Scrutineer.ai

Scrutineer · By framework

21 CFR Part 11 compliance software for FDA electronic records and signatures

Part 11 decides whether the FDA will accept your electronic records instead of paper, and most of what it asks for is ordinary IT control evidence.

Scrutineer maps those controls once and keeps the proof dated, so a Part 11 question during an inspection has an answer already on file.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with 21 CFR part 11 compliance software

Most of Part 11 is access control, audit trails and training records

Read 11.10 closely and the majority of it is limiting system access to authorized individuals, authority checks, operational sequencing, training records and written accountability policies. Those are the same controls a SOC 2 or ISO 27001 program already evidences. Scrutineer maps your existing control set to the Part 11 clauses so the work counts twice rather than being rebuilt in a separate quality silo.

Evidence dated across the period, because an investigator asks how long it has been true

A screenshot proves a setting today. An FDA investigator asks who had access last quarter, when the audit trail was last reviewed, and whether the leaver was removed. Scrutineer pulls that proof from your identity, cloud and ticketing systems on a schedule and timestamps it, so the record shows operation over time.

Honest about the line between controls and validation

Part 11 compliance is not one purchase. The access, audit trail, training and policy side is controls work, and that is our half. Installation and operational qualification of a specific application, and the cryptographic binding of a signature to a record, belong to your validation programme and your eQMS or signature platform. We say which is which rather than implying one tool closes all of it.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps your control set to the 11.10 controls for closed systems, clause by clause
  • Evidences limiting system access to authorized individuals under 11.10(d), with the leaver record behind it
  • Runs and documents the periodic access review that shows authority checks under 11.10(g) still hold
  • Tracks that audit trail settings are enabled and reviewed, and flags a system where they are not
  • Holds the training records 11.10(i) requires for everyone who touches an electronic record
  • Keeps the written policies 11.10(j) asks for, versioned, with who approved them and when
  • Maintains the inventory of systems holding Part 11 records, which is the question that stalls most inspections
  • Runs the same evidence base against ISO 13485, SOC 2 and ISO 27001 so a life sciences team files once
21 CFR PART 11 COMPLIANCE SOFTWARE readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Requirement reference

Every 21 CFR Part 11 requirement, whether the FDA is currently enforcing it, and which are controls work

Almost every published Part 11 checklist lists the requirements as though they carry equal enforcement weight. They do not. The FDA narrowed enforcement on exactly four of them in its August 2003 scope and application guidance, and that guidance is still the agency position. The third column marks those four. The last column says which requirements a controls platform genuinely covers and which belong to your validation programme or e-signature layer, including the rows where the answer is not us.

Part 11 requirement Clause Under the 2003 enforcement discretion? What covers it in practice
Validation of systems to ensure accuracy, reliability and consistent intended performance 11.10(a) Yes, for the Part 11 clause only. The predicate rule validation duty, notably 21 CFR 820.70(i), is untouched. Your validation programme, run risk-based under the FDA Computer Software Assurance guidance. Not a controls platform.
Ability to generate accurate and complete copies for agency review 11.10(b) Yes. The record system itself must be able to export. A controls platform evidences that the capability was tested, not the export.
Protection of records to enable accurate and ready retrieval throughout the retention period 11.10(c) Yes, on the retention element. Backup, retention and integrity controls. Squarely controls work, and our row.
Limiting system access to authorized individuals 11.10(d) No. Enforced as written. Identity and access management, joiner and leaver process, periodic access review. Our row, and the one investigators open with.
Secure, computer-generated, time-stamped audit trails 11.10(e) Yes, for the Part 11 clause. Predicate rule data integrity expectations still apply. The application supplies the audit trail. A controls platform evidences that it is switched on, protected and reviewed.
Operational system checks to enforce permitted sequencing of steps and events 11.10(f) No. Enforced as written. Application configuration, evidenced through change control. Shared between the system owner and controls.
Authority checks that only authorized individuals may use the system and sign records 11.10(g) No. Enforced as written. Role design and access review evidence. Our row.
Device checks to determine validity of the source of data input or operational instruction 11.10(h) No. Enforced as written. Application and instrument configuration. Not a controls platform.
Documented training: education, training and experience for everyone who works with the system 11.10(i) No. Enforced as written. Training records, completion tracking and role mapping. Our row, and a frequent finding.
Written policies holding individuals accountable for actions taken under their electronic signature 11.10(j) No. Enforced as written. Policy management, versioning and attestation. Our row.
Control over systems documentation, including change control on documentation 11.10(k) No. Enforced as written. Document control and change management evidence. Shared with your eQMS.
Signature manifestations: printed name, date and time, and meaning of the signature 11.50 No. Enforced as written. The e-signature platform or eQMS renders this. Not a controls platform.
Signature to record linking, so signatures cannot be excised, copied or transferred 11.70 No. Enforced as written. Cryptographic binding in the signature platform. Not a controls platform.
Electronic signature components, controls and identification code and password controls 11.100 to 11.300 No. Enforced as written. Identity proofing, unique credentials, MFA and password controls. Shared between IAM and the signature platform.

Clause references are to 21 CFR Part 11 and the enforcement column reflects the FDA guidance "Part 11, Electronic Records; Electronic Signatures, Scope and Application", issued August 2003 and announced in the Federal Register on September 5, 2003, which remains the agency position as at August 2026. Enforcement discretion is a statement of current FDA intent, not a repeal, and it never displaces a predicate rule obligation. Scope depends on which of your records a predicate rule requires, so confirm your own scope with your regulatory affairs function. Scrutineer prepares and maintains control evidence and does not validate systems, issue certifications or make determinations on your behalf.

Good questions

Questions about 21 CFR part 11 compliance software

21 CFR Part 11 is the FDA regulation that sets the conditions under which the agency will accept electronic records and electronic signatures as equivalent to paper records and handwritten signatures. It applies to records that an FDA predicate rule already requires you to keep. It does not create the recordkeeping obligation itself, it governs the form that record may take.
It applies to any organization that keeps records the FDA requires in electronic form: pharmaceutical and biotech manufacturers, medical device companies, contract research organizations, clinical sites, blood establishments and food safety operations under FSMA. The trigger is not your industry label. It is whether a predicate rule such as 21 CFR 211, 820 or 312 requires the record you are storing electronically.
Yes, but not uniformly, and this is the single most misunderstood point in the category. In its August 2003 guidance "Part 11, Electronic Records; Electronic Signatures, Scope and Application", the FDA said it intends to exercise enforcement discretion over four specific areas: validation, audit trails, record retention and record copying. Every other Part 11 requirement, including access controls, authority checks and the electronic signature provisions, remains enforced as written. That guidance is still the agency position.
For closed systems, 11.10 requires validation, the ability to generate accurate copies, record protection and retention, limiting access to authorized individuals, secure computer-generated time-stamped audit trails, operational and authority checks, device checks, documented training, written accountability policies, and control over systems documentation. Subpart C then adds requirements for signature manifestations, signature to record linking, and electronic signature components and controls.
No. The FDA does not certify, accredit or approve any software as Part 11 compliant, and no third party can issue a certificate that carries regulatory weight. Compliance is a property of how a system is configured, validated and operated in your environment, not a badge a vendor earns once. A vendor can honestly say its product supports Part 11 controls. It cannot make you compliant on its own.
Section 11.10(e) requires secure, computer-generated, time-stamped audit trails that independently record the operator entries and actions which create, modify or delete electronic records. Record changes must not obscure previously recorded information, and the audit trail must be retained at least as long as the record itself and be available for agency review and copying. Audit trails are one of the four areas under 2003 enforcement discretion, but predicate rule data integrity expectations still apply.
Computer system validation is the older, documentation-heavy approach that tends to test every function to the same depth regardless of risk. Computer software assurance is the FDA-endorsed risk-based successor for production and quality system software: it concentrates testing effort where a software failure could affect product quality or patient safety, and accepts lighter, less scripted evidence elsewhere. CSA is a change of emphasis rather than a change of law.
No, and this is where the discretion is most often misread. The 2003 guidance relaxes enforcement of the Part 11 validation clause specifically. It does not touch the separate validation requirement that sits in the predicate rules, notably 21 CFR 820.70(i) for software used as part of production or the quality management system. The FDA restated that point directly in its Computer Software Assurance guidance. The obligation survives even where the Part 11 clause is not being enforced.
DocuSign sells a Part 11 module, as do several e-signature vendors, and it supplies the signature manifestation, linking and authentication features the rule expects. That gets you the Subpart C half. It does not by itself satisfy your obligations for access management, training records, written accountability policies or the audit trail on the underlying record system. The honest answer is that it is a component, not compliance.
If a spreadsheet holds a record a predicate rule requires and you are relying on it instead of paper, then yes, and it is a common inspection finding. Ordinary spreadsheets struggle with the audit trail, access control and record protection requirements because entries can be overwritten without trace. Most teams either move the record into a controlled system or keep a validated, locked-down configuration with the controls evidenced.
A predicate rule is the underlying FDA regulation that requires you to keep the record in the first place, such as 21 CFR Part 211 for drug GMP, Part 820 for devices, or Part 312 for clinical investigations. Part 11 is parasitic on those rules: if no predicate rule requires the record, Part 11 does not reach it. Working out which of your records are predicate rule records is the first scoping step and it decides everything downstream.
The Quality Management System Regulation took effect on February 2, 2026, amending 21 CFR Part 820 to incorporate ISO 13485:2016 by reference. Device manufacturers now work to a quality system framework aligned with the international standard rather than the older QSR text. The FDA also updated its device manufacturer inspection programme at the same time. Part 11 itself was not amended, but the predicate rule underneath it was restructured.
Start from records, not systems. List the records your predicate rules require, mark which are kept electronically and which carry electronic signatures, and only then list the systems holding them. Most teams find the real scope is far smaller than their application inventory, because a large share of business systems never touch a predicate rule record. Scoping outward from systems is what turns a six-week project into an eighteen-month one.
No. Scrutineer maps controls to the Part 11 clauses and maintains the evidence behind them, so you can see where you stand and answer an investigator quickly. Qualification and validation of a specific application is performed by your validation team or a specialist provider, and the FDA makes its own determination during an inspection. We are explicit about that line because the accountability sits with you.

Keep reading

Guides that go deeper on FDA and life sciences controls

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification