QA and regulatory teams: build one traceability matrix plus QRM to produce a single evidence package that meets Part 11 and Annex 11 audits.
Part 11 governs electronic records and signatures under FDA predicate rules, while Annex 11 governs the full lifecycle of computerised systems under EU GMP and PIC/S guidance. If your systems touch both markets, the first practical step is to list every system holding predicate records and apply a risk-based mapping to Annex 11’s lifecycle controls.
TL;DR:
- Systems holding predicate records require validation and controls aligned with either Part 11 or Annex 11, depending on jurisdiction and use case.
- Misclassifying predicate-rule coverage is a common audit issue, leading to overvalidation or overlooked vulnerable systems.
- A combined evidence package should map predicate records, classify system criticality, and document both validation and supplier oversight processes.
- Annex 11 emphasizes risk-based validation, lifecycle management, and supplier oversight, while Part 11 focuses narrowly on record-specific controls.
- Validation depth can differ for the same system under each framework, but a unified justification supports compliance across both regulations.
Part 11 sits inside the United States Code of Federal Regulations and sets out when the FDA will accept an electronic record or electronic signature as equivalent to a paper record or handwritten signature. The authoritative text runs from scope and definitions through to the technical controls, and it is worth reading directly rather than relying on summaries, starting with the electronic records and signatures rule itself.
Part 11 does not apply to every digital file a regulated company creates. It applies only where a “predicate rule” (an existing FDA regulation such as Good Manufacturing Practice or Good Laboratory Practice requirements) already requires a record to be kept or a signature to be captured. If no predicate rule requires the record, Part 11 controls do not attach to it. The FDA’s own scope and application guidance narrows this further, explaining where the agency intends to exercise enforcement discretion rather than demand full validation of every legacy system.
Once a record is identified as falling under a predicate rule, Part 11 expects specific technical and procedural controls. These typically include:
Getting this classification wrong, treating every system as Part 11-relevant, or missing one that genuinely is, is one of the most common starting points for an audit finding.
Annex 11 takes a wider view. Rather than focusing narrowly on records and signatures, it addresses the entire lifecycle of a computerised system used in a GMP-regulated process, from specification through retirement. It sits within EudraLex Volume 4 and is echoed in PIC/S member-country guidance, and the current version is available directly from the Annex 11 computerised systems document.
Because Annex 11 is a guidance document rather than a binding regulation in the way Part 11 is, it leaves more room for a risk-based approach, but that flexibility comes with an expectation that every decision is justified and documented. Key expectations include:
Recent consultation activity around Chapter 4 and Annex 11 revisions points to stronger supplier oversight expectations and a growing insistence on traceability matrices as a standard audit artefact, tying user requirements through testing to the SOPs that govern daily use.
Both frameworks share the same underlying goal: confidence that electronic data is accurate, attributable, and protected from tampering. Where they diverge is in focus, legal weight, and the depth of lifecycle documentation expected.
| Axis | 21 CFR Part 11 | EU Annex 11 |
|---|---|---|
| Scope / primary focus | Electronic records and electronic signatures | Full lifecycle of computerised systems |
| Legal status | Binding US federal regulation | EU GMP guidance, reinforced through PIC/S |
| Validation approach | Validation tied to predicate-rule records | Risk-based validation across the system lifecycle |
| Audit trail and signature coverage | Specific controls for closed and open systems | Audit trails and IAM framed as ongoing lifecycle controls |
| Risk management emphasis | Implicit, tied to record criticality | Explicit QRM drives validation depth |
| Supplier / cloud oversight | Limited direct guidance | Explicit supplier qualification and oversight expectations |
| Enforcement posture | FDA inspection, enforcement discretion on some elements | Inspectorate review under GMP, PIC/S alignment |
A few points are worth drawing out beyond the table:
Reconciling the two is less about matching one clause to another and more about building a single evidence set, a traceability matrix and risk assessment, that happens to satisfy both. Where a system holds US predicate records and operates under EU GMP, the safest approach is to validate to the higher of the two expectations and let the documentation show which requirement each control satisfies.
Most inspection observations trace back to one of four recurring mismatches between what a team assumed and what each framework actually expects; properly displayed and updated workshop safety signs can help enforce procedural compliance and safety awareness in such regulated environments.
Pro Tip: Treat predicate-rule classification as the first deliverable in any validation project, not an afterthought; everything else inherits from that decision.
A single, well-structured evidence package can satisfy an FDA inspector and an EU GMP auditor without duplicating effort, provided it is built in the right order.
Supporting documentation that keeps this checklist audit-ready includes:
QRM is not a formality; it is the mechanism that determines how deep validation needs to go for a given system. Document the rationale behind that decision, because an auditor will ask for it before asking for the test scripts themselves.
Supplier oversight evidence should include:
Pro Tip: Keep supplier evidence in the same folder structure as your internal validation files; auditors move faster when the two sit side by side.
Take a laboratory information management system (LIMS) used to record batch release test results. The predicate record here is the test result itself, since a GMP predicate rule requires it to be retained.
Part 11 is satisfied by the record-level audit trail and signature control. Annex 11 adds a further layer: evidence that the LIMS vendor was qualified, that the system is scheduled for periodic evaluation, and that configuration changes since go-live have been tracked through change control, not just the original validation.
Instrument data feeding a validated system is only as credible as the calibration behind it. We provide calibration certificates and digital calibration outputs designed to sit alongside validation evidence, giving auditors traceable asset identifiers, calibration dates, and tolerance data they can check against the records a LIMS or batch system produces. When selecting a calibration partner, ask for digital outputs that integrate cleanly into your evidence package rather than standalone paper certificates.

Map your evidence once, justify validation depth through quality risk management, and keep jurisdiction-specific proofs ready for the auditor who asks for them. A one-to-one checkbox mapping between Part 11 and Annex 11 clauses looks tidy but rarely survives contact with a real inspection.
— Kaz
We supply the traceable measurement evidence that sits underneath both frameworks’ data integrity expectations.
Explore our calibration services to see how a calibration record set can strengthen your next validation package.
Part 11 is a binding US regulation covering electronic records and electronic signatures tied to predicate rules. Annex 11 is EU GMP guidance covering the full lifecycle of computerised systems, with quality risk management setting the validation depth.
It is the FDA rule that says an electronic record or signature can replace paper, but only when specific controls like audit trails, authentication, and system validation are in place. It only applies where an existing predicate rule already requires that record to be kept, as explained in the FDA’s scope guidance.
Annex 11 requires computerised systems used in GMP processes to be validated across their lifecycle, risk-assessed through QRM, periodically evaluated, and supported by documented supplier oversight for outsourced or cloud-hosted components. The current expectations are set out in the Annex 11 guidance document.
Any organisation operating under an FDA predicate rule, such as GMP or GLP requirements, must apply Part 11 controls to the electronic records and signatures that rule requires. Organisations with no predicate-rule record in a given system fall outside Part 11’s scope for that system.