SlideShare a Scribd company logo
1 of 77
Download to read offline
Decoding 21 CFR Part 11
Sally Miranker, Head of Computer System Validation, Life Sciences, Perficient
2
ABOUT PERFICIENT
Perficient is a leading information
technology consulting firm serving
clients throughout North America.
We help clients implement business-driven technology
solutions that integrate business processes, improve
worker productivity, increase customer loyalty and create
a more agile enterprise to better respond to new
business opportunities.
3
Founded in 1997
Public, NASDAQ: PRFT
2014 revenue $456 million
Major market locations:
Allentown, Atlanta, Ann Arbor, Boston, Charlotte,
Chicago, Cincinnati, Columbus, Dallas, Denver,
Detroit, Fairfax, Houston, Indianapolis, Lafayette,
Milwaukee, Minneapolis, New York City, Northern
California, Oxford (UK), Southern California,
St. Louis, Toronto
Global delivery centers in China and India
>2,600 colleagues
Dedicated solution practices
~90% repeat business rate
Alliance partnerships with major technology vendors
Multiple vendor/industry technology and growth awards
PERFICIENT PROFILE
4
Business Process
Management
Customer Relationship
Management
Enterprise Performance
Management
Enterprise Information
Solutions
Enterprise Resource
Planning
Experience Design
Portal / Collaboration
Content Management
Information Management
Mobile
BUSINESSSOLUTIONS
50+PARTNERS
Safety / PV
Clinical Data
Management
Electronic Data Capture
Medical Coding
Clinical Data
Warehousing
Clinical Data Analytics
Clinical Trial
Management
Healthcare Data
Warehousing
Healthcare Analytics
CLINICAL/HEALTHCAREIT
Consulting
Implementation
Integration
Migration
Upgrade
Managed Services
Private Cloud Hosting
Validation
Study Setup
Project Management
Application Development
Software Licensing
Application Support
Staff Augmentation
Training
SERVICES
OUR SOLUTIONS PORTFOLIO
5
WELCOME & INTRODUCTION
Sally Miranker
Senior Project Manager,
Life Sciences, Perficient
• Senior Project Manager and head of computer system validation (CSV)
• Oversees CSV, system development life cycle (SDLC), and all project-related
validation-related activities performed by Perficient’s life sciences practice
• Ensures that internal and client systems are implemented effectively, in
compliance with internal procedures and federal regulations, and following best
industry practices
• 20 years experience in life sciences; past eight years focused on implementing
computer systems within regulated environments
6
AGENDA
• Explain what the name
“21 CFR Part 11” means
• Define key concepts
and terms
• Review the regulations,
section by section
• Highlight common points
of confusion and provide
clarification
• Discuss examples and
case studies
• Answer your questions
7
DECODING “21 CFR PART 11”
• CFR = “Code of Federal Regulations”
• 21 = “Title 21”
• Part 11 = Scope is specific to electronic records & electronic
signatures, including electronic submissions to the FDA
Details missing from the common title:
• Chapter I = Part 11 falls under “Chapter I” of the CFR
• Subchapter A = Part 11 falls under “Subchapter A – General” of
Chapter I of the CFR
8
21 CFR PART 11 CONTENT
9
SUBPART A:
GENERAL PROVISIONS
10
SUBPART A, SECTION 11.1
– SCOPE
11
SUBPART A, SECTION 11.1 – SCOPE
(a) The regulations in
this part set forth the
criteria under which
the agency considers
electronic records,
electronic signatures,
and handwritten
signatures executed to
electronic records to
be trustworthy,
reliable, and generally
equivalent to paper
records and handwritten
signatures executed on
paper.
Part 11 regs establish the
agency’s conditions for treating
electronic records the same as
paper records, and ink
signatures the same as
electronic signatures.
12
(b) This part applies to
records in electronic form
that are created, modified,
maintained, archived,
retrieved, or transmitted,
under any records
requirements set forth in
agency regulations. This part
also applies to electronic
records submitted to the
agency under requirements of
the Federal Food, Drug, and
Cosmetic Act and the Public
Health Service Act, even if
such records are not
specifically identified in
agency regulations. However,
this part does not apply to
paper records that are, or
have been, transmitted by
electronic means.
Part 11 applies to electronic
records that are used for
federally regulated purposes.
One clarification is made – a
paper record that is transmitted
electronically (e.g., as an email
attachment) is not subject
to Part 11.
SUBPART A, SECTION 11.1 – SCOPE
13
(c) Where electronic
signatures and their
associated electronic
records meet the
requirements of this
part, the agency will
consider the electronic
signatures to be
equivalent to full
handwritten signatures,
initials, and other
general signings as
required by agency
regulations, unless
specifically excepted by
regulation(s) effective
on or after August 20,
1997.
If an organization can prove that
its electronic signatures and
associated electronic records
comply with Part 11, the FDA will
accept electronic instead of ink.
However, an exception is
noted - if another regulation
specifically requires ink
signatures, that regulation
supersedes Part 11.
SUBPART A, SECTION 11.1 – SCOPE
14
(d) Electronic records
that meet the
requirements of this
part may be used in
lieu of paper records,
in accordance with
11.2, unless paper
records are
specifically required.
Same as (c) but specific to the
use of electronic records vs.
electronic signatures and their
associated electronic records.
An exception is noted - if some
other regulation specifically
requires paper records, that
regulation supersedes Part 11.
SUBPART A, SECTION 11.1 – SCOPE
15
(e) Computer systems
(including hardware and
software), controls,
and attendant
documentation
maintained under this
part shall be readily
available for, and
subject to, FDA
inspection.
Proof that a system complies
with Part 11 must be maintained
in such a way that the FDA can
inspect it.
SUBPART A, SECTION 11.1 – SCOPE
16
(f) This part does not
apply to records
required to be
established or
maintained by 1.326
through 1.368 of this
chapter. Records that
satisfy the
requirements of part 1,
subpart J of this
chapter, but that also
are required under
other applicable
statutory provisions or
regulations, remain
subject to this part.
A few very specific types of
records are excluded from
Part 11, but the vast majority
need to comply.
SUBPART A, SECTION 11.1 – SCOPE
17
SUBPART A, SECTION 11.2
– IMPLEMENTATION
18
SUBPART A, SECTION 11.2 – IMPLEMENTATION
(a) For records
required to be
maintained but not
submitted to the
agency, persons may use
electronic records in
lieu of paper records
or electronic
signatures in lieu of
traditional signatures,
in whole or in part,
provided that the
requirements of this
part are met.
For regulated records that are
not submitted to the FDA,
organizations may use
electronic instead of paper as
long as they can prove that their
electronic records comply with
Part 11.
19
SUBPART A, SECTION 11.2 – IMPLEMENTATION
(b) For records
submitted to the
agency, persons may use
electronic records in
lieu of paper records
or electronic
signatures in lieu of
traditional signatures,
in whole or in part,
provided that:
(1) The requirements of
this part are met; and
For regulated records that
are submitted to the FDA,
organizations may use
electronic instead of paper as
long as two conditions are met:
First, they can prove that their
electronic records comply
with Part 11.
20
SUBPART A, SECTION 11.2 – IMPLEMENTATION
(b)(2) The document or
parts of a document to be
submitted have been
identified in public docket
No. 92S-0251 as being the
type of submission the
agency accepts in
electronic form. This
docket will identify
specifically what types of
documents or parts of
documents are acceptable
for submission in
electronic form without
paper records and the
agency receiving unit(s)
(e.g., specific center,
office, division, branch)
to which such submissions
may be made.
Second, the FDA is capable of
accepting those types of
records electronically.
The types of e-records that the
FDA accepts are listed in
public docket No. 92S-0251.
21
SUBPART A, SECTION 11.2 – IMPLEMENTATION
(b)(2) (cont.) Documents to
agency receiving unit(s)
not specified in the public
docket will not be
considered as official if
they are submitted in
electronic form; paper
forms of such documents
will be considered as
official and must accompany
any electronic records.
Persons are expected to
consult with the intended
agency receiving unit for
details on how (e.g.,
method of transmission,
media, file formats, and
technical protocols) and
whether to proceed with the
electronic submission.
Electronic documents submitted
to the FDA that are not called
out in the public docket won’t be
considered as official. In these
cases, the paper documents are
considered as official and must
also be sent along.
22
SUBPART A, SECTION 11.3
– DEFINITIONS
23
SUBPART A, SECTION 11.3 – DEFINITIONS
(a) The definitions and
interpretations of
terms contained in
section 201 of the act
apply to those terms
when used in this part.
Some terms that are defined in
the Food, Drug, and Cosmetic
Act also apply to Part 11.
24
SUBPART A, SECTION 11.3 – DEFINITIONS
(b) The following
definitions of terms
also apply to this
part:
(1) Act means the
Federal Food, Drug, and
Cosmetic Act (secs.
201-903 (21 U.S.C. 321-
393)).
(2) Agency means the
Food and Drug
Administration.
Act: Short for Food, Drug,
and Cosmetic Act
Agency: Short for Food and
Drug Administration (FDA)
25
SUBPART A, SECTION 11.3 – DEFINITIONS
(3) Biometrics means a
method of verifying an
individual's identity
based on measurement of
the individual's
physical feature(s) or
repeatable action(s)
where those features
and/or actions are both
unique to that
individual and
measurable.
Biometrics: A way to verify
someone’s identity through
a unique physical trait
(e.g., fingerprint).
26
SUBPART A, SECTION 11.3 – DEFINITIONS
(4) Closed system means
an environment in which
system access is
controlled by persons
who are responsible for
the content of
electronic records that
are on the system.
Closed System: A computer
system where access is
controlled by the same people
responsible for its content.
27
SUBPART A, SECTION 11.3 – DEFINITIONS
(5) Digital
signature means an
electronic signature
based upon
cryptographic methods
of originator
authentication,
computed by using a set
of rules and a set of
parameters such that
the identity of the
signer and the
integrity of the data
can be verified.
Digital Signature: A type
of electronic signature that
includes a way of verifying
the identity of the signer and
the integrity of the record
they signed.
28
SUBPART A, SECTION 11.3 – DEFINITIONS
(6) Electronic
record means any
combination of text,
graphics, data, audio,
pictorial, or other
information
representation in
digital form that is
created, modified,
maintained, archived,
retrieved, or
distributed by a
computer system.
Electronic Record: Information
in digital form that is created or
used in some way by a
computer system.
29
SUBPART A, SECTION 11.3 – DEFINITIONS
(7) Electronic
signature means a
computer data
compilation of any
symbol or series of
symbols executed,
adopted, or authorized
by an individual to be
the legally binding
equivalent of the
individual's
handwritten signature.
Electronic Signature:
Compilation of electronic data
that is as unique and legally
binding as a handwritten
signature, but is used to sign
records in a computer system.
30
SUBPART A, SECTION 11.3 – DEFINITIONS
(8) Handwritten
signature means the
scripted name or legal
mark of an individual
handwritten by that
individual and executed or
adopted with the present
intention to authenticate
a writing in a permanent
form. The act of signing
with a writing or marking
instrument such as a pen
or stylus is preserved.
The scripted name or legal
mark, while conventionally
applied to paper, may also
be applied to other
devices that capture the
name or mark.
Handwritten Signature:
A scripted name or legal mark
created by an individual that
is unique to that individual
and is used to authenticate
something in writing.
31
SUBPART A, SECTION 11.3 – DEFINITIONS
(9) Open system means
an environment in which
system access is not
controlled by persons
who are responsible for
the content of
electronic records that
are on the system.
Open System: A computer
system that’s access is not
controlled by the same people
responsible for its contents.
32
SUBPART B:
ELECTRONIC RECORDS
33
SUBPART B, SECTION
11.10 – CONTROLS FOR
CLOSED SYSTEMS
34
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
Persons who use closed
systems to create,
modify, maintain, or
transmit electronic
records shall employ
procedures and controls
designed to ensure the
authenticity, integrity,
and, when appropriate,
the confidentiality of
electronic records, and
to ensure that the
signer cannot readily
repudiate the signed
record as not genuine.
Such procedures and
controls shall include
the following:
Organizations responsible for
electronic records in a closed
system must document the
procedures they follow and the
controls they have in place for
ensuring that their electronic
records have these qualities:
• Authenticity
• Integrity
• Confidentiality (as needed)
• Irrefutability
35
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
(a) Validation of
systems to ensure
accuracy, reliability,
consistent intended
performance, and the
ability to discern
invalid or altered
records.
Organizations responsible for
electronic records in a closed
system must validate the system
to prove that the records in the
system can be trusted.
36
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
(b) The ability to
generate accurate and
complete copies of
records in both human
readable and electronic
form suitable for
inspection, review, and
copying by the agency.
Persons should contact
the agency if there are
any questions regarding
the ability of the
agency to perform such
review and copying of
the electronic records.
Organizations must ensure
that the electronic records
generated from a closed system
contain complete and accurate
data, and must be in a
language/format that humans
can understand.
37
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
(c) Protection of
records to enable their
accurate and ready
retrieval throughout
the records retention
period.
Organizations must ensure
electronic records (data and
documents) in a closed system
are protected and retrievable by
establishing and maintaining
processes for the storage,
retrieval, and retention period.
38
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
(d) Limiting system
access to authorized
individuals.
Organizations need to
ensure that only authorized
people have access to each
computer system.
39
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
(e) Use of secure,
computer-generated, time-
stamped audit trails to
independently record the
date and time of operator
entries and actions that
create, modify, or delete
electronic records. Record
changes shall not obscure
previously recorded
information. Such audit
trail documentation shall
be retained for a period
at least as long as that
required for the subject
electronic records and
shall be available for
agency review and copying.
A secure and complete
history (audit trail) of an
electronic record should be
automatically generated by
a computer system.
