I still see it every quarter during audits and internal cleanups: an SOP, change request, or release note where the "approval" is a forwarded email with a typed name at the bottom. To be fair, emails are convenient. People are busy. But 21 CFR Part 11 has been clear for decades: a typed name in an email is not an electronic signature. If you rely on that for controlled documents, you are one surprise away from a finding.
The surprise I still see in practice
I've been the person who had to explain to a team — calmly, repeatedly — that the email thread that shows "Reviewed. John Smith" does not meet signature requirements. In notified-body and FDA-style inspections the questions are straightforward:
- Who exactly approved this revision?
- How was their identity assured?
- When did approval occur (timestamp on the record)?
- What does the signature mean (approved, reviewed, for implementation)?
- Can the signature be repudiated or the record altered?
An email chain rarely answers those cleanly. In practice this means extra work during audits: reconstructing a timeline, getting retrospective attestations, and in some cases redoing approvals in the right system.
Why a typed name fails 21 CFR Part 11 (and basic document control)
21 CFR Part 11 is not mystical; it requires that electronic records and electronic signatures be attributable, linked to the record, and maintained with controls that ensure integrity and non‑repudiation. Practically speaking, an approval needs to cover:
- Identity: Is the approver uniquely identified and authenticated?
- Intent/meaning: What did the approver mean by that signature?
- Integrity: Can the record be altered without detection?
- Traceability: Is there an auditable trail tying action to person/time?
- Retention/binding: Is the signature bound to the record, not floating in an inbox?
A typed name in an email fails on all five counts:
- Emails can be sent by others (delegation, shared mailboxes) or spoofed.
- The intent is ambiguous—"Thanks" is not "Approved for release".
- Email content and attachments can be edited or forwarded, breaking integrity.
- Your document control system has no record of the approval action and so traceability is lost.
- The signature (the typed name) isn’t bound to the controlled document version — the inbox is not your Technical File.
Practical fixes that don't require a full IT rewrite
Granted, not every company can rip out their process and buy a new eQMS tomorrow. Some practical, audit-defensible steps that I have used (and seen accepted) include:
- Use your controlled QMS for approvals. A modern eQMS provides authenticated logins, a discrete "approve" action, timestamping, and a locked, versioned copy of the document. This is the cleanest path.
- If you must use email temporarily, require a documented hand-off: the approver must perform the approval action in the QMS within a defined short window (24–72 hours) and the system must capture who did it, date/time, and the "meaning" (e.g. "Approved for release"). Keep the email only as supplementary evidence.
- Use digitally signed documents where feasible. Digital signatures (PKI-backed or PAdES-style) that assert identity and integrity are acceptable when your organisation validates them against Part 11 controls.
- For truly legacy, low-volume situations — wet signature pages scanned and attached into the QMS, with the scanned image locked and linked to the record — can work. But be careful: the scanned image itself must be protected against tampering and your QMS must capture who uploaded it and when.
- Standardise signature meanings. Make your approval buttons or signature fields explicitly state the meaning (e.g. "Approved for release", "Approved for training only") and record that meaning in the audit trail.
A short checklist before relying on any "approval" method
Before you accept an approval method, check it against these minimal questions:
- Can the approver be uniquely authenticated?
- Is the approval action captured and time-stamped in the QMS?
- Is the approval explicitly tied to a document version?
- Is the meaning of the signature recorded?
- Can we detect if the document or signature has been altered?
If you answer "no" to any of these, you are accepting risk — audit risk, regulatory risk, and patient-safety risk.
Why this matters beyond a citation in Part 11
This isn't just about ticking a box for FDA inspectors. Approval-by-email breaks traceability, which propagates into change impact analysis, CAPA triage, and PMCF/PSUR workflows. If a CAPA is triggered by a document change, and that change cannot be reliably attributed to an approver and time, your CAPA root-cause and risk assessment suffer. Connected workflow isn't marketing noise; it's how you retain defensible decisions and maintain product safety.
How I handle legacy email approvals
When I inherited processes that used email approvals, I did three things:
- I mapped where email approvals were used and why (speed, lack of automation, habit).
- I fixed the quick wins: reconfigure the QMS so that approvals are one-click in the system and auto-notify approvers.
- For the stubborn parts, I documented a temporary bridging SOP: emails were allowed only for acknowledgement, not for approval, and a follow-up QMS approval was mandatory within 48 hours.
To be fair, changing behaviour is the hard part. Tech helps, but policy and training close the last mile.
How are you handling legacy email approvals in your organisation — pragmatic fixes, full migrations, or still hoping no one inspects that inbox?
Top comments (0)