Define the operating boundary
A useful definition names the triggering event, required inputs, governing source, accountable owner, decision or action, exception path, evidence retained, and downstream handoff. Buyers should adapt those elements to their own population, jurisdictions, policies, systems, and control model before writing requirements.
The most important distinction is between a label and an operational capability. A provider may document electronic signatures audit trails and record history while depending on customer-supplied policy, licensed content, third-party data, integration partners, manual review, or services. The demonstration should expose those dependencies rather than hiding them behind a completed interface.
What a demonstration should prove
- Begin with representative source records and a named policy, standard, or controlled rule.
- Show the normal path, an ambiguous case, missing data, an exception, an override, and a material source change.
- Identify who can change rules, who can approve or reject, and how accountability is preserved.
- Trace every output back to inputs, versions, timestamps, user actions, and governing evidence.
- Export the resulting record and reconcile it with downstream systems and retained obligations.
Authority and operating context
21 CFR Part 11
Part 11 sets criteria under which FDA considers electronic records and signatures trustworthy, reliable, and generally equivalent to paper records and handwritten signatures. Laboratory buyers need to connect system features to the actual electronic records, signatures, controls, and predicate-rule obligations in scope rather than treating a product label as a compliance conclusion.
21 CFR 211.194
The section specifies content for laboratory records, including samples, methods, test data, calculations, results, initials, dates, second-person review, and investigation references. It anchors a buyer's record model for sample identity, method control, raw data, calculation, result review, and traceable exceptions in relevant drug-manufacturing laboratories.
21 CFR Part 58
Part 58 establishes organizational, personnel, facility, equipment, protocol, operating-procedure, record, reporting, and archive requirements for specified nonclinical studies. Research-system evaluations should trace study, specimen, protocol, instrument, observation, amendment, report, and archive records without assuming an ELN or LIMS alone constitutes a GLP system.
FDA Part 11 Scope Guidance
The guidance explains FDA's narrow interpretation of Part 11 scope and enforcement discretion for certain provisions while retaining applicable predicate-rule requirements. It requires buyers to identify the authoritative record, reliance on the electronic record, predicate rule, copies, retention, and controls before converting a feature checklist into a regulatory assertion.
FDA Data Integrity Guidance
The guidance addresses complete, consistent, accurate data; metadata; audit trails; access; review; blank forms; testing into compliance; and investigation of data-integrity problems. Laboratory systems must preserve record context, metadata, changes, roles, review, and investigation across instruments, CDS, SDMS, LIMS, LES, and manual steps rather than treating an audit-trail feature as the complete control system.
FDA Computer Software Assurance Guidance
The guidance describes a risk-based approach to establishing confidence in automation used for production or quality systems, including intended use, risk analysis, assurance activities, records, and appropriate testing. It gives laboratory and quality buyers a disciplined way to separate vendor evidence, configured intended use, process risk, assurance activity, unscripted testing, and retained objective evidence.
EU GMP Annex 11
Annex 11 addresses risk management, personnel, suppliers, validation, data, accuracy checks, storage, printouts, audit trails, change, security, incident management, signatures, business continuity, and archiving. It keeps laboratory-system assurance connected to the full system lifecycle and regulated process, not merely a list of application functions.
EU GMP Chapter 4
Chapter 4 places specifications, instructions, procedures, records, reports, controls, approval, availability, legibility, traceability, correction, retention, and hybrid-system relationships within the pharmaceutical quality system. Laboratory architecture should show which system owns each instruction, specification, raw record, result, review, approval, exception, and retained copy across electronic and paper processes.
MHRA Data Integrity Guidance
The MHRA record addresses data governance, lifecycle, criticality, metadata, audit trails, access, review, retention, hybrid systems, and organizational culture. It supports a system-of-record map that follows data from creation through processing, review, reporting, transfer, archive, and destruction while preserving organizational accountability.
PIC/S PI 041-1
PI 041-1 describes data governance, risk, lifecycle, organizational controls, computerized and paper systems, audit trails, review, outsourcing, and remediation considerations. It helps buyers examine data ownership, criticality, system boundaries, third parties, review, backup, archive, and remediation across the laboratory stack.
OECD GLP Principles
OECD GLP principles organize test-facility management, quality assurance, facilities, apparatus, test systems, materials, procedures, study performance, reporting, and archives. Scientific systems should preserve study responsibilities, test-system identity, methods, observations, changes, reports, and archives without conflating system capability with study validity.
OECD GLP Advisory Document No. 22
The advisory document addresses data governance, lifecycle, criticality, metadata, computerized systems, dynamic data, cloud and service arrangements, review, archive, and reconstruction in GLP settings. It supports deeper evaluation of whether a laboratory architecture retains enough context and metadata to reconstruct activity across instruments, analytical systems, scientific repositories, and study records.
ISO/IEC 17025:2017
ISO/IEC 17025 specifies requirements for laboratory competence, impartiality, and consistent operation across resources, processes, and management systems. A laboratory platform can support requests, methods, equipment, samples, technical records, results, reporting, nonconforming work, and improvement while competence remains an organizational and technical determination.
ISO 15189:2022
ISO 15189 specifies quality and competence requirements for medical laboratories, including governance, resources, pre-examination, examination, post-examination, information, risk, and improvement. Clinical laboratory systems should support patient and specimen identity, orders, methods, results, critical communication, quality, records, and interfaces while clinical competence and diagnostic validity remain outside software alone.
ISO 9001:2015
ISO 9001 specifies requirements for a quality management system covering context, leadership, planning, support, operation, performance evaluation, and improvement. Laboratory systems can support controlled operational records and evidence, but the quality system spans leadership, competence, risk, suppliers, process performance, nonconformity, and improvement.
NIST RDaF 2.0
RDaF organizes research-data concerns across planning, lifecycle, infrastructure, standards, governance, workforce, and community perspectives. It gives R&D buyers a broader research-data operating model for stewardship, interoperability, access, preservation, reuse, and governance beyond notebook authoring or file storage.
NIH DMS Policy
The policy requires applicable researchers to plan for management and sharing of scientific data and to comply with approved plans, subject to limitations and protections. R&D platforms should make data identification, metadata, access, repository, retention, sharing, privacy, and stewardship responsibilities visible without implying that an ELN alone satisfies the plan.
Operating domains
Sample identity and chain of custody
The control system for assigning identity, preserving parent-child and container relationships, recording location and custody, managing quantity and condition, and retaining every material transition from receipt through disposition.
Laboratory requests, specifications, and workload
The operating layer that converts a customer, study, production, quality, or clinical need into an authorized request with defined samples, tests, methods, specifications, priority, due date, status, and responsibility.
Method, procedure, and laboratory execution control
The maintained relationship among approved methods, parameters, specifications, versioned instructions, execution steps, observations, calculations, deviations, and reviewer evidence.
Result calculation, review, and exceptions
The decision chain that preserves raw observations, processing, calculations, units, specifications, flags, changes, technical review, investigation, approval, and reportable result status.
Electronic records and data integrity
The governance and control system for attributable, legible, contemporaneous, original or verified-copy, accurate, complete, consistent, enduring, available records and their metadata throughout the lifecycle.
Scientific data lifecycle and provenance
The architecture for retaining the identity, source, context, transformations, relationships, versions, ownership, access, preservation, and reuse conditions of scientific data and files.
Instrument connectivity and physical-digital custody
The governed boundary among instrument state, material placement, method parameters, worklists, acquisition, raw data, status events, error handling, transfer, and downstream record acknowledgement.
System integration, master data, and interoperability
The operating model for authoritative identities, reference data, transactions, scientific objects, events, documents, error handling, reconciliation, and ownership across laboratory and enterprise systems.
Computerized-system lifecycle, assurance, and change
The managed lifecycle from intended use and process ownership through supplier assessment, risk analysis, configuration, testing, release, operation, access, incident, change, continuity, retirement, and retained evidence.
Scientific knowledge, collaboration, and reuse
The research operating layer that relates hypotheses, entities, materials, experiments, protocols, observations, files, analysis, decisions, authorship, permissions, and reusable knowledge.
Evidence and comparison limits
Official provider documentation can establish product positioning. Provider confirmation can clarify package or availability. Independent observation requires a disclosed scenario, environment, date, inputs, and reproducible result. None of those sources alone establishes buyer-specific legal, clinical, regulatory, quality, or operational fitness.
Buyer questions
- What exact outcome and evidence should electronic signatures audit trails and record history produce?
- Which source, version, and customer facts govern the workflow?
- Which decisions remain human and who is accountable for them?
- What is native, configured, integrated, service-delivered, or planned?
- How does a changed source affect open and historical records?
Recent changes
FDA's CSA record keeps assurance tied to intended use and process risk — Laboratory-system evidence is decision-useful only when the market label, authoritative record, configured workflow, scientific data, technical control, accountable reviewer, and unresolved boundary remain visible.
Part 11 scope starts with the record—not the feature checklist — Laboratory-system evidence is decision-useful only when the market label, authoritative record, configured workflow, scientific data, technical control, accountable reviewer, and unresolved boundary remain visible.
MHRA's current page points GLP readers to the later OECD data-integrity advisory — Laboratory-system evidence is decision-useful only when the market label, authoritative record, configured workflow, scientific data, technical control, accountable reviewer, and unresolved boundary remain visible.
ISO/IEC 17025 is a laboratory competence system—not a LIMS badge — Laboratory-system evidence is decision-useful only when the market label, authoritative record, configured workflow, scientific data, technical control, accountable reviewer, and unresolved boundary remain visible.
LabVantage's current portfolio shows LIMS, ELN, LES, and SDMS convergence without erasing the boundaries — Laboratory-system evidence is decision-useful only when the market label, authoritative record, configured workflow, scientific data, technical control, accountable reviewer, and unresolved boundary remain visible.
Agilent SLIMS connects laboratory workflow with the OpenLab analytical ecosystem — Laboratory-system evidence is decision-useful only when the market label, authoritative record, configured workflow, scientific data, technical control, accountable reviewer, and unresolved boundary remain visible.