A change to an electronic
record should not alter the
record’s history.
Audit trail documentation
should be:
• Retained for the correct
amount of time
• Available for viewing
40
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
(f) Use of operational
system checks to
enforce permitted
sequencing of steps and
events, as appropriate.
Organizations should ensure
that electronic workflows in
computer systems function
correctly.
41
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
(g) Use of authority
checks to ensure that
only authorized
individuals can use the
system, electronically
sign a record, access
the operation or
computer system input
or output device, alter
a record, or perform
the operation at hand.
Organizations should limit
system access (at the system
and record level) and verify
that the users performing
functions in the system
are authorized to do so.
42
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
(h) Use of device
(e.g., terminal) checks
to determine, as
appropriate, the
validity of the source
of data input or
operational
instruction.
Organizations should ensure
that devices used to enter
data into a computer system
operate correctly and that
the entered data is valid.
43
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
(i) Determination that
persons who develop,
maintain, or use
electronic
record/electronic
signature systems have
the education,
training, and
experience to perform
their assigned tasks.
Organizations should
ensure that people who
perform functions on or
within the system are
appropriately qualified.
44
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
(j) The establishment
of, and adherence to,
written policies that
hold individuals
accountable and
responsible for actions
initiated under their
electronic signatures,
in order to deter
record and signature
falsification.
Organizations should
establish policies to hold
individuals accountable for the
integrity of their actions related
to electronic records and
electronic signatures.
45
SUBPART B, SECTION 11.10 –
CONTROLS FOR CLOSED SYSTEMS
(k) Use of appropriate
controls over systems
documentation
including:
(1) Adequate controls
over the distribution
of, access to, and use
of documentation for
system operation and
maintenance.
(2) Revision and change
control procedures to
maintain an audit trail
that documents time-
sequenced development
and modification of
systems documentation.
Organizations should control
documents related to system
operation and maintenance
and preserve the complete
history of changes made
to these documents.
46
SUBPART B, SECTION
11.30 – CONTROLS FOR
OPEN SYSTEMS
47
SUBPART B, SECTION 11.30 –
CONTROLS FOR OPEN SYSTEMS
Persons who use open systems to
create, modify, maintain, or
transmit electronic records
shall employ procedures and
controls designed to ensure the
authenticity, integrity, and,
as appropriate, the
confidentiality of electronic
records from the point of their
creation to the point of their
receipt. Such procedures and
controls shall include those
identified in 11.10, as
appropriate, and additional
measures such as document
encryption and use of
appropriate digital signature
standards to ensure, as
necessary under the
circumstances, record
authenticity, integrity, and
confidentiality.
When organizations use
open systems, all of the
regulations for closed
systems still apply but,
additional steps need to be
taken to ensure the record
qualities of authenticity,
integrity, confidentiality, and
irrefutability described in
section 11.10.
48
SUBPART B, SECTION
11.50 – SIGNATURE
MANIFESTATIONS
49
SUBPART B, SECTION 11.50 –
SIGNATURE MANIFESTATIONS
(a) Signed electronic
records shall contain
information associated
with the signing that
clearly indicates all
of the following:
(1) The printed name of
the signer;
(2) The date and time
when the signature was
executed; and
(3) The meaning (such
as review, approval,
responsibility, or
authorship) associated
with the signature.
When an electronic record is
signed, the record must contain
information associated with its
signing that indicates:
• Printed name of signer
• Date and time of signature
• Meaning of signature
50
SUBPART B, SECTION 11.50 –
SIGNATURE MANIFESTATIONS
(b) The items
identified in
paragraphs (a)(1),
(a)(2), and (a)(3) of
this section shall be
subject to the same
controls as for
electronic records and
shall be included as
part of any human
readable form of the
electronic record (such
as electronic display
or printout).
When an electronic record is
signed, the bulleted items in (a)
are subject to the same controls
for electronic records and must
be in human-readable format.
51
SUBPART B, SECTION
11.70 –
SIGNATURE/RECORD
LINKING
52
SUBPART B, SECTION 11.70 –
SIGNATURE/RECORD LINKING
Electronic signatures
and handwritten
signatures executed to
electronic records
shall be linked to
their respective
electronic records to
ensure that the
signatures cannot be
excised, copied, or
otherwise transferred
to falsify an
electronic record by
ordinary means.
A signature (ink or electronic)
executed on an electronic
record has to be connected
to that record forever. It cannot
be removed, covered over,
erased, transferred, etc.
53
SUBPART C:
ELECTRONIC
SIGNATURES
54
SUBPART C, SECTION
11.100 – GENERAL
REQUIREMENTS
55
SUBPART C, SECTION 11.100 –
GENERAL REQUIREMENTS
(a) Each electronic
signature shall be
unique to one
individual and shall
not be reused by, or
reassigned to, anyone
else.
Organizations using electronic
signatures should ensure that
each signer has a unique
electronic signature cannot
be used by anyone else.
56
SUBPART C, SECTION 11.100 –
GENERAL REQUIREMENTS
(b) Before an
organization
establishes, assigns,
certifies, or otherwise
sanctions an
individual's electronic
signature, or any
element of such
electronic signature,
the organization shall
verify the identity of
the individual.
Before allowing an individual
to execute their electronic
signature, an organization
needs to first verify the
identity of that individual.
57
SUBPART C, SECTION 11.100 –
GENERAL REQUIREMENTS
(c) Persons using
electronic signatures
shall, prior to or at
the time of such use,
certify to the agency
that the electronic
signatures in their
system, used on or
after August 20, 1997,
are intended to be the
legally binding
equivalent of
traditional handwritten
signatures.
Before an organization
implements the use of
electronic signatures, it must
notify the FDA of its intention
and state that it will consider
electronic signatures to be
as legally binding as ink
signatures.
58
SUBPART C, SECTION 11.100 –
GENERAL REQUIREMENTS
(c)(1) The certification
shall be submitted in
paper form and signed with
a traditional handwritten
signature, to the Office
of Regional Operations
(HFC-100), 5600 Fishers
Lane, Rockville, MD 20857.
(c)(2) Persons using
electronic signatures
shall, upon agency
request, provide
additional certification
or testimony that a
specific electronic
signature is the legally
binding equivalent of the
signer's handwritten
signature.
The first step in the notification
process is to write an Electronic
Signature Certificate Statement
that is signed with ink signatures
and mail it to the FDA at the
Office of Regional Operations
(HFC-100), 5600 Fishers Lane,
Rockville, MD 20857.
If the FDA asks for additional
proof that the organization will
consider electronic signatures
to be legally binding, the
organization must provide it.
59
SUBPART C, SECTION
11.200 – ELECTRONIC
SIGNATURE
COMPONENTS AND
CONTROLS
60
SUBPART C, SECTION 11.200 – ELECTRONIC
SIGNATURE COMPONENTS AND CONTROLS
(a) Electronic
signatures that are not
based upon biometrics
shall:
(1) Employ at least two
distinct identification
components such as an
identification code and
password.
Electronic signatures that are
not biometric (i.e., not based
on a physical feature, like a
fingerprint) should employ at
least two distinct identification
components (i.e., user ID
and password).
61
SUBPART C, SECTION 11.200 – ELECTRONIC
SIGNATURE COMPONENTS AND CONTROLS
(a)(1)(i) When an
individual executes a
series of signings
during a single,
continuous period of
controlled system
access, the first
signing shall be
executed using all
electronic signature
components; subsequent
signings shall be
executed using at least
one electronic signature
component that is only
executable by, and
designed to be used only
by, the individual.
When using electronic signatures:
• The first time after logging in,
to execute their e-sig, a signer
must enter all of their
credentials (e.g., user ID and
password)
• For signings after that, but
during that same login
session, the signer has to only
enter one credential (e.g.,
password)
62
SUBPART C, SECTION 11.200 – ELECTRONIC
SIGNATURE COMPONENTS AND CONTROLS
(a)(1)(ii) When an
individual executes one
or more signings not
performed during a
single, continuous
period of controlled
system access, each
signing shall be
executed using all of
the electronic
signature components.
Each time a user logs out
(or is timed out) and logs back
into a system, the user executes
their electronic signature, the
clock restarts, and the user has
to enter all of their signature
components (i.e., user ID and
password).
63
SUBPART C, SECTION 11.200 – ELECTRONIC
SIGNATURE COMPONENTS AND CONTROLS
(a)(2) Be used only by
their genuine owners;
and
(a)(3) Be administered
and executed to ensure
that attempted use of
an individual's
electronic signature by
anyone other than its
genuine owner requires
collaboration of two or
more individuals.
Electronic signatures may only
be used by the individuals to
which they are assigned.
Electronic signatures should be
set up so that it would take two
or more people acting together
to attempt to use someone
else’s signature.
64
SUBPART C, SECTION 11.200 – ELECTRONIC
SIGNATURE COMPONENTS AND CONTROLS
(b) Electronic
signatures based upon
biometrics shall be
designed to ensure that
they cannot be used by
anyone other than their
genuine owners.
Electronic signatures that
are biometric (e.g., based on
a retinal scan) can only be
used by the individuals they
are assigned to.
65
SUBPART C, SECTION
11.300 – CONTROLS FOR
IDENTIFICATION
CODES/PASSWORDS
66
SUBPART C, SECTION 11.300 – CONTROLS
FOR IDENTIFICATION CODES/PASSWORDS
Persons who use
electronic signatures
based upon use of
identification codes in
combination with
passwords shall employ
controls to ensure
their security and
integrity. Such
controls shall include:
Organizations using
electronic signatures should
employ controls over user
identification codes.
67
SUBPART C, SECTION 11.300 – CONTROLS
FOR IDENTIFICATION CODES/PASSWORDS
(a) Maintaining the
uniqueness of each
combined identification
code and password, such
that no two individuals
have the same
combination of
identification code and
password.
Controls should ensure that
no two users can have the
same combination of user ID
and password; each
combination must be unique.
68
SUBPART C, SECTION 11.300 – CONTROLS
FOR IDENTIFICATION CODES/PASSWORDS
(b) Ensuring that
identification code and
password issuances are
periodically checked,
recalled, or revised
(e.g., to cover such
events as password
aging).
Passwords must be changed
periodically and should be
set to expire after a set period
of time. Organizations should
establish and maintain
policies and/or procedures
to address password
distribution and expiration.
69
SUBPART C, SECTION 11.300 – CONTROLS
FOR IDENTIFICATION CODES/PASSWORDS
(c) Following loss
management procedures
to electronically
deauthorize lost,
stolen, missing, or
otherwise potentially
compromised tokens,
cards, and other
devices that bear or
generate identification
code or password
information, and to
issue temporary or
permanent replacements
using suitable,
rigorous controls.
If a passcode token/device
is lost or stolen, it must be
de-authorized and a secure
replacement must be issued.
70
SUBPART C, SECTION 11.300 – CONTROLS
FOR IDENTIFICATION CODES/PASSWORDS
(d) Use of transaction
safeguards to prevent
unauthorized use of
passwords and/or
identification codes,
and to detect and
report in an immediate
and urgent manner any
attempts at their
unauthorized use to the
system security unit,
and, as appropriate, to
organizational
management.
Unauthorized attempts to use
a user ID or password/passcode
must be detected and
reported to the appropriate
person/group in the
organization for investigation.
71
SUBPART C, SECTION 11.300 – CONTROLS
FOR IDENTIFICATION CODES/PASSWORDS
(e) Initial and
periodic testing of
devices, such as tokens
or cards, that bear or
generate identification
code or password
information to ensure
that they function
properly and have not
been altered in an
unauthorized manner.
Passcode tokens must be
tested before they are issued
for use and tested periodically
while in use to make sure
they are functioning correctly.
72
21 CFR PART 11:
ONE FINAL LOOK
73
SUMMARY
Subpart A – General Provisions
 Part 11 applies to all electronic records that fall under
FDA regulations.
 If an organization can prove to an auditor that their electronic
records/signatures are as trustworthy as paper records/ink signatures,
the FDA will accept electronic instead of paper.
 The FDA will accept electronic submission instead of paper IF those
submissions 1) adhere to Part 11 requirements and 2) are included
among the types of documents that the FDA accepts electronically.
74
SUMMARY (CONT.)
Subpart B – Electronic Records
 Organizations using electronic records must establish and document
procedures and controls that ensure the authenticity, integrity,
confidentiality, and irrefutability of their records.
 The following topics must be addressed in documented procedures and
controls: computer system validation (CSV), record rendering, document
storage and record retention, system access, audit trails, workflows,
authority checks, device checks, personnel qualifications, personnel
accountability, and document control.
 Systems that fall into the category of “Open” (as defined in Subpart A)
require additional measures of control.
 Electronic signatures must include information to indicate the printed name
of the signer, the date and time of the signature, and the meaning of the
signature.
 Electronic signatures must be forever linked to their respective records.
75
SUMMARY (CONT.)
Subpart C – Electronic Signatures
 Organizations that wish to use electronic signatures must inform the
FDA in writing prior to making the switch.
 Each individual who will be using an electronic signature must 1) have
their identity confirmed and 2) use a unique signature that has never
been and will never be used by another individual.
 There are specific design requirements for electronic signatures that
are biometric (e.g., fingerprint scan) and those that are not (e.g., user
ID and password).
 For electronic signatures that make use of user IDs and
passwords/passcodes, there are specific requirements for passwords
and for passcode-generating devices.
76
QUESTIONS?
77
www.facebook.com/perficientwww.twitter.com/perficient_LS
For more information, please contact:
Sally.Miranker@perficient.com
LifeSciencesInfo@perficient.com (Sales)
+1 877 654 0033 (U.S. Sales)
+1 303 570 8464 (U.S. Sales)
+44 (0) 1865 910200 (U.K. Sales)
Submit a question directly to the FDA via email:
Industry.Drugs@fda.gov
(source www.fda.gov, Home>For Industry>FDA Basics for Industry>Submit Questions and Comments)
THANK YOU
linkedin.com/company/perficient

