This is a ready-to-use SOP for managing electronic signatures across their lifecycle in GxP computerized systems. It covers the procedural controls that sit around the technical signature functionality: verifying identity, provisioning and deprovisioning signing accounts, controlling the meaning list, setting and justifying timeout and password policy, filing and maintaining the 21 CFR Part 11 certification letter, and reviewing the whole arrangement periodically. Replace every <<FILL: ...>> placeholder with your own specifics and route it through your normal document control. A filled specimen follows so you can see how a completed record reads. Verify each cited regulation against the current source before you rely on it.
Document control header
| Field | Entry |
|---|---|
| Document title | Electronic Signature Lifecycle Management |
| Document number | <<FILL: SOP-ID, e.g. SOP-QA-031>> |
| Version | <<FILL: version, e.g. 1.0>> |
| Effective date | <<FILL: effective date>> |
| Supersedes | <<FILL: prior version or "New">> |
| Document owner | <<FILL: role, e.g. Head of Quality Assurance>> |
| Applies to | <<FILL: sites / systems in scope>> |
1. Purpose
This procedure defines how <<FILL: COMPANY NAME>> manages electronic signatures so that every signature applied to a GxP record is attributable to one identity-verified individual, carries a clear meaning, is bound to the record signed, and cannot be repudiated. It sets the controls that make the technical signature functionality trustworthy in operation.
2. Scope
This procedure applies to all computerized systems that apply electronic signatures to GxP records at the sites listed in the header. It governs the people-and-process controls: identity, provisioning, meaning, policy, certification, deprovisioning, and review. The technical configuration and its qualification are governed by <<FILL: e-signature OQ protocol ID>>. Hybrid paper-and-electronic signing is governed by <<FILL: SOP for hybrid records>>.
3. Responsibilities
| Role | Responsibility |
|---|---|
| System / process owner | Defines the signature points, the meaning of each, and who is authorized to sign each; owns the workflow requirements. |
| Quality Assurance | Approves the signature design and meaning list, owns this procedure and the Part 11 certification letter, and approves periodic review. |
| IT / system administrator | Provisions and deprovisions accounts, configures timeout and password policy, and maintains the technical controls; does not hold a routine signing role on records in a system they administer. |
| Human Resources / manager | Confirms identity at onboarding and notifies IT and QA of departures and role changes. |
| Information security | Sets the authentication standard, monitors unauthorized-use detection, and manages any biometric-template privacy obligations. |
| Signer (end user) | Verifies identity at enrollment, protects credentials, applies signatures with the correct meaning, and never shares or delegates credentials. |
4. Definitions
- Electronic signature: the regulated substitute for a handwritten signature, executed to a GxP electronic record, that attaches a person, an intent, and a moment in time to that record. See 21 CFR Part 11 and EU GMP Annex 11.
- Signature meaning: the controlled statement of what the signing represents, for example Authored, Reviewed, or Approved.
- Signing account: a unique, identity-verified user account with rights to apply electronic signatures.
- Continuous session: the period from authenticated login until that access ends by logout, inactivity timeout, or session break; it governs whether a signing needs one or two components.
5. Procedure
5.1 Verify identity before granting signing rights
- Before a signing account is provisioned,
<<FILL: HR or QA>>verifies the individual’s identity against an authoritative source and records that verification. - Retain the identity-verification evidence for the life of the account so the organization can show that the person behind an account is the real individual (11.100(b)).
5.2 Provision the signing account
- Provision a unique account with an identifier that is never reused or reassigned over the system’s life (11.100(a), 11.300(a)).
- Grant least-privilege signing rights matched to the authorized signature points for that person’s role.
- Record the provisioning on the signing-account register (section 8).
5.3 Control the signature meaning list
- Configure the meaning list as a controlled selection, not free text, so a meaning cannot be left blank or made ambiguous (11.50(a)).
- Change the meaning list only through change control, with QA approval.
- Confirm each configured meaning matches the workflow step it is applied at.
5.4 Set and justify timeout and password policy
- Set the inactivity timeout per system risk and document the value and rationale in the risk assessment; do not accept a vendor default without justification.
- Set the password policy (length, aging, lockout threshold) to satisfy 11.300 and the organization’s information-security standard, and document how any tension between frequent rotation and modern length-based guidance was resolved.
- Configure the two-component logic so the first signing in a session requires both components and subsequent in-session signings require the individual-executable component (the password), per 11.200(a)(1).
5.5 File and maintain the Part 11 certification letter
- Before first use of electronic signatures, confirm the one-time certification under 11.100(c) has been submitted to the FDA, stating that the organization’s electronic signatures are the legally binding equivalent of handwritten signatures.
- Retain the certification letter with the quality records and reference it in the inspection-readiness pack. This is organization-wide, not per system.
5.6 Deprovision on departure or role change
- On departure, disable the signing account promptly and record the date; do not delete records the account signed.
- Do not reissue the identifier to a new hire (11.100(a)).
- On role change, adjust signing rights to match the new authorized signature points.
5.7 Handle compromised or lost credentials
- On any suspected credential compromise, loss, or theft, deauthorize the credential and issue a replacement with suitable controls (11.300(c)).
- Assess whether any signature may have been applied by an unauthorized person and raise a deviation if so.
6. Acceptance criteria
The signature arrangement is under control when all of the following hold:
- Every signing account is unique, identity-verified, and never reassigned.
- The meaning list is controlled, complete, and matched to the workflow.
- Timeout and password policy are configured, risk-justified, and documented.
- The Part 11 certification letter is on file and current.
- Departures and role changes are reflected in signing rights within
<<FILL: number>>working days. - A periodic review confirms all of the above at the defined cadence.
7. Periodic review
Review the signature arrangement for each system at least <<FILL: frequency, e.g. annually>>: confirm account uniqueness and identity evidence, that leavers are disabled, that the meaning list and policy settings are unchanged or change-controlled, and that the certification letter is current. Record the review and route it to QA.
8. Record generated: signing-account register
| Field | Format | Required | Who | When |
|---|---|---|---|---|
| Account ID | text, unique | Yes | IT | At provisioning |
| Individual (printed name) | text | Yes | HR/QA | At provisioning |
| Identity verified (evidence ref) | text | Yes | HR/QA | Before provisioning |
| Systems and signature points authorized | list | Yes | System owner | At provisioning |
| Provisioned date | date | Yes | IT | At provisioning |
| Disabled date | date | Yes | IT | At departure |
| Last periodic review | date | Yes | QA | Each review |
9. References
21 CFR Part 11, sections 11.50, 11.70, 11.100, 11.200, 11.300. EU GMP Annex 11 (Computerised Systems), electronic signatures, in-force 2011 version; track the draft revision published 7 July 2025 that renumbers electronic signatures to section 13 and points toward multi-factor authentication and time-zone-aware timestamps. eIDAS Regulation (EU) No 910/2014 for signatures that carry legal weight outside the company. ICH Q9(R1), Quality Risk Management (for timeout and password risk basis).
Confirm the current version and clause numbers of each reference before issue.
10. Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
11. Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Author | <<FILL>> | ||
| Reviewer (QA) | <<FILL>> | ||
| Approver (Quality Head) | <<FILL>> |
Filled specimen
The following shows the signing-account register completed for one individual on an example laboratory system, so you can see the expected detail. The names and numbers are illustrative; replace them with your own.
| Field | Entry |
|---|---|
| Account ID | jsmith (never reassigned) |
| Individual | Jane A. Smith |
| Identity verified | Government ID checked at onboarding, evidence HR-ONB-2025-0442 |
| Systems and signature points authorized | Chromatography Data System: Review result, Approve result |
| Provisioned date | 12-Jan-2026 |
| Disabled date | (active) |
| Last periodic review | 30-Jun-2026, confirmed unique, identity evidence on file, rights unchanged |
In this example the register ties the account to a real, identity-verified person, records exactly which signature points the person may sign, and shows a periodic review that re-confirmed the controls. If Jane leaves, the disabled date is filled in and the identifier “jsmith” is never given to another hire, which is what keeps every past signature attributable to her alone.
Common inspection findings this SOP prevents
- Shared or generic accounts used for signing, so no signature can be attributed to a person.
- An identifier recycled to a new hire, breaking the attribution of the previous holder’s signatures.
- A blank or vague signature meaning, because the meaning list was free text rather than controlled.
- Timeout and password settings taken as vendor defaults with no risk justification.
- No Part 11 certification letter on file for a company asserting its electronic signatures are legally binding.
- Leavers whose signing accounts stayed active for weeks after departure.
How to adapt this SOP
- Set your document number, owner, and effective date, and point the cross-references to your real OQ protocol and hybrid-records SOP.
- Set the timeout and password values to your risk-justified configuration and reference the risk assessment.
- Confirm the Part 11 certification letter is on file before you claim it in section 5.5.
- Set the deprovisioning and periodic-review timeframes to values you can actually meet.
- Confirm every regulation in section 9 against the current published version before issue.