21 CFR Part 11: A Practical Compliance Checklist for 2026
A concise, audit-ready walkthrough of what FDA inspectors look for in electronic records and signatures — and how modern platforms close every gap.
21 CFR Part 11 has been the FDA’s rulebook for electronic records and electronic signatures since 1997. Nearly three decades in, most warning letters still cite the same handful of failures — and they all trace back to how systems handle identity, audit trails, and data integrity.
The good news: a modern platform can close every gap by design. The bad news: bolted-on tools rarely do. Below is the checklist we walk every new customer through before their first inspection.
1. Unique user identities — no shared logins, ever. Every action on a GxP record must be traceable to a single named person, verified by a second factor.
2. Time-stamped, tamper-evident audit trails. Inspectors will ask to see the audit trail on a random record. If your system can’t render who, what, and when in under 10 seconds, you have a problem.
3. Electronic signatures bound to their records. A signature is not a checkbox — it must include the signer’s printed name, the date and time, and the meaning of the signature, and it must be cryptographically bound to the record.
4. Validated system, documented in a VMP. IQ, OQ, and PQ scripts should live inside the platform itself, not in a filing cabinet. Continuous validation beats point-in-time validation every audit cycle.
5. Data integrity per ALCOA+. Attributable, Legible, Contemporaneous, Original, Accurate — plus Complete, Consistent, Enduring, and Available. Every one of these must be enforceable by the system, not by policy alone.
If your current platform can’t check every box above without custom work, you’re carrying compliance debt into every inspection. That’s the debt KOŚA was built to eliminate.
