You already know Part 11. What you may not know is whether the signing tool your teams actually use satisfies it, because a vendor's marketing page and the regulation are not the same document. This checklist is the way to test that, control by control, using the exact provisions an inspector will.
What an inspector opens first
The audit trail. Under §11.10(e), you need a secure, computer-generated, time-stamped record that independently captures the operator, the action, and the time, without obscuring previously recorded entries, retained at least as long as the record itself. Test it directly: can you produce, for a given signed document, a complete history of who opened, viewed, signed, or declined it, that no one could have edited after the fact?
Signature manifestations (§11.50)
Every signed record must display the signer's printed name, the date and time of signing, and the meaning of the signature, review, approval, or authorship. A signature with no stated meaning is incomplete. Open a signed document from your current system: are all three present, on the record itself, not just in a separate certificate?
Signature/record linking (§11.70)
Signatures must be linked to their records so they cannot be excised, copied, or transferred to falsify a record. The practical test: if a single byte of the signed document changes, is the signature invalidated? If a signature can be lifted onto another document, you do not have a Part 11 signature.
Identity and credentials (§11.100–11.300)
Each signature must be unique to one individual and never reused; identity must be verified before a signature is issued; and non-biometric signatures must use at least two distinct components with controls over issuance, use, and periodic change. Shared logins fail this immediately. Confirm re-authentication occurs at the moment of signing, not just at login.
Validation evidence
Part 11 expects the system to be validated. Ask the concrete question: can the vendor hand you validation documentation you could place in front of an auditor, or are you being asked to take compliance on faith?
The Annex 11 revision
The EU Annex 11 draft revision (published July 2025, public consultation closed October 2025) adds explicit cybersecurity, identity-and-access-management, and expanded audit-trail requirements, including capturing data creation events, not only changes and deletions. It has not yet been formally adopted, with finalization anticipated around 2026–2027. If you support EU trials, evaluate signing systems against where the requirement is heading, not only where it has been.
The printable checklist
- Immutable, time-stamped audit trail incl. view/access events (§11.10(e))
- Name, date/time, and meaning on every signed record (§11.50)
- Signature invalidated by any change to the document (§11.70)
- Unique, identity-verified signatures with re-authentication (§11.100–300)
- Two-component authentication with credential controls (§11.200/11.300)
- Validation documentation available on request
- Audit-trail export for the full retention period
- Annex 11 alignment including the current revision; ISO 27001 & SOC 2
If a vendor hesitates on any line, treat it as a finding.
How Capque Sign is designed against it
Capque Sign is being built to answer every line above with evidence rather than assurances: immutable audit trails, signature manifestations on the record, tamper-evident binding, identity-verified signatures with re-authentication, and exportable histories. It is designed around Part 11 and Annex 11 as requirements, not features to add later, and it lives inside the Capque platform so signatures stay tied to their studies. Capque is in early access; we work directly with QA teams to validate these controls against real inspection expectations.