ELN Compliance and Data Integrity: A Practical Guide for Regulated Labs

ELN compliance and data integrity

Quick verdict: An electronic lab notebook is not compliant or non-compliant by itself. It becomes a compliance question the moment it holds records that a regulation requires you to keep: GLP study data, GMP development records, clinical investigation data. From that point, the ELN must meet the same expectations as any other GxP computerised system: validation for intended use, attributable and secure audit trails, controlled electronic signatures, and records that stay complete and readable for the full retention period. In research-only labs the drivers are different (IP, reproducibility, funder data policies), but the same controls are what make notebook records credible.

ELN compliance and data integrity overview

When compliance applies to an ELN

Most ELN compliance confusion comes from mixing two situations.

1. The ELN holds regulated records. Examples: a GLP test facility documenting a nonclinical safety study, a pharma development group producing data that will support a GMP filing, a lab generating data for a clinical investigation. Here the regulations apply directly:

  • FDA 21 CFR Part 11 for electronic records and signatures required by FDA regulations.
  • FDA GLP, 21 CFR 58.130(e) requires raw data entries to be dated and attributed, and any change to keep the original entry visible, state the reason, and identify who made it and when. For automated systems, the person responsible for data input must be identified at the time of input.
  • OECD GLP Advisory Document No. 17 (2016) on computerised systems, and its 2023 supplement on cloud computing, for GLP facilities in OECD member countries.
  • EU GMP Annex 11 and the MHRA GxP Data Integrity Guidance (2018) where development or QC records fall under GMP.

2. The ELN is used for research that is not regulated. No GxP regulation applies, but three pressures remain: proving inventorship and dates for patents, reproducing results, and meeting funder or journal data policies. The NIH Data Management and Sharing Policy, in force since January 2023, is one example.

Many organizations have both situations in one ELN. In that case, define in your procedures which projects or notebooks are regulated, and apply validated controls to those at minimum.


Data integrity: what ALCOA+ means inside a notebook

ALCOA+ data integrity principles

Regulators assess electronic records against the ALCOA+ principles: attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring and available. Our ALCOA+ guide covers the framework. In an ELN, each principle turns into specific, testable behaviour:

PrincipleWhat it means in an ELNWhat to check
AttributableEvery entry and change is linked to one named userNo shared accounts; audit trail records user, date, time
LegibleRecords readable for the full retention periodExport formats, long-term readability of attachments
ContemporaneousData recorded when the work is doneServer-side time stamps; clock synchronization; no editable entry dates
OriginalThe first capture of data is kept, or a verified true copyRaw instrument files attached, not only screenshots or retyped values
AccurateCalculations and transcriptions are correctValidated templates and calculations; locked formulas
CompleteNothing deleted or hidden, including metadataDeleted or abandoned experiments remain traceable
Enduring and availableRecords survive system changes and can be retrieved for inspectionBackup, archiving, vendor exit terms

The technical controls that matter most

Audit trails

Part 11 §11.10(e) requires secure, computer-generated, time-stamped audit trails that record the date and time of operator entries and actions, without obscuring previously recorded information. GLP rules go further: 21 CFR 58.130(e) also requires the reason for each change. In practice, a usable ELN audit trail shows the old value, the new value, who changed it, when, and why. Two common weak points:

  • Draft mode. Some systems do not trail changes until an entry is saved, submitted or signed. Check exactly when audit trailing starts, and whether that matches when data becomes a record in your procedures.
  • Embedded files and spreadsheets. Changes inside an attached spreadsheet are often invisible to the ELN audit trail, which only sees a new file version.

Recording changes is only half of the requirement. The FDA’s data integrity Q&A and the draft Annex 11 revision both expect audit trails for critical data to be reviewed, at a risk-based frequency.

Electronic signatures and witnessing

Part 11 requires signatures to show the signer’s printed name, the date and time, and the meaning of the signature, such as authorship, review or approval (§11.50), and to be permanently linked to the record (§11.70). In an ELN, check:

  • whether an entry is locked after signature, and how amendments after signing are handled (new version with reason, or unlocked edit);
  • whether the system supports a separate reviewer or witness signature, which matters for both GxP review and IP evidence;
  • how long entries can stay unsigned, and whether the system reports overdue signatures.

Access control

Role-based permissions should prevent users from altering others’ entries, disabling audit trails, or changing system settings. Administrator rights should sit with people who do not generate the data they could modify.

