FDA 21 CFR Part 11 Compliance: The Complete Guide for Supplement, Food, and Cosmetics Manufacturers
If you use any electronic system to create, modify, or store records that a predicate rule, 21 CFR Part 111 for supplements, Part 110/117 for food, MoCRA for cosmetics, requires you to keep, 21 CFR Part 11 governs how those electronic records and any electronic signatures on them have to be handled. This guide covers scope, the closed-vs-open systems distinction, the specific controls FDA inspectors check, electronic signature requirements, and how validation actually works in practice.
Who Should Read This Guide
This guide is written for QA managers, compliance leads, and operators at supplement, food, and cosmetics manufacturers evaluating or already running electronic recordkeeping systems. It assumes you already know you need to think about Part 11, and walks through exactly what the regulation requires, how the requirements are enforced in practice, and how to evaluate whether a system, yours or a vendor's, actually satisfies them.
Scope and Applicability: Does Part 11 Apply to Supplements?
Part 11 does not stand alone. It applies whenever a "predicate rule", an underlying regulation that requires you to keep a record or provide a signature, is satisfied using an electronic record or electronic signature instead of paper. For dietary supplement manufacturers, the predicate rule is Part 111: §111.605 requires you to retain batch production records, master manufacturing records, and related quality documentation. If you keep those records on paper with wet-ink signatures, Part 11 does not apply to them. The moment you keep any of those records electronically, or sign them electronically, Part 11's controls attach to that record.
This means the honest answer to "does Part 11 apply to supplements?" is: Part 111 is what requires supplement manufacturers to keep records; Part 11 is what governs those records once, and only once, they exist in electronic form. In practice, essentially every modern supplement manufacturer's batch records, formulation records, and quality sign-offs are electronic, so Part 11 is not optional in any practical sense, but the legal mechanism is worth understanding: Part 11 is a records-format regulation that rides on top of your substantive recordkeeping obligation, not a separate, standalone requirement to build a compliance program from scratch.
Closed vs. Open Systems (§11.10 vs. §11.30)
Part 11 distinguishes between two categories of systems, and the applicable controls differ:
Closed systems (§11.10) are systems where access is controlled by the persons responsible for the content of the electronic records on the system, generally an internal manufacturing platform where your own IT/quality function controls who has access. Most manufacturing software, including EBR and quality management platforms, operates as a closed system. §11.10 requires: validation of the system to ensure accuracy, reliability, and the ability to detect invalid or altered records; the ability to generate accurate and complete copies of records for inspection; protection of records to enable their accurate retrieval throughout the retention period; limiting system access to authorized individuals; and the secure, computer-generated, time-stamped audit trails discussed below.
Open systems (§11.30) are systems where access is not controlled by the persons responsible for the content, records transmitted over a network the record owner does not control, for example. Open systems require additional controls, including document encryption and the use of appropriate digital signature standards, to ensure record authenticity, integrity, and confidentiality from the point of creation to the point of receipt.
Most day-to-day manufacturing software questions concern closed systems. The open-system provisions become relevant when records leave your controlled environment, for example, when a batch record or certificate is transmitted to a client or regulator over the open internet without the sending platform's own access controls following the record.
Controls Walkthrough
Validation
§11.10(a) requires validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records. This is where Installation Qualification, Operational Qualification, and Performance Qualification (covered in detail below) come in.
Audit Trails (§11.10(e))
§11.10(e) requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions that create, modify, or delete electronic records, without obscuring previously recorded information, retained for as long as the underlying record and available for FDA review and copying. Our companion guide, Audit Trail vs. Change Log: Why the Difference Matters to the FDA, breaks this requirement down clause by clause and gives five concrete tests for whether your system's "history" feature is a genuine audit trail or a change log wearing an audit trail's name.
Record Retention and Copies for FDA
Your system must be able to generate accurate and complete copies of records, in both human-readable and electronic form suitable for FDA inspection, review, and copying, on request. A system that can display a record on screen but cannot export a complete, accurate copy for an inspector is not meeting this requirement in practice, even if the underlying data is technically intact.
Access Controls and Authority Checks
§11.10(d) and §11.10(g) require limiting system access to authorized individuals and requiring authority checks to ensure that only authorized individuals can use the system, alter a record, or electronically sign a record. In practice, this means role-based permissions that actually gate what a given user can do, not just a login screen.
Identity Verification (§11.100(b))
Before an organization allows an individual to use their electronic signature, it must verify the identity of that individual. This is a one-time (or periodically renewed) identity-verification obligation distinct from the day-to-day authentication that happens at each signature event.
