{ "id": "21 CFR Part 11", "name": "21 CFR Part 11", "logo": { "light": "", "dark": "" }, "controls": [ { "id": "11.10(a)", "name": "System Validation", "description": "Validate electronic record systems to ensure accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records." }, { "id": "11.10(b)", "name": "Record Copies", "description": "Generate accurate and complete copies of electronic records in both human-readable and electronic form suitable for FDA inspection, review, and copying." }, { "id": "11.10(c)", "name": "Record Protection and Retention", "description": "Protect electronic records to ensure accurate and ready retrieval throughout the required retention period." }, { "id": "11.10(d)", "name": "Access Control", "description": "Limit system access to authorized individuals." }, { "id": "11.10(e)", "name": "Audit Trails", "description": "Use secure, computer-generated, time-stamped audit trails to record creation, modification, or deletion of electronic records; ensure prior information is not obscured and audit trails are retained with the records." }, { "id": "11.10(f)", "name": "Operational Controls", "description": "Implement system checks to enforce permitted sequencing of steps and events." }, { "id": "11.10(g)", "name": "Authority Controls", "description": "Ensure only authorized individuals can use the system, sign records, access devices, or alter records." }, { "id": "11.10(h)", "name": "Device Controls", "description": "Verify the validity of data input sources and operational instructions where applicable." }, { "id": "11.10(i)", "name": "Personnel Competency", "description": "Ensure individuals who develop, maintain, or use electronic record or signature systems are trained, qualified, and competent." }, { "id": "11.10(j)", "name": "Accountability Policies", "description": "Establish and enforce written policies holding individuals accountable for actions taken under electronic signatures." }, { "id": "11.10(k)(1)", "name": "Documentation Access Controls", "description": "Control the distribution, access, and use of system documentation." }, { "id": "11.10(k)(2)", "name": "Documentation Change Control", "description": "Maintain an audit trail of time-sequenced development and changes to system documentation." }, { "id": "11.30", "name": "Open System Protections", "description": "Apply additional safeguards (e.g., encryption, digital signatures) to protect the authenticity, integrity, and confidentiality of records in open systems." }, { "id": "11.50(a)", "name": "Signature Manifestation", "description": "Ensure signed electronic records display the signer's name, date/time of signing, and meaning of the signature." }, { "id": "11.50(b)", "name": "Signature Record Integrity", "description": "Subject signature information to the same controls as electronic records and include it in human-readable outputs." }, { "id": "11.70", "name": "Signature-to-Record Linking", "description": "Securely link electronic signatures to their respective records to prevent excision, copying, or transfer." }, { "id": "11.100(a)", "name": "Signature Uniqueness", "description": "Ensure each electronic signature is unique to one individual and is not reused or reassigned." }, { "id": "11.100(b)", "name": "Identity Verification", "description": "Verify an individual's identity before assigning or authorizing an electronic signature." }, { "id": "11.100(c)", "name": "Signature Legal Certification", "description": "Certify to the FDA that electronic signatures are intended to be legally binding equivalents of handwritten signatures." }, { "id": "11.200(a)(1)", "name": "Multi-Factor Signature Components", "description": "Require at least two distinct identification components (e.g., ID and password) for non-biometric electronic signatures." }, { "id": "11.200(a)(2)", "name": "Signature Ownership Control", "description": "Ensure electronic signatures are used only by their genuine owners." }, { "id": "11.200(a)(3)", "name": "Signature Misuse Prevention", "description": "Implement controls requiring collaboration of two or more individuals for unauthorized signature use." }, { "id": "11.200(b)", "name": "Biometric Signature Protection", "description": "Ensure biometric electronic signatures cannot be used by anyone other than their genuine owners." }, { "id": "11.300(a)", "name": "Credential Uniqueness", "description": "Maintain the uniqueness of identification code and password combinations." }, { "id": "11.300(b)", "name": "Credential Lifecycle Management", "description": "Periodically check, recall, or revise identification codes and passwords." }, { "id": "11.300(c)", "name": "Credential Loss Management", "description": "Deauthorize lost, stolen, or compromised authentication devices and issue replacements securely." }, { "id": "11.300(d)", "name": "Unauthorized Access Detection", "description": "Implement safeguards to detect and immediately report unauthorized use of credentials." }, { "id": "11.300(e)", "name": "Authentication Device Integrity Testing", "description": "Perform initial and periodic testing of authentication devices to detect unauthorized alteration." } ] }