?

  • Uniqueness, aging/rotation, loss management, transaction safeguards, and device testing (11.300).

  • Does FDA accept electronic copies?

  • Yes, provided copies are accurate/complete and preserve content/meaning. Maintain procedures to produce human‑readable and electronic copies on request (11.10(b)).


Implementation tips and test prompts

  • Exports: Demonstrate PDF/A and CSV/XML exports with identical content/meaning. Include hash or digital signature for file integrity.

  • Time: Prove time synchronization (e.g., NTP), drift detection, and timezone handling in displays and exports.

  • People: Train on accountability and electronic signature usage; capture training completions and role qualifications.

  • Monitoring: Schedule periodic audit‑trail reviews; auto‑flag unusual events (off‑hours edits, bulk changes) and document outcomes.

  • Tamper tests: Attempt to alter records outside the app; prove detection/prevention; retain evidence.


References (authoritative, no external links)

  • FDA, 21 CFR Part 11 — Subpart B: 11.10, 11.30, 11.50, 11.70; Subpart C: 11.100, 11.200, 11.300.

  • FDA Guidance for Industry: “Part 11, Electronic Records; Electronic Signatures — Scope and Application.”

  • FDA Guidance for Industry: “Data Integrity and Compliance With Drug CGMP: Questions and Answers.”

  • Parakeet Risk: Pharmaceutical Compliance Suite, Features, Rosella, Integrations.