Skip to content
Assyro AI
Audit Trail Requirements: Capture, Review and Export
audit trail requirements
fda audit trail
audit trail 21 cfr part 11

Audit Trail Requirements: Capture, Review and Export

Guide

Map audit-trail requirements to Part 11, drug CGMP, EU GMP and clinical records. Use an EDMS example to assess attribution, revisions, timestamps and review evidence.

Assyro Team
14 min read

Audit-trail requirements concern the evidence needed to reconstruct relevant electronic-record activity: what changed, who or what performed it, when it happened, and the affected record. The applicable controls depend on the record's regulated use. Part 11, drug CGMP, EU GMP and clinical guidance should not be collapsed into a rule that every technical log needs the same review schedule.

For an electronic document management system, the practical test is whether a reviewer can connect a decision to the correct document revision and explain changes or exceptions using retained evidence. A list of timestamps, an Approved badge or a vendor's audit-ready claim is insufficient by itself.

This guide is for quality, document-control, regulatory operations and system owners. Primary sources were checked October 6, 2026. Its event tables and review exercise are proposed controls and invented examples, not results from a product trial or legal certification.

Establish which requirement applies to the record

Start with the record and its use, then assess the system. A spreadsheet maintaining required quality data cannot be excluded just because it is an office application. Conversely, an EDMS label does not establish that every stored business document falls under Part 11.

Comparison table with columns Framework, Relevant scope, Practical decision
FrameworkRelevant scopePractical decision
21 CFR Part 11Electronic records and signatures within its scope; section 11.10 addresses closed systemsIdentify regulated record use and applicable controls before specifying the trail
US drug CGMPRequired manufacturing, laboratory and related quality recordsConnect review responsibilities and timing to the underlying record requirements
EU GMP Annex 11Computerized systems in the human-medicines GMP scope discussed hereAssess GMP-relevant changes, deletions, security and regular review
FDA clinical electronic-record guidanceElectronic systems and records in clinical investigations within its stated scopeApply clinical responsibilities and risks, including access to sensitive trial information

For covered closed systems, 21 CFR 11.10(e) specifies secure, computer-generated, time-stamped trails of operator entries and actions creating, modifying or deleting electronic records. Earlier information must not be obscured, and audit documentation must remain available for FDA review and copying for at least the subject record's required period. Open-system controls require a separate assessment under 11.30. 21 CFR Part 11.

That regulatory text must be read with FDA's 2003 Scope and Application guidance. FDA describes enforcement discretion for specified Part 11 audit-trail provisions while underlying record obligations remain. Its scope discussion also distinguishes submitted records from working material used to prepare a submission: the latter is not automatically a Part 11 record unless otherwise required and maintained electronically. Document the actual applicability decision; enforcement discretion is not permission to discard trustworthy history. FDA Part 11 scope guidance, sections III.B and III.C.2.

For EU human-medicines GMP, the current Commission index lists Annex 11, revision January 2011, operational June 30, 2011. Section 9 addresses risk-based consideration of system-generated trails for GMP-relevant changes and deletions, reasons for those changes, intelligibility and regular review. Section 12.4 separately addresses operator identity and date/time in data and document management. This discussion does not assess the separate veterinary framework or every clinical or commercial system. European Commission Annex 11.

Keep an applicability record naming the record class, process, governing source, retention basis, owner and decision. If intended use or jurisdiction is unknown, leave the control assessment unresolved rather than choosing a convenient interpretation. The broader Part 11 guide provides surrounding context; the sources above govern the distinctions here.

Specify events that reconstruct the document's history

Version history and an audit trail answer related questions. Version history may preserve successive document contents. Audit evidence should also explain the relevant actions: who changed a status, which revision was reviewed, what failed and how the system responded. Security logs may supply supporting information without being interchangeable with record history.

Define an event inventory for the actual workflow. In an EDMS, useful candidates include creation, content revision, metadata correction, review submission, approval or rejection, effective-status change, withdrawal and controlled export. Add administrative changes that could affect capture, access or record interpretation. Do not promise that recording every page view or keystroke is universally required.

Use the following as an event-definition worksheet. It is a proposed evidence model, not a prescribed universal database schema.

Comparison table with columns Field or relationship, What the reviewer must be able to determine, Example for an EDMS
Field or relationshipWhat the reviewer must be able to determineExample for an EDMS
Record identityWhich controlled object was affectedDocument D-208 in repository REG
Revision identityWhich content/state the action concernedRevision 7, not whichever revision is current today
Action and resultWhat was attempted and what actually happenedApproval attempted; rejected because revision changed
Actor and authorityIdentified person or service and relevant roleUser U-17 as approver; separate service identity for an automated task
Previous and resulting stateMeaningful before/after values or retrievable contentDraft to In Review; old/new metadata values
Reason or authorizationWhy the change was allowed where applicableChange request CR-61 and recorded rationale
Event timeWhen the originating action occurred, with interpretable time basisSource event at 14:03:12 UTC
Recorded/received timeWhen another component stored or received itCentral receipt at 14:03:15 UTC
CorrelationRelated workflow, transaction or transfer evidenceWorkflow W-49 and request Q-801
Provenance and retention linkWhere evidence originated and how it remains availableSource-system identity and retained record package

Not every event needs an old and new scalar value. Creating a document has no prior revision; a denied action may leave the state unchanged. The definition should explain those cases explicitly instead of populating misleading default values. For content changes, a retrievable prior revision and usable comparison may be more meaningful than a database field containing an opaque binary value.

