Data Integrity

Electronic Signatures: Legally Sound and GxP-Compliant

Electronic signatures must satisfy two worlds at once: the GxP requirements of 21 CFR Part 11 and EU GMP Annex 11, and EU law under the eIDAS regulation. We show which signature tier fits which use case and implement signature workflows that hold up in audits and in court.

Our services for digital signatures

Cloud services such as DocuSign, Adobe Acrobat Sign or d.velop sign provide the signature technology, but not your GxP responsibility. As soon as GxP-relevant documents are signed, the service counts as a computerised system and is qualified and validated on a risk basis: supplier assessment, review of the signature manifestation, verification of the link between signature and document, user and permissions concept, and rules for export and archiving of signed documents across the full retention period.

Methodically the assessment follows our approach from Computer System Validation (CSV); for pure configuration products we work risk-based along CSA principles.

Clarify scope?

Book an intro call

Leistungs-Wegweiser

Welche Ausgangslage beschreibt Ihr Vorhaben?

Wählen Sie die Ausgangslage. Sie erhalten einen fokussierten Startpunkt mit Vertiefungen und Kontaktweg.

In everyday language both terms are mixed up; legally and technically they mean different things. The electronic signature is the legal umbrella term: any form in which a person declares their intent electronically, from a typed name under an email to a signature card. The digital signature is the cryptographic technique behind it: a hash of the document is encrypted with the signatory's private key, and any later change to the document invalidates the signature.

Our approach in GxP projects: from planning through release – each step delivers evidence you can present in QA review and audit. View GxP consulting in five steps

Electronic or Digital: What Is the Difference?

In everyday language both terms are mixed up; legally and technically they mean different things. The electronic signature is the legal umbrella term: any form in which a person declares their intent electronically, from a typed name under an email to a signature card. The digital signature is the cryptographic technique behind it: a hash of the document is encrypted with the signatory's private key, and any later change to the document invalidates the signature.

In practice this means: advanced and qualified electronic signatures use digital signatures as their technology. A scanned handwritten signature or a typed name, by contrast, is only a simple electronic signature without cryptographic protection.

Two Regulatory Worlds, One Workflow

Anyone signing electronically in pharma, medical devices or the food industry has to reconcile two independent sets of rules.

  • GxP world: 21 CFR Part 11 governs electronic records and signatures for the US authorities, EU GMP Annex 11 the computerised systems in the EU. The focus is attributability, audit trail and the link between signature and record.
  • EU civil law: The eIDAS regulation (EU) No 910/2014 defines three tiers of electronic signatures and governs their legal effect in the single market, including the equivalence of the qualified signature with handwriting.

A signature workflow can be Part 11 compliant and still weak under civil law, and vice versa. That is why we assess both levels together.

The Three eIDAS Tiers at a Glance

1
Simple Electronic Signature
Typed name, scanned signature, click on approve. Low evidential weight, but sufficient for many internal records when the system provides the GxP controls.
2
Advanced Signature (AdES)
Uniquely linked to the signatory, created under their sole control, subsequent changes detectable. Technically a digital signature with a certificate.
3
Qualified Signature (QES)
AdES plus a qualified certificate from an audited trust service provider and a secure signature creation device. Legally equivalent to a handwritten signature.

What Part 11 and Annex 11 Require of a Signature

Regardless of the eIDAS tier, the GxP rules place their own requirements on every electronic signature.

  • Signature manifestation: The signed record shows the signatory's full name, date and time, and the meaning of the signature, such as created, reviewed or approved.
  • Inseparable link: Signature and record are bound together so the signature cannot be copied or transferred to another document.
  • Two components: The first signing of a session uses at least two identification components, for example user ID and password.
  • Unique identity: Each signature belongs to exactly one person. Shared accounts and passed-on passwords break attributability, one of the core principles of ALCOA+.
  • Audit trail: The act of signing and every change to the record are logged and remain reconstructable throughout the retention period.

Whether your system meets these points is shown in a first self-assessment by our Part 11 Check; for EU systems the Annex 11 Check adds the European perspective.

Regulatory or Technical: Two Different Questions

Hardly any question reaches us more often in consulting than this one: are user name and password enough to execute a Part 11 compliant signature? The answer is: yes. In § 11.200(a), Part 11 explicitly permits electronic signatures without biometrics and without a certificate, provided they consist of at least two distinct components, for example user ID and password. The first signing of a session uses both components, every subsequent signing within the same session at least one. Added to this are the controls of § 11.300: the combination is uniquely assigned to one person, is periodically reviewed, and there are deactivation and replacement processes for lost or compromised passwords.

