Audit Trail in Pharmaceutical QC: Data Integrity & Review

Aanand Singh
0

Introduction

Modern pharmaceutical quality-control laboratories depend heavily on computerized systems. HPLC, GC, UV-Visible spectrophotometers, balances, dissolution testers, laboratory information management systems and other computerized systems can generate, process, store and modify electronic data.

Because electronic data are important evidence of laboratory activities, pharmaceutical companies need controls that help demonstrate what happened to the data and when it happened.

One important control is the audit trail.

An audit trail provides a chronological record of certain activities performed in a computerized system. Depending on the system, it may record events such as creation, modification or deletion of data, together with information about the user and time of the activity.

For QC professionals, understanding audit trails is especially important because audit-trail review can support investigations involving OOS results, deviations, incidents, data-integrity concerns and other quality events.

Audit Trail in Pharmaceutical QC – Data Integrity and Compliance

For example, if an unexpected HPLC result occurs, the investigation may require review of the chromatogram, sequence, processing method, integration events, user activity and other relevant electronic records.

This article explains audit trails in pharmaceutical QC, audit-trail review, examples, data integrity, OOS investigations, common deficiencies and good practices.

What Is an Audit Trail?

An audit trail is a chronological record generated by a computerized system that can help reconstruct important activities performed within that system.

Depending on the system and configuration, an audit trail may record:

  • Who performed an activity
  • What activity was performed
  • When the activity occurred
  • What data were created or changed
  • Previous and new values, where applicable
  • The reason for a change, where required
  • Other relevant system events

The exact information recorded depends on the design and configuration of the computerized system.

An audit trail should not be considered a replacement for the original electronic record. Instead, it is an important component of the overall electronic-record and data-integrity control system.

Why Is Audit Trail Important in Pharmaceutical QC?

Pharmaceutical QC laboratories generate large amounts of data.

Examples include:

  • HPLC chromatograms
  • GC chromatograms
  • UV spectra
  • Dissolution results
  • Assay results
  • Balance records
  • pH measurements
  • Microbiological results
  • System-suitability results
  • Sample sequences
  • Integration data
  • Electronic worksheets

If important electronic activities can be changed without an appropriate record, it may become difficult to determine what actually happened.

An audit trail can help investigators understand the history of relevant electronic data.

It can therefore support:

  • Data-integrity controls
  • Laboratory investigations
  • OOS investigations
  • Deviation investigations
  • Incident investigations
  • CAPA investigations
  • Internal audits
  • Regulatory inspections
  • Review of unexpected data changes

For a broader understanding of investigation methodology, see our article on Root Cause Analysis (RCA) in the Pharmaceutical Industry:

Root Cause Analysis (RCA) in Pharmaceutical Industry.

Audit Trail in a Pharmaceutical QC Laboratory

Audit trails are particularly relevant when computerized laboratory systems are used to generate or process GMP-related data.

For example, an HPLC system may contain information related to:

  • Sample identification
  • Injection sequence
  • Instrument method
  • Processing method
  • Chromatograms
  • Integration parameters
  • User activity
  • Reprocessing
  • Data processing
  • System suitability
  • Report generation

Suppose an analyst processes a chromatogram and obtains an unexpected result.

During an appropriate investigation, the reviewer may need to determine whether the chromatogram was processed correctly and whether any relevant processing changes were made.

The audit trail can provide additional evidence about the history of the electronic record.

You can also read our detailed HPLC Interview Questions and Answers article for more information about HPLC, chromatograms, system suitability and troubleshooting:

HPLC Interview Questions and Answers.

What Information Does an Audit Trail Record?

The information depends on the computerized system.

Common audit-trail information may include:

1. User Identification

The system may record the user account associated with an activity.

2. Date and Time

The system may record when an activity occurred.

3. Data Creation

Creation of a new record or dataset may be recorded.

4. Data Modification

Changes to certain data may be recorded.

5. Data Deletion

Where applicable, deletion or attempted deletion of data may be recorded.

6. Previous and New Values

Some systems can show the original value and the changed value.

7. Reason for Change

Certain systems may require or support documentation of the reason for a change.

8. Processing Activities

Laboratory systems may record certain processing or reprocessing activities.

The exact audit-trail content should be evaluated according to the intended use, system functionality, GMP requirements and the organization's procedures.

Audit Trail Example in HPLC

Consider an HPLC assay analysis.

The analyst performs the analysis and obtains a chromatogram.

The initial result appears unusual.

During investigation, the reviewer checks the electronic data and finds that the chromatogram was reprocessed.

The reviewer may then need to determine:

  • Who reprocessed the data?
  • When was it reprocessed?
  • What processing parameters were used?
  • Was the original processing retained?
  • Was the change scientifically justified?
  • Was the change documented?
  • Did the change affect the reported result?

The audit trail can provide important information for answering these questions.

However, the audit trail should be reviewed together with the complete original data and other investigation evidence.

What Is Audit Trail Review?

Audit-trail review is the documented examination of relevant audit-trail information to determine whether electronic activities are consistent with the approved procedure and whether unexpected or unauthorized activities occurred.

The review should be appropriate to the system, data and risk.

Not every audit-trail event necessarily indicates a problem.

For example, a legitimate correction performed according to an approved procedure may generate an audit-trail entry.

Therefore, reviewers should evaluate the context rather than treating every change as suspicious.

How to Perform Audit Trail Review

A practical audit-trail review may include the following steps.

Step 1: Identify the Relevant Data

Determine which electronic records are associated with the activity being reviewed.

For example:

  • Sample data
  • Chromatograms
  • Sequences
  • Instrument methods
  • Processing methods
  • Calculations
  • Reports

Step 2: Identify Relevant Users

Review the users associated with the activity.

Step 3: Review the Timeline

Check whether activities occurred at reasonable times and in the expected sequence.

Step 4: Review Changes

Look for relevant changes to:

  • Methods
  • Processing parameters
  • Results
  • Calculations
  • Sample information
  • Electronic records

Step 5: Evaluate Reprocessing

If data were reprocessed, determine why.

Step 6: Compare With Supporting Records

Compare audit-trail information with:

  • Laboratory worksheets
  • SOPs
  • Instrument logbooks
  • Training records
  • OOS records
  • Deviation records
  • Investigation documents

Step 7: Document the Review

The review and conclusion should be documented according to the organization's approved procedure.

What Should Be Checked During Audit Trail Review?

Depending on the system and risk, reviewers may consider:

  • Unexpected data changes
  • Reprocessing
  • Deleted or invalidated results
  • Changes to integration
  • Changes to analytical methods
  • Changes to sample information
  • Changes to calculations
  • User activity
  • Multiple processing attempts
  • Unusual timing
  • Repeated testing
  • Unauthorized access
  • Changes without documented justification

The reviewer should not automatically conclude that an unusual event represents misconduct.

The event should be investigated using objective evidence.

Audit Trail and ALCOA+

Audit trails are closely connected with data integrity.

The ALCOA principles describe important characteristics of reliable data:

  • Attributable
  • Legible
  • Contemporaneous
  • Original
  • Accurate

The commonly used ALCOA+ concept also includes:

  • Complete
  • Consistent
  • Enduring
  • Available

An audit trail can support some of these principles by helping establish who performed an activity, when it occurred and what changes were made.

However, an audit trail alone does not guarantee data integrity.

A complete data-integrity system also requires appropriate procedures, access controls, training, system validation, review processes and organizational controls.

Audit Trail and Data Integrity

Data integrity means that data remain reliable and trustworthy throughout their lifecycle.

In pharmaceutical QC, data-integrity controls are important because laboratory data can influence decisions about product quality.

Potential data-integrity concerns may include:

  • Unauthorized data changes
  • Shared user accounts
  • Deletion of electronic records
  • Inappropriate reprocessing
  • Uncontrolled spreadsheets
  • Inadequate access control
  • Incomplete review
  • Poor documentation
  • Uncontrolled computerized systems

Audit trails can provide evidence that helps identify and investigate such events.

Audit Trail and OOS Investigation

Audit trails can be particularly important during an OOS investigation.

For example, suppose an HPLC assay produces an OOS result.

The investigation may examine:

  • Original chromatogram
  • Sample preparation
  • Standard preparation
  • Calculations
  • System suitability
  • Instrument performance
  • Processing method
  • Audit trail
  • Analyst activity
  • Previous results

If the electronic record shows that the data were reprocessed after the original result, the investigator may need to determine why the reprocessing occurred and whether it affected the reported result.

For a complete explanation of OOS investigations, see:

OOS Investigation in Pharmaceutical Industry.

The goal of an OOS investigation is to understand what happened and determine the scientifically supported cause. Audit-trail information can be one part of that evidence.

Audit Trail and Deviation Investigation

Audit trails may also support deviation investigations.

A deviation can involve an unexpected departure from an approved procedure, process or requirement.

For example, an investigation may identify that a laboratory result was processed using an unexpected method.

The investigