Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
SOP Plug-and-play starting point CSV / CSA

SOP: Electronic Signature Lifecycle Management

A plug-and-play standard operating procedure for managing electronic signatures across their lifecycle: identity verification, account provisioning, meaning-list control, timeout and password policy, the Part 11 certification letter, deprovisioning, and periodic review, with a filled specimen and the regulations it satisfies.

Document type: SOP

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use SOP for managing electronic signatures across their lifecycle in GxP computerized systems. It covers the procedural controls that sit around the technical signature functionality: verifying identity, provisioning and deprovisioning signing accounts, controlling the meaning list, setting and justifying timeout and password policy, filing and maintaining the 21 CFR Part 11 certification letter, and reviewing the whole arrangement periodically. Replace every <<FILL: ...>> placeholder with your own specifics and route it through your normal document control. A filled specimen follows so you can see how a completed record reads. Verify each cited regulation against the current source before you rely on it.

Document control header

FieldEntry
Document titleElectronic Signature Lifecycle Management
Document number<<FILL: SOP-ID, e.g. SOP-QA-031>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Supersedes<<FILL: prior version or "New">>
Document owner<<FILL: role, e.g. Head of Quality Assurance>>
Applies to<<FILL: sites / systems in scope>>

1. Purpose

This procedure defines how <<FILL: COMPANY NAME>> manages electronic signatures so that every signature applied to a GxP record is attributable to one identity-verified individual, carries a clear meaning, is bound to the record signed, and cannot be repudiated. It sets the controls that make the technical signature functionality trustworthy in operation.

2. Scope

This procedure applies to all computerized systems that apply electronic signatures to GxP records at the sites listed in the header. It governs the people-and-process controls: identity, provisioning, meaning, policy, certification, deprovisioning, and review. The technical configuration and its qualification are governed by <<FILL: e-signature OQ protocol ID>>. Hybrid paper-and-electronic signing is governed by <<FILL: SOP for hybrid records>>.

3. Responsibilities

RoleResponsibility
System / process ownerDefines the signature points, the meaning of each, and who is authorized to sign each; owns the workflow requirements.
Quality AssuranceApproves the signature design and meaning list, owns this procedure and the Part 11 certification letter, and approves periodic review.
IT / system administratorProvisions and deprovisions accounts, configures timeout and password policy, and maintains the technical controls; does not hold a routine signing role on records in a system they administer.
Human Resources / managerConfirms identity at onboarding and notifies IT and QA of departures and role changes.
Information securitySets the authentication standard, monitors unauthorized-use detection, and manages any biometric-template privacy obligations.
Signer (end user)Verifies identity at enrollment, protects credentials, applies signatures with the correct meaning, and never shares or delegates credentials.

4. Definitions

  • Electronic signature: the regulated substitute for a handwritten signature, executed to a GxP electronic record, that attaches a person, an intent, and a moment in time to that record. See 21 CFR Part 11 and EU GMP Annex 11.
  • Signature meaning: the controlled statement of what the signing represents, for example Authored, Reviewed, or Approved.
  • Signing account: a unique, identity-verified user account with rights to apply electronic signatures.
  • Continuous session: the period from authenticated login until that access ends by logout, inactivity timeout, or session break; it governs whether a signing needs one or two components.

5. Procedure

5.1 Verify identity before granting signing rights

  1. Before a signing account is provisioned, <<FILL: HR or QA>> verifies the individual’s identity against an authoritative source and records that verification.
  2. Retain the identity-verification evidence for the life of the account so the organization can show that the person behind an account is the real individual (11.100(b)).

5.2 Provision the signing account

  1. Provision a unique account with an identifier that is never reused or reassigned over the system’s life (11.100(a), 11.300(a)).
  2. Grant least-privilege signing rights matched to the authorized signature points for that person’s role.
  3. Record the provisioning on the signing-account register (section 8).

5.3 Control the signature meaning list

  1. Configure the meaning list as a controlled selection, not free text, so a meaning cannot be left blank or made ambiguous (11.50(a)).
  2. Change the meaning list only through change control, with QA approval.
  3. Confirm each configured meaning matches the workflow step it is applied at.

5.4 Set and justify timeout and password policy

  1. Set the inactivity timeout per system risk and document the value and rationale in the risk assessment; do not accept a vendor default without justification.
  2. Set the password policy (length, aging, lockout threshold) to satisfy 11.300 and the organization’s information-security standard, and document how any tension between frequent rotation and modern length-based guidance was resolved.
  3. Configure the two-component logic so the first signing in a session requires both components and subsequent in-session signings require the individual-executable component (the password), per 11.200(a)(1).

5.5 File and maintain the Part 11 certification letter

  1. Before first use of electronic signatures, confirm the one-time certification under 11.100(c) has been submitted to the FDA, stating that the organization’s electronic signatures are the legally binding equivalent of handwritten signatures.
  2. Retain the certification letter with the quality records and reference it in the inspection-readiness pack. This is organization-wide, not per system.

5.6 Deprovision on departure or role change

  1. On departure, disable the signing account promptly and record the date; do not delete records the account signed.
  2. Do not reissue the identifier to a new hire (11.100(a)).
  3. On role change, adjust signing rights to match the new authorized signature points.

5.7 Handle compromised or lost credentials

  1. On any suspected credential compromise, loss, or theft, deauthorize the credential and issue a replacement with suitable controls (11.300(c)).
  2. Assess whether any signature may have been applied by an unauthorized person and raise a deviation if so.

6. Acceptance criteria

The signature arrangement is under control when all of the following hold:

  • Every signing account is unique, identity-verified, and never reassigned.
  • The meaning list is controlled, complete, and matched to the workflow.
  • Timeout and password policy are configured, risk-justified, and documented.
  • The Part 11 certification letter is on file and current.
  • Departures and role changes are reflected in signing rights within <<FILL: number>> working days.
  • A periodic review confirms all of the above at the defined cadence.

7. Periodic review

Review the signature arrangement for each system at least <<FILL: frequency, e.g. annually>>: confirm account uniqueness and identity evidence, that leavers are disabled, that the meaning list and policy settings are unchanged or change-controlled, and that the certification letter is current. Record the review and route it to QA.

8. Record generated: signing-account register

FieldFormatRequiredWhoWhen
Account IDtext, uniqueYesITAt provisioning
Individual (printed name)textYesHR/QAAt provisioning
Identity verified (evidence ref)textYesHR/QABefore provisioning
Systems and signature points authorizedlistYesSystem ownerAt provisioning
Provisioned datedateYesITAt provisioning
Disabled datedateYesITAt departure
Last periodic reviewdateYesQAEach review

9. References

21 CFR Part 11, sections 11.50, 11.70, 11.100, 11.200, 11.300. EU GMP Annex 11 (Computerised Systems), electronic signatures, in-force 2011 version; track the draft revision published 7 July 2025 that renumbers electronic signatures to section 13 and points toward multi-factor authentication and time-zone-aware timestamps. eIDAS Regulation (EU) No 910/2014 for signatures that carry legal weight outside the company. ICH Q9(R1), Quality Risk Management (for timeout and password risk basis).

Confirm the current version and clause numbers of each reference before issue.

10. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

11. Approvals

RoleNameSignatureDate
Author<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality Head)<<FILL>>

Filled specimen

The following shows the signing-account register completed for one individual on an example laboratory system, so you can see the expected detail. The names and numbers are illustrative; replace them with your own.

FieldEntry
Account IDjsmith (never reassigned)
IndividualJane A. Smith
Identity verifiedGovernment ID checked at onboarding, evidence HR-ONB-2025-0442
Systems and signature points authorizedChromatography Data System: Review result, Approve result
Provisioned date12-Jan-2026
Disabled date(active)
Last periodic review30-Jun-2026, confirmed unique, identity evidence on file, rights unchanged

In this example the register ties the account to a real, identity-verified person, records exactly which signature points the person may sign, and shows a periodic review that re-confirmed the controls. If Jane leaves, the disabled date is filled in and the identifier “jsmith” is never given to another hire, which is what keeps every past signature attributable to her alone.

Common inspection findings this SOP prevents

  • Shared or generic accounts used for signing, so no signature can be attributed to a person.
  • An identifier recycled to a new hire, breaking the attribution of the previous holder’s signatures.
  • A blank or vague signature meaning, because the meaning list was free text rather than controlled.
  • Timeout and password settings taken as vendor defaults with no risk justification.
  • No Part 11 certification letter on file for a company asserting its electronic signatures are legally binding.
  • Leavers whose signing accounts stayed active for weeks after departure.

How to adapt this SOP

  1. Set your document number, owner, and effective date, and point the cross-references to your real OQ protocol and hybrid-records SOP.
  2. Set the timeout and password values to your risk-justified configuration and reference the risk assessment.
  3. Confirm the Part 11 certification letter is on file before you claim it in section 5.5.
  4. Set the deprovisioning and periodic-review timeframes to values you can actually meet.
  5. Confirm every regulation in section 9 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.