Why do we Need it
•Astandardrequiredtohandleandmaintaintheelectronicrecords
generatedinindustrymovingtowardstheAutomation.
•Toreducetheriskofhumanerrorssignificantly.
•Decreasingtime-to-marketforpharmaceuticalproducts.
5
ImportanceofPart11
6
• 21 CFR Part 11 regulations set forth the criteria under which the FDA
considers:
1. electronic records,
2. electronic signatures
3. handwritten signatures executed to electronic records
to be trustworthy, reliable, and generally equivalent to paper records
and handwritten signatures executed on paper
•Part11wasenactedtoensuretheauthenticity,integrity,and,when
appropriate,theconfidentialityofelectronicrecords,andtoensure
thatthesignercannotreadilyrepudiatethesignedrecordasnot
genuine
Presented By: Arvind Kumar Srivastava Manager –Qualification –Validation
BenefitsofPart11
6
TherearemanyreasonstopursuePart11,notjustbecauseit’sa
regulation.BelowaresomeofthebenefitsofbeingFDA21CFR11
compliant;
➢Patient safety
➢Product quality
➢Protection and retrieval of electronic records
➢Operational consistency
➢Improve productivity and efficiency through automation
➢Minimize or eliminate management of paper documentation
➢Enable faster data-related searches
➢Enable trending
➢Electronic submissions to the FDA
Presented By: Arvind Kumar Srivastava Manager –Qualification –Validation
Electronic Data Lifecycle
14
Integrity , Accuracy ,
Confidentiality , Availability ,
Traceability
Its manage by the approved
SOP
Applicability of Part 11
•21CFRPart11isaU.S.federalregulationspecifyingFDAguidelinesforelectronic
RecordsandSignatures.
•Theregulationappliestopharmaceuticalcompaniesandmedicaldevice
manufacturers,anditrequiresthecompaniestoimplementcontrolsthatensurethe
integrityoftheirdocuments.
15
Presented By: Arvind Kumar Srivastava Manager –Qualification –Validation
Applicability of Part 11
15
•Appliesto:
AllGxPRecordsinthe
electronicformthatare
created, modified,
maintained, archived,
retrievedortransmitted.
•Doesnotapplyto:
Anypaperrecordseveniftheyaresent
electronically(forexample,ascanofpaperrecords
transmittedbyemailorFax).Howeverifafileina
pdfformatgeneratedoutofa21CFRPart11
compliantsystemistransmittedbyemailis
exception.
Open System & Closed System
➢21CFRPart11isasetofregulationsissuedbytheUSFoodandDrug
Administration(FDA)thatgovernstheuseofelectronicrecordsandsignaturesin
regulatedindustries.Itappliestoorganizationsdealingwithhealthcare,
pharmaceuticals,andmedicaldevices.Thegoalof21CFRPart11istoprotect
thesecurityandintegrityofdatausedintheseindustries.
➢Opensystemsandclosedsystemsaretwodifferentapproachestomanaging
dataandrecordkeeping.
➢Anopensystemisonethatallowsformultipleuserstoaccessandmodifydata
onasingleplatform.Aclosedsystemrestrictsaccesstotheplatformorcontrols
whocanmodifythedata.
Presented By: Arvind Kumar Srivastava Manager –Qualification –Validation
Open System & Closed System
Open System
❖Anopensystemisacomputerizedsystemthatallowsunrestrictedaccesstoits
dataandfeatures.
❖Itcouldbeaserver,client-server,web-basedorcustom-designedsystem.Open
systemsarebuilttoprovideageneralplatformwhereuserscaninteractwith
differenttypesofdata,applications,anddevices.
Some examples of open systems include Windows, MacOS, Android, iOS, and Linux.
Each of these operating systems provides users with the ability to install and use
different applications that are compatible with the system.
Presented By: Arvind Kumar Srivastava Manager –Qualification –Validation
Open System & Closed System
Closed System
❖Aclosedsystemisatypeofcomputersystemwhereaccesstothesystemislimitedandrestricting.
❖Ithascompletecontroloverwhoisallowedtoview,access,ormanipulatethedata.
❖Toaccessthesystem,usersarerequiredtoauthenticatethemselveswithauserIDandpassword,andin
somecases,biometricauthenticationsuchasfingerprintscanning.
❖Theclosedsystem’smainpurposeistoprotectthedatafromunauthorisedaccessormanipulation.
