Compliance explainer · EU and USUpdated October 8, 2026

Annex 11 vs 21 CFR Part 11: where they overlap and where they differ

Part 11 is a US regulation about electronic records and signatures. Annex 11 is an EU GMP guideline about the whole life of a computerised system. They share most of their technical controls, but they are built differently, and the gaps between them are where audits find problems.

  • Side-by-side table
  • One control set for both
  • Not legal advice

Free sandbox · No credit card · 21 CFR Part 11 aligned

Annex 11 vs Part 11 at a glance
EU Annex 1121 CFR Part 11
Legal formGMP guidelineUS regulation
Audit trail
Reason for changePredicate rules
E-signature controls
Risk management clause
Supplier oversight clause
Periodic review clause
Signature letter to regulator
Partial: Part 11 has no risk clause, but FDA's 2003 guidance applies a risk-based approach.

Key differences in five lines

  • Different legal shape. 21 CFR Part 11 is a binding US regulation (final rule 1997) with FDA guidance on how it is applied. Annex 11 is part of the EU GMP guidelines (2011 revision), and the EU applies its own GCP guideline to clinical trial systems.
  • Different focus. Part 11 centres on records and signatures. Annex 11 covers the system lifecycle: risk, suppliers, validation, operation, periodic evaluation and retirement.
  • Shared core. Both expect validation, secure audit trails, limited access and signatures that are linked to their records.
  • Different extras. Part 11 asks signers to certify their e-signatures to FDA and spells out signature components. Annex 11 adds supplier agreements, periodic evaluation, incident management and business continuity.
  • One system can meet both if you build to the stricter requirement on each topic. This page is general information, not legal advice.

Side by side

Annex 11 vs 21 CFR Part 11, topic by topic

Annex 11 references are to the 2011 clauses; Part 11 references are to sections of 21 CFR Part 11.

TopicEU Annex 11 (2011)21 CFR Part 11What to do for both
ScopeComputerised systems used in GMP-regulated activitiesElectronic records required by predicate rules or submitted to FDA, and their signaturesList every system and record in scope for each regime
Legal statusEU GMP guideline, also adopted by PIC/S; trials use the EMA GCP guidelineBinding federal regulation, with non-binding FDA guidanceTreat both as inspection standards
ValidationClause 4: lifecycle validation based on risk, with user requirements11.10(a): validation for accuracy, reliability and consistent performanceOne risk-based validation package per intended use
Audit trailClause 9: risk-based; reason for change or deletion documented; regularly reviewed11.10(e): secure, computer-generated, time-stamped; must not obscure earlier valuesField-level trail with reason for change, plus scheduled review
E-signaturesClause 14: same impact as handwritten, permanently linked, time and date11.50, 11.70, 11.100 to 11.300: name, date, time, meaning; linked; two identification componentsMeaning, re-authentication and linking on every signature
Risk managementClause 1: applied across the whole lifecycleNot in the rule; FDA's 2003 guidance asks for a risk-based approachDocument a risk assessment that drives validation depth
Suppliers and service providersClause 3: formal agreements; supplier assessment or audit based on riskNot in the rule; FDA's 2024 Q&A guidance covers IT service providersSupplier assessment plus a written agreement
Periodic reviewClause 11: periodic evaluation to confirm a valid stateNo explicit requirementSchedule and document a review
Data integrityClauses 5 to 7 and 12: accuracy checks, secure storage, backups, security11.10(b) to (d), (g), (h): readable copies, record protection, access and authority checksEdit checks, access control and tested backups
OtherIncident management, business continuity, archiving, printoutsOpen-system controls (11.30); signature certification letter to FDAAdd both sets to your SOPs

Overlap

Where they agree

Strip away the legal form and the two texts want the same core evidence. The system is validated for what you use it for. Every creation, change and deletion of regulated data leaves a computer-generated, time-stamped trail that shows who did it and does not hide the earlier value. Access is limited to authorised individuals with their own accounts. Signatures are tied to one person and to the exact record, and they show when they were applied. Records stay readable and retrievable for as long as you must keep them. If your EDC does these things and your procedures prove it, you have covered most of both documents.

Differences

Where they differ, and why it matters at audit

The differences are mostly about how far each text reaches beyond the record itself. They are also where a system built for one market tends to fall short in the other.

Reason for change

Annex 11 asks for the reason when GMP-relevant data is changed or deleted. Part 11's audit trail section does not mention reasons; for trial data, the expectation usually comes from GCP and the predicate rules instead. Capture the reason on every edit to clinical data and you satisfy both.

