FDA · 21 CFR Part 11 · Electronic Records
Part 11 exists so that an electronic record can be trusted like paper. The hard part is the audit trail — proving a record has not been altered. A trail your own system writes is only as trustworthy as that system. LedgerProof adds an independent, tamper-evident, cryptographically anchored layer: proof anyone can check that a record existed in exactly that form, at that time.
What Part 11 is. Title 21 of the Code of Federal Regulations, Part 11 — Electronic Records; Electronic Signatures — is the FDA rule that sets the criteria under which electronic records and electronic signatures are considered trustworthy, reliable, and generally equivalent to paper records and handwritten signatures. It took effect on 20 August 1997 and applies to the electronic records FDA-regulated companies keep under the agency's underlying “predicate” rules — across pharma, biotech, medical devices and more. Its controls live in three subparts: general provisions, electronic records, and electronic signatures.
Why the audit trail is the crux. Part 11's most consequential control, § 11.10(e), requires a secure, computer-generated, time-stamped audit trail that records who did what, and when, to a record — and that does not obscure earlier information. But an audit trail is only as credible as the system that produces it. To make it evidence a third party can rely on, it has to be independently checkable and tamper-evident. That is exactly what LedgerProof adds.
Four of Part 11's controls for closed systems bear directly on record integrity. Each is a place a cryptographically anchored receipt turns “trust our system” into “check it yourself.”
Part 11 asks for: Secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions which create, modify or delete records — without obscuring earlier information — retained and available for FDA review.
LedgerProof: Anchor a fingerprint of the record and its audit trail, so the trail itself is independently verifiable — tamper-evidence on top of the log your own system writes.
Part 11 asks for: Protect records so they can be accurately and readily retrieved throughout the entire records-retention period.
LedgerProof: Anchor each record so its integrity across the full retention period is provable years later, not merely asserted.
Part 11 asks for: Validate systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records.
LedgerProof: Anchor validation packages and change records as fixed, dated artifacts an assessor can independently check.
Part 11 asks for: Electronic signatures must be linked to their records so they cannot be excised, copied or otherwise transferred to falsify a record.
LedgerProof: Anchor the signed record so the signature-to-record binding is fixed and verifiable after the fact.
The centrepiece · § 11.10(e)
“Use of secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records. Record changes shall not obscure previously recorded information. Such audit trail documentation shall be retained … and shall be available for agency review and copying.”
A LedgerProof receipt fingerprints the record and its audit trail and anchors that fingerprint to the public chain. The trail stops being something an inspector has to take on trust from your system, and becomes something anyone can independently verify — tamper-evidence layered on top of your own controls, not a replacement for them.
Two things people often attach to Part 11 are actually FDA guidance, not the regulation. The 2003 guidance Part 11 — Scope and Application set a risk-based approach under which FDA exercises enforcement discretion for certain Part 11 clauses — but the record must still meet the underlying predicate rules, and Part 11 remains in effect. And ALCOA (Attributable, Legible, Contemporaneous, Original, Accurate) is a data-integrity expectation from FDA's guidance — notably the 2018 Data Integrity and Compliance With Drug CGMP Q&A — not text in Part 11 itself. Independently verifiable evidence supports both: it makes a record’s integrity checkable no matter which rule or guidance is being applied.
The authoritative material, ranked by how cleanly it can be fingerprinted and cryptographically anchored. Every URL was verified.
A Anchor directly — a fixed CFR/guidance PDF at a permanent URL. B Anchor a snapshot — a living eCFR or FDA page that changes over time.
The FDA issued Part 11 — Electronic Records; Electronic Signatures — and it took effect on 20 August 1997. It remains in effect today.
No tool can. LedgerProof produces independently verifiable evidence that a record — or its audit trail — existed, unaltered, at a specific time. Whether a system satisfies Part 11 is a determination your quality unit, auditor, or the FDA makes.
No. ALCOA (Attributable, Legible, Contemporaneous, Original, Accurate) comes from FDA's data-integrity guidance — notably the 2018 CGMP Questions & Answers — not from the Part 11 regulation text. Part 11 sets the electronic-records and audit-trail rules; ALCOA is how FDA describes data-integrity expectations more broadly.
No. LedgerProof is hash-only: it anchors the SHA-256 fingerprint of a record, never the record itself. The document never leaves your validated systems, which keeps the approach confidentiality-safe.
Your system's audit trail is only as trustworthy as the system that writes it. A LedgerProof receipt adds an independent, tamper-evident layer: anyone can confirm the record and its trail existed in that exact form at that time, without trusting your system or any vendor.
LedgerProof produces independently verifiable evidence, not a verdict — it does not make any system “Part 11 compliant,” and it is not affiliated with or endorsed by the FDA. Whether anchored evidence satisfies a given requirement is a determination your quality unit, auditor, or the agency makes. Authoritative text always remains the version in the eCFR / Code of Federal Regulations. Proofs are tamper-evident, not tamper-proof. Not legal advice.