21 CFR Part 11 vs Annex 11: Requirements Mapping for Business Central
By Thomas Brünger, Managing Partner
This maps the core requirements of FDA 21 CFR Part 11 (electronic records and signatures) and EU GMP Annex 11 (computerised systems) to Microsoft Dynamics 365 Business Central: what each rule requires, how it is met by configuration, and what validation evidences it. It is a design aid, not a compliance certificate - the controls still have to be validated and evidenced.
What is the difference between 21 CFR Part 11 and Annex 11?
The two overlap heavily but are not identical, and satisfying both with a single control set is normal practice rather than an exception.
- Both require audit trails, access control, electronic signatures, and system validation.
- Annex 11 adds explicit supplier assessment and data-lifecycle expectations.
- Part 11 is more prescriptive about linking a signature to the record it signs.
In practice the question is rarely which rule is stricter, but which control satisfies both at once. The requirement-by-requirement view below shows where each rule lands.
Requirements mapping
| Requirement | Part 11 / Annex 11 | How it is met in Business Central | Validation evidence |
|---|---|---|---|
| Audit trail | Part 11 §11.10(e); Annex 11 §9 | Secure, time-stamped change logging on GxP-relevant tables; not disableable by users | OQ test of change capture + tamper-evidence |
| Access control | Part 11 §11.10(d); Annex 11 §12 | Role-based permission sets, least privilege, no shared accounts, segregation of duties | Permission review + OQ access tests |
| Electronic signatures | Part 11 §11.50/§11.70; Annex 11 §14 | Signature configured where the process requires it, linked to the record, meaning recorded | OQ signature/record-link test |
| Data integrity (ALCOA+) | Annex 11 §5/§6; Part 11 §11.10(a) | Controls across create/change/archive; input checks; retention | Data-lifecycle test + retention check |
| System validation | Part 11 §11.10(a); Annex 11 §4 | Risk-based CSV (GAMP 5): URS, IQ/OQ/PQ, VSR | The full validation package |
| Copies / record retention | Part 11 §11.10(b/c); Annex 11 §7/§8 | Human-readable and exportable records; backup and archival | OQ export test + backup/restore check |
| Supplier assessment | Annex 11 §3.1 | Microsoft assessed via documented SaaS controls | Supplier assessment record |
How to use it
Read the mapping as the design layer: it shows the control that satisfies each requirement. Compliance is then achieved by validating those controls for your intended use and retaining the evidence - see 21 CFR Part 11 and Business Central and is Business Central 21 CFR Part 11 compliant?.
An independent architecture governance review can confirm the mapping holds in your configuration before an inspection.
Frequently asked questions
- What is the difference between 21 CFR Part 11 and EU Annex 11?
- They overlap heavily but are not identical. Both cover audit trails, access control, electronic signatures, and validation; Annex 11 adds explicit supplier and data-lifecycle expectations, Part 11 is more prescriptive on signature/record linking. A control set that satisfies both is normal practice.
- Is Annex 11 the European equivalent of 21 CFR Part 11?
- Broadly, yes: Annex 11 is the EU GMP expectation for computerised systems, Part 11 is the FDA rule for electronic records and signatures. They are not translations of each other, so treat them as two requirement sets to satisfy with one control set rather than assuming one covers the other.
- Do 21 CFR Part 11 and Annex 11 map one-to-one?
- No. The requirement-by-requirement mapping below shows where each rule lands; several Business Central controls satisfy both rules at once, and Annex 11 has expectations, such as supplier assessment, with no direct Part 11 counterpart.
- Is the mapping enough to be compliant?
- No. The mapping shows how each requirement is met by configuration; compliance still requires validating that the configuration works as intended and retaining the evidence. The mapping is the design; validation is the proof.