QA Teams: Map One Evidence Package to Satisfy Part 11 and Annex 11
News

QA Teams: Map One Evidence Package to Satisfy Part 11 and Annex 11

QA and regulatory teams: build one traceability matrix plus QRM to produce a single evidence package that meets Part 11 and Annex 11 audits.

Default Author

PCS Precision

Part 11 governs electronic records and signatures under FDA predicate rules, while Annex 11 governs the full lifecycle of computerised systems under EU GMP and PIC/S guidance. If your systems touch both markets, the first practical step is to list every system holding predicate records and apply a risk-based mapping to Annex 11’s lifecycle controls.


TL;DR:

  • Systems holding predicate records require validation and controls aligned with either Part 11 or Annex 11, depending on jurisdiction and use case.
  • Misclassifying predicate-rule coverage is a common audit issue, leading to overvalidation or overlooked vulnerable systems.
  • A combined evidence package should map predicate records, classify system criticality, and document both validation and supplier oversight processes.
  • Annex 11 emphasizes risk-based validation, lifecycle management, and supplier oversight, while Part 11 focuses narrowly on record-specific controls.
  • Validation depth can differ for the same system under each framework, but a unified justification supports compliance across both regulations.

PCS Precision
Support Your Calibration Evidence
PCS Precision provides calibration, equipment sales, and servicing to support accurate measurement records and compliance across regulated industries.
Book a calibration

Table of Contents

1. What 21 CFR Part 11 covers and how to tell if it applies

Part 11 sits inside the United States Code of Federal Regulations and sets out when the FDA will accept an electronic record or electronic signature as equivalent to a paper record or handwritten signature. The authoritative text runs from scope and definitions through to the technical controls, and it is worth reading directly rather than relying on summaries, starting with the electronic records and signatures rule itself.

Part 11 does not apply to every digital file a regulated company creates. It applies only where a “predicate rule” (an existing FDA regulation such as Good Manufacturing Practice or Good Laboratory Practice requirements) already requires a record to be kept or a signature to be captured. If no predicate rule requires the record, Part 11 controls do not attach to it. The FDA’s own scope and application guidance narrows this further, explaining where the agency intends to exercise enforcement discretion rather than demand full validation of every legacy system.

Once a record is identified as falling under a predicate rule, Part 11 expects specific technical and procedural controls. These typically include:

  • Audit trails that record who changed a record, when, and what the change was.
  • Authentication controls that confirm the identity of the person signing or entering data.
  • System validation appropriate to the record’s regulatory weight.
  • Record protection against unauthorised alteration, loss, or premature destruction.
  • Additional controls for open systems, such as encryption or digital signature standards, where the system is not fully controlled by the regulated organisation.

Getting this classification wrong, treating every system as Part 11-relevant, or missing one that genuinely is, is one of the most common starting points for an audit finding.

2. What EU GMP Annex 11 covers and key expectations

Annex 11 takes a wider view. Rather than focusing narrowly on records and signatures, it addresses the entire lifecycle of a computerised system used in a GMP-regulated process, from specification through retirement. It sits within EudraLex Volume 4 and is echoed in PIC/S member-country guidance, and the current version is available directly from the Annex 11 computerised systems document.

Because Annex 11 is a guidance document rather than a binding regulation in the way Part 11 is, it leaves more room for a risk-based approach, but that flexibility comes with an expectation that every decision is justified and documented. Key expectations include:

  • Lifecycle validation, covering specification, configuration, testing, and ongoing maintenance in a validated state.
  • Quality risk management (QRM) as the mechanism for deciding how much validation effort a system warrants.
  • Periodic evaluation of systems already in production, not just validation at go-live.
  • Audit trails, identity and access management, and data integrity controls comparable in intent to Part 11 but framed around the system’s whole life rather than a single record type.
  • Supplier oversight, particularly for outsourced or cloud-hosted systems, where the regulated company remains accountable even when a third party operates the infrastructure.

Recent consultation activity around Chapter 4 and Annex 11 revisions points to stronger supplier oversight expectations and a growing insistence on traceability matrices as a standard audit artefact, tying user requirements through testing to the SOPs that govern daily use.

3. Side-by-side comparison: axes auditors care about

Both frameworks share the same underlying goal: confidence that electronic data is accurate, attributable, and protected from tampering. Where they diverge is in focus, legal weight, and the depth of lifecycle documentation expected.

Axis 21 CFR Part 11 EU Annex 11
Scope / primary focus Electronic records and electronic signatures Full lifecycle of computerised systems
Legal status Binding US federal regulation EU GMP guidance, reinforced through PIC/S
Validation approach Validation tied to predicate-rule records Risk-based validation across the system lifecycle
Audit trail and signature coverage Specific controls for closed and open systems Audit trails and IAM framed as ongoing lifecycle controls
Risk management emphasis Implicit, tied to record criticality Explicit QRM drives validation depth
Supplier / cloud oversight Limited direct guidance Explicit supplier qualification and oversight expectations
Enforcement posture FDA inspection, enforcement discretion on some elements Inspectorate review under GMP, PIC/S alignment

A few points are worth drawing out beyond the table:

  • Part 11’s narrower focus means a system can be entirely out of scope if it holds no predicate records, whereas Annex 11 applies to any GMP-relevant computerised system regardless of record type.
  • Annex 11’s QRM requirement means two organisations running the same software can legitimately apply different validation depths, provided each documents its reasoning.
  • Comparative industry analysis of the two frameworks notes that both aim at data integrity and traceability, but a literal clause-by-clause mapping tends to produce gaps rather than clarity.

Reconciling the two is less about matching one clause to another and more about building a single evidence set, a traceability matrix and risk assessment, that happens to satisfy both. Where a system holds US predicate records and operates under EU GMP, the safest approach is to validate to the higher of the two expectations and let the documentation show which requirement each control satisfies.

