Audit Trail Review SOP
A procedure for routine, risk-based review of electronic audit trails: what to review, how often, who reviews it, and how audit-trail review is built into batch-record and data review rather than treated as a separate exercise. Aligned to MHRA GXP data-integrity guidance, EU GMP Annex 11, and 21 CFR Part 11.
What a template is not
A template is a document baseline to adapt inside your own quality system. SPEQ does not approve, validate, or take responsibility for what you issue from it, and using one is not evidence of compliance.
The procedure that turns audit-trail review from a claim into a demonstrable control — what is reviewed, how often, by whom, and how the review attaches to batch-record and data review rather than running beside it. The characteristic failure is a review that confirms the audit trail exists without examining any entry in it. Which systems and which events warrant review is your risk determination.
What's Inside
How to Use It
The full section structure of this template — every section and sub-section, so you can use it as a baseline for your own site document.
EU GMP Annex 11 §9 requires audit trails to be generated and reviewed, 21 CFR Part 11 requires secure, computer-generated, time-stamped audit trails for electronic records, and the MHRA GXP data-integrity guidance places their review inside data governance rather than alongside it. None of them sets your review frequency, your sampling depth, or which events matter in your systems. Those are risk determinations your organisation makes and defends; the frequency matrix here is SPEQ synthesis for recording them consistently.