FDA E-Signatures: What You Actually Need to Know (And What You Don't)
E signatures FDA rules confuse a lot of business professionals, and honestly, most of what's out there makes it worse. Either you get the dense text of 21 CFR Part 11 itself, or you get a thin summary that skips the hard parts. You don't need either. You need to know what the FDA actually requires, when those rules apply to the documents you're signing, and which parts of the regulation you can safely ignore. That's what this guide does. It translates Part 11 into plain English, states plainly what you cannot do with FDA e-signatures, and walks through a vendor-neutral checklist you can use to evaluate any signing tool. LoreSign is one option that handles compliant signing without the regulatory noise, but you'll see exactly what to look for regardless of what you use. This guide covers the real requirements, the legal backdrop, the documents that still need ink, and the honest answer on whether tools like DocuSign are compliant out of the box.
| At a glance | Details |
|---|---|
| Who it applies to | FDA-regulated records under 21 CFR Part 11 |
| Core rule | 21 CFR Part 11 for electronic records and signatures |
| Key requirement | Signed, attributed, and linked to the record |
| System validation | Required for Part 11 scope; not for routine contracts |
| FDA pre-approval | None; FDA does not certify e-signature tools |
| Everyday contracts | ESIGN and UETA govern, not Part 11 |
In This Guide
- What Is an FDA E-Signature?
- FDA Part 11 vs. Everyday E-Signature Rules
- 21 CFR Part 11 Requirements for E-Signatures
- E Signatures Fda: A Step-by-Step Guide
- Legal Requirements for Electronic Signatures
- What Documents Cannot Be Electronically Signed?
- What You Cannot Do with FDA E-Signatures
- How to Choose an FDA-Compliant E-Signature Tool
- Is DocuSign 21 CFR 11 Compliant?
- The Bottom Line on E Signatures FDA Compliance
What Is an FDA E-Signature?
An FDA e-signature is any electronic mark — a typed name, a drawn signature, a checked box — that a person executes or adopts to sign an FDA-regulated record, and that carries the same legal weight as a handwritten signature.
In practice, it's the same e-signature you'd use on a contract or consent form. What makes it an "FDA e-signature" is the context: the document falls under FDA rules, so the signature must meet 21 CFR Part 11.
Electronic signature vs. digital signature
An electronic signature is the act of signing. A digital signature is the technology underneath: encryption that locks the document and proves it hasn't changed. You can have an electronic signature without a digital signature. Part 11 requires the electronic signature; it doesn't mandate a specific digital signature algorithm.
Where 21 CFR Part 11 applies
Part 11 applies to records that FDA regulations require you to keep or submit electronically. That covers clinical trial data, drug manufacturing logs, and certain regulatory submissions. It doesn't apply to every document a pharma company signs — an internal memo or an office lease isn't an FDA record.
The FDA does not pre-approve or certify e-signature vendors. Compliance depends on how you configure, validate, and use the system for your specific records.
FDA Part 11 vs. Everyday E-Signature Rules
| Factor | 21 CFR Part 11 | ESIGN / UETA |
|---|---|---|
| Applies to | FDA-regulated records and submissions | General commercial and personal documents |
| System validation | Required for Part 11 scope | Not required |
| Audit trail | Required, with identity and timestamp | Recommended, not mandated by statute |
| Identity checks | Controls to ensure signer identity | Generally relies on signer attestation |
| Best fit | Life sciences and regulated workflows | Contracts, HR, real estate, and similar |
21 CFR Part 11 Requirements for E-Signatures
Part 11 doesn't tell you which software to buy. It tells you what your signing process must prove: that the right person signed, they meant to sign, and the record hasn't changed since. Four requirements carry most of the weight.
Unique user identification
Each signer needs an ID that belongs to them and no one else. That ID is tied to a password, a PIN, a biometric like a fingerprint, or a combination. The point isn't the technology. It's that you can prove who signed. Shared logins fail this requirement outright. If two people can sign under one account, you have no way to show which one actually did.
Signature manifestation
The signature has to appear in the record itself. That means the signed document shows the signer's name, the date and time, and what the signature means — approval, review, authorship. A signature that lives only in a database isn't enough. The person receiving the document has to see it.
Audit trails and record retention
Every signature event needs a timestamped, computer-generated log: who signed, when, and what they signed. That log can't be edited by the signer. You also need to keep the signed record and its audit trail for as long as the underlying predicate rule requires — often years, sometimes decades. Retention is part of compliance, not an afterthought.
