Skip to content

Audit Trail

What is Audit Trail?

A chronological record of system activities that enables the reconstruction and examination of events. Essential for forensic analysis and regulatory compliance.

Audit

What the standards actually require on audit trail

Requirements naming audit trail across 6 standards, quoted from the control text.

Section 11.10(e) audit trail requirement: USE OF SECURE + COMPUTER-GENERATED + TIME-STAMPED AUDIT TRAILS to independently record the date and time of operator entries and actions that create + modify + or delete electronic records.

Part11.AuditTrail · Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
IEEE 16863 controls

Section 5.2 establishes audit trail records requirements for IEDs. Per public IEEE 1686 abstract + vendor capability statements (full IEEE text NOT reproduced): audit trail of security-relevant events including authentication + authorization + configuration ch...

IEEE1686-Section5.2-5.3-AuditLog-Retention-Export-Monitoring · IEEE 1686 Section 5.2 + 5.3 - Audit Trail Records + Retention + Export + Supervisory Monitoring and Control + Network Security Monitoring

Human Oversight is mandated by the Human-Centric Principle (1st of 10 Principles) per Japan AI Guidelines for Business + reinforced by APPI 2022 Amendment Article 21-2 right to human review + intersects with Hiroshima AI Process Code of Conduct.

JP-AIG-Human-Oversight-Control-In-the-Loop-On-the-Loop-Article-22-GDPR-Equivalent-Automated-Decision-Restrictions · Japan AI Guidelines Human Oversight + Human-in-the-Loop + Human-on-the-Loop + Human-out-of-Loop + Article 22 GDPR Equivalent APPI Automated Decision Restrictions + Override Capability + Pause Functionality + Audit Trail

Section 820.35 establishes FDA-specific record-control requirements that supplement ISO 13485:2016 Section 4.2.5. SPECIFIC REQUIREMENTS: (a) RECORD RETENTION - records must be retained for a period of time equivalent to the design + expected life of the device...

QMSR-820.35 · Control of records - record retention, audit trail, UDI, medical-device reporting (§820.35)

ICH E6(R3) Annex 1 (Computer Systems Used in Clinical Trials) is the new section consolidating data integrity + electronic systems + computer system validation (CSV) - replacing scattered E6(R2) provisions.

ICH-E6-Annex1-ElectronicSystems-CSV-eSig-Audit-ALCOA-DataIntegrity · ICH E6(R3) Annex 1 - Computer Systems + Computer System Validation (CSV) + Electronic Signature + Audit Trail + ALCOA+ Data Integrity

Time-stamped audit trail records of all GMP-relevant changes and deletions must be maintained with documented reasons.

Clause 9 · Audit trails

Questions people ask about audit trail

What is Audit Trail?
A chronological record of system activities that enables the reconstruction and examination of events. Essential for forensic analysis and regulatory compliance.
Why is Audit Trail important for compliance?
Audit Trail is a key concept in Audit. Understanding audit trail helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Audit Trail?
Key concepts related to Audit Trail include SIEM (Security Information and Event Management). Understanding these interconnected concepts provides a more comprehensive view of Audit requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Audit Trail?
Audit Trail appears in the requirement text of FDA 21 CFR Part 11, IEEE 1686, Japan AI Guidelines, FDA Quality Management System Regulation (QMSR), ICH E6(R3) - Good Clinical Practice. Across these standards we have identified 14 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Audit Trail?
Explore our compliance framework pages to see how audit trail applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Audit Trail applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.