A SCADA system can control a process flawlessly and still fail an FDA inspection. The reason is that 21 CFR Part 11 does not ask whether the automation works. It asks whether the electronic records the system produces can be trusted, whether they are attributable to a person, protected from change, and complete. A 21 CFR Part 11 compliant SCADA is one that can prove all three.
This guide sets out what the regulation actually requires, where automation projects commonly leave gaps, and what to verify before you accept a system. It is written for QA managers and validation leads reviewing or specifying plant automation, and for the project engineers who have to deliver against their requirements.
What 21 CFR Part 11 actually governs
21 CFR Part 11 is the FDA regulation covering electronic records and electronic signatures. It sits on top of the predicate GMP rules. Where GMP requires a record to exist, Part 11 sets the conditions under which that record can be created, kept, and signed electronically instead of on paper.
The underlying question is simple to state and hard to fake: can you demonstrate that an electronic record is genuine, complete, and unaltered, and that the person who created or approved it is who the record says it is? If that cannot be shown, the record is not compliant, however well the process ran. Part 11 is not a feature you switch on. It is a combination of system capability, procedure, and validation.
Audit trails, the heart of it
A compliant SCADA records who did what and when, automatically, in a secure and time-stamped log that operators cannot switch off or overwrite. Every relevant action is captured with the user identity and timestamp: a setpoint change, a batch start, an alarm acknowledgement, a manual override.
This is what makes falsified production or temperature data detectable. An operator cannot quietly lower a temperature setpoint or backdate an entry without the system recording it against their name. The audit trail has to be retained for as long as the record it belongs to, and be available for review and copying during an inspection.
Access control and electronic signatures
Trust in a record depends on knowing exactly who acted. That requires unique user IDs with no shared logins, and authority checks so that only the people permitted to perform an action can perform it.
Electronic signatures must be uniquely linked to a single individual and to the specific record, and cannot be reused or transferred. When a record is signed, it has to show the signer’s name, the date and time, and the meaning of the signing, whether that is review, approval, or responsibility. A signature that does not carry that context is not a compliant signature.
The requirements teams forget
Audit trails and signatures get the attention. These are the ones that surface late in a project, often at inspection.
- Accurate, complete copies of records, both readable and electronic, that can be produced for review without losing data or metadata.
- Record retention and protection across the full retention period, so records remain accurate and retrievable years later.
- System validation to confirm accuracy and reliability, and the ability to discern when a record has been altered.
- Controls over system access, device checks, and the documentation for operating and maintaining the system.
Why compliance cannot be bolted on afterwards
A general automation integrator can build a SCADA that runs the process correctly and still leaves the audit trail, access model, and validation gaps that fail an inspection. Those gaps are not visible when the line is producing. They appear when an auditor asks to see the record and the trail behind it.
Retrofitting audit trails and access controls into a live system is expensive, disruptive, and forces re-validation. GAMP 5 is the framework that structures how these systems are specified, built, and validated across their lifecycle. A vendor working to GAMP 5 designs the compliance in from the user requirement specification rather than patching it in after the fact.
How Esteril builds automation for regulated lines
Esteril builds pharmaceutical automation with IPC and SCADA to 21 CFR Part 11, delivered to GAMP 5 guidelines. Systems include electronic batch records, audit trails, backup, and HMI or IPC for centralised control, on a PLC and SCADA open solution. Esteril works with Siemens, Schneider, Allen Bradley, and Mitsubishi, and delivers the validation lifecycle with DQ, IQ, OQ, and PQ documentation, so the compliance evidence is in place when QA needs it.
What to require in a 21 CFR Part 11 compliant SCADA
If you are writing or reviewing the specification, these are the points where a functional system and a compliant one diverge.
| Requirement | What it means | What to verify |
|---|---|---|
| Audit trail | Secure, time-stamped, computer-generated log of every relevant action | It cannot be disabled or edited, and is retained with the record |
| Access control | Unique user IDs and authority checks | No shared logins; permissions match role and responsibility |
| Electronic signatures | Signatures linked to one individual and to the record | Name, date, time, and meaning are shown; a signature cannot be reused |
| Record copies | Readable and electronic copies available for inspection | Export and print without losing data or metadata |
| Validation | Documented DQ, IQ, OQ, and PQ | Evidence the system performs as intended and can flag altered records |
| Framework | Built to GAMP 5 | Compliance designed in from the specification, not patched later |
Frequently asked questions
Is 21 CFR Part 11 the same as GMP?
No. The GMP predicate rules require the records to exist. 21 CFR Part 11 sets the conditions for keeping and signing those records electronically. A compliant plant needs both, and Part 11 only comes into play because a GMP record is being kept electronically.
Does Part 11 apply if we just export data to a spreadsheet?
If an electronic record is used to satisfy a GMP requirement, Part 11 applies to how it is created, protected, and signed. Exporting critical data into an uncontrolled spreadsheet, where it can be edited without a trail, is one of the most common compliance gaps.
Can we make an existing SCADA compliant?
Sometimes, but retrofitting audit trails, access control, and validation into a live system is costly and usually needs re-validation. It is consistently cheaper and cleaner to specify compliance from the start than to correct it later.
