Start Free Trial
Home/Regulations/FDA 21 CFR Part 11 — Electronic Records, Electronic Signatures — Regulatory Reference
Regulatory Reference
Healthcare Federal (US) high

FDA 21 CFR Part 11 — Electronic Records, Electronic Signatures — Regulatory Reference

Electronic records integrity and signatures — tamper-evident audit chain maps directly to Part 11 audit trail requirements.

Key Provisions
  • §11.10 — controls for closed systems (validation, audit trails, access)
  • §11.30 — controls for open systems
  • §11.50 — signature manifestations
  • §11.70 — signature/record linking
How AutoPIL Enforces It
  • Hash-linked audit chain implements §11.10(e) secure, computer-generated, time-stamped audit trails
  • Agent registry binds the AI agent identity to each electronic record action
  • Tamper-evident chain prevents §11.10(e) 'obscuring previously recorded information'
Audit LogPolicy EngineSensitivity LabelsAgent RegistryLineage
AutoPIL Policy IDs
HC-21CFR11-10E-001Secure Time-Stamped Audit Trail for AI Records
HC-21CFR11-70-001Signature-to-Record Linking via Hash Chain
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What does FDA 21 CFR Part 11 require for AI agent systems handling electronic records?
FDA 21 CFR Part 11 requires that electronic records be created, modified, maintained, and transmitted under controls that ensure their integrity, authenticity, and reliability. For AI agents, this means every action the agent takes on an electronic record — read, retrieve, transform — must generate a secure, computer-generated, time-stamped audit trail under §11.10(e). The agent identity must be traceable to each action, and previously recorded information must not be obscured or altered without detection. Organizations deploying AI agents in regulated workflows must validate those systems and demonstrate that the audit trail is tamper-evident and attributable to a specific, known actor.
When does 21 CFR Part 11 apply to AI deployments in life sciences and pharmaceutical organizations?
Part 11 applies when an AI agent creates, modifies, maintains, archives, retrieves, or transmits electronic records that are required by FDA predicate rules — such as cGMP (21 CFR Parts 210–211), clinical trial regulations (21 CFR Part 312), or device regulations (21 CFR Part 820). If your AI agent queries a validated data system, extracts study data, or generates outputs that feed into submission-ready records, Part 11 controls apply. FDA's 2003 guidance on scope and application narrows enforcement focus to records that are relied upon to demonstrate compliance, but that covers most AI use cases in drug development, clinical operations, and quality systems.
What are the audit trail requirements under §11.10(e) and how do they apply to AI agents?
Section 11.10(e) requires audit trails that are computer-generated, independently record the date and time of operator entries and actions, and capture who made a change, what was changed, and when — without the ability to overwrite or obscure the prior record. For AI agents, this means every retrieval and write operation must be logged with agent identity, timestamp, action type, and the record affected. The challenge is that AI agents often act faster and more frequently than humans, making manual audit trail management impractical. An automated, hash-linked audit chain that captures each agent action at the access layer satisfies §11.10(e) without requiring post-hoc reconstruction from application logs.
How does AutoPIL help with FDA 21 CFR Part 11 compliance for AI agents?
AutoPIL intercepts every AI agent request before data enters the agent's context window and writes an immutable, hash-linked audit record of the decision — source accessed, agent identity, policy applied, sensitivity level, timestamp, and outcome. This directly satisfies §11.10(e): the chain is computer-generated, time-stamped, and tamper-evident because each record is cryptographically linked to the prior one. AutoPIL's agent registry binds a specific, registered agent identity to every audit event, satisfying the attributability requirement. Policy IDs HC-21CFR11-10E-001 and HC-21CFR11-70-001 map to the secure audit trail and signature-to-record linking requirements in §11.10(e) and §11.70 respectively.
What are the FDA enforcement risks for organizations using AI agents in Part 11-regulated workflows without proper audit controls?
FDA inspectors reviewing electronic records systems under Part 11 look for audit trail gaps, uncontrolled system access, and the inability to attribute record changes to a specific individual or system. AI agents that access regulated data without generating attributable, tamper-evident audit records create Form 483 observations and, in repeat or serious cases, Warning Letters. In clinical trial contexts, data integrity findings can result in rejection of submission data. FDA has issued guidance reaffirming that the predicate rule controls — not Part 11 itself — drive the compliance obligation, but the audit trail requirements in §11.10 are not discretionary. Organizations that cannot demonstrate end-to-end traceability of AI agent actions on regulated records face material inspection risk.
Covered Industries

FDA 21 CFR Part 11 applies to any organization operating under FDA jurisdiction that uses electronic records and electronic signatures in place of paper records — including pharmaceutical manufacturers, medical device companies, clinical research organizations, and their technology vendors. As AI agents are deployed into regulated workflows, every agent action on a covered record becomes subject to the same audit trail and attribution controls that apply to human users.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries