Skip to content
Assyro AI
Back to Glossary
General

Audit Trail

Audit trail is the secure, computer-generated, time-stamped metadata record of who created, modified, or deleted a regulated record and when, captured independently of the record so that previously recorded values are never obscured.

Usage Examples

  • QA held the release because the audit trail showed the integration parameters were changed after the result was reported.
  • Pull the audit trail for that batch record and show me who edited the yield entry and when.
  • The system is validated, but the audit trail can be switched off by a site administrator, so we cannot rely on it.

What is Audit Trail?

Audit trail is the secure, computer-generated, time-stamped metadata record of who created, modified, or deleted a regulated record and when, captured independently of the record so that previously recorded values are never obscured.

Audit trails exist because an electronic record can be changed without leaving a mark. Paper left evidence of its own history: a struck-through entry, an initial, a date. When batch records, chromatograms, and case report forms moved into software, that visible history vanished, and the regulatory answer was to make the system itself record every entry and every change, independently of the user making it.

Audit trails cover the electronic records a company creates, modifies, maintains, or transmits under 21 CFR Part 11, and, in clinical work, the metadata associated with data of higher criticality under ICH E6(R3). Audit trails do not cover every log a system emits. E6(R3) puts the responsible party in charge of determining which metadata actually require review and retention, so scope is a documented decision, not a system default.

Audit trails are applied through planned review, not by switching a feature on. ICH E6(R3) requires procedures for reviewing trial data, audit trails, and other relevant metadata, risk-based and adjusted as the trial runs. Under CGMP, the audit trail is the evidence that changes to master production and control records came only from authorized personnel, which is what an investigator asks to see.

Not to be confused with

Data integrity
data integrity is the property a record must have; the audit trail is one control that makes that property demonstrable. Complete audit trails do not make data accurate, and accurate data with no audit trail cannot be verified by anyone who was not in the room.
21 CFR Part 11
Part 11 is the regulation; the audit trail is one of the controls it requires, alongside validation, access limits, and signature controls. A system described as "Part 11 compliant" is claiming the whole set, not the audit trail alone.
Validation
validation demonstrates the system does what it is specified to do, including generating an audit trail. The audit trail then records what users actually did with the system. A validated system whose audit trail is disabled satisfies neither obligation.
Batch record
the batch record is the underlying regulated record; the audit trail is the metadata describing who changed it and when. Audit trail retention is set by the batch record's retention period, not by the system's log-rotation setting.

Audit trail obligations attach to the record holder, not to the software vendor.

What you must do

  1. 1Generate secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions creating, modifying, or deleting electronic records, and never obscure previously recorded information21 CFR 11.10(e)
  2. 2Retain audit trail documentation for at least as long as the subject electronic records, and make it available for agency review and copying21 CFR 11.10(e)
  3. 3Limit system access to authorized individuals, so every audit trail entry attributes to one identified person21 CFR 11.10(d)
  4. 4Exercise controls over computer or related systems so that changes to master production and control records or other CGMP records are instituted only by authorized personnel21 CFR 211.68(b)
  5. 5Keep audit trails, reports and logs enabled; modify an audit trail only in rare circumstances, and only with a log of the action and its justificationICH E6(R3) 4.2.2
  6. 6Put procedures in place for reviewing trial data, audit trails, and other relevant metadata as a planned, risk-based activity adjusted during the trialICH E6(R3) 4.2.3

Common mistakes

  • Leaving the audit trail disabled or user-configurable

    ICH E6(R3) requires that audit trails, reports and logs are not disabled, and that trails are not modified except in rare, logged, justified cases. If an administrator can switch the trail off, every record the system holds becomes unverifiable, and the finding lands on the sponsor or manufacturer, not the vendor.

  • Treating a vendor's "Part 11 compliant" claim as compliance

    21 CFR 11.10 places the duties on the person using the closed system: secure time-stamped trails, non-obscured changes, and access limited to authorized individuals. Configuration, user administration, and review are yours. Purchasing does not transfer them, and no vendor is inspected in your place.

  • Letting the audit trail expire on the system's default retention

    21 CFR 11.10(e) ties audit trail retention to the retention period of the underlying electronic records. A 90-day log rotation over data retained for years quietly destroys the evidence, and the gap surfaces during an inspection, at the one moment it cannot be recreated.

When This Matters

  • QA held the release because the audit trail showed the integration parameters were changed after the result was reported.
  • Pull the audit trail for that batch record and show me who edited the yield entry and when.
  • The system is validated, but the audit trail can be switched off by a site administrator, so we cannot rely on it.

Frequently Asked Questions

21 CFR Part 11 requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions creating, modifying, or deleting electronic records. Record changes must not obscure previously recorded information, and the audit trail must be available to FDA for review and copying.

Related Use Cases

Related Regulatory Intelligence

Related Actions

Sources & References

Share this page
Agent CTA Background

Simplify Audit Trail compliance