The strictest common regime
Most electronic signatures in the US answer to one law: the ESIGN Act and UETA, which make an electronic signature broadly equivalent to a wet one. For the great majority of business documents, that is the whole story. Life sciences is the notable exception. When a record falls under FDA oversight — a batch record, a clinical trial document, a quality-system approval — a second, stricter rulebook applies: 21 CFR Part 11, the FDA regulation on electronic records and electronic signatures.
Part 11 does not replace ESIGN; it sits on top of it. A signature that is perfectly valid for a commercial contract can still fall short of Part 11 if the surrounding controls are not in place. This is a plain-language walk through what Part 11 actually asks for, and — importantly — which parts are a platform capability and which are things only your organization can do. It is general guidance, not regulatory or legal advice; your quality and regulatory teams own the compliance determination.
When Part 11 applies (and when it does not)
Part 11 applies to records that a predicate rule — an underlying FDA regulation, such as good manufacturing practice or good clinical practice — requires you to keep, when you keep them electronically or sign them electronically. That scoping matters. Part 11 is not triggered by any electronic signature at a life-sciences company. Signing an office lease or a vendor NDA is ordinary commercial signing under ESIGN. Part 11 attaches specifically to the FDA-regulated records the predicate rules govern. Getting the scope right is the first step; over-applying Part 11 to everything is a common and costly mistake.
What Part 11 requires of a signature
For the records in scope, Part 11 asks for more than "the signer intended to sign." The core requirements cluster into a few areas:
1. A durable signature manifestation
Every signed electronic record must carry, in the record itself, the printed name of the signer, the date and time of signing, and the meaning of the signature (approved, reviewed, authored, and so on). This manifestation has to travel with any human-readable copy of the record. This is stricter than general practice: it is not enough that the system knows who signed and why — the signed document must say so on its face.
2. Identity and unique attribution
Each electronic signature must be unique to one individual and never reused or reassigned. The signer's identity must be established before they are issued signing credentials, and the signature must be genuinely attributable to that person. This is where Part 11 leans hard on signer identity verification and on account controls that prevent one person signing as another.
3. Signing that requires the signer to act
Non-biometric electronic signatures under Part 11 must use at least two distinct identification components (for example, an identifier and a password), and the controls must make it so that an individual signature cannot be executed without the signer's own credentials. The point is to ensure the signature reflects a deliberate act by the specific person, not a shared login or an automated stamp.
4. A trustworthy, tamper-evident record
The signed record and its audit trail must be protected so that any change is detectable, and the audit trail must be secure, computer-generated, and time-stamped, recording who did what and when without allowing the entries to be altered or obscured. This is the requirement that maps most directly to how a well-built signing platform already works.
Platform versus process: drawing the line honestly
It would be misleading to say any product "makes you Part 11 compliant." Part 11 compliance is a property of your whole system — technology plus your validated procedures, training, and controls. It is worth being precise about which side of the line each requirement lands on.
What a signing platform can provide:
- A tamper-evident, time-stamped audit trail of every event, of the kind described in audit trails that hold up. Every document sent through Hitt Hosting Sign is sealed with a SHA-256 hash and an RFC 3161 trusted timestamp, and each action is written to a hash-chained record that surfaces as a portable evidence certificate.
- Integrity protection so that any change to a signed record is detectable — the core of securing signed documents.
- Identity controls at signing — access codes and one-time codes that raise the bar on attribution.
- A captured record of who signed, when, and in what order, through a defined routing workflow.
What only your organization can do:
- Validate the system for its intended use and document that validation.
- Establish the identity of each individual before issuing credentials, and maintain unique, non-shared accounts.
- Author SOPs governing signing, records retention, and access, and train people on them.
- Confirm the signature manifestation (printed name, date/time, meaning) appears on the record as the predicate rule and Part 11 require.
- Certify to the FDA, as Part 11 requires, that your electronic signatures are intended to be the legally binding equivalent of handwritten ones.
A platform gives you strong building blocks; the compliance determination is yours to make with your quality and regulatory functions.
How Part 11 relates to the rest of your compliance stack
Part 11 does not exist in isolation. A life-sciences organization signing regulated records still needs ordinary ESIGN consent where consumer-facing, still cares about long-term verifiability of what it signed, and often carries HIPAA obligations alongside — see HIPAA-conscious e-signing. Part 11 is the strictest layer, but it stacks with the others rather than replacing them. The broader map of overlapping regimes is in compliance for regulated industries.
The takeaway
For FDA-regulated records, a valid electronic signature is the floor, not the ceiling. Part 11 adds real requirements: a durable signature manifestation on the record, identity that is unique and pre-established, signing that demands the signer's own credentials, and a secure, time-stamped, tamper-evident audit trail. A strong signing platform supplies the integrity, identity, and audit-trail building blocks; validation, identity establishment, SOPs, and the FDA certification remain your organization's responsibility. Scope Part 11 to the records the predicate rules actually cover, build on a platform that seals and time-stamps what it signs, and pair it with the procedures only you can put in place.
This article is general guidance, not regulatory or legal advice. Part 11 determinations are fact-specific and belong to your quality, regulatory, and legal teams.