Audit Trail Reviews in GCP and GVP: Expectation vs Reality

Most organizations already generate compliant audit trails. Far fewer actually review them the way ICH E6(R3) and GVP expect – with defined scope, meaningful timing, and documented outcomes.

An audit trail records who did what, when, and sometimes why. But having an audit trail enabled is not the same as actively reviewing it.

So, where does the gap between expectation and reality typically appear?

Audit Trail Reviews in GCP and GVP: Expectation
vs Reality

Expectation

Reality

·     Is the Scope defined in advance for review, for
example, are critical data endpoints identified such as eligibility, consent,
causality, seriousness etc.

·     When to review:
Do reviews happen at meaningful milestones throughout the trial or
case lifecycle, not just once at the end for example at the time of database
locks

·     Documentation of outcome
of
 each review for example what was checked,
what was found and  what was escalated.

·     Integrated oversight. Discrepancies are
fed into Risk Based Quality Management (RBQM) than sitting in a standalone
log that nobody revisits.

·     General perception is that systems are validated and 21
CFR Part 11 compliant meaning they are audit trail enabled. Many teams equate
having an audit trail with reviewing  it. The system logs everything; almost
nobody looks.

·     Review at the wrong time.
Checks often happen retrospectively,
at database lock, at inspection prep / audits, instead of during the
trial or case lifecycle when action is still possible.

·     No prioritization: Without a defined
critical data set, reviewers either abbreviate everything superficially or
default to reviewing nothing systematically.

·     Vendor blind spots: Sponsors and MAHs
assume CRO or vendor systems are being reviewed, but rarely verify it or
cannot always even extract the trail themselves.

·     Reviews not adequately
documented to be able to demonstrate during audits / inspection

Conclusion

Maintaining an audit trail and actively reviewing it represent distinct compliance claims. During an inspection, only the latter will withstand scrutiny.

Leave a Comment

Your email address will not be published. Required fields are marked *

Need Help?
Scroll to Top

Let's discuss your project