21 CFR Part 11 vs Annex 11: Requirements Mapping for Business Central

By Thomas Brünger, Managing Partner

21-cfr-part-11 · annex-11 · complianceJuly 19, 2026

This maps the core requirements of FDA 21 CFR Part 11 (electronic records and signatures) and EU GMP Annex 11 (computerised systems) to Microsoft Dynamics 365 Business Central: what each rule requires, how it is met by configuration, and what validation evidences it. It is a design aid, not a compliance certificate - the controls still have to be validated and evidenced.

What is the difference between 21 CFR Part 11 and Annex 11?

The two overlap heavily but are not identical, and satisfying both with a single control set is normal practice rather than an exception.

  • Both require audit trails, access control, electronic signatures, and system validation.
  • Annex 11 adds explicit supplier assessment and data-lifecycle expectations.
  • Part 11 is more prescriptive about linking a signature to the record it signs.

In practice the question is rarely which rule is stricter, but which control satisfies both at once. The requirement-by-requirement view below shows where each rule lands.

Requirements mapping

RequirementPart 11 / Annex 11How it is met in Business CentralValidation evidence
Audit trailPart 11 §11.10(e); Annex 11 §9Secure, time-stamped change logging on GxP-relevant tables; not disableable by usersOQ test of change capture + tamper-evidence
Access controlPart 11 §11.10(d); Annex 11 §12Role-based permission sets, least privilege, no shared accounts, segregation of dutiesPermission review + OQ access tests
Electronic signaturesPart 11 §11.50/§11.70; Annex 11 §14Signature configured where the process requires it, linked to the record, meaning recordedOQ signature/record-link test
Data integrity (ALCOA+)Annex 11 §5/§6; Part 11 §11.10(a)Controls across create/change/archive; input checks; retentionData-lifecycle test + retention check
System validationPart 11 §11.10(a); Annex 11 §4Risk-based CSV (GAMP 5): URS, IQ/OQ/PQ, VSRThe full validation package
Copies / record retentionPart 11 §11.10(b/c); Annex 11 §7/§8Human-readable and exportable records; backup and archivalOQ export test + backup/restore check
Supplier assessmentAnnex 11 §3.1Microsoft assessed via documented SaaS controlsSupplier assessment record

How to use it

Read the mapping as the design layer: it shows the control that satisfies each requirement. Compliance is then achieved by validating those controls for your intended use and retaining the evidence - see 21 CFR Part 11 and Business Central and is Business Central 21 CFR Part 11 compliant?.

An independent architecture governance review can confirm the mapping holds in your configuration before an inspection.

Frequently asked questions

What is the difference between 21 CFR Part 11 and EU Annex 11?
They overlap heavily but are not identical. Both cover audit trails, access control, electronic signatures, and validation; Annex 11 adds explicit supplier and data-lifecycle expectations, Part 11 is more prescriptive on signature/record linking. A control set that satisfies both is normal practice.
Is Annex 11 the European equivalent of 21 CFR Part 11?
Broadly, yes: Annex 11 is the EU GMP expectation for computerised systems, Part 11 is the FDA rule for electronic records and signatures. They are not translations of each other, so treat them as two requirement sets to satisfy with one control set rather than assuming one covers the other.
Do 21 CFR Part 11 and Annex 11 map one-to-one?
No. The requirement-by-requirement mapping below shows where each rule lands; several Business Central controls satisfy both rules at once, and Annex 11 has expectations, such as supplier assessment, with no direct Part 11 counterpart.
Is the mapping enough to be compliant?
No. The mapping shows how each requirement is met by configuration; compliance still requires validating that the configuration works as intended and retaining the evidence. The mapping is the design; validation is the proof.