An audit trail that nobody reads is worth nothing in an inspection, and regulators have said so in every guidance document since 2015. The difficulty is practical. A chromatography data system generates thousands of audit trail entries a week, and a review that reads all of them is impossible, so sites either do not review at all or export the whole thing and file it unread. Both are findings. This guide describes a review that is achievable and defensible.
What the regulations expect
Annex 11 section 9 says audit trails should be 'regularly reviewed'. EU GMP Chapter 6 requires the test record to carry the initials of the person who verified the testing and the calculations, and the EMA data integrity Q&A states that audit trails capturing changes to critical data should be reviewed with each record and before the record is approved, by the person who reviews the data. PIC/S PI 041-1 section 9.5 expects the review to be risk-based and to focus on the data that support decisions.
So the review is not a separate monthly ritual. For data that support a release decision, it is part of the data review, before certification, by the reviewer. A broader periodic review of the system, its configuration, its user list and its audit trail settings, is a second and different activity.
What to look for
The audit trail review is a search for events that could have changed a reported result. In a chromatography system there are perhaps eight event types that matter, and a good data system can filter for them. In a LIMS or an MES the list is similar in kind.
- Reprocessing: a result that was calculated more than once. Why, and what changed between the versions?
- Manual integration: baselines or peak boundaries set by hand. Justified by the method, or by the result?
- Aborted, incomplete or unprocessed injections and runs. Every one needs an explanation.
- Renamed samples, sequences or files, especially names like 'test', 'trial', 'SST' or 'demo' applied to a sample.
- Deleted data, of any kind. Deletion of raw data should not be possible for routine users, so any deletion is a serious event.
- Changes to methods, processing parameters or calculations between acquisition and reporting.
- Changes to audit trail settings, user privileges or the system clock.
- Time stamps that are out of sequence with the activity as recorded elsewhere.
How to document it
A review record needs to show what was reviewed, not just that a review happened. 'Audit trail reviewed, no issues, initials, date' is what most sites have and what inspectors decline to accept, because it cannot be distinguished from no review at all. The record should name the system, the data set or period, the filters or event types examined, the number of entries returned, each entry that needed an explanation and the explanation, and the reviewer. It can be a form, a LIMS workflow step, or a section of the analytical report.
Hybrid systems
A hybrid system is one where the record is partly electronic and partly paper. The commonest form is an instrument that generates electronic data, a printout that is signed as the reviewed result, and QA who look only at the paper. Hybrid systems are not prohibited. PIC/S PI 041-1 section 9.4 and the EMA data integrity Q&A accept them, but with a condition that sites routinely miss: the electronic file is the original record and must be retained, controlled and reviewed like any electronic record. The printout is a copy, and for dynamic data (chromatograms, spectra, anything that can be reprocessed) it cannot be a true copy, because it does not contain the processing history.
- Name, for each system, what the original record is. If it is electronic, the retention, backup, access and audit trail rules apply to it regardless of what is printed.
- The printout must carry enough information to identify the electronic original: file name, sequence, date and time, method version, user.
- Review of the printout does not replace review of the audit trail. Someone still has to look at the electronic record for the events above.
- Have a documented rationale for why the arrangement is hybrid and a plan to move to electronic review. Inspectors accept hybrid systems as a transition, not as a destination.
Where hybrid systems fail
Three patterns account for most findings. The electronic file is overwritten or deleted on a cycle shorter than the retention period, so the original is gone while the copy is filed. The printout is produced after reprocessing and shows only the final version, while the audit trail shows a failing first version nobody reviewed. And the system has a shared login, so the printout is attributed by initials but the electronic original is attributed to nobody. Each of these is discovered by an inspector who asks to see the electronic file behind a specific printout, which they always do.
Module 4 of the course gives you a real chromatography audit trail export with nine events in it and asks you to find them, explain them and write the review record. Then it does the same for a hybrid FTIR system, working from the printout back to the electronic original.