Compliance checklistUpdated September 26, 2026

21 CFR Part 11: what it actually requires, checked against Capture

Part 11 sets rules for electronic records and signatures, not a badge a vendor can hand you. Here is each requirement in plain language and the specific control that meets it.

  • Field-level audit trail
  • Verified e-signatures
  • Role-based access

Free sandbox · No credit card · 21 CFR Part 11 aligned

Stage 1

Draft

Build and edit freely

Stage 2

Approved

Locked for live use

Stage 3

In the casebook

Only approved forms

Audit trail
  • SDV requirement changed on Systolic BP

    Data manager · Reason: critical safety value

  • Form approved: Vital Signs (VS) v2

    Study owner · Locked for live use

  • Answer changed: Weight 68.0 to 68.5 kg

    Site coordinator · Reason: transcription error

4

fields logged on every change: user, time, old value, new value

2

signature steps: participant sign, then countersign

3

access roles: researcher, site coordinator, admin

0

ways to edit the audit trail from the app

The regulation

Part 11 is a shared responsibility, not a checkbox

The FDA rule says electronic records and signatures can stand in for paper and ink, provided the system meets specific controls and the sponsor validates their own use of it. No agency certifies software as Part 11 compliant. What you can check is whether a system gives you the controls the rule actually asks for.

  • Audit trail on every record, not editable by users.
  • Electronic signatures uniquely linked to one signer.
  • Access limited by role, with individual logins.
  • Records available for review throughout the retention period.
Vital signs · Systolic blood pressure

Edit checks / auto-queries

2
Auto-query

Type

Range High

Operator

Greater than

Value

180

Priority: High

Auto-query

Type

Range Low

Operator

Less than

Value

80

Priority: Normal

Query raised automatically

Value 192 violates limit (180). Please verify.

The checklist

Six things to verify before you sign off

Walk any vendor, Capture included, through this list before you rely on their claim.

Audit trail on every record

Who changed it, when, the old value, the new value and the reason, on every field.

Audit trail cannot be edited or disabled

Recorded by the database, not the browser. No admin setting turns it off.

Electronic signatures tied to one signer

Email OTP verification plus a legal-binding acknowledgment before the signature is captured.

Role-based access control

Researcher, site coordinator and admin roles, each seeing only what their role needs.

Individual logins, not shared accounts

Every user signs in as themselves, so every action is attributable.

Documentation for your own validation

Available on Enterprise plans to support your Part 11 validation and UAT.

Signatures

A signature that proves who signed and what they signed

Part 11 signatures need to survive a challenge: prove the signer, prove the moment, and prove the document has not changed since. Capture verifies the participant by email one-time passcode, then requires an investigator or authorized staff member to countersign with a password before a consent is treated as final.

  • Each signature is hashed to the exact document content at signing time.
  • Countersignature requires password re-authentication and a legal meaning statement.
  • Optional witness co-signature and Legally Authorized Representative signing.
Read the full electronic signatures page

Blank eCRF · no subject data

Visit by form matrix

FormSCRD1W2W4W8EOS
DemographicsX
Vital signsXXXXXX
LaboratoryXXX
ECGXX

3. Was the ECG performed?

☐ Yes☐ No

If No, complete question 4.

Protocol CAP-001 · v1.0Page 3 of 24

The difference

A paper trail vs a Part 11 audit trail

Who changed a value
Whoever had the file open at the time
Logged automatically to the signed-in user
Why it changed
Rarely written down
Required reason for change on every edit
Original value
Overwritten and lost
Kept alongside the new value, permanently
Signature proof
A scanned wet-ink page
OTP-verified signature, hashed to the document

Check the audit trail for yourself

Build a free sandbox study, make a few edits, and look at the audit trail entries directly.

See the audit trail free

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Does 21 CFR Part 11 certify software?

No. Part 11 is an FDA regulation that sets requirements for electronic records and signatures. There is no FDA certification for software; a sponsor validates their own use of a system against Part 11 and their SOPs.

What is the minimum an audit trail needs to capture?

Who made the change, when, the value before and after, and the reason for the change, on every field, without the ability for a user to edit or clear that history.

Is Capture 21 CFR Part 11-aligned?

Yes. Capture provides a field-level audit trail that cannot be edited from the UI, electronic signatures verified by OTP and countersignature, and role-based access control. Documentation to support your own validation is available on Enterprise.

Do I still need to validate the system myself?

Yes. Part 11 compliance depends on how you configure and use a system, not only on the software. Most teams complete a lightweight validation and UAT pass even on a vendor-supplied platform.

What is the difference between Part 11 and ALCOA+?

Part 11 is an FDA regulation covering electronic records and signatures. ALCOA+ is a data-integrity framework used across GCP more broadly. A good audit trail and signature workflow tend to satisfy most of both at once.

Can I see the audit trail before committing to a plan?

Yes. The free sandbox includes full audit trail and e-signature functionality with sample data, no credit card required.

See the controls, not just the claim

Build a free sandbox study and check the audit trail and signature flow yourself.