Research
What makes an electronic laboratory record count
A number on a screen is not a record. Federal rules set out what an electronic system has to do before its output is treated as equivalent to a signed page — and the central requirement is an audit trail that cannot quietly overwrite what came before.
What the rule is trying to establish
The electronic records rule states its own purpose in its first sentence: it sets the criteria under which the agency considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and generally equivalent to paper records and handwritten signatures executed on paper.
Its reach is wide. It applies to records in electronic form that are created, modified, maintained, archived, retrieved or transmitted under any records requirement set out in agency regulations, and to electronic records submitted to the agency even where not specifically identified in those regulations. It does not apply to paper records that are, or have been, transmitted by electronic means. Where the criteria are met, electronic signatures are considered equivalent to full handwritten signatures, initials and other general signings required by agency regulations, and electronic records may be used in lieu of paper records unless paper records are specifically required.
One clause is easy to miss and matters for anyone thinking about what a regulator can actually see. Computer systems — including hardware and software — controls, and attendant documentation maintained under the part must be readily available for, and subject to, agency inspection. The system itself is inspectable, not only its printouts.
The definitions distinguish two environments. A closed system means one in which system access is controlled by persons responsible for the content of the electronic records on it. An open system means one in which access is not controlled by those persons. The controls required differ accordingly.
Eleven controls, and the one that does the work
For a closed system, the rule requires procedures and controls designed to ensure the authenticity, integrity and, where appropriate, the confidentiality of electronic records, and to ensure that the signer cannot readily repudiate the signed record as not genuine. Eleven specific controls follow.
Validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records. The ability to generate accurate and complete copies of records in both human readable and electronic form suitable for inspection, review and copying by the agency. Protection of records to enable their accurate and ready retrieval throughout the retention period. Limiting system access to authorised individuals.
Then the central one. Use of secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records. The rule adds two conditions in the same paragraph: record changes shall not obscure previously recorded information, and audit trail documentation shall be retained for a period at least as long as that required for the subject electronic records, and be available for agency review and copying.
That single paragraph is the electronic equivalent of the paper rule requiring a correction to be struck through rather than erased. It is why an electronic system can be more auditable than a notebook rather than less.
The remaining controls fill in around it. Operational system checks to enforce permitted sequencing of steps and events. Authority checks to ensure only authorised individuals can use the system, sign a record, alter a record, or perform the operation at hand. Device checks on the validity of the source of data input. A determination that the people who develop, maintain or use the systems have the education, training and experience to perform their tasks. Written policies that hold individuals accountable for actions initiated under their electronic signatures, in order to deter record and signature falsification. And controls over systems documentation, including change control procedures that maintain an audit trail of time-sequenced modification of that documentation.
An open system takes all of the above as appropriate, plus additional measures — the rule names document encryption and use of appropriate digital signature standards — to ensure record authenticity, integrity and confidentiality from the point of creation to the point of receipt.
What an electronic signature has to be
A signed electronic record must carry information associated with the signing that clearly indicates three things: the printed name of the signer, the date and time when the signature was executed, and the meaning associated with the signature — the rule gives review, approval, responsibility and authorship as examples. Those three items are subject to the same controls as the record itself and must be included in any human readable form of it, whether displayed or printed.
The linking requirement is stated as an anti-forgery rule. Electronic signatures and handwritten signatures executed to electronic records must be linked to their respective records to ensure that the signatures cannot be excised, copied or otherwise transferred to falsify an electronic record by ordinary means.
Each electronic signature must be unique to one individual and must not be reused by, or reassigned to, anyone else. Before an organisation establishes, assigns, certifies or otherwise sanctions an individual's electronic signature or any element of it, the organisation must verify the identity of that individual.
There is also a filing obligation that surprises people. Persons using electronic signatures must certify to the agency, before or at the time of use, that the electronic signatures in their system are intended to be the legally binding equivalent of traditional handwritten signatures. That certification must itself be signed with a traditional handwritten signature. On request, additional certification or testimony may be required that a specific electronic signature is the legally binding equivalent of the signer's handwritten signature.
The mechanics for signatures not based on biometrics are prescribed. They must employ at least two distinct identification components, such as an identification code and a password, and must be used only by their genuine owners. They must be administered and executed to ensure that attempted use by anyone other than the genuine owner requires collaboration of two or more individuals. The identification code and password controls run to five further items, including maintaining the uniqueness of each combination so that no two individuals share one, loss management procedures for compromised tokens or cards, and transaction safeguards that detect and report attempted unauthorised use in an immediate and urgent manner.
