7 Things to Check in a 21 CFR Part 11-Ready ELN

A practical vendor-evaluation checklist for audit trails, electronic signatures, validation, record retention, and controlled workflows
Table of Contents
5
min read
Scientist reviewing an electronic laboratory record on a computer, representing audit trails, electronic signatures, and controlled data in a regulated ELN.

A vendor saying its ELN is “21 CFR Part 11 compliant” is not the end of the conversation. It is the start of one.

Part 11 establishes requirements for electronic records and electronic signatures used in FDA-regulated contexts. It covers the controls needed to help ensure electronic records are authentic, reliable, available for review, and appropriately linked to the people and actions behind them. FDA’s Part 11 guidance is clear that scope depends on how records are used and the applicable predicate rules.

For an ELN evaluation, the practical question is not whether the software has a compliance badge. It is whether the system, your configuration, and your operating procedures can support the controls your organization needs.

This is an informational checklist, not legal advice. Use it to structure vendor demonstrations and internal discussions with Quality, IT, Compliance, and validation teams.

1. Can You Reconstruct the History of a Record?

An audit trail should make it possible to understand what happened to a record over time.

Under 21 CFR §11.10(e), closed systems must use secure, computer-generated, time-stamped audit trails to independently record the date and time of actions that create, modify, or delete electronic records. Changes must not obscure previously recorded information, and audit-trail documentation must remain available for review and copying for at least as long as the underlying record is required to be retained.

For an ELN, that means a reviewer should be able to see the original value, the changed value, who made the change, when it happened, and the relevant context around it.

The most useful vendor-demo question is simple:

Show the full history of a specific experimental result after it has been entered, amended, reviewed, and approved.

Do not accept a generic audit-log screenshot. Ask to see the history attached to a real record, including a change to a result or condition.

2. Can You Identify Exactly Who Did What?

Part 11 requires controls that limit system access to authorized individuals. It also requires authority checks to ensure that only authorized people can use the system, access operations, sign records, alter records, or perform the action in question.

In practice, that means individual user accounts, appropriate authentication, and role-based permissions.

Shared logins are a clear problem because they make individual accountability impossible. A system where every authenticated user can change every record is also difficult to defend. The organization needs to show who had the authority to create, edit, review, approve, or sign a particular record.

Ask the vendor: Can we define and review permissions by role, project, workflow, or record state?

Then ask your own team: Who should be able to make this change, and what should happen if someone without that authority tries?

The second question matters just as much as the first. Compliance depends on the system configuration matching the organization’s actual responsibilities and SOPs.

3. Do Electronic Signatures Carry the Right Information?

Electronic signatures are not simply a typed name in an approval field.

Under §11.50, signed electronic records must show the signer’s printed name, the date and time the signature was executed, and the meaning associated with the signature, such as review, approval, responsibility, or authorship. Under §11.70, the signature must remain linked to the record so that it cannot be excised, copied, or transferred to falsify another record.

In an ELN, a signature event should make clear what the person signed, why they signed it, and when the action occurred.

Ask the vendor to demonstrate an approval workflow from start to finish. The signature should remain visible in the completed record, alongside the relevant audit history.

Ask: Does the signature show the signer, date, time, and meaning? Can the signature remain attached to the exact record version that was signed?

4. Can You Validate the System for Its Intended Use?

Validation is where many “Part 11-ready” conversations become real.

A vendor may provide validation documentation, testing materials, or a prebuilt validation package. That can reduce the work required. It does not eliminate the organization’s responsibility to validate its own intended use, configuration, workflows, integrations, and controls.

FDA materials describe validation as confirming that an electronic system performs its intended function correctly, with risk assessment focused on functions that affect product quality, safety, and record integrity.

The important phrase is “intended use.”

A simple ELN configuration for recording research notes does not carry the same validation burden as a workflow used to create, review, approve, and retain records supporting a regulated product decision.

Ask the vendor: What validation documentation is available, and how is it maintained after releases?

Then ask internally: Which workflows, records, calculations, integrations, and signatures need to be validated for our use case?

