[{"data":1,"prerenderedAt":213},["ShallowReactive",2],{"\u002Fblog\u002Fgmp-audit-trail-review-checks":3},{"id":4,"title":5,"author":6,"body":7,"category":194,"date":195,"description":196,"draft":197,"excerpt":198,"extension":199,"heroImage":198,"heroImageAlt":198,"meta":200,"navigation":201,"path":202,"seo":203,"slug":204,"stem":205,"tags":206,"__hash__":212},"blog\u002Fblog\u002Fgmp-audit-trail-review-checks.md","Audit-Trail Review in GMP: What Should the Reviewer Actually Look For?","QikSolve",{"type":8,"value":9,"toc":177},"minimark",[10,14,17,22,25,28,31,35,38,73,76,80,85,88,92,95,99,102,106,109,113,116,120,123,126,129,133,136,153,156,160,163],[11,12,13],"p",{},"A GMP reviewer who is handed an audit trail has a different job from someone confirming that one\nexists. The reviewer's question is not \"is there a log?\" but \"does this history let me understand\nwhat happened to this record, and do I accept the explanation?\"",[11,15,16],{},"This article offers practical reviewer checks. It is not a validation protocol, a complete\nregulatory checklist, or a determination that any particular system or process is compliant. Your\norganisation's own risk assessment, approved procedures, and quality system should guide how you\napply them, subject to the requirements that apply to you.",[18,19,21],"h2",{"id":20},"existence-is-not-review","Existence is not review",[11,23,24],{},"An audit trail is a record of actions taken on an electronic record, and when. Whether it also shows\nwho acted, and shows it reliably, is something a reviewer should verify rather than assume. Its\nvalue depends on someone looking at it with a clear question in mind.",[11,26,27],{},"In the United States, 21 CFR 11.10(e) describes secure, computer-generated, time-stamped audit\ntrails that record operator entries and actions that create, modify, or delete electronic records.\nIt also says record changes must not obscure previously recorded information. Section 11.10 sets out\ncontrols for closed systems, and whether Part 11 applies to a given record depends on the\ncircumstances, so that determination needs to be made rather than assumed.",[11,29,30],{},"That wording is about the audit trail's characteristics. It does not tell a reviewer how to read\none. That part is practice, and the checks below are suggested practice, not regulatory text.",[18,32,34],{"id":33},"start-with-scope","Start with scope",[11,36,37],{},"Before opening the audit trail, decide what you are reviewing and why:",[39,40,41,49,55,61,67],"ul",{},[42,43,44,48],"li",{},[45,46,47],"strong",{},"System and record:"," which record or record type is under review?",[42,50,51,54],{},[45,52,53],{},"Review period:"," which events fall within the review?",[42,56,57,60],{},[45,58,59],{},"Relevant events:"," creation, modification, deletion, status changes, approvals?",[42,62,63,66],{},[45,64,65],{},"Risk:"," how much would an undetected change matter to product quality or patient safety?",[42,68,69,72],{},[45,70,71],{},"Responsible role:"," who performs the review, and is that person independent of the work being\nreviewed where your procedure requires it?",[11,74,75],{},"Your approved procedure should define the review frequency and depth. This article does not state a\nuniversal frequency, because the sources checked for it do not establish one.",[18,77,79],{"id":78},"practical-reviewer-checks","Practical reviewer checks",[81,82,84],"h3",{"id":83},"_1-attribution-and-authorisation","1. Attribution and authorisation",[11,86,87],{},"Can each action be tied to an identifiable person? Was that person authorised to perform that action\non that record at that time? Access limits and authority checks sit in the same section of 21 CFR\n11.10, and a reviewer can reasonably use them as context. Shared logins or unexplained generic\naccounts are worth escalating.",[81,89,91],{"id":90},"_2-changes-and-deletions-with-preserved-history","2. Changes and deletions with preserved history",[11,93,94],{},"Where a value changed, can you see the earlier value as well as the new one? A change that hides\nwhat was there before leaves the reviewer unable to judge it. Deletions deserve particular\nattention: what was removed, by whom, and why?",[81,96,98],{"id":97},"_3-timestamps-and-event-sequence","3. Timestamps and event sequence",[11,100,101],{},"Do the times make sense together? An approval stamped before the entry it approves, or edits\nclustered just after a deadline, may have a simple explanation. The reviewer's job is to notice the\npattern and ask.",[81,103,105],{"id":104},"_4-stated-reasons-and-supporting-context","4. Stated reasons and supporting context",[11,107,108],{},"Is there a reason for the change, and does it match what the surrounding records show? A reason such\nas \"updated\" says little. A reason that points to a deviation, an investigation, or a documented\ncorrection gives the reviewer something to verify.",[81,110,112],{"id":111},"_5-unusual-patterns-that-need-an-explanation","5. Unusual patterns that need an explanation",[11,114,115],{},"Repeated edits to the same field, activity outside normal working patterns, or many corrections by\none person are prompts for a question, not conclusions. Avoid deciding what a pattern means before\nyou have asked.",[18,117,119],{"id":118},"a-fictional-example","A fictional example",[11,121,122],{},"Imagine a reviewer examining a batch-related electronic record. The audit trail shows a result\nchanged from one value to another by a named, authorised analyst. The original value is still\nvisible. The stated reason refers to a transcription error and cites a documented correction in the\nlaboratory notebook, which the reviewer can see.",[11,124,125],{},"Now imagine a second entry on a different record. The result changed, the original value is visible,\nbut the reason reads only \"correction\" and no supporting record can be found.",[11,127,128],{},"Both entries show a change. The first has an explanation the reviewer can verify. The second has an\nunresolved gap. That does not mean something improper happened, and the reviewer should not assume\nit did. It means the review is not finished until someone with the right knowledge explains the\nentry.",[18,130,132],{"id":131},"record-what-the-review-concluded","Record what the review concluded",[11,134,135],{},"A review that leaves no trace is hard to defend later. Consider recording:",[39,137,138,141,144,147,150],{},[42,139,140],{},"the system, record scope, and review period;",[42,142,143],{},"what was examined and how;",[42,145,146],{},"observations, including those that were explained and those that were not;",[42,148,149],{},"the rationale for the reviewer's conclusion;",[42,151,152],{},"any follow-up or escalation, and who owns the next decision.",[11,154,155],{},"These are proposed practice aids. They do not replace your procedure, and completing them does not\nguarantee compliance or inspection outcomes.",[18,157,159],{"id":158},"from-one-review-to-ongoing-control","From one review to ongoing control",[11,161,162],{},"A single review tells you about one period. The real question for a quality system is whether this\nkind of review happens consistently, produces decisions, and drives follow-up. That is the\ndifference between point-in-time confidence and ongoing control.",[11,164,165,166,171,172,176],{},"To explore that idea further, see\n",[167,168,170],"a",{"href":169},"\u002Fproduct\u002Fongoing-control-beyond-validation","ongoing control beyond validation",". For the wider\npicture of how connected quality processes fit together, see the\n",[167,173,175],{"href":174},"\u002Fproduct\u002Fquality-systems","quality systems overview",".",{"title":178,"searchDepth":179,"depth":179,"links":180},"",2,[181,182,183,191,192,193],{"id":20,"depth":179,"text":21},{"id":33,"depth":179,"text":34},{"id":78,"depth":179,"text":79,"children":184},[185,187,188,189,190],{"id":83,"depth":186,"text":84},3,{"id":90,"depth":186,"text":91},{"id":97,"depth":186,"text":98},{"id":104,"depth":186,"text":105},{"id":111,"depth":186,"text":112},{"id":118,"depth":179,"text":119},{"id":131,"depth":179,"text":132},{"id":158,"depth":179,"text":159},"GMP","2026-10-08","Having an audit trail is not the same as reviewing it. A practical look at the checks a GMP reviewer can apply to audit-trail evidence, and how to record what the review concluded.",false,null,"md",{},true,"\u002Fblog\u002Fgmp-audit-trail-review-checks",{"title":5,"description":196},"gmp-audit-trail-review-checks","blog\u002Fgmp-audit-trail-review-checks",[207,208,209,210,211],"audit-trail-review","gmp","data-integrity","electronic-records","ongoing-control","_kLumorpxRjxlJr2WycZEkkBTkJSySi4OhwluAbusMk",1791470689061]