Quick verdict: An electronic lab notebook is not compliant or non-compliant by itself. It becomes a compliance question the moment it holds records that a regulation requires you to keep: GLP study data, GMP development records, clinical investigation data. From that point, the ELN must meet the same expectations as any other GxP computerised system: validation for intended use, attributable and secure audit trails, controlled electronic signatures, and records that stay complete and readable for the full retention period. In research-only labs the drivers are different (IP, reproducibility, funder data policies), but the same controls are what make notebook records credible.

When compliance applies to an ELN
Most ELN compliance confusion comes from mixing two situations.
1. The ELN holds regulated records. Examples: a GLP test facility documenting a nonclinical safety study, a pharma development group producing data that will support a GMP filing, a lab generating data for a clinical investigation. Here the regulations apply directly:
- FDA 21 CFR Part 11 for electronic records and signatures required by FDA regulations.
- FDA GLP, 21 CFR 58.130(e) requires raw data entries to be dated and attributed, and any change to keep the original entry visible, state the reason, and identify who made it and when. For automated systems, the person responsible for data input must be identified at the time of input.
- OECD GLP Advisory Document No. 17 (2016) on computerised systems, and its 2023 supplement on cloud computing, for GLP facilities in OECD member countries.
- EU GMP Annex 11 and the MHRA GxP Data Integrity Guidance (2018) where development or QC records fall under GMP.
2. The ELN is used for research that is not regulated. No GxP regulation applies, but three pressures remain: proving inventorship and dates for patents, reproducing results, and meeting funder or journal data policies. The NIH Data Management and Sharing Policy, in force since January 2023, is one example.
Many organizations have both situations in one ELN. In that case, define in your procedures which projects or notebooks are regulated, and apply validated controls to those at minimum.
Data integrity: what ALCOA+ means inside a notebook

Regulators assess electronic records against the ALCOA+ principles: attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring and available. Our ALCOA+ guide covers the framework. In an ELN, each principle turns into specific, testable behaviour:
| Principle | What it means in an ELN | What to check |
|---|---|---|
| Attributable | Every entry and change is linked to one named user | No shared accounts; audit trail records user, date, time |
| Legible | Records readable for the full retention period | Export formats, long-term readability of attachments |
| Contemporaneous | Data recorded when the work is done | Server-side time stamps; clock synchronization; no editable entry dates |
| Original | The first capture of data is kept, or a verified true copy | Raw instrument files attached, not only screenshots or retyped values |
| Accurate | Calculations and transcriptions are correct | Validated templates and calculations; locked formulas |
| Complete | Nothing deleted or hidden, including metadata | Deleted or abandoned experiments remain traceable |
| Enduring and available | Records survive system changes and can be retrieved for inspection | Backup, archiving, vendor exit terms |
The technical controls that matter most
Audit trails
Part 11 §11.10(e) requires secure, computer-generated, time-stamped audit trails that record the date and time of operator entries and actions, without obscuring previously recorded information. GLP rules go further: 21 CFR 58.130(e) also requires the reason for each change. In practice, a usable ELN audit trail shows the old value, the new value, who changed it, when, and why. Two common weak points:
- Draft mode. Some systems do not trail changes until an entry is saved, submitted or signed. Check exactly when audit trailing starts, and whether that matches when data becomes a record in your procedures.
- Embedded files and spreadsheets. Changes inside an attached spreadsheet are often invisible to the ELN audit trail, which only sees a new file version.
Recording changes is only half of the requirement. The FDA’s data integrity Q&A and the draft Annex 11 revision both expect audit trails for critical data to be reviewed, at a risk-based frequency.
Electronic signatures and witnessing
Part 11 requires signatures to show the signer’s printed name, the date and time, and the meaning of the signature, such as authorship, review or approval (§11.50), and to be permanently linked to the record (§11.70). In an ELN, check:
- whether an entry is locked after signature, and how amendments after signing are handled (new version with reason, or unlocked edit);
- whether the system supports a separate reviewer or witness signature, which matters for both GxP review and IP evidence;
- how long entries can stay unsigned, and whether the system reports overdue signatures.
Access control
Role-based permissions should prevent users from altering others’ entries, disabling audit trails, or changing system settings. Administrator rights should sit with people who do not generate the data they could modify.
Templates and calculations
Templates bring structure to ELN data, and they are also where errors spread. A calculation built into a template used by 40 scientists is a validated function, not a convenience. Lock formulas, version templates, and test critical calculations as part of validation.
Records, copies and exports
MHRA’s guidance distinguishes static records from dynamic records, where the user can reprocess or interact with data. A PDF export of a notebook page is a static copy: it can lose metadata, audit trail and the ability to re-examine the original data. Before relying on exports for archiving or for sharing with partners, confirm they qualify as complete, true copies for your purpose.
Validation of an ELN

