In a clinical trial, a signature is not a formality. It is a legal and regulatory event. When a principal investigator signs a case report form, when a sponsor approves a protocol amendment, when a monitor signs off on source data verification, that signature has to hold up years later in front of an FDA inspector or an EMA auditor who was not in the room and does not take your word for anything.
Most general-purpose electronic signature tools were never built for that scrutiny. They were built to close sales contracts fast. Drop one into a regulated trial and you inherit a quiet, compounding risk: signatures that look valid but cannot survive an audit.
The two regulations that define a compliant e-signature
Two frameworks govern electronic signatures in FDA- and EU-regulated clinical research. If your signature system does not satisfy both, it is not fit for global trials.
21 CFR Part 11 (United States, FDA)
Issued by the FDA in 1997, 21 CFR Part 11 sets the conditions under which the agency treats electronic records and signatures as equivalent to paper. The sections that matter most: §11.10 (validation, access control, and secure time-stamped audit trails), §11.50 (every signature must show the signer's name, date/time, and meaning), §11.70 (signatures cryptographically bound to their records), and §11.100–11.300 (signatures unique to a verified individual, using at least two authentication components).
The keystone is the audit trail under §11.10(e): a secure, time-stamped, computer-generated record of who did what and when, that does not obscure prior entries and is retained at least as long as the record.
EU Annex 11, and why the current revision matters
Annex 11 of the EudraLex GMP guidelines governs computerised systems in GxP environments. It stood largely unchanged since 2011 until the European Commission published a draft revision on 7 July 2025, expanding it from 5 to 19 pages and adding explicit requirements for cybersecurity, identity and access management, stricter electronic-signature controls, and expanded audit-trail obligations. Public consultation closed in October 2025; as of this writing the revision has not yet been formally adopted, with finalization anticipated around 2026–2027. Either way the direction is clear: the bar is rising, not holding steady.
What a compliant signing ceremony looks like
A signature that survives an audit is a controlled ceremony, not a single click:
- Authenticated identity using credentials unique to the signer.
- Explicit meaning, the system captures why the person signed and shows it on the record.
- Re-authentication at the moment of signing.
- An immutable, time-stamped audit trail of every action.
- A tamper-evident bond between signature and document.
- Retention and retrievability for the full record lifetime.
Evaluating any e-signature system for trials
A credible vendor answers yes, with evidence, to all of it: immutable audit trail (§11.10(e)); name/date/meaning on every record (§11.50); cryptographic record binding (§11.70); unique, identity-verified signatures (§11.100–300); compliant multi-signer workflows; validation documentation; Annex 11 alignment including the current revision; ISO 27001 and SOC 2; and full audit-trail export.
How Capque Sign approaches compliance
Capque Sign is being built specifically for this problem: electronic signatures designed around 21 CFR Part 11 and EU Annex 11 from the first line of code, not retrofitted onto a consumer product. It is part of the broader Capque clinical trial platform, whose purpose is to break down the data silos that fragment trial management, so a signature is connected to the study it belongs to, not stranded in a separate tool. Capque is in a focused early-access phase, working directly with clinical teams to get these controls right before wide release.
Frequently asked questions
Is a general-purpose e-signature account enough for clinical trials?
Not on its own. Consumer-grade services can be configured toward Part 11, but out of the box they typically lack the validation documentation, audit-trail depth, unique-signature controls, and record-binding that regulated trials require.
What is the single most important Part 11 requirement?
The audit trail under §11.10(e): a secure, time-stamped record of who did what and when, that cannot be altered to obscure prior entries.
Does EU Annex 11 apply to my US-based biotech?
If you run trials in the EU or partner with EU sponsors, yes, and the current revision raises the bar further.