Direct answer
Part 11 and Annex 11 do not make a machine compliant through one software feature or certificate. The regulated organisation must define intended use, records, risks and procedural controls, then validate the computerised system and manage access, audit trails, electronic signatures, backup, change and periodic review as applicable.
Key takeaways
- Define regulated records and system boundaries.
- Perform a risk-based data integrity and functional assessment.
- Validate functions and control the lifecycle.
- Maintain data integrity after changes and updates.
Establish the legal and technical scope
Identify which recipes, batch data, code records, inspections, alarms, user actions and reports form or support regulated records. Include interfaces with printers, vision, SCADA, MES, historians and enterprise systems.
- List electronic records and retention periods
- Map data creation, transfer and storage
- Define open or closed system context
- Identify electronic signature use
Assess the actual machine, task and site
Review how data are attributable, legible, contemporaneous, original or true copies, accurate, complete, consistent, enduring and available. Consider manual overrides, local files, shared accounts, clock changes and disconnected operation.
- Define user roles and least privilege
- Assess audit trail generation and review
- Verify time synchronisation and record sequence
- Challenge failure, recovery and offline scenarios
Create and retain suitable evidence
Test configuration, access, audit trails, records, reports, backup, restore, interfaces and signatures against approved requirements. Retain traceability, supplier assessment, deviations and controlled procedures.
- Approved validation plan and requirements
- Configuration and test evidence
- Backup and restore demonstration
- Training, access and periodic review records
Keep the control current
Software, interfaces, users, recipes and reports change over time. Use change control, access review, audit-trail review, incident management and tested recovery to preserve the validated state.
- Periodically review users and privileges
- Assess patches and supplier remote access
- Review audit trails based on risk
- Test backups and disaster recovery
Comparison table
| Control area | Key question | Typical evidence |
|---|---|---|
| Scope | Define regulated records and system boundaries. | Applicable legislation, standards and responsibility |
| Assessment | Perform a risk-based data integrity and functional assessment. | Risk assessment and verified safeguards |
| Records | Validate functions and control the lifecycle. | Drawings, declarations, tests and training records |
| Review | Maintain data integrity after changes and updates. | Change control, inspection and periodic review |
Free working templates
Download these files and adapt them to the actual machine, product, site and acceptance plan.
Official guidance and further reading
These sources provide the current regulatory or standards context. Always check the latest version before making a compliance decision.
Related buyer guides and tools
Relevant machinery and support routes
Use the guide to define the requirement, then compare the specialist routes below against representative product, packaging and output evidence.