An ELN that holds regulated records must be validated for its intended use, like a LIMS. The approach is the same risk-based lifecycle described in our LIMS validation guide: requirements, supplier assessment, risk assessment, testing proportionate to risk, and ongoing change control and periodic review.
ELNs differ from LIMS in where the risk sits. A LIMS concentrates risk in workflows, specifications and result approval. An ELN concentrates it in:
- templates and embedded calculations, which behave like small applications;
- integrations that pull instrument data or push results into a LIMS or SDMS;
- the boundary between regulated and non-regulated work, if both live in the same system;
- frequent vendor updates on SaaS platforms, which need impact assessment under change control.
Cloud ELNs
Most ELNs sold today are cloud or SaaS products. Regulators accept this, provided the lab keeps control. The OECD’s 2023 supplement on GLP and cloud computing states the principle clearly: test facility management keeps responsibility for GLP compliance even when operations are outsourced. In practice, the service agreement should cover roles and responsibilities, data location, security, backup and disaster recovery, change control, and your right to obtain all data and metadata, including audit trails, in a readable format when the contract ends.
For the deployment choice itself, see cloud vs on-premise ELN.
Common compliance gaps in ELN deployments
- Treating the ELN as “just a notebook”. Once it holds GLP or GMP data, it is a GxP computerised system and needs a validation file.
- Shared or generic accounts in instrument rooms, which break attributability.
- Paper-electronic hybrids with no defined master record. When results exist both on paper and in the ELN, the procedure must say which one is the record.
- Unsigned entries accumulating for months, which weakens contemporaneousness and IP evidence.
- Critical data kept only in attachments the ELN cannot trail.
- No review of audit trails despite them being switched on.
- No exit plan, so the lab cannot prove it could retrieve complete records if it changed vendor.
What to ask ELN vendors
- At what point does the audit trail start recording: draft, save, or signature?
- How are changes after signature handled and displayed?
- Can templates and calculations be locked and version-controlled?
- Does the system support reviewer or witness signatures with a defined meaning?
- What validation documentation and test evidence do you provide?
- How are releases communicated, and is there a validation environment?
- In what formats can we export complete records with metadata and audit trails?
Our how to choose an ELN checklist covers the non-compliance criteria, and ELN vs LIMS explains when a notebook is the wrong tool for regulated testing.
Frequently asked questions
Does every ELN need to be validated?
Only when it holds records required by GxP regulations or supports accredited results. A research-only ELN has no validation obligation, although verifying templates and calculations is still good practice.
Can a cloud ELN be used in a GLP or GMP environment?
Yes, if the lab assesses the provider, defines responsibilities in the service agreement, validates the system for its intended use and keeps the ability to retrieve complete records.
Are ELN electronic signatures legally equivalent to handwritten ones?
For FDA-regulated records, Part 11 sets the conditions under which electronic signatures are considered equivalent to handwritten signatures, including certification to the FDA that the organization intends them to be binding (§11.100). Other jurisdictions and uses, such as patent disputes, have their own rules.
Is a PDF export enough for archiving?
Not always. A PDF may lose metadata, audit trails and the ability to reprocess data. Assess whether it is a complete and true copy for the records it replaces.
Do non-regulated research labs need audit trails?
Not by regulation, but audit trails and signed, time-stamped entries are what make notebook records useful as evidence for inventorship and reproducibility.
The bottom line
ELN compliance is decided less by the product than by how the lab uses it. Identify which records are regulated, validate the system for that use, and give particular attention to templates, attachments, signatures and audit trail review, where notebooks most often fall short. The same controls also protect unregulated research: they are what turn notebook entries into records a patent attorney, a partner or an inspector can rely on.
This article is independent editorial content and does not replace regulatory advice for your specific context. No vendor paid for inclusion. Read how we review lab software.
Sources
- U.S. eCFR, 21 CFR Part 11, Electronic Records; Electronic Signatures: https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11
- U.S. eCFR, 21 CFR 58.130, Conduct of a nonclinical laboratory study: https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-58/subpart-E/section-58.130
- U.S. FDA, Data Integrity and Compliance With Drug CGMP: Questions and Answers (guidance, 2018): https://www.fda.gov/regulatory-information/search-fda-guidance-documents/data-integrity-and-compliance-drug-cgmp-questions-and-answers
- U.S. FDA, Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers (final guidance, October 2024): https://www.fda.gov/regulatory-information/search-fda-guidance-documents/electronic-systems-electronic-records-and-electronic-signatures-clinical-investigations-questions
- OECD, Application of GLP Principles to Computerised Systems, Series on GLP No. 17 (2016): https://www.oecd.org/en/publications/2016/04/application-of-glp-principles-to-computerised-systems_7d05366e.html
- OECD, Advisory Document on GLP and Cloud Computing, Supplement 1 to Document No. 17 (2023): https://www.bfr.bund.de/cm/349/no-17-supplement-1-advisory-document-on-glp-cloud-computing.pdf
- MHRA, GXP Data Integrity Guidance and Definitions, Revision 1 (March 2018): https://assets.publishing.service.gov.uk/media/5aa2b9ede5274a3e391e37f3/MHRA_GxP_data_integrity_guide_March_edited_Final.pdf
- ECA Academy, EU GMP Annex 11 (Draft 2025): Computerised Systems: https://www.gmp-compliance.org/guidelines/gmp-guideline/eu-gmp-annex-11-draft-2025-computerised-systems
- NIH, Data Management and Sharing Policy: https://grants.nih.gov/policy-and-compliance/policy-topics/sharing-policies/dms


