Most "Part 11 compliant e-signature" content is written for the document layer: SOPs, batch record sign-offs, deviation approvals. A LIMS is a different animal. It doesn't just route documents for signature. It captures raw instrument output, runs calculations against that output, and produces a result that a chemist signs and a second person reviews before it becomes the number that determines whether a batch passes or fails. LIMS software 21 CFR Part 11 requirements sit on top of that entire chain, not just the signature at the end of it.
That difference matters when you're evaluating a LIMS or an ELN, or deciding whether the e-signature layer you already have is enough to cover the one you're about to buy. This post walks through what Part 11 and the GMP predicate rules underneath it actually require of a laboratory system specifically, what EU GMP Annex 11 adds, and what to ask a LIMS vendor before you sign a contract.
Key Takeaways
- A LIMS is regulated as automated GMP equipment under 21 CFR 211.68, not just as a record-keeping tool, and separately as the source of laboratory records under 21 CFR 211.194.
- 211.194(a)(4) requires "a complete record of all data secured in the course of each test, including all graphs, charts, and spectra from laboratory instrumentation." That's the specific clause that makes instrument-generated data, not just the final result, part of the record a LIMS audit trail has to cover.
- 211.194(a)(7) and (a)(8) require two separate signatures on lab data: the analyst who performed the test, and a second person who reviewed it "for accuracy, completeness, and compliance with established standards." A LIMS e-signature workflow has to support both roles as distinct, attributable signing events.
- EU GMP Annex 11's clause 6 requires an equivalent second check on critical manually entered data, "done by a second operator or by validated electronic means," and clause 9 requires audit trails for GMP-relevant changes and deletions with the reason documented.
- IQ/OQ/PQ validates that the LIMS itself works as intended. It's a separate exercise from validating that the e-signature layer meets Part 11 Subpart C, and a vendor evaluation checklist needs to ask about both.
A LIMS Sits Under Two Regulatory Layers, Not One
Ask most people what makes a system "Part 11 compliant" and they'll describe the signature layer: unique credentials, two-component authentication at signing, a printed name and timestamp tied to the record. That's Subpart C of Part 11, and it's real. But a LIMS is also, first, a piece of GMP equipment, and the equipment rules apply before a single signature ever gets captured.
21 CFR 211.68(a) covers this directly: "Automatic, mechanical, or electronic equipment or other types of equipment, including computers, or related systems that will perform a function satisfactorily, may be used in the manufacture, processing, packing, and holding of a drug product. If such equipment is so used, it shall be routinely calibrated, inspected, or checked according to a written program designed to assure proper performance. Written records of those calibration checks and inspections shall be maintained." A LIMS pulling data from a balance, a spectrophotometer, or an HPLC is exactly the "related systems" language covers.
211.68(b) goes further and is the part most e-signature vendors never touch, because it describes controls over the computer system itself rather than the document it produces: "Appropriate controls shall be exercised over computer or related systems to assure that changes in master production and control records or other records are instituted only by authorized personnel. Input to and output from the computer or related system of formulas or other records or data shall be checked for accuracy... A backup file of data entered into the computer or related system shall be maintained except where certain data, such as calculations performed in connection with laboratory analysis, are eliminated by computerization or other automated processes." That last clause is written almost as if it anticipated a LIMS specifically: it names laboratory calculations as the example of data that computerization can eliminate the manual version of, and then requires a written record of the program plus validation data to stand in for it.
211.194: The Clause That Names Instrument Data Specifically
The record-content requirement for laboratory data lives in 21 CFR 211.194, and it's more specific to a LIMS than any general Part 11 audit trail language. 211.194(a)(4) requires "a complete record of all data secured in the course of each test, including all graphs, charts, and spectra from laboratory instrumentation, properly identified to show the specific component, drug product container, closure, in-process material, or drug product, and lot tested." That's not a signature requirement. It's a data completeness requirement, and it means an audit trail scoped only to who signed a result and when is missing the part FDA actually named: the graphs, charts, and spectra that came off the instrument before anyone signed anything.
