HomeQuality Guide

Audit Trail Review in Pharma: FDA, 21 CFR Part 11, HPLC/CDS & Data Integrity

 

Audit trail review in pharmaceutical quality control showing HPLC chromatography data system electronic records data integrity and GMP compliance

Published by: Pharma Quality System Editorial Team Editorial basis: FDA Data Integrity guidance, FDA Part 11 guidance, CGMP laboratory controls, Health Canada GUI-0050 and GUI-0001
DATA INTEGRITY • 21 CFR PART 11 • HPLC/CDS • FDA • HEALTH CANADA

Audit trail review is a key control for detecting unauthorized, unexplained or inappropriate changes to GMP electronic records. In pharmaceutical laboratories, it can reveal deleted injections, repeated analyses, altered integrations, method changes, sequence modifications and other events that may affect the reliability of reported results.

Quick answer

An audit trail is a secure computer-generated history that allows reconstruction of relevant electronic-record events. Audit trail review should be risk-based, documented and focused on GMP-relevant events. In HPLC/CDS environments, review should consider sequence changes, deleted or aborted injections, reintegration, reprocessing, method changes, user actions and other relevant metadata-not only the final chromatogram.

Important Part 11 nuance:
FDA's Part 11 Scope and Application guidance describes enforcement discretion for certain specific Part 11 audit-trail provisions, but Part 11 remains in effect and predicate-rule requirements for complete, reliable and accurate GMP records remain enforceable.

What Is an Audit Trail in Pharma?

An audit trail is a computer-generated record that helps reconstruct the sequence of events associated with an electronic record. Depending on system design, it can capture creation, modification, deletion, reprocessing, reintegration, configuration changes and user activities.

In a GMP environment, an audit trail should support traceability by identifying relevant details such as what changed, who performed the action, when it occurred and, where applicable, why the change was made.

Simple definition:
The audit trail is the electronic history behind the result-not merely the final result itself.

Why Audit Trail Review Matters in Pharmaceutical GMP

Electronic GMP record lifecycle showing data creation acquisition processing review approval retention retrieval and audit trail traceability

A final passing analytical result does not tell the full story. A reviewer may need to determine whether earlier injections were deleted or ignored, a sample was reinjected after an unfavorable result, integration parameters were changed, a method or sequence was modified, files were deleted, or data were reprocessed without documented scientific justification.

FDA requires CGMP records to be complete and subject to appropriate review. Recent warning letters continue to show that failure to review raw analytical data and audit trails can undermine batch-release, stability and other quality decisions.

21 CFR Part 11, Audit Trails and Predicate Rules

21 CFR Part 11 and FDA predicate rules relationship for electronic records audit trails access controls data integrity and GMP record review

21 CFR Part 11 applies to certain electronic records and electronic signatures used to satisfy FDA record requirements. FDA's Scope and Application guidance explains that Part 11 is interpreted narrowly and that the Agency exercises enforcement discretion for certain specified Part 11 provisions, including some audit-trail requirements.

This does not mean audit trails are irrelevant. Underlying predicate rules for complete laboratory data, controlled computerized systems and adequate review remain enforceable. FDA recommends risk-based audit trails or other controls where needed to ensure trustworthy and reliable records.

HPLC and Chromatography Data System (CDS) Audit Trail Review

HPLC chromatography data system audit trail review showing sequence changes injections deleted injections reprocessing integration method changes and user actions

Chromatography is a high-risk data-integrity area because one run can generate many layers of electronic information beyond the printed chromatogram. Relevant records can include:

  • sample-set or sequence creation and modification
  • sample identifiers and vial positions
  • injection history, aborted runs and reinjections
  • acquisition and processing methods
  • manual integration and reprocessing history
  • result changes and calculation changes
  • deleted files or projects
  • user-login and administrator actions

Audit trail review should therefore be integrated with review of raw data, chromatograms, methods, calculations and metadata.

What Should Be Reviewed in an Audit Trail?

EventReviewer Question
Deleted injection / fileWhy was it deleted? Was original data preserved and the event assessed?
ReinjectionWas reinjection scientifically justified and allowed by procedure?
Manual integrationWas it justified, consistent, traceable and reviewed?
Method / sequence changeWas the approved method altered or the sample sequence changed?
ReprocessingWhat triggered it, and are original/reprocessed results retained?
User / privilege changeWas it authorized and consistent with assigned responsibilities?

How Often Should Audit Trails Be Reviewed?

There is no single review frequency that applies to every computerized system. The frequency should be based on GMP relevance, data criticality, risk, system use and timing of the quality decision.

For analytical electronic records supporting release or stability decisions, relevant audit-trail review is commonly incorporated into the associated data review before the quality decision is finalized. Health Canada Annex 11 states that GMP-relevant audit trails should be available in intelligible form and regularly reviewed.

Manual Integration, Reintegration and Reprocessing

HPLC manual integration and audit trail review comparing automatic integration scientifically justified manual integration reviewer approval and data traceability

Manual integration is not automatically prohibited, but uncontrolled or result-driven integration is a major data-integrity risk. A compliant procedure should define when it is justified, who may perform it, how reasons are documented, how original and modified integrations remain traceable, and what level of independent review is required.

Red flag:
Repeatedly reintegrating a peak until a passing result appears-without a predefined scientific basis-is not acceptable data handling.

User Access and Administrator Controls

Analysts should not have unnecessary privileges that allow them to change configurations, delete records or disable controls protecting GMP data. Health Canada GUI-0001 requires user rights to be controlled, while GUI-0050 expects creation, change and cancellation of access authorizations to be recorded.

FDA warning letters have likewise cited analytical systems where users had administrator rights enabling file modification or deletion.

Practical Audit Trail Review Checklist

Pharmaceutical audit trail review checklist covering record identity injections sequence history processing integration method changes user actions metadata and documentation

  1. Confirm record identity: batch, sample, test, system and analyst.
  2. Review injections / runs: identify missing, aborted, deleted or repeated analyses.
  3. Review sequence history: additions, removals, renaming, vial-position changes and reordering.
  4. Review processing history: reprocessing, recalculation and result changes.
  5. Review integration events: automatic versus manual integration and integration-parameter changes.
  6. Review method changes: acquisition or processing method modifications.
  7. Review user actions: analyst, supervisor and administrator activities relevant to the record.
  8. Verify reasons: where a reason for change is required, confirm it is meaningful and scientifically appropriate.
  9. Compare records: chromatograms, worksheets, logbooks, sample sequences, OOS and deviation records.
  10. Document the review: reviewer identity, date, scope, observations and follow-up actions.

Common Audit Trail Red Flags

Red FlagWhy It Matters
Repeated injections without investigationMay indicate trial testing or selective reporting.
Deleted injections / projectsCan obscure unfavorable or original data.
Multiple manual integrationsCan signal result-driven manipulation when not controlled.
Analysts with administrator accessCreates unnecessary ability to modify or delete GMP data.
Audit trail disabled or unavailableLimits ability to reconstruct GMP-relevant electronic events.
Unexplained date/time inconsistenciesMay compromise contemporaneousness and traceability.

FDA vs Health Canada Audit Trail Expectations

United States - FDACanada - Health Canada
Electronic GMP records must satisfy applicable predicate rules and relevant Part 11 controls.GUI-0001 expects electronic records to be tracked through audit trails when created or modified.
All laboratory data, including failing, suspect and passing data, must be retained and reviewed.Audit trails should identify the change, user, date/time and, where applicable, reason for modification.
Warning letters evaluate raw data, injections, integrations, deletion capability and administrator access.GUI-0050 says GMP-relevant audit trails should be available in intelligible form and regularly reviewed.
Part 11 guidance supports a documented risk-based approach.Risk management should determine the extent of validation and data-integrity controls.

Recent FDA Warning Letter Lessons

Ava Inc. - April 2026: FDA cited trial HPLC injections, incomplete records and failure of the Quality Unit to establish an adequate written procedure to review audit trails and raw analytical data for data reliability.

Laboratorios Jaloma - May 2026: FDA cited GC software that was not adequately validated, audit trails that were not enabled, inaccurate file dates and missing electronic raw data.

Wisconsin Pharmacal - August 2025: FDA cited failure to review LC/GC audit trails and raw analytical data and insufficient control of administrator privileges for file modification and deletion.

These cases show that audit trail review is not merely an IT responsibility. It is a Quality Unit, laboratory and data-governance responsibility connected directly to product-release and stability decisions.

What Should an Audit Trail Review SOP Include?

  • systems and records within scope
  • risk classification and review frequency
  • roles, responsibilities and reviewer independence
  • which audit-trail views/reports must be reviewed
  • events considered critical or suspicious
  • documentation requirements
  • handling of unexplained changes
  • linkage to deviation, OOS and CAPA processes
  • escalation to QA / Quality Unit
  • periodic effectiveness review

Common Audit Trail Review Mistakes

  • Reviewing only the final PDF chromatogram.
  • Ignoring data-specific audit trails while checking only system logs.
  • Checking that a reason exists without judging whether it is scientifically meaningful.
  • Ignoring aborted, deleted or unprocessed injections.
  • Failing to connect audit-trail observations to OOS, deviation or CAPA systems.
  • Using administrator accounts for routine laboratory work.
  • Assuming Part 11 enforcement discretion means audit trails are unnecessary.

Audit Trail Review Interview Questions

What is an audit trail?

A secure computer-generated history that allows reconstruction of relevant events involving an electronic record.

What would you review in an HPLC audit trail?

Sequence changes, injections, reinjections, deletions, reprocessing, integration changes, method changes, user actions and other GMP-relevant events.

Is manual integration prohibited?

No, but it must be scientifically justified, controlled, traceable and appropriately reviewed.

Who should review audit trails?

Qualified personnel with sufficient independence, system knowledge and authority to evaluate GMP-relevant changes according to the approved procedure.

Frequently Asked Questions

Is audit trail review required by FDA?

FDA expects firms to maintain complete, reliable and trustworthy GMP records and has repeatedly cited inadequate audit-trail review in inspections and warning letters. The exact control strategy should reflect applicable predicate rules, Part 11 scope and documented risk.

Does every audit trail event require investigation?

No. Normal and authorized activity does not automatically require investigation. Reviewers should identify events that are unexplained, unauthorized, inconsistent with procedure or potentially significant to product quality or data integrity.

Should audit trails be reviewed before batch release?

For critical electronic analytical records supporting release decisions, relevant audit-trail review is commonly incorporated into the data-review process before the associated quality decision is finalized. Scope and timing should be risk-based and proceduralized.

Can an audit trail be turned off?

For GMP-relevant systems, disabling an available audit trail without justified compensating controls creates a serious data-integrity risk. Health Canada Annex 11 expects consideration of system-generated audit trails for GMP-relevant changes and deletions based on risk.

What is the difference between an audit trail and an activity log?

An audit trail is intended to reconstruct relevant changes to regulated records. An activity or system log may capture broader operational or security events. Terminology and capabilities depend on system design.

Related Pharma Quality Guides

Official and Authoritative Sources

Key takeaway
Audit trail review is not about checking whether an audit trail exists. It is about using the electronic history to determine whether GMP data remain complete, traceable, scientifically justified and trustworthy throughout the record lifecycle.


Comments

Popular posts from this blog

OOS in Pharmaceutical Industry: Investigation, Phase I & II, Examples

CAPA in Pharmaceutical Industry: Process, Examples & Root Cause Analysis

Data Integrity in Pharmaceutical Industry: ALCOA+ Principles, FDA Guidance & Examples