And in 2026, that misunderstanding costs more than ever
It happens at least a few times a year as I work with pharma, biotech, and medtech clients. We start talking about computerized system use or the data integrity of records, and I invariably hear some version of:
“Our electronic data is printed out and stored as the ‘original data,’ so we don’t have a computerized systems data integrity issue.”
Even though I know this is patently untrue, I understand exactly how we all got here. And with three major regulatory shifts landing across 2025 and 2026, it is worth revisiting why this belief persists, and why it is now a riskier assumption than ever.
How We Got Here: The Evolution of 21 CFR Part 11
The pharmaceutical industry originally asked the FDA for guidance around using computer systems to eliminate paper records in the early 1990s, back when some of us were still saving data to floppy disks. A task force was convened, and the final rule for 21 CFR Part 11 (Electronic Records; Electronic Signatures) was published in 1997.
Part 11 applied across all FDA program areas and stated that using electronic records was not mandatory. That single point created widespread confusion. In 1999, a Compliance Policy Guide (CPG) and five guidance documents were drafted to clear things up…but the consensus was that they significantly increased the cost of using technology, discouraging innovation and restricting adoption. Essentially the opposite of what was intended.
In 2003, the FDA revoked the CPG and those five documents, replacing them with the Guidance on the Scope and Application of Part 11 (September 3, 2003), which deliberately narrowed which records fell under the full authority of Part 11. When records that must be maintained under predicate rules (such as 21 CFR 211 for drugs or 21 CFR 820 for devices), or submitted to FDA, are kept electronically, Part 11 applies. When a computer is merely used to generate a permanent paper record, Part 11 does not. This is the so-called “typewriter clause”: just as a typewriter would not be inspected, the computer that generated a document would not be either, as long as the document itself is the true and official record.
Does Printing Data Exempt It From Part 11? Not Necessarily.
The belief that printing electronic data makes the paper copy the “original” is a misinterpretation of the regulatory intent.
- If a system stores electronic records and is used for any GxP function, the electronic data is the original record, whether or not you print it.
- If a system is used only to generate a permanent paper record, and that paper is the sole basis for regulated decisions, Part 11 may not apply, but that determination needs to be assessed, documented, and justified.
- Simply printing data does not shield a system from compliance obligations, and regulators scrutinize these decisions more closely every year.
The Modern Landscape: Three Shifts You Can’t Ignore
The understanding and application of how electronic data is treated has moved well beyond where it sat even a few years ago. Through Form 483 observations and Warning Letter trends, enforcement has become far more consistent, and the FDA’s Data Integrity and Compliance With Drug CGMP: Questions and Answers guidance (December 2018) made the framework explicit: electronic records must be trustworthy, reliable, and accurate, and printing them does not eliminate the need for electronic controls. Today that expectation is framed around the ALCOA+ principles. Data that is Attributable, Legible, Contemporaneous, Original, and Accurate, plus Complete, Consistent, Enduring, and Available.
What has genuinely changed since I first wrote on this topic is the regulatory environment surrounding those principles. Three developments now shape how data integrity will be inspected:
1. FDA’s Computer Software Assurance (CSA) guidance is final.
On September 24, 2025, the FDA finalized Computer Software Assurance for Production and Quality System Software (Docket FDA-2022-D-0795), superseding Section 6 of the 2002 General Principles of Software Validation. CSA replaces exhaustive, documentation-heavy validation with a risk-based, least-burdensome assurance model built around a system’s intended use and patient-safety risk, and, for the first time, it directly addresses cloud, SaaS, PaaS, and IaaS environments. It does not change data integrity expectations; it changes how you demonstrate that the systems holding your regulated data are trustworthy.
2. The QMSR is now in effect and it changes the predicate rule I referenced above.
As of February 2, 2026, 21 CFR Part 820 is the Quality Management System Regulation (QMSR), which incorporates ISO 13485:2016 by reference. The device predicate rule that determines when Part 11 applies now points to an international standard, one that carries its own explicit expectations for control of documents, records, and software. For device manufacturers, data integrity and Part 11 obligations do not relax under the QMSR; they arrive framed in ISO 13485 language, and inspections have shifted to match.
3. EU Annex 11 is being rewritten around the same principles.
The European Commission and PIC/S published a complete rewrite of EU GMP Annex 11 (Computerised Systems) in draft on July 7, 2025, with a public consultation that closed in October 2025 and a final version expected in mid-2026. The draft expands a five-page guideline into a comprehensive document covering ALCOA+, audit trails, identity and access management, supplier oversight, and, for the first time, cybersecurity as a core GMP requirement, alongside a new Annex 22 on artificial intelligence. For any company exporting to the EU, the direction of travel is unmistakable: global regulators are converging on the same data integrity expectations. Although this doesn’t explicitly implicate medical devices, its aligned with expectations.
Enforcement Is Not Slowing Down
If any of this reads as theoretical, the enforcement data says otherwise. FDA inspections returned to full pace in 2025, warning-letter volume rose sharply year over year, and data integrity remained one of the most frequently cited problem areas, driven by audit-trail gaps, weak access controls, and poorly governed hybrid paper-and-electronic systems. Quality-system and data integrity findings continue to dominate, and they are increasingly treated as systemic culture problems rather than isolated slips.
The Bottom Line: The Paper Copy Is Not the Original Record
So, simply: if you print the electronic data and store it as a paper record … that’s nice. But it is not the original record. The original record is the electronic data held within the computerized system. The good news is that today’s operating systems and validated platforms include features that make Part 11 and ALCOA+ compliance far more achievable than they were in the floppy-disk era. The catch, as with most things, is that these features are not automatic. Data integrity has to be deliberately designed, assessed, and maintained and under CSA, the QMSR, and the coming Annex 11, that expectation is only sharpening.
Take a critical look at your electronic systems and documentation strategies before the regulators do.
Have questions about meeting Part 11 and data integrity expectations under the CSA guidance, the QMSR, or the evolving EU framework? Contact QLeaR Advisors at contact@QLeaRAdvisors.com. We help medtech and life sciences teams bring QLaRity to computerized-system compliance proactively.
Key References
FDA, 21 CFR Part 11 — Electronic Records; Electronic Signatures (final rule, 1997).
FDA, Guidance for Industry: Part 11, Electronic Records; Electronic Signatures — Scope and Application (September 2003).
FDA, Data Integrity and Compliance With Drug CGMP: Questions and Answers, Guidance for Industry (December 2018).
FDA, Computer Software Assurance for Production and Quality System Software, Final Guidance (September 24, 2025; Docket FDA-2022-D-0795).
FDA, Quality Management System Regulation (QMSR), amended 21 CFR Part 820 incorporating ISO 13485:2016 by reference (effective February 2, 2026).
European Commission / PIC/S, Draft revision of EU GMP Annex 11 (Computerised Systems) and new Annex 22 (Artificial Intelligence), published July 7, 2025; final expected mid-2026.
