Skip to contact

Authority checks under Part 11: §11.10(g) in practice

What the clause actually requires

21 CFR §11.10(g) requires the use of authority checks to ensure that only authorized individuals can use the system, electronically sign a record, access the operation or computer system input or output device, alter a record, or perform the operation at hand. 21 CFR §11.10(g)

Its neighbour, §11.10(h), requires device checks — determining, as appropriate, the validity of the source of data input or operational instruction. Authority checks are about who; device checks are about where the data came from. 21 CFR §11.10(h)

FDA's 2003 scope-and-application guidance narrowed enforcement in several Part 11 areas — validation, audit trails, record retention, record copying — but the access and authority controls were not among them and remain fully enforced. FDA Guidance for Industry: Part 11, Electronic Records; Electronic Signatures — Scope and Application (August 2003)

What this looks like as evidence

  • A permissions matrix: which role may do which operation, on which record type
  • Named accounts only — attribution dies with a shared login
  • Periodic access review, recorded: who checked, when, what was removed
  • A record of every grant and revocation, tied to a request or a leaver process
  • Separation between authorizing an action and performing it, where the risk warrants it

The inspection question is rarely whether the system has roles — every modern system does. It is whether you can show that the permissions in production match the matrix on paper, and who last verified that. A permissions export with a review signature answers it; a screenshot of the admin panel does not.

Frequently asked questions

What is the difference between authority checks and device checks?

Authority checks (§11.10(g)) verify the person: only authorized individuals may use the system, sign, alter records or perform an operation. Device checks (§11.10(h)) verify the source: that data or an instruction came from a valid terminal or device. One is about identity and permission, the other about origin. 21 CFR §11.10(g); §11.10(h)

Are shared accounts acceptable in a regulated system?

Not where records or signatures are involved: a shared login makes actions unattributable, which defeats the authority check and collides with the requirement that electronic signatures be unique to one individual and not reused or reassigned. 21 CFR §11.10(g); §11.100(a)

Did FDA's enforcement discretion relax access controls?

No. The 2003 guidance applied discretion to validation, audit trails, retention and copying — access and authority controls stayed outside it and are among the most frequently cited clauses in practice. FDA Guidance: Part 11 — Scope and Application (August 2003)