Häufig gestellte Fragen
Who falls under 21 CFR Part 11?
21 CFR Part 11 affects companies from FDA-regulated industries — that is, pharmaceuticals, biotechnology, medical technology and in some cases also food and cosmetics — as soon as they manufacture products for the US market, supply it or conduct clinical trials in the USA. What matters is not the company's registered office, but whether quality-relevant records required by a so-called predicate rule (such as cGMP regulations) are kept electronically. European mid-sized companies can therefore also fall within the scope if they supply the USA. The specific scope always depends on the individual processes and on which data must actually be demonstrated to the FDA.
What are the central requirements 21 CFR Part 11 places on a system?
At its core, the regulation requires that electronic records be as trustworthy and reliable as paper documents. This includes a complete audit trail that cannot be altered after the fact (who changed what, when and with what justification), granular access control via unique user IDs, and electronic signatures that are firmly linked to the record and unambiguously attributable to a person. In addition, the data must remain readable and exportable throughout the retention period, and there must be documented proof that the system is validated. Non-biometric signatures must use at least two components in accordance with § 11.200, for example a user ID and password.
Is an ERP system automatically "21 CFR Part 11 compliant"?
No. Part 11 is not a software feature that can simply be switched on, but a catalog of requirements whose compliance only emerges from the interplay of correctly configured software, documented processes (SOPs) and demonstrated validation. Marketing claims such as "Part 11-ready" merely mean that the technical prerequisites such as an audit trail and role concept are in place — not that the operating company fulfils the regulation. Regulatory responsibility always remains with the operator, not the manufacturer. Functions are necessary but not sufficient; what matters is how they are configured, validated and operated.
Do I need a separate eQMS in addition to the ERP?
That depends on the risk class, product type and the depth of the quality processes already mapped in the ERP. Many manufacturers use a dedicated electronic quality management system (eQMS) because it covers document control, CAPA, deviation and change management in a more specialised way than a classic ERP; widely used solutions include Veeva Vault QMS and MasterControl. Wherever the ERP itself handles quality-relevant operations such as batch release or blocking, its functions must also be operated and validated in a Part 11-compliant manner. For lower risk classes, a well-configured ERP can be sufficient — there is no one-size-fits-all answer, and the decision should be made on a risk basis.
What is the difference between 21 CFR Part 11 and EU GMP Annex 11?
Both sets of rules aim at the integrity of computerised records but differ in status and focus: 21 CFR Part 11 is a legally binding FDA regulation that specifically governs electronic records and signatures, while Annex 11 is an annex to the EU GMP guidelines and takes a more holistic view of computerised systems within quality management. Annex 11 explicitly requires a documented risk assessment that also defines the scope and review frequency of audit trails, as well as supplier qualification and periodic system reviews, whereas Part 11 (§ 11.10(e)) requires audit trails in principle for all electronic records relevant to predicate rules. Companies serving both markets must therefore observe both sets of rules in parallel, as they overlap but are not identical.
How much effort does validating an ERP system for Part 11 involve?
The effort depends on system complexity and risk and typically follows the scheme of installation, operational and performance qualification (IQ/OQ/PQ), derived from a user requirements specification and a risk assessment. Industry practice is to follow the ISPE GAMP 5 standard, which calls for intensive testing where the risk to data integrity, product quality or patient safety is highest. The FDA finalised its Computer Software Assurance guidance (CSA) in September 2025; this risk-based approach replaces the earlier, more documentation-heavy CSV practice and can noticeably reduce validation effort. What remains important is a change-control process that checks with every update, patch or integration whether revalidation is necessary.
