21 CFR Part 11 Compliance Software Module for Data Integrity & Compliance

 

EOS 21 CFR Part 11 software add-on is the perfect solution for the deployment of EOS Classizer™ ONE in regulated environments, where analytical data must be attributable, legible, contemporaneous, original and accurate throughout its whole lifecycle. The add-on extends the standard Classizer™ ONE software with a secure user management layer, a tamper-evident audit trail and electronic signature capabilities, addressing the technical controls required by FDA 21 CFR Part 11 and by the corresponding EU GMP Annex 11 expectations for computerised systems. Access to the instrument is granted through an internal, password-protected user store with configurable roles and privilege levels, automatic account lockout and session control, so that every action performed on the system — from user login to measurement acquisition, from analysis settings to data export — is unambiguously attributed to an individual operator. Every event is recorded in a secure, computer-generated, time-stamped audit trail which is written independently of the operator and cannot be edited or disabled from the user interface: records are protected by a SHA-256 hash chain, in which each entry cryptographically links to the previous one and each log file links to the preceding file, so that any deletion, insertion or modification of a record — including the removal of an entire log file — is immediately detectable at verification. Electronic signatures can be applied to measurements and to generated reports: the signature binds the signer identity, the date and time and the meaning of the signature (e.g. review, approval, responsibility) to the cryptographic fingerprint of the signed document, and it cannot be transferred to any other record. A dedicated consultation panel allows authorised users to browse, filter and export the audit trail by date range, user, event category and record, and to run an integrity verification of the chain at any time, producing the objective evidence expected during an internal audit or an inspection. The add-on is delivered together with a compliance matrix mapping each requirement of 21 CFR Part 11 to the corresponding software control, to support the customer’s own validation activities (IQ/OQ/PQ) and to shorten the qualification of the instrument within an existing quality system.

 

Principal Characteristics:

  • User management panel: role-based access control with configurable privileges, password policy and automatic account lockout. Credentials are never stored in clear text.
  • Audit trail consultation panel: time-stamped records of every system and analytical event, filterable by date, user, category and record. Each entry reports the previous-record hash, making the chain verifiable end to end.
  • Electronic signature dialog: signer identity, date/time and meaning of the signature are bound to the cryptographic fingerprint of the signed report.
  • Integrity verification result: a single command re-computes the whole hash chain across all log files and reports any broken link.