21 CFR Part 11 & ISO 17025 in Practice: What Your LIMS Must Actually Do

21 CFR Part 11 and ISO 17025, clause by clause: audit trails, e-signatures, document control, and what your LIMS must actually do.

Written by

Camille Claudet

An inspector doesn't ask whether your software is compliant. They ask you to show them who changed a result on a Tuesday in March, when they changed it, and why. Then they wait.

🎧 Prefer to listen? Here's the full audio version of this article:

That's the gap this guide closes. Below, we map what 21 CFR Part 11 and ISO/IEC 17025:2017 actually require onto the specific things your Laboratory Information Management System (LIMS) has to do: audit trails, electronic signatures, document control, corrective actions, and record retrieval. By the end you'll be able to tell a vendor who helps you comply from one who says the word "compliant" a lot.

The short answer: The 21 CFR Part 11 LIMS requirements come down to two mechanisms — secure, computer-generated, time-stamped audit trails, and electronic signatures built from at least two identification components. Part 11 governs how you keep electronic records so the FDA can trust them. ISO/IEC 17025:2017 governs whether your lab is technically competent to produce valid results, and asks your system for controlled documents, traceable technical records, competence records, and a corrective-action trail. No LIMS is "compliant" on its own — your lab validates it, operates it, and owns the outcome.

21 CFR Part 11 vs ISO 17025: what each one actually governs

These two get bundled together in vendor marketing, and they shouldn't be. They answer different questions.

21 CFR Part 11 is a US FDA regulation. It applies when you choose to keep records electronically in place of paper, under an underlying FDA rule (what the agency calls a "predicate rule"). It's about trust in the record itself: can it be altered without a trace, and is that signature really from the person whose name is on it?

ISO/IEC 17025:2017 is an international standard — third edition, published November 2017 and reconfirmed in 2023 — titled General requirements for the competence of testing and calibration laboratories (ISO). It's about competence: are your methods valid, your staff qualified, your equipment calibrated, and your records traceable?

One is a legal requirement in a specific regulatory scope. The other is a voluntary accreditation standard that your clients and regulators increasingly treat as mandatory. A food lab might live under both. A cannabis lab under state rules might live under neither, formally, but be held to the same expectations by its accreditation body.

Here's the thing worth internalizing: both come down to the same operational question. Can you reconstruct what happened to a sample, and prove it?

One nuance most articles skip

The FDA's own guidance, Part 11, Electronic Records; Electronic Signatures — Scope and Application (September 2003), narrowed how Part 11 gets enforced. The agency said it would "narrowly interpret the scope of part 11" and exercise enforcement discretion on certain requirements — including validation, audit trails, record retention, and copying — while it re-examined the rule (FDA).

Don't read that as permission to skip audit trails. The same guidance is explicit that "records must still be maintained or submitted in accordance with the underlying predicate rules," and notes it may still be important to have audit trails in place to ensure the trustworthiness and reliability of records. Enforcement discretion is not an exemption. It's a reason to make a documented, risk-based decision — and your LIMS should let you show your work.

What a Part 11 audit trail must actually capture

This is the clause that decides whether your LIMS passes or fails an inspection. The regulation, at 21 CFR § 11.10(e), requires:

"Use of secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records." (eCFR)

Read that word by word, because each one is a system requirement.

  • Secure — the trail can't be edited or deleted, including by administrators. If your system administrator can quietly rewrite history, you don't have an audit trail. You have a log.
  • Computer-generated — it's written by the system, not typed in by an analyst. A field labeled "reason for change" that a user fills in is a good practice; it is not the audit trail itself.
  • Time-stamped — with a trustworthy clock, and ideally a single time source across sites.
  • Independently record — the trail sits apart from the record it describes. Modifying the result shouldn't touch the history of the result.
  • Create, modify, or delete — all three. Deletions matter most, and they're what weak systems hide.

The FDA's Data Integrity and Compliance With Drug CGMP guidance (December 2018) puts a finer definition on it: an audit trail is "a secure, computer-generated, time-stamped electronic record that allows for reconstruction of the course of events relating to the creation, modification, or deletion of an electronic record" (FDA).

Reconstruction is the operative word. The test isn't whether events were logged. It's whether someone can rebuild the story from them.

The question to ask in a demo

Ask the vendor to change a result in front of you, then produce the full history of that single sample — who touched it, when, what changed, and why — as an exportable record. Time it.

If it takes more than a minute, or if it requires someone from their support team, you've learned what audit day will feel like.

Electronic signatures: the two-component requirement

Part 11 is unusually specific here, which makes it easy to check.

Under § 11.200(a)(1), an electronic signature that isn't based on biometrics must "employ at least two distinct identification components such as an identification code and password." And under § 11.50, a signed electronic record has to clearly indicate three things: the printed name of the signer, the date and time the signature was executed, and the meaning associated with it — "such as review, approval, responsibility, or authorship" (eCFR).

That last one trips up more labs than the first two. A signature that just says "signed by J. Alvarez" doesn't tell an inspector whether Alvarez ran the test, reviewed it, or approved its release. The meaning has to travel with the signature, permanently linked to the record.

Practically, your LIMS needs to support:

  • Unique user accounts — never shared logins, which quietly break attributability across every other requirement
  • Role-based access, so signing authority actually maps to your org chart
  • Signature meanings that are configurable per workflow step (analyst → reviewer → approver)
  • A signature that stays bound to the record when it's exported, copied, or archived

Data integrity and ALCOA: what the FDA is really looking for

The FDA defines data integrity as "the completeness, consistency, and accuracy of data," and says complete, consistent, and accurate data should be "attributable, legible, contemporaneously recorded, original or a true copy, and accurate (ALCOA)" (FDA).

Here's ALCOA translated into things your LIMS either does or doesn't do:

  • Attributable — Tie every entry to a named user via a unique account. No generic "lab1" logins.
  • Legible — Keep records readable and retrievable for the full retention period, in a format that outlives the vendor contract.
  • Contemporaneous — Capture the timestamp at the moment of the action — not when someone gets around to entering it.
  • Original — Preserve the original record and any true copy, with the raw instrument data traceable back from the result.
  • Accurate — Enforce validation rules, controlled method versions, and a review step before release.

The guidance is also clear that audit trails should cover both data-level changes — reprocessing, integration parameters — and system-level activity like access attempts. Result-level history alone leaves half the story untold.

ISO 17025:2017 in practice: competence, documents, and CAPA

Where Part 11 is about the record, ISO 17025 is about the system that produces it. Four areas carry most of the LIMS weight.

Personnel competence (clause 6.2). The standard requires labs to demonstrate that staff are competent for the work they perform. In practice that means training records, method authorizations per analyst, and evidence of ongoing competence — linked to the tests those analysts are actually signing off on. A training log in a spreadsheet, disconnected from your sample workflow, satisfies nobody.

Document control (clauses 7.2 and 8.3). SOPs and methods need version control, controlled distribution, and a hard link between the version in force and the result produced under it. The failure mode is common and expensive: an analyst runs the current method, but the report cites the superseded version — or worse, nobody can say which version was in force that day.

Technical records and traceability (clause 7.5). Every result needs a traceable path back through the analyst, the instrument, its calibration status, and the method version. This is where paper and spreadsheets break first, because the links live in someone's memory.

Nonconforming work and corrective action (clauses 7.10 and 8.7). When something goes wrong, you need the deviation logged against the specific samples, equipment, or method involved; the root-cause analysis; the action taken; and the effectiveness check. Assessors look hard at whether corrective actions actually closed, or only ever got opened.

A LIMS that treats CAPA as a separate module you have to remember to open is a LIMS that will have empty CAPA records at assessment time. It should be raised from the workflow where the problem surfaced.

21 CFR Part 11 LIMS requirements: your readiness checklist

Use this to score any system you're evaluating — including your current one. Every line is traceable to a requirement above. Where a line fails you have a gap an assessor will eventually ask about — we walk through the common ones in closing regulatory compliance gaps before an audit.

Audit trail

  • Secure, computer-generated, time-stamped — not editable by any role, including admin
  • Records creates, modifies, and deletes
  • Independent of the record it describes
  • Covers data-level and system-level events
  • Exportable, human-readable, retrievable per sample in under a minute

Electronic signatures

  • At least two distinct identification components
  • Unique accounts, no shared logins
  • Printed name, date/time, and meaning captured with every signature
  • Signature stays bound to the record on export and archive
  • Role-based signing authority

Documents and methods

  • Versioned SOPs and methods, with controlled distribution
  • Result links to the method version in force at run time
  • Superseded versions retained and clearly marked

Competence

  • Training and authorization records per analyst, per method
  • Expiry alerts before authorizations lapse
  • Competence status visible from the sample workflow

Corrective action

  • Nonconformances raised from the workflow, linked to samples, equipment, or methods
  • Root cause, action, owner, due date, and effectiveness check
  • Open/closed status reportable at any time

Validation and retention

  • Vendor supplies validation documentation before you sign, not after
  • You can run your own IQ/OQ/PQ against a sandbox
  • Records exportable in an open format for the full retention period

That second-to-last one is the sharpest filter in the whole list. Ask for validation documentation during evaluation. A vendor who promises it after signature is telling you something.

Where Confident fits

Let's be direct about the framing, because the industry is sloppy here: no LIMS is "21 CFR Part 11 compliant" or "ISO 17025 certified." Software can't be. Labs get accredited; labs validate their systems; labs own compliance. Any vendor claiming otherwise is either confused or hoping you are.

What Confident does is help you comply — by making the mechanisms above part of the daily workflow instead of a pre-audit scramble. Audit trails on every action. Configurable signature meanings mapped to your review and approval steps. Versioned methods tied to results. Competence records that live next to the samples they authorize. Nonconformances raised where the problem actually shows up.

We work with labs across cannabis, environmental, food and beverage, nutraceuticals, and more — a 15,000+ client network, with over 20K scientists running more than 5M samples a year through the platform. That range matters here: a lab under FDA predicate rules and a lab under a state cannabis program need the same underlying record integrity, expressed differently. Confident is configurable for both, without custom code.

Onboarding runs 2-6 weeks. Support is same-day, with typical resolution in 1-2 days. Compliance is still your responsibility — but the evidence shouldn't be hard to produce. If budget is your next question, we break down what a LIMS actually costs separately.

FAQ

What does 21 CFR Part 11 require of a LIMS?

Principally: secure, computer-generated, time-stamped audit trails that independently record creates, modifies, and deletes (§ 11.10(e)); electronic signatures using at least two distinct identification components (§ 11.200(a)(1)); and signed records showing the signer's printed name, the date and time, and the meaning of the signature (§ 11.50). It also expects system validation, access controls, and the ability to produce accurate copies of records.

What's the difference between 21 CFR Part 11 and ISO 17025?

Part 11 is a US FDA regulation about the trustworthiness of electronic records and signatures. ISO/IEC 17025:2017 is an international standard about a laboratory's technical competence to produce valid results. Part 11 governs the record; ISO 17025 governs the system that produced it. Many labs are subject to both.

What must a 21 CFR Part 11 audit trail capture?

The date and time of operator entries and actions that create, modify, or delete electronic records — recorded independently of the record itself, by the system rather than the user, and secured so it can't be altered. The FDA's data integrity guidance adds that it must allow full reconstruction of the course of events.

How does a LIMS help with ISO 17025 accreditation?

By making four things continuously provable rather than periodically assembled: personnel competence records (clause 6.2), controlled document and method versions (clauses 7.2 and 8.3), traceable technical records linking result to analyst, instrument, calibration and method (clause 7.5), and a closed-loop corrective action trail (clauses 7.10 and 8.7).

What are the ALCOA principles?

Attributable, legible, contemporaneously recorded, original or a true copy, and accurate — the FDA's shorthand for data that is complete, consistent, and accurate across its full lifecycle.

Start with the audit trail

If you take one thing into your next vendor call, make it this: ask to see a full sample history produced live, in under a minute, by someone who doesn't work for the vendor's support team.

Everything else in this guide follows from whether that's possible.

Want to see what that looks like in a system purpose-built for regulated labs? Get Demo

Let's share!

Confident LIMS