System validation
You must have documented evidence that your e-signature system does what it claims. That means testing it, writing down the results, and keeping those records. Validation isn't a one-time event. When you change the system, you re-validate. The FDA doesn't inspect your tool. It inspects your validation records.
If your documents are routine contracts rather than FDA-regulated records, you likely do not need Part 11 validation. Focus on a tool with a clear audit trail, ordered routing, and automatic delivery of the signed PDF so your records stay complete.
E Signatures Fda: A Step-by-Step Guide
- Confirm the document is an FDA-regulated record under 21 CFR Part 11.
- Choose an e-signature tool that supports audit trails, signer identity, and record linking.
- Validate the system for your intended use and document the validation.
- Configure signer identity checks and ordered routing for multiple signers.
- Send the signing link and track each signer until completion.
- Retrieve the completed PDF and store the audit trail with the record.
- Review access controls, retention, and training on a regular schedule.
Legal Requirements for Electronic Signatures
Electronic signatures are legal across the US. Two federal laws set the baseline: the ESIGN Act and UETA. Part 11 sits on top of those for FDA-regulated records. It doesn't replace them. It adds requirements.
ESIGN Act and UETA basics
The ESIGN Act (2000) says an electronic signature can't be denied legal effect just because it's electronic. UETA is the state-level version, adopted by 47 states. Both require consent, attribution to the signer, and record retention. If a signature meets those tests, it holds up in court the same as ink.
How Part 11 adds requirements on top
Part 11 doesn't change whether your signature is legal. It changes what you must prove about it. ESIGN says the signature is valid. Part 11 says you also need unique user IDs, signature manifestation, audit trails, and system validation. For FDA-regulated records, meeting ESIGN alone isn't enough. You need both layers.
What Documents Cannot Be Electronically Signed?
Most documents can be e-signed. But not all. The exceptions fall into three buckets: documents that need a notary, documents where a predicate rule demands ink, and FDA-specific carve-outs.
Documents requiring notarization
A notary verifies identity in person and witnesses the signature. E-signatures don't remove that step. Some states now allow remote online notarization (RON), where the notary watches via video and applies an electronic seal. But traditional notarization still requires a wet signature in many jurisdictions. Wills, deeds, and certain affidavits often fall here. Check your state's rules before assuming an e-signature works.
Contexts where handwritten signatures are still required
Some agencies and courts simply haven't updated their rules. Certain court filings, immigration forms, and government paperwork still demand ink. The IRS accepts e-signatures on many forms now, but not all. If a form's instructions say "sign in blue ink," that's the rule. No e-signature tool overrides it.
FDA-specific exceptions
Part 11 doesn't force e-signatures on anyone. It only sets rules if you choose to use them. Some FDA contexts still expect handwritten signatures, particularly where predicate rules were written before electronic records existed. If a specific regulation says "signed" without defining electronic options, the agency may read that as ink. When in doubt, ask the reviewing division.
What You Cannot Do with FDA E-Signatures
Here's the part most vendor pages skip. FDA e-signatures don't make a document automatically compliant. They don't transfer responsibility to the software. And they don't come with an agency stamp of approval. You're still on the hook.
FDA does not pre-approve e-signature tools
The FDA doesn't certify, endorse, or approve e-signature software. No vendor can honestly claim their tool is "FDA-approved." What exists is 21 CFR Part 11, a regulation that sets requirements. Your system either meets those requirements in practice, or it doesn't. The agency doesn't run a compliance testing program. If a vendor says otherwise, walk away.
Compliance is your responsibility, not the vendor's
A tool can offer every Part 11 feature and still fail an inspection. Why? Because compliance lives in how you configure and use it. You set the password rules. You decide who gets access. You control whether audit trails stay intact. The vendor provides capabilities. You provide the compliant operation. When an FDA inspector asks for records, they're asking you, not your software provider.
Common misconceptions
Three myths show up constantly. First, that any e-signature is FDA-compliant. It isn't. A basic click-to-sign without authentication or audit trail fails Part 11. Second, that Part 11 applies to everything. It doesn't. It only covers records required by predicate rules. Third, that buying a compliant tool solves the problem. It doesn't. Configuration, training, and ongoing monitoring do the real work.
How to Choose an FDA-Compliant E-Signature Tool
You can't buy compliance off a feature list. You buy capabilities, then configure them. Here's the checklist to run against any vendor before you sign a contract.
