New Analytics Dashboards for Testing Clients: See the Trends Hiding in Your Testing Data
Analytics dashboards are now live in the Confident Client Portal: free Volume dashboards for everyone, plus 19 advanced dashboards for Client Pro.
READ MORE21 CFR Part 11 and ISO 17025, clause by clause: audit trails, e-signatures, document control, and what your LIMS must actually do.

An inspector doesn't ask whether your software is compliant. They ask you to show them who changed a result on a Tuesday in March, when they changed it, and why. Then they wait.
🎧 Prefer to listen? Here's the full audio version of this article:
That's the gap this guide closes. Below, we map what 21 CFR Part 11 and ISO/IEC 17025:2017 actually require onto the specific things your Laboratory Information Management System (LIMS) has to do: audit trails, electronic signatures, document control, corrective actions, and record retrieval. By the end you'll be able to tell a vendor who helps you comply from one who says the word "compliant" a lot.
The short answer: The 21 CFR Part 11 LIMS requirements come down to two mechanisms — secure, computer-generated, time-stamped audit trails, and electronic signatures built from at least two identification components. Part 11 governs how you keep electronic records so the FDA can trust them. ISO/IEC 17025:2017 governs whether your lab is technically competent to produce valid results, and asks your system for controlled documents, traceable technical records, competence records, and a corrective-action trail. No LIMS is "compliant" on its own — your lab validates it, operates it, and owns the outcome.
These two get bundled together in vendor marketing, and they shouldn't be. They answer different questions.
21 CFR Part 11 is a US FDA regulation. It applies when you choose to keep records electronically in place of paper, under an underlying FDA rule (what the agency calls a "predicate rule"). It's about trust in the record itself: can it be altered without a trace, and is that signature really from the person whose name is on it?
ISO/IEC 17025:2017 is an international standard — third edition, published November 2017 and reconfirmed in 2023 — titled General requirements for the competence of testing and calibration laboratories (ISO). It's about competence: are your methods valid, your staff qualified, your equipment calibrated, and your records traceable?
One is a legal requirement in a specific regulatory scope. The other is a voluntary accreditation standard that your clients and regulators increasingly treat as mandatory. A food lab might live under both. A cannabis lab under state rules might live under neither, formally, but be held to the same expectations by its accreditation body.
Here's the thing worth internalizing: both come down to the same operational question. Can you reconstruct what happened to a sample, and prove it?
The FDA's own guidance, Part 11, Electronic Records; Electronic Signatures — Scope and Application (September 2003), narrowed how Part 11 gets enforced. The agency said it would "narrowly interpret the scope of part 11" and exercise enforcement discretion on certain requirements — including validation, audit trails, record retention, and copying — while it re-examined the rule (FDA).
Don't read that as permission to skip audit trails. The same guidance is explicit that "records must still be maintained or submitted in accordance with the underlying predicate rules," and notes it may still be important to have audit trails in place to ensure the trustworthiness and reliability of records. Enforcement discretion is not an exemption. It's a reason to make a documented, risk-based decision — and your LIMS should let you show your work.
This is the clause that decides whether your LIMS passes or fails an inspection. The regulation, at 21 CFR § 11.10(e), requires:
"Use of secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records." (eCFR)
Read that word by word, because each one is a system requirement.
The FDA's Data Integrity and Compliance With Drug CGMP guidance (December 2018) puts a finer definition on it: an audit trail is "a secure, computer-generated, time-stamped electronic record that allows for reconstruction of the course of events relating to the creation, modification, or deletion of an electronic record" (FDA).
Reconstruction is the operative word. The test isn't whether events were logged. It's whether someone can rebuild the story from them.
Ask the vendor to change a result in front of you, then produce the full history of that single sample — who touched it, when, what changed, and why — as an exportable record. Time it.
If it takes more than a minute, or if it requires someone from their support team, you've learned what audit day will feel like.
Part 11 is unusually specific here, which makes it easy to check.
Under § 11.200(a)(1), an electronic signature that isn't based on biometrics must "employ at least two distinct identification components such as an identification code and password." And under § 11.50, a signed electronic record has to clearly indicate three things: the printed name of the signer, the date and time the signature was executed, and the meaning associated with it — "such as review, approval, responsibility, or authorship" (eCFR).
That last one trips up more labs than the first two. A signature that just says "signed by J. Alvarez" doesn't tell an inspector whether Alvarez ran the test, reviewed it, or approved its release. The meaning has to travel with the signature, permanently linked to the record.
Practically, your LIMS needs to support:
The FDA defines data integrity as "the completeness, consistency, and accuracy of data," and says complete, consistent, and accurate data should be "attributable, legible, contemporaneously recorded, original or a true copy, and accurate (ALCOA)" (FDA).
Here's ALCOA translated into things your LIMS either does or doesn't do:
The guidance is also clear that audit trails should cover both data-level changes — reprocessing, integration parameters — and system-level activity like access attempts. Result-level history alone leaves half the story untold.
