Data Integrity and Compliance

Electronic Signature

Last updated:
October 3, 2026

TL;DR

An electronic signature is data in electronic form, usually a user ID and password, that a person executes or adopts to sign a record with the same legal intent as a handwritten signature. In FDA-regulated labs, 21 CFR Part 11 sets the conditions these signatures have to meet before they count.

What is an electronic signature?

An electronic signature is a computer data compilation of any symbol or series of symbols that a person executes, adopts, or authorizes to be the legally binding equivalent of their handwritten signature. That is close to the wording of the definition in section 11.3 of 21 CFR Part 11. In a lab it usually means typing your user ID and password at the moment you sign a notebook entry, approve an SOP, or release a result.

The legal weight comes from intent and linkage. The signer has to mean it, and the signature has to stay attached to the record it signs. In the US, the ESIGN Act of 2000 gives electronic signatures general legal standing in commerce, and Part 11 adds the specific controls FDA expects for records required by its predicate rules, such as GLP and GMP. In the EU, the eIDAS Regulation (EU) No 910/2014 sets out three levels: simple, advanced, and qualified electronic signatures.

An electronic signature is often confused with a digital signature. A digital signature is one specific technology, cryptographic signing with a private key and a certificate issued by a certificate authority, known as PKI. Every digital signature is a type of electronic signature, but most electronic signatures in lab software are not digital signatures. And a scanned image of a handwritten signature pasted into a PDF is neither, at least in the Part 11 sense, because nothing ties it to a verified identity or to the record.

What makes an electronic signature count under Part 11?

Picture a research associate finishing an ELISA run late on a Thursday. The plate reader export is attached, the standard curve looks clean, and she signs the entry with her credentials. The system records who signed, when, and what the signature means. From that point the entry is the signed version, and any later change shows up as a change.

Part 11 spells out what that signing event needs, mostly in Subpart C plus two sections of Subpart B:

  • Section 11.50: the signed record shows the printed name of the signer, the date and time of signing, and the meaning of the signature, such as review, approval, responsibility, or authorship.
  • Section 11.70: signatures are linked to their records so they cannot be removed, copied, or transferred to falsify another record.
  • Section 11.100: each electronic signature is unique to one person and never reused or reassigned, and the organization verifies the person's identity before issuing it.
  • Section 11.200: signatures that are not biometric use at least two distinct identification components, such as an ID code and a password.

Section 11.200 also covers signing a stack of records in one sitting. The first signing in a continuous session uses all components, and later signings in the same session can use at least one component, as long as only the genuine owner can use it. Section 11.300 adds controls on the ID codes and passwords themselves, including periodic checks and procedures for lost credentials.

Then there is the administrative step people forget. Under section 11.100(c), an organization using electronic signatures for FDA-regulated records certifies to the agency, in a letter, that it intends those signatures to be the legally binding equivalent of handwritten ones.

Where do electronic signatures go wrong?

Most often at the account level. A shared lab login that three technicians use to sign off instrument runs breaks the uniqueness requirement in section 11.100, and so does a supervisor signing on behalf of someone on leave. Inspectors look for exactly these, because afterwards nobody can say who actually approved the record.

To check your own setup, list the records your lab signs today, such as notebook entries, SOP approvals, deviation reports, and reagent release, and write down what each signature means, because Part 11 expects the meaning to appear with the signature. Check each system against the uniqueness, linkage, and two-component rules above. Shared accounts are usually the first thing to go. Then come the procedures: an SOP for how signing accounts are issued and revoked, a policy that makes people accountable for actions taken under their signatures and, for FDA-regulated work, the certification letter. Part 11 compliance for your studies depends on these procedures and on your own validation, so the software is only one part of it.

Electronic signatures are a regulatory requirement only when a lab uses them in place of handwritten signatures on records covered by FDA predicate rules, for example in studies conducted under GLP or in GMP manufacturing. A university lab doing discovery work has no Part 11 obligation. But a signed, locked entry still settles practical questions later, like which version of a protocol was approved before a grant report or a patent filing.

In IGOR, notebook entries and SOPs are signed with electronic signatures compliant with 21 CFR Part 11. The author signs an entry in the electronic lab notebook and then assigns witnesses, and approved entries are permanently locked. Signing in IGOR takes the signer's initials and account password. The SOP Generator uses the same signing for its review and approval workflow, with the number of required approvals set by a Super Admin, and every signing step is recorded in the audit trail.

Frequently asked questions

Is an electronic signature legally equivalent to a handwritten signature?

Yes, when the signer intends it and the controls are in place. In the US, the ESIGN Act gives electronic signatures general legal effect, and 21 CFR Part 11 sets the conditions FDA applies to regulated records. In the EU, eIDAS gives a qualified electronic signature the same legal effect as a handwritten signature.

What is the difference between an electronic signature and a digital signature?

An electronic signature is any electronic means of signing with legal intent, while a digital signature is a specific cryptographic method based on public and private keys and certificates. Part 11 accepts electronic signatures that meet its controls and does not require PKI, and most ELN and LIMS platforms use credential-based electronic signatures.

Does a scanned signature count as an electronic signature under Part 11?

Not on its own, because nothing verifies who placed the image or links it to the record. Part 11 does treat a signature written with a pen or stylus as a handwritten signature, but that covers the act of signing, not an image pasted into a file afterwards. If the record needs an electronic signature, it has to come from a controlled signing process.

Can two people share one login to sign lab records?

No. Part 11 requires each electronic signature to be unique to one individual and never reused by or reassigned to anyone else. With a shared login nobody can prove who signed, which is one of the most common data integrity findings in inspections.

Do academic labs need Part 11 compliant electronic signatures?

Only for records that support FDA submissions, such as nonclinical studies conducted under GLP. For most basic research, signed and locked entries are good practice for reproducibility and intellectual property, but not a legal requirement.

Related terms

References

  1. 21 CFR Part 11, Electronic Records; Electronic Signatures (eCFR)
  2. FDA, Part 11, Electronic Records; Electronic Signatures: Scope and Application (August 2003)
  3. Regulation (EU) No 910/2014 (eIDAS) on electronic identification and trust services
  4. Electronic Signatures in Global and National Commerce Act (ESIGN), Public Law 106-229 (2000)

This page is a general overview for lab scientists. It is not formal compliance or legal advice, and the requirements that apply to your lab depend on your regulated activities, your predicate rules, and your own validated processes.