More Related Content

What's hot

Top 20 observation series # 5 21 CFR 211.100
Top 20 observation series # 5   21 CFR 211.100Top 20 observation series # 5   21 CFR 211.100
Top 20 observation series # 5 21 CFR 211.100Sathish Vemula
 
GOOD AUTOMATED LABORATORY PRACTICE
GOOD AUTOMATED LABORATORY PRACTICEGOOD AUTOMATED LABORATORY PRACTICE
GOOD AUTOMATED LABORATORY PRACTICEjagrutivasava
 
Difference european drug master file & us drug master file
Difference european drug master file & us drug master fileDifference european drug master file & us drug master file
Difference european drug master file & us drug master fileDinesh Kumar M Prajapati
 
Post Marketing Survelliance.pptx
Post Marketing Survelliance.pptxPost Marketing Survelliance.pptx
Post Marketing Survelliance.pptxPrachiSharma575050
 
Good Documentation Practice (GDP)
Good Documentation Practice (GDP)Good Documentation Practice (GDP)
Good Documentation Practice (GDP)Hossen M. Faruk
 
ASEAN COUNTRIES.pptx
ASEAN COUNTRIES.pptxASEAN COUNTRIES.pptx
ASEAN COUNTRIES.pptxAartiVats5
 
21 cfr part 11 an approach towards compliance
21 cfr part 11   an approach towards compliance21 cfr part 11   an approach towards compliance
21 cfr part 11 an approach towards compliancedeepak mishra
 
Auditing of manufacturing facilities by international regulatory agencies ppt
Auditing of manufacturing facilities by international regulatory agencies pptAuditing of manufacturing facilities by international regulatory agencies ppt
Auditing of manufacturing facilities by international regulatory agencies pptTek kaushik
 
Pharmaceutical Data integrity training
Pharmaceutical Data integrity trainingPharmaceutical Data integrity training
Pharmaceutical Data integrity trainingMoataz El Halawany
 
Anda refuse to receive
Anda   refuse to receiveAnda   refuse to receive
Anda refuse to receivesantoshnarla
 
Ich Q7A Guidelines
Ich Q7A GuidelinesIch Q7A Guidelines
Ich Q7A GuidelinesManali Parab
 

What's hot (20)

Cfr 21 part 11
 Cfr 21 part 11 Cfr 21 part 11
Cfr 21 part 11
 
Top 20 observation series # 5 21 CFR 211.100
Top 20 observation series # 5   21 CFR 211.100Top 20 observation series # 5   21 CFR 211.100
Top 20 observation series # 5 21 CFR 211.100
 
21 cfr, parts 210 211
21 cfr, parts 210 21121 cfr, parts 210 211
21 cfr, parts 210 211
 
21 CFR Part 11.pptx
21 CFR Part 11.pptx21 CFR Part 11.pptx
21 CFR Part 11.pptx
 
21 cfr part 11 basic
21 cfr part 11 basic21 cfr part 11 basic
21 cfr part 11 basic
 
GOOD AUTOMATED LABORATORY PRACTICE
GOOD AUTOMATED LABORATORY PRACTICEGOOD AUTOMATED LABORATORY PRACTICE
GOOD AUTOMATED LABORATORY PRACTICE
 
Difference european drug master file & us drug master file
Difference european drug master file & us drug master fileDifference european drug master file & us drug master file
Difference european drug master file & us drug master file
 
Post Marketing Survelliance.pptx
Post Marketing Survelliance.pptxPost Marketing Survelliance.pptx
Post Marketing Survelliance.pptx
 
