You are on page 1of 4

21 CFR PART-11 REQUIREMENT

Page 1 of 27
21 CFR PART-11 REQUIREMENT

MANDIDEEP

Sr. No. Requirement Description


The system should provide viewing & printing capabilities for all relevant e-records.
1.

2. The system should allow for the export of e-records to portable file formats.

The system should have implemented a mechanism for backup of e-records.


3.
The system should have at least two distinct identification components (e.g. User ID / password)
4.
System should have facility to create, deactivate the individual account with different user levels (like operator, supervisor, maintenance,
5.
manager etc.)

6. The system should provide a mechanism to lock out/ interrupt access of any user after a configurable period of non-attendance/ non-
interaction with the system. Auto logout in idle condition after specific time.

7. Upon auto log off system should ask for re-login with user ID and password.

8.
Password entries field must be hidden.(e.g. "*********").

9. The number of character of password should be as per password as per our company policy (e.g. 8-Character minimum, alphanumeric).

10. The system should provide the secured, computer-generated audit trails for e-records, they must be enabled.

Page 2 of 27
21 CFR PART-11 REQUIREMENT

MANDIDEEP

System audit trails should contain information about:


- Person performing the activity (WHO)
- Date and time of its execution (WHEN)
11.
- What was changed/ done(WHAT)
- The reason for the activity (WHY)
Backup of audit trail should be available

12. System clock time should be easy to synchronize with our standard server time.

Time & date settings should be subject to rigorous/precise control to ensure the accuracy of time stamps, the computerized system should
13.
provide the ability to restrict access to time settings. Users should not be able to change time & date settings.

14.
The ability to change computer generated audit trails must be restricted.

Operational system checks to enforce the execution of operations according to the predefined order. Execution of operation should be in
15. auto mode as per recipe loaded. And recipe should be restricted to authorized user only.

16. Records which are automatically captured by system (e.g. process data ) must not be modified. Report should have user name printed
on it who has executed the test.

17. System should be able to generate electronic record in human readable form with the full name (at least name & surname) of the signer,
date and time of the application of the signature and meaning of the signature are displayed or print.

18. The system must not accept duplicate user accounts i.e. It should be unique to an individual.

Page 3 of 27
21 CFR PART-11 REQUIREMENT

MANDIDEEP

19. The system should support password-aging processes as per our company policy. User ID & Password should be locked after password
expiry get overdue.

The system is able to lock a user account after a specified number of failed access attempts (As per our IT policy).
20.

21. The system should be able to log unauthorized access attempts.

Alarm reports should have Date, time of alarm generation, alarm normal time, alarm ack. time, and alarm ack. by user name.
22.
Alarm list should be filterable by critical/process alarm, safety alarm, and maintenance alarm.

23. Ensure the communication mode of system i.e. LAN, RS 485, USB etc.

Page 4 of 27

You might also like