FDA 21 CFR Part 11
21 CFR Part 11 - Validation, Audit Trail, Operational Controls (§11.10(a) + (e) + (f))

FDA 21 CFR Part 11 Part11.RecordRetention: Record protection + retention + readiness for inspection (21 CFR §11.10(b) + (c))

Section 11.10(b) + (c) record protection + retention + inspection requirements: (b) THE ABILITY TO GENERATE ACCURATE AND COMPLETE COPIES OF RECORDS IN BOTH HUMAN READABLE AND ELECTRONIC FORM SUITABLE FOR INSPECTION + REVIEW + AND COPYING BY THE AGENCY - records must be exportable in both human-readable (PDF + print) + electronic (XML + JSON + CSV + native format) forms; copies must be ACCURATE (faithful to original) + COMPLETE (no omissions or summarisation); FDA inspectors expect to receive copies on request typically within minutes for routine inspection + hours for complex queries. (c) PROTECTION OF RECORDS TO ENABLE THEIR ACCURATE AND READY RETRIEVAL THROUGHOUT THE RECORDS RETENTION PERIOD - retention periods derive from underlying agency-regulation requirements (typically 2 years post-clinical-trial-close for clinical; 5+ years for medical-device QMSR records; longer for biologics + manufacturing batch records); records must be: (i) protected against accidental + deliberate alteration + destruction during the retention period; (ii) accessible + retrievable throughout the retention period including across system migrations + obsolescence; (iii) backed up with disaster recovery; (iv) destroyed only after retention period elapses + with documented authorisation. Part 11 record retention coordinates with HIPAA + state record-retention rules + the FDA Bioresearch Monitoring (BIMO) inspection scope.

What else in your programme already covers this

This control maps to 72 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

ISO/IEC 27011:2024 · 3 controls

  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection

Bahrain PDPL · 2 controls

  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing

ISO/IEC 27400:2022 · 2 controls

  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • ASD37-27 Outbound data loss prevention (Very Good)
  • QMSR-820.35 Control of records - record retention, audit trail, UDI, medical-device reporting (§820.35)

India DPDP Act · 1 control

  • RUSPD-4 Special Categories, Biometric Data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 21 CFR Part 11 - Validation, Audit Trail, Operational Controls (§11.10(a) + (e) + (f))

Query this from an agent

The graph holds this control, the 72 it maps to, and the evidence behind each claim, over MCP and REST.