The confusion arises because two different questions get mixed up.

  • The regulatory question (Part 11, Annex 11): Under which controls is a signature valid in GxP records? What counts here are unique identity, two-component sign-on, signature manifestation, inseparable linking and the audit trail. Cryptography is not a condition.
  • The technical question (eIDAS): How strongly does the signature prove in court who signed? What counts here are certificates, keys and trust service providers. A user name and password signature is only a simple electronic signature in this world, with low evidential weight.

Both levels are independent of each other. A user name and password signature in a validated LIMS is Part 11 compliant, but weak under civil law. Conversely, a QES with a signature card does not automatically make a record GxP compliant: if the meaning of the signature or the audit trail is missing, it remains a finding. The rule of thumb for practice: Part 11 and Annex 11 govern the controls around the signature, eIDAS governs the evidential strength of the signature technology. For internal GxP records the first question decides, for contracts and documents with external effect the second one as well.

Which Signature Tier for Which Use Case?

The right tier follows from risk and legal framework, not from what is technically possible. Proven mapping from our projects:

  • Internal GxP records such as batch release in the MES, test results in the LIMS or SOP approvals in document management: simple or advanced signature in a validated system; the Part 11 and Annex 11 controls are what matters.
  • Documents with external effect such as quality agreements, supplier contracts or employment contracts: advanced signature, and a qualified signature where written form is required by law or the amount in dispute is high.
  • Communication with authorities and submission documents: check the requirements of the respective authority; some prescribe portals with their own authentication.

Typical Findings from Audits and Inspections

  • The meaning of the signature is missing: the system shows name and date, but not whether the record was reviewed or approved.
  • Printouts of electronically signed documents circulate as supposed originals, unmarked and without reference to the electronic record.
  • Signature workflows run through shared mailboxes or passed-on accounts; attributability is broken.
  • The signature service was never assessed: no supplier assessment, no verification, no SOP.
  • Signed PDF documents sit on file shares without access control and without protection against substitution.

What You Get

We support you from strategy to validated operation.

  • Inventory of all signature use cases with the appropriate signature tier assigned
  • Gap analysis of existing systems against Part 11, Annex 11 and eIDAS
  • Selection and assessment of signature services including supplier assessment
  • Validation documentation: risk analysis, test plans, verification of the signature manifestation
  • SOP drafts for signature workflows, hybrid processes and archiving, DE and EN

FAQ: Electronic Signatures in GxP

What is the difference between an electronic and a digital signature?
Electronic signature is the legal umbrella term for any electronic declaration of intent, from a typed name to a qualified signature. Digital signature describes the cryptographic technique behind it: a hash of the document is encrypted with a private key. Advanced and qualified electronic signatures use digital signatures as their technology.
Are user name and password enough for a Part 11 compliant signature?
Yes. In § 11.200(a), Part 11 permits electronic signatures made of two identification components such as user ID and password: both components for the first signing of a session, at least one for subsequent signings. The prerequisite are the controls of § 11.300, such as the unique assignment of the combination to exactly one person and deactivation processes for lost credentials. Part 11 does not require certificates or signature cards; those are a matter of eIDAS evidential weight, not of GxP compliance.
Is a simple electronic signature sufficient for GxP documents?
For many internal GxP records yes, provided the system meets the requirements of 21 CFR Part 11 and EU GMP Annex 11: unique user identification, two-component sign-on, inseparable linking to the record and a complete signature manifestation. The eIDAS tier is a separate civil-law question and matters mainly for contracts and external documents.
When do I need a qualified electronic signature (QES)?
Whenever the law requires written form or the litigation risk is high, for example for certain contracts. Within GxP documentation neither Part 11 nor Annex 11 requires a QES; what counts there are system controls, attributability and the audit trail.
Do DocuSign, Adobe Sign and similar services need to be validated?
Yes, as soon as GxP-relevant documents are signed with them. The service is assessed like any computerised system on a risk basis: supplier assessment, configuration review, verification of the signature manifestation and of the link between signature and document, plus defined processes for user management and archiving.
Are hybrid processes with paper and electronic signatures permitted?
Yes, but they need clear rules: which document is the original, how printouts of electronically signed documents are marked, and how the link between signature and record is preserved. Undefined hybrid processes are among the most frequent findings in inspections.

Next Step: Assess Your Signature Workflows

Tell us your use cases and the tools in place. We will propose signature tiers, assessment scope and sequence.

Get in touch