Part 11 is a US regulation about electronic records and signatures. Annex 11 is an EU GMP guideline about the whole life of a computerised system. They share most of their technical controls, but they are built differently, and the gaps between them are where audits find problems.
Free sandbox · No credit card · 21 CFR Part 11 aligned
| EU Annex 11 | 21 CFR Part 11 | |
|---|---|---|
| Legal form | GMP guideline | US regulation |
| Audit trail | ||
| Reason for change | Predicate rules | |
| E-signature controls | ||
| Risk management clause | ||
| Supplier oversight clause | ||
| Periodic review clause | ||
| Signature letter to regulator |
Key differences in five lines
Background
21 CFR Part 11 is part of the US Code of Federal Regulations. FDA published it as a final rule in 1997. It applies to electronic records that FDA's predicate rules require you to keep, and to records submitted to the agency. Two guidance documents shape how it is applied. The 2003 "Scope and Application" guidance narrowed FDA's interpretation and announced enforcement discretion for some requirements, including validation, audit trails and record copying, while asking firms to take a risk-based approach. For trials, FDA's final guidance Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers (October 2024) replaced the 2007 computerised systems guidance and covers IT service providers and digital health technologies. The requirement-by-requirement view is in the 21 CFR Part 11 compliance checklist.
Annex 11 is in EudraLex Volume 4, the EU GMP guidelines, with an equivalent text in the PIC/S GMP guide. The current revision dates from January 2011. It applies to computerised systems used in GMP-regulated activities. For clinical trial data, the EU equivalent in scope is the EMA guideline on computerised systems and electronic data in clinical trials (2023), which covers eCRF, ePRO, IRT and cloud services and is what GCP inspectors work from. In practice sponsors use Annex 11 as a shared vocabulary across GMP and GCP, which is why the comparison comes up so often. The product view is on our Annex 11 compliant EDC page.
Side by side
Annex 11 references are to the 2011 clauses; Part 11 references are to sections of 21 CFR Part 11.
| Topic | EU Annex 11 (2011) | 21 CFR Part 11 | What to do for both |
|---|---|---|---|
| Scope | Computerised systems used in GMP-regulated activities | Electronic records required by predicate rules or submitted to FDA, and their signatures | List every system and record in scope for each regime |
| Legal status | EU GMP guideline, also adopted by PIC/S; trials use the EMA GCP guideline | Binding federal regulation, with non-binding FDA guidance | Treat both as inspection standards |
| Validation | Clause 4: lifecycle validation based on risk, with user requirements | 11.10(a): validation for accuracy, reliability and consistent performance | One risk-based validation package per intended use |
| Audit trail | Clause 9: risk-based; reason for change or deletion documented; regularly reviewed | 11.10(e): secure, computer-generated, time-stamped; must not obscure earlier values | Field-level trail with reason for change, plus scheduled review |
| E-signatures | Clause 14: same impact as handwritten, permanently linked, time and date | 11.50, 11.70, 11.100 to 11.300: name, date, time, meaning; linked; two identification components | Meaning, re-authentication and linking on every signature |
| Risk management | Clause 1: applied across the whole lifecycle | Not in the rule; FDA's 2003 guidance asks for a risk-based approach | Document a risk assessment that drives validation depth |
| Suppliers and service providers | Clause 3: formal agreements; supplier assessment or audit based on risk | Not in the rule; FDA's 2024 Q&A guidance covers IT service providers | Supplier assessment plus a written agreement |
| Periodic review | Clause 11: periodic evaluation to confirm a valid state | No explicit requirement | Schedule and document a review |
| Data integrity | Clauses 5 to 7 and 12: accuracy checks, secure storage, backups, security | 11.10(b) to (d), (g), (h): readable copies, record protection, access and authority checks | Edit checks, access control and tested backups |
| Other | Incident management, business continuity, archiving, printouts | Open-system controls (11.30); signature certification letter to FDA | Add both sets to your SOPs |
Overlap
Strip away the legal form and the two texts want the same core evidence. The system is validated for what you use it for. Every creation, change and deletion of regulated data leaves a computer-generated, time-stamped trail that shows who did it and does not hide the earlier value. Access is limited to authorised individuals with their own accounts. Signatures are tied to one person and to the exact record, and they show when they were applied. Records stay readable and retrievable for as long as you must keep them. If your EDC does these things and your procedures prove it, you have covered most of both documents.
