An Easy to Understand Guide 21 CFR Part 11

Similar documents
Writing & Executing a Software Validation Protocol: Plain and Simple

21 CFR PART 11 FREQUENTLY ASKED QUESTIONS (FAQS)

ComplianceQuest Support of Compliance to FDA 21 CFR Part 11Requirements WHITE PAPER. ComplianceQuest In-Depth Analysis and Review

21 CFR Part 11 LIMS Requirements Electronic signatures and records

White Paper Assessment of Veriteq viewlinc Environmental Monitoring System Compliance to 21 CFR Part 11Requirements

Introduction. So what is 21 CFR Part 11? Who Should Comply with 21CFR Part 11?

Assessment of Vaisala Veriteq viewlinc Continuous Monitoring System Compliance to 21 CFR Part 11 Requirements

ABB Limited. Table of Content. Executive Summary

WHITE PAPER AGILOFT COMPLIANCE WITH CFR 21 PART 11

FDA 21 CFR Part 11 Compliance by Metrohm Raman

NucleoCounter NC-200, NucleoView NC-200 Software and Code of Federal Regulation 21 Part 11; Electronic Records, Electronic Signatures (21 CFR Part 11)

Complying with FDA's 21 CFR Part 11 Regulation

SDA COMPLIANCE SOFTWARE For Agilent ICP-MS MassHunter Software

Adobe Sign and 21 CFR Part 11

Integration of Agilent OpenLAB CDS EZChrom Edition with OpenLAB ECM Compliance with 21 CFR Part 11

ChromQuest 5.0. Tools to Aid in 21 CFR Part 11 Compliance. Introduction. General Overview. General Considerations

Automation Change Management for Regulated Industries

EXAM PREPARATION GUIDE

Industry Guidelines for Computerized Systems Validation (GAMP, PDA Technical Reports)

Sparta Systems TrackWise Digital Solution

Part 11 Compliance SOP

Compliance Matrix for 21 CFR Part 11: Electronic Records

MicroLab FTIR Software 21 CFR Part 11 Compliance

Electronic Data Processing 21 CFR Part 11

Sparta Systems Stratas Solution

Guide to the implementation and auditing of ISMS controls based on ISO/IEC 27001

NIST Risk Assessment for Part 11 Compliance: Evaluation of a GXP Case Study

Publications. ACH Audit Requirements. A new approach to payments advising SM. Sound Practices Checklists

OpenLAB ELN Supporting 21 CFR Part 11 Compliance

Compliance of Shimadzu Total Organic Carbon (TOC) Analyzer with FDA 21 CFR Part 11 Regulations on Electronic Records and Electronic Signatures

COMPLIANCE. associates VALIDATOR WHITE PAPER. Addressing 21 cfr Part 11

Electronic Signature Guidance

Data Integrity and the FDA AFDO Education Conference

Implementing Electronic Signature Solutions 11/10/2015

Sparta Systems TrackWise Solution

Pharma IT ELECTRONIC RECORDS

REGULATION ASPECTS 21 CFR PART11. 57, av. Général de Croutte TOULOUSE (FRANCE) (0) Fax +33 (0)

EXAM PREPARATION GUIDE

Signature Practices and Technologies for TMF An Industry Overview. Kathie Clark Wingspan Technology Vice President Product Management

21 CFR PART 11 COMPLIANCE

Electronic Signature Policy

The Impact of 21 CFR Part 11 on Product Development

ISSUE N 1 MAJOR MODIFICATIONS. Version Changes Related Release No. PREVIOUS VERSIONS HISTORY. Version Date History Related Release No.

WHITE PAPER. The General Data Protection Regulation: What Title It Means and How SAS Data Management Can Help

Integration of Agilent UV-Visible ChemStation with OpenLAB ECM

Comment sheet for MHRA draft document:

Part 11 is Dead Long Live Part CFR 11, the Electronic Records and Electronic Signatures 21 CFR PART 11. Introduction

CRITERIA FOR CERTIFICATION BODY ACCREDITATION IN THE FIELD OF RISK BASED INSPECTION MANAGEMENT SYSTEMS

CONTINUOUS PROFESSIONAL DEVELOPMENT (CPD) POLICY

Institute of Certified Forensic Accountants. Certificate in Internal Auditing

New York Department of Financial Services Cybersecurity Regulation Compliance and Certification Deadlines

Good Laboratory Practice GUIDELINES FOR THE ARCHIVING OF ELECTRONIC RAW DATA IN A GLP ENVIRONMENT. Release Date:

