This is a ready-to-use assessment checklist for the electronic-record controls on a decentralized clinical trial (DCT) system, covering 21 CFR Part 11 and EU Annex 11. Run it per in-scope system (eConsent, ePRO/eCOA, wearable/sensor platform, televisit), because “the vendor is Part 11 compliant” is not an assessment; there is no inherently compliant product, only how you implement and validate one. Replace every <<FILL: ...>> placeholder. A filled specimen follows. This content is general educational reference, not legal or regulatory advice.
System under assessment
| Field | Entry |
|---|---|
| System / component | <<FILL: eConsent / ePRO / sensor / televisit>> |
| Vendor / hosting | <<FILL>> |
| GxP records held | <<FILL: consent records, diary entries, sensor streams>> |
| Predicate rule(s) | <<FILL: 21 CFR 50/56, ICH E6, etc.>> |
| Assessor / date | <<FILL>> |
Part 11 / Annex 11 control checklist
Mark Pass / Fail / NA with evidence for each.
| # | Control | Where it bites in DCT | Result | Evidence |
|---|---|---|---|---|
| 1 | Validation (11.10(a); Annex 11 p4) | Every in-scope system: risk-based validation evidence, current, with a release statement | ||
| 2 | Accurate copies (11.10(b)) | Human-readable and electronic copies of consent, ePRO, sensor data producible for inspection | ||
| 3 | Record protection and retrieval (11.10(c)) | Records retrievable through the full retention period, including after vendor exit; a documented exit/archival plan exists and is tested | ||
| 4 | Audit trail (11.10(e); Annex 11 s9) | Secure, computer-generated, time-stamped, independently reviewable; covers consent events, ePRO edits, sensor pairing | ||
| 5 | Authority checks / access (11.10(g); 11.300) | Role-based access, least privilege, periodic access review across site/participant/sponsor roles | ||
| 6 | Operational system checks (11.10(f)) | Sequencing enforced where required (e.g. entry windows, workflow order) | ||
| 7 | Signature meaning (11.50) | eConsent and investigator sign-offs show name, date/time, and meaning | ||
| 8 | Signature/record linking (11.70) | Signature bound to the exact ICF version; non-transferable | ||
| 9 | Signature uniqueness/identity (11.100/11.200/11.300) | Remote signer identity verified; credentials unique, not shared | ||
| 10 | Supplier / service management (Annex 11 s3) | Vendor assessed; quality agreement defines validation evidence, change notification, data segregation, and exit | ||
| 11 | Change control (Annex 11 s10) | Vendor updates to the production system are under sponsor-controlled change assessment | ||
| 12 | Data (Annex 11 s5/s6) | Data integrity checks on entry and transfer; accuracy checks where data is entered manually | ||
| 13 | Periodic evaluation (Annex 11 s11) | The validated state is reviewed on a risk-based schedule | ||
| 14 | Business continuity (Annex 11 s16) | Continuity plan for the records if the system is unavailable |
Part B: vendor reliance record
| Question | Entry |
|---|---|
| What vendor validation evidence was reviewed? | <<FILL>> |
| What did the sponsor re-test on the configured system? | <<FILL>> |
| Why is the reliance sufficient? | <<FILL>> |
| Residual gaps and actions | <<FILL>> |
Acceptance criteria
The assessment is acceptable when: every applicable control has a Pass with evidence, or a Fail with a time-bound action and an interim risk control; the record-retrieval-through-retention control (item 3) is demonstrated, not assumed; and the vendor-reliance record documents what was reviewed, what was re-tested, and why that is sufficient. Item 3 is the control that quietly fails on vendor-hosted systems and deserves specific proof.
Filled specimen
The following shows three assessed controls for a vendor-hosted eConsent system, including one failed control with an action. Details are illustrative.
| # | Control | Result | Evidence / action |
|---|---|---|---|
| 1 | Validation | Pass | Sponsor validation protocol VAL-eCON-011 executed on the configured system; VSR released 2026-07-15 |
| 3 | Record retrieval through retention | Fail | Contract had no exit/archival clause; records could be lost on vendor change. Action: amend the quality agreement to require export of consent and audit-trail records in a readable format on exit; test the export. Interim: quarterly export held by sponsor. Owner: Vendor Management, due 2026-08-30 |
| 8 | Signature/record linking | Pass | TC-05 in the validation protocol shows the signature bound to the exact ICF version; audit-trail export AT-05 |
Item 3 is the classic quiet failure: creation works, retrieval a decade later after the vendor is gone does not. Assessing it explicitly, and testing the export, turns an inspection risk into a contract clause and a scheduled test.
Common inspection findings this checklist prevents
- Reliance on a vendor’s “Part 11 compliant” marketing claim with no sponsor assessment.
- An audit trail that exists but cannot be exported and read independently of the application.
- Records that cannot be retrieved through the full retention period from a vendor-hosted system.
- A vendor update pushed to the live system with no sponsor change assessment, invalidating the validated state.
How to adapt this checklist
- Run one checklist per in-scope component; the controls that bite hardest differ between eConsent, ePRO, sensors, and televisit.
- Fill the “where it bites” column with your actual records and workflows.
- Treat item 3 (retrieval through retention) as a required demonstration, and build the exit plan into the contract.
- Confirm the current clause numbers of Part 11 and Annex 11 (and track the Annex 11 revision) before you rely on them.