AIThis post was created with the assistance of artificial intelligence (AI).

Meta: Understand how electronic signatures work in QAtrial, including identity verification, review and approval use cases, signature records, and audit trail linkage.

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get monitors, keyboards and dev gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Why Signatures Matter in Regulated Workflows

In everyday software, clicking “Approve” is a casual action. In regulated industries, approval carries legal and regulatory weight. When a QA manager approves a requirement, they are attesting — with their professional identity — that the requirement has been reviewed and meets the applicable quality criteria. When a reviewer signs a Validation Summary Report, they are confirming that the report accurately represents the project’s quality status.

QAtrial – Electronic Signatures
QAtrial · Compliance Infrastructure
Electronic
Signatures
Clicking “Approve” in everyday software is a casual action. In regulated industries it carries legal and regulatory weight — a professional attestation, with verified identity, permanent timestamp, and tamper-evident binding to the record it signs. QAtrial implements 21 CFR Part 11 and EU Annex 11 compliant e-signatures natively.
1
Who signed?
Identity verified through password re-authentication at the moment of signing — not just session login
2
What did they mean?
Authored · Reviewed · Approved · Verified · Rejected — each a distinct quality responsibility
3
When did they sign?
ISO 8601 timestamp permanently recorded in the audit trail — cannot be retroactively modified
Regulatory
Basis
21 CFR Part 11 (FDA)
§11.50 — Record must contain signer’s name, date/time, and meaning
§11.70 — Signature bound to record; cannot be excised or transferred
§11.100 — Each e-sig unique to one individual; not reused or reassigned
§11.200 — At least two ID components; single continuous access window allowed
EU Annex 11 (EMA)
§14 — Electronic signatures carry same impact as handwritten signatures within the company
§12.4 — Clear indication of the approving person’s identity; audit trail convertible to intelligible form
Signature Meanings
Five Purposes — Each a Distinct Quality Responsibility
Authored
Creator
Applied by the person who created or substantially wrote the content. Establishes who is responsible for the original content of a requirement, test procedure, or report.
Establishes origin
Reviewed
Peer / SME
Applied by a peer or subject matter expert who confirms technical accuracy. Quality checkpoint — another qualified person has examined the work.
Technical accuracy
Approved
QA Manager / Admin
Highest regulatory weight. Formal acceptance by an authorized person. An approved requirement is baselined. An approved report is ready for submission.
Formal acceptance
Verified
QA Engineer
Confirms a specific condition was met — test executed as described, corrective action effective. Common on test results and CAPA closure.
Condition confirmed
Rejected
Any Authorized Role
Formally documents that an authorized person reviewed the content and it does not meet quality criteria. Reason field is critical — the author needs to know what to fix.
Documented rejection
The Signing Workflow
Four Steps in the Signature Modal
1
Action Context Display
The modal shows the entity being signed — its ID, title, current status, and type. The signer knows exactly what they are attesting to. Signing the wrong record is a compliance risk the context display prevents.
REQ-042 · Active
2
Meaning Selection
Signer selects the purpose of their signature: authored, reviewed, approved, verified, or rejected. Selected meaning is recorded permanently — it cannot be changed retroactively.
approved ✓
3
Reason Entry
Signer enters a reason explaining their action. Treat as mandatory in GxP environments — a signature without a rationale is difficult to defend in an audit. Should be specific enough to be self-explanatory in 5 years.
Required in GxP
4
Password Re-Authentication
Before the signature is accepted, the signer re-enters their password. This verifies that the person clicking “Sign” is the person whose name will appear on the record. Prevents signing on another person’s behalf.
21 CFR 11.200
The Signature Record
What Gets Permanently Stored
Signature Record approve · REQ-042
signerId usr_3b9f1c
signerName j.rodriguez
signerRole QA Manager
timestamp 2025-11-12T09:42:07.311Z
meaning approved
method password
reason “Reviewed against 21 CFR 11.10(e) and confirmed audit trail implementation satisfies Part 11 completeness requirements. REQ-042 baselined.”
Signature is embedded directly in the audit trail entry — bound to the record in a way that satisfies 21 CFR Part 11 §11.70: it cannot be excised, copied, or transferred.
Why Each Field Matters
Regulatory Purpose per Field
signerId + signerName
Satisfies 21 CFR Part 11 §11.50 — “printed name of the signer.” Unique ID prevents reassignment; name provides human-readable identity for auditors. §11.100: each signature unique to one individual.
signerRole
Shows organizational authority — that the person who approved a record had the role to do so. Auditors verify that approval signatures come from authorized roles, not from QA Engineers approving their own work.
timestamp
Satisfies 21 CFR Part 11 §11.50 — “date and time of signing.” ISO 8601 to millisecond precision. Permanently recorded in the audit trail — verifies the signing occurred before or after specific events.
meaning
Satisfies 21 CFR Part 11 §11.50 — “the meaning of the signature such as review, approval, responsibility, or authorship.” Without this field, a signature is legally ambiguous about what was attested.
method
Satisfies 21 CFR Part 11 §11.200 — documents the authentication method used (password, pin, biometric). Shows the signature used at least one identification component at signing time.
The 15-Minute Verification Window
Security and usability — aligned with 21 CFR Part 11 §11.200
Step 01
🔐
First Signature in Session
Full credential verification required: user ID confirmation + password re-authentication. Both identification components, as required by Part 11 §11.200.
Step 02
⏱️
15-Minute Window Opens
After successful full authentication, a verification window begins. Subsequent signatures within this window require only password re-authentication — one component, not two.
15:00
Step 03
✅
Additional Signatures During Window
Password only — no need for full credential re-entry when reviewing and approving multiple records in sequence. Practical for bulk review sessions.
Step 04
🔒
Window Closes
After 15 minutes of inactivity, the window closes. The next signature requires full re-authentication with both identification components again.
Why 15 minutes? Industry standard for “single continuous period of controlled system access” under Part 11 §11.200(a)(1). Balances the regulatory requirement for positive identification at each signing against the practical friction of full credential entry when a QA manager is approving 20 requirements in one sitting. The window is not configurable — it reflects the regulatory standard.
Workflow Integration
Signatures as Gated Steps in Approval Workflows
Requirement Approval on_status_change
1 Review QA Engineer · peer review of technical accuracy 1 reviewer
2 Approve QA Manager · formal quality decision 1 approver
3 Sign QA Manager · e-signature via signature modal Part 11
Design Gate Review phase_advance
1 Review QA Engineer · technical review of design phase 1 reviewer
2 Approve QA Manager · multiple independent approvals required 2 approvers
3 Sign Reviewer · phase gate formally closed via e-signature Part 11
Signatures in Reports
How Signature Data Surfaces in Audit-Ready Documents
📄
Validation Summary Report
Signature section lists all approval signatures associated with requirements and tests — signer name, role, meaning, and timestamp. The VSR itself can be signed after generation.
Section: Approval Signatures
🏛️
Regulatory Submission Package
Signature blocks formatted per target authority. FDA submissions include Part 11-compliant records. EU submissions reference Annex 11. Both include all six signature fields.
FDA 510(k) · EU MDR · PMDA
📊
Traceability Matrix
Each requirement row includes an indicator of whether it has been signed and approved. Signature completeness is one of the five Compliance Readiness Score metrics (15% weight).
15% of Compliance Score
“Electronic signatures are not decorative — they are formal attestations with identity verification, defined meanings, and permanent audit trail records that cannot be separated from the records they sign.”
🔒
Bound, not attached. Signatures are embedded in audit trail entries — §11.70 compliance. They cannot be excised or transferred.
🪪
Identity at the moment of signing. Password re-auth prevents signing on another person’s behalf — even if their session is open.
⛓️
Append-only. Signature records cannot be retroactively modified or deleted. The immutability is itself a compliance requirement.

Electronic signatures exist to make this attestation formal, traceable, and tamper-evident. They answer three questions that auditors will always ask:

  1. Who signed? The identity of the person, verified through authentication.
  2. What did they mean? The purpose of the signature — authoring, reviewing, approving, verifying, or rejecting.
  3. When did they sign? The exact timestamp, permanently recorded.

Without formal signatures, approvals are ambiguous. “Someone clicked a button at some point” is not an adequate quality record. Signatures convert that ambiguity into a durable, auditable record.


Amazon

electronic signature pad for regulated industries

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Regulatory Context: 21 CFR Part 11 and EU Annex 11

Two regulations define the requirements for electronic signatures in regulated industries:

21 CFR Part 11 (FDA)

The FDA’s rule on electronic records and electronic signatures, applicable to all FDA-regulated industries (pharmaceuticals, medical devices, biologics, food). Key requirements relevant to QAtrial:

  • Section 11.50: Signed electronic records must contain the printed name of the signer, the date and time of signing, and the meaning of the signature (such as review, approval, responsibility, or authorship).
  • Section 11.70: Signatures must be linked to their respective electronic records so that signatures cannot be excised, copied, or otherwise transferred to falsify a record.
  • Section 11.100: Each electronic signature must be unique to one individual and not reused by or reassigned to anyone else.
  • Section 11.200: Electronic signatures not based on biometrics must employ at least two distinct identification components (such as user ID and password). When performed during a single continuous period of access, the first signing requires both components; subsequent signings require at least one component (e.g., password only).

EU Annex 11 (EMA)

The European guidance on computerized systems, applicable to GMP-regulated activities. Key requirements:

  • Section 14: Electronic signatures should have the same impact as handwritten signatures within the boundaries of the company.
  • Section 12.4: Records must be clear indication of the identity of the person who approved the record. The audit trail must be available and convertible to a generally intelligible form.

QAtrial implements these requirements through its signature modal, re-authentication mechanism, and permanent audit trail recording.


Amazon

digital signature verification device

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

When Users Apply Signatures in QAtrial

Electronic signatures in QAtrial are applied in the context of specific quality actions. Each signature carries a “meaning” that defines the purpose of the signing:

Authored

Applied by the person who created or substantially wrote the content. Authorship signatures are common on requirements, test procedures, and reports. They establish who is responsible for the original content.

Reviewed

Applied by a peer or subject matter expert who has read the content and confirmed it is technically accurate. Review signatures are a quality checkpoint — they verify that another qualified person has examined the work.

Approved

Applied by an authorized person (typically a QA Manager or Admin) who formally accepts the record for use. Approval signatures carry the most regulatory weight — they represent a quality decision. An approved requirement is baselined. An approved report is ready for submission.

Verified

Applied to confirm that a specific condition has been met. Verification signatures are common on test results (confirming the test was executed as described) and CAPA records (confirming that corrective actions were effective).

Rejected

Applied to formally reject a record. Rejection signatures document that an authorized person reviewed the content and determined it does not meet quality criteria. The reason field is especially important for rejection signatures — the author needs to know what to fix.


Amazon

tamper-evident electronic signature software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

The Signature Modal

When a user clicks the signature icon on a requirement, test, CAPA record, or report, QAtrial opens the electronic signature modal. This modal enforces the signing workflow:

Action Context

The modal displays the entity being signed — its ID, title, current status, and type. This ensures the signer knows exactly what they are attesting to. Signing the wrong record is a compliance risk that the modal’s context display helps prevent.

Meaning Selection

The signer selects the meaning of their signature from the available options: authored, reviewed, approved, verified, or rejected. The selected meaning is recorded permanently in the signature record and the audit trail.

Reason Field

The signer must enter a reason or comment explaining their action. In GxP environments, this field should be treated as mandatory — a signature without a rationale is difficult to defend during an audit. The reason might be as simple as “Reviewed against ISO 13485 §7.3 requirements and confirmed coverage” or as specific as “Rejected: boundary conditions in section 3.2 are not testable as written.”

Password Re-Authentication

Before the signature is accepted, the signer must re-enter their password. This is a critical 21 CFR Part 11 requirement — it verifies that the person clicking “Sign” is actually the person whose name will appear on the signature record.

Re-authentication prevents the scenario where someone walks away from their desk and another person signs on their behalf. The password challenge creates a positive identification at the moment of signing.


Amazon

audit trail management software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What Gets Recorded

Every electronic signature produces a permanent record with the following fields:

FieldDescription
signerIdThe unique identifier of the signing user
signerNameThe full name of the signer (as registered in the system)
signerRoleThe role of the signer at the time of signing (Admin, QA Manager, QA Engineer, Reviewer)
timestampISO 8601 timestamp of when the signature was applied
meaningThe purpose of the signature (authored, reviewed, approved, verified, rejected)
methodThe authentication method used (password, pin, biometric)

This record satisfies 21 CFR Part 11 §11.50, which requires the printed name, date and time, and meaning of the signature to be included. The signer role provides additional context that auditors value — it shows that the person who approved a record had the organizational authority to do so.


How Signature Records Appear in the Audit Trail

Signatures are not stored in isolation. They are embedded directly into the audit trail as part of the event that triggered them.

When a user signs a requirement with meaning “approved,” the audit trail records:

  1. An approve action on the requirement entity
  2. The full signature record (signerId, signerName, signerRole, timestamp, meaning, method) embedded within the audit trail entry
  3. The previousValue and newValue JSON snapshots showing the requirement’s state before and after the approval

This binding between signatures and audit trail entries satisfies 21 CFR Part 11 §11.70 — the signature is linked to its electronic record in a way that cannot be separated. You cannot view the signature without seeing the record it applies to, and you cannot view the record’s history without seeing the signatures applied to it.

The audit trail is append-only. Signature records cannot be retroactively modified or deleted. This immutability is a core compliance requirement.


How Signatures Integrate with Workflows

QAtrial’s workflow engine can require electronic signatures as part of structured approval processes. A workflow definition specifies a sequence of steps, and each step can be of type “approval,” “review,” or “sign.”

For example, the default “Requirement Approval” workflow consists of three steps:

  1. Review (QA Engineer) — The requirement is reviewed by a peer
  2. Approve (QA Manager) — The requirement is formally approved
  3. Sign (QA Manager) — An electronic signature is applied

When a workflow step of type “sign” is reached, the assignee must apply an electronic signature through the signature modal. The workflow does not advance until the signature is recorded. This creates a gated process where quality decisions cannot be skipped.

For regulated verticals like pharmaceuticals or medical devices, the “Design Gate Review” workflow requires two approvals before a signature step — ensuring multiple qualified individuals agree before a design phase is formally completed.


How Signatures Appear in Reports

When you generate a report in QAtrial, signature data is included in the relevant sections:

  • Validation Summary Report (VSR): The signature section lists all approval signatures associated with the project’s requirements and tests, including signer name, role, meaning, and timestamp.
  • Regulatory Submission Package: Signature blocks are formatted per the target authority’s expectations. FDA submissions include Part 11-compliant signature records. EU submissions reference Annex 11 requirements.
  • Traceability Matrix: Each requirement row includes an indicator of whether it has been signed and approved.

Reports generated in QAtrial can also be signed themselves. After generating a VSR, the reviewing manager can apply an “approved” signature to the report, creating a signed audit-ready document.


The 15-Minute Verification Window

To balance security with practical usability, QAtrial implements a 15-minute verification window aligned with 21 CFR Part 11 §11.200.

Here is how it works:

  1. When a user applies their first electronic signature in a session (or after the window has expired), they must provide their full credentials: user ID confirmation plus password re-authentication.
  2. After successful authentication, a 15-minute window begins.
  3. During this window, subsequent signatures from the same user require only password re-authentication (one component), not full credential entry.
  4. After 15 minutes of inactivity, the window closes, and the next signature requires full re-authentication.

This approach respects the regulatory requirement for positive identification while avoiding the frustration of full re-authentication for every signature when a reviewer is approving multiple records in sequence. The 15-minute duration is a common industry practice for “single continuous period of access.”


Final Takeaway

Electronic signatures in QAtrial are not decorative — they are formal attestations with identity verification, defined meanings, and permanent audit trail records. Every signature captures who signed, what they meant, when they signed, and how they authenticated. Signatures are bound to the records they apply to and cannot be separated or retroactively modified.

The signature workflow supports the full range of quality activities: authoring, reviewing, approving, verifying, and rejecting. Integration with the workflow engine ensures signatures happen at the right points in the process. Integration with reports ensures signatures are visible in audit-ready documents.


  • Audit Trails — How signature records are embedded in the audit trail and how to view them
  • Reports — How signature blocks appear in Validation Summary Reports and Submission Packages
  • Audit Readiness — How signature completeness contributes to the Compliance Readiness Score

Review how signatures and reports work together. Run npm install && npm run dev, and create a project. Apply signatures to a few requirements, then generate a Validation Summary Report to see how signature records are included in the output.

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

A Practical Guide to Audit Trails in QAtrial

AIThis post was created with the assistance of artificial intelligence (AI).Meta: Learn…

How CAPA Workflows Work in QAtrial

AIThis post was created with the assistance of artificial intelligence (AI).Meta: Learn…

Inside QAtrial’s Architecture: A Technical Overview of the Latest Release

AIThis post was created with the assistance of artificial intelligence (AI).QAtrial v3.0.0…

How QAtrial Handles Traceability from Requirement to Evidence

AIThis post was created with the assistance of artificial intelligence (AI).Traceability is…