21 CFR 11 Assistant Software. 21 CFR Part 11 Compliance Booklet

ISO/IEC INTERNATIONAL STANDARD

EXAM PREPARATION GUIDE

TECHNICAL BULLETIN [ 1 / 13 ]

EXAM PREPARATION GUIDE

Metasys for Validated Environments, Extended Architecture Catalog Page

HIPAA by the Numbers. Presented by: Mark L. Schuweiler Director of Global Information Assurance Services EDS Corporation

Measuring the effectiveness of your ISMS implementations based on ISO/IEC 27001

PAA PKI Mutual Recognition Framework. Copyright PAA, All Rights Reserved 1

EXAM PREPARATION GUIDE

The HITRUST CSF. A Revolutionary Way to Protect Electronic Health Information

Approved 10/15/2015. IDEF Baseline Functional Requirements v1.0

Security and Architecture SUZANNE GRAHAM

Auditing and Monitoring for HIPAA Compliance. HCCA COMPLIANCE INSTITUTE 2003 April, Presented by: Suzie Draper Sheryl Vacca, CHC

ACH Clearing Rules. Guidance Note No. 5 NEW CLIENTS ELECTRONIC CLIENT AGREEMENTS KEY TOPICS ACH CLEARING RULES. Guidance Note History.

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

EXAM PREPARATION GUIDE

ACCREDITATION COMMISSION FOR CONFORMITY ASSESSMENT BODIES

INFORMATION. Guidance on the use of the SM1000 and SM2000 Videographic Recorders for Electronic Record Keeping in FDA Approved Processes

IQ Level 4 Award in Understanding the External Quality Assurance of Assessment Processes and Practice (QCF) Specification

ISO27001:2013 The New Standard Revised Edition

By Cornelia Wawretchek. The Drug Manufacturer s Guide to Site Master Files

EXAM PREPARATION GUIDE

IIA EXAM - IIA-CGAP. Certified Government Auditing Professional. Buy Full Product.

Guide for 21 CFR part 11 on NucleoView NC-200

Trust Services for Electronic Transactions

ETSI TR V1.1.1 ( )

What is cloud computing? The enterprise is liable as data controller. Various forms of cloud computing. Data controller

EU Annex 11 Compliance Regulatory Conformity of eve

Standard CIP 007 3a Cyber Security Systems Security Management

Introduction to ISO/IEC 27001:2005

Agilent ICP-MS ChemStation Complying with 21 CFR Part 11. Application Note. Overview

You may use the Service to either access, establish or change the following:

Mastersizer CFR Part 11 User Guide

ACCREDITATION COMMISSION FOR CONFORMITY ASSESSMENT BODIES

21 CFR Part 11 FAQ (Frequently Asked Questions)

PR GB. 21 CFR part 11 Compliance

DATA PROCESSING TERMS

Electronic Data Capture (EDC) Systems and Part 11 Compliance

Frequently Asked Question Regarding 201 CMR 17.00

ARTICLE 29 DATA PROTECTION WORKING PARTY

Section Qualifications of Audit teams Qualifications of Auditors Maintenance and Improvement of Competence...

Summary of PIC/S Guidance Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments

Pharmaceutical Supplier Auditor Certification Scheme The PS Scheme

eidas Workshop Return on Experience from Conformity Assessment Bodies - EY June 13, 2016 Contacts: Arvid Vermote

Using "TiNet 2.5 Compliant SR1" software to comply with 21 CFR Part 11

EXAM PREPARATION GUIDE

EXAM PREPARATION GUIDE

Transcription:

An Easy to Understand Guide 21 CFR Part 11 The Validation Specialists askaboutvalidation Connecting the Lifesciences

An Easy to Understand Guide 21 CFR Part 11 Published by Premier Validation

21 CFR Part 11 First Edition Copyright 2011 Premier Validation All rights reserved. No part of the content or the design of this book maybe reproduced or transmitted in any form or by any means without the express written permission of Premier Validation. The advise and guidelines in this book are based on the experience of the authors, after more than a decade in the Life Science industry, and as such is either a direct reflection of the "predicate rules" (the legislation governing the industry) or are best practices used within the industry. The author takes no responsibility for how this advice is implemented. Visit Premier Validation on the web at www.premiervalidation.com or visit or forum at www.askaboutvalidation.com ISBN 978-1-908084-01-9

So what's this book all about? Hey there, If you've decided to invest some time in reading this book, I am making the assumption that you are pretty tired of wading through the regulations developed by the FDA that were designed to confuse the hell out of everyone! This may sound quite dramatic, but how many people out there can really say that they fully understand the 21 CFR Part 11 regulations. I know many people claim to know what they are talking about, but why trust someone when you can use this book to bring clarity to the regulations in seconds. We are confident that if you use this book, as a reference guide next time you are testing a system for Part 11 compliance it will make the project so much easier. Of course if you need to refer to the FDA website to check for each regulation feel free, but if you need each one explained in plain English this is the book for you. Understanding the Part 11 regulations is an invaluable weapon in your arsenal. Next time you are validating or trying to explain a certain aspect of Part 11 to an auditor refer to this book and all will be revealed very quickly. So I think it's pretty clear, you've just purchased the 21 CFR Part 11 bible. Enjoy!