Templates and calculations

Templates bring structure to ELN data, and they are also where errors spread. A calculation built into a template used by 40 scientists is a validated function, not a convenience. Lock formulas, version templates, and test critical calculations as part of validation.

Records, copies and exports

MHRA’s guidance distinguishes static records from dynamic records, where the user can reprocess or interact with data. A PDF export of a notebook page is a static copy: it can lose metadata, audit trail and the ability to re-examine the original data. Before relying on exports for archiving or for sharing with partners, confirm they qualify as complete, true copies for your purpose.


Validation of an ELN

Key regulatory frameworks impacting ELN compliance

An ELN that holds regulated records must be validated for its intended use, like a LIMS. The approach is the same risk-based lifecycle described in our LIMS validation guide: requirements, supplier assessment, risk assessment, testing proportionate to risk, and ongoing change control and periodic review.

ELNs differ from LIMS in where the risk sits. A LIMS concentrates risk in workflows, specifications and result approval. An ELN concentrates it in:

  • templates and embedded calculations, which behave like small applications;
  • integrations that pull instrument data or push results into a LIMS or SDMS;
  • the boundary between regulated and non-regulated work, if both live in the same system;
  • frequent vendor updates on SaaS platforms, which need impact assessment under change control.

Cloud ELNs

Most ELNs sold today are cloud or SaaS products. Regulators accept this, provided the lab keeps control. The OECD’s 2023 supplement on GLP and cloud computing states the principle clearly: test facility management keeps responsibility for GLP compliance even when operations are outsourced. In practice, the service agreement should cover roles and responsibilities, data location, security, backup and disaster recovery, change control, and your right to obtain all data and metadata, including audit trails, in a readable format when the contract ends.

For the deployment choice itself, see cloud vs on-premise ELN.


Common compliance gaps in ELN deployments

  • Treating the ELN as “just a notebook”. Once it holds GLP or GMP data, it is a GxP computerised system and needs a validation file.
  • Shared or generic accounts in instrument rooms, which break attributability.
  • Paper-electronic hybrids with no defined master record. When results exist both on paper and in the ELN, the procedure must say which one is the record.
  • Unsigned entries accumulating for months, which weakens contemporaneousness and IP evidence.
  • Critical data kept only in attachments the ELN cannot trail.
  • No review of audit trails despite them being switched on.
  • No exit plan, so the lab cannot prove it could retrieve complete records if it changed vendor.

What to ask ELN vendors

  • At what point does the audit trail start recording: draft, save, or signature?
  • How are changes after signature handled and displayed?
  • Can templates and calculations be locked and version-controlled?
  • Does the system support reviewer or witness signatures with a defined meaning?
  • What validation documentation and test evidence do you provide?
  • How are releases communicated, and is there a validation environment?
  • In what formats can we export complete records with metadata and audit trails?

Our how to choose an ELN checklist covers the non-compliance criteria, and ELN vs LIMS explains when a notebook is the wrong tool for regulated testing.


Frequently asked questions

Does every ELN need to be validated?
Only when it holds records required by GxP regulations or supports accredited results. A research-only ELN has no validation obligation, although verifying templates and calculations is still good practice.

Can a cloud ELN be used in a GLP or GMP environment?
Yes, if the lab assesses the provider, defines responsibilities in the service agreement, validates the system for its intended use and keeps the ability to retrieve complete records.

Are ELN electronic signatures legally equivalent to handwritten ones?
For FDA-regulated records, Part 11 sets the conditions under which electronic signatures are considered equivalent to handwritten signatures, including certification to the FDA that the organization intends them to be binding (§11.100). Other jurisdictions and uses, such as patent disputes, have their own rules.

Is a PDF export enough for archiving?
Not always. A PDF may lose metadata, audit trails and the ability to reprocess data. Assess whether it is a complete and true copy for the records it replaces.

Do non-regulated research labs need audit trails?
Not by regulation, but audit trails and signed, time-stamped entries are what make notebook records useful as evidence for inventorship and reproducibility.


The bottom line

ELN compliance is decided less by the product than by how the lab uses it. Identify which records are regulated, validate the system for that use, and give particular attention to templates, attachments, signatures and audit trail review, where notebooks most often fall short. The same controls also protect unregulated research: they are what turn notebook entries into records a patent attorney, a partner or an inspector can rely on.

This article is independent editorial content and does not replace regulatory advice for your specific context. No vendor paid for inclusion. Read how we review lab software.


Sources

Share the Post:

Related Posts