What the data integrity guidance adds
A separate agency guidance, issued in December 2018 under docket FDA-2018-D-3984, addresses the same subject from the manufacturing side. It is explicitly non-binding: the document states that guidances describe the agency's current thinking and should be viewed only as recommendations unless specific regulatory or statutory requirements are cited, and that the word should means something is suggested or recommended, but not required.
It supplies the working definition most often quoted. For the purposes of the guidance, data integrity refers to the completeness, consistency, and accuracy of data — and complete, consistent, and accurate data should be attributable, legible, contemporaneously recorded, original or a true copy, and accurate. That last list is the acronym ALCOA, and the guidance footnotes each element to a specific manufacturing regulation.
It defines metadata as the contextual information required to understand data, and makes the point with a number: the guidance observes that the number twenty-three is meaningless without metadata, such as an indication of the unit milligrams. Metadata for a piece of data could include a date and time stamp documenting when the data were acquired, a user identifier for the person who conducted the test, the instrument identifier, the material identification number, and audit trails.
Its audit trail definition matches the regulation and then makes it concrete. An audit trail means a secure, computer-generated, time-stamped electronic record that allows for reconstruction of the course of events relating to the creation, modification, or deletion of an electronic record. The worked example is a chromatography run: the audit trail should include the user name, the date and time of the run, the integration parameters used, and details of any reprocessing, with documentation including the justification for that reprocessing.
On who reviews audit trails, the guidance draws an analogy worth keeping. Audit trail review is similar to assessing cross-outs on paper when reviewing data. Personnel responsible for record review should review the audit trails that capture changes to data associated with the record as they review the rest of the record. On frequency, where the review frequency for the data is specified in regulation, the same frequency applies to the audit trail; where it is not, the frequency should be determined using process knowledge and risk assessment tools.
Static, dynamic, and the practices the guidance names as violative
One distinction in the guidance explains a whole category of laboratory disputes. Static means a fixed-data record such as a paper record or an electronic image. Dynamic means the record format allows interaction between the user and the record content — and the guidance gives the example of a dynamic chromatographic record that may allow the user to change the baseline and reprocess the data so that the resulting peaks may appear smaller or larger.
The consequence is stated directly. A paper printout may satisfy retention requirements where it is the original record or a true copy: the guidance names pH meters and balances as instruments that may create a paper printout as the original record. But electronic records from certain laboratory instruments are dynamic, and a printout or static record does not preserve the dynamic format that is part of the complete original record. The guidance names a spectral file created by Fourier transform infrared spectroscopy as an example, and adds a plain warning: if the full spectrum is not displayed in the printout, contaminants may be excluded.
On invalidating a result, the guidance restates the underlying rule and adds an important consequence. Invalidating test results to exclude them from decisions about conformance to a specification requires a valid, documented, scientifically sound justification — and even where results are legitimately invalidated on the basis of a sound investigation, the full batch record provided to the quality unit would include the original invalidated data along with the investigation report justifying the invalidation. Removing a number from the decision does not remove it from the record.
Two practices are named as inconsistent with good manufacturing practice. The guidance states that the agency prohibits sampling and testing with the goal of achieving a specific result or to overcome an unacceptable result — testing different samples until the desired passing result is obtained, a practice it calls testing into compliance — and that it considers it a violative practice to use an actual sample in test, preparation or equilibration runs as a means of disguising it. Asked whether it is acceptable to save only the final results of reprocessed chromatography, the guidance answers no, and requires each result to be retained for review.
It also closes off informal handling of the worst case. Asked whether an internal tip about potential data falsification can be handled outside the documented quality system, it answers no: regardless of intent or from whom the information came, suspected or known falsification or alteration of required records must be fully investigated under the quality system to determine the effect on patient safety, product quality and data reliability, to determine the root cause, and to ensure necessary corrective actions are taken.
For a reader looking at a laboratory result on a product page, none of this is visible. A certificate is a static document, and nothing on its face reveals whether the chromatogram behind it came from a validated system with an audit trail, whether the run was reprocessed, or whether earlier runs exist. That is the honest limit of what any single-page test report can tell anyone.
Key takeaways
- The rule exists to establish when electronic records and signatures are treated as trustworthy, reliable and generally equivalent to paper.
- Eleven controls apply to a closed system, and the central one is a secure, time-stamped audit trail that must not obscure previously recorded information.
- A signed electronic record must show the signer's printed name, the date and time, and the meaning of the signature — and the signature must be linked so it cannot be transferred to another record.
- A non-binding agency guidance supplies the working definition of data integrity and the ALCOA characteristics, and defines an audit trail with a chromatography worked example.
- A printout of a dynamic instrument record is not the complete original record, and a partial spectrum can hide contaminants.
- An invalidated result stays in the batch record alongside the investigation that justified invalidating it.
Frequently asked questions
What does an audit trail have to record?
The regulation requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions creating, modifying or deleting electronic records. Record changes must not obscure previously recorded information, and the audit trail must be retained at least as long as the records themselves and be available for agency review and copying.
Is an electronic signature legally equivalent to a written one?
Where the criteria in the rule are met, the agency considers electronic signatures equivalent to full handwritten signatures, initials and other general signings required by its regulations. Users must also certify to the agency, before or at the time of use, that the signatures in their system are intended to be the legally binding equivalent of handwritten signatures — and that certification must itself be signed by hand.
What does ALCOA mean?
It is an acronym from an agency guidance, not a regulation. That guidance states data integrity refers to the completeness, consistency and accuracy of data, and that complete, consistent and accurate data should be attributable, legible, contemporaneously recorded, original or a true copy, and accurate. The guidance footnotes each element to specific manufacturing regulations, and states that its recommendations are not binding.
Why does it matter whether a record is static or dynamic?
Because a printout of a dynamic record is not the whole record. The guidance defines static as a fixed-data record such as a paper record or electronic image, and dynamic as a format allowing interaction between user and content — such as a chromatographic record that permits changing the baseline and reprocessing the data so peaks appear smaller or larger. It notes that where a full spectrum is not displayed in a printout, contaminants may be excluded.
Can a failing test result simply be deleted?
No. Invalidating a result to exclude it from a conformance decision requires a valid, documented, scientifically sound justification, and even where a result is legitimately invalidated, the full batch record given to the quality unit includes the original invalidated data along with the investigation report that justifies invalidating it.
Can I tell from a certificate of analysis whether these controls were in place?
No. A certificate is a static one-page output. Nothing on its face indicates whether the underlying system was validated, whether an audit trail exists, whether the chromatography was reprocessed, or whether earlier runs of the same sample exist. That is a limitation of the document format, not an allegation about any particular certificate.
Sources
Each document below is named as it names itself, with the date printed on that document rather than the day it was read.
- 21 CFR 11.1 and 11.3 — Scope and Definitions, read in full for the trustworthy-reliable-equivalent purpose statement, the application to electronic records created, modified, maintained, archived, retrieved or transmitted under agency records requirements, the exclusion of paper records transmitted electronically, the inspectability of computer systems and attendant documentation, and the definitions of closed system, open system, electronic record and electronic signature — Electronic Code of Federal Regulations, National Archives and Records Administration, September 2026
- 21 CFR 11.10 — Controls for closed systems, read in full for all eleven required controls including system validation, generation of accurate and complete human-readable and electronic copies, secure computer-generated time-stamped audit trails, the requirement that record changes not obscure previously recorded information, authority and device checks, and written accountability policies to deter record and signature falsification — Electronic Code of Federal Regulations, National Archives and Records Administration, September 2026
- 21 CFR 11.50 and 11.70 — Signature manifestations and Signature/record linking, read in full for the three items a signed electronic record must show (printed name, date and time, meaning of the signature) and for the requirement that signatures be linked so they cannot be excised, copied or transferred to falsify a record — Electronic Code of Federal Regulations, National Archives and Records Administration, September 2026
- 21 CFR 11.100, 11.200 and 11.300 — General requirements, Electronic signature components and controls, and Controls for identification codes and passwords, read in full for signature uniqueness and non-reassignment, identity verification before assignment, the handwritten-signature certification to the agency, the two-component rule and its session behaviour, the two-person collaboration requirement, and the five identification code and password controls — Electronic Code of Federal Regulations, National Archives and Records Administration, September 2026
- Data Integrity and Compliance With Drug CGMP: Questions and Answers — Guidance for Industry, docket FDA-2018-D-3984. The guidance PDF was downloaded and its full text read for the non-binding statement, the definition of data integrity and the ALCOA characteristics, the definition of metadata with the milligrams example, the audit trail definition and chromatography example, the audit trail review analogy and frequency rule, the static and dynamic record distinction with the spectroscopy example, the requirement that invalidated data remain in the batch record, the statements on testing into compliance and on system suitability runs, the refusal to permit informal handling of suspected falsification, and the answer that only final reprocessed chromatography results may not be saved — U.S. Food and Drug Administration, December 2018