21C CRF Part 11
21C CRF Part 1121C CRF Part 11
21C CRF Part 11
 
Good Documentation Practice (GDP)
Good Documentation Practice (GDP)Good Documentation Practice (GDP)
Good Documentation Practice (GDP)
 
ASEAN COUNTRIES.pptx
ASEAN COUNTRIES.pptxASEAN COUNTRIES.pptx
ASEAN COUNTRIES.pptx
 
ALCOA & ALCOA+
ALCOA & ALCOA+ALCOA & ALCOA+
ALCOA & ALCOA+
 
21 CFR part 11 Overview
21 CFR part 11 Overview21 CFR part 11 Overview
21 CFR part 11 Overview
 
Fda Inspection
Fda InspectionFda Inspection
Fda Inspection
 
21 cfr part 11 an approach towards compliance
21 cfr part 11   an approach towards compliance21 cfr part 11   an approach towards compliance
21 cfr part 11 an approach towards compliance
 
Auditing of manufacturing facilities by international regulatory agencies ppt
Auditing of manufacturing facilities by international regulatory agencies pptAuditing of manufacturing facilities by international regulatory agencies ppt
Auditing of manufacturing facilities by international regulatory agencies ppt
 
Pharmaceutical Data integrity training
Pharmaceutical Data integrity trainingPharmaceutical Data integrity training
Pharmaceutical Data integrity training
 
C gmp final
C gmp finalC gmp final
C gmp final
 
Anda refuse to receive
Anda   refuse to receiveAnda   refuse to receive
Anda refuse to receive
 
Ich Q7A Guidelines
Ich Q7A GuidelinesIch Q7A Guidelines
Ich Q7A Guidelines
 

Viewers also liked

21 cfr part 11 compliance
21 cfr part 11 compliance21 cfr part 11 compliance
21 cfr part 11 complianceKiran Kota
 
Interpretation of Part 11 by the GxP Predicate Rules
Interpretation of Part 11 by the GxP Predicate RulesInterpretation of Part 11 by the GxP Predicate Rules
Interpretation of Part 11 by the GxP Predicate RulesTony Steinberg
 
Medical device regulations in india
Medical device regulations in indiaMedical device regulations in india
Medical device regulations in indiaSuraj Pamadi
 
2013 OHSUG - Clinical Data Warehouse Implementation
2013 OHSUG - Clinical Data Warehouse Implementation2013 OHSUG - Clinical Data Warehouse Implementation
2013 OHSUG - Clinical Data Warehouse ImplementationPerficient
 
"GAMP 5 & 21 CFR Part 11 Compliance with Computer System Validation”
"GAMP 5 & 21 CFR Part 11 Compliance with Computer System Validation”"GAMP 5 & 21 CFR Part 11 Compliance with Computer System Validation”
"GAMP 5 & 21 CFR Part 11 Compliance with Computer System Validation”Marcep Inc.
 
FDA/EC/WHO Expectations for Computer System Validation
FDA/EC/WHO Expectations for Computer System Validation FDA/EC/WHO Expectations for Computer System Validation
FDA/EC/WHO Expectations for Computer System Validation Muhammad Luqman Ikram
 
Presentation on regulatory affairs 30032013
Presentation on regulatory affairs 30032013Presentation on regulatory affairs 30032013
Presentation on regulatory affairs 30032013Nishodh Saxena Ph. D.
 
eTMF Structure, Setup, and Implementation Case Study
eTMF Structure, Setup, and Implementation Case StudyeTMF Structure, Setup, and Implementation Case Study
eTMF Structure, Setup, and Implementation Case StudyAdair Turner, MS, RAC
 
Introduction to pharma industry
Introduction to pharma industryIntroduction to pharma industry
Introduction to pharma industryGirish Swami
 
Pharma data integrity
Pharma data integrityPharma data integrity
Pharma data integrityGirish Swami
 
Dissolution and In Vitro In Vivo Correlation (IVIVC)
Dissolution and In Vitro In Vivo Correlation (IVIVC)Dissolution and In Vitro In Vivo Correlation (IVIVC)
Dissolution and In Vitro In Vivo Correlation (IVIVC)Jaspreet Guraya
 
Computer System Validation
Computer System ValidationComputer System Validation
Computer System ValidationEric Silva
 
Pharma regulatory affairs
Pharma regulatory affairsPharma regulatory affairs
Pharma regulatory affairsGirish Swami
 
Testing Big Data: Automated Testing of Hadoop with QuerySurge
Testing Big Data: Automated  Testing of Hadoop with QuerySurgeTesting Big Data: Automated  Testing of Hadoop with QuerySurge
Testing Big Data: Automated Testing of Hadoop with QuerySurgeRTTS
 
What is a Data Warehouse and How Do I Test It?
What is a Data Warehouse and How Do I Test It?What is a Data Warehouse and How Do I Test It?
What is a Data Warehouse and How Do I Test It?RTTS
 
Overview of Computerized Systems Compliance Using the GAMP® 5 Guide
Overview of Computerized Systems Compliance Using the GAMP® 5 GuideOverview of Computerized Systems Compliance Using the GAMP® 5 Guide
Overview of Computerized Systems Compliance Using the GAMP® 5 GuideProPharma Group
 

Viewers also liked (20)

21 cfr part 11 compliance
21 cfr part 11 compliance21 cfr part 11 compliance
21 cfr part 11 compliance
 
FDA 21 CFR Part 11 and Related Regulations and Guidances
FDA 21 CFR Part 11 and Related Regulations and GuidancesFDA 21 CFR Part 11 and Related Regulations and Guidances
FDA 21 CFR Part 11 and Related Regulations and Guidances
 
Interpretation of Part 11 by the GxP Predicate Rules
Interpretation of Part 11 by the GxP Predicate RulesInterpretation of Part 11 by the GxP Predicate Rules
Interpretation of Part 11 by the GxP Predicate Rules
 
HySynth Clinical Data Repository
HySynth Clinical Data RepositoryHySynth Clinical Data Repository
HySynth Clinical Data Repository
 
Understanding 21 cfr part 11
Understanding 21 cfr part 11Understanding 21 cfr part 11
Understanding 21 cfr part 11
 
Medical device regulations in india
Medical device regulations in indiaMedical device regulations in india
Medical device regulations in india
 
2013 OHSUG - Clinical Data Warehouse Implementation
2013 OHSUG - Clinical Data Warehouse Implementation2013 OHSUG - Clinical Data Warehouse Implementation
2013 OHSUG - Clinical Data Warehouse Implementation
 
"GAMP 5 & 21 CFR Part 11 Compliance with Computer System Validation”
"GAMP 5 & 21 CFR Part 11 Compliance with Computer System Validation”"GAMP 5 & 21 CFR Part 11 Compliance with Computer System Validation”
"GAMP 5 & 21 CFR Part 11 Compliance with Computer System Validation”
 
FDA/EC/WHO Expectations for Computer System Validation
FDA/EC/WHO Expectations for Computer System Validation FDA/EC/WHO Expectations for Computer System Validation
FDA/EC/WHO Expectations for Computer System Validation
 
Presentation on regulatory affairs 30032013
Presentation on regulatory affairs 30032013Presentation on regulatory affairs 30032013
Presentation on regulatory affairs 30032013
 
eTMF Structure, Setup, and Implementation Case Study
eTMF Structure, Setup, and Implementation Case StudyeTMF Structure, Setup, and Implementation Case Study
eTMF Structure, Setup, and Implementation Case Study
 
Introduction to pharma industry
Introduction to pharma industryIntroduction to pharma industry
Introduction to pharma industry
 
Pharma data integrity
Pharma data integrityPharma data integrity
Pharma data integrity
 
Dissolution and In Vitro In Vivo Correlation (IVIVC)
Dissolution and In Vitro In Vivo Correlation (IVIVC)Dissolution and In Vitro In Vivo Correlation (IVIVC)
Dissolution and In Vitro In Vivo Correlation (IVIVC)
 
USFDA NDA Vs BLA
USFDA NDA Vs BLAUSFDA NDA Vs BLA
USFDA NDA Vs BLA
 
Computer System Validation
Computer System ValidationComputer System Validation
Computer System Validation
 
Pharma regulatory affairs
Pharma regulatory affairsPharma regulatory affairs
Pharma regulatory affairs
 
Testing Big Data: Automated Testing of Hadoop with QuerySurge
Testing Big Data: Automated  Testing of Hadoop with QuerySurgeTesting Big Data: Automated  Testing of Hadoop with QuerySurge
Testing Big Data: Automated Testing of Hadoop with QuerySurge
 
What is a Data Warehouse and How Do I Test It?
What is a Data Warehouse and How Do I Test It?What is a Data Warehouse and How Do I Test It?
What is a Data Warehouse and How Do I Test It?
 
Overview of Computerized Systems Compliance Using the GAMP® 5 Guide
Overview of Computerized Systems Compliance Using the GAMP® 5 GuideOverview of Computerized Systems Compliance Using the GAMP® 5 Guide
Overview of Computerized Systems Compliance Using the GAMP® 5 Guide
 

Similar to Decoding 21 CFR Part 11

Clear cut line by line interpretation on 21 cfr part 11
Clear cut line by line interpretation on 21 cfr part 11Clear cut line by line interpretation on 21 cfr part 11
Clear cut line by line interpretation on 21 cfr part 11Pari S
 
Achieving 21 Code of Federal Regulations (CFR) Part11
Achieving 21 Code of Federal Regulations (CFR) Part11Achieving 21 Code of Federal Regulations (CFR) Part11
Achieving 21 Code of Federal Regulations (CFR) Part11SamuelP9
 
21 CFR Part11_CSV Training_Katalyst HLS
21 CFR Part11_CSV Training_Katalyst HLS21 CFR Part11_CSV Training_Katalyst HLS
21 CFR Part11_CSV Training_Katalyst HLSKatalyst HLS
 
WP_UL Compliance wth 21CFR Part_11
WP_UL Compliance wth 21CFR Part_11WP_UL Compliance wth 21CFR Part_11
WP_UL Compliance wth 21CFR Part_11Jamie Corn, MBA
 
21 CFR part 11- ELECTRONIC RECORDS; ELECTRONIC SIGNATURES
21 CFR part 11-ELECTRONIC RECORDS;ELECTRONIC SIGNATURES21 CFR part 11-ELECTRONIC RECORDS;ELECTRONIC SIGNATURES
21 CFR part 11- ELECTRONIC RECORDS; ELECTRONIC SIGNATURESMayur Patil
 