Your Quality team should own the second question.

5. Will the Record Still Be Available When You Need It?

Part 11 requires protection of records so they can be accurately and readily retrieved throughout the retention period. That requirement matters well beyond the active life of a project or the current version of an ELN.

A record is not truly retained if it is inaccessible after a software upgrade, difficult to export, or only meaningful inside a legacy interface that nobody can operate.

For long-lived regulated records, ask how the organization will preserve:

  • The human-readable record.
  • The relevant electronic record and metadata.
  • Audit history.
  • Electronic-signature information.
  • Linked attachments, conditions, and results.
  • The ability to retrieve the record after a system change or vendor transition.

You do not need to solve every future migration during a vendor demo. You do need a credible archival and retrieval strategy before the system becomes the record of regulated work.

6. Can You Produce a Complete Record for Review?

Under §11.10(b), systems must be able to generate accurate and complete copies of records in both human-readable and electronic form for inspection, review, and copying by the FDA.

That means an export should contain enough context to stand on its own.

A PDF containing only a result table may not be enough if the relevant method, sample identity, conditions, attached data, signatures, and audit history are elsewhere in the system. The exported package needs to let a reviewer understand what the record represents and how it reached its final state.

Ask the vendor to export a completed, signed record.

Then ask: Can a reviewer understand the experiment, its data, the associated metadata, and its approval history without navigating through the live system?

If the answer is no, the export process needs more work.

7. Does the System Prevent Invalid Actions?

Audit trails are important because they show what happened. Operational and authority checks are important because they help prevent the wrong thing from happening in the first place.

Part 11 requires operational checks to enforce the permitted sequencing of steps and events. It also requires authority checks to confirm that only authorized people can perform relevant actions.

In practice, that can mean:

  • A record cannot be approved before required information is complete.
  • A user cannot sign a record they are not authorized to sign.
  • A completed record cannot be edited without following the defined procedure.
  • A deletion request is controlled rather than treated as a routine edit.
  • A workflow cannot skip required review or approval steps.

This is where an ELN moves beyond recordkeeping and begins enforcing the organization’s process.

Ask the vendor: Can the workflow reflect our SOPs, including required fields, review sequence, approval authority, and controlled changes after approval?

The Common Gaps to Watch For

The most serious problems often appear in routine workflow details, not in the vendor’s headline compliance claims.

Watch for audit trails that do not preserve the original value, shared accounts that prevent individual traceability, signatures that are not clearly linked to the version signed, and exports that lose the surrounding context needed to interpret the record.

Also pay attention to change management. A validated system is not static. Software releases, configuration changes, new integrations, and revised workflows can all affect the system’s validated state. Your vendor should provide a clear release and change-notification process, while your organization should have a defined approach to impact assessment and revalidation.

What This Means for ELN Selection

A regulated ELN evaluation should involve more than the lab team.

Quality, Compliance, IT, validation, and the scientists who will use the system should all be able to see how the relevant records are created, changed, reviewed, signed, exported, and retained.

The goal is not to buy an ELN that makes a broad compliance claim. It is to select a system that can support the controls your organization needs, then validate and operate that system in a way that makes the resulting records defensible.

FAQs

What does 21 CFR Part 11 require for electronic lab notebooks?

For electronic records and signatures that fall within its scope, Part 11 requires controls such as system validation, secure time-stamped audit trails, limited access to authorized individuals, accurate and complete record copies, record protection, operational checks, authority checks, and properly linked electronic signatures.

How do you make an ELN ready for 21 CFR Part 11 use?

Start by determining whether the records and workflows fall within the relevant regulatory scope. Then evaluate the ELN’s controls, configure it for your intended use, validate the applicable workflows, establish SOPs, train users, and maintain change-control processes over time.

Does an ELN vendor’s Part 11 claim make my laboratory compliant?

No. A vendor may provide software controls and validation materials that support regulated use, but the regulated organization remains responsible for its intended use, configuration, validation, procedures, user training, and ongoing governance.