The Complete 21 CFR Part 11 Compliance Checklist for 2026

Spreadsheets, lab data, paper records, and AI: what the regulation requires, where organizations fail, and how to fix it.

WHY THIS MATTERS NOW
FY2024 saw the highest FDA warning letter volume in five years, with data integrity as the leading citation category. Three forces are compounding the challenge: stricter FDA enforcement, digital transformation creating new compliance surfaces, and AI adoption creating obligations that most Part 11 programs were never designed for.

What Is 21 CFR Part 11?

Enacted in 1997, 21 CFR Part 11 is the FDA regulation that governs electronic records and electronic signatures in regulated industries, including pharmaceutical, biotech, medical device, and clinical research. Its core standard: electronic records must be at least as trustworthy, reliable, and complete as paper records.

Part 11 does not stand alone. It applies on top of predicate rules, 21 CFR Part 211 (cGMP), Part 58 (GLP), Part 50 (GCP), that require the underlying record in the first place. If your predicate rule requires a batch record, Part 11 governs how that batch record is created, stored, signed, and audited if it exists in electronic form.

Two important updates since 1997 that every compliance team needs to know:

  • FDA 2018 Data Integrity and cGMP Guidance introduced ALCOA+ as the explicit standard for record quality under Part 11. Meeting ALCOA+ is now the practical test for Part 11 compliance.
  • FDA 2026 Computer Software Assurance (CSA) Guidance changes how validation works under Part 11: from documentation-heavy to risk-proportionate, calibrated to the system's GxP impact.

The CFR Part 11 Compliance Checklist

Use this checklist to assess your current compliance posture. Each item maps to a specific Part 11 requirement. All five sections must be addressed, deficiencies in any one are findings.

What Is 21 CFR Part 11?

Enacted in 1997, 21 CFR Part 11 is the FDA regulation that governs electronic records and electronic signatures in regulated industries, including pharmaceutical, biotech, medical device, and clinical research. Its core standard: electronic records must be at least as trustworthy, reliable, and complete as paper records.

Part 11 does not stand alone. It applies on top of predicate rules, 21 CFR Part 211 (cGMP), Part 58 (GLP), Part 50 (GCP), that require the underlying record in the first place. If your predicate rule requires a batch record, Part 11 governs how that batch record is created, stored, signed, and audited if it exists in electronic form.

Two important updates since 1997 that every compliance team needs to know:

  • FDA 2018 Data Integrity and cGMP Guidance introduced ALCOA+ as the explicit standard for record quality under Part 11. Meeting ALCOA+ is now the practical test for Part 11 compliance.
  • FDA 2026 Computer Software Assurance (CSA) Guidance changes how validation works under Part 11: from documentation-heavy to risk-proportionate, calibrated to the system's GxP impact.

The CFR Part 11 Compliance Checklist

A. System Validation
Risk-based approach Validation effort proportional to GxP impact under CSA 2026. Low-risk systems need less evidence.
Validation master plan Single VMP covering all computerized systems with scope, risk tiering, and review schedule.
System is validated IQ/OQ/PQ or equivalent evidence that the system functions as intended and data is accurate.
Change control Software changes impact-assessed, re-validated when material. Changes documented before deployment.
Supplier qualification Vendor quality system assessed. Supplier documentation leveraged to reduce internal testing burden.
B. Audit Trails
Auto-generated Audit trail created by the system automatically, never manual. Cannot be disabled by users.
Full capture Records: old value, new value, user ID, full name, timestamp, reason for change.
Stored separately Audit data stored apart from the record it references. Cannot be altered or deleted by users.
Retained Audit trails retained for the full record retention period and retrievable throughout.
Regularly reviewed Audit trails are reviewed, not just generated. Review frequency documented in SOP.
Available for FDA System can export or copy audit trails on demand for FDA inspectors.
C. Electronic Signatures
Unique per individual Each signature linked to one person only. No shared or reassigned signatures.
Dual factor Minimum two identification components (e.g. password + ID code) to execute a signature.
Signature meaning System captures what the signature means: approved, reviewed, rejected.
Non-repudiable Signature linked to the record and cannot be transferred, copied, or falsely attributed.
Retention Signature records retained for same period as associated data.
D. Access Controls
Unique user IDs No shared logins. Every action attributable to a specific individual.
Authorized access only Access limited by role. Users can only access what their role requires.
Password governance Minimum length, complexity, aging, and account lockout after failed attempts.
Access review Periodic review of user access. Prompt de-provisioning when roles change or employees leave.
Unauthorized access log Failed login attempts logged with user, timestamp, and system.
E. Record Integrity and Retention
Protected from alteration Records cannot be overwritten without a controlled, recorded action.
Original raw data retained Raw data files retained in original form, not just summary reports.
Accurate copies on demand System produces complete, accurate copies of records as required by FDA.
Retention schedule Documented retention schedule aligned to predicate rule requirements.
Hybrid systems Paper and electronic controls equivalent where both are used.

Related Regulations You Must Know

ALCOA+ (FDA 2018 Data Integrity Guidance)
ALCOA+ is the practical quality standard for every record governed by Part 11. Part 11 tells you what controls to implement; ALCOA+ tells you what quality the records themselves must have.

  • Attributable, every entry traceable to the person who made it
  • Legible, readable throughout its retention period
  • Contemporaneous, recorded at the time of the activity, not reconstructed later
  • Original, first-capture record retained, not just a summary or transcription
  • Accurate, reflects what actually occurred, no unauthorized alterations
  • Plus: Complete, Consistent, Enduring, Available

Where organizations most commonly fail: Contemporaneous (backdating), Original (summaries replacing raw data), Attributable (shared logins masking who did what).

EU GMP Annex 11
The European equivalent of Part 11 for organizations selling into EU markets. Key differences: more explicit requirements on supplier audit, data migration validation, and business continuity planning. ALCOA+ applies under Annex 11 as well. Organizations operating in both markets must satisfy both.

FDA CSA Guidance (2026)
The 2026 CSA Guidance replaces the documentation-heavy validation paradigm with a risk-based, evidence-based approach. The practical impact on your Part 11 program: lower-risk systems require less validation documentation, supplier-provided validation packages can substitute for internal testing, and critical thinking replaces box-checking. The validation effort is now explicitly proportionate to the system's risk to product quality and data integrity.

Part 11 Compliance by System Type: Where the Real Risk Lives

Spreadsheets and End-User Computing (EUC)
Spreadsheets are the most common source of Part 11 deficiencies. They have no native audit trail, formulas can be modified without detection, and access is typically unrestricted. FDA inspectors routinely examine spreadsheets used in batch release, QC, and stability calculations, and find missing controls.

Three specific failure modes: values overwritten with no record of the change, formula modifications that shift results without documentation, and shared network access that makes attribution impossible.

CIMCON: eInfotree Excel Desktop
Part 11 controls overlaid on existing Excel spreadsheets, no migration required. Field-level audit trail stored in a secure SQL database, electronic signatures, user access controls, and password governance. No change to user experience. Pre-built IQ/OQ/PQ validation package available under CSA. Deployed at 17 sites at Charles River Laboratories with an estimated 20% reduction in compliance-related costs.

Lab Instrument Data

Lab instruments generate raw data files automatically and save them to network folders. In most facilities, these folders have no access controls, no version management, and no audit trail. FDA's 2018 guidance requires original raw data to be retained in a demonstrably unaltered form. Most organizations cannot meet this requirement for instrument output files.

FDA 483 observations regularly cite: 'laboratory data was not adequately controlled to prevent unauthorized access or alteration' and 'the firm could not demonstrate raw data files were retained in their original form.

CIMCON: LabMonitor
Continuous automatic monitoring of lab instrument folders. Every file creation, modification, or deletion captured with user identity and timestamp, no analyst action required. Secure repository prevents overwriting. Version control retains every file version. Per-instrument access controls with unauthorized access logging. Full audit trail with electronic signature support.

Paper Records and Forms

Paper records fail ALCOA+ on multiple dimensions: handwriting legibility varies, backdating is difficult to detect, there is no automatic audit trail, and paper cannot be searched or analyzed. Under FDA's 2026 CSA Guidance, digitizing paper forms now requires less validation effort than before, making this the right time to act.

CIMCON: CIMCON TransForm
Import existing paper, PDF, or Word forms without redesign. Data validation at entry enforces ALCOA+ quality at the point of capture. Automated workflow routing replaces physical document routing. Electronic signatures fully Part 11 compliant. All form data stored in a structured SQL database, immediately available for reporting, trending, and AI analysis. Pre-built CSA-aligned validation package available.

How to Augment Your Part 11 Program with AI

AI does not replace the controls Part 11 requires. It makes those controls more effective, more scalable, and more valuable as your data environment grows.

AI-Enabled Audit Trail Review
Audit trails are generated but rarely reviewed effectively, the volume is too large for meaningful manual analysis. AI changes this by classifying every change by risk category: formula modifications, scope reductions, external dependency shifts, permission changes, structural modifications. It detects patterns across thousands of changes that no individual reviewer would catch. For example, the same analyst changing the same formula type across 40 spreadsheets over six months.

AI Risk Assessment for Electronic Systems
Most organizations have dozens of systems. Prioritizing which ones need attention is manual, inconsistent, and often political. AI scans your electronic system inventory to identify AI/ML components, third-party risks, PII vulnerabilities, and anomalous data patterns automatically, giving compliance teams an objective, risk-ranked view of where to focus.

AI-Generated Validation Documentation
Generating and maintaining IQ/OQ/PQ documentation is one of the largest time costs in any quality department. AI agents extract requirements from system documentation automatically, generate test protocols, and produce the evidence package needed under CSA, with a human-in-the-loop built in at every step. Every AI output traces back to a specific source document. Every AI decision is recorded. Confidence scores flag what needs closer human review.

CIMCON: AIValidator AI Agents
CIMCON’s AI Agents can help automate the laborious elements of Part 11 Compliance through its use of AI Agents that do all of the above and more!

New in 2025-2026: AI Governance as a Part 11 Obligation
FDA's 2025 AI Draft Guidance creates a new obligation: if you use AI in GxP processes, that AI system must itself be governed as a computerized system under Part 11 and GAMP 5. It needs its own inventory entry, risk assessment, credibility assessment plan, performance monitoring, and change control process. Organizations deploying AI tools without this governance are creating a new category of Part 11 exposure.

About CIMCON Software

CIMCON has been helping pharmaceutical, biotech, and life sciences organizations achieve and maintain 21 CFR Part 11 compliance for over 30 years. Our customers include 8 of the top 10 life science companies globally, with 1,000+ deployments across 30 countries. We are ranked #1 by Gartner, Bloor, and our customers.

Our product portfolio covers every Part 11 compliance need across spreadsheets, lab instruments, paper records, AI/ML governance, and validation documentation, and our Validation as a Service model means you can start with a defined project and see results before any software commitment.

  • eInfotree Excel Desktop, spreadsheet Part 11 compliance
  • XLValidator, AI-enabled audit trail review and anomaly detection
  • LabMonitor, lab instrument data integrity and version control
  • CIMCON TransForm, paper to electronic, Part 11-compliant forms
  • AIValidator AI Agents, AI-generated validation documentation with HITL
  • AIValidator Risk Platform, AI/ML governance and risk management
TALK TO A PART 11 COMPLIANCE EXPERT
CIMCON offers a free Part 11 gap assessment for qualified organizations. We will review your current electronic record environment and identify the highest-risk gaps, no commitment required. Contact us at part11solutions.com or call our 24/7 support line.