Meta: Understand how electronic signatures work in QAtrial, including identity verification, review and approval use cases, signature records, and audit trail linkage.
Get monitors, keyboards and dev gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
Why Signatures Matter in Regulated Workflows
In everyday software, clicking “Approve” is a casual action. In regulated industries, approval carries legal and regulatory weight. When a QA manager approves a requirement, they are attesting — with their professional identity — that the requirement has been reviewed and meets the applicable quality criteria. When a reviewer signs a Validation Summary Report, they are confirming that the report accurately represents the project’s quality status.
Signatures
Basis
Electronic signatures exist to make this attestation formal, traceable, and tamper-evident. They answer three questions that auditors will always ask:
- Who signed? The identity of the person, verified through authentication.
- What did they mean? The purpose of the signature — authoring, reviewing, approving, verifying, or rejecting.
- When did they sign? The exact timestamp, permanently recorded.
Without formal signatures, approvals are ambiguous. “Someone clicked a button at some point” is not an adequate quality record. Signatures convert that ambiguity into a durable, auditable record.
electronic signature pad for regulated industries
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Regulatory Context: 21 CFR Part 11 and EU Annex 11
Two regulations define the requirements for electronic signatures in regulated industries:
21 CFR Part 11 (FDA)
The FDA’s rule on electronic records and electronic signatures, applicable to all FDA-regulated industries (pharmaceuticals, medical devices, biologics, food). Key requirements relevant to QAtrial:
- Section 11.50: Signed electronic records must contain the printed name of the signer, the date and time of signing, and the meaning of the signature (such as review, approval, responsibility, or authorship).
- Section 11.70: Signatures must be linked to their respective electronic records so that signatures cannot be excised, copied, or otherwise transferred to falsify a record.
- Section 11.100: Each electronic signature must be unique to one individual and not reused by or reassigned to anyone else.
- Section 11.200: Electronic signatures not based on biometrics must employ at least two distinct identification components (such as user ID and password). When performed during a single continuous period of access, the first signing requires both components; subsequent signings require at least one component (e.g., password only).
EU Annex 11 (EMA)
The European guidance on computerized systems, applicable to GMP-regulated activities. Key requirements:
- Section 14: Electronic signatures should have the same impact as handwritten signatures within the boundaries of the company.
- Section 12.4: Records must be clear indication of the identity of the person who approved the record. The audit trail must be available and convertible to a generally intelligible form.
QAtrial implements these requirements through its signature modal, re-authentication mechanism, and permanent audit trail recording.
digital signature verification device
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
When Users Apply Signatures in QAtrial
Electronic signatures in QAtrial are applied in the context of specific quality actions. Each signature carries a “meaning” that defines the purpose of the signing:
Authored
Applied by the person who created or substantially wrote the content. Authorship signatures are common on requirements, test procedures, and reports. They establish who is responsible for the original content.
Reviewed
Applied by a peer or subject matter expert who has read the content and confirmed it is technically accurate. Review signatures are a quality checkpoint — they verify that another qualified person has examined the work.
Approved
Applied by an authorized person (typically a QA Manager or Admin) who formally accepts the record for use. Approval signatures carry the most regulatory weight — they represent a quality decision. An approved requirement is baselined. An approved report is ready for submission.
Verified
Applied to confirm that a specific condition has been met. Verification signatures are common on test results (confirming the test was executed as described) and CAPA records (confirming that corrective actions were effective).
Rejected
Applied to formally reject a record. Rejection signatures document that an authorized person reviewed the content and determined it does not meet quality criteria. The reason field is especially important for rejection signatures — the author needs to know what to fix.
tamper-evident electronic signature software
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The Signature Modal
When a user clicks the signature icon on a requirement, test, CAPA record, or report, QAtrial opens the electronic signature modal. This modal enforces the signing workflow:
Action Context
The modal displays the entity being signed — its ID, title, current status, and type. This ensures the signer knows exactly what they are attesting to. Signing the wrong record is a compliance risk that the modal’s context display helps prevent.
Meaning Selection
The signer selects the meaning of their signature from the available options: authored, reviewed, approved, verified, or rejected. The selected meaning is recorded permanently in the signature record and the audit trail.
Reason Field
The signer must enter a reason or comment explaining their action. In GxP environments, this field should be treated as mandatory — a signature without a rationale is difficult to defend during an audit. The reason might be as simple as “Reviewed against ISO 13485 §7.3 requirements and confirmed coverage” or as specific as “Rejected: boundary conditions in section 3.2 are not testable as written.”
Password Re-Authentication
Before the signature is accepted, the signer must re-enter their password. This is a critical 21 CFR Part 11 requirement — it verifies that the person clicking “Sign” is actually the person whose name will appear on the signature record.
Re-authentication prevents the scenario where someone walks away from their desk and another person signs on their behalf. The password challenge creates a positive identification at the moment of signing.
As an affiliate, we earn on qualifying purchases.
What Gets Recorded
Every electronic signature produces a permanent record with the following fields:
| Field | Description |
|---|---|
signerId | The unique identifier of the signing user |
signerName | The full name of the signer (as registered in the system) |
signerRole | The role of the signer at the time of signing (Admin, QA Manager, QA Engineer, Reviewer) |
timestamp | ISO 8601 timestamp of when the signature was applied |
meaning | The purpose of the signature (authored, reviewed, approved, verified, rejected) |
method | The authentication method used (password, pin, biometric) |
This record satisfies 21 CFR Part 11 §11.50, which requires the printed name, date and time, and meaning of the signature to be included. The signer role provides additional context that auditors value — it shows that the person who approved a record had the organizational authority to do so.
How Signature Records Appear in the Audit Trail
Signatures are not stored in isolation. They are embedded directly into the audit trail as part of the event that triggered them.
When a user signs a requirement with meaning “approved,” the audit trail records:
- An
approveaction on the requirement entity - The full signature record (signerId, signerName, signerRole, timestamp, meaning, method) embedded within the audit trail entry
- The
previousValueandnewValueJSON snapshots showing the requirement’s state before and after the approval
This binding between signatures and audit trail entries satisfies 21 CFR Part 11 §11.70 — the signature is linked to its electronic record in a way that cannot be separated. You cannot view the signature without seeing the record it applies to, and you cannot view the record’s history without seeing the signatures applied to it.
The audit trail is append-only. Signature records cannot be retroactively modified or deleted. This immutability is a core compliance requirement.
How Signatures Integrate with Workflows
QAtrial’s workflow engine can require electronic signatures as part of structured approval processes. A workflow definition specifies a sequence of steps, and each step can be of type “approval,” “review,” or “sign.”
For example, the default “Requirement Approval” workflow consists of three steps:
- Review (QA Engineer) — The requirement is reviewed by a peer
- Approve (QA Manager) — The requirement is formally approved
- Sign (QA Manager) — An electronic signature is applied
When a workflow step of type “sign” is reached, the assignee must apply an electronic signature through the signature modal. The workflow does not advance until the signature is recorded. This creates a gated process where quality decisions cannot be skipped.
For regulated verticals like pharmaceuticals or medical devices, the “Design Gate Review” workflow requires two approvals before a signature step — ensuring multiple qualified individuals agree before a design phase is formally completed.
How Signatures Appear in Reports
When you generate a report in QAtrial, signature data is included in the relevant sections:
- Validation Summary Report (VSR): The signature section lists all approval signatures associated with the project’s requirements and tests, including signer name, role, meaning, and timestamp.
- Regulatory Submission Package: Signature blocks are formatted per the target authority’s expectations. FDA submissions include Part 11-compliant signature records. EU submissions reference Annex 11 requirements.
- Traceability Matrix: Each requirement row includes an indicator of whether it has been signed and approved.
Reports generated in QAtrial can also be signed themselves. After generating a VSR, the reviewing manager can apply an “approved” signature to the report, creating a signed audit-ready document.
The 15-Minute Verification Window
To balance security with practical usability, QAtrial implements a 15-minute verification window aligned with 21 CFR Part 11 §11.200.
Here is how it works:
- When a user applies their first electronic signature in a session (or after the window has expired), they must provide their full credentials: user ID confirmation plus password re-authentication.
- After successful authentication, a 15-minute window begins.
- During this window, subsequent signatures from the same user require only password re-authentication (one component), not full credential entry.
- After 15 minutes of inactivity, the window closes, and the next signature requires full re-authentication.
This approach respects the regulatory requirement for positive identification while avoiding the frustration of full re-authentication for every signature when a reviewer is approving multiple records in sequence. The 15-minute duration is a common industry practice for “single continuous period of access.”
Final Takeaway
Electronic signatures in QAtrial are not decorative — they are formal attestations with identity verification, defined meanings, and permanent audit trail records. Every signature captures who signed, what they meant, when they signed, and how they authenticated. Signatures are bound to the records they apply to and cannot be separated or retroactively modified.
The signature workflow supports the full range of quality activities: authoring, reviewing, approving, verifying, and rejecting. Integration with the workflow engine ensures signatures happen at the right points in the process. Integration with reports ensures signatures are visible in audit-ready documents.
Related Topics
- Audit Trails — How signature records are embedded in the audit trail and how to view them
- Reports — How signature blocks appear in Validation Summary Reports and Submission Packages
- Audit Readiness — How signature completeness contributes to the Compliance Readiness Score
Review how signatures and reports work together. Run npm install && npm run dev, and create a project. Apply signatures to a few requirements, then generate a Validation Summary Report to see how signature records are included in the output.
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
