Why 21 CFR Part 11 also applies to AI

21 CFR Part 11 defines the criteria under which electronic records and electronic signatures can be considered trustworthy, reliable, and equivalent to paper records. When AI is used within a regulated clinical workflow, it becomes part of the validated application landscape and quality system.

In other words, an AI tool used to produce or transform content with regulatory impact cannot be treated like a simple office productivity assistant. If it influences trial data, submitted documents, quality review activities, or documented operational decisions, it enters a scope that requires validation, access control, traceability, and change governance.

Les 5 garanties incontournables — 21 CFR Part 11 & AI Infographie présentant les 5 exigences réglementaires clés pour un outil IA conforme à 21 CFR Part 11 en recherche clinique 21 CFR Part 11 & AI The 5 non-negotiable safeguards for a regulated AI tool 1 Formal system validation Document intended uses, functional requirements, performance tests, known limitations and revalidation triggers whenever the model or its configuration changes. 2 Complete and tamper-evident audit trail Track prompts, relevant inputs, generated outputs, model versions and human review actions. Time-stamped, secure, computer-generated — non-modifiable. 3 Access controls and security Unique user IDs, robust authentication, role-based permissions, data encryption, environment segregation and strict partitioning across studies and sponsors. 4 Data integrity, retention and retrieval Records must remain complete, readable, protected against alteration and retrievable for the full applicable retention period — prompts and outputs included. 5 Compliant electronic signatures Uniquely linked to an individual, permanently associated with the signed record. AI integrates into the approval workflow — it does not bypass it. Source : 21 CFR Part 11 — eCFR · FDA Guidance for Industry · aigesis.com

The 5 regulatory safeguards for any AI tool deployed in FDA-regulated clinical research

1. Formal system validation

Any system used in a regulated environment must be validated to demonstrate that it performs as intended in a consistent and reliable manner. For AI tools, this means documenting intended uses, functional requirements, performance testing, known limitations, and revalidation triggers whenever the model or its configuration changes.

2. Complete and tamper-evident audit trail

The regulation requires secure, computer-generated, time-stamped audit trails that record the creation, modification, and deletion of records, together with the identity of the person performing the action. In an AI setting, this should also extend to prompts, relevant inputs, generated outputs, model versions, and associated human review actions.

3. Access controls and security

Systems compliant with 21 CFR Part 11 must implement appropriate access controls, including unique user IDs, robust authentication, and permission management aligned with user roles. For AI tools, this should also include data encryption, environment segregation, and strict partitioning across studies, sponsors, or teams where required.

4. Data integrity, retention and retrieval

Compliance also requires records to remain complete, readable, protected against alteration, and retrievable for the full applicable retention period. For AI tools, this means structured retention of prompts, outputs, source documents, and technical logs needed to justify how a result was produced.

5. Compliant electronic signatures

Part 11 also governs electronic signatures, which must be uniquely linked to an individual, supported by appropriate authentication controls, and permanently associated with the signed record. When AI is part of an approval workflow, it must integrate with a compliant review and signature process rather than bypass it.

Clinical data management — regulated workflow in clinical research

Concrete AI use cases in clinical research

What to require from vendors

Sponsors, CROs, and quality teams should request clear documentation covering architecture, security, validation, logging, change control, and model governance. A vendor that cannot explain how logs are protected, how model versions are controlled, or how data is segregated presents a clear risk for regulated use.