Audit Trail Review
What a definition is not
A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.
Audit trail review is the routine, risk-based examination of a system’s audit trail entries to detect changes, deletions, aborted runs, re-tests, and other events that could indicate data-integrity problems. Having an audit trail is not enough — regulators expect it to be actively reviewed, or it provides no assurance.
Reviews should focus on GMP-relevant changes: modifications to results, changes to methods or parameters, invalidated or reprocessed data, and out-of-sequence timestamps. The review is typically performed as part of the batch record or result review, before the data is used to make a quality decision.
Purely time-based review of every entry is often impractical; a risk-based approach targets the high-consequence events and uses exception reporting where the system can flag anomalies. The frequency and scope of review, and who performs it, must be defined and documented.
- —Audit trails must be reviewed, not merely enabled.
- —Focus on GMP-relevant changes, deletions, and reprocessing.
- —Performed before the data drives a quality decision.
- —Risk-based scope with exception reporting where possible.
EU GMP Annex 11 §9 (audit trail review); MHRA GXP Data Integrity Guidance (2018); 21 CFR 211.68 and Part 11 audit-trail expectations.
Frequently asked questions
What is Audit Trail Review?
Audit trail review is the routine, risk-based examination of a system’s audit trail entries to detect changes, deletions, aborted runs, re-tests, and other events that could indicate data-integrity problems. Having an audit trail is not enough — regulators expect it to be actively reviewed, or it provides no assurance.
Which regulations cover Audit Trail Review?
EU GMP Annex 11 §9 (audit trail review); MHRA GXP Data Integrity Guidance (2018); 21 CFR 211.68 and Part 11 audit-trail expectations.