21 CFR Part 11 and Annex 11 Requirements Mapping for Business Central

By Thomas Brünger, Managing Partner

21-cfr-part-11 · annex-11 · complianceJuly 19, 2026

This maps the core requirements of FDA 21 CFR Part 11 (electronic records and signatures) and EU GMP Annex 11 (computerised systems) to Microsoft Dynamics 365 Business Central: what each rule requires, how it is met by configuration, and what validation evidences it. It is a design aid, not a compliance certificate - the controls still have to be validated and evidenced.

Requirements mapping

RequirementPart 11 / Annex 11How it is met in Business CentralValidation evidence
Audit trailPart 11 §11.10(e); Annex 11 §9Secure, time-stamped change logging on GxP-relevant tables; not disableable by usersOQ test of change capture + tamper-evidence
Access controlPart 11 §11.10(d); Annex 11 §12Role-based permission sets, least privilege, no shared accounts, segregation of dutiesPermission review + OQ access tests
Electronic signaturesPart 11 §11.50/§11.70; Annex 11 §14Signature configured where the process requires it, linked to the record, meaning recordedOQ signature/record-link test
Data integrity (ALCOA+)Annex 11 §5/§6; Part 11 §11.10(a)Controls across create/change/archive; input checks; retentionData-lifecycle test + retention check
System validationPart 11 §11.10(a); Annex 11 §4Risk-based CSV (GAMP 5): URS, IQ/OQ/PQ, VSRThe full validation package
Copies / record retentionPart 11 §11.10(b/c); Annex 11 §7/§8Human-readable and exportable records; backup and archivalOQ export test + backup/restore check
Supplier assessmentAnnex 11 §3.1Microsoft assessed via documented SaaS controlsSupplier assessment record

How to use it

Read the mapping as the design layer: it shows the control that satisfies each requirement. Compliance is then achieved by validating those controls for your intended use and retaining the evidence - see 21 CFR Part 11 and Business Central and is Business Central 21 CFR Part 11 compliant?.

An independent architecture governance review can confirm the mapping holds in your configuration before an inspection.

Frequently asked questions

Do 21 CFR Part 11 and Annex 11 map one-to-one?
They overlap heavily but are not identical. Both cover audit trails, access control, electronic signatures, and validation; Annex 11 adds explicit supplier and data-lifecycle expectations, Part 11 is more prescriptive on signature/record linking. A control set that satisfies both is normal practice.
Is the mapping enough to be compliant?
No. The mapping shows how each requirement is met by configuration; compliance still requires validating that the configuration works as intended and retaining the evidence. The mapping is the design; validation is the proof.