Two misconceptions show up in almost every conversation about digital manufacturing records in medical device production.
The first: that implementing electronic signatures means replacing a handwritten signature with a password. Someone types credentials, a name appears in a box, and the assumption is that the requirement has been met.
The second: that an electronic Device History Record is a scanned PDF of the paper traveler. The binder gets photographed, the images land in a shared folder, and the record is declared electronic.
Neither is true, and the gap between them is where audit findings live.
Trustworthy digital manufacturing records depend on a set of conditions working together: authenticated users who are individually identified, controlled revisions so everyone builds to the same released instructions, traceability from incoming material to shipped device, audit trails that record change without being asked, electronic approvals that gate the process rather than summarize it, and a production history that assembles itself as work is performed.
This guide covers both halves of that picture: what electronic signatures actually are and what 21 CFR Part 11 expects of them, and what an electronic Device History Record contains and how it comes together on the floor. They are treated as one topic here because in practice they are one topic. A signature without a record to bind to is meaningless, and a record without signatures is not defensible.
1. Why digital manufacturing records matter
It is tempting to frame this as a regulatory conversation. It is more useful to frame it as an operational one, because the reasons manufacturers benefit from good records have very little to do with inspections and a great deal to do with running a business well.
Product quality
A record that captures actual measurements — not just a checkmark saying the measurement was within spec — tells you where your process really sits. Over a few hundred units, that data shows drift long before it shows up as a failure. Paper records almost never get analyzed this way, not because the data isn't there, but because extracting it costs more than the insight seems worth.
Traceability
When a supplier notifies you of a material issue affecting a specific lot, the question is simple and the answer needs to be fast: which units contain that lot, and where are they now? With connected digital records, that's a query. With paper, it's a team of people in a records room for two days, and a scope that ends up wider than it needed to be because nobody could prove otherwise.
Repeatability
The record and the instruction are the same artifact in a digital system. The operator follows the released revision and the act of following it produces the evidence. That coupling is what makes builds repeatable across shifts, cells, and new hires.
Accountability
Not blame — clarity. Knowing who performed an operation lets you connect results to training, identify where coaching helps, and confirm that qualified people did qualified work. That is a management tool before it is a compliance artifact.
Regulatory confidence
Confidence is the right word. An organization that can produce any record on request, complete and consistent, walks into audits differently than one that spends the week before an inspection assembling binders. The records didn't get better in that week. The anxiety just got louder.
Knowledge retention
In small manufacturers, an enormous amount of process knowledge lives in a handful of experienced people. Digital records with photos, notes, and captured values move some of that knowledge into a form that survives a resignation.
Customer expectations
If you build for OEMs, their supplier quality teams increasingly expect electronic records and quick retrieval. Being able to answer a supplier audit question during the call rather than a week later is a commercial advantage, not just a quality one.
2. Electronic signatures explained in plain English
An electronic signature is a recorded event. It says: this specific identified person, at this specific moment, approved this specific record, for this specific reason. All four elements matter. Remove any one of them and what remains is a note, not a signature.
What an electronic signature is not
- It is not a typed name. A text field containing "J. Alvarez" proves nothing about who typed it.
- It is not a scanned image of a handwritten signature pasted into a document. An image can be copied to any file.
- It is not a checkbox on a form that anyone logged into a shared terminal can tick.
- It is not a login. Logging in at 6:00 a.m. does not authorize an approval applied at 2:00 p.m. by whoever happened to be standing at the station.
Handwritten signature vs digital approval vs electronic signature
These three terms get used interchangeably and they should not be. A handwritten signature is ink on a physical record; its trustworthiness comes from the difficulty of forging a person's hand and from the physical control of the document. A digital approval is any software gesture that advances a workflow — a button, a status change, an email reply. It is useful for moving work along, but it may carry no identity binding at all. An electronic signature is a digital approval that has been made trustworthy: credentials applied at the moment of signing, an unalterable timestamp, a defined meaning, and a permanent link to the exact record version being approved.
When signatures are required
Your procedures decide this, not your software. But in practice, medical device manufacturers require signatures at a consistent set of points: release of a work order to production, completion of a critical or special-process operation, verification of an in-process inspection, disposition of a nonconformance, approval of rework, quality review of the completed record, and final release for distribution.
A practical example. An operator completes a heat-seal operation on a sterile barrier package. The step requires a peel-strength check. The operator records the reading, and a second person — the inspector — verifies it. Two signatures, two meanings: performed by and verified by. If both come from the same account, the control has failed no matter what the record says.
Why identity matters
Identity is what connects the record to your quality system. It is how you show that a qualified, trained person performed a qualified operation. Shared accounts break that chain instantly, and they are still one of the most common findings in small-manufacturer audits. The fix is unglamorous: one account per person, no exceptions, and enough terminals or a fast enough badge scan that following the rule isn't a productivity penalty.
Why timestamps matter
Timestamps establish sequence, and sequence is where most record problems surface. Was the inspection signed before or after the operation it verifies? Did the release signature come before the last nonconformance was closed? On paper, dates are written by hand, often at the end of the shift, and sequence is effectively unverifiable. A system-applied timestamp removes the guesswork — and occasionally reveals a process problem nobody knew about.
3. Understanding 21 CFR Part 11 without the legal jargon
Part 11 has a reputation for complexity that it mostly doesn't deserve. Strip away the structure and the regulation is answering one question: under what conditions should an electronic record be trusted as much as a paper one?
The answer breaks into a handful of operational concepts. Everything else is implementation detail.
Identity
Every account belongs to one named, trained person. No shared logins, no 'the line lead's tablet,' no generic operator account passed around a cell.
Authentication
The system verifies the person at the moment of signing, not just at the start of the shift. Signing is a deliberate act with credentials attached.
Record integrity
Completed records cannot be quietly overwritten. Corrections create a new entry that preserves what was there before and why it changed.
Audit trail
Every create, change, and approval is logged automatically with user, timestamp, and prior value — generated by the system, not maintained by a person.
Controlled access
Permissions match roles. Operators execute, inspectors verify, quality releases. The system enforces the separation your procedures describe.
Binding
A signature is attached to a specific record and a specific meaning. It cannot be copied, reused, or reassigned to a different lot.
What this looks like on the floor
An operator badges into a station and opens the work order. The system serves the released revision — there is no other revision available to open. She completes the step, enters two measurements, and photographs the assembly. When she signs the step, the system asks for her credentials again; that act writes her identity, the timestamp, and the meaning of the signature into the record.
An hour later she realizes one measurement was transposed. She cannot erase it. She enters a correction, the system requires a reason, and the record now shows both the original value and the corrected one with who changed it and why. Nothing was hidden. Nothing needed to be. That is record integrity in practice, and it happened without anyone thinking about a regulation.
The part people underestimate
Part 11 is not only a software question. It also expects procedures, training, and documented validation that the system does what you say it does. A vendor can supply a compliant-capable platform and validation documentation; only you can define your signature policy, train your people to it, and keep the user list current when someone changes roles. Most Part 11 findings are not defects in software — they are gaps between what a procedure says and what the configuration actually enforces.
4. What is an electronic Device History Record (eDHR)?
A Device History Record is the evidence that a specific device, or a specific lot of devices, was manufactured according to the approved process. Not a summary of that evidence. The evidence itself.
An electronic Device History Record is that same evidence, created natively in a digital system at the moment the work occurs. The distinction matters enormously, because there are three very different things all commonly called an eDHR.
Paper DHR
A printed traveler with handwritten entries and ink signatures, filed in a binder. It works. It is legal. It is also slow to search, easy to lose, prone to illegible entries, impossible to analyze in aggregate, and it exists in exactly one place.
Scanned DHR
The same paper record, photographed or scanned into PDFs. This solves storage and, partly, retrieval. It solves nothing else. The scan inherits every gap in the original: no audit trail behind the entries, no way to confirm the sequence of signatures, no structured data to analyze, no enforcement that anything required was actually completed. A scanned record is a picture of compliance, not compliance.
True electronic DHR
Data captured at the source, by identified users, against controlled revisions, with system-generated timestamps and an audit trail behind every entry. Required steps cannot be skipped because the system won't advance. Measurements outside limits are flagged as they are entered rather than discovered in review. The record is queryable, so "show me every unit containing lot 24-3391" takes seconds.
| Paper DHR | Scanned PDF | True eDHR | |
|---|---|---|---|
| Legible, complete entries | |||
| Enforced revision control | |||
| System-generated timestamps | |||
| Identity-bound signatures | |||
| Automatic audit trail | |||
| Required steps cannot be skipped | |||
| Searchable by lot or serial | |||
| Structured data for analysis | |||
| Retrieval in minutes | |||
| Survives fire, flood, coffee |
5. What belongs inside an eDHR?
Use this as a working checklist. Each item exists because it answers a question somebody will eventually ask — an auditor, a customer, a complaint investigator, or your own team six months from now.
Work order
The production authorization: what was built, how many, and against which released process.
Serial numbers / UDI
The unique identity of each unit, so a field event can be traced back to one specific build.
Lot traceability
Component and raw material lots tied to the units they went into — the backbone of any recall scope.
Revision used
The exact revision of every instruction, drawing, and specification served at the time of the work.
Operator identity
Who performed each operation, which links the record to training records and qualification.
Equipment used
The fixture, tool, or instrument identified at the step — not assumed from the routing.
Calibration verification
Proof the instrument was in calibration when the measurement was taken, not just today.
Measurements
Actual recorded values against acceptance limits, captured at the step where they were read.
Inspection results
In-process and final inspection outcomes with criteria, results, and the inspector's identity.
Photos
Visual evidence of critical assemblies, labeling, and packaging where a picture settles the question.
Nonconformances
What went wrong, when it was found, how it was dispositioned, and who authorized the disposition.
Rework
Rework performed, the instructions followed, and the re-inspection that confirmed the result.
Electronic approvals
Step-level and operation-level signoffs that gate the process rather than summarize it afterward.
Electronic signatures
Identity-bound approvals at each point your procedures require one, with meaning recorded.
Quality review
The documented review of the complete record before product moves toward release.
Release authorization
The final signature that permits distribution — the single point of accountability for shipping.
Audit trail
The system-generated history behind every entry above: who, when, what changed, and why.
A note on completeness: the goal is not maximum documentation. It is sufficient evidence. Capturing a value nobody will ever use adds cost to every unit you build and gives an auditor one more thing to find inconsistent. The right question for each field is whether its absence would leave a real question unanswerable.
6. How an eDHR builds itself during production
This is the part that changes how a plant actually feels to run. In a paper process, the record is a parallel activity: you build the device, and separately you document that you built it. Two streams of work, and the documentation stream is always the one that falls behind.
In a digital execution process, there is one stream. Performing the work produces the record, because the instruction and the record are the same object.
Walking through it
A work order is released. Because release is a controlled action, the system locks the revision of every instruction and specification that order will use. If engineering releases a new revision on Thursday, orders already in process keep building to the revision they started with, and the record permanently reflects that.
The operator opens the first operation on a station tablet. She sees the current step, the visual reference for it, the values she needs to record, and nothing else. She cannot skip ahead to step 12 because step 11 requires an inspection that hasn't happened.
She scans the torque driver at the step that requires it. The system checks its calibration status and, if it lapsed yesterday, stops the step rather than letting a hundred units get built with an out-of-calibration tool. That single check has prevented more rework in real plants than most quality initiatives.
She enters the measured value. It is inside the limit, so the step advances. If it weren't, the system would raise a nonconformance at the moment of discovery — with the operator standing there, able to describe what she saw — rather than three weeks later when Quality is reviewing a stack of paperwork and nobody remembers the unit.
She signs. The inspector verifies and signs. Both signatures carry identity, time, and meaning. Neither can be applied by the other person's account.
Multiply that across fifty units, four shifts, and seven operators. When the last step closes on Friday, there is nothing to assemble. The record is done, because it was never separate from the work.
7. What auditors actually want to see
Auditors are not looking for perfection and they are not looking for reasons to write findings. They are testing whether your records support the story your quality system tells. Nearly every line of questioning reduces to a handful of practical checks.
Who performed the work?
Named individuals per operation, cross-referenced to current training records.
Which revision was used?
The revision in effect at the time of build — not the revision that is current today.
Were inspections completed?
Every required inspection present, with results and no quietly skipped steps.
Can materials be traced?
Forward from an incoming lot to shipped units, and backward from a unit to its components.
Who approved release?
One accountable signature, applied after review, with authority defined by role.
Was the equipment qualified?
Calibration and qualification status verified at time of use, not reconstructed later.
Can records be retrieved quickly?
Minutes, not afternoons. Retrieval speed is read as a signal of overall record discipline.
Is the record complete and consistent?
The narrative holds together: timestamps, sequence, signatures, and results all agree.
How an audit conversation usually goes
An investigator picks a serial number, often tied to a complaint or chosen at random from a shipping log. She asks to see the record. Then she follows a thread: which revision, who signed, was the inspection done, where did this component lot come from, was that fixture calibrated, who released it.
The finding rarely comes from a single missing entry. It comes from the record being internally inconsistent — a signature dated before the operation it approves, an inspection signed by someone whose training record expired, a revision reference that doesn't match the document control log. Those are exactly the inconsistencies a digital system makes structurally difficult to create.
Retrieval speed is its own signal. If a record appears in thirty seconds, confidence goes up and the sample often stays small. If it takes two hours and three phone calls, the auditor learns something about your record control before she ever reads the contents.