The brains behind the operation! Program Director: Graham O'Keeffe Content Author: Orlando Lopez Technical Editor: Mark Richardson Editor: Anne-Marie Smith Printing History: First Edition: February 2011 Cover and Graphic Design: Louis Je Tonno Notes of Rights All rights reserved. No part of this book may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written permission of the copyright holder, except in the case of brief quotations embedded in critical articles or reviews. Notes of Liability The author and publisher have made every effort to ensure the accuracy of the information herein. However, the information contained in this book is sold without warranty, either express or implied. Neither the authors and Premier Validation Ltd, nor its dealers or distributors will be held liable for any damages to be caused either directly or indirectly by the instructions contained in this book The Validation Specialists Published by Premier Validation Ltd Web: www.premiervalidation.com Forum: www.askaboutvalidation.com Email: query@premiervalidation.com ISBN 978-1-908084-01-9 Print and bound in the United Kingdom

Table of Contents The Starting Point What is 21 CFR Part 11? 2 History of 21 CFR Part 11 3 Benefits 4 Why you should read this Book? 4 E-Signatures and E-Records Explained The Regulation 6 E-Records 8 Sample Regulatory Action 9 E-Records not impacted by Part 11 10 E-Signatures 11 E-Signatures not impacted by Part 11 11 Enforcement 12 General Rules of System Access System Access to Authorized Individuals 14 Sample Regulatory Action 15 Operational System Checks 16 Electronic Signatures 17 Multi-signing 18

Unauthorized use of user IDs and Passwords 19 Automatic log out 20 Signature/record linkage 20 Validating Operational Checks 20 Authority Checks 21 Sample Regulatory Action 22 Device Checks 23 Qualifications of Electronic Systems Developers and Users 24 E-Signatures E-sig Written Policies 27 Authentication and non-repudiation 28 Methods of Authentication 29 E-sig Certification 30 Documentation and Regulation Controls System Documentation Control 32 Sample Regulatory Action 33 The Difference between Open and Closed Systems Open System Controls 35 Closed System Controls 36

Computer System Validation Computer Systems Validation 38 Elements to Successful Validation 40 Validation Documentation 39 SampleRegulatory Action 39 Audit Trails Audit Trails 41 Sample Regulatory Action 42 E-Records Record Retention 44 Records Archiving 45 Record Copying 47 Sample regulatory action 47 Hybrid & Legacy Systems Hybrid Systems 49 Legacy Systems 49 Summary 51 Appendix A: References 52 Correlation between Part 11 and Annex 11 55

The Starting Point What is Part 11? History of Part 11 Benefits Why you should read this Book 1

What is 21 CFR Part 11? 21 CFR Part 11 is a section in the Code of Federal Regulations (CFR) that sets forth the United States Food and Drug Administration's (FDA) guidelines on using electronic records (e-recs) and electronic signatures (e-sigs). Part 11, as it's commonly called, defines the criteria under which electronic records and electronic signatures are considered to be accurate, authentic, trustworthy, reliable, confidential, and equivalent to paper records and handwritten signatures on paper. Currently, the scope of this regulation is all FDA program areas. 2

History of 21 CFR Part 11 In the late 1980s, drug and medical device manufacturers, biotech companies, and other FDA-regulated industries requested FDA guidelines for the use of e-sigs in paperless batch record systems. Part 11 was published in 1997. After it was published, however, its enforcement was put on hold as the result of discussions among industry, contractors, and the FDA concerning the interpretation and implementation of the regulation. In August 2003, the FDA published FDA Guidance for Industry Part 11, Electronic Records; Electronic Signatures Scope and Application, which describes how Part 11 should be implemented and how the FDA would enforce the regulation. These guidelines acknowledged that the need for security measures was not the same for every piece of electronic information. It also introduced the concept of risk analysis and promoted the formal process of risk assessment to determine appropriate security measures. The regulation has never been fully enforced, but in 2011 the FDA will begin conducting audits to ensure understanding of and compliance with Part 11 as an element of routine quality inspections. 3