Six frameworks shaping data integrity, AI risk management and clinical evidence in the United States, from 21 CFR Part 11 to the NIST AI Risk Management Framework.
21 CFR Part 11, in force since 1997, establishes FDA requirements concerning certain electronic records and electronic signatures where regulated records are maintained or submitted electronically. It sets the criteria under which such records are considered trustworthy, reliable and generally equivalent to paper records and handwritten signatures.
FDA guidance describes the circumstances in which electronic records and signatures should be considered trustworthy, reliable and generally equivalent to paper records and handwritten signatures.
Part 11 makes record integrity, access controls, auditability and electronic identity central concerns in regulated digital systems.
Evidence governance extends that logic beyond an individual validated system. The question becomes whether those records retain a meaningful relationship to downstream results after evidence moves between systems, laboratories, sponsors or analytical platforms.
FDA’s data-integrity guidance for pharmaceutical manufacturing addresses the reliability and completeness of data generated under Current Good Manufacturing Practice requirements.
FDA expects regulated organisations to preserve data necessary to reconstruct activities and appropriately review records relevant to product quality and compliance.
Manufacturing and laboratory environments often contain complex evidence chains involving instruments, raw data, laboratory systems, intermediate calculations, quality review and final release decisions.
A provenance failure may occur even where individual records exist, if the organisation cannot reliably demonstrate how those records contributed to a later conclusion.
The principle is simple: a result should remain connected to the records necessary to understand how it was produced.
Issued on 2 October 2024 in question-and-answer form, the guidance addresses sponsors, investigators, institutional review boards, contract research organisations and other parties using digital systems in clinical investigations. It finalises a March 2023 draft and supplements the 2003 Part 11 scope and application guidance. Notably, FDA does not intend to assess electronic health record systems that are sources of real-world data against Part 11, but Part 11 applies once records enter the sponsor’s electronic data capture system.
Clinical trials increasingly depend upon distributed electronic systems. Source information may move through electronic data-capture systems, laboratories, devices, statistical environments and sponsor platforms.
The regulatory record therefore depends not only upon storing electronic information but upon being able to establish who created it, which system changed it and which version ultimately contributed to the submitted evidence.
The HIPAA Privacy Rule establishes federal requirements governing the use and disclosure of protected health information by covered entities and their business associates, including specific provisions relating to research.
A proposed overhaul of the HIPAA Security Rule was published in the Federal Register on 6 January 2025, with comments closing in March 2025. It would remove the “addressable” designation for implementation specifications and introduce mandatory encryption, multi-factor authentication, incident reporting timescales and expanded business-associate obligations. It has attracted substantial opposition, including calls for withdrawal from a coalition of provider organisations. Final action has been pushed back and is currently indicated for 2027. The existing Security Rule continues to apply in the meantime.
Separately, the 2024 Privacy Rule provisions concerning reproductive health care were vacated nationwide by the US District Court for the Northern District of Texas in June 2025.
Organisations should treat the US position as unsettled and verify the current rule text before relying on it.
HIPAA illustrates the distinction between access to protected information and the scientific evidence subsequently generated from it.
Evidence provenance should not become a mechanism for unnecessarily reproducing protected health information.
Organisations should be able to preserve relevant relationships between authorised data use and downstream evidence while maintaining the access controls required for the underlying records.
The NIST AI Risk Management Framework provides a voluntary, cross-sector framework for organisations designing, developing, deploying or using artificial intelligence. Although voluntary, it is widely referenced by US federal agencies and in procurement.
AI RMF 1.0 is being revised following the White House AI Action Plan of July 2025. NIST has also published a Generative AI Profile, a preliminary draft Cyber AI Profile, and in April 2026 a concept note for a profile on trustworthy AI in critical infrastructure covering sectors including healthcare.
Risk management depends upon understanding the AI lifecycle. For evidence-producing systems, that lifecycle should include the relationship between model, data, configuration, output and downstream decision.
The BioChain’s evidence-governance model is complementary to AI risk management: it asks how relevant information about that lifecycle can remain attached to the evidence the system ultimately produces.
FDA has said it does not intend to assess EHR systems that are sources of real-world data against Part 11 — but Part 11 applies once records enter the sponsor’s electronic data capture system.
A proposed overhaul was published for comment in January 2025 and has attracted substantial opposition. Final action is currently indicated for 2027, and the existing Security Rule continues to apply until then — treat the US position as unsettled.
No, it is voluntary, but it is widely referenced by US federal agencies and in procurement, and it is currently being revised alongside sector-specific profiles including one for critical infrastructure covering healthcare.
Because trial source data increasingly moves through distributed electronic systems — data-capture platforms, laboratories, devices, sponsor systems — and the regulatory record depends on being able to establish who created and changed each version that ultimately contributed to submitted evidence.