Separate a human decision from the service that carries it out. An integration account may legitimately identify a transfer, but it does not establish which person approved the source. Preserve that approval relationship rather than assigning the service account credit for the human decision.

FDA's December 2018 drug-CGMP guidance distinguishes shared read-only viewing accounts from actions requiring individual attribution. That nuance does not make shared approval credentials acceptable. FDA drug data-integrity guidance, question 5.

Set review timing from the record obligation and risk

Audit-trail review is a task with scope, evidence and a decision. A dashboard showing that logging is enabled does not demonstrate that relevant history was reviewed.

For drug CGMP, FDA's December 2018 guidance, questions 7 and 8, connects audit review to the review of the associated record. Where regulations specify data-review timing, that timing applies to the trail; where unspecified, the guidance recommends a process-informed risk assessment considering criticality, controls and quality impact. FDA data-integrity guidance. Production and control records also have a specific quality-unit review obligation before release or distribution under 21 CFR 211.192.

Write a review plan with four parts: the record population, events to inspect, trigger/deadline and qualified owner. Explain exclusions and any targeted or sampled review. A sampling shortcut cannot silently replace an applicable record-review obligation. Security surveillance, document-release review and periodic system oversight may have different owners and timing.

Clinical investigations need their own assessment. FDA's October 2024, Revision 1 electronic-systems guidance discusses risk-based audit-trail review, deliberate record actions rather than every keystroke, and access evidence where unblinding information is involved. Apply those clinical considerations instead of importing a manufacturing batch-release schedule. FDA clinical guidance, questions 12–14.

For EU GMP records, regular review under Annex 11 section 9 belongs in the operating procedure. Define the justified cadence and event-driven triggers for the actual use; the section does not prescribe a universal daily, weekly or monthly interval. An anomaly affecting a pending decision should reach the responsible owner promptly even if the next periodic review is later.

Distinguish the event clock from the recording clock

An audit display may show an action time, a database commit time, an integration-receipt time or an export time. Those are different facts. Label them so reviewers do not accidentally sort by receipt time and infer a false sequence of decisions.

For example, an originating system records an approval attempt at 14:03:12 UTC and a central review service receives that event at 14:03:15 UTC. The three-second difference is not automatically evidence of backdating or an acceptable delay. The assessment depends on trustworthy source capture, clock controls, transport behavior, completeness and the defined intended use.

A delayed central copy differs from a user inventing an earlier event after the fact. Preserve source event identity, original capture evidence and the receipt timestamp. If the only evidence is an editable date typed later, the event's actual timing remains uncertain.

Define suitable clock accuracy and ordering criteria for the process, including relevant time-zone and daylight-saving boundaries. Do not invent a universal FDA tolerance of plus or minus one second. The clinical guidance's question 14 addresses correct system time, authorized changes and discrepancy notification; it does not supply that universal limit. FDA clinical electronic-systems guidance.

Test queue delays, retries, unavailable downstream logging and clock changes against those criteria. Decide what the application does if required evidence cannot be captured reliably. A design that silently completes consequential changes while losing their history has not met the intended control just because it performs well under normal load.

Work through an EDMS review and escalation record

The following invented fixture concerns a controlled procedure D-208. Revision 7 entered review. Before approval, revision 8 was created through a permitted revision workflow, making the earlier approval task stale under this example's procedure. The configured rule requires an approval to match the reviewed revision.

Review record AR-26 covers workflow W-49 and its related events, with evidence bundle EB-26. Times below are UTC on the same illustrative day. This is a documentary exercise, not an observed incident.

Comparison table with columns Event and supplied evidence, Review result, Required disposition
Event and supplied evidenceReview resultRequired disposition
E-101: U-17 sends D-208 revision 7 to review; before/after state and authority resolvePass for this eventRetain linked evidence in AR-26
E-102: authorized editor creates revision 8; revision 7 remains retrievablePass for recorded revision changeAssess dependent review task under the procedure
E-103: U-17 attempts approval of revision 7; system denies it as stale; document state remains unchangedPass for the stale-approval prevention controlReissue the correct task; do not count the attempt as a completed approval
E-104: export says Approved, but identifies revision 8 while linked approval evidence identifies revision 7Fail: decision and exported revision disagreeHold affected release and investigate mapping/export behavior
E-105: an independent metadata correction identifies only a shared account, with no attributable personUnresolved attribution for that correctionPreserve evidence; system/process owners investigate and assess affected decisions
E-106: source event time 14:03:12; central receipt 14:03:15; retained source and queue evidence explain the delayPotentially acceptable, subject to established clock/capture criteriaRecord the assessment; do not replace either timestamp
E-107: failed export is logged with error code, no completed artifact and a later separately identified retryFailure correctly representedResolve the transfer exception and reconcile the successful retry

E-103 demonstrates why a failed business action can be evidence that a control worked. E-104 demonstrates the opposite: a successful export can contain an invalid approval association. E-107 must remain failed even when a later retry succeeds; changing its result to Success would destroy useful history.

