Click on the magnifying glass to the right. Starting typing a topic you wish to learn about

Validated Projects, part 1: Requirements and Definitions

Version: 1

Who needs to follow 21 CFR part 11 compliance?

Anyone conducting a clinical trial that uses electronic records in place of paper records, including electronic signatures that are intended to be the equivalent of handwritten signatures. 

 

Definitions

Electronic Consent: in the scope of REDCap, electronic consent refers to the electronic capture of a ‘wet' signature from a participant using the e-consent framework. This requirement covers the ‘Electronic Signature’ definition found in the FDA part 11 regulations.

Electronic Signature (E-Signature): in the scope of REDCap, an E-signature refers to the individual verifying the data being captured electronically, digitally signing, and authenticating their identity. This requirement covers the ‘Digital Signature’ definition found in the FDA part 11 regulations.

 

View the FDA Title 21 Chapter I Subchapter A Part 11 regulations here.

 

User Rights

Security features that limit user access and their privileges must be in place. Some examples of these security features include making sure users have unique usernames and passwords, being able to detect and prevent unauthorized system access, and locking compromised accounts.

The three primary tools for enforcing limited system access:

  1. User passwords to access a system

  2. Two-factor authentication during log in (DUO)

  3. Program time-outs which lock the system when not in use for an extended period of time (30 minutes)

 

 

User Roles

It is up to the discretion of the project PI in conjunction with the study team to set up User Rights & Roles in a project. In order for a study to be Part 11 Compliant, project sponsor / investigator roles and responsibilities must be clearly articulated to provide awareness to sponsors and investigators of responsibilities to adequately conduct clinical trials.

It is important to separate roles and their designated rights in each project. The following examples would meet Part 11 compliance for separation of concerns:

  • Administrator

  • Auditor / Monitor

  • Data Entry Analyst

  • Principle Investigator

  • Study Coordinator

Note: The eConsent REDCap Template includes 5 unique roles. Please add additional or remove roles as needed for your project needs.

 

Relevant Resource: https://utahctsi.atlassian.net/servicedesk/customer/portal/3/article/276988105?src=543000090

 

Go to Next Page, or return to Table of Contents