Exploring 21 CFR Part 11 Compliance

Major Projects

Client

Formulatrix

Service

UI/UX

Year

2024

Context

As our company prepared to expand into regulated markets, one challenge became unavoidable: compliance with 21 CFR Part 11. This FDA regulation defines how electronic records and electronic signatures must be managed to ensure data accuracy, integrity, confidentiality, and traceability.

For our customers, especially in pharmaceutical and biotechnology labs, compliance was not optional. Without it, they could not legally use our system in their workflows. That meant our software risked being excluded from an entire segment of the market — a serious business limitation.

At that time, our product had several gaps:

  • Weak or non-existent user access controls.

  • No reliable audit trail to trace actions.

  • Limited enforcement of security and accountability.

As the UX/UI Designer, I was tasked with exploring the regulation from the ground up. My role was to translate complex compliance requirements into practical design directions that could later be developed into usable features. This became the foundation for two major projects: User Management and Audit Trail.

Problem Point

At the time, our software did not fully meet the requirements for compliance. In particular:

  • No robust user management to enforce security and access controls.

  • No audit trail to record who did what, and when.

  • Gaps in data integrity and traceability, limiting adoption in regulated labs.

To address this, we needed to explore 21 CFR Part 11 in depth and identify which areas applied to our software.

Exploration & Brainstorming

I began by reviewing the official 21 CFR Part 11 documentation to understand the full scope of the regulation. From this, I identified which clauses were relevant and which features would directly impact our product.

This process revealed two main categories:

  • Electronic records (§ 11.10 – § 11.70)

  • Electronic signatures (§ 11.100 – § 11.300)

Focus Areas

After mapping regulatory requirements to our software context, I defined the objective:

  • Design a User Management and Audit Trail system that ensures compliance with 21 CFR Part 11, focusing on data integrity, security, and traceability.

From this point, my work split into two dedicated projects:

  1. User Management – building secure access controls and role-based permissions.

  2. Audit Trail – creating a traceable, computer-generated log of all actions.

Outcome

This brainstorming phase created the foundation for our compliance initiative. By narrowing scope early, we ensured the team could focus on two critical areas that delivered the most impact. These became the basis for the detailed projects that followed — the User Management and Audit Trail features, both of which strengthened customer confidence and moved our product closer to full compliance.

Create a free website with Framer, the website builder loved by startups, designers and agencies.