The AI-Agent Separation-of-Duties Question
An emerging and, as of this writing, unsettled question in Part 11 compliance is how AI agents that can take manufacturing actions, receiving inventory, updating a formulation, initiating a production step, fit into the accountability model Part 11 assumes: a human user, uniquely identified, accountable for a specific record. FDA has not issued specific Part 11 guidance addressing AI-agent-initiated actions as of this guide's last review, and the industry does not yet have a settled answer. The most conservative and currently defensible position is that any AI-suggested action affecting a Part 11 record must pass through a human confirmation step before execution, so the record of "who acted" remains a specific, accountable individual rather than the model itself. We treat this as an open industry question, not a solved one, and our own Confirmation Gate architecture reflects that conservative position rather than a claim that the question is settled.
Electronic Signature Requirements (§11.50–11.200)
Part 11 electronic signatures must be unique to one individual, never reused or reassigned, linked to their respective records so they cannot be copied or transferred to falsify another record, and must capture the printed name of the signer, the date and time of signing, and the meaning of the signature (authorship, review, approval, or verification). Non-biometric signatures require at least two distinct identification components (such as a user ID and password). Our detailed guide, Electronic Signatures Under 21 CFR Part 11: What Counts and What Doesn't, walks through which common practices, typed names, scanned wet-ink signatures pasted into PDFs, shared-account approvals, email approvals, checkbox confirmations, fail this standard, and what a compliant signature workflow looks like end to end.
Audit Trail Review as a QA Process, Not an IT Feature
A recurring failure mode is treating the audit trail as a technical artifact that exists for the IT department to maintain, rather than a quality control tool the quality unit actively reviews. A mature quality system schedules periodic audit trail review, not just at the point of a specific investigation, but as a routine check for patterns: repeated failed signature attempts, unusual after-hours record modifications, or a spike in deviation records around a particular operator or shift. Reviewing the difference between a change log and a true audit trail is a prerequisite to this kind of review being meaningful; you cannot review data for suspicious patterns if the underlying trail is incomplete or editable in the first place.
Validation: IQ/OQ/PQ, From First-Hand Experience
Validation under §11.10(a) is often treated as an abstract checkbox. In practice, it breaks into three distinct qualification stages:
- Installation Qualification (IQ) confirms the system was installed as specified, in the intended environment, with the intended configuration, and documents that installation.
- Operational Qualification (OQ) confirms the system operates according to its functional specification across the range of conditions it will actually encounter, does step-sequencing actually block out-of-order entry, does the audit trail actually capture every action type, tested and documented, not assumed.
- Performance Qualification (PQ) confirms the system performs reliably under real, sustained operating conditions, not just in a controlled test environment, over a defined period of live use.
BatchBuddy is currently working through our own DOC-VAL-001 validation protocol, moving from internal IQ/OQ documentation toward third-party performance qualification. We describe this honestly as in progress: we have not completed third-party validation, and we do not claim otherwise. What we can describe from direct experience is the practical discipline validation imposes, every functional claim in our own audit trail and signature architecture had to be documented against a written test protocol, executed, and recorded, before we could assert it with confidence rather than intent. That discipline is the actual value of IQ/OQ/PQ; the paperwork is a byproduct of having actually verified the system does what you are telling an inspector it does.
The 2003 Scope and Application Guidance and Enforcement Discretion
In 2003, FDA issued guidance titled "Part 11, Electronic Records; Electronic Signatures — Scope and Application", which narrowed FDA's enforcement approach to Part 11 relative to the 1997 rule as originally written. The guidance clarified that FDA would exercise enforcement discretion regarding certain Part 11 requirements (including some validation, audit trail, and legacy system provisions) and would interpret the regulation's scope narrowly, focused on records specifically required by predicate rules, rather than every electronic record a company happens to generate. This guidance remains in effect and is the reason Part 11 discussions among regulatory professionals typically distinguish between records required by a predicate rule (squarely within Part 11's scope) and records a company keeps voluntarily (generally outside Part 11's mandatory scope, though good practice may still apply comparable controls). Manufacturers should read the 2003 guidance directly, it is short, and it materially affects how the underlying 1997 regulation is actually enforced today.
Common Part 11 Myths
A few misconceptions recur often enough in vendor marketing and internal compliance discussions to address directly:
- "Part 11 requires FDA pre-approval of our software." It does not. There is no FDA software certification or pre-market approval process for Part 11 compliance. Companies validate their own systems (or hire a third party to help), and FDA evaluates that validation during an inspection or for-cause investigation, not in advance.
- "An electronic signature has to be a biometric signature (fingerprint, retina scan) to be Part 11 compliant." Non-biometric signatures are explicitly permitted under §11.200, provided they use at least two distinct identification components, typically a unique user ID and a password, employed together as a single act of signing.
- "Once we buy Part 11 compliant software, we're compliant." Compliance is a property of how a system is configured, used, and governed, not a property that transfers automatically with a software purchase. A genuinely capable EBR platform used with shared logins, or without a documented validation record, is not Part 11 compliant in practice regardless of what the vendor's marketing claims.
- "Part 11 applies to every electronic file our company creates." It applies specifically to records required to be kept, or signatures required to be provided, by a predicate rule. Internal working documents, draft marketing copy, or general business correspondence are outside Part 11's mandatory scope, though many companies choose to apply similar rigor as a matter of good practice.
Legacy Systems and Systems Nearing End of Life
FDA's 2003 guidance acknowledged that some legacy systems, implemented before Part 11 or before an organization had current Part 11 controls in place, may not have every technical control the regulation describes, and indicated enforcement discretion in some such cases where the system was otherwise operating with appropriate procedural controls and the underlying data integrity was not in question. This is a narrow, fact-specific allowance, not a blanket exemption for old software, and a manufacturer relying on it should have documented, current risk assessments and compensating procedural controls (like enhanced manual review) rather than simply asserting a system is "legacy" and leaving the gap unaddressed. If a legacy system is due for replacement, the safer posture is a documented remediation plan and timeline, not indefinite reliance on enforcement discretion for a system with no planned end date.
Frequently Asked Questions
(See the FAQ section below the article for answers to common questions about DocuSign, validation obligations, open systems, audit trail export requests, and self-declared compliance.)
Building a Part 11 Self-Assessment
Before evaluating any vendor, it is worth running your current system, whatever it is, through a short internal self-assessment against the controls above. Ask, for each Part 111 (or equivalent predicate rule) record you keep electronically: Is access to this record limited to authorized individuals, and can you demonstrate that limitation? Does every creation, modification, and deletion generate an automatic, unmodifiable audit trail entry? Is every signature applied to this record tied to a uniquely identified individual through at least two authentication factors, and does it capture the signer's name, timestamp, and the meaning of the signature? Has the system been validated, documented IQ/OQ/PQ, or an equivalent, rather than simply assumed to work correctly? If the honest answer to any of these is "we're not sure," that gap is where an FDA inspection or a serious data integrity incident is most likely to surface, and it is worth resolving before, not after, either happens.
How BatchBuddy Implements Part 11 Electronic Signatures and Controls
BatchBuddy's electronic signature system requires re-authentication, a fresh entry of user credentials, at the moment of every signable action rather than relying on an existing session, and records the signer's name, a system-generated timestamp, and the declared meaning of the signature as part of the permanent record. Every record creation, modification, and deletion across formulations, ingredients, batch records, and quality decisions is captured in an immutable, hash-chained audit trail that cannot be edited or deleted by any user, including administrators. Role-based access controls enforce authority checks so that, for example, a production operator cannot apply a quality release signature. Our AI copilot's Confirmation Gate requires an explicit human confirmation before any AI-suggested write action executes, and logs the confirming human's identity to the same audit trail as every manually-initiated action, reflecting our conservative position on the open AI-agent accountability question discussed above. To be direct about where we stand on validation: BatchBuddy's Part 11 posture is self-declared, not third-party certified, and our IQ/OQ/PQ validation work is in progress, not complete. We describe our controls as they exist today rather than asserting a compliance status we have not yet independently verified.
Frequently Asked Questions
Does 21 CFR Part 11 apply to dietary supplement manufacturers?
Part 11 applies whenever a predicate rule, for supplements that is 21 CFR Part 111, requires you to keep a record and you keep that record electronically or sign it electronically. Part 111 sets the recordkeeping requirement; Part 11 governs the electronic format once you choose (or need) to go digital.
Is DocuSign or a similar e-signature tool Part 11 compliant on its own?
A general-purpose e-signature tool can satisfy some Part 11 signature mechanics, but Part 11 compliance is a property of the whole record-keeping system, including audit trails, access controls, and record retention, not the signature widget alone. Using DocuSign to sign a PDF does not make the surrounding record-keeping system compliant.
What is the difference between a closed and an open system under Part 11?
A closed system is one where the company responsible for the records controls access to the system, typical of internal manufacturing software. An open system is one where access is not controlled by the record owner, such as records transmitted over an uncontrolled network. Open systems require additional controls like encryption and digital signature standards.
Do I need third-party validation to be Part 11 compliant?
Part 11 requires that your system be validated (§11.10(a)), but the regulation does not mandate a specific third-party certification body. Many companies self-validate through documented IQ/OQ/PQ; third-party validation adds independent assurance but is not itself a Part 11 requirement.
What has to be in a Part 11 audit trail?
Under §11.10(e), the audit trail must be secure, computer-generated, and time-stamped, must independently record the date, time, and nature of entries and actions that create, modify, or delete a record, must not obscure previously recorded information, and must be retained as long as the record itself and available for FDA review.
Can I keep some records on paper and others electronically under the same quality system?
Yes. Part 11 attaches record by record, based on the format you actually use for that specific record. A hybrid system with some paper records and some electronic records is legally permissible, though it creates more operational complexity than a single consistent format.
What is the 2003 Part 11 Scope and Application guidance?
It is FDA guidance narrowing the agency's enforcement approach to the original 1997 Part 11 rule, focusing enforcement on records required by predicate rules and exercising discretion on some validation and legacy-system provisions. It remains in effect and shapes how Part 11 is enforced today.