For E-104, inspect the original approval event, version mapping, export request and resulting artifact. If supplied evidence establishes that the export resolves the latest revision while approval resolves an earlier revision, that mismatch is the supported causal explanation. Correct the identity boundary and repeat the stale-revision challenge. Do not conclude that a person approved revision 8 simply because the export says Approved.

For E-105, interview evidence may help an investigation, but it cannot justify silently rewriting the original trail to identify an assumed actor. Retain the original deficiency and add a traceable investigation or correction record under the procedure. Assess other corrections made through the same account; the affected scope may exceed D-208.

Now remove the originating timestamp or clock evidence from E-106. The timing result becomes Unknown, not Pass. If sequence is material to approval or release, hold that decision until its significance is resolved. Conversely, a traceable, explained receipt delay that satisfies the approved criteria should not be escalated as proven falsification merely because two timestamps differ.

AR-26 should retain the reviewer and date, exact record/revision population, filters and time basis, evidence references, individual findings, immediate containment, investigation owners and final disposition. In this fixture, the overall review is not closed: the export mismatch and attribution gap remain open. Passing neighboring rows cannot override them.

Verify protection, failure handling and usable exports

Ask a supplier to demonstrate protections in the configured environment and document administrative boundaries. An append-only application screen does not establish what a privileged database or infrastructure account can do. Database triggers can also have configuration and privilege boundaries. Evaluate the complete control design instead of declaring one architecture inherently compliant.

For drug CGMP computerized systems, 21 CFR 211.68(b) addresses authorized changes and protection of backup data. Apply the relevant obligations to your system design; the provision is not a mandate for a particular SQL table, separate audit database or cryptographic product.

An evaluation should challenge ordinary and privileged roles, configuration changes, record correction, deletion/withdrawal, failure recovery and restoration. Preserve the requested action, observed outcome and supporting evidence. Controlled retention expiry is a different decision from an unauthorized deletion during required retention.

For exports, compare the underlying population with the exported result, including revision identity, actor interpretation, event outcomes and timestamp labels. Check pagination, filters, date-boundary behavior and permissions. A report that contains only the newest revision may look complete while omitting the history under review. Record the export scope so an inspector or later reviewer can distinguish an intentional subset from missing records.

For AR-26, the fixture defines seven expected event IDs: E-101 through E-107. Suppose page one contains E-101–E-105 and page two contains E-106–E-107. Downloading only page one leaves five of seven events, even if the visible export has a valid signature and opens normally. Now suppose the file contains seven rows because E-105 is duplicated while E-107 is missing: the count matches, but the identity reconciliation still fails. Compare both the expected identifiers and their required content; do not accept a row total as proof of completeness.

This check needs an independent population basis. If the reviewer does not know which events, filters or interval the export should cover, seven rows establish neither completeness nor a failure. Resolve the source population and time basis first. Keep the failed export, corrected export and reconciliation result separately so the later reviewer can see what was repaired.

Test retrieval after archiving or changing systems. Keep necessary identifiers, role mappings and relationships interpretable after users leave and integrations end. Annex 11 section 17 addresses archive accessibility, readability, integrity and retrieval following relevant changes. EU GMP Annex 11.

A readable PDF may support review, but decide whether it preserves the needed relationships and functionality. Do not discard source evidence merely because a summary exports successfully. FDA's clinical guidance recommends searchable, sortable trails where practical, with understandable static alternatives linked to the corresponding records when that is not practical. FDA clinical guidance, question 12.

Apply the same reasoning across connected systems

The useful event population changes with the process. In a laboratory workflow, result edits, processing decisions and retained source data may matter; in manufacturing, executed steps and disposition decisions do. EDMS review concentrates on controlled content, versions, status and authority. A publishing workflow also needs to preserve the relationship between accepted source documents, prepared output and delivery evidence.

Those relationships do not require every system to copy every other system's logs. They require a reliable way to reconstruct the relevant chain. Identify which system is authoritative for each event and how a reviewer follows the link. A generic integration log stating Sync complete cannot substitute for an attributable document approval.

Use the computerized-system validation guide to organize intended-use requirements and verification evidence. For this audit-trail scope, include positive capture, wrong revision, missing attribution, rejected action, queue failure, time interpretation and export completeness. Retest affected boundaries when configuration, releases or interfaces change; a historical supplier demonstration does not establish today's configured behavior.

Assyro publishes this guide and provides document-management workflows for regulatory teams. Assess its actual event coverage, review access and exports against the same controlled example. This article does not establish an immutable architecture, a complete GMP quality system or universal compliance for an Assyro deployment.

Discuss your record and review workflow with Assyro. Bring one permitted document, its revision history, the decision it supports and the evidence your reviewer needs to reconstruct it.

About the author

Assyro Team

Expert regulatory operations consultants helping pharmaceutical companies navigate complex compliance challenges.

Related articles

Demos available this week