← GXP GLOSSARY
Data Integrity

Audit Trail

A secure, computer-generated, time-stamped record of who did what and when to an electronic record — created, modified, or deleted — that cannot be altered. Reviewing audit trails as part of record review is a core data-integrity expectation.

An audit trail is what makes an electronic record trustworthy. It must be computer-generated (not a manual log someone maintains), time-stamped from a controlled clock, attributable to a unique individual, and secure — meaning it cannot be switched off, edited, or overwritten by the users whose actions it records. Critically, it must not obscure previously recorded information: a change records the old value, the new value, who changed it, when, and why.

Having one is only half the requirement. The expectation across FDA, MHRA, and PIC/S is that audit trails are reviewed as part of routine record review — before batch release, not during an investigation after something went wrong. Review is risk-based and targeted at what matters: changes to results, aborted or repeated runs, altered integration parameters, changed sequences, deleted data. Reviewing every line of a chromatography audit trail is neither expected nor useful.

The recurring failures are consistent across warning letters: audit trail functionality disabled or never enabled; shared or generic logins that destroy attributability; system administrators who are also analysts and can therefore delete their own data; system clocks users can change; and audit trails that exist but which no one has ever reviewed. Each one converts otherwise good data into unreliable data.

KEY POINTS
  • Computer-generated, time-stamped, attributable, and secure against the users it records.
  • Must not obscure prior information — old value, new value, who, when, and why.
  • Having one is insufficient; risk-based review as part of record review is the expectation.
  • Target review at result changes, repeats/aborts, re-integration, and deletions — not every line.
  • Common failures: disabled trails, shared logins, analyst-administrators, changeable clocks, unreviewed trails.
  • Retained and readable for the full record retention period, including after system decommissioning.
REGULATORY BASIS

21 CFR 11.10(e); EU GMP Annex 11 §9 and Chapter 4; MHRA GXP Data Integrity Definitions and Guidance for Industry (2018); PIC/S PI 041-1 (Good Practices for Data Management and Integrity); WHO TRS 1033 Annex 4.

Frequently asked questions

What is Audit Trail?

A secure, computer-generated, time-stamped record of who did what and when to an electronic record — created, modified, or deleted — that cannot be altered. Reviewing audit trails as part of record review is a core data-integrity expectation.

Which regulations cover Audit Trail?

21 CFR 11.10(e); EU GMP Annex 11 §9 and Chapter 4; MHRA GXP Data Integrity Definitions and Guidance for Industry (2018); PIC/S PI 041-1 (Good Practices for Data Management and Integrity); WHO TRS 1033 Annex 4.

SEE ALSO
Data IntegrityData Integrity (DI)ALCOA+Attributable, Legible, Contemporaneous, Original, Accurate — plus Complete, Consistent, Enduring, AvailableCSVComputer System Validation
Browse the standards library →Explore GxP disciplines →

SPEQ decodes published regulatory concepts in plain language. Definitions are a practitioner reference, not legal or regulatory advice.

Weekly Briefing

Get the Weekly GxP Briefing

Curated regulatory intelligence — enforcement, recalls, guidance, and quality signals — in one practitioner-grade email each week. Free.

Read a past issue →