Guides

The electronic batch record (EBR): what EU GMP Annex 11 and 21 CFR Part 11 require, and what it looks like in practice

Flacoane farmaceutice pe o linie de producție, cu structuri moleculare

In short: the electronic batch record (EBR) replaces the printed, hand-filled batch record with a record made at the moment each step is performed: the operator scans the materials, enters the parameters and signs electronically, while the system checks quantities and limits on the spot. To be accepted at inspection, the system has to comply with EU GMP Annex 11 and, for the US market, 21 CFR Part 11: audit trail, electronic signatures with meaning, access control and validation at the user’s site.

What the batch record is and why it matters

The batch record is the document that proves a batch of medicine, cosmetic or supplement was manufactured according to the approved procedure: which materials went in, in what quantities, who performed each step, which parameters were measured, which checks were done and who verified. It is the document every inspection asks for and the basis for the batch release decision.

On paper, the record is printed, filled in by hand and then checked line by line by quality assurance. Every transcription is a chance for error, and releasing a batch can wait for days because of a missing signature or an illegible figure.

What EU GMP Annex 11 requires

Annex 11 to the EU GMP guide applies to all computerised systems used in GMP-regulated activities. The requirements that matter most for an EBR:

  • Validation: the system is validated on the user’s processes, based on a risk assessment, with documented requirements and tests that cover them.
  • Audit trail: any creation, modification or deletion of regulated data is recorded with author, time and reason, and the log cannot be disabled or edited.
  • Access and security: individual accounts, role-based permissions, blocking of unauthorised access.
  • Electronic signatures: permanently linked to the signed record, with date and time, equivalent to a handwritten signature within the company.
  • Data integrity: checks when critical data is entered, periodic backups, the ability to print records and reconstruct the history.
  • Periodic review of the system, incidents and changes.

What 21 CFR Part 11 requires

The FDA regulation covers electronic records and signatures. In practice, the requirements largely overlap with Annex 11, with a few points of emphasis:

  • An electronic signature has at least two components (for example user and password) and is re-entered at every signing, not just at login.
  • Every signature shows the signatory’s name, the date, the time and the meaning: performed, verified, approved, released.
  • The audit trail is system-generated, time-stamped and kept at least as long as the record it refers to.
  • The system must be able to produce legible, complete copies of the records for inspection.

The ALCOA+ principles (attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring and available) sum up what inspectors look for in both frameworks.

What a day with an EBR looks like in practice

  1. The master procedure approved by QA becomes a record for the batch to be manufactured, with targets calculated for its size.
  2. Line clearance is done as a checklist before start-up: clean equipment, valid calibration, area free of foreign materials.
  3. Materials are added by scanning the label on the container. The system refuses a wrong material or an unapproved batch and checks the quantity tolerance.
  4. Process parameters and in-process controls (IPC) are entered at the moment of measurement, with an on-the-spot verdict against the limits.
  5. Every step is signed, and critical steps also have a witness. Uncleaned equipment or expired calibration requires a reason and becomes an exception.
  6. Material reconciliation at the end: how much was received, consumed, returned and lost, with thresholds per item.
  7. QA review by exception: quality assurance looks at what went out of parameters, not at dozens of pages, then releases the batch with an electronic signature.

Validation: software isn’t certified, it is validated

There is no “GMP certificate” for a piece of software. The system is validated at each user’s site, on their processes. What you should get from the vendor as a starting point:

  • user requirements (URS) and a traceability matrix that links every requirement to a test;
  • a risk analysis and the system’s position against Annex 11 and 21 CFR Part 11;
  • a data integrity statement, based on the ALCOA+ principles;
  • IQ, OQ and PQ qualification templates;
  • procedures for users and roles, backup, continuity, incidents and audit trail review;
  • the GAMP 5 classification: a configured and custom-developed system is treated as category 5 software, and the validation documentation starts from there.

What you gain compared with paper

  • Transcription errors disappear, because data is recorded once, at the source.
  • Deviations are visible during the batch, not at the review afterwards.
  • Batch release no longer waits for a missing signature or an illegible figure.
  • In a market recall, the list of customers who received the batch is ready on the spot.
  • At inspection, the record, the audit trail, deviations and laboratory results are in the same place.

Frequently asked questions

Do we have to give up the batch records we use now?

No. The master procedures are built starting from your current records. The steps, parameters and controls stay yours; only the place where they are filled in changes.

Does it apply to cosmetics or food supplements too?

Yes, with different rules. Cosmetics follow the good practices of ISO 22716 and Regulation 1223/2009, supplements focus on raw material specifications, deadlines and HACCP principles. The basic flows (batches, specifications, quality control, traceability) are the same.

Can an administrator modify the audit trail?

In a compliant system, no. Log entries are only ever added; they cannot be edited, deleted or switched off, not even by an administrator.

How long does an EBR implementation take?

It depends on the number of products and procedures and on the connections to the ERP. The stages: process analysis and writing the requirements, configuring recipes and procedures, importing data from the ERP in a test run, IQ/OQ/PQ validation, training and go-live with real batches. You can start with the warehouse and quality control and move to the electronic record afterwards.

Where does the system run?

On your own server, in the plant’s network, or in a dedicated cloud, with backups configured locally or externally and the retention period you choose.

DataFlows Pharma is our pharmaceutical manufacturing system, built on the requirements of EU GMP, Annex 11 and 21 CFR Part 11, with an electronic batch record on a tablet. See how it works or request a demo.

Mihai Postelnicu
Author
Mihai Postelnicu

Mihai Postelnicu leads DataFlows implementations. He has 20 years of experience delivering custom software solutions, 10 years analysing workflows in warehouses, manufacturing and public institutions, and has led large implementation teams on custom software projects.

Previous article
What is a WMS and when do you need one
Next article
Custom software or off-the-shelf product? How to choose, and what starting from a platform means

More articles

Lucrător de depozit cu laptop, între rafturi cu marfă

What is a WMS and when do you need one

What a warehouse management system (WMS) does, how it differs from the stock module of your invoicing software, the signs you need one, how long implementation takes and what the cost is made of.

Like what you read?

See how it would look on your data

We show you the right solution, on a scenario close to yours.

Request a demoCall us: +40 712 344 092
Monday–Friday, 9:00–18:00

Read next

More guides and case studies from the DataFlows blog.

Let’s talk about your process

Choose from many ready-to-run solutions or tell us about your specific scenario

keyboard_arrow_up