Motionwell Automation builds and retrofits GMP production equipment in Singapore, a tray-fed filling and sealing machine dosing through three heads in parallel for an ISO Class 7 or Class 8 cleanroom, and control retrofits that replace the controller, the drives and the operator panel on machines whose mechanics are still sound, and nearly every one of those projects reaches the same argument in the specification meeting. A retrofit is where the argument bites hardest, because the panel being removed could not hold a named user account at all and the one going in can, which turns a new capability into a new expectation. It surfaces just as early when we design a multi-station rotary assembly machine with a force-monitored press at each insertion station, because every press curve is a candidate record. Somebody says the machine must be Part 11 compliant. Nobody in the room agrees on what that sentence covers. These 21 CFR Part 11 questions and answers deal with the rule itself: which machine data becomes a regulated record, what the clause text actually asks for, and which duties belong to the licence holder and not the equipment supplier. The engineering side, how accounts, audit trails and signatures are implemented on a PLC and HMI, is covered separately on our page about Part 11 compliance built into production equipment.
The short answer. Part 11 is a conditional rule. It attaches to a record only when two things are true at the same time: some other FDA regulation, the predicate rule, requires you to keep that record, and you have chosen to keep it electronically. Nothing on a machine becomes a Part 11 record because it is technically interesting, because a supplier logged it, or because it lives in a database. Identify the predicate rule first. Every later question, what the audit trail must capture, what a signature binds to, how long anything is retained, has a different answer depending on which records fall inside that first answer. The current consolidated text is published as 21 CFR Part 11 on eCFR, and it is short enough to read in an afternoon.
Which Data on a Production Machine Is a 21 CFR Part 11 Record?
This is the question that decides the size of the project. Your quality unit answers it, and a machine builder cannot answer it for you.
A modern machine generates far more data than the regulation cares about. A servo drive publishes torque, position and following error every cycle. A vision system produces an image and a decision per unit. The HMI holds trends, alarm history, maintenance counters and shift totals. None of that is regulated by default. It becomes regulated when your quality system points at it and says: this is the evidence that the product was made correctly.
| Data the machine produces | Why it exists | Part 11 status |
|---|---|---|
| Measured fill volume per container, retained as batch evidence | The batch record has to show what the process actually did | Regulated record |
| Vision result and reject reason for an individual unit | The unit record has to include failures as well as passes | Regulated record |
| Operator entry of an incoming component lot number | Traceability required by the predicate rule | Regulated record, and usually a signature point |
| Recipe parameter set used to run the batch | The record must show which process was run | Regulated record |
| Live trend on the HMI that nobody retains | Operator information during the shift | Not a record |
| Machine hours and maintenance counters | Maintenance planning | Not regulated unless your quality system pulls them into a required record |
| PLC program version and change history | Clause 11.10(k) asks for controls over systems documentation | Controlled document |
The failure mode here is generosity. A project team that cannot decide declares everything regulated, on the theory that more evidence is safer. It is not safer, it is heavier: every record type declared regulated inherits the audit trail, the retention obligation, the copy obligation and its share of the validation protocol. Good scoping is being able to say, in one sentence per data item, why that item is or is not part of a record a rule requires.
A useful discipline: write the scope statement as a list of records. “The batch record for product family A, comprising eleven operator entries, four machine-generated parameters and three signatures” is a scope. “The filling line” is not.
Does Part 11 Apply If the Record Is Never Sent to the FDA?
Yes. Part 11 covers records required to be maintained as well as records submitted, so a batch record that never leaves your document store is squarely in scope. Submission is not the trigger. The predicate rule is.
| Predicate rule | What it requires you to keep | What Part 11 adds once it is electronic |
|---|---|---|
| 21 CFR 211.188, batch production and control records | A record of each batch: what was made, what was used, what was checked, who verified it | Audit trail, signature manifestation and linking, protected retention, human-readable and electronic copies |
| 21 CFR 820, since 2 February 2026 the Quality Management System Regulation incorporating ISO 13485:2016 by reference | The obligation survives in ISO 13485 clause 7.5.1: records for each batch showing what was made, how much was approved for release, and who verified it | The same set of controls, applied to the unit or batch record instead of a pharmaceutical batch |
| No predicate rule | Nothing | Part 11 does not attach. Your own data integrity policy may still bind you, and an inspector cites the rule that applies |
There is a route out, and it is legitimate: keep the record on paper. If the printed batch record is the official record, it is reviewed and wet-signed, and the machine file is a convenience copy, Part 11 does not attach to the machine file. The catch is that the arrangement has to be real. A site that declares paper as the record and then, during a deviation investigation, reaches for the electronic file because the paper does not have the detail has answered the question against itself. Whichever version you actually rely on is the record.
Hybrid arrangements survive audits when the split is written down before anyone needs it: which fields exist only on paper, which exist only electronically, how the two are reconciled, and what happens when they disagree. Left undocumented, the hybrid becomes two records that drift apart.
What Does Clause 11.10(e) Actually Ask an Audit Trail to Do?
The 21 CFR Part 11 audit trail requirements sit in one sentence of clause text, and four words in it do most of the work: secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions that create, modify or delete electronic records. Changes must not obscure previously recorded information. The trail is retained at least as long as the record itself and must be available for review and copying.
- Independently. The trail is generated by the system, not by the person being recorded. An operator typing a note into a comment field is not an audit trail entry, however accurate the note.
- Computer-generated. A logbook, a spreadsheet, a maintenance record filled in afterwards, none of these qualify, no matter how disciplined the site is.
- Secure. The people whose actions the trail records cannot alter it. That includes the engineer with the administrator password. A trail that can be trimmed quietly is not a trail; it is a report.
- Shall not obscure. Overwriting a value in place fails this even if the change was correct and authorised. The previous value has to survive the change.
- At least as long as. The audit trail inherits the retention period of the record it describes, which is set by the predicate rule.
Equally worth noting is what the clause does not say. It does not name a file format, a database product, a storage medium, or a review frequency. Those decisions come from your risk assessment and your procedures, and they get tested during qualification, never argued from the regulation. A supplier who tells you a particular product is required by 11.10(e) is selling. How the entries are structured and where they are written on a real controller is set out on the equipment-side Part 11 page.
What Must an Electronic Signature Be Bound To?
Three clauses answer this, and they are usually collapsed into one in conversation.
Clause 11.50 covers manifestation: the signed record has to display the printed name of the signer, the date and time of signing, and the meaning of the signature, review, approval, responsibility or authorship. Meaning is not decoration. “Approved by” and “reviewed by” carry different liability, and a system that captures a tick without capturing which of the two it was has produced an ambiguous record.
Clause 11.70 covers linking: the signature is bound to its record so it cannot be excised, copied, or transferred to another record by ordinary means. This is the clause that rules out storing signatures in a separate table joined by a key anyone can edit.
Clause 11.200 covers the components: at least two distinct identification components for a non-biometric signature, all of them for the first signing in a continuous session, and at least one component executable only by the signer for subsequent signings in that session.
Read together, they draw a line that plant floors cross regularly: a login is not a signature. An access control event proves someone was authenticated at some point. A signature is an act performed against a specific record at a specific moment with a stated meaning. A system that logs “user was signed in when the batch was released” has recorded neither the act nor its meaning, and the gap only appears when an inspector asks who released the batch and on what basis.
One further point that changes who does the work: clause 11.100(c) requires the organisation using electronic signatures to certify to the FDA that they are the legally binding equivalent of handwritten signatures. That letter is written by the manufacturer. No equipment supplier can send it on your behalf, and no purchase order transfers it.
Why Is Clock Synchronisation a Part 11 Question?
Because 11.10(e) asks for time-stamped entries and then declines to say whose clock. Real-time clocks in PLCs, HMIs and industrial PCs run independently and drift at different rates, so two devices on one machine can disagree by minutes after a year in service. When an investigation turns on the order of events, did the operator acknowledge the alarm before or after the reject, a merged trail assembled from unsynchronised clocks cannot answer.
The rule-reading consequence is small and specific. Nominate one time source for everything that touches a regulated record. Write the convention into the validation documents, including which timezone is stored and which is displayed, so the answer exists on paper before anyone asks. Then log clock adjustments as audit trail events in their own right, because a corrected clock is a change to the evidence and Part 11 treats changes to evidence as recordable. None of this is expensive at design time. All of it is awkward to retrofit into a validated system.
What Happens to a Record the Machine Had Not Finished Writing When the Power Failed?
Part 11 has no clause about power failures. The clause that decides the argument is 11.10(a): a validated system, with the ability to discern invalid or altered records. So the question is not “what does the rule say about blackouts” but “can you tell, afterwards, which records are trustworthy”.
| Where the supply drops | What exists afterwards | How the record survives it |
|---|---|---|
| Mid-cycle, before the unit is finished | No completed unit; the part itself is incomplete | Log an aborted cycle. A gap in serial numbers that nothing explains is worse than a recorded abort |
| Cycle complete, data held in the local buffer, still unforwarded | The record exists at the machine only | The buffer must survive a power loss, and must forward with the original timestamps |
| Data forwarded, server transaction not committed | A partial write | The record store has to be transactional: a record is written completely or not at all. Append-to-file storage fails this quietly |
| Signature captured, record write failed | A signature bound to nothing | Clause 11.70 requires the signature to be linked to its record. If the record does not exist, the signature must not stand alone |
| Operator retypes the missing entries after restart | A record that looks contemporaneous but is not | The later entry is marked as a later entry, with its own audit trail line. Backdating is the failure the rule exists to prevent |
This is a design question with a qualification answer. Operational qualification is where it gets tested: pull the supply mid-cycle and prove the machine restarts in a defined, safe state without corrupting the record. Negative tests like that carry more weight than another pass of the happy path, and they belong in the protocol from the first draft, see our page on computer system validation and IQ/OQ/PQ for machines for how the protocol is structured.
Is a Production Machine a Closed System or an Open System?
The distinction sets which controls apply, and it is decided by one thing only: who controls access to the system that holds the records. Clause 11.10 governs closed systems, where access is managed by the people responsible for the content of the records. Clause 11.30 governs open systems, adding measures such as document encryption and appropriate digital signature standards to ensure authenticity, integrity and confidentiality.
A machine on your own plant network, with accounts your site administers, is a closed system. What pushes a project toward the open-system reading is rarely the machine itself:
- A vendor remote-support tunnel where the supplier holds the credentials
- Records replicated to a service the site does not administer
- A contract manufacturer holding records on behalf of the licence holder
- Data leaving the plant network for analysis and coming back as a decision
None of these are prohibited. They change the control set, and that change belongs in the validation plan long before an audit goes looking for it. The network architecture behind that decision, segmentation, the conduits between zones, who holds which credentials, is a security question as much as a compliance one, and is covered in our article on IEC 62443 for machine builders.
What Counts as an Accurate and Complete Copy for an Inspector?
Clause 11.10(b) asks for the ability to generate accurate and complete copies of records in both human-readable and electronic form, suitable for inspection, review and copying by the agency. Two words in that sentence get skipped.
Complete means the copy carries the whole record. That includes the audit trail entries belonging to it and the signature manifestation with name, date, time and meaning. A batch report that shows results but drops the four modifications made during the run is not a complete copy of the record; it is an extract.
Accurate is something you demonstrate, and the demonstration is cheap. Export one record, hand it to someone who did not build the system, and ask them to reconstruct what happened during that batch. If they cannot, the export is not yet a copy in the sense the clause means.
Clause 11.10(c) adds protection of records to enable their accurate and ready retrieval throughout the retention period, and the retention period is set by the predicate rule. Two consequences follow. The record has to outlive the software that produced it, which is why the export matters more than the viewer. And retrieval has to be tested: a restore that has never been performed is a plan.
Who Owns Each Part 11 Obligation, the Site, or the Machine Builder?
Splitting this early prevents the specification meeting from ending with “the supplier will make the machine compliant”, a sentence that cannot be delivered.
| Obligation | Where it comes from | Who discharges it |
|---|---|---|
| Deciding which records are regulated | The predicate rule | Licence holder’s quality unit. No supplier can determine this |
| A system technically capable of the required controls | 11.10 as a whole | Equipment supplier, through the control platform, record store and interfaces |
| Validation evidence that the controls work | 11.10(a) | Shared: supplier writes specifications and protocols and executes with the site; the quality unit approves and owns the result |
| Named accounts, role definitions, removal of leavers | 11.10(d) and 11.10(g) | Site IT and quality, using the account and role structure the supplier builds |
| Retention, backup and tested retrieval | 11.10(c) | Site. Records live on site infrastructure |
| Certification letter to the FDA on electronic signatures | 11.100(c) | The licence holder, always. No purchase order moves it to a supplier |
| Training and written accountability for actions taken under a signature | The people-facing controls in 11.10 | Site procedures and training records |
The pattern is consistent: the supplier delivers capability and evidence, the site delivers decisions, procedures and custody. A purchase specification that reflects that split reads very differently from one that does not. It asks for named controls with acceptance criteria, audit trail content, role matrix, export formats, buffer depth, time source, never for a compliance adjective.
Does Part 11 Apply to a Machine That Already Logs to a File?
Older equipment on a plant floor often writes CSV files that nobody looks at. Those files are not regulated records simply because they exist. They become regulated on the day the quality system relies on them as evidence, cited in an investigation, referenced in a batch review, attached to a release decision. The trigger is reliance, never the file format and never the age of the machine.
That is why control retrofits, now Motionwell’s largest project family in 2026, are so often driven by compliance. The machine still runs to specification; the controller simply cannot hold a user account, and the site has decided to start relying on what the machine produces. Which of the available routes fits, new controller, added data layer, or leaving the machine alone and signing beside it, depends on where the regulated record is actually created, and is set out on our machine retrofit and modernisation page.
Two traps recur on legacy equipment. The first is a file that is regulated in practice but has never been declared, so it has no audit trail, no retention plan and no place in any protocol. The second is the opposite: a folder of historical data declared regulated during a nervous moment, committing the site to a retention obligation on data it does not need. Both are scope errors, and both are cheaper to fix before a rollout than during one. Serialised packaging adds a third dimension to the same question, because coding and reading data becomes part of the regulated record set, the detail is on our pharmaceutical serialization page, and the production context on the pharmaceutical packaging automation and medical device manufacturing pages.
How Do the Requirements Chain Together?
Read as Part 11 guidelines for pharmaceutical manufacturers, the rule works badly as a checklist and well as a chain of dependencies. A predicate rule requires a record. You decide to keep it electronically. That decision brings validation, access control, an audit trail, signature rules, retention and the ability to hand over a copy. Change the first link, a different predicate rule, a different scope of records, a decision to keep paper, and everything downstream changes with it. Teams that argue about audit trail formats before agreeing the record list are arguing about the wrong link.
As a pharmaceutical machine builder in Singapore, our side of that chain is concrete: we build the capability and produce the evidence that it works, at factory acceptance testing in our Woodlands Link facility and at site acceptance testing in your cleanroom. The records, the procedures and the certification letter stay with you.