Our services for digital signatures
Cloud services such as DocuSign, Adobe Acrobat Sign or d.velop sign provide the signature technology, but not your GxP responsibility. As soon as GxP-relevant documents are signed, the service counts as a computerised system and is qualified and validated on a risk basis: supplier assessment, review of the signature manifestation, verification of the link between signature and document, user and permissions concept, and rules for export and archiving of signed documents across the full retention period.
Methodically the assessment follows our approach from Computer System Validation (CSV); for pure configuration products we work risk-based along CSA principles.
Clarify scope?
Book an intro callLeistungs-Wegweiser
Welche Ausgangslage beschreibt Ihr Vorhaben?
Wählen Sie die Ausgangslage. Sie erhalten einen fokussierten Startpunkt mit Vertiefungen und Kontaktweg.
Vom Erstgespräch zum Plan
Wir klären Umfang, Rollen, Risiken und regulatorischen Rahmen und schlagen einen belastbaren Fahrplan vor.
Finding schließen
Root Cause, CAPA und Nachweise strukturiert aufbauen und QA-Abschluss vorbereiten.
Programm statt Einzelprojekt
PMO, Change Control und einheitliche Vorlagen über viele parallele Vorhaben hinweg.
In everyday language both terms are mixed up; legally and technically they mean different things. The electronic signature is the legal umbrella term: any form in which a person declares their intent electronically, from a typed name under an email to a signature card. The digital signature is the cryptographic technique behind it: a hash of the document is encrypted with the signatory's private key, and any later change to the document invalidates the signature.
Our approach in GxP projects: from planning through release – each step delivers evidence you can present in QA review and audit. View GxP consulting in five steps
Electronic or Digital: What Is the Difference?
In everyday language both terms are mixed up; legally and technically they mean different things. The electronic signature is the legal umbrella term: any form in which a person declares their intent electronically, from a typed name under an email to a signature card. The digital signature is the cryptographic technique behind it: a hash of the document is encrypted with the signatory's private key, and any later change to the document invalidates the signature.
In practice this means: advanced and qualified electronic signatures use digital signatures as their technology. A scanned handwritten signature or a typed name, by contrast, is only a simple electronic signature without cryptographic protection.
Two Regulatory Worlds, One Workflow
Anyone signing electronically in pharma, medical devices or the food industry has to reconcile two independent sets of rules.
- GxP world: 21 CFR Part 11 governs electronic records and signatures for the US authorities, EU GMP Annex 11 the computerised systems in the EU. The focus is attributability, audit trail and the link between signature and record.
- EU civil law: The eIDAS regulation (EU) No 910/2014 defines three tiers of electronic signatures and governs their legal effect in the single market, including the equivalence of the qualified signature with handwriting.
A signature workflow can be Part 11 compliant and still weak under civil law, and vice versa. That is why we assess both levels together.
The Three eIDAS Tiers at a Glance
What Part 11 and Annex 11 Require of a Signature
Regardless of the eIDAS tier, the GxP rules place their own requirements on every electronic signature.
- Signature manifestation: The signed record shows the signatory's full name, date and time, and the meaning of the signature, such as created, reviewed or approved.
- Inseparable link: Signature and record are bound together so the signature cannot be copied or transferred to another document.
- Two components: The first signing of a session uses at least two identification components, for example user ID and password.
- Unique identity: Each signature belongs to exactly one person. Shared accounts and passed-on passwords break attributability, one of the core principles of ALCOA+.
- Audit trail: The act of signing and every change to the record are logged and remain reconstructable throughout the retention period.
Whether your system meets these points is shown in a first self-assessment by our Part 11 Check; for EU systems the Annex 11 Check adds the European perspective.
Regulatory or Technical: Two Different Questions
Hardly any question reaches us more often in consulting than this one: are user name and password enough to execute a Part 11 compliant signature? The answer is: yes. In § 11.200(a), Part 11 explicitly permits electronic signatures without biometrics and without a certificate, provided they consist of at least two distinct components, for example user ID and password. The first signing of a session uses both components, every subsequent signing within the same session at least one. Added to this are the controls of § 11.300: the combination is uniquely assigned to one person, is periodically reviewed, and there are deactivation and replacement processes for lost or compromised passwords.
The confusion arises because two different questions get mixed up.
- The regulatory question (Part 11, Annex 11): Under which controls is a signature valid in GxP records? What counts here are unique identity, two-component sign-on, signature manifestation, inseparable linking and the audit trail. Cryptography is not a condition.
- The technical question (eIDAS): How strongly does the signature prove in court who signed? What counts here are certificates, keys and trust service providers. A user name and password signature is only a simple electronic signature in this world, with low evidential weight.
Both levels are independent of each other. A user name and password signature in a validated LIMS is Part 11 compliant, but weak under civil law. Conversely, a QES with a signature card does not automatically make a record GxP compliant: if the meaning of the signature or the audit trail is missing, it remains a finding. The rule of thumb for practice: Part 11 and Annex 11 govern the controls around the signature, eIDAS governs the evidential strength of the signature technology. For internal GxP records the first question decides, for contracts and documents with external effect the second one as well.
Which Signature Tier for Which Use Case?
The right tier follows from risk and legal framework, not from what is technically possible. Proven mapping from our projects:
- Internal GxP records such as batch release in the MES, test results in the LIMS or SOP approvals in document management: simple or advanced signature in a validated system; the Part 11 and Annex 11 controls are what matters.
- Documents with external effect such as quality agreements, supplier contracts or employment contracts: advanced signature, and a qualified signature where written form is required by law or the amount in dispute is high.
- Communication with authorities and submission documents: check the requirements of the respective authority; some prescribe portals with their own authentication.
Typical Findings from Audits and Inspections
- The meaning of the signature is missing: the system shows name and date, but not whether the record was reviewed or approved.
- Printouts of electronically signed documents circulate as supposed originals, unmarked and without reference to the electronic record.
- Signature workflows run through shared mailboxes or passed-on accounts; attributability is broken.
- The signature service was never assessed: no supplier assessment, no verification, no SOP.
- Signed PDF documents sit on file shares without access control and without protection against substitution.
What You Get
We support you from strategy to validated operation.
- Inventory of all signature use cases with the appropriate signature tier assigned
- Gap analysis of existing systems against Part 11, Annex 11 and eIDAS
- Selection and assessment of signature services including supplier assessment
- Validation documentation: risk analysis, test plans, verification of the signature manifestation
- SOP drafts for signature workflows, hybrid processes and archiving, DE and EN
FAQ: Electronic Signatures in GxP
eSignature reference projects
Annex 11 and Part 11 relevant systems from CSV and IT programmes.
eSignature
SYSPRO Annex 11
Canadian pharma manufacturer, new site in Germany: AI-assisted CSV with significantly reduced effort.
View case story
eSignature
Periodic review
Up to 600 change requests per year: annual Q1 close-out in human pharma production.
View case story
eSignature
ESSV sample management
Validated spreadsheets for lab inventory and temperature loggers with audit trail and AD integration.
View case story