Secure, attributable and traceable analytical records – Technical controls supporting 21 CFR Part 11 compliance

 

The EOS Instruments Audit Trail & Electronic Signature Software Module extends the standard Classizer™ software with advanced controls for data integrity, user accountability and electronic record management. Designed for organizations operating controlled QC workflows, the module helps ensure that analytical records remain attributable, legible, contemporaneous, original and accurate throughout their lifecycle. It provides the technical controls needed to support data-integrity requirements and workflows aligned with FDA 21 CFR Part 11 and EU GMP Annex 11.

The module is also valuable beyond formally regulated environments. It provides a robust framework for laboratories and production departments that need to control access to analytical data, document individual user actions, protect records against undetected modification, and implement structured review and approval workflows.

 

Controlled access and individual accountability
Access to Classizer™ is managed through a secure, password-protected user system with configurable roles and privileges. Each user is assigned an individual account, ensuring that measurements, changes, exports and other relevant actions can be attributed to the person who performed them. Configurable password policies, automatic account lockout and session controls help prevent unauthorized access and protect the integrity of the analytical workflow. User permissions can be adapted to different responsibilities, such as system administration, measurement execution, data review and approval.

 

Secure and tamper-evident audit trail
Relevant system and analytical events are automatically recorded in a secure, computer-generated and time-stamped audit trail. Recorded events can include:

  • user login and logout.
  • account and permission changes.
  • measurement acquisition.
  • changes to analytical settings.
  • data processing and review activities.
  • report generation and export.
  • application of electronic signatures.
  • other relevant system actions.

Audit trail recording operates independently of the user and cannot be edited or disabled through the standard user interface. Records are protected through a SHA-256 hash chain. Each audit trail entry is cryptographically linked to the preceding entry, and each log file is linked to the previous file. This makes unauthorized deletion, insertion or modification of individual records, as well as removal of an entire log file, detectable during integrity verification.

 

Electronic signatures linked to analytical records
Authorized users can apply electronic signatures to measurements and generated reports. Each signature records:

  • the identity of the signer;
  • the date and time of signing;
  • the meaning of the signature, such as review, approval or responsibility;
  • the cryptographic fingerprint of the signed document.

The electronic signature is permanently linked to the relevant record and cannot be transferred to another document. Any subsequent change to the signed document would alter its cryptographic fingerprint and can therefore be detected.

 

Audit trail review and integrity verification
A dedicated consultation panel allows authorized users to browse, filter and export audit trail information according to:

  • date and time range;
  • individual user;
  • event category;
  • measurement or record;
  • relevant system activity.

Authorized personnel can perform an integrity check of the complete audit trail chain at any time. The software recalculates the cryptographic links across the available records and log files and reports any detected interruption or inconsistency. These functions provide objective evidence to support routine QC review, internal investigations, quality audits and system assessments.

 

Supporting customer qualification and compliance activities
The module is supplied with a controlled 21 CFR Part 11 Requirements and Functionality Matrix mapping applicable regulatory requirements to the corresponding EOS software controls.
This documentation helps customers:

  • assess the module against their internal requirements;
  • identify technical and procedural responsibilities;
  • prepare their system qualification and validation activities;
  • reduce the effort required to introduce Classizer™ ONE into a controlled QC environment;
  • maintain documented evidence of the software functions available in the installed release.

The EOS Instruments module provides the technical controls that support 21 CFR Part 11 and data-integrity-oriented workflows. Overall compliance also depends on the customer’s intended use, system validation, standard operating procedures, personnel training, IT infrastructure, user administration, backup, record retention and change-control processes.

 

Principal characteristics

  • Role-based user management. Individual user accounts, configurable privileges, password policies, session controls and automatic account lockout. Credentials are never stored in clear text.
  • Secure, time-stamped audit trail. Automatic recording of relevant system and analytical events, filterable by date, user, category and record.
  • Tamper-evident record integrity. SHA-256 hash-chain protection makes unauthorized deletion, insertion or modification of audit trail records detectable.
  • Electronic signatures. Signer identity, date and time, signature meaning and document fingerprint are permanently linked to the signed measurement report.
  • Audit trail consultation and export. Authorized users can review, filter and export audit trail records for internal review, investigation and audit support.
  • End-to-end integrity verification. A dedicated function verifies the complete hash chain across audit trail records and log files and reports any detected inconsistency.
  • Controlled compliance documentation. A requirements and functionality matrix supports the customer’s internal assessment, qualification and validation activities.
  • Enhanced QC data governance. The module supports structured attribution, review and approval of analytical results in both regulated and internally controlled environments

 

Would you like to evaluate the module for your QC workflow?

Contact our team to discuss your data integrity requirements, review the Compliance Matrix and identify the most appropriate configuration and qualification support for your intended use.