FDA 21 CFR Part 11
21 CFR Part 11 - Validation, Audit Trail, Operational Controls (§11.10(a) + (e) + (f))

FDA 21 CFR Part 11 Part11.CSV: Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)

Section 11.10(a) requires VALIDATION of closed systems to ensure accuracy + reliability + consistent intended performance + the ability to discern invalid or altered records. Validation is operationalised through: (a) Computer System Validation (CSV) lifecycle including URS (User Requirements Specification) + FS (Functional Specification) + DS (Design Specification) + IQ (Installation Qualification) + OQ (Operational Qualification) + PQ (Performance Qualification) + risk assessment + traceability matrix + validation summary report + ongoing validation maintenance; (b) GAMP 5 framework (ISPE Good Automated Manufacturing Practice) categorising systems as Category 1 (infrastructure software) through Category 5 (custom software) with proportionate validation rigour; (c) ICH Q9 (Quality Risk Management) + ICH Q10 (Pharmaceutical Quality System) risk-based approaches; (d) FDA 2003 SCOPE AND APPLICATION GUIDANCE (the 'enforcement discretion' guidance) clarifying that Part 11 requirements should be implemented based on RISK + CRITICALITY + intended use - not strictly across all systems; (e) FDA 2023 COMPUTER SOFTWARE ASSURANCE (CSA) DRAFT GUIDANCE proposing a modernised approach focused on critical thinking + risk + intended use + appropriate testing - reducing the prescriptive testing burden of traditional CSV; (f) Software Bill of Materials (SBOM) expectations for medical device + production software per the Cures Act 524B + the FDA 2024 pre-market cybersecurity guidance. The CSV-to-CSA transition is the most significant modernisation of Part 11 implementation in the past decade.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 60 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

API 1164 · 2 controls

  • API1164-07 Remote Access
  • API1164-24 Vulnerability assessment for critical systems
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • 4.3.1 Risk Assessment and Impact Analysis

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training
  • CJIS-17 Risk Assessment
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)
  • HKMA-CRAF-Domain1-2-Governance-Identification HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment
  • IACS-UR-E26-Identify-Plan-Risk-Survey-Documentation IACS UR E26 Identify Goal - Ship Cyber Resilience Plan + CBS Risk Assessment + Survey + Documentation

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

India DPDP Act · 1 control

  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • CPSC-RA.3 Lifecycle Risk Assessment
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 21 CFR Part 11 - Validation, Audit Trail, Operational Controls (§11.10(a) + (e) + (f))

Query this from an agent

The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.