21 CFR Part 11.pptx
21 CFR Part 11.pptx21 CFR Part 11.pptx
21 CFR Part 11.pptxUrvi
 
21 CFR Part 11–The Biggest Security Regulation You Never Heard Of
21 CFR Part 11–The Biggest Security Regulation You Never Heard Of21 CFR Part 11–The Biggest Security Regulation You Never Heard Of
21 CFR Part 11–The Biggest Security Regulation You Never Heard OfBen Rothke
 
21 CFR Part 11–The Biggest Security Regulation You Never Heard Of
21 CFR Part 11–The Biggest Security Regulation You Never Heard Of21 CFR Part 11–The Biggest Security Regulation You Never Heard Of
21 CFR Part 11–The Biggest Security Regulation You Never Heard OfBen Rothke
 
Computer system validation
Computer system validationComputer system validation
Computer system validationGaurav Kr
 
Excel spreadsheets how to ensure 21 cfr part 11 compliance
Excel spreadsheets  how to ensure 21 cfr part 11 complianceExcel spreadsheets  how to ensure 21 cfr part 11 compliance
Excel spreadsheets how to ensure 21 cfr part 11 compliancecomplianceonline123
 
Cia 2011-0004-0001
Cia 2011-0004-0001Cia 2011-0004-0001
Cia 2011-0004-0001Margus Meigo
 
Computerized system validation
Computerized system validationComputerized system validation
Computerized system validationsimpleyadav8880
 
Federal Register - Oct 22, 2015 - EPA 40 CFR Part 98 - Greenhouse Gas Reporti...
Federal Register - Oct 22, 2015 - EPA 40 CFR Part 98 - Greenhouse Gas Reporti...Federal Register - Oct 22, 2015 - EPA 40 CFR Part 98 - Greenhouse Gas Reporti...
Federal Register - Oct 22, 2015 - EPA 40 CFR Part 98 - Greenhouse Gas Reporti...Marcellus Drilling News
 
21 hvac design manual
21 hvac design manual21 hvac design manual
21 hvac design manualbhattbhai
 

Similar to Decoding 21 CFR Part 11 (20)

Clear cut line by line interpretation on 21 cfr part 11
Clear cut line by line interpretation on 21 cfr part 11Clear cut line by line interpretation on 21 cfr part 11
Clear cut line by line interpretation on 21 cfr part 11
 
Achieving 21 Code of Federal Regulations (CFR) Part11
Achieving 21 Code of Federal Regulations (CFR) Part11Achieving 21 Code of Federal Regulations (CFR) Part11
Achieving 21 Code of Federal Regulations (CFR) Part11
 
21 CFR Part11_CSV Training_Katalyst HLS
21 CFR Part11_CSV Training_Katalyst HLS21 CFR Part11_CSV Training_Katalyst HLS
21 CFR Part11_CSV Training_Katalyst HLS
 
WP_UL Compliance wth 21CFR Part_11
WP_UL Compliance wth 21CFR Part_11WP_UL Compliance wth 21CFR Part_11
WP_UL Compliance wth 21CFR Part_11
 
Fda Pred Rules
Fda Pred RulesFda Pred Rules
Fda Pred Rules
 
Fda qms term
Fda   qms termFda   qms term
Fda qms term
 
21 CFR part 11- ELECTRONIC RECORDS; ELECTRONIC SIGNATURES
21 CFR part 11-ELECTRONIC RECORDS;ELECTRONIC SIGNATURES21 CFR part 11-ELECTRONIC RECORDS;ELECTRONIC SIGNATURES
21 CFR part 11- ELECTRONIC RECORDS; ELECTRONIC SIGNATURES
 
21 cfr part 11 hplc
21 cfr part 11 hplc21 cfr part 11 hplc
21 cfr part 11 hplc
 
21 cfr part 11 hplc
21 cfr part 11 hplc21 cfr part 11 hplc
21 cfr part 11 hplc
 
21 CFR Part 11.pptx
21 CFR Part 11.pptx21 CFR Part 11.pptx
21 CFR Part 11.pptx
 
21 CFR Part 11.pptx
21 CFR Part 11.pptx21 CFR Part 11.pptx
21 CFR Part 11.pptx
 
21 CFR Part 11–The Biggest Security Regulation You Never Heard Of
21 CFR Part 11–The Biggest Security Regulation You Never Heard Of21 CFR Part 11–The Biggest Security Regulation You Never Heard Of
21 CFR Part 11–The Biggest Security Regulation You Never Heard Of
 
21 CFR Part 11–The Biggest Security Regulation You Never Heard Of
21 CFR Part 11–The Biggest Security Regulation You Never Heard Of21 CFR Part 11–The Biggest Security Regulation You Never Heard Of
21 CFR Part 11–The Biggest Security Regulation You Never Heard Of
 
Computer system validation
Computer system validationComputer system validation
Computer system validation
 
21 CFR Part 11 Code of Federal Regulations.pptx
21 CFR Part 11 Code of Federal Regulations.pptx21 CFR Part 11 Code of Federal Regulations.pptx
21 CFR Part 11 Code of Federal Regulations.pptx
 
Excel spreadsheets how to ensure 21 cfr part 11 compliance
Excel spreadsheets  how to ensure 21 cfr part 11 complianceExcel spreadsheets  how to ensure 21 cfr part 11 compliance
Excel spreadsheets how to ensure 21 cfr part 11 compliance
 
Cia 2011-0004-0001
Cia 2011-0004-0001Cia 2011-0004-0001
Cia 2011-0004-0001
 
Computerized system validation
Computerized system validationComputerized system validation
Computerized system validation
 
Federal Register - Oct 22, 2015 - EPA 40 CFR Part 98 - Greenhouse Gas Reporti...
Federal Register - Oct 22, 2015 - EPA 40 CFR Part 98 - Greenhouse Gas Reporti...Federal Register - Oct 22, 2015 - EPA 40 CFR Part 98 - Greenhouse Gas Reporti...
Federal Register - Oct 22, 2015 - EPA 40 CFR Part 98 - Greenhouse Gas Reporti...
 
21 hvac design manual
21 hvac design manual21 hvac design manual
21 hvac design manual
 

More from Perficient, Inc.

Driving Strong 2020 Holiday Season Results
Driving Strong 2020 Holiday Season ResultsDriving Strong 2020 Holiday Season Results
Driving Strong 2020 Holiday Season ResultsPerficient, Inc.
 
Transforming Pharmacovigilance Workflows with AI & Automation
Transforming Pharmacovigilance Workflows with AI & Automation Transforming Pharmacovigilance Workflows with AI & Automation
Transforming Pharmacovigilance Workflows with AI & Automation Perficient, Inc.
 
The Secret to Acquiring and Retaining Customers in Financial Services
The Secret to Acquiring and Retaining Customers in Financial ServicesThe Secret to Acquiring and Retaining Customers in Financial Services
The Secret to Acquiring and Retaining Customers in Financial ServicesPerficient, Inc.
 
Oracle Strategic Modeling Live: Defined. Discussed. Demonstrated.
Oracle Strategic Modeling Live: Defined. Discussed. Demonstrated.Oracle Strategic Modeling Live: Defined. Discussed. Demonstrated.
Oracle Strategic Modeling Live: Defined. Discussed. Demonstrated.Perficient, Inc.
 
Content, Commerce, and... COVID
Content, Commerce, and... COVIDContent, Commerce, and... COVID
Content, Commerce, and... COVIDPerficient, Inc.
 
Centene's Financial Transformation Journey: A OneStream Success Story
Centene's Financial Transformation Journey: A OneStream Success StoryCentene's Financial Transformation Journey: A OneStream Success Story
Centene's Financial Transformation Journey: A OneStream Success StoryPerficient, Inc.
 
Automate Medical Coding With WHODrug Koda
Automate Medical Coding With WHODrug KodaAutomate Medical Coding With WHODrug Koda
Automate Medical Coding With WHODrug KodaPerficient, Inc.
 
Preparing for Your Oracle, Medidata, and Veeva CTMS Migration Project
Preparing for Your Oracle, Medidata, and Veeva CTMS Migration ProjectPreparing for Your Oracle, Medidata, and Veeva CTMS Migration Project
Preparing for Your Oracle, Medidata, and Veeva CTMS Migration ProjectPerficient, Inc.
 
Accelerating Partner Management: How Manufacturers Can Navigate Covid-19
Accelerating Partner Management: How Manufacturers Can Navigate Covid-19Accelerating Partner Management: How Manufacturers Can Navigate Covid-19
Accelerating Partner Management: How Manufacturers Can Navigate Covid-19Perficient, Inc.
 
The Critical Role of Audience Intelligence with Eric Enge and Rand Fishkin
The Critical Role of Audience Intelligence with Eric Enge and Rand FishkinThe Critical Role of Audience Intelligence with Eric Enge and Rand Fishkin
The Critical Role of Audience Intelligence with Eric Enge and Rand FishkinPerficient, Inc.
 
Cardtronics Future Ready with Oracle EPM Cloud
Cardtronics Future Ready with Oracle EPM CloudCardtronics Future Ready with Oracle EPM Cloud
Cardtronics Future Ready with Oracle EPM CloudPerficient, Inc.
 
Teams Summit - What is New and Coming
Teams Summit -  What is New and ComingTeams Summit -  What is New and Coming
Teams Summit - What is New and ComingPerficient, Inc.
 
Empower Your Organization with Teams & Remote Work Crisis Management
Empower Your Organization with Teams & Remote Work Crisis ManagementEmpower Your Organization with Teams & Remote Work Crisis Management
Empower Your Organization with Teams & Remote Work Crisis ManagementPerficient, Inc.
 
Adoption & Change Management Overview
Adoption & Change Management OverviewAdoption & Change Management Overview
Adoption & Change Management OverviewPerficient, Inc.
 
Microsoft Teams: Measuring Activity of Employees Working from Home
Microsoft Teams: Measuring Activity of Employees Working from HomeMicrosoft Teams: Measuring Activity of Employees Working from Home
Microsoft Teams: Measuring Activity of Employees Working from HomePerficient, Inc.
 
Securing Teams with Microsoft 365 Security for Remote Work
Securing Teams with Microsoft 365 Security for Remote WorkSecuring Teams with Microsoft 365 Security for Remote Work
Securing Teams with Microsoft 365 Security for Remote WorkPerficient, Inc.
 
