What Is Audit Trail Review?
Audit trail review is the periodic, documented, risk-based examination of a system's audit trail - the secure log of who created, changed, or deleted regulated data, when, and why. In GxP environments (good manufacturing, laboratory, and clinical practice), it is the control that turns an audit trail from a passive record nobody reads into an active line of defense against data integrity failures. Recording every change is necessary but not sufficient; someone qualified has to actually look at those changes and ask whether they make sense.
Regulators treat audit trail review as a core data integrity control precisely because the failures it catches are the ones that matter most: a result quietly overwritten, a test repeated until it passed, a timestamp that does not line up with the shift record. These are not caught by a system that merely logs events - they are caught by a review that reads the log with a skeptical eye.
Audit trail review is the periodic, risk-based check of a GxP audit trail by a qualified reviewer - looking for altered results, suspicious repeats, and changes without justification. It is required or expected under FDA 21 CFR Part 11, EU GMP Annex 11, and the MHRA data integrity guidance, and it enforces the ALCOA+ principles that keep records reliable. The audit trail answers who, what, when, and why; the review is the human judgment that the "what" and "why" are legitimate. It is a process inside validated GxP systems - supported by, but distinct from, the lineage and provenance a governance platform provides across the wider data estate.
What Audit Trail Review Is
Audit trail review is a defined quality activity with four characteristics that distinguish it from simply having audit trails switched on:
- Periodic. It happens on a defined cadence - often tied to batch release, result approval, or a scheduled interval - not only when something has already gone wrong.
- Risk-based. The depth and frequency scale with the risk of the data. A result that determines whether a drug batch is released warrants closer review than a low-impact configuration log.
- Performed by a qualified, independent reviewer. Typically quality assurance or a suitably trained second person - not the same analyst who generated the data.
- Documented. The review itself produces evidence: what was reviewed, by whom, when, and what was found. To a regulator, a review that left no trace did not happen.
First, What an Audit Trail Is
You cannot review what you have not captured, so audit trail review depends on a properly built audit trail. In a GxP system, an audit trail is a secure, computer-generated, time-stamped record that captures actions affecting regulated data and configuration. A well-formed entry answers four questions:
- Who performed the action, via a unique, attributable identity.
- What changed - the field, the old value, and the new value.
- When it happened, with a trustworthy timestamp.
- Why, where a change is involved - a recorded reason.
Three properties make it trustworthy: it is automatic (the user cannot switch it off), secure (entries cannot be altered or deleted after the fact), and independent (it survives even if the underlying record is deleted). An audit trail that a user can pause or edit is not an audit trail; it is a suggestion.
The Regulatory Basis
Audit trail review sits at the intersection of several regulations and guidances, all pointing the same direction.
- FDA 21 CFR Part 11 requires secure, computer-generated, time-stamped audit trails for electronic records in regulated activities, recording operator entries and actions that create, modify, or delete records.
- EU GMP Annex 11 (Computerised Systems) calls for audit trails covering GMP-relevant changes and deletions, available in an intelligible form, and expects them to be reviewed on a risk basis - which is the explicit mandate for audit trail review.
- MHRA GxP Data Integrity Guidance (2018) formalized the ALCOA+ principles (Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, Available) and describes routine audit trail review as an effective means of detecting integrity problems.
- ISPE GAMP Guide on Records and Data Integrity gives practical guidance on distinguishing true audit-trail data from ordinary system logs and on designing a proportionate review.
The common thread: integrity is not assumed from the presence of a log. It is demonstrated by the act of reviewing it. This is the same discipline that underlies data integrity as a whole - a record must be trustworthy across its entire lifecycle, and a reviewed audit trail is the evidence that it is.
How Review Works in Practice
A workable audit trail review program answers a few practical questions before the first review is ever run:
- Which audit trails matter? Not every log is a GxP audit trail. The program identifies the records whose integrity affects product quality or patient safety and focuses effort there.
- How often, and how deeply? Frequency and depth follow a documented risk assessment. High-impact data (release-determining results) is reviewed before the decision it supports; lower-impact data may be reviewed on a schedule or by sampling.
- What is the reviewer looking for? Changes without a justification, results modified after the fact, repeated tests or reprocessing, activity at implausible times, and entries that contradict paper or shift records.
- What happens on a finding? A genuine anomaly routes into the quality system - investigation, and where warranted, corrective and preventive action (CAPA). A review that never produces a finding, over a long enough period, is itself a red flag about how it is being run.
The recurring failure mode is volume. Modern systems generate far too many entries to read line by line, so mature programs rely on the system to surface the entries that matter - exception-based review that flags changes to critical fields rather than asking a human to scroll through everything.
How Dawiso Fits
It is worth being precise here, because this is a regulated activity and overclaiming helps no one. Audit trail review is performed inside the validated GxP systems that hold the records - the LIMS, MES, chromatography data system, or QMS. Dawiso is not that system and does not perform Part 11 audit trail review. What Dawiso provides is the governed context around those systems that makes an integrity program easier to run and to evidence:
- Traceability across the estate. The audit trail answers "who changed this record"; interactive lineage answers the complementary question - "where did this data come from and what does it feed" - across systems, which is the estate-level analog of the traceability that data integrity depends on.
- An inventory of GxP-relevant systems and data. The data catalog documents which systems hold regulated data, who owns them, and how they are classified, so a data-integrity program knows where audit trails must exist in the first place.
- Consistent definitions. The business glossary keeps terms like "batch," "result," and "critical data" defined the same way across teams, so reviews and investigations speak one language.
In short: the review is the regulated system's job; the surrounding governance, provenance, and inventory are where a platform like Dawiso earns its place in the program.
Conclusion
Audit trail review is the deceptively simple idea that a log of who changed what, when, and why is only worth having if someone qualified actually reads it - on a schedule, with a skeptical eye, and with a documented result. It is the control regulators lean on because it catches the integrity failures that pure logging misses, and it is anchored in ALCOA+ and codified across Part 11, Annex 11, and the MHRA guidance. The review itself belongs to the validated system that holds the records. The governance around it - traceability, a governed inventory of regulated systems, and consistent definitions - is what keeps the whole program coherent, and it is where a data governance platform contributes without pretending to be the regulated system.
Sources
- European Commission - EudraLex Volume 4, Annex 11: Computerised Systems (audit trails and risk-based review).
- MHRA - 'GXP' Data Integrity Guidance and Definitions (2018) (ALCOA+ and audit trail review).
See it in action
Interactive Data Lineage
Visualizing how data moves, transforms, and connects across systems, applications, and reports.