Skip to main content
audit trail reviewGxP21 CFR Part 11EU Annex 11data integrityALCOA+

What Is Audit Trail Review?

Audit trail review is the periodic, documented, risk-based examination of a system's audit trail - the secure log of who created, changed, or deleted regulated data, when, and why. In GxP environments (good manufacturing, laboratory, and clinical practice), it is the control that turns an audit trail from a passive record nobody reads into an active line of defense against data integrity failures. Recording every change is necessary but not sufficient; someone qualified has to actually look at those changes and ask whether they make sense.

Regulators treat audit trail review as a core data integrity control precisely because the failures it catches are the ones that matter most: a result quietly overwritten, a test repeated until it passed, a timestamp that does not line up with the shift record. These are not caught by a system that merely logs events - they are caught by a review that reads the log with a skeptical eye.

TL;DR

Audit trail review is the periodic, risk-based check of a GxP audit trail by a qualified reviewer - looking for altered results, suspicious repeats, and changes without justification. It is required or expected under FDA 21 CFR Part 11, EU GMP Annex 11, and the MHRA data integrity guidance, and it enforces the ALCOA+ principles that keep records reliable. The audit trail answers who, what, when, and why; the review is the human judgment that the "what" and "why" are legitimate. It is a process inside validated GxP systems - supported by, but distinct from, the lineage and provenance a governance platform provides across the wider data estate.

What Audit Trail Review Is

Audit trail review is a defined quality activity with four characteristics that distinguish it from simply having audit trails switched on:

  • Periodic. It happens on a defined cadence - often tied to batch release, result approval, or a scheduled interval - not only when something has already gone wrong.
  • Risk-based. The depth and frequency scale with the risk of the data. A result that determines whether a drug batch is released warrants closer review than a low-impact configuration log.
  • Performed by a qualified, independent reviewer. Typically quality assurance or a suitably trained second person - not the same analyst who generated the data.
  • Documented. The review itself produces evidence: what was reviewed, by whom, when, and what was found. To a regulator, a review that left no trace did not happen.
Audit Trail Review - Entry Contents and Review Cycle AUDIT TRAIL REVIEW WHAT AN AUDIT TRAIL ENTRY CAPTURES WHO Analyst identity (unique login) WHAT Field changed: Result old value 98.2 becomes new value 101.0 WHEN Timestamp WHY Reason for change Secure, time-stamped, cannot be edited or disabled by the user THE REVIEW CYCLE 1. Set risk-based frequency higher risk data, closer review 2. Qualified, independent reviewer not the person who generated the data 3. Document what was found evidence that the review happened 4. Route issues to investigation / CAPA the point of the whole exercise ENFORCES ALCOA+ Attributable . Legible . Contemporaneous . Original . Accurate . Complete . Consistent . Enduring . Available REQUIRED OR EXPECTED UNDER FDA 21 CFR Part 11 (secure audit trails) . EU GMP Annex 11 (risk-based audit trails, regular review) MHRA GxP Data Integrity Guidance 2018 . ISPE GAMP Records and Data Integrity Guide
Click to enlarge

First, What an Audit Trail Is

You cannot review what you have not captured, so audit trail review depends on a properly built audit trail. In a GxP system, an audit trail is a secure, computer-generated, time-stamped record that captures actions affecting regulated data and configuration. A well-formed entry answers four questions:

  • Who performed the action, via a unique, attributable identity.
  • What changed - the field, the old value, and the new value.
  • When it happened, with a trustworthy timestamp.
  • Why, where a change is involved - a recorded reason.

Three properties make it trustworthy: it is automatic (the user cannot switch it off), secure (entries cannot be altered or deleted after the fact), and independent (it survives even if the underlying record is deleted). An audit trail that a user can pause or edit is not an audit trail; it is a suggestion.

The Regulatory Basis

Audit trail review sits at the intersection of several regulations and guidances, all pointing the same direction.

  • FDA 21 CFR Part 11 requires secure, computer-generated, time-stamped audit trails for electronic records in regulated activities, recording operator entries and actions that create, modify, or delete records.
  • EU GMP Annex 11 (Computerised Systems) calls for audit trails covering GMP-relevant changes and deletions, available in an intelligible form, and expects them to be reviewed on a risk basis - which is the explicit mandate for audit trail review.
  • MHRA GxP Data Integrity Guidance (2018) formalized the ALCOA+ principles (Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, Available) and describes routine audit trail review as an effective means of detecting integrity problems.
  • ISPE GAMP Guide on Records and Data Integrity gives practical guidance on distinguishing true audit-trail data from ordinary system logs and on designing a proportionate review.

