GMP & GDP Audits · 7 min read
Audit Trail Review: A Practical Guide for GMP Systems
A practical, risk-based guide to audit trail review for GMP systems, aligned to Annex 11, MHRA data integrity guidance and ALCOA+ for UK and EU teams.
By Balasubramanian Ramaiah · 9 June 2026 · Updated 11 August 2026

An audit trail review is one of the most revealing checks in any GMP inspection: it shows not just what a system recorded, but whether anyone was paying attention to what it recorded. Done well, it confirms that your electronic records are trustworthy and that data integrity controls are working as intended. Done poorly — or not at all — it becomes one of the most common findings cited against UK and EU manufacturers and importers.

Why audit trail review matters under EU GMP and MHRA expectations
An audit trail is the secure, computer-generated record that captures who did what, when, and — where relevant — why a GMP-significant action took place. EU GMP Annex 11 requires audit trails for changes and deletions of GMP-relevant data, and the MHRA's data integrity guidance is explicit that generating an audit trail is not enough on its own: it must actually be reviewed. Regulators increasingly treat the absence of meaningful review as equivalent to having no control at all.
This expectation sits directly on top of the ALCOA+ principles. Data must be Attributable, Legible, Contemporaneous, Original and Accurate, with the "plus" extending to Complete, Consistent, Enduring and Available. A robust audit trail review is the mechanism by which you demonstrate, on an ongoing basis, that those attributes hold true for the records your batch decisions depend upon.
What a meaningful audit trail review actually covers
The purpose is to detect events that may signal data integrity weaknesses, errors, or — at the serious end — falsification. A reviewer is not re-checking every keystroke; they are looking for the events that carry quality risk. Typical focus areas include:
- Changes to, or deletions of, original results, sequences or processing methods.
- Reprocessing, reintegration or reanalysis of analytical data, and the documented justification for it.
- Aborted, repeated or "trial" injections and test runs.
- Changes to system clocks, date/time settings or critical configuration.
- Manual overrides of automated steps, out-of-sequence activities, or actions performed under a shared or generic login.
- Modifications to user privileges, audit trail settings, or the audit trail's own status (for example, being switched off).
The discipline is to distinguish the routine from the GMP-significant. A mature procedure defines, per system, which event types are critical and therefore warrant scrutiny — so reviewers spend their time where the risk genuinely lies rather than drowning in benign entries.
A practical, risk-based approach to audit trail review
ICH Q9 expects quality risk management to drive the depth and frequency of GMP controls, and audit trail review is no exception. A proportionate programme generally follows a clear sequence.
1. Inventory and classify your systems
List every computerised system that creates, modifies or stores GMP data — from chromatography data systems and LIMS to MES, ERP and building management systems. Classify each by data integrity risk, considering criticality of the data, complexity, and the strength of existing technical controls.
2. Define what, who and how often
For each system, specify which audit trail events are reviewed, by whom, and at what frequency. Higher-risk activities — analytical results supporting batch release, for instance — typically warrant review before the associated decision is taken, ideally as part of the second-person check of the original record rather than as a separate, after-the-fact exercise.
3. Make the review independent and competent
The person reviewing should be independent of the person who generated the data and should understand both the process and the system well enough to recognise an anomaly. Reviewing your own audit trail offers little assurance.
4. Document, escalate and act
Record that the review took place, what was examined, and the outcome. Anomalies must be escalated through deviation, CAPA and — where integrity is in question — a formal data integrity investigation, consistent with your ICH Q10 pharmaceutical quality system. A review that never produces a finding often signals that it is not being performed with genuine rigour.
Common pitfalls that draw inspector attention
Most audit trail review deficiencies fall into a handful of recurring patterns. Recognising them early is far cheaper than addressing them in an inspection response.
- Review in name only. A signature confirming "audit trail reviewed" with no defined scope, no evidence of what was examined, and no findings over many months.
- Technically incapable systems. Legacy equipment that cannot generate a secure, time-stamped audit trail, or where the function can be disabled by ordinary users — a long-standing concern echoed in 21 CFR Part 11 expectations as well as EU GMP.
- Shared logins. Generic accounts that make actions non-attributable, undermining the first principle of ALCOA+.
- Reviewing the wrong layer. Checking application-level entries while ignoring database-level or operating-system changes where data could be altered or deleted unseen.
- No link to decisions. Audit trail review divorced from the point at which the data is actually used, so problems surface only after release.
If the audit trail is not reviewed, the organisation has, in effect, decided not to look for the very problems the system was designed to catch.
Building audit trail review into your quality system
Sustainable compliance comes from designing review into business-as-usual rather than treating it as a periodic chore. Embed it in your data governance framework: define roles and accountability, train reviewers on what "good" and "suspicious" look like, and use periodic self-inspection to confirm the programme is working. Where you operate under contract — as a CMO, importer or distributor — make audit trail review responsibilities explicit in the quality and technical agreements, so there is no ambiguity about who reviews what. The same logic extends across the supply chain, where GDP expectations for traceability and record control apply to distribution data as firmly as GMP does to manufacturing.
Many teams find that a focused, independent review of their approach pays for itself, surfacing gaps before an inspector does. Our GMP audit services include a pragmatic assessment of computerised system controls and audit trail review practices, and you can see how we have supported comparable organisations in our case studies. For the wider picture of how this connects to QMS design, contract QP support and supplier oversight, explore our full range of consultancy services.
Key takeaways
A credible audit trail review programme is risk-based, independent, documented and tied to the moment a decision is made — not a retrospective signature exercise. Anchor it in Annex 11, MHRA data integrity guidance and ALCOA+, drive its depth with ICH Q9, and govern it through your ICH Q10 quality system. Above all, treat findings as evidence the control is working, not as a problem to be hidden.
If you would like an experienced QP to assess how your audit trail review stands up to current MHRA expectations, get in touch with our team to arrange a confidential discussion.
Regulatory sources
This guidance reflects current UK and EU GMP/GDP requirements. Primary references:
- EU GMP Annex 11 — Computerised Systems
- EudraLex Volume 4 — EU GMP Guidelines
- EU GMP Chapter 9 — Self Inspection
- MHRA Inspectorate Blog
Always confirm against the latest published version of each source.
Frequently asked questions
How often should audit trails be reviewed?+
Frequency should be driven by risk under ICH Q9 rather than a fixed calendar. For high-risk, GMP-critical data such as analytical results supporting batch release, the audit trail is best reviewed before the associated decision is made, ideally as part of the second-person review of the original record. Lower-risk system events may be reviewed on a defined periodic basis, provided the rationale is documented.
Who should perform an audit trail review?+
The reviewer should be independent of the person who generated the data and competent in both the process and the computerised system. This independence is essential, as reviewing your own audit trail provides little genuine assurance. They must understand the system well enough to recognise anomalies such as reprocessing, deletions or out-of-sequence activity, and escalate them through your deviation and CAPA process.
What is the difference between an audit trail and an audit trail review?+
An audit trail is the secure, computer-generated record of who did what and when within a system. An audit trail review is the active human evaluation of that record to detect errors, integrity weaknesses or falsification. The MHRA is clear that simply generating an audit trail is not sufficient; without meaningful review, regulators may treat the control as effectively absent.