Signature mechanics

Part 11 is more prescriptive about signatures. A signature must show the printed name, date and time, and meaning. Non-biometric signatures need at least two distinct identification components, such as an ID and a password. Organisations must also certify to FDA that their electronic signatures are the legally binding equivalent of handwritten ones. Annex 11 states the outcome (same impact as a handwritten signature, permanently linked, dated) without prescribing components or a letter.

The system lifecycle

Annex 11 reaches into supplier agreements, periodic evaluation, incident management, business continuity and archiving. Part 11 says little about these, although FDA guidance and the predicate rules fill some of the gap. A US-only quality system often lacks a periodic review procedure and a formal supplier agreement, and EU inspectors notice.

What is changing

A draft revision of Annex 11 went out for consultation from 7 July to 7 October 2025, with more detail on access management, audit trail review, security and cloud providers. As of 8 October 2026 it has not replaced the 2011 text. Part 11 itself has not changed since 1997; the October 2024 FDA Q&A guidance is the most recent clinical update.

See one control set working for both

Edit a value with a reason, sign a form and export the audit trail in the free sandbox. No credit card required.

Test both control sets free

Dual compliance

How one system can satisfy both

Build to the stricter requirement on each topic, then write procedures that cover the gaps neither piece of software can.

  1. 1

    Inventory systems and records

    List each computerised system, the records it holds and whether they fall under FDA predicate rules, EU GCP, EU GMP or all three.

  2. 2

    Write one risk assessment

    Use Annex 11's lifecycle risk approach. It also gives you the risk-based rationale FDA's 2003 guidance expects.

  3. 3

    Set the audit trail to the stricter rule

    Field-level, append-only, time-stamped, with the reason for every change. Add a documented review frequency.

  4. 4

    Set signatures to the stricter rule

    Name, date, time and meaning on every signature, re-authentication at signing, and linking that survives export. File the Part 11 certification letter with FDA.

  5. 5

    Assess and contract suppliers

    Run a supplier assessment and sign an agreement that names responsibilities, change notification and data location.

  6. 6

    Validate once, for intended use

    One validation package that cites both texts, executed against your configured study.

  7. 7

    Add the Annex 11 extras to SOPs

    Periodic evaluation, incident management, business continuity and archiving, with owners and frequencies.

Where Capture fits

The controls Capture provides for both

Capture provides 21 CFR Part 11-aligned controls and maps them to Annex 11 the same way. The audit trail is field-level and append-only, records old value, new value, user, time and reason, and is hash-chained per study. Staff signatures re-authenticate with the password and store a meaning statement; eConsent adds an emailed one-time code for the participant and a countersignature, with each signature hashed to the document content. Access follows study roles with row-level security, and studies can be hosted in the EU (Frankfurt) or the USA (N. Virginia). Enterprise customers get documentation to support validation and UAT. Supplier agreements, the FDA certification letter, periodic review and your SOPs stay with you, as the computer system validation guide explains.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

What is the main difference between Annex 11 and 21 CFR Part 11?

Part 11 is a binding US regulation focused on electronic records and signatures. Annex 11 is an EU GMP guideline that covers the whole lifecycle of a computerised system, including risk management, suppliers, periodic evaluation and business continuity.

If my system meets Part 11, does it meet Annex 11?

Mostly on the technical controls, not on the lifecycle. You usually need to add a documented reason for change, supplier agreements, periodic evaluation and incident and continuity procedures.

Does Annex 11 apply to clinical trials?

Annex 11 is a GMP text. For clinical trial systems, EU GCP inspectors apply the EMA guideline on computerised systems and electronic data in clinical trials (2023), which covers similar ground. Many sponsors map their systems against both.

Does Annex 11 require a letter to the regulator like Part 11?

No. The certification letter to FDA that electronic signatures are legally binding is a Part 11 requirement (11.100(c)). Annex 11 has no equivalent.

Has Annex 11 been revised?

A draft revision was consulted on from 7 July to 7 October 2025. As of 8 October 2026 the January 2011 version is still the one listed in force by the European Commission.

Is Capture compliant with both?

Compliance with either is shared between the software and the sponsor. Capture provides the controls both texts ask for: audit trail with reason for change, re-authenticated signatures with meaning, role-based access and EU or US hosting. You validate and write the procedures.

Test the controls both regulators ask for

Free sandbox with every feature, including audit trail and e-signatures. No credit card, and you pay only when you go live.

Test both control sets free