Citation concordance
An index of sections in different instruments that address the same subject, so a reader consulting one can find the others.
contextual mapping — not a regulatory applicability determination The policy, stated once
Access control
- EU AI Act (whole) uses “access controls” — source (opens in new tab)
and established solutions, and cyber and physical access controls, appropriate to the relevant circumstances
- EU Cyber Resilience Act Annex III — source (opens in new tab)
tems and privileged access management software and hardware, including authentication and access control readers,
- EU NIS2 Directive (whole) — source (opens in new tab)
resources security and have in place appropriate access control policies. Those measures should be
- NIST SP 800-82 (whole) — source (opens in new tab)
systems, building automation systems, transportation systems, physical access control systems, physical environment monitoring systems,
Audit trail
- EMA CT computerised systems (whole) — source (opens in new tab)
trials EMA Computerised systems electronic data validation audit trail user management security electronic clinical
- FDA Part 11 scope (whole) — source (opens in new tab)
Approach to Specific Part 11 Requirements Validation Audit Trail Legacy Systems Copies of Records
- 21 CFR Part 11 § 11.10 uses “audit trails” — source (opens in new tab)
e ) Use of secure, computer-generated, time-stamped audit trails to independently record the date
Backup
- EU AI Act Paragraph 1 — source (opens in new tab)
through technical redundancy solutions, which may include backup or fail-safe plans. High-risk AI systems
- EU Machinery Regulation (whole) — source (opens in new tab)
mode. Emergency stop devices shall be a backup to other safeguarding measures and not
- EU NIS2 Directive Article 11 — source (opens in new tab)
shall be equipped with redundant systems and backup working space to ensure continuity of
- 21 CFR Part 211 § 211.68 — source (opens in new tab)
of the computer or related system. A backup file of data entered into the
Data integrity
- FDA data integrity (whole) — source (opens in new tab)
Data Integrity and Compliance With Drug CGMP: Questions and Answers | FDA Skip to
- MHRA data integrity (whole) — source (opens in new tab)
Guidance on GxP data integrity - GOV.UK Cookies on GOV.UK We use some essential
Electronic record
- EMA CT computerised systems (whole) uses “electronic records” — source (opens in new tab)
meetings/GCP IWG Subgroup on Computer Systems/Computers and electronic records Archive/2018 Guideline on electronic systems
- FDA electronic systems (clinical) (whole) uses “electronic records” — source (opens in new tab)
24 for Word uuid: uuid: 9 application/pdf Electronic Systems, Electronic Records, and Electronic Signatures
- FDA Part 11 scope (whole) uses “electronic records” — source (opens in new tab)
Part 11, Electronic Records; Electronic Signatures - Scope and Application | FDA Skip to
- 21 CFR Part 11 (whole) uses “electronic records” — source (opens in new tab)
eCFR :: 21 CFR Part 11 -- Electronic Records; Electronic Signatures Site Feedback You
Electronic signature
- EMA CT computerised systems (whole) uses “electronic signatures” — source (opens in new tab)
response technology (IRT) case report form (CRF) electronic signatures artificial intelligence (AI) Adobe PDF
- FDA electronic systems (clinical) (whole) uses “electronic signatures” — source (opens in new tab)
24 for Word uuid: uuid: 9 application/pdf Electronic Systems, Electronic Records, and Electronic Signatures
- FDA Part 11 scope (whole) uses “electronic signatures” — source (opens in new tab)
Part 11, Electronic Records; Electronic Signatures - Scope and Application | FDA Skip to
- 21 CFR Part 11 (whole) uses “electronic signatures” — source (opens in new tab)
eCFR :: 21 CFR Part 11 -- Electronic Records; Electronic Signatures Site Feedback You
Human oversight
- CEN/CLC JTC 21 (whole) — source (opens in new tab)
and ensure compliance with risk management, transparency, human oversight, cybersecurity, and quality assurance requirements.
- EU AI Act (whole) — source (opens in new tab)
and the provision of information to deployers, human oversight, and robustness, accuracy and cybersecurity.
Risk management
- CEN/CLC JTC 21 (whole) — source (opens in new tab)
presumption of conformity and ensure compliance with risk management, transparency, human oversight, cybersecurity, and
- EU AI Act (whole) — source (opens in new tab)
and appropriate. (66) Requirements should apply to high-risk AI systems as regards risk management,
- EU Cyber Resilience Act (whole) — source (opens in new tab)
develop and build their products by applying risk management principles and by setting out
- EU Cybersecurity Act (whole) — source (opens in new tab)
and ICT processes to improve their cybersecurity risk management activities by improving, for example,
- Regulation (EU) 2026/1744 Article 9 — source (opens in new tab)
with the sectoral legislation, Article 9(10) on risk management and Article 17(3) on quality
- EU GMP Annex 11 Chapter 9 — source (opens in new tab)
related documents Site Master File Q9 Quality Risk Management Q10 Note for Guidance on
- EU IVDR (whole) — source (opens in new tab)
such as those relating to quality and risk management, laid down in this Regulation.
