Demo environment — fictional staff and data. Do not enter PHI.

Evelyn Marchetti-Sung

Quality Assurance Director · QCR-0057

Back to library
DAT-002Electronic Records & Electronic Signatures (21 CFR Part 11)v3.0EffectiveEffective Feb 16, 2026Data Integrity
0% read

Scroll to the end of the document to enable signing.

1. Purpose

To ensure electronic records and electronic signatures used at Quillbrook are trustworthy, reliable and equivalent to paper records and handwritten signatures, in accordance with 21 CFR Part 11.

2. Scope

Applies to all computerised systems used to create, modify, maintain, archive, retrieve or transmit records required by predicate rules, including electronic data capture, electronic source, the SOP acknowledgment system, the training system and email containing study records.

3. Responsibilities

  • IT Director & HIPAA Security Officer: Maintains system inventory, validation records, access control and audit trail review.
  • Quality Assurance Director: Approves validation documentation and periodically reviews electronic signature records.
  • System Owners: Define user roles, request access changes, and confirm access reviews.
  • All Users: Use only their own credentials, never share passwords, and understand that their electronic signature is legally binding.

4. Definitions

Electronic record
Any combination of text, graphics, data, audio or other information in digital form that is created, modified, maintained, archived, retrieved or distributed by a computer system.
Electronic signature
A computer data compilation of any symbol or series of symbols executed, adopted or authorised by an individual to be the legally binding equivalent of the individual's handwritten signature.
Signature manifestation
The displayed or printed information accompanying a signed record showing the printed name of the signer, the date and time, and the meaning of the signature.
Audit trail
Secure, computer-generated, time-stamped records that independently record the date, time and author of entries and changes, without obscuring previously recorded information.

5. Procedure

  1. Maintain an inventory of all computerised systems that hold records required by predicate rules, recording the system owner, validation status, and whether it holds protected health information.
  2. Validate each system before production use and after significant change, retaining requirements, test scripts, test evidence and a release approval.
  3. Assign every user a unique user identification; never create shared or generic accounts, and never permit one person to sign using another person's credentials.
  4. Apply role-based access with least privilege, and require a documented request from the system owner for every grant, change or revocation of access.
  5. Revoke access on the same business day that a person's employment ends or their role no longer requires the system, coordinating with HR & Admin and IT & Security.
  6. Enforce password complexity, expiry and lockout, and require automatic session logoff after a defined period of inactivity.
  7. Require a signature component check at the point of signing: the signer must confirm intent and re-enter credentials to execute an electronic signature.
  8. Include in every electronic signature record the printed name of the signer, the date and time of signing with the time zone offset, and the meaning associated with the signature such as read and understood, authored, reviewed or approved.
  9. Display the signature manifestation with the signed record and include it in any human-readable copy or printout of that record.
  10. Never allow an executed electronic signature or the record it applies to be altered or deleted; corrections are made by a new record that references the original, and a void action must record the reason, the actor and the time.
  11. Enable a secure, computer-generated, time-stamped audit trail in every system, retain it for at least as long as the underlying record, and make it available for review and copying.
  12. Review audit trails for critical records at a documented frequency, at minimum quarterly, and investigate anomalies through QA-002.
  13. Retain electronic records so they remain accurate, complete and readable throughout the retention period, and verify readability of archived records at least annually.
  14. Confirm that any external system or vendor holding regulated records provides Part 11 capability, an audit trail, and, where protected health information is involved, an executed business associate agreement per HIP-002.
  15. Certify to the FDA, where required, that electronic signatures used at the site are intended to be the legally binding equivalent of handwritten signatures.

6. References

  • 21 CFR Part 11 — Electronic Records; Electronic Signatures
  • FDA Guidance: Part 11, Electronic Records; Electronic Signatures — Scope and Application
  • ICH E6(R3) Good Clinical Practice, computerised systems
  • 45 CFR 164.312 — Technical safeguards
  • DAT-001 Source Documentation & ALCOA+ Principles

7. Revision History

  • v2.0 · Jul 11, 2023 — Added quarterly audit trail review.
  • v3.0 · Feb 16, 2026 — Added signature manifestation and void-with-reason requirements for the SOP acknowledgment system.

— End of document —

Document control
OwnerGideon Mbeki-Turner
ApproverEvelyn Marchetti-Sung
EffectiveFeb 16, 2026
Next reviewFeb 16, 2027
Estimated read13 minutes
Applies toAll departments
My statusIn Progress
Signed this version (38)

Devan Ramaswamy

Read and understood · Jun 22, 2026, 09:57 AM UTC

Thaddeus Moreau, MD

Read and understood · Sep 23, 2026, 09:57 AM UTC

Priyanka Venkataraman, MD

Read and understood · Jul 08, 2026, 11:57 AM UTC

Cornelius Abara, MD

Read and understood · Sep 21, 2026, 11:57 AM UTC

Rosalind Achterberg, DO

Read and understood · Sep 18, 2026, 01:57 PM UTC

Silas Wentworth, PA-C

Read and understood · Sep 06, 2026, 08:57 AM UTC

Noor Al-Rashidi, NP

Read and understood · Sep 05, 2026, 02:57 PM UTC

Sunniva Lindqvist, RN

Read and understood · Sep 25, 2026, 10:57 AM UTC

Tomasz Wierzbicki

Read and understood · Jul 29, 2026, 08:57 AM UTC

Anaya Bhattacharya

Read and understood · Jun 30, 2026, 02:57 PM UTC

Lucinda Ferreira-Mota

Read and understood · Aug 24, 2026, 02:57 PM UTC

Adebayo Ogunleye

Read and understood · Jun 18, 2026, 01:57 PM UTC

Renzo Palacios, RN

Read and understood · Sep 05, 2026, 01:57 PM UTC

Ingeborg Strand, RN

Read and understood · Jun 21, 2026, 11:57 AM UTC

Delphine Rousseau

Read and understood · Aug 18, 2026, 09:57 AM UTC

Milo Ferrante

Read and understood · Sep 26, 2026, 03:57 PM UTC

Saoirse MacLochlainn, RN

Read and understood · Jun 30, 2026, 03:57 PM UTC

Jamal Whitfield

Read and understood · Jun 21, 2026, 03:57 PM UTC

Ximena Arredondo

Read and understood · Aug 30, 2026, 03:57 PM UTC

Ilse Vermeulen

Read and understood · Aug 31, 2026, 12:57 PM UTC

Sebastián Duarte

Read and understood · Jul 25, 2026, 09:57 AM UTC

Harriet Oyelaran

Read and understood · Jul 07, 2026, 08:57 AM UTC

Rosalie Beauchamp

Read and understood · Aug 15, 2026, 10:57 AM UTC

Tallulah Winthrop

Read and understood · Sep 28, 2026, 12:57 PM UTC

Solveig Aune, PharmD

Read and understood · Sep 20, 2026, 03:57 PM UTC

Rashida Karimova

Read and understood · Sep 01, 2026, 10:57 AM UTC

Desmond Achebe

Read and understood · Aug 04, 2026, 10:57 AM UTC

Ingrid Bäckström

Read and understood · Jul 14, 2026, 01:57 PM UTC

Casimir Olszewski

Read and understood · Jul 12, 2026, 02:57 PM UTC

Farrukh Tashkentov

Read and understood · Jun 27, 2026, 12:57 PM UTC

Coretta Blanchard

Read and understood · Jun 21, 2026, 02:57 PM UTC

Ravi Choudhury

Read and understood · Sep 15, 2026, 10:57 AM UTC

Malachi Osei-Tutu

Read and understood · Jul 19, 2026, 02:57 PM UTC

Adaeze Okafor

Read and understood · Aug 27, 2026, 10:57 AM UTC

Jasper Lindholm

Read and understood · Sep 27, 2026, 11:57 AM UTC

Ezekiel Barrantes

Read and understood · Jun 19, 2026, 12:57 PM UTC

Augustin Delacroix

Read and understood · Aug 27, 2026, 02:57 PM UTC

Miriam Sandoval-Reyes

Read and understood · Sep 28, 2026, 11:57 AM UTC