The common thread: integrity is not assumed from the presence of a log. It is demonstrated by the act of reviewing it. This is the same discipline that underlies data integrity as a whole - a record must be trustworthy across its entire lifecycle, and a reviewed audit trail is the evidence that it is.

How Review Works in Practice

A workable audit trail review program answers a few practical questions before the first review is ever run:

  1. Which audit trails matter? Not every log is a GxP audit trail. The program identifies the records whose integrity affects product quality or patient safety and focuses effort there.
  2. How often, and how deeply? Frequency and depth follow a documented risk assessment. High-impact data (release-determining results) is reviewed before the decision it supports; lower-impact data may be reviewed on a schedule or by sampling.
  3. What is the reviewer looking for? Changes without a justification, results modified after the fact, repeated tests or reprocessing, activity at implausible times, and entries that contradict paper or shift records.
  4. What happens on a finding? A genuine anomaly routes into the quality system - investigation, and where warranted, corrective and preventive action (CAPA). A review that never produces a finding, over a long enough period, is itself a red flag about how it is being run.

The recurring failure mode is volume. Modern systems generate far too many entries to read line by line, so mature programs rely on the system to surface the entries that matter - exception-based review that flags changes to critical fields rather than asking a human to scroll through everything.

How Dawiso Fits

It is worth being precise here, because this is a regulated activity and overclaiming helps no one. Audit trail review is performed inside the validated GxP systems that hold the records - the LIMS, MES, chromatography data system, or QMS. Dawiso is not that system and does not perform Part 11 audit trail review. What Dawiso provides is the governed context around those systems that makes an integrity program easier to run and to evidence:

  • Traceability across the estate. The audit trail answers "who changed this record"; interactive lineage answers the complementary question - "where did this data come from and what does it feed" - across systems, which is the estate-level analog of the traceability that data integrity depends on.
  • An inventory of GxP-relevant systems and data. The data catalog documents which systems hold regulated data, who owns them, and how they are classified, so a data-integrity program knows where audit trails must exist in the first place.
  • Consistent definitions. The business glossary keeps terms like "batch," "result," and "critical data" defined the same way across teams, so reviews and investigations speak one language.

In short: the review is the regulated system's job; the surrounding governance, provenance, and inventory are where a platform like Dawiso earns its place in the program.

Conclusion

Audit trail review is the deceptively simple idea that a log of who changed what, when, and why is only worth having if someone qualified actually reads it - on a schedule, with a skeptical eye, and with a documented result. It is the control regulators lean on because it catches the integrity failures that pure logging misses, and it is anchored in ALCOA+ and codified across Part 11, Annex 11, and the MHRA guidance. The review itself belongs to the validated system that holds the records. The governance around it - traceability, a governed inventory of regulated systems, and consistent definitions - is what keeps the whole program coherent, and it is where a data governance platform contributes without pretending to be the regulated system.

Sources

See it in action

Interactive Data Lineage

Visualizing how data moves, transforms, and connects across systems, applications, and reports.

A cookie a day keeps bad UX away.

We use cookies to personalize content, ads and to analyze our traffic. We also share information about your use of our site with our advertising and analytics partners who may combine it with other information that you've provided to them or that they've collected from your use of their services. By clicking "Accept All", you allow us to use cookies for analytics and ads via Google Tag Manager. You can also customize cookies.

Customize Consent Preferences

We use cookies to personalize content, ads and to analyze our traffic. We also share information about your use of our site with our advertising and analytics partners. Privacy Policy

Necessary cookies allow core website functionality such as user login and account management. The website cannot be used properly without strictly necessary cookies.

Functionality cookies are used to remember visitor information on the website, eg. language, timezone, enhanced content.

Analytics cookies are used to see how visitors use the website, eg. analytics cookies. Those cookies cannot be used to directly identify a certain visitor.

We use Microsoft Clarity to see how you use our website (including heatmaps and session replays) so we can improve it. By using our site, you agree that we and Microsoft can collect and use this data. See our Privacy Policy for details.

Advertisement cookies are used to identify visitors between different websites, eg. content partners, banner networks. Those cookies may be used by companies to build a profile of visitor interests or show relevant ads on other websites.