- EU MDR (whole) — source (opens in new tab)
at least with regard to application of risk management and, where necessary, clinical evaluation
- EU NIS2 Directive (whole) — source (opens in new tab)
relating to information and communication technology (ICT) risk management, management of ICT-related incidents and,
- FDA Part 11 scope (whole) — source (opens in new tab)
2000) ISO 14971:2002 Medical Devices- Application of risk management to medical devices (ISO, 2001)
- Health Canada ML (whole) — source (opens in new tab)
New regulations strengthening the post-market surveillance and risk management of medical devices in Canada
- ISO/IEC SC 42 (whole) — source (opens in new tab)
ISO/TC 261 Additive manufacturing ISO ISO/TC 262 Risk management ISO ISO/TC 267 Facility management
- NIST agent standards (whole) — source (opens in new tab)
Does Conducts fundamental research, emphasizing measurements and risk management: NIST’s AI portfolio includes fundamental
- NIST AI 600-1 (whole) — source (opens in new tab)
Word uuid: uuid: 13 application/pdf Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile
- NIST AI RMF (whole) — source (opens in new tab)
AI Risk Management Framework | NIST Skip to main content Official websites use .gov
- NIST AI RMF Playbook (whole) — source (opens in new tab)
the outcomes laid out in the AI Risk Management Framework (AI RMF) Core (Tables
- NIST CSF 2.0 (whole) — source (opens in new tab)
rsecurity ; Cybersecurity Framework (CSF) ; cybersecurity risk governance ; cybersecurity risk management ;
- NIST SP 800-82 (whole) — source (opens in new tab)
(OT) ; programmable logic controllers (PLC) ; risk management ; security controls ; supervisory
- NISTIR 8183 (whole) — source (opens in new tab)
manufacturing; network security; programmable logic controllers (PLC); risk management; security controls; supervisory control and
- PIC/S PI 011 Annex 4 — source (opens in new tab)
documents Aide Memoire on Assessment of Quality Risk Management (QRM) Implementation PI 038-2 Documents
- PIC/S PI 041 Annex 4 — source (opens in new tab)
documents Aide Memoire on Assessment of Quality Risk Management (QRM) Implementation PI 038-2 Documents
Validation
- EMA CT computerised systems (whole) — source (opens in new tab)
clinical trials EMA Computerised systems electronic data validation audit trail user management security electronic
- EU AI Act (whole) — source (opens in new tab)
Union law. High-quality data sets for training, validation and testing require the implementation of
- EU Cyber Resilience Act (whole) — source (opens in new tab)
requiring the manufacturer to ensure adequate input validation. In assessing whether a feature update
- Regulation (EU) 2026/1744 Paragraph 1 — source (opens in new tab)
be developed on the basis of training, validation and testing data sets that meet
- EU GMP Annex 11 Annex 15 — source (opens in new tab)
Plasma (May 2011) Annex 15 Qualification and validation (into operation since 1 October 2015)
- EU IVDR Article 48 — source (opens in new tab)
be validated by that body. After its validation, the notified body shall upload the
- EU Machinery Regulation Article 30 — source (opens in new tab)
Member States within two weeks of the validation of the notification where it includes
- EU MDR Article 5 — source (opens in new tab)
its planned application after reprocessing, — the validation of procedures for the entire process,
- FDA Part 11 scope (whole) — source (opens in new tab)
Records Approach to Specific Part 11 Requirements Validation Audit Trail Legacy Systems Copies of
- FDA software validation (whole) — source (opens in new tab)
General Principles of Software Validation | FDA Skip to main content Skip to FDA
- PIC/S PI 011 (whole) — source (opens in new tab)
Category Section PIC/S Recommendations on Qualification and Validation PI 006-4 Documents for Inspectors Guidance
- PIC/S PI 041 (whole) — source (opens in new tab)
Category Section PIC/S Recommendations on Qualification and Validation PI 006-4 Documents for Inspectors Guidance
- 21 CFR Part 11 § 11.10 — source (opens in new tab)
shall include the following: ( a ) Validation of systems to ensure accuracy, reliability,
- 21 CFR Part 211 (whole) — source (opens in new tab)
program shall be maintained along with appropriate validation data. Hard copy or alternative systems,
Where each subject sits in the text
A subject can be printed in the passage a document opens as its scope, or elsewhere in that document, or nowhere in it. Each of those is a position in a document’s own arrangement, and a position is not a degree. What the difference between two of them is worth is the reader’s to settle. The values below carry no order of their own: they are listed alphabetically by their own label, and every cell beneath one is a count.
What was read
The record holds 132 tracked entries. Of those, 94 name a retained text in the observation store, and the reading below covers exactly them: for each, the text its newest observation carrying one names. Another 33 carry a licence position under which no text is read here at all — a restricted text is cited and linked, never excerpted — and 5 name no retained text, so nothing was searched for them and no absence is filed against them.
A subject is matched verbatim: the words as written, an optional trailing s, ignoring case, on word boundaries. No synonym, no stem, no paraphrase. A scope passage opens where the text prints a structural marker of its own — an article number, a section symbol, a clause number — followed immediately by the word scope, and closes where that same marker form next appears followed by a capitalised word. Two printings are not read as openings, because each is how a publisher sets a contents list rather than a passage: one whose marker is followed by dot leaders within 40 characters, and one the next marker of the same form crowds within 60. Where a text prints markers of more than one form, the most specific form yielding a candidate is the one read, so an article number is read as an article and not as a bare clause number. Where the text prints more than one opening under all of that, nothing is published for it: several openings is an ambiguity, and choosing between them mechanically would be this record inventing which passage a publisher meant.
The values, and what each one says
- absent from the retained text
- the retained text was read and the subject is not in it
- in the retained text, outside the scope passage
- the subject is in the retained text, and every occurrence of it falls outside the passage that text opens as its scope
- in the retained text; no scope passage located
- the subject is in the retained text, and this read located no passage opening as scope in that text — so neither of the two values above can be stated for it
- within the scope passage
- at least one occurrence falls inside the passage the text opens as its scope
Where each subject sits, across the texts read
| Subject | absent from the retained text | in the retained text, outside the scope passage | in the retained text; no scope passage located | within the scope passage |
|---|---|---|---|---|
| Access control | 82 | 5 | 7 | 0 |
| Audit trail | 83 | 4 | 7 | 0 |
| Backup | 80 | 6 | 8 | 0 |
| Data integrity | 82 | 3 | 9 | 0 |
| Electronic record | 84 | 2 | 7 | 1 |
| Electronic signature | 88 | 1 | 4 | 1 |
| Human oversight | 90 | 1 | 3 | 0 |
| Risk management | 46 | 8 | 38 | 2 |
| Validation | 46 | 12 | 35 | 1 |
The texts that open a passage this way
Of the 94 retained texts read, 17 print exactly one opening of that form, 75 print none, and 2 print more than one. That a text prints none is a fact about what this reader can locate in a retained text and not a statement about how a publisher arranges a document.
| Text | Opens at | Subjects inside the passage | Read from |
|---|---|---|---|
| EMA CT computerised systems | 2. Scope | Validation | answered (opens in new tab) · retrieved |
| EMA data quality framework | 4. Scope | — | answered (opens in new tab) · retrieved |
| EU AI Act | Article 2 Scope | — | answered (opens in new tab) · retrieved |
| EU Cyber Resilience Act | Article 2 Scope | — | answered (opens in new tab) · retrieved |
| EU Cybersecurity Act | Article 1 Subject matter and scope | — | answered (opens in new tab) · retrieved |
| EU GMP Annex 2 | 1 Scope | — | answered (opens in new tab) · retrieved |
| EU GMP Annex 21 | 1. Scope | — | answered (opens in new tab) · retrieved |
| EU IVDR | Article 1 Subject matter and scope | — | answered (opens in new tab) · retrieved |
| EU Machinery Regulation | Article 2 Scope | — | answered (opens in new tab) · retrieved |
| EU MDR | Article 1 Subject matter and scope | Risk management | answered (opens in new tab) · retrieved |
| EU NIS2 Directive | Article 2 Scope | — | answered (opens in new tab) · retrieved |
| ICH Q14 | 1.2 Scope | — | answered (opens in new tab) · retrieved |
| ICH Q2(R2) | 1.2 Scope | — | answered (opens in new tab) · retrieved |
| ICH Q9(R1) | 2. Scope | Risk management | answered (opens in new tab) · retrieved |
| 21 CFR Part 11 | § 11.1 Scope | Electronic record · Electronic signature | answered (opens in new tab) · retrieved |
| 21 CFR Part 211 | § 211.1 Scope | — | answered (opens in new tab) · retrieved |
| 21 CFR Part 820 (QMSR) | § 820.1 Scope | — | answered (opens in new tab) · retrieved |
2 print more than one opening, and nothing is published for them, because nothing mechanical says which passage a publisher meant: EU GMP Annex 1 1. Scope · 1 Scope; EU GMP Annex 11 (draft) 12.7. Scope · 13.1. Scope · 14.2. Scope · 16.5. Scope.
How this section and the lists above were measured
Every count in this section was taken from the retained texts this build read, on the day it read them.
The citation list under each subject was generated on and names the sources that carried a quotable span for that subject on that day. The two readings were taken at different times over a store that keeps growing, so they are not the same measurement and are not presented as one; the later of the two is the one in this section.
Compared subject by subject: for 9 of 9 the count of texts holding the subject now exceeds the length of that subject’s list, for 0 it falls short of it, and the rest agree.
Last updated: