{
  "id": 13604168,
  "title": "21 CFR Part 11 is where 'approve by email' shops quietly fail — a typed name is not a signature",
  "url": "https://urgent.news/2026/10/11/21-cfr-part-11-is-where-approve-by-email-shops-quietly-fail-a-typed",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-11T01:24:09.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jwithfield_qa/21-cfr-part-11-is-where-approve-by-email-shops-quietly-fail-a-typed-name-is-not-a-signature-500p"
  },
  "original_language": "en",
  "account": "21 CFR Part 11 compliance is a critical requirement for electronic records, but many organizations fall short by treating email approvals as valid signatures. In a recent CAPA audit, a four-message email thread was found to be insufficient evidence. The signer typed their name, and there was no binding proof that the document's version and meaning were correctly captured. An email inbox is not a closed system; attachments can be overwritten, threads pruned, and replies may not link to a specific file version. To meet Part 11 standards, the signature must meet stringent criteria: unique to the individual, two distinct identification components, first-time signing with identity verification, a printed name, date, time, and signature meaning, and permanent linking to the record with a secure, computer-generated audit trail. Many organizations continue to rely on email approvals because they are already part of their workflow and can be authenticated through SSO. However, this approach is easily forgeable and lacks the necessary security controls. A compliant e-signature workflow involves logging into the Quality Management System (QMS) with unique credentials, opening the document version under review, and capturing the signer's name, meaning, and server-side timestamp. The signature and document must be permanently linked, and any subsequent changes must trigger a new approval cycle. The evidence should reside within the same system as the document, with an audit trail readily accessible to auditors.",
  "summary": "The CAPA that taught me what an email isn't Two years ago I inherited a CAPA queue that included a finding from our prior notified body audit. The wording was polite but unambiguous: \"The approval records for the post-market surveillance report could not be verified against a Part 11-compliant system.\" I went looking. The approval record was a four-message email thread. The approver had typed…",
  "key_points": [
    "21 CFR Part 11 requires stringent e-signature criteria",
    "Email approvals insufficient for valid signatures",
    "Compliant workflow involves QMS login and server-side timestamp"
  ],
  "editors_take": "Relying on email approvals with typed names as valid signatures leaves organizations vulnerable to non-compliance with 21 CFR Part 11, as this approach lacks necessary security controls and is easily forgeable.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}