| CFR 21 Part 11 Regulation Content | IND400 Response |
| Part 11 11.10(a) | Validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records. | METTLER TOLEDO has developed the IND400 Data Integrity Application Package (IND400 DI) under the ISO 9001 Quality Management System. This functionality has undergone thorough and reliable testing to ensure its accuracy, reliability, and consistent intended performance. According to the GAMP5 CSV standards, METTLER TOLEDO classifies the IND400 Data Integrity System as a Category 3 type computer device. Furthermore, the IND400 indicator‘s operating system is an unconfigurable embedded closed system. The „regulated records“ that need to be verified under this regulation concerning the IND400 Data Integrity Application Package should include the following: • Measurement parameters • Weighing records • Instrument settings parameters • Audit Log • Weighing application parameters • Material list parameters • Print template parameters • User management parameters • Electronic signature parameters |
| Part 11 11.10(b) | The ability to generate accurate and complete copies of records in both human readable and electronic form suitable for inspection, review, and copying by FDA. Persons should contact the FDA if there are any questions regarding the ability of the FDA to perform such review and copying of the electronic records. | The records can be directly printed as paper labels or tickets, and they can also be exported in PDF format or as CSV files protected by the SHA-256 encryption algorithm. |
| Part 11 11.10(c) | Protection of records to enable their accurate and ready retrieval throughout the records retention period. | After activating the Data Integrity Feature Package, IND400 produces the data, including measurement parameters, weighing records, instrument settings parameters, audit log, weighing application parameters, material list parameters, print template parameters, user management parameters, and electronic signature parameters in the indicator’s internal memory. After data acquisition (or after data review if the electronic signature feature is activated), the IND400 DI uses the SHA256 encryption algorithm to encrypt the metadata and then automatically archives all raw data, metadata, and result data. All activities involving data and files, including data acquisition, review, and operations marked for deletion, are monitored through the system‘s audit trails and logs. These records are securely stored in IND400 and can be extracted during the review process. The user organization holds the responsibility for managing the physical security. |
| Part 11 11.10(d) | Limiting system access to authorized individuals. | Each user is identified by a unique ID and password combination. Each user is assigned a role. IND400 DI also has a Role Definition feature, which enables the customization of permissions and access settings for different permission groups. |
| Part 11 11.10(e) | Use of secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records. Record changes shall not obscure previously recorded information. Such audit trail documentation shall be retained for a period at least as long as that required for the subject electronic records. and shall be available for FDA review and copying. | The IND400 audit trail log captures the date and time of operator entries and actions that create, modify, or delete electronic records with time-stamps and encryption by SHA-256. IND400 audit trail records are immutable, meaning they cannot be altered, overwritten, or deleted, and they can be fully backed up when needed. IND400 has the capacity to store up to 1 million audit trail records, which adequately supports the required storage for the maximum of 300,000 weight records designed into the system. Audit trails can be exported as PDF or SHA-256 encrypted CSV files. |
| Part 11 11.10(f) | Use of operational system checks to enforce permitted sequencing of steps and events, as appropriate. | The IND400 features built-in applications for over/under checkweighing, totalization, and manual filling. These applications operate within a framework that ensures data integrity. All weighing results comply with data integrity requirements and are generated according to established rules. |
| Part 11 11.10(g) | Use of authority checks to ensure that only authorized individuals can use the system, electronically sign a record, access the operation or computer system input or output device, alter a record, or perform the operation at hand. | Only authorized persons can access IND400 DI with assigned login and password information. Login and password credentials are also required to sign records. The identity of the operator is captured in the audit trail, which records entered and changed data, including the date and time. |
| Part 11 11.10(h) | Use of device (e.g., terminal) checks to determine, as appropriate, the validity of the source of data input or operational instruction. | The IND400 can be connected to only one weighing platform, and the data from the weighing source will be recorded along with its identification number. Any changes to the weighing source will generate an audit trail. Additionally, external physical tamper-proof seals further ensure that the weighing source data cannot be altered without detection. |
| Part 11 11.10(i) | Determination that persons who develop, maintain, or use electronic record/electronic signature systems have the education, training, and experience to perform their assigned tasks. | The user organization holds the responsibility for managing this. |
| Part 11 11.10(j) | The establishment of, and adherence to, written policies that hold individuals accountable and responsible for actions initiated under their electronic signatures, in order to deter record and signature falsification. | The user organization holds the responsibility for managing this. |
| Part 11 11.10(k) | Use of appropriate controls over systems documentation including: (1) Adequate controls over the distribution of, access to, and use of documentation for system operation and maintenance. (2) Revision and change control procedures to maintain an audit trail that documents time-sequenced development and modification of systems documentation. | It is the responsibility of the user organization to establish systems documentation. METTLER TOLEDO IND400 User Manual includes the firmware change history. |
| Part 11 11.30 | Persons who use open systems to create, modify, maintain, or transmit electronic records shall employ procedures and controls designed to ensure the authenticity, integrity, and, as appropriate, the confidentiality of electronic records from the point of their creation to the point of their receipt. Such procedures and controls shall include those identified in § 11.10, as appropriate, and additional measures such as document encryption and use of appropriate digital signature standards to ensure, as necessary under the circumstances, record authenticity, integrity, and confidentiality. | IND400 is a closed system – this category is not applicable. |
| Part 11 11.50(a) | Signed electronic records shall contain information associated with the signing that clearly indicates all of the following: (1) The printed name of the signer. (2) The date and time when the signature were executed (3) The meaning (such as review, approval, responsibility, or authorship) associated with the signature. | Signed electronic weighing records show the name of the reviewer, the date and time the signature was executed, meaning of the signature e.g. Reviewed or Cancelled. |
| Part 11 11.50(b) | The items identified in paragraphs (a)(1), (a)(2), and (a)(3) of this section shall be subject to the same controls as for electronic records and shall be included as part of any human readable form of the electronic record (such as electronic display or printout). | The weighing records with electronic signatures from the IND400 are stored in a human-readable format within the indicator’s memory. Users can query these records through the transaction log on the IND400. Additionally, the records can be exported as PDF or CSV files, and they can also be printed directly as receipts or labels using a printer. |
| Part 11 11.70 | Electronic signatures and handwritten signatures executed to electronic records shall be linked to their respective electronic records to ensure that the signatures cannot be excised, copied, or otherwise transferred to falsify an electronic record by ordinary means. | The IND400 weighing log contains audit trail records associated with each electronic signature for every weighing entry. The audit trail records these actions in chronological order, including the creation of weighing records, reviews, or cancel. Additionally, the IND400 can generate a data integrity report in PDF format by filtering based on a specific time range. This report will clearly and accurately present the weighing records and their corresponding electronic signature audit trails for the selected period. It will also include an appendix that contains all audit trail records from the same time frame. |