From a recent ICH E6(R3) inspection
"I was asked directly: 'Can you show me your documented process for periodic audit trail review — and produce a signed review report?' The question wasn't whether the audit trail existed. It was whether we had systematically reviewed it. This is the gap that catches even experienced CDM teams."
— Sarah Huntley, 25+ years CDM experience
The regulatory basis: two overlapping requirements
Audit trail requirements for clinical trials come from two primary sources that, together, define what every CDM team must have in place.
21 CFR Part 11.10(e) requires computer-generated, time-stamped audit trails for any computerised system that creates, modifies, or deletes electronic records that are required to be maintained. The audit trail must record the date and time of any operator entry or action that creates, modifies, or deletes the record — and must be available for review and copying by authorised FDA representatives.
ICH E6(R3) §4.2.2 goes further. It requires that relevant metadata — including audit trail data — be preserved as part of the trial record. More specifically, it requires that the source data cannot be altered without a full record of the change, and that the original entry is preserved. E6(R3) Annex 1 further specifies that audit trails must include the date and time in a format that resolves ambiguity across time zones.
The practical implication: UTC timestamps are now the expected standard for audit trails in global multi-site studies.
Configuration requirements your SOP must specify
The first function of an audit trail SOP is to document what a correctly configured audit trail looks like — so that every system in use can be verified against it. At minimum, your SOP should specify that audit trails must capture:
- The user identity of the person making the change
- The date and time of the change (in UTC for global trials)
- The original value before the change
- The new value after the change
- A mandatory reason-for-change for any modification to a previously entered value
The SOP should also specify — explicitly — that audit trails must never be disabled on any GxP-critical system. This sounds obvious. It is still one of the most common audit trail findings at FDA inspection, because shared service accounts, temporary configurations, and EDC system upgrades can inadvertently disable audit trail functionality for periods that are only discovered during audit.
Periodic review — the most commonly missing element
Configuring an audit trail correctly is the baseline. What ICH E6(R3) and 21 CFR Part 11 inspectors are now asking for — and what most CDM SOPs do not yet address — is evidence of periodic review.
A periodic audit trail review is a structured, documented examination of the audit trail records for a defined period. It is not a passive check that the audit trail is turned on. It involves actively reviewing the records for anomalies: patterns of data deletion, unusual correction volumes at specific sites, corrections made after database lock, corrections made without a reason-for-change, or multiple corrections to the same data field.
Your SOP must specify:
- The frequency of periodic review (quarterly is the expected standard for active studies)
- What the review covers — which systems, which data fields, which sites, and what anomaly patterns are examined
- Who conducts and who approves the review
- The format of the review report — and the requirement for a signed, dated report documenting what was reviewed, what was found, and what action was taken
That signed quarterly report is what inspectors ask to see. Producing a report that says "reviewed — no issues" is not sufficient. A credible review report documents what specifically was checked, any anomalies identified, and the resolution of those anomalies. If no anomalies are found, the report should state what was examined and why no action was required.
Anomaly investigation — what the SOP must define
When a periodic audit trail review identifies an anomaly — an unexpected pattern of data corrections, a record of changes made by an inactive user account, a gap in the audit trail timestamp sequence — the SOP must define what happens next.
The investigation procedure should specify: who is notified, within what timeframe, what the investigation involves, how it is documented, and what the escalation path is if the anomaly indicates a potential data integrity issue. An uninvestigated anomaly in the audit trail is a data integrity finding. An anomaly that was identified and fully investigated — even if the root cause was benign — demonstrates a functioning quality system.
Retention requirements
Audit trail records are subject to the same retention requirements as the clinical records they govern. For FDA-regulated studies, this means 2 years following the date on which the sponsor receives marketing approval, or following discontinuation of the IND. For EMA-regulated studies, the EU requirement of 25 years applies to audit trail records as it does to all essential documents. Audit trail records must be in a format that allows authorised reviewers to retrieve and review them throughout the retention period — which means the archival format must be validated and the retrieval mechanism must be maintained.
"The audit trail question in my recent inspection was not 'is the audit trail enabled?' It was 'show me your quarterly review report and the signature on it.' That report did not exist. Writing an audit trail SOP that specifies periodic review and a signed report format is a one-time task that protects you for the life of every study."— Sarah Huntley, 25+ years CDM experience
What EU Annex 11 adds
For organisations operating under EU GMP/GCP, EU Annex 11 §9 adds that audit trails should be regularly reviewed. The Annex does not specify frequency, but regulatory convention and inspection experience place quarterly as the expected minimum for active clinical studies. The requirement to review audit trails is explicitly part of the validation and operational requirements for computerised systems under Annex 11.
CDM Library
CDM-SOP-022: Audit Trail Management & Periodic Review
A complete audit trail SOP for CDM teams — mandatory configuration specifications, UTC timestamp requirement, quarterly review content checklist, signed report format, anomaly investigation matrix, retention requirements by jurisdiction. Built from 21 CFR Part 11.10(e), ICH E6(R3) §4.2.2, and EU Annex 11 §9.
Related articles: What Is RBQM? ICH E6(R3) §3.10 Explained · ICH E6(R3) vs E6(R2): What Changed for CDM