Infrastructure Best Practices for Teams Remote Workers
Infrastructure Best Practices for Teams Remote WorkersInfrastructure Best Practices for Teams Remote Workers
Infrastructure Best Practices for Teams Remote WorkersPerficient, Inc.
 
Accelerate Adoption for Microsoft Teams
Accelerate Adoption for Microsoft TeamsAccelerate Adoption for Microsoft Teams
Accelerate Adoption for Microsoft TeamsPerficient, Inc.
 
Preparing for Project Cortex and the Future of Knowledge Management
Preparing for Project Cortex and the Future of Knowledge ManagementPreparing for Project Cortex and the Future of Knowledge Management
Preparing for Project Cortex and the Future of Knowledge ManagementPerficient, Inc.
 
Utilizing Microsoft 365 Security for Remote Work
Utilizing Microsoft 365 Security for Remote Work Utilizing Microsoft 365 Security for Remote Work
Utilizing Microsoft 365 Security for Remote Work Perficient, Inc.
 

More from Perficient, Inc. (20)

Driving Strong 2020 Holiday Season Results
Driving Strong 2020 Holiday Season ResultsDriving Strong 2020 Holiday Season Results
Driving Strong 2020 Holiday Season Results
 
Transforming Pharmacovigilance Workflows with AI & Automation
Transforming Pharmacovigilance Workflows with AI & Automation Transforming Pharmacovigilance Workflows with AI & Automation
Transforming Pharmacovigilance Workflows with AI & Automation
 
The Secret to Acquiring and Retaining Customers in Financial Services
The Secret to Acquiring and Retaining Customers in Financial ServicesThe Secret to Acquiring and Retaining Customers in Financial Services
The Secret to Acquiring and Retaining Customers in Financial Services
 
Oracle Strategic Modeling Live: Defined. Discussed. Demonstrated.
Oracle Strategic Modeling Live: Defined. Discussed. Demonstrated.Oracle Strategic Modeling Live: Defined. Discussed. Demonstrated.
Oracle Strategic Modeling Live: Defined. Discussed. Demonstrated.
 
Content, Commerce, and... COVID
Content, Commerce, and... COVIDContent, Commerce, and... COVID
Content, Commerce, and... COVID
 
Centene's Financial Transformation Journey: A OneStream Success Story
Centene's Financial Transformation Journey: A OneStream Success StoryCentene's Financial Transformation Journey: A OneStream Success Story
Centene's Financial Transformation Journey: A OneStream Success Story
 
Automate Medical Coding With WHODrug Koda
Automate Medical Coding With WHODrug KodaAutomate Medical Coding With WHODrug Koda
Automate Medical Coding With WHODrug Koda
 
Preparing for Your Oracle, Medidata, and Veeva CTMS Migration Project
Preparing for Your Oracle, Medidata, and Veeva CTMS Migration ProjectPreparing for Your Oracle, Medidata, and Veeva CTMS Migration Project
Preparing for Your Oracle, Medidata, and Veeva CTMS Migration Project
 
Accelerating Partner Management: How Manufacturers Can Navigate Covid-19
Accelerating Partner Management: How Manufacturers Can Navigate Covid-19Accelerating Partner Management: How Manufacturers Can Navigate Covid-19
Accelerating Partner Management: How Manufacturers Can Navigate Covid-19
 
The Critical Role of Audience Intelligence with Eric Enge and Rand Fishkin
The Critical Role of Audience Intelligence with Eric Enge and Rand FishkinThe Critical Role of Audience Intelligence with Eric Enge and Rand Fishkin
The Critical Role of Audience Intelligence with Eric Enge and Rand Fishkin
 
Cardtronics Future Ready with Oracle EPM Cloud
Cardtronics Future Ready with Oracle EPM CloudCardtronics Future Ready with Oracle EPM Cloud
Cardtronics Future Ready with Oracle EPM Cloud
 
Teams Summit - What is New and Coming
Teams Summit -  What is New and ComingTeams Summit -  What is New and Coming
Teams Summit - What is New and Coming
 
Empower Your Organization with Teams & Remote Work Crisis Management
Empower Your Organization with Teams & Remote Work Crisis ManagementEmpower Your Organization with Teams & Remote Work Crisis Management
Empower Your Organization with Teams & Remote Work Crisis Management
 
Adoption & Change Management Overview
Adoption & Change Management OverviewAdoption & Change Management Overview
Adoption & Change Management Overview
 
Microsoft Teams: Measuring Activity of Employees Working from Home
Microsoft Teams: Measuring Activity of Employees Working from HomeMicrosoft Teams: Measuring Activity of Employees Working from Home
Microsoft Teams: Measuring Activity of Employees Working from Home
 
Securing Teams with Microsoft 365 Security for Remote Work
Securing Teams with Microsoft 365 Security for Remote WorkSecuring Teams with Microsoft 365 Security for Remote Work
Securing Teams with Microsoft 365 Security for Remote Work
 
Infrastructure Best Practices for Teams Remote Workers
Infrastructure Best Practices for Teams Remote WorkersInfrastructure Best Practices for Teams Remote Workers
Infrastructure Best Practices for Teams Remote Workers
 
Accelerate Adoption for Microsoft Teams
Accelerate Adoption for Microsoft TeamsAccelerate Adoption for Microsoft Teams
Accelerate Adoption for Microsoft Teams
 
Preparing for Project Cortex and the Future of Knowledge Management
Preparing for Project Cortex and the Future of Knowledge ManagementPreparing for Project Cortex and the Future of Knowledge Management
Preparing for Project Cortex and the Future of Knowledge Management
 
Utilizing Microsoft 365 Security for Remote Work
Utilizing Microsoft 365 Security for Remote Work Utilizing Microsoft 365 Security for Remote Work
Utilizing Microsoft 365 Security for Remote Work
 

Recently uploaded

Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 

Recently uploaded (20)

Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 

Decoding 21 CFR Part 11

  • 1. Decoding 21 CFR Part 11 Sally Miranker, Head of Computer System Validation, Life Sciences, Perficient
  • 2. 2 ABOUT PERFICIENT Perficient is a leading information technology consulting firm serving clients throughout North America. We help clients implement business-driven technology solutions that integrate business processes, improve worker productivity, increase customer loyalty and create a more agile enterprise to better respond to new business opportunities.
  • 3. 3 Founded in 1997 Public, NASDAQ: PRFT 2014 revenue $456 million Major market locations: Allentown, Atlanta, Ann Arbor, Boston, Charlotte, Chicago, Cincinnati, Columbus, Dallas, Denver, Detroit, Fairfax, Houston, Indianapolis, Lafayette, Milwaukee, Minneapolis, New York City, Northern California, Oxford (UK), Southern California, St. Louis, Toronto Global delivery centers in China and India >2,600 colleagues Dedicated solution practices ~90% repeat business rate Alliance partnerships with major technology vendors Multiple vendor/industry technology and growth awards PERFICIENT PROFILE
  • 4. 4 Business Process Management Customer Relationship Management Enterprise Performance Management Enterprise Information Solutions Enterprise Resource Planning Experience Design Portal / Collaboration Content Management Information Management Mobile BUSINESSSOLUTIONS 50+PARTNERS Safety / PV Clinical Data Management Electronic Data Capture Medical Coding Clinical Data Warehousing Clinical Data Analytics Clinical Trial Management Healthcare Data Warehousing Healthcare Analytics CLINICAL/HEALTHCAREIT Consulting Implementation Integration Migration Upgrade Managed Services Private Cloud Hosting Validation Study Setup Project Management Application Development Software Licensing Application Support Staff Augmentation Training SERVICES OUR SOLUTIONS PORTFOLIO
  • 5. 5 WELCOME & INTRODUCTION Sally Miranker Senior Project Manager, Life Sciences, Perficient • Senior Project Manager and head of computer system validation (CSV) • Oversees CSV, system development life cycle (SDLC), and all project-related validation-related activities performed by Perficient’s life sciences practice • Ensures that internal and client systems are implemented effectively, in compliance with internal procedures and federal regulations, and following best industry practices • 20 years experience in life sciences; past eight years focused on implementing computer systems within regulated environments
  • 6. 6 AGENDA • Explain what the name “21 CFR Part 11” means • Define key concepts and terms • Review the regulations, section by section • Highlight common points of confusion and provide clarification • Discuss examples and case studies • Answer your questions
  • 7. 7 DECODING “21 CFR PART 11” • CFR = “Code of Federal Regulations” • 21 = “Title 21” • Part 11 = Scope is specific to electronic records & electronic signatures, including electronic submissions to the FDA Details missing from the common title: • Chapter I = Part 11 falls under “Chapter I” of the CFR • Subchapter A = Part 11 falls under “Subchapter A – General” of Chapter I of the CFR
  • 8. 8 21 CFR PART 11 CONTENT
  • 10. 10 SUBPART A, SECTION 11.1 – SCOPE
  • 11. 11 SUBPART A, SECTION 11.1 – SCOPE (a) The regulations in this part set forth the criteria under which the agency considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and generally equivalent to paper records and handwritten signatures executed on paper. Part 11 regs establish the agency’s conditions for treating electronic records the same as paper records, and ink signatures the same as electronic signatures.
  • 12. 12 (b) This part applies to records in electronic form that are created, modified, maintained, archived, retrieved, or transmitted, under any records requirements set forth in agency regulations. This part also applies to electronic records submitted to the agency under requirements of the Federal Food, Drug, and Cosmetic Act and the Public Health Service Act, even if such records are not specifically identified in agency regulations. However, this part does not apply to paper records that are, or have been, transmitted by electronic means. Part 11 applies to electronic records that are used for federally regulated purposes. One clarification is made – a paper record that is transmitted electronically (e.g., as an email attachment) is not subject to Part 11. SUBPART A, SECTION 11.1 – SCOPE
  • 13. 13 (c) Where electronic signatures and their associated electronic records meet the requirements of this part, the agency will consider the electronic signatures to be equivalent to full handwritten signatures, initials, and other general signings as required by agency regulations, unless specifically excepted by regulation(s) effective on or after August 20, 1997. If an organization can prove that its electronic signatures and associated electronic records comply with Part 11, the FDA will accept electronic instead of ink. However, an exception is noted - if another regulation specifically requires ink signatures, that regulation supersedes Part 11. SUBPART A, SECTION 11.1 – SCOPE
  • 14. 14 (d) Electronic records that meet the requirements of this part may be used in lieu of paper records, in accordance with 11.2, unless paper records are specifically required. Same as (c) but specific to the use of electronic records vs. electronic signatures and their associated electronic records. An exception is noted - if some other regulation specifically requires paper records, that regulation supersedes Part 11. SUBPART A, SECTION 11.1 – SCOPE
  • 15. 15 (e) Computer systems (including hardware and software), controls, and attendant documentation maintained under this part shall be readily available for, and subject to, FDA inspection. Proof that a system complies with Part 11 must be maintained in such a way that the FDA can inspect it. SUBPART A, SECTION 11.1 – SCOPE
  • 16. 16 (f) This part does not apply to records required to be established or maintained by 1.326 through 1.368 of this chapter. Records that satisfy the requirements of part 1, subpart J of this chapter, but that also are required under other applicable statutory provisions or regulations, remain subject to this part. A few very specific types of records are excluded from Part 11, but the vast majority need to comply. SUBPART A, SECTION 11.1 – SCOPE
  • 17. 17 SUBPART A, SECTION 11.2 – IMPLEMENTATION
  • 18. 18 SUBPART A, SECTION 11.2 – IMPLEMENTATION (a) For records required to be maintained but not submitted to the agency, persons may use electronic records in lieu of paper records or electronic signatures in lieu of traditional signatures, in whole or in part, provided that the requirements of this part are met. For regulated records that are not submitted to the FDA, organizations may use electronic instead of paper as long as they can prove that their electronic records comply with Part 11.
  • 19. 19 SUBPART A, SECTION 11.2 – IMPLEMENTATION (b) For records submitted to the agency, persons may use electronic records in lieu of paper records or electronic signatures in lieu of traditional signatures, in whole or in part, provided that: (1) The requirements of this part are met; and For regulated records that are submitted to the FDA, organizations may use electronic instead of paper as long as two conditions are met: First, they can prove that their electronic records comply with Part 11.
  • 20. 20 SUBPART A, SECTION 11.2 – IMPLEMENTATION (b)(2) The document or parts of a document to be submitted have been identified in public docket No. 92S-0251 as being the type of submission the agency accepts in electronic form. This docket will identify specifically what types of documents or parts of documents are acceptable for submission in electronic form without paper records and the agency receiving unit(s) (e.g., specific center, office, division, branch) to which such submissions may be made. Second, the FDA is capable of accepting those types of records electronically. The types of e-records that the FDA accepts are listed in public docket No. 92S-0251.
  • 21. 21 SUBPART A, SECTION 11.2 – IMPLEMENTATION (b)(2) (cont.) Documents to agency receiving unit(s) not specified in the public docket will not be considered as official if they are submitted in electronic form; paper forms of such documents will be considered as official and must accompany any electronic records. Persons are expected to consult with the intended agency receiving unit for details on how (e.g., method of transmission, media, file formats, and technical protocols) and whether to proceed with the electronic submission. Electronic documents submitted to the FDA that are not called out in the public docket won’t be considered as official. In these cases, the paper documents are considered as official and must also be sent along.
  • 22. 22 SUBPART A, SECTION 11.3 – DEFINITIONS
  • 23. 23 SUBPART A, SECTION 11.3 – DEFINITIONS (a) The definitions and interpretations of terms contained in section 201 of the act apply to those terms when used in this part. Some terms that are defined in the Food, Drug, and Cosmetic Act also apply to Part 11.
  • 24. 24 SUBPART A, SECTION 11.3 – DEFINITIONS (b) The following definitions of terms also apply to this part: (1) Act means the Federal Food, Drug, and Cosmetic Act (secs. 201-903 (21 U.S.C. 321- 393)). (2) Agency means the Food and Drug Administration. Act: Short for Food, Drug, and Cosmetic Act Agency: Short for Food and Drug Administration (FDA)
  • 25. 25 SUBPART A, SECTION 11.3 – DEFINITIONS (3) Biometrics means a method of verifying an individual's identity based on measurement of the individual's physical feature(s) or repeatable action(s) where those features and/or actions are both unique to that individual and measurable. Biometrics: A way to verify someone’s identity through a unique physical trait (e.g., fingerprint).
  • 26. 26 SUBPART A, SECTION 11.3 – DEFINITIONS (4) Closed system means an environment in which system access is controlled by persons who are responsible for the content of electronic records that are on the system. Closed System: A computer system where access is controlled by the same people responsible for its content.
  • 27. 27 SUBPART A, SECTION 11.3 – DEFINITIONS (5) Digital signature means an electronic signature based upon cryptographic methods of originator authentication, computed by using a set of rules and a set of parameters such that the identity of the signer and the integrity of the data can be verified. Digital Signature: A type of electronic signature that includes a way of verifying the identity of the signer and the integrity of the record they signed.
  • 28. 28 SUBPART A, SECTION 11.3 – DEFINITIONS (6) Electronic record means any combination of text, graphics, data, audio, pictorial, or other information representation in digital form that is created, modified, maintained, archived, retrieved, or distributed by a computer system. Electronic Record: Information in digital form that is created or used in some way by a computer system.
  • 29. 29 SUBPART A, SECTION 11.3 – DEFINITIONS (7) Electronic signature means a computer data compilation of any symbol or series of symbols executed, adopted, or authorized by an individual to be the legally binding equivalent of the individual's handwritten signature. Electronic Signature: Compilation of electronic data that is as unique and legally binding as a handwritten signature, but is used to sign records in a computer system.
  • 30. 30 SUBPART A, SECTION 11.3 – DEFINITIONS (8) Handwritten signature means the scripted name or legal mark of an individual handwritten by that individual and executed or adopted with the present intention to authenticate a writing in a permanent form. The act of signing with a writing or marking instrument such as a pen or stylus is preserved. The scripted name or legal mark, while conventionally applied to paper, may also be applied to other devices that capture the name or mark. Handwritten Signature: A scripted name or legal mark created by an individual that is unique to that individual and is used to authenticate something in writing.
  • 31. 31 SUBPART A, SECTION 11.3 – DEFINITIONS (9) Open system means an environment in which system access is not controlled by persons who are responsible for the content of electronic records that are on the system. Open System: A computer system that’s access is not controlled by the same people responsible for its contents.
  • 33. 33 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS
  • 34. 34 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS Persons who use closed systems to create, modify, maintain, or transmit electronic records shall employ procedures and controls designed to ensure the authenticity, integrity, and, when appropriate, the confidentiality of electronic records, and to ensure that the signer cannot readily repudiate the signed record as not genuine. Such procedures and controls shall include the following: Organizations responsible for electronic records in a closed system must document the procedures they follow and the controls they have in place for ensuring that their electronic records have these qualities: • Authenticity • Integrity • Confidentiality (as needed) • Irrefutability
  • 35. 35 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS (a) Validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records. Organizations responsible for electronic records in a closed system must validate the system to prove that the records in the system can be trusted.
  • 36. 36 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS (b) The ability to generate accurate and complete copies of records in both human readable and electronic form suitable for inspection, review, and copying by the agency. Persons should contact the agency if there are any questions regarding the ability of the agency to perform such review and copying of the electronic records. Organizations must ensure that the electronic records generated from a closed system contain complete and accurate data, and must be in a language/format that humans can understand.
  • 37. 37 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS (c) Protection of records to enable their accurate and ready retrieval throughout the records retention period. Organizations must ensure electronic records (data and documents) in a closed system are protected and retrievable by establishing and maintaining processes for the storage, retrieval, and retention period.
  • 38. 38 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS (d) Limiting system access to authorized individuals. Organizations need to ensure that only authorized people have access to each computer system.
  • 39. 39 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS (e) Use of secure, computer-generated, time- stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records. Record changes shall not obscure previously recorded information. Such audit trail documentation shall be retained for a period at least as long as that required for the subject electronic records and shall be available for agency review and copying. A secure and complete history (audit trail) of an electronic record should be automatically generated by a computer system. A change to an electronic record should not alter the record’s history. Audit trail documentation should be: • Retained for the correct amount of time • Available for viewing