Differences
The differences are mostly about how far each text reaches beyond the record itself. They are also where a system built for one market tends to fall short in the other.
Annex 11 asks for the reason when GMP-relevant data is changed or deleted. Part 11's audit trail section does not mention reasons; for trial data, the expectation usually comes from GCP and the predicate rules instead. Capture the reason on every edit to clinical data and you satisfy both.
Part 11 is more prescriptive about signatures. A signature must show the printed name, date and time, and meaning. Non-biometric signatures need at least two distinct identification components, such as an ID and a password. Organisations must also certify to FDA that their electronic signatures are the legally binding equivalent of handwritten ones. Annex 11 states the outcome (same impact as a handwritten signature, permanently linked, dated) without prescribing components or a letter.
Annex 11 reaches into supplier agreements, periodic evaluation, incident management, business continuity and archiving. Part 11 says little about these, although FDA guidance and the predicate rules fill some of the gap. A US-only quality system often lacks a periodic review procedure and a formal supplier agreement, and EU inspectors notice.
A draft revision of Annex 11 went out for consultation from 7 July to 7 October 2025, with more detail on access management, audit trail review, security and cloud providers. As of 8 October 2026 it has not replaced the 2011 text. Part 11 itself has not changed since 1997; the October 2024 FDA Q&A guidance is the most recent clinical update.
Edit a value with a reason, sign a form and export the audit trail in the free sandbox. No credit card required.
Dual compliance
Build to the stricter requirement on each topic, then write procedures that cover the gaps neither piece of software can.
List each computerised system, the records it holds and whether they fall under FDA predicate rules, EU GCP, EU GMP or all three.
Use Annex 11's lifecycle risk approach. It also gives you the risk-based rationale FDA's 2003 guidance expects.
Field-level, append-only, time-stamped, with the reason for every change. Add a documented review frequency.
Name, date, time and meaning on every signature, re-authentication at signing, and linking that survives export. File the Part 11 certification letter with FDA.
Run a supplier assessment and sign an agreement that names responsibilities, change notification and data location.
One validation package that cites both texts, executed against your configured study.
Periodic evaluation, incident management, business continuity and archiving, with owners and frequencies.
Where Capture fits
Capture provides 21 CFR Part 11-aligned controls and maps them to Annex 11 the same way. The audit trail is field-level and append-only, records old value, new value, user, time and reason, and is hash-chained per study. Staff signatures re-authenticate with the password and store a meaning statement; eConsent adds an emailed one-time code for the participant and a countersignature, with each signature hashed to the document content. Access follows study roles with row-level security, and studies can be hosted in the EU (Frankfurt) or the USA (N. Virginia). Enterprise customers get documentation to support validation and UAT. Supplier agreements, the FDA certification letter, periodic review and your SOPs stay with you, as the computer system validation guide explains.
Part 11 is a binding US regulation focused on electronic records and signatures. Annex 11 is an EU GMP guideline that covers the whole lifecycle of a computerised system, including risk management, suppliers, periodic evaluation and business continuity.
Mostly on the technical controls, not on the lifecycle. You usually need to add a documented reason for change, supplier agreements, periodic evaluation and incident and continuity procedures.
Annex 11 is a GMP text. For clinical trial systems, EU GCP inspectors apply the EMA guideline on computerised systems and electronic data in clinical trials (2023), which covers similar ground. Many sponsors map their systems against both.
No. The certification letter to FDA that electronic signatures are legally binding is a Part 11 requirement (11.100(c)). Annex 11 has no equivalent.
A draft revision was consulted on from 7 July to 7 October 2025. As of 8 October 2026 the January 2011 version is still the one listed in force by the European Commission.
Compliance with either is shared between the software and the sponsor. Capture provides the controls both texts ask for: audit trail with reason for change, re-authenticated signatures with meaning, role-based access and EU or US hosting. You validate and write the procedures.
Keep exploring
Annex 11 compliant EDC
Clause-by-clause mapping for an EDC.
21 CFR Part 11 compliance checklist
Each Part 11 requirement in plain language.
EMA computerised systems guideline
The EU GCP text for trial systems.
Computer system validation
One validation package for both regimes.
Electronic signatures
How signatures are verified and linked.
Free sandbox with every feature, including audit trail and e-signatures. No credit card, and you pay only when you go live.