Back to blog
Compliance8 min readMarch 20, 2026

21 CFR Part 11 Compliance Checklist for Compounding Pharmacies

Understanding 21 CFR Part 11

21 CFR Part 11 establishes the FDA's criteria for accepting electronic records and electronic signatures as equivalent to paper records and handwritten signatures. For compounding pharmacies transitioning from paper-based systems to digital platforms, Part 11 compliance is not optional — it is the regulatory foundation that gives your electronic records legal standing during FDA inspections.

This checklist breaks down the key requirements into actionable items that compounding pharmacies can implement and verify. Use it as both an implementation guide and an ongoing compliance assessment tool.

1. Electronic Signature Requirements

Electronic signatures under Part 11 must be legally binding and uniquely tied to the signer. This goes far beyond simply clicking an "approve" button.

  • Unique user identification: Every person who signs electronic records must have a unique user ID and password combination. Shared accounts are a direct violation.
  • Password re-authentication: At the point of signing, the system must require the user to re-enter their credentials. A user who is already logged in must still authenticate again to execute a signature.
  • Signature manifestation: Each electronic signature must display the printed name of the signer, the date and time of signing, and the meaning of the signature (e.g., "authored," "reviewed," "approved").
  • Signature linking: Electronic signatures must be cryptographically linked to their respective records so that signatures cannot be transferred, copied, or otherwise falsified.
  • Non-repudiation: Once applied, a signature cannot be repudiated by the signer. The system must make it technically infeasible for a signer to claim they did not sign a record.

2. Audit Trail Requirements

The audit trail is arguably the most critical Part 11 requirement. It provides the unbroken chain of evidence that inspectors rely on to verify data integrity.

  • Automatic generation: The system must automatically record audit trail entries — users should not be able to disable or modify the audit trail.
  • Who, what, when, why: Every audit trail entry must capture who made the change, what was changed (old value and new value), when the change occurred (timestamp), and why (reason for change).
  • Immutability: Audit trail records must be immutable. No user, including administrators, should be able to modify or delete audit trail entries.
  • Retention: Audit trails must be retained for at least as long as the records they document — and must be readily available for FDA review.
  • Independent review: The audit trail must be reviewable independently of the record it documents, allowing inspectors to trace the complete history of any record.

3. System Access Controls

Part 11 requires that access to electronic records systems be controlled and limited to authorized individuals.

  • Role-based access: Users should only have access to the functions and data required for their role. A technician should not have the same access as an administrator.
  • Account management: Procedures must exist for creating, modifying, and deactivating user accounts. When an employee leaves, their access must be revoked promptly while preserving their historical records.
  • Session controls: Systems should automatically log out inactive sessions and require re-authentication after defined periods of inactivity.
  • Failed login handling: After a defined number of failed login attempts, accounts should be locked and require administrative intervention to unlock.

4. Data Integrity — ALCOA+ Principles

Part 11 compliance is built on the ALCOA+ framework for data integrity. Every electronic record must be:

  • Attributable: Traceable to the person who created or modified it.
  • Legible: Readable and permanently recorded.
  • Contemporaneous: Recorded at the time the activity occurred, not after the fact.
  • Original: The first recording of the data, or a verified true copy.
  • Accurate: Free from errors, or with corrections clearly documented.
  • Complete: All data is present, including any repeat or reprocessed results.
  • Consistent: Data elements are logically consistent (e.g., timestamps are sequential).
  • Enduring: Recorded on permanent media that will last for the required retention period.
  • Available: Accessible for review throughout the retention period.

5. System Validation Requirements

Any system used to maintain Part 11 records must be validated to ensure it performs as intended.

  • Validation documentation: Maintain documented evidence that the system has been tested and meets its intended requirements.
  • Change control: Any changes to the system must go through a documented change control process with impact assessment and re-validation as needed.
  • Periodic review: Systems must be periodically reviewed to ensure they continue to meet Part 11 requirements.

How CompliRx Addresses Part 11

CompliRx was built with 21 CFR Part 11 compliance as a core requirement, not an afterthought. Every electronic signature requires password re-authentication with SHA-256 hash verification. The audit trail automatically captures who, what, when, and why for every action — and is immutable by design. Role-based access control limits users to appropriate functions, and all data follows ALCOA+ principles with contemporaneous recording, complete traceability, and permanent retention. When your next FDA inspection occurs, CompliRx provides the documentation foundation that demonstrates Part 11 compliance across your entire operation.

CE

CompliRx Editorial

Compliance & Regulatory Team

The CompliRx editorial team brings decades of combined experience in pharmaceutical compliance, USP standards, and FDA regulatory requirements.

Share this article

More articles

Related articles

See CompliRx on a facility like yours.

See how CompliRx helps compounding pharmacies stay inspection-ready with automated monitoring, documentation, and training management.