Audit trail capabilities
The audit trail is your inspection record. It must capture who signed, what they signed, when, and every change made after signing. Ask whether the trail is tamper-evident and whether you can export it in a readable format. If the vendor can't show you a sample trail, that's your answer.
User authentication and identity verification
Part 11 requires unique user IDs and either passwords or biometrics. Check that the tool enforces individual accounts, not shared logins. Multi-factor authentication matters if signers access records remotely. Ask how the tool verifies a signer's identity at the moment of signing.
Signature manifestation
The signature must display in the record: printed name, date, time, and meaning. Confirm the tool attaches this information to the signed document itself, not just to a separate log.
Validation documentation
You need evidence the system works as intended. Ask the vendor for validation documentation: test scripts, IQ/OQ/PQ records, or a validation package. If they don't offer one, you'll be building it yourself.
Data retention and export
FDA records must stay readable for the retention period in the predicate rule. Check export formats. Can you pull signed PDFs and audit trails out in a non-proprietary format? LoreSign, for example, delivers the completed PDF with a certificate of completion and audit trail automatically. That covers the export question. Most tools don't.
Is DocuSign 21 CFR 11 Compliant?
The honest answer is it depends on how you configure it. DocuSign offers a Part 11 module, but the tool itself isn't compliant out of the box. You have to turn on the right settings and use them correctly.
What DocuSign offers for Part 11
DocuSign's Part 11 module adds signature manifestation, unique user identification, and audit trail features designed for FDA-regulated records. The module also supports the password and identity verification controls Part 11 requires. What it doesn't do is make your signing process compliant by itself.
Why configuration matters
Compliance lives in your setup, not the vendor's marketing page. You need to enable the Part 11 settings, assign unique accounts to each signer, and keep the audit trail for the full retention period. If someone signs with a shared login or you skip the audit trail export, the signature doesn't meet Part 11. The vendor can't fix that for you after the fact.
The Bottom Line on E Signatures FDA Compliance
E signatures FDA compliance isn't a product you buy. It's a process you run. The regulation tells you what to prove: who signed, that they meant to, and that nothing changed after. Your tool provides the capabilities. You provide the configuration, the training, and the records. Get those right and an FDA inspection is a paperwork exercise, not a crisis. Get them wrong and no vendor logo on your invoice saves you. The checklist above is your starting point. Run it against any tool you're considering, including LoreSign, and keep the audit trail exportable. That's the part most people skip until an inspector asks for it.
Frequently Asked Questions
What are the requirements for electronic signatures according to FDA 21 CFR Part 11?
Part 11 requires that electronic signatures be unique to one individual, verified before use, and linked to their electronic record with the signer's name, date, and time. Systems must include audit trails, access controls, and validation for the intended use. The rule applies to records the FDA regulates, not to every document a business signs.
What are the legal requirements for electronic signatures?
Outside FDA scope, the ESIGN Act and UETA generally require intent to sign, consent to do business electronically, and a record that can be retained and reproduced. The signature must be attributable to the signer and associated with the document. State law may add requirements for specific document types.
Is DocuSign 21 CFR 11 compliant?
DocuSign states that its platform can support Part 11 compliance when configured and validated appropriately for your use case. Compliance is not automatic: your organization must validate the system, set up identity checks and audit trails, and document your process. The same is true for any e-signature vendor, including LoreSign.
What documents cannot be electronically signed?
Some documents still require wet signatures or specific formalities, such as certain wills, adoption papers, and some court filings. In FDA scope, certain submissions or records may have specific signing requirements. Always check the governing rule or ask counsel for your document type.
Does the FDA approve e-signature software?
- The FDA does not certify or pre-approve e-signature vendors. It sets requirements in 21 CFR Part 11 and expects regulated organizations to validate their systems and maintain compliance. Vendor claims of 'FDA approval' should be treated with caution.
Do I need Part 11 compliance for ordinary business contracts?
Usually not. Part 11 applies to FDA-regulated records, so routine contracts, HR forms, and sales agreements typically fall under ESIGN and UETA instead. Those laws are far less prescriptive and do not require system validation.
How do I evaluate an e-signature tool for FDA-scope work?
Look for audit trails with signer identity and timestamps, access controls, record linking, and support for validation documentation. Confirm the tool can deliver the completed PDF automatically and retain records for your required period. Ask the vendor for their Part 11 support materials before you commit.
About LoreSign
LoreSign helps individuals and businesses create, send, sign, and track documents in one place. You can upload a PDF or create an agreement, add the required signing fields, send it to recipients, and automatically receive the completed document once everyone has signed.


