Compliance

Designed and tested against 21 CFR Part 11.

The controls below are built into the data layer, not bolted on. Nexrial is software, not a compliance certification — the controls are real and verifiable; the validation attestation is yours to make, with the evidence we provide.

Immutable audit trail

Every create, update, and signature is captured at the database layer with the user, a server-side timestamp, and the reason for change. Entries can’t be edited or switched off.

21 CFR §11.10(e)

Native e-signature manifestations

Each electronic signature records the signer’s identity, the date and time, and the meaning of the signing (review, approval, responsibility) — bound to the record it signs.

21 CFR §11.50 · §11.70

Delegation-driven access

The delegation of authority log governs system permissions: access is limited to authorized individuals, and what each person can do mirrors what an inspector reviews on day one.

21 CFR §11.10(d)

Authority checks

Only authorized individuals can use the system, sign a record, or perform a delegated operation — enforced against the same delegation log, not a separate permission table.

21 CFR §11.10(g)

Record retention & export

Records are protected for accurate, ready retrieval throughout the retention period, with full on-demand export in standard formats — no lock-in, no exit fee.

21 CFR §11.10(c)

Unique credentials

Each user has a unique account; signings are attributable to one identifiable person. Administrative actions are themselves logged in the audit trail.

21 CFR §11.300
On inspection day

The two documents an inspector asks for first.

Nexrial keeps both current automatically. The delegation log governs system access; the audit trail records every edit with its reason. No reconstructing binders the night before.

Delegation of Authority LogSupports Form FDA 1572
Team memberDelegatedEffective
Dr. A. SamplePrincipal Investigator
Oversight, consent, AE review
04 Apr 2026
J. Rivera, NPSub-Investigator
Exams, consent, dosing
04 Apr 2026
M. OseiCoordinator (CRC)
Visits, eCRF, IP logs
11 Apr 2026
L. Tran, PharmDPharmacist
IP accountability
18 Apr 2026
Audit Trail21 CFR §11.10(e)
2026-06-16 14:02:11Z · m.osei UPDATESubj 1042 · Visit 4 date  12 Jun16 Junreason: within protocol visit window
2026-06-16 11:48:30Z · a.sample SIGNSubj 1039 · AE assessment — meaning: approved§11.50 signature manifestation captured
2026-06-16 09:15:02Z · l.tran UPDATEIP lot 7841 · count  120116reason: dispensed to Subj 1051
2026-06-15 16:37:55Z · j.rivera CREATESubj 1051 · Screening visit recordentry contemporaneous · ALCOA+

Sample records, de-identified. Audit entries can’t be edited or switched off — that’s the point of §11.10(e).

Artificial intelligence

Where AI touches your records.

AI assists; people decide.

Nexrial uses AI to assist with drafting and analysis — protocol summaries, adverse-event narratives, and eligibility checklists. Every output is a clearly-marked draft.

All regulated records require human review and signature; AI does not sign or approve controlled records. AI runs on enterprise infrastructure under contract, and your data is never used to train third-party AI models.

Compliance questions

What sponsors and monitors ask.

Is Nexrial validated against 21 CFR Part 11?

Nexrial is designed and tested against 21 CFR Part 11 — audit trail, native e-signatures, and access controls. Validation documentation is available for your procurement and sponsor review. (Nexrial is software, not a compliance certification — the controls are real; the attestation is yours to make with the evidence we provide.)

Can monitors and CRAs get access?

Yes — scoped, read-only monitor access for visits, so a CRA reviews exactly what they need without touching your live data.

Do you sign a HIPAA BAA?

Yes. A Business Associate Agreement is executed before any PHI is entered into the Service — not after onboarding, not on request. Request the BAA →

Where does AI touch my regulated records?

Only where you invoke it, and only to produce clearly-marked drafts for human review — protocol summaries, AE narratives, eligibility checklists. AI does not sign or approve controlled records. Your data is never used to train third-party AI models.

Can I export my data and audit trail?

Yes — full export on demand, anytime, in standard formats, including the audit trail. No lock-in and no exit fee, during the subscription and after it.

Bring your sponsor’s questions.

A 30-minute walkthrough on your own studies — audit trail, delegation log, and validation evidence.