  • 40. 40 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS (f) Use of operational system checks to enforce permitted sequencing of steps and events, as appropriate. Organizations should ensure that electronic workflows in computer systems function correctly.
  • 41. 41 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS (g) Use of authority checks to ensure that only authorized individuals can use the system, electronically sign a record, access the operation or computer system input or output device, alter a record, or perform the operation at hand. Organizations should limit system access (at the system and record level) and verify that the users performing functions in the system are authorized to do so.
  • 42. 42 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS (h) Use of device (e.g., terminal) checks to determine, as appropriate, the validity of the source of data input or operational instruction. Organizations should ensure that devices used to enter data into a computer system operate correctly and that the entered data is valid.
  • 43. 43 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS (i) Determination that persons who develop, maintain, or use electronic record/electronic signature systems have the education, training, and experience to perform their assigned tasks. Organizations should ensure that people who perform functions on or within the system are appropriately qualified.
  • 44. 44 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS (j) The establishment of, and adherence to, written policies that hold individuals accountable and responsible for actions initiated under their electronic signatures, in order to deter record and signature falsification. Organizations should establish policies to hold individuals accountable for the integrity of their actions related to electronic records and electronic signatures.
  • 45. 45 SUBPART B, SECTION 11.10 – CONTROLS FOR CLOSED SYSTEMS (k) Use of appropriate controls over systems documentation including: (1) Adequate controls over the distribution of, access to, and use of documentation for system operation and maintenance. (2) Revision and change control procedures to maintain an audit trail that documents time- sequenced development and modification of systems documentation. Organizations should control documents related to system operation and maintenance and preserve the complete history of changes made to these documents.
  • 46. 46 SUBPART B, SECTION 11.30 – CONTROLS FOR OPEN SYSTEMS
  • 47. 47 SUBPART B, SECTION 11.30 – CONTROLS FOR OPEN SYSTEMS Persons who use open systems to create, modify, maintain, or transmit electronic records shall employ procedures and controls designed to ensure the authenticity, integrity, and, as appropriate, the confidentiality of electronic records from the point of their creation to the point of their receipt. Such procedures and controls shall include those identified in 11.10, as appropriate, and additional measures such as document encryption and use of appropriate digital signature standards to ensure, as necessary under the circumstances, record authenticity, integrity, and confidentiality. When organizations use open systems, all of the regulations for closed systems still apply but, additional steps need to be taken to ensure the record qualities of authenticity, integrity, confidentiality, and irrefutability described in section 11.10.
  • 48. 48 SUBPART B, SECTION 11.50 – SIGNATURE MANIFESTATIONS
  • 49. 49 SUBPART B, SECTION 11.50 – SIGNATURE MANIFESTATIONS (a) Signed electronic records shall contain information associated with the signing that clearly indicates all of the following: (1) The printed name of the signer; (2) The date and time when the signature was executed; and (3) The meaning (such as review, approval, responsibility, or authorship) associated with the signature. When an electronic record is signed, the record must contain information associated with its signing that indicates: • Printed name of signer • Date and time of signature • Meaning of signature
  • 50. 50 SUBPART B, SECTION 11.50 – SIGNATURE MANIFESTATIONS (b) The items identified in paragraphs (a)(1), (a)(2), and (a)(3) of this section shall be subject to the same controls as for electronic records and shall be included as part of any human readable form of the electronic record (such as electronic display or printout). When an electronic record is signed, the bulleted items in (a) are subject to the same controls for electronic records and must be in human-readable format.
  • 51. 51 SUBPART B, SECTION 11.70 – SIGNATURE/RECORD LINKING
  • 52. 52 SUBPART B, SECTION 11.70 – SIGNATURE/RECORD LINKING Electronic signatures and handwritten signatures executed to electronic records shall be linked to their respective electronic records to ensure that the signatures cannot be excised, copied, or otherwise transferred to falsify an electronic record by ordinary means. A signature (ink or electronic) executed on an electronic record has to be connected to that record forever. It cannot be removed, covered over, erased, transferred, etc.
  • 54. 54 SUBPART C, SECTION 11.100 – GENERAL REQUIREMENTS
  • 55. 55 SUBPART C, SECTION 11.100 – GENERAL REQUIREMENTS (a) Each electronic signature shall be unique to one individual and shall not be reused by, or reassigned to, anyone else. Organizations using electronic signatures should ensure that each signer has a unique electronic signature cannot be used by anyone else.
  • 56. 56 SUBPART C, SECTION 11.100 – GENERAL REQUIREMENTS (b) Before an organization establishes, assigns, certifies, or otherwise sanctions an individual's electronic signature, or any element of such electronic signature, the organization shall verify the identity of the individual. Before allowing an individual to execute their electronic signature, an organization needs to first verify the identity of that individual.
  • 57. 57 SUBPART C, SECTION 11.100 – GENERAL REQUIREMENTS (c) Persons using electronic signatures shall, prior to or at the time of such use, certify to the agency that the electronic signatures in their system, used on or after August 20, 1997, are intended to be the legally binding equivalent of traditional handwritten signatures. Before an organization implements the use of electronic signatures, it must notify the FDA of its intention and state that it will consider electronic signatures to be as legally binding as ink signatures.
  • 58. 58 SUBPART C, SECTION 11.100 – GENERAL REQUIREMENTS (c)(1) The certification shall be submitted in paper form and signed with a traditional handwritten signature, to the Office of Regional Operations (HFC-100), 5600 Fishers Lane, Rockville, MD 20857. (c)(2) Persons using electronic signatures shall, upon agency request, provide additional certification or testimony that a specific electronic signature is the legally binding equivalent of the signer's handwritten signature. The first step in the notification process is to write an Electronic Signature Certificate Statement that is signed with ink signatures and mail it to the FDA at the Office of Regional Operations (HFC-100), 5600 Fishers Lane, Rockville, MD 20857. If the FDA asks for additional proof that the organization will consider electronic signatures to be legally binding, the organization must provide it.
  • 59. 59 SUBPART C, SECTION 11.200 – ELECTRONIC SIGNATURE COMPONENTS AND CONTROLS
  • 60. 60 SUBPART C, SECTION 11.200 – ELECTRONIC SIGNATURE COMPONENTS AND CONTROLS (a) Electronic signatures that are not based upon biometrics shall: (1) Employ at least two distinct identification components such as an identification code and password. Electronic signatures that are not biometric (i.e., not based on a physical feature, like a fingerprint) should employ at least two distinct identification components (i.e., user ID and password).
  • 61. 61 SUBPART C, SECTION 11.200 – ELECTRONIC SIGNATURE COMPONENTS AND CONTROLS (a)(1)(i) When an individual executes a series of signings during a single, continuous period of controlled system access, the first signing shall be executed using all electronic signature components; subsequent signings shall be executed using at least one electronic signature component that is only executable by, and designed to be used only by, the individual. When using electronic signatures: • The first time after logging in, to execute their e-sig, a signer must enter all of their credentials (e.g., user ID and password) • For signings after that, but during that same login session, the signer has to only enter one credential (e.g., password)
  • 62. 62 SUBPART C, SECTION 11.200 – ELECTRONIC SIGNATURE COMPONENTS AND CONTROLS (a)(1)(ii) When an individual executes one or more signings not performed during a single, continuous period of controlled system access, each signing shall be executed using all of the electronic signature components. Each time a user logs out (or is timed out) and logs back into a system, the user executes their electronic signature, the clock restarts, and the user has to enter all of their signature components (i.e., user ID and password).
  • 63. 63 SUBPART C, SECTION 11.200 – ELECTRONIC SIGNATURE COMPONENTS AND CONTROLS (a)(2) Be used only by their genuine owners; and (a)(3) Be administered and executed to ensure that attempted use of an individual's electronic signature by anyone other than its genuine owner requires collaboration of two or more individuals. Electronic signatures may only be used by the individuals to which they are assigned. Electronic signatures should be set up so that it would take two or more people acting together to attempt to use someone else’s signature.
  • 64. 64 SUBPART C, SECTION 11.200 – ELECTRONIC SIGNATURE COMPONENTS AND CONTROLS (b) Electronic signatures based upon biometrics shall be designed to ensure that they cannot be used by anyone other than their genuine owners. Electronic signatures that are biometric (e.g., based on a retinal scan) can only be used by the individuals they are assigned to.
  • 65. 65 SUBPART C, SECTION 11.300 – CONTROLS FOR IDENTIFICATION CODES/PASSWORDS
  • 66. 66 SUBPART C, SECTION 11.300 – CONTROLS FOR IDENTIFICATION CODES/PASSWORDS Persons who use electronic signatures based upon use of identification codes in combination with passwords shall employ controls to ensure their security and integrity. Such controls shall include: Organizations using electronic signatures should employ controls over user identification codes.
  • 67. 67 SUBPART C, SECTION 11.300 – CONTROLS FOR IDENTIFICATION CODES/PASSWORDS (a) Maintaining the uniqueness of each combined identification code and password, such that no two individuals have the same combination of identification code and password. Controls should ensure that no two users can have the same combination of user ID and password; each combination must be unique.
  • 68. 68 SUBPART C, SECTION 11.300 – CONTROLS FOR IDENTIFICATION CODES/PASSWORDS (b) Ensuring that identification code and password issuances are periodically checked, recalled, or revised (e.g., to cover such events as password aging). Passwords must be changed periodically and should be set to expire after a set period of time. Organizations should establish and maintain policies and/or procedures to address password distribution and expiration.
  • 69. 69 SUBPART C, SECTION 11.300 – CONTROLS FOR IDENTIFICATION CODES/PASSWORDS (c) Following loss management procedures to electronically deauthorize lost, stolen, missing, or otherwise potentially compromised tokens, cards, and other devices that bear or generate identification code or password information, and to issue temporary or permanent replacements using suitable, rigorous controls. If a passcode token/device is lost or stolen, it must be de-authorized and a secure replacement must be issued.
  • 70. 70 SUBPART C, SECTION 11.300 – CONTROLS FOR IDENTIFICATION CODES/PASSWORDS (d) Use of transaction safeguards to prevent unauthorized use of passwords and/or identification codes, and to detect and report in an immediate and urgent manner any attempts at their unauthorized use to the system security unit, and, as appropriate, to organizational management. Unauthorized attempts to use a user ID or password/passcode must be detected and reported to the appropriate person/group in the organization for investigation.
  • 71. 71 SUBPART C, SECTION 11.300 – CONTROLS FOR IDENTIFICATION CODES/PASSWORDS (e) Initial and periodic testing of devices, such as tokens or cards, that bear or generate identification code or password information to ensure that they function properly and have not been altered in an unauthorized manner. Passcode tokens must be tested before they are issued for use and tested periodically while in use to make sure they are functioning correctly.
  • 72. 72 21 CFR PART 11: ONE FINAL LOOK
  • 73. 73 SUMMARY Subpart A – General Provisions  Part 11 applies to all electronic records that fall under FDA regulations.  If an organization can prove to an auditor that their electronic records/signatures are as trustworthy as paper records/ink signatures, the FDA will accept electronic instead of paper.  The FDA will accept electronic submission instead of paper IF those submissions 1) adhere to Part 11 requirements and 2) are included among the types of documents that the FDA accepts electronically.
  • 74. 74 SUMMARY (CONT.) Subpart B – Electronic Records  Organizations using electronic records must establish and document procedures and controls that ensure the authenticity, integrity, confidentiality, and irrefutability of their records.  The following topics must be addressed in documented procedures and controls: computer system validation (CSV), record rendering, document storage and record retention, system access, audit trails, workflows, authority checks, device checks, personnel qualifications, personnel accountability, and document control.  Systems that fall into the category of “Open” (as defined in Subpart A) require additional measures of control.  Electronic signatures must include information to indicate the printed name of the signer, the date and time of the signature, and the meaning of the signature.  Electronic signatures must be forever linked to their respective records.
  • 75. 75 SUMMARY (CONT.) Subpart C – Electronic Signatures  Organizations that wish to use electronic signatures must inform the FDA in writing prior to making the switch.  Each individual who will be using an electronic signature must 1) have their identity confirmed and 2) use a unique signature that has never been and will never be used by another individual.  There are specific design requirements for electronic signatures that are biometric (e.g., fingerprint scan) and those that are not (e.g., user ID and password).  For electronic signatures that make use of user IDs and passwords/passcodes, there are specific requirements for passwords and for passcode-generating devices.
  • 77. 77 www.facebook.com/perficientwww.twitter.com/perficient_LS For more information, please contact: Sally.Miranker@perficient.com LifeSciencesInfo@perficient.com (Sales) +1 877 654 0033 (U.S. Sales) +1 303 570 8464 (U.S. Sales) +44 (0) 1865 910200 (U.K. Sales) Submit a question directly to the FDA via email: Industry.Drugs@fda.gov (source www.fda.gov, Home>For Industry>FDA Basics for Industry>Submit Questions and Comments) THANK YOU linkedin.com/company/perficient