Where Part 11 is about the record, ISO 17025 is about the system that produces it. Four areas carry most of the LIMS weight.
Personnel competence (clause 6.2). The standard requires labs to demonstrate that staff are competent for the work they perform. In practice that means training records, method authorizations per analyst, and evidence of ongoing competence — linked to the tests those analysts are actually signing off on. A training log in a spreadsheet, disconnected from your sample workflow, satisfies nobody.
Document control (clauses 7.2 and 8.3). SOPs and methods need version control, controlled distribution, and a hard link between the version in force and the result produced under it. The failure mode is common and expensive: an analyst runs the current method, but the report cites the superseded version — or worse, nobody can say which version was in force that day.
Technical records and traceability (clause 7.5). Every result needs a traceable path back through the analyst, the instrument, its calibration status, and the method version. This is where paper and spreadsheets break first, because the links live in someone's memory.
Nonconforming work and corrective action (clauses 7.10 and 8.7). When something goes wrong, you need the deviation logged against the specific samples, equipment, or method involved; the root-cause analysis; the action taken; and the effectiveness check. Assessors look hard at whether corrective actions actually closed, or only ever got opened.
A LIMS that treats CAPA as a separate module you have to remember to open is a LIMS that will have empty CAPA records at assessment time. It should be raised from the workflow where the problem surfaced.
Use this to score any system you're evaluating — including your current one. Every line is traceable to a requirement above. Where a line fails you have a gap an assessor will eventually ask about — we walk through the common ones in closing regulatory compliance gaps before an audit.
Audit trail
Electronic signatures
Documents and methods
Competence
Corrective action
Validation and retention
That second-to-last one is the sharpest filter in the whole list. Ask for validation documentation during evaluation. A vendor who promises it after signature is telling you something.
Let's be direct about the framing, because the industry is sloppy here: no LIMS is "21 CFR Part 11 compliant" or "ISO 17025 certified." Software can't be. Labs get accredited; labs validate their systems; labs own compliance. Any vendor claiming otherwise is either confused or hoping you are.
What Confident does is help you comply — by making the mechanisms above part of the daily workflow instead of a pre-audit scramble. Audit trails on every action. Configurable signature meanings mapped to your review and approval steps. Versioned methods tied to results. Competence records that live next to the samples they authorize. Nonconformances raised where the problem actually shows up.
We work with labs across cannabis, environmental, food and beverage, nutraceuticals, and more — a 15,000+ client network, with over 20K scientists running more than 5M samples a year through the platform. That range matters here: a lab under FDA predicate rules and a lab under a state cannabis program need the same underlying record integrity, expressed differently. Confident is configurable for both, without custom code.
Onboarding runs 2-6 weeks. Support is same-day, with typical resolution in 1-2 days. Compliance is still your responsibility — but the evidence shouldn't be hard to produce. If budget is your next question, we break down what a LIMS actually costs separately.
What does 21 CFR Part 11 require of a LIMS?
Principally: secure, computer-generated, time-stamped audit trails that independently record creates, modifies, and deletes (§ 11.10(e)); electronic signatures using at least two distinct identification components (§ 11.200(a)(1)); and signed records showing the signer's printed name, the date and time, and the meaning of the signature (§ 11.50). It also expects system validation, access controls, and the ability to produce accurate copies of records.
What's the difference between 21 CFR Part 11 and ISO 17025?
Part 11 is a US FDA regulation about the trustworthiness of electronic records and signatures. ISO/IEC 17025:2017 is an international standard about a laboratory's technical competence to produce valid results. Part 11 governs the record; ISO 17025 governs the system that produced it. Many labs are subject to both.
What must a 21 CFR Part 11 audit trail capture?
The date and time of operator entries and actions that create, modify, or delete electronic records — recorded independently of the record itself, by the system rather than the user, and secured so it can't be altered. The FDA's data integrity guidance adds that it must allow full reconstruction of the course of events.
How does a LIMS help with ISO 17025 accreditation?
By making four things continuously provable rather than periodically assembled: personnel competence records (clause 6.2), controlled document and method versions (clauses 7.2 and 8.3), traceable technical records linking result to analyst, instrument, calibration and method (clause 7.5), and a closed-loop corrective action trail (clauses 7.10 and 8.7).
What are the ALCOA principles?
Attributable, legible, contemporaneously recorded, original or a true copy, and accurate — the FDA's shorthand for data that is complete, consistent, and accurate across its full lifecycle.
🎧 Short on time? Here's the podcast brief:
If you take one thing into your next vendor call, make it this: ask to see a full sample history produced live, in under a minute, by someone who doesn't work for the vendor's support team.
Everything else in this guide follows from whether that's possible.
Want to see what that looks like in a system purpose-built for regulated labs? Get Demo
Let's share!