❖Ithasadvancedsecurityfeaturesthatcanpreventhackersorintrudersfromgainingaccesstothesystem.
❖Allsoftwareinstalledonthesystemmustbeapprovedbytheadministratorsandanynewapplications
mustbeapprovedbeforetheycanbeusedonthesystem.
ExamplesofClosedSystems
➢Some systems are typically closed, as they are designed to manage specific business processes within a
company and are not intended to be accessible or modifiable by external parties.
➢Examples of closed systems include Document Management Systems (DMS) and Quality Management
System (QMS) software solutions.
➢DMS can help companies manage electronic documents, such as standard operating procedures, batch
records, and analytical test reports.
➢QMS solutions help companies manage quality-related activities such as deviation or nonconformance's,
change controls, audits, suppliers, employee training, CAPA workflows, and so on.
➢Here are some other examples of typically closed systems:Enterprise Resource Planning (ERP),
Laboratory information management systems (LIMS), Electronic batch record (EBR) systems
Relation Between 21 CFR Part 11
and EU Annex 11?
•21CFR(CodeofFederalRegulations)Part11hasdefinedbytheUSFDA
regulationsthatsetforththecriteriaappliestoelectronicrecordsand
electronicsignaturesthatpersonscreate,modify,maintain,archive,
retrieve,ortransmitunderanyrecordsorsignaturerequirementsetforth
intheFederalFood,Drug,andCosmeticAct,thePublicHealthService
Act,oranyFDAregulation
•Annex11ispartoftheEuropeanGMPGuidelinesanddefinestheterms
ofreferenceforcomputerizedsystemssoftwareusedbyorganizationsin
thepharmaceuticalindustry.
Presented By: Arvind Kumar Srivastava Manager –Qualification –Validation
21 CFR Part 11 vs Annexure 11
EU GMP Annexure 11FDA 21 CFR Part 11
19
S I M I L A R I T I E S
21CFRpart11 ANNEXURE11
Validation(11.10(a)) Validation(Principle)
PersonnelTraining,Qualification (11.10(i))Personnel(General)
Documentation(11.10(k) (1)(2)) Changecontrol, deviations(Project(4.2))
DeviceChecks (11.10(h)) Data transfer validation(Project(4.8))
SecurityandAccessible(11.10(c)(d)(e)(g))Securedandaccessible(Operation,7.1)
Audit Trails(11.10(e)) AuditTrails (9)
AccurateandCompletecopies(11.10(b) Printouts(8.1)
SignatureManifestation(11.50) ElectronicSignature(14 (b))
Certifyequivalenttohandwritten (11.100(c))Sameashand-written(14(a))
Basedonbiometric,notbiometric
(11.2..(a)(b), 11.300(e))
Security,physical/logical(12.1)
Periodicallychecked (11.300(b)) PeriodicEvaluation(11.)
Periodicchecking,revisionorrecalled
(11.300(b)(e))
Accessauthorizationrecording(12.3)
Operational SystemChecks(11.10(f)) Data(5)
Protection ofrecords(11.10(c)) Datastorage(7)
20
G A P S
21CFRpart11 ANNEXURE11
Risk assessmentNotcovered Risk assessmentisintegralPart
SecurityforopenandclosedsystemswithExtra
securitymeasuresforOpensystemlike Encryption
SecuritycontrolsbasedonCriticalityof
Computerizedsystems
Useraccountabilityforactionsinitiatedundere-
signature
UseraccountabilityisnotinScope
Uniqueness/notreusedofElectronicsignature NotinscopeofAnnexure11
ControlsforSupplierandServiceProviders, Formal
agreements,supplierauditsarenotin scopeof 21
CFRPart11
InScopeunderGeneralsection
Systeminventory,Userrequirement specification,
Qualitymanagementsystemnotin Scope.
Systeminventory,Userrequirement
specification,Qualitymanagementsystem
coversunderProjectPhase Validation
Backupnotinscope Backup–anintegralpart
Batch release outof scope Batchrelease inScope
IncidentManagementOutofscope IncidentManagementinscope
Business Continuityplanoutofscope Business Continuityplaninscope
21
✓Is Electronic Signature and hand written signature are linked?
✓Are users of the computerized systems are trained for the execution
of activities assigned?
✓Is there Change management system for up gradation/modifications in system?
29
Assess your Compliance
Presented By: Arvind Kumar Srivastava Manager –Qualification –Validation