<img src="https://secure.office-information-24.com/785669.png" style="display:none;">
Glossary Document & Records Control

Audit Trail

Also called: System Audit Log
An audit trail is a secure, computer-generated, time-stamped record that documents the creation, modification and deletion of electronic records, capturing who made a change, what was changed, and when it occurred. Required under FDA 21 CFR Part 11 for regulated electronic records, an audit trail must never obscure or overwrite previously recorded information, preserving a complete, transparent history of every action even when records are later updated or corrected. 

Quick facts

Category Chronological, tamper-evident record of system changes
Used by Pharmaceuticals, medical devices, biotechnology, and other FDA-regulated industries
Also called None widely standardized
Related standards FDA 21 CFR Part 11, ALCOA+
Related processes Electronic signature, data integrity, timeline traceability, document control
Semantic match audit trail, FDA 21 CFR Part 11 audit trail, data integrity log, electronic record history

What is Audit Trail?

An audit trail automatically logs every meaningful action taken on an electronic record, capturing the original value, the changed value, who made the change, when it occurred, and often the reason for the change, without requiring manual documentation by the user.

A defining principle of a compliant audit trail is that it must never obscure previously recorded information. Even when a record is corrected or updated, the audit trail preserves the complete history, showing both the original and the corrected values rather than simply replacing one with the other.

Audit trails are foundational to data integrity, supporting the ALCOA+ principles regulators use to evaluate electronic record trustworthiness: that data be attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring and available.

Why is Audit Trail important?

A complete audit trail gives organizations and regulators confidence that electronic records have not been altered without a documented, attributable history, directly protecting data integrity.

Audit trails simplify source data verification during regulatory inspections, since inspectors can quickly confirm what changed, who changed it, and why, without needing to reconstruct the history from separate, disconnected sources.

Because shared user logins undermine attribution and are frequently cited during FDA inspections, enforcing unique user IDs and thorough audit trail practices is essential to meeting both the letter and intent of audit trail requirements.

How does Audit Trail work?

A typical audit trail implementation includes:

  1. Automatic logging. Capture every creation, modification and deletion of a record without manual entry.
  2. Timestamping. Record the precise date and time of each action.
  3. User attribution. Link each action to a unique, identifiable user, avoiding shared logins.
  4. Change preservation. Retain both original and changed values rather than overwriting history.
  5. Security. Protect the audit trail itself from unauthorized alteration or deletion.
  6. Review. Periodically review audit trail data as part of quality oversight and inspection readiness.

Audit Trail vs. Timeline Traceability

Comparison Audit Trail Timeline Traceability
Nature The underlying logged record of changes Chronological, visual presentation of events
Scope Typically tied to a single record or system Often combines multiple related records

Real-world examples of Audit Trail

A pharmaceutical manufacturer's electronic batch record system automatically logs every data entry and correction, preserving both the original and corrected values for full transparency.

An FDA inspector reviews a company's audit trail during an inspection, confirming that a specific data correction was made by an identifiable user with a documented reason.

A quality team investigates a data integrity concern, using the audit trail to reconstruct exactly when a record was created, who accessed it, and what changes were made over time.

Regulations and standards related to Audit Trail

FDA 21 CFR Part 11 requires secure, computer-generated audit trails for regulated electronic records, documenting record creation, modification and deletion to support data integrity and traceability.

Audit trails also underpin the ALCOA+ data integrity framework, attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring and available, which regulators including FDA and international agencies use to evaluate the trustworthiness of electronic records.

Required by

How QT9 helps with Audit Trail

QT9 QMS and ERP audit trail capabilities

  • Automatically store a time-stamped audit trail of every transaction.
  • Enforce unique user logins and role-based access controls.
  • Preserve complete change history without obscuring original values.
  • Support FDA 21 CFR Part 11-compliant electronic records and signatures.
  • Provide instant, searchable access to audit trail data during inspections.
  • Connect audit trail data with timeline traceability for complete visibility.

Request a QMS Demo Explore FDA 21 CFR Part 11 Compliance →

See QT9 Software in Action

Discover how QT9 Software helps manufacturers improve efficiency, strengthen compliance and connect quality management and ERP processes within one integrated platform.

Common mistakes with Audit Trail

Common mistakes include allowing shared user logins, which undermines attribution and is a frequently cited finding during FDA inspections.

Other problems include implementing systems that overwrite prior values instead of preserving a complete history, violating the core principle that an audit trail must never obscure previously recorded information.

Frequently asked questions

An audit trail must capture the creation, modification and deletion of electronic records, including original and changed values, who made the change, and when it occurred.
No. A compliant audit trail must never obscure previously recorded information, and the audit trail itself must be protected from unauthorized alteration or deletion to maintain its integrity as evidence.
Shared logins make it impossible to attribute a specific action to a specific individual, undermining the audit trail's core purpose and are frequently cited as a finding during FDA inspections.
ALCOA+ is a data integrity framework, standing for Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring and Available, and a well-maintained audit trail directly supports most of these principles.
Many regulated systems require capturing a reason for significant changes or corrections, in addition to who made the change and when, to provide full context during a review or inspection.
Audit trail records should generally be retained for as long as the underlying records themselves, since deleting audit trail history would undermine the ability to demonstrate a complete, traceable record history.

Related terms

Related content

Ready to Transform Your Business?

See how QT9 Software helps manufacturers simplify operations, improve traceability and drive continuous improvement with integrated quality management and ERP software.

Last reviewed: July 21, 2026