21 CFR Part 11 and Annex 11 Requirements Mapping for Business Central
By Thomas Brünger, Managing Partner
This maps the core requirements of FDA 21 CFR Part 11 (electronic records and signatures) and EU GMP Annex 11 (computerised systems) to Microsoft Dynamics 365 Business Central: what each rule requires, how it is met by configuration, and what validation evidences it. It is a design aid, not a compliance certificate - the controls still have to be validated and evidenced.
Requirements mapping
| Requirement | Part 11 / Annex 11 | How it is met in Business Central | Validation evidence |
|---|---|---|---|
| Audit trail | Part 11 §11.10(e); Annex 11 §9 | Secure, time-stamped change logging on GxP-relevant tables; not disableable by users | OQ test of change capture + tamper-evidence |
| Access control | Part 11 §11.10(d); Annex 11 §12 | Role-based permission sets, least privilege, no shared accounts, segregation of duties | Permission review + OQ access tests |
| Electronic signatures | Part 11 §11.50/§11.70; Annex 11 §14 | Signature configured where the process requires it, linked to the record, meaning recorded | OQ signature/record-link test |
| Data integrity (ALCOA+) | Annex 11 §5/§6; Part 11 §11.10(a) | Controls across create/change/archive; input checks; retention | Data-lifecycle test + retention check |
| System validation | Part 11 §11.10(a); Annex 11 §4 | Risk-based CSV (GAMP 5): URS, IQ/OQ/PQ, VSR | The full validation package |
| Copies / record retention | Part 11 §11.10(b/c); Annex 11 §7/§8 | Human-readable and exportable records; backup and archival | OQ export test + backup/restore check |
| Supplier assessment | Annex 11 §3.1 | Microsoft assessed via documented SaaS controls | Supplier assessment record |
How to use it
Read the mapping as the design layer: it shows the control that satisfies each requirement. Compliance is then achieved by validating those controls for your intended use and retaining the evidence - see 21 CFR Part 11 and Business Central and is Business Central 21 CFR Part 11 compliant?.
An independent architecture governance review can confirm the mapping holds in your configuration before an inspection.
Frequently asked questions
- Do 21 CFR Part 11 and Annex 11 map one-to-one?
- They overlap heavily but are not identical. Both cover audit trails, access control, electronic signatures, and validation; Annex 11 adds explicit supplier and data-lifecycle expectations, Part 11 is more prescriptive on signature/record linking. A control set that satisfies both is normal practice.
- Is the mapping enough to be compliant?
- No. The mapping shows how each requirement is met by configuration; compliance still requires validating that the configuration works as intended and retaining the evidence. The mapping is the design; validation is the proof.