Audit Trail Reviews in GCP and GVP: Expectation vs Reality

Most organizations already generate compliant audit trails. Far fewer actually review them the way ICH E6(R3) and GVP expect – with defined scope, meaningful timing, and documented outcomes.

An audit trail records who did what, when, and sometimes why. But having an audit trail enabled is not the same as actively reviewing it.

So, where does the gap between expectation and reality typically appear?

1. Defined Scope

Expectation:
The scope of the audit trail review is defined in advance based on risk and critical data endpoints  for example, eligibility, consent, causality, seriousness, and other critical data.

Reality:
Systems are often validated and 21 CFR Part 11 compliant, creating a perception that audit trail compliance is already addressed. The system logs everything, but the review itself may not be clearly defined or consistently performed.

2. Meaningful Timing

Expectation:
Reviews take place at meaningful milestones throughout the trial or case lifecycle, when issues can still be identified, investigated, and addressed.

Reality:
Reviews often happen retrospectively at database lock, during inspection preparation, or just before an audit. By then, opportunities for timely intervention may have been missed.

3. Documented Outcomes

Expectation:
Each review has a documented outcome showing what was checked, what was found, and what was escalated or addressed.

Reality:
Organizations may be able to demonstrate that a review occurred, but not always what was actually reviewed or what the review concluded.

4. Integrated Oversight

Expectation:
Relevant findings feed into broader quality and risk management processes, including Risk-Based Quality Management (RBQM), where appropriate.

Reality:
Audit trail findings can remain in standalone logs rather than becoming part of an ongoing quality and risk discussion.

5. Vendor Blind Spots

Expectation:
Sponsors and MAHs understand who is responsible for audit trail review across CRO and vendor systems and have appropriate oversight of the process.

Reality:
There can be an assumption that vendors are reviewing their systems, without sufficient visibility into the scope, timing, findings, or ability to access the audit trail when needed.

Conclusion

Maintaining an audit trail and actively reviewing it represent distinct compliance claims.

The question during an inspection may not simply be:

“Does your system have an audit trail?”

It may be:

“Show me how you review it, what you found, and what you did about it.”

That is where the gap between expectation and reality becomes most visible.

Leave a Comment

Your email address will not be published. Required fields are marked *

Need Help?
Scroll to Top

Let's discuss your project