A secure, computer-generated, time-stamped record of who did what and when to an electronic record — created, modified, or deleted — that cannot be altered. Reviewing audit trails as part of record review is a core data-integrity expectation.
An audit trail is what makes an electronic record trustworthy. It must be computer-generated (not a manual log someone maintains), time-stamped from a controlled clock, attributable to a unique individual, and secure — meaning it cannot be switched off, edited, or overwritten by the users whose actions it records. Critically, it must not obscure previously recorded information: a change records the old value, the new value, who changed it, when, and why.
Having one is only half the requirement. The expectation across FDA, MHRA, and PIC/S is that audit trails are reviewed as part of routine record review — before batch release, not during an investigation after something went wrong. Review is risk-based and targeted at what matters: changes to results, aborted or repeated runs, altered integration parameters, changed sequences, deleted data. Reviewing every line of a chromatography audit trail is neither expected nor useful.
The recurring failures are consistent across warning letters: audit trail functionality disabled or never enabled; shared or generic logins that destroy attributability; system administrators who are also analysts and can therefore delete their own data; system clocks users can change; and audit trails that exist but which no one has ever reviewed. Each one converts otherwise good data into unreliable data.
- —Computer-generated, time-stamped, attributable, and secure against the users it records.
- —Must not obscure prior information — old value, new value, who, when, and why.
- —Having one is insufficient; risk-based review as part of record review is the expectation.
- —Target review at result changes, repeats/aborts, re-integration, and deletions — not every line.
- —Common failures: disabled trails, shared logins, analyst-administrators, changeable clocks, unreviewed trails.
- —Retained and readable for the full record retention period, including after system decommissioning.
21 CFR 11.10(e); EU GMP Annex 11 §9 and Chapter 4; MHRA GXP Data Integrity Definitions and Guidance for Industry (2018); PIC/S PI 041-1 (Good Practices for Data Management and Integrity); WHO TRS 1033 Annex 4.
Frequently asked questions
What is Audit Trail?
A secure, computer-generated, time-stamped record of who did what and when to an electronic record — created, modified, or deleted — that cannot be altered. Reviewing audit trails as part of record review is a core data-integrity expectation.
Which regulations cover Audit Trail?
21 CFR 11.10(e); EU GMP Annex 11 §9 and Chapter 4; MHRA GXP Data Integrity Definitions and Guidance for Industry (2018); PIC/S PI 041-1 (Good Practices for Data Management and Integrity); WHO TRS 1033 Annex 4.
SPEQ decodes published regulatory concepts in plain language. Definitions are a practitioner reference, not legal or regulatory advice.
Get the Weekly GxP Briefing
Curated regulatory intelligence — enforcement, recalls, guidance, and quality signals — in one practitioner-grade email each week. Free.