4. Detailed divergences that lead to audit findings

Most inspection observations trace back to one of four recurring mismatches between what a team assumed and what each framework actually expects; properly displayed and updated workshop safety signs can help enforce procedural compliance and safety awareness in such regulated environments.

  1. Predicate-rule misclassification. Teams either apply Part 11 controls to records no predicate rule covers, wasting validation effort, or miss a record that genuinely triggers Part 11 and leave it unprotected. The FDA’s own scope guidance is the reference point for resolving this, not internal assumption.
  2. Audit-trail scope gaps. Part 11 auditors look for a trail tied to the specific record and signature event. Annex 11 inspectors expect the trail to demonstrate system-wide integrity across its operating life, including configuration changes that never touch a single record directly.
  3. Electronic signature linkage. Both frameworks expect a signature to be unrepudiable and permanently linked to the record it authorises; a system that allows a signature to be copied, reused, or detached from its record fails both standards at once.
  4. Change control and periodic review mismatches. Part 11 expects controls at the point of record creation and amendment. Annex 11 additionally expects scheduled periodic evaluation of the system itself, something teams built only around Part 11 often skip entirely.

Pro Tip: Treat predicate-rule classification as the first deliverable in any validation project, not an afterthought; everything else inherits from that decision.

5. Practical compliance checklist to build one evidence package for both frameworks

A single, well-structured evidence package can satisfy an FDA inspector and an EU GMP auditor without duplicating effort, provided it is built in the right order.

  1. Identify every predicate record and the system that generates, stores, or signs it.
  2. Classify each system’s criticality using quality risk management, and set validation scope to match.
  3. Build a traceability matrix linking user requirements to test cases, SOPs, and the evidence that proves each was executed.
  4. Assess suppliers and cloud providers, and write audit and change-notification rights into contracts.
  5. Schedule periodic evaluation and audit-trail review, not just a one-off validation at go-live.

Supporting documentation that keeps this checklist audit-ready includes:

  • A predicate-record register, updated whenever a new system or process is introduced.
  • A risk assessment log showing the rationale behind each validation decision.
  • Supplier qualification files, including acceptance testing records and service-level agreements.

6. Quality risk management and supplier oversight: what Annex 11 now requires

QRM is not a formality; it is the mechanism that determines how deep validation needs to go for a given system. Document the rationale behind that decision, because an auditor will ask for it before asking for the test scripts themselves.

Supplier oversight evidence should include:

  • Supplier qualification and acceptance testing records.
  • Change notification agreements, so you know before a vendor alters a hosted system.
  • Service-level agreements with an explicit right-to-audit clause.

Pro Tip: Keep supplier evidence in the same folder structure as your internal validation files; auditors move faster when the two sit side by side.

7. Mapping example: one system mapped to Part 11 and Annex 11

Take a laboratory information management system (LIMS) used to record batch release test results. The predicate record here is the test result itself, since a GMP predicate rule requires it to be retained.

  • URS item: “System shall capture analyst identity and timestamp on result entry.”
  • Test case: Confirm the system blocks result entry without an authenticated login.
  • Evidence document: Signed test script plus the audit trail export showing the control in action.

Part 11 is satisfied by the record-level audit trail and signature control. Annex 11 adds a further layer: evidence that the LIMS vendor was qualified, that the system is scheduled for periodic evaluation, and that configuration changes since go-live have been tracked through change control, not just the original validation.

8. PCS Precision perspective: calibration records as audit evidence

Instrument data feeding a validated system is only as credible as the calibration behind it. We provide calibration certificates and digital calibration outputs designed to sit alongside validation evidence, giving auditors traceable asset identifiers, calibration dates, and tolerance data they can check against the records a LIMS or batch system produces. When selecting a calibration partner, ask for digital outputs that integrate cleanly into your evidence package rather than standalone paper certificates.

Calibrated instrument beside evidence folder

9. A pragmatic compliance stance

Map your evidence once, justify validation depth through quality risk management, and keep jurisdiction-specific proofs ready for the auditor who asks for them. A one-to-one checkbox mapping between Part 11 and Annex 11 clauses looks tidy but rarely survives contact with a real inspection.

— Kaz

How PCS Precision supports validation evidence through calibration services

We supply the traceable measurement evidence that sits underneath both frameworks’ data integrity expectations.

  • Calibration certificates and digital outputs built to slot into existing validation files.
  • Equipment servicing and trade verification that keep instrument evidence current between audits.

Explore our calibration services to see how a calibration record set can strengthen your next validation package.

FAQ

What is the difference between Part 11 and Annex 11?

Part 11 is a binding US regulation covering electronic records and electronic signatures tied to predicate rules. Annex 11 is EU GMP guidance covering the full lifecycle of computerised systems, with quality risk management setting the validation depth.

What is 21 CFR Part 11 in simple words?

It is the FDA rule that says an electronic record or signature can replace paper, but only when specific controls like audit trails, authentication, and system validation are in place. It only applies where an existing predicate rule already requires that record to be kept, as explained in the FDA’s scope guidance.

What are Annex 11 requirements?

Annex 11 requires computerised systems used in GMP processes to be validated across their lifecycle, risk-assessed through QRM, periodically evaluated, and supported by documented supplier oversight for outsourced or cloud-hosted components. The current expectations are set out in the Annex 11 guidance document.

Who must comply with 21 CFR Part 11?

Any organisation operating under an FDA predicate rule, such as GMP or GLP requirements, must apply Part 11 controls to the electronic records and signatures that rule requires. Organisations with no predicate-rule record in a given system fall outside Part 11’s scope for that system.

Sources

Default Author

PCS Precision

Your Cart