Veja como o Actiz LIMS pode transformar seu laboratório

Peça uma demo

Commitment to Quality: A Guide to FDA 21 CFR Part 11 Compliance

Ensure compliance with FDA 21 CFR Part 11: data integrity and quality in the life sciences industry. Learn more on the Actiz blog!

FDA 21 CFR Part 11, often referred to simply as Part 11, is a regulation issued by the U.S. Food and Drug Administration (FDA) that establishes the criteria for electronic records and electronic signatures in the pharmaceutical, biotechnology, and medical device industries. In Brazil, these rules were formally adopted when ANVISA (the Brazilian Health Regulatory Agency) published RDC 17/2010; the current version in force is RDC No. 658/2022.

The regulation was introduced to ensure the security, integrity, and reliability of electronic records and signatures across regulated industries. It helps maintain data accuracy and prevent fraud, and its purpose is to regulate computerized automation systems, making it a fundamental regulatory milestone across the global industry.

In this article, we’ll explore the main requirements of this regulation and discuss its importance to the industry, along with its implications.

The Importance of FDA 21 CFR Part 11 Compliance

Compliance with FDA 21 CFR Part 11 plays a critical role in maintaining the integrity and quality of industrial and laboratory processes. Ensuring product safety and reliability is essential, and rigorous adherence to this regulation takes center stage in that context.

Also read: External audits: how a LIMS can help with preparation and compliance

Validation

System validation emerges as one of the most crucial aspects in the context of FDA 21 CFR Part 11 compliance. Computerized System Validation provides documented proof that the computerized systems used in industrial production properly perform their intended functions and help ensure the traceability of produced batches. Below are the items that should be verified in a system:

1.    System Validation: It is essential to ensure that the system is properly validated to guarantee its effectiveness and compliance.

2.    Electronic Signature Policy: Verify the existence of a policy that assigns full accountability to individuals for their electronic signatures.

1.    Record Storage and Retrieval: Ensuring that records remain readily retrievable throughout the entire retention period.

3.    Data Security: It must be ensured that data is properly encrypted, preserving its integrity.

4.    Data Source Verification: When necessary, it is important to verify the validity of the source of data or instructions received.

5.    Access Control: Ensuring that only authorized individuals have access to the system and to electronic signatures is essential.

6.    Documented Training: A training record must be maintained for system users, developers, and the IT support team.

Audit Trail

The audit trail plays a fundamental role in monitoring actions performed within the system, creating a history of activities and identifying unauthorized events. This practice reinforces data security and system reliability. It is imperative to ensure that systems meet the following requirements:

1.    Secure Audit Trail: The system must maintain a secure audit trail that records the date and time of entries and actions performed by operators.

2.    Change Tracking: After a change is made to an electronic record, it is essential that the prior information be preserved.

3.    Audit Trail Access: Ensure that the audit trail is available for review and copying by the regulatory body.

4.    Electronic Signature Details: Electronic signatures must contain specific information, including the signer’s name, date, time, and the purpose of the signature.

5.    Signature Protection: Ensure that signatures are securely linked to records in order to prevent forgery.

6.    Change Control Procedure: A formal change control procedure must be maintained for system documentation.

7.    Unique Identification: Electronic signatures must be unique to each individual and must never be reused.

8.    Identity Verification: Before an electronic signature is assigned, it is important to properly verify the identity of the signer.

9.    Biometric Security: If biometric signatures are in use, it is necessary to ensure they are unique to their true owner.

Meeting these requirements ensures not only compliance with FDA 21 CFR Part 11, but also the maintenance of system integrity and security, fostering trust in electronic operations and records.

Record Copies

The ability to produce accurate and complete copies of electronic records plays a fundamental role both in regulatory inspections and in maintaining continuous operations, even in the face of potential failures in the primary system. Continuing the analysis, it is essential to validate that the system is capable of generating:

  1. Accurate Printed Copies: It is necessary to ensure that the system is capable of creating accurate copies of electronic records in printed format.
  2. Electronic Formats: Verify that the system has the capability to generate complete copies in electronic formats, such as PDF, XML, or SGML.
  3. Access to Electronic Copies: Ensure that electronic copies of records are readily accessible for inspection by the regulatory body.

By meeting these requirements, organizations ensure not only compliance with regulations, but also the preservation of the ability to maintain intact and accessible records regardless of circumstances, promoting the reliability of operations and regulatory audits.

See also: LIMS: What is it and how does it work?

Record Retention

Maintaining rigorous control over IDs and passwords is an essential pillar for ensuring system security and the integrity of electronic records. In this context, it is fundamental to validate that systems are capable of performing the following actions:

  1. ID and Password Control: The system must maintain rigorous controls to ensure that each identification code and password is unique.
  2. Password Expiration: Ensure that passwords expire periodically and undergo regular review.
  3. Reporting of Unauthorized Attempts: A procedure must be established to immediately report unauthorized attempts to management.
  4. Token and Card Testing: Perform initial and periodic testing on tokens and cards to ensure their effectiveness.
  5. Deactivation of IDs and Passwords: Procedures must be in place for the electronic deactivation of identification codes or passwords that have been compromised or lost.
  6. Recall of Codes and Passwords: Implement procedures for recalling identification codes and passwords when an individual leaves the company or is transferred to another role.
  7. Loss Management Procedure: Have a procedure in place to handle situations involving lost or stolen devices.
  8. Integrity Testing: Regularly verify the integrity of records to detect possible unauthorized alterations.

Compliance with these procedures not only strengthens system security and the integrity of electronic records, but also meets essential regulatory requirements, ensuring reliable and secure operations.

Actiz: Your Solution for FDA 21 CFR Part 11 Compliance

Using a system that is regulated in accordance with ANVISA’s requirements and that also follows FDA CFR 21 Part 11 is necessary, as it ensures that your entire process follows the applicable rules and is unlikely to produce errors.

In this context, Actiz is a LIMS that offers a robust platform for data and documentation management, ensuring compliance with regulatory standards. It provides a solid validation system, comprehensive audit trail tracking, and the ability to generate accurate copies of electronic records. In addition, it effectively implements system security, including access control and password protection.

With Actiz, data integrity is preserved, contributing to more efficient and reliable operations. It simplifies compliance with FDA 21 CFR Part 11 requirements, allowing companies to focus on their core operations rather than on regulatory challenges.

Felippe Domingos

Felippe Domingos

Felippe Domingos is a chemical engineer and Co-Founder of Actiz, a company that offers the most advanced LIMS in Latin America to optimize laboratory management with a focus on efficiency and cost reduction. With more than 200 projects in sectors such as pharmaceuticals, food, and petrochemicals, Felippe has built extensive experience in implementing LIMS systems.

In 2020, after a request from an oil industry company in Colombia, he founded Actiz — a modern and accessible solution specially developed to address the challenges faced by laboratories in Latin America. Today, Actiz is present in four countries, serving segments such as food, biotechnology, and environmental analysis.

Felippe shares his insights on laboratory automation and digitalization on LinkedIn. Connect with him to learn more about the future of laboratories with LIMS.

Leave a Reply

Your email address will not be published. Required fields are marked *