Scrutineer · By framework
21 CFR Part 11 compliance software for FDA electronic records and signatures
Part 11 decides whether the FDA will accept your electronic records instead of paper, and most of what it asks for is ordinary IT control evidence.
Scrutineer maps those controls once and keeps the proof dated, so a Part 11 question during an inspection has an answer already on file.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with 21 CFR part 11 compliance software
Most of Part 11 is access control, audit trails and training records
Read 11.10 closely and the majority of it is limiting system access to authorized individuals, authority checks, operational sequencing, training records and written accountability policies. Those are the same controls a SOC 2 or ISO 27001 program already evidences. Scrutineer maps your existing control set to the Part 11 clauses so the work counts twice rather than being rebuilt in a separate quality silo.
Evidence dated across the period, because an investigator asks how long it has been true
A screenshot proves a setting today. An FDA investigator asks who had access last quarter, when the audit trail was last reviewed, and whether the leaver was removed. Scrutineer pulls that proof from your identity, cloud and ticketing systems on a schedule and timestamps it, so the record shows operation over time.
Honest about the line between controls and validation
Part 11 compliance is not one purchase. The access, audit trail, training and policy side is controls work, and that is our half. Installation and operational qualification of a specific application, and the cryptographic binding of a signature to a record, belong to your validation programme and your eQMS or signature platform. We say which is which rather than implying one tool closes all of it.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps your control set to the 11.10 controls for closed systems, clause by clause
- Evidences limiting system access to authorized individuals under 11.10(d), with the leaver record behind it
- Runs and documents the periodic access review that shows authority checks under 11.10(g) still hold
- Tracks that audit trail settings are enabled and reviewed, and flags a system where they are not
- Holds the training records 11.10(i) requires for everyone who touches an electronic record
- Keeps the written policies 11.10(j) asks for, versioned, with who approved them and when
- Maintains the inventory of systems holding Part 11 records, which is the question that stalls most inspections
- Runs the same evidence base against ISO 13485, SOC 2 and ISO 27001 so a life sciences team files once
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Requirement reference
Every 21 CFR Part 11 requirement, whether the FDA is currently enforcing it, and which are controls work
Almost every published Part 11 checklist lists the requirements as though they carry equal enforcement weight. They do not. The FDA narrowed enforcement on exactly four of them in its August 2003 scope and application guidance, and that guidance is still the agency position. The third column marks those four. The last column says which requirements a controls platform genuinely covers and which belong to your validation programme or e-signature layer, including the rows where the answer is not us.
| Part 11 requirement | Clause | Under the 2003 enforcement discretion? | What covers it in practice |
|---|---|---|---|
| Validation of systems to ensure accuracy, reliability and consistent intended performance | 11.10(a) | Yes, for the Part 11 clause only. The predicate rule validation duty, notably 21 CFR 820.70(i), is untouched. | Your validation programme, run risk-based under the FDA Computer Software Assurance guidance. Not a controls platform. |
| Ability to generate accurate and complete copies for agency review | 11.10(b) | Yes. | The record system itself must be able to export. A controls platform evidences that the capability was tested, not the export. |
| Protection of records to enable accurate and ready retrieval throughout the retention period | 11.10(c) | Yes, on the retention element. | Backup, retention and integrity controls. Squarely controls work, and our row. |
| Limiting system access to authorized individuals | 11.10(d) | No. Enforced as written. | Identity and access management, joiner and leaver process, periodic access review. Our row, and the one investigators open with. |
| Secure, computer-generated, time-stamped audit trails | 11.10(e) | Yes, for the Part 11 clause. Predicate rule data integrity expectations still apply. | The application supplies the audit trail. A controls platform evidences that it is switched on, protected and reviewed. |
| Operational system checks to enforce permitted sequencing of steps and events | 11.10(f) | No. Enforced as written. | Application configuration, evidenced through change control. Shared between the system owner and controls. |
| Authority checks that only authorized individuals may use the system and sign records | 11.10(g) | No. Enforced as written. | Role design and access review evidence. Our row. |
| Device checks to determine validity of the source of data input or operational instruction | 11.10(h) | No. Enforced as written. | Application and instrument configuration. Not a controls platform. |
| Documented training: education, training and experience for everyone who works with the system | 11.10(i) | No. Enforced as written. | Training records, completion tracking and role mapping. Our row, and a frequent finding. |
| Written policies holding individuals accountable for actions taken under their electronic signature | 11.10(j) | No. Enforced as written. | Policy management, versioning and attestation. Our row. |
| Control over systems documentation, including change control on documentation | 11.10(k) | No. Enforced as written. | Document control and change management evidence. Shared with your eQMS. |
| Signature manifestations: printed name, date and time, and meaning of the signature | 11.50 | No. Enforced as written. | The e-signature platform or eQMS renders this. Not a controls platform. |
| Signature to record linking, so signatures cannot be excised, copied or transferred | 11.70 | No. Enforced as written. | Cryptographic binding in the signature platform. Not a controls platform. |
| Electronic signature components, controls and identification code and password controls | 11.100 to 11.300 | No. Enforced as written. | Identity proofing, unique credentials, MFA and password controls. Shared between IAM and the signature platform. |
Clause references are to 21 CFR Part 11 and the enforcement column reflects the FDA guidance "Part 11, Electronic Records; Electronic Signatures, Scope and Application", issued August 2003 and announced in the Federal Register on September 5, 2003, which remains the agency position as at August 2026. Enforcement discretion is a statement of current FDA intent, not a repeal, and it never displaces a predicate rule obligation. Scope depends on which of your records a predicate rule requires, so confirm your own scope with your regulatory affairs function. Scrutineer prepares and maintains control evidence and does not validate systems, issue certifications or make determinations on your behalf.
Good questions
Questions about 21 CFR part 11 compliance software
Keep reading
Guides that go deeper on FDA and life sciences controls
Computer software assurance explained
What the FDA CSA guidance changed against traditional CSV, and how to decide the assurance effort a system actually needs.
Read the guideHow to run a user access review
The six-step process behind 11.10(d) and 11.10(g), and the five exceptions auditors write up most often.
Read the guideIT general controls explained
Access, change management, program development and operations, and the evidence sampled in each.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification