It was a Tuesday night before a surveillance audit. I spent four hours printing, hole-punching, and stapling controlled records because the lead auditor's pre-questionnaire asked for "wet-signed evidence of approval." I did it. I do not do it anymore.
That session taught me two things. The first is that I had not done the work ahead of time to make the eQMS audit trail legible to someone who had not seen the system before. The second is that, in most cases, the wet-signature request is not what the standard asks for — it is what the auditor has always asked for, and no one on my side has ever argued back with a clean answer.
What the standard actually requires
If you go looking, the standards are surprisingly quiet about ink.
- ISO 13485:2016, clause 4.2.5 (control of records) requires records to remain legible, readily identifiable, and retrievable, and to be protected from unauthorised changes. It does not specify wet signatures.
- ISO 13485:2016, clause 4.2.4 (control of documents) requires documents to be approved for adequacy prior to issue, and changes to be reviewed and re-approved. Approval can be electronic if the system is controlled.
- EU MDR 2017/745, Article 10(9) sets out documentation obligations for manufacturers. Annex II (technical documentation), Annex III (post-market surveillance), and Annex XIV (PMCF) do not mandate wet ink for any record class.
- EU GMP Annex 11, section 14 covers electronic signatures. Where the requirements are satisfied, an electronic signature is equivalent to a handwritten one.
- 21 CFR Part 11, where it applies to your product set, makes the same equivalence point explicit for the US side.
In other words, the wet-signature request is, in most audit contexts I have worked under, a request the auditor is making on personal or firm-habit grounds — not because the regulation requires it. Granted, there are cases where a printed record genuinely helps. But as a default, it is not a regulatory requirement.
When the printouts are actually defensible
I do not want to be absolutist about this. There are real cases where a paper copy answers the audit question better than a screen:
- The auditor wants to physically annotate findings during document review. Paper is a defensible tool here.
- The eQMS does not have a validated audit trail (some legacy systems, some homegrown databases). If you cannot demonstrate who signed, when, and from what role, a wet signature may be the only evidence of approval you have.
- The record predates your eQMS validation — it was created in a paper system and never migrated properly.
- You are walking an auditor through a controlled form that is normally filled in on paper on the production floor — a cleanroom logbook, a sterilisation cycle printout, a calibration sticker.
If none of those apply, and the eQMS is validated and has a working audit trail, the wet request is mostly habit.
What I do differently now
A few concrete changes, all of which are unglamorous but cut the midnight prep down to about an hour.
- Before the audit, I export the eQMS audit trail as a PDF for each of the major record classes — design history file, CAPA log, complaint log, change control, training records. I put them in a labelled folder and walk the auditor through the structure once. After that, screen-based review is usually fine.
- I keep a one-page "eQMS evidence pack" that includes: the validation summary, the access control matrix, the electronic signature policy, and screenshots of the audit trail in action. Half the time this alone answers the wet-signature question before it gets asked.
- If the request persists, I offer a sampled wet signature on a single specific record, not the whole file. I document the conversation in our internal lessons-learned — not to embarrass anyone, but so we can pre-empt it next year with the same audit firm.
- I never promise "everything is in the system" without testing the actual click path. The fastest way to lose control of an audit is to claim a record is one click away and then spend ten minutes finding it.
- I push back gently on the wet-signature line in the pre-questionnaire. Something along the lines of: "We can demonstrate approval via the validated eQMS audit trail, per ISO 13485 4.2.5 and our internal electronic signature procedure — would a screen walk-through plus audit trail PDF meet the requirement?" This is not confrontation. It is giving the auditor a better answer.
The defensibility question
The honest part of audit prep is not whether you have the paper. It is whether you can answer, for any record the auditor picks, three questions: who approved it, when, and through what controlled process. If your eQMS answers all three with a validated audit trail and electronic signatures, the wet signature is not adding defensibility — it is adding cost, time, and a paper copy that is, paradoxically, easier to tamper with than the electronic record it duplicates.
The stapled printout at midnight is a comfort object, not a control.
There is a Swiss German word for the bureaucratic act of pushing things into a drawer to be dealt with later — Schubladisierig. A lot of audit prep, on both sides of the table, is Schubladisierig. The real work is in showing the system, not in producing the paper.
What is the most unreasonable wet-signature or printout request you have pushed back on during an audit — and what did the auditor accept instead?
Top comments (0)