The signature requirements sit two clauses later, and they establish a two-person pattern that's specific to laboratory work rather than general document approval. 211.194(a)(7) requires "the initials or signature of the person who performs each test and the date(s) the tests were performed." 211.194(a)(8) requires "the initials or signature of a second person showing that the original records have been reviewed for accuracy, completeness, and compliance with established standards." Those are two distinct signing events, by two distinct people, with two distinct meanings: one attests the test was performed, the other attests it was checked. A LIMS e-signature workflow built around a single generic "approve" action doesn't capture that distinction. It has to record which signature was the analyst's and which was the reviewer's, as separate, attributable events, the same distinction we cover in more general terms in e-signatures for pharmaceutical QA.
What the Audit Trail Actually Has to Cover
21 CFR 11.10(e) requires "secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions" that create, modify, or delete electronic records, with the audit trail retained for at least as long as the underlying record itself. For a general document-signing platform, that clause is satisfied by logging who opened, edited, and signed a document. For a LIMS, the "records" in scope are broader, per 211.194(a)(4), so the audit trail has to reach further too. That means logging things a document platform never has to think about: which raw instrument file a result was calculated from, whether a chromatogram was reprocessed or reintegrated and by whom, what integration parameters were used, and whether a result was ever manually overridden before the analyst's signature was applied. We cover the general Part 11 audit trail structure, including retention and review-frequency obligations, in 21 CFR Part 11 audit trail requirements. For a LIMS, apply that same structure to instrument data and reprocessing events, not just to the final signed result.
EU GMP Annex 11: The Same Pattern, in Different Clause Numbers
EU GMP Annex 11, the annex to EudraLex Volume 4 that's governed computerised systems in the EU since coming into operation on 30 June 2011, sets out the same two ideas through different clauses. This is the currently in-force version, not the 2025 draft revision covered elsewhere on this site; that draft would replace it once finalized, but as of this writing the 2011 text is what a manufacturer is actually held to.
Clause 6, Accuracy Checks, is Annex 11's version of 211.194's two-signature pattern: "For critical data entered manually, there should be an additional check on the accuracy of the data. This check may be done by a second operator or by validated electronic means." Clause 9, Audit Trails, is Annex 11's version of Part 11's 11.10(e): "Consideration should be given, based on a risk assessment, to building into the system the creation of a record of all GMP-relevant changes and deletions (a system generated 'audit trail'). For change or deletion of GMP-relevant data the reason should be documented. Audit trails need to be available and convertible to a generally intelligible form and regularly reviewed." Note the "reason should be documented" language: an accurate LIMS audit trail for a result that got reintegrated needs to capture why, not just that it happened.
Clause 14 defines what Annex 11 expects of the signature itself: electronic signatures should "have the same impact as hand-written signatures within the boundaries of the company," "be permanently linked to their respective record," and "include the time and date that they were applied." Clause 15, Batch Release, adds a role-specific requirement worth knowing if the LIMS result in question feeds into a release decision: "the system should allow only Qualified Persons to certify the release of the batches and it should clearly identify and record the person releasing or certifying the batches. This should be performed using an electronic signature." We cover the broader set of computerized-system obligations, including the pending 2025 revision, in our guide to EU GMP Annex 11.
IQ/OQ/PQ Validates the LIMS. It Doesn't Validate the Signature.
A common gap: a lab runs a full IQ/OQ/PQ on its LIMS, confirms the instrument integrations work, confirms calculations are correct, and treats that as covering Part 11 too. It doesn't. IQ/OQ/PQ under 21 CFR 11.10(a) validates that the system performs its intended function reliably. It's a separate question from whether the signature component meets Subpart C: unique credentials, two-component authentication at the moment of signing, a signature manifestation showing the signer's printed name, date, time, and the meaning of the signature (approval, review, authorship), and permanent linkage between the signature and the specific record version it was applied to. A LIMS can pass every instrument-qualification test in its validation protocol and still fail an inspector's question about whether the analyst's signature on a result is cryptographically or procedurally tied to that exact version of the data. We walk through the validation process itself, including what documentation an inspector expects to see, in 21 CFR Part 11 electronic signature validation.
A Vendor Evaluation Checklist Specific to LIMS
A generic e-signature vendor checklist asks about audit trails, unique credentials, and signature meaning. For a LIMS, ask these too:
- Does the audit trail capture the raw instrument file or output, not just the calculated result, per 211.194(a)(4)?
- Does the system distinguish an analyst's "performed" signature from a reviewer's "verified" signature as two separate, attributable events, per 211.194(a)(7) and (a)(8)?
- If a result is reprocessed or reintegrated, does the audit trail log the reason for the change, matching Annex 11 clause 9's "for change or deletion of GMP-relevant data the reason should be documented"?
- Can the system produce a printout indicating whether data has changed since the original entry, the standard Annex 11 sets in clause 8.2 for records supporting batch release?
- Is the accuracy check on critical manually entered data performed by a second operator or validated electronic means, per Annex 11 clause 6?
- Is there a written program plus validation data on file for any calculation that 211.68(b) allows to be automated in place of a manual, backed-up entry?
None of these questions are answerable from a marketing page. They're answerable from the vendor's own validation documentation, which is exactly what a supplier qualification assessment under Annex 11 clause 3 is supposed to surface before deployment, not after an inspection finding.
Where This Leaves the E-Signature Layer
Klyverity doesn't interface with instruments, run IQ/OQ/PQ on a LIMS, or replace the laboratory system's own validation. That work belongs to the LIMS vendor and to your own validation team. What Klyverity secures is the signature layer sitting on top of a lab result once it's ready to be signed: unique two-component credentials at the moment of signing, a signature manifestation showing who signed, when, and what the signature meant, and an audit trail permanently linked to that exact record. It's the piece of the chain described in 211.194(a)(7) and (a)(8), captured as attributable, non-repudiable signing events rather than a shared login and a checkbox. If you're evaluating how that layer fits alongside a LIMS you already run or are about to buy, talk to us.
FAQ
Is a LIMS regulated the same way as a general e-signature platform under Part 11?
No. A LIMS is regulated as GMP equipment under 21 CFR 211.68, and as the source of laboratory records under 21 CFR 211.194, in addition to whatever Part 11 signature controls apply once a result is signed electronically. A general document e-signature platform only has to satisfy the signature layer; a LIMS has equipment and record-content obligations underneath it that a document platform never encounters.
What does 21 CFR 211.194 require that's specific to instrument data?
211.194(a)(4) requires "a complete record of all data secured in the course of each test, including all graphs, charts, and spectra from laboratory instrumentation." That means the raw instrument output has to be part of the retained record, not just the final calculated result an analyst signs off on.
Does a LIMS need two separate signatures on a test result?
Yes, per 21 CFR 211.194(a)(7) and (a)(8): the initials or signature of the person who performed the test, and the initials or signature of a second person who reviewed the original records "for accuracy, completeness, and compliance with established standards." A LIMS e-signature workflow needs to capture these as two distinct, attributable signing events tied to two different people.
How does EU GMP Annex 11 handle the same requirements?
Annex 11 clause 6 requires an additional accuracy check on critical manually entered data, done "by a second operator or by validated electronic means." Clause 9 requires an audit trail of GMP-relevant changes and deletions with the reason documented. Clause 14 sets the standard for the electronic signature itself: the same impact as a hand-written signature, permanently linked to its record, with time and date included. This is the 2011 version of Annex 11, currently in force.
Does IQ/OQ/PQ on a LIMS also validate its e-signature capability?
Not automatically. IQ/OQ/PQ validates that the LIMS performs its intended function, instrument integration, calculations, data handling, reliably. Part 11 Subpart C signature requirements, unique credentials, two-component authentication, signature manifestation, and permanent signature-to-record linkage, are a separate set of controls that need their own validation evidence.