8. Common misconceptions
"Electronic signatures are just passwords"
A password authenticates. A signature attests. The password is how the system confirms who you are; the signature is the permanent record that you — that specific person — approved that specific thing at that specific time for a stated reason. Systems that treat the login as the signature are the ones that generate findings.
"PDFs are electronic records"
A PDF is a container. If the content inside it was captured by an identified user in a controlled system, the PDF is a rendering of an electronic record. If it is a scan of a handwritten traveler, it is a photograph of a paper record, with all the same limits plus a false sense of modernization.
"Paper is always safer"
Paper has one genuine advantage: it doesn't go down. Everything else favors well-implemented digital records. Paper can be lost, damaged, backdated, filled out from memory at the end of a shift, or completed by someone other than the person whose initials appear. None of those failure modes are hypothetical; they are the ordinary texture of paper manufacturing. The honest comparison is not paper versus a perfect digital system — it is paper's real failure modes versus a digital system's real ones.
"Only enterprise companies need eDHRs"
Regulatory expectations don't scale with headcount. A 25-person manufacturer shipping a Class II device is held to the same record requirements as a large one, but with fewer people to absorb the administrative load. Small manufacturers arguably benefit more, because the burden per person is higher.
"Digital systems make audits harder"
The concern behind this is real: a digital system records everything, including your mistakes. But an auditor is going to find the mistakes either way, and a system that surfaces a nonconformance at the moment of discovery, with a documented disposition, reads far better than a gap discovered during review with no one able to explain it. Visibility is not exposure. It is control.
"Compliance requires more paperwork"
Compliance requires evidence. Paperwork is one way to produce evidence and it is the most expensive one. When evidence is generated automatically by the act of doing the work, the total documentation effort goes down while the quality of the record goes up. That is the entire argument for digital execution, stated plainly.
9. How a manufacturing execution system supports digital records
Setting aside any specific product, here is what a manufacturing execution system contributes to this problem — the capabilities that turn the principles above into daily practice.
- Digital work instructions. The operator sees one step at a time, with the visuals and values that step requires. Execution and documentation become the same action.
- Revision control. Only released revisions reach the floor, and the revision in use is captured permanently in the record.
- Authentication. Individual accounts, role-based permissions, and credential prompts at signing points.
- Electronic signatures. Identity-bound approvals with defined meaning applied at the points your procedures require.
- Automatic timestamps. Sequence established by the system, not reconstructed from handwriting.
- Audit trails. A complete change history generated without anyone maintaining it.
- Equipment verification. Tool and fixture identification with calibration status checked at time of use.
- Data collection. Structured measurements, pass/fail results, and photos captured at the step rather than transcribed later.
- Production dashboards. Live status by work order and operation, so supervision doesn't depend on walking the floor.
- Automatic eDHR assembly. The completed record available for review the moment the last step closes.
Notice what isn't on that list: a document management module, a workflow builder for approval routing, or an electronic forms designer. Those tools produce electronic paperwork. They are not the same as capturing the work.
10. Characteristics of a well-designed digital record system
If you are evaluating systems, or assessing the one you already run, these are the characteristics that separate a genuine execution record from a digital filing cabinet.
| Scanned / filed records | Electronic forms | Execution record | |
|---|---|---|---|
| Authentication per signature | |||
| Controlled revisions enforced | |||
| Searchable by lot, serial, date | |||
| Electronic approvals gate the process | |||
| Complete audit history | |||
| Material traceability | |||
| Inspection integrated with execution | |||
| Photo documentation at the step | |||
| Equipment and calibration tracking | |||
| Automatic timestamps | |||
| Live production visibility | |||
| Record retrieval in minutes |
Questions worth asking a vendor
- Show me the audit trail for a corrected measurement. Who changed it, when, what was the prior value, and what reason was captured?
- Can two different signatures on the same operation be applied from one account? Demonstrate that they can't.
- Pull up a record by serial number while I watch. How long does it take?
- What happens when an operator scans a tool that is out of calibration?
- What validation documentation do you provide, and what remains our responsibility?
Frequently asked questions
Bringing it together
Electronic signatures and electronic Device History Records are not independent compliance features to be procured separately and reconciled later. Together they create a trustworthy record of how every product was built.
When work instructions, inspections, approvals, traceability, and electronic signatures are integrated into daily production, compliance stops being a project. It becomes the natural outcome of disciplined manufacturing — evidence produced by doing the work well, rather than paperwork assembled afterward to describe work that already happened.
That is the standard worth building toward. Not more electronic paperwork. Trustworthy manufacturing records, created automatically, as the work is performed.