Urgent.News

What's breaking now, across thousands of outlets.

Tech

21 CFR Part 11 is where 'approve by email' shops quietly fail — a typed name is not a signature

The CAPA that taught me what an email isn't Two years ago I inherited a CAPA queue that included a finding from our prior notified body audit. The wording was polite but unambiguous: "The approval records for the post-market surveillance report could not be verified against a Part 11-compliant system." I went looking. The approval record was a four-message email thread. The approver had typed…

21 CFR Part 11 compliance is a critical requirement for electronic records, but many organizations fall short by treating email approvals as valid signatures. In a recent CAPA audit, a four-message email thread was found to be insufficient evidence. The signer typed their name, and there was no binding proof that the document's version and meaning were correctly captured.

An email inbox is not a closed system; attachments can be overwritten, threads pruned, and replies may not link to a specific file version. To meet Part 11 standards, the signature must meet stringent criteria: unique to the individual, two distinct identification components, first-time signing with identity verification, a printed name, date, time, and signature meaning, and permanent linking to the record with a secure, computer-generated audit trail.

Many organizations continue to rely on email approvals because they are already part of their workflow and can be authenticated through SSO. However, this approach is easily forgeable and lacks the necessary security controls. A compliant e-signature workflow involves logging into the Quality Management System (QMS) with unique credentials, opening the document version under review, and capturing the signer's name, meaning, and server-side timestamp.

The signature and document must be permanently linked, and any subsequent changes must trigger a new approval cycle. The evidence should reside within the same system as the document, with an audit trail readily accessible to auditors.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Your seed data is lying to you — the case for foreign-key-consistent test data

Here's a bug I've shipped more than once: tests pass locally, demo looks great, then something breaks the moment real relational data shows up.

  • Seed data with foreign keys fails when real relational data introduced.
  • Faker-style tools generate values in isolation, not considering relationships.
  • Automating data generation ensures foreign keys point to existing records.

Hreflang for SaaS Docs: Test the Language Pair Before Shipping More Pages

For hreflang multilingual SEO, test a complete pair of equivalent pages before expanding to more languages. Check the English page, its French counterpart, and the annotations on both.

  • Test language pairs (English, French) before expanding hreflang for SaaS docs
  • Verify hreflang rules, language/region codes, and run QA checks for English/French outputs

More from Sunday 11 October →