SOPREFERENCE OUTLINE

Audit Trail Review SOP

A procedure for routine, risk-based review of electronic audit trails: what to review, how often, who reviews it, and how audit-trail review is built into batch-record and data review rather than treated as a separate exercise. Aligned to MHRA GXP data-integrity guidance, EU GMP Annex 11, and 21 CFR Part 11.

What a template is not

A template is a document baseline to adapt inside your own quality system. SPEQ does not approve, validate, or take responsibility for what you issue from it, and using one is not evidence of compliance.

CHECKING ACCESS

Checking your Professional access…

REGULATIONS MAPPED
MHRA GXP Data Integrity (2018)EU GMP Annex 1121 CFR Part 11
DOCUMENT TYPE
SOP
LAST UPDATED
August 2026
PURPOSE

The procedure that turns audit-trail review from a claim into a demonstrable control — what is reviewed, how often, by whom, and how the review attaches to batch-record and data review rather than running beside it. The characteristic failure is a review that confirms the audit trail exists without examining any entry in it. Which systems and which events warrant review is your risk determination.

What's Inside

Inventory of GxP systems and the audit trails each produces, including the ones nobody owns
Risk-based review frequency matrix, driven by the data’s influence on product and release decisions
Definition of a reviewable event and of a discrepancy, so reviewers reach consistent conclusions
Reviewer roles and independence, with the practical limits stated where full segregation is impossible
Review method — what is sampled, what is examined in full, and on what basis
Escalation route and deviation or CAPA linkage for findings that affect a released decision
Record of the review itself, because an unrecorded review is indistinguishable from no review

How to Use It

1List every GxP system and the audit trails it produces; the trails nobody claims are where unreviewed changes accumulate
2Set frequency by the data’s impact on product and release decisions rather than by how easy the trail is to read
3Define the events a reviewer looks for and what a discrepancy is, or reviewers will each invent their own threshold
4Assign reviewers independent of the data where practical, and state the compensating control where that is not achievable
5Sample deliberately and record what you examined; a review recorded only as completed proves attendance, not examination
6Escalate findings that touch a released decision through deviation and CAPA, not through an email to the system owner
DOCUMENT CONTENTS

The full section structure of this template — every section and sub-section, so you can use it as a baseline for your own site document.

Document Control
Document InformationApproval SignaturesRevision HistoryDistribution List
1Purpose, Scope, and Definitions
2Systems in Scope and Review Frequency
3Review Procedure
4Escalation and Records
REGULATORY CONTEXT

EU GMP Annex 11 §9 requires audit trails to be generated and reviewed, 21 CFR Part 11 requires secure, computer-generated, time-stamped audit trails for electronic records, and the MHRA GXP data-integrity guidance places their review inside data governance rather than alongside it. None of them sets your review frequency, your sampling depth, or which events matter in your systems. Those are risk determinations your organisation makes and defends; the frequency matrix here is SPEQ synthesis for recording them consistently.

MAPPED STANDARDS
MHRA GXP Data Integrity (2018)EU GMP Annex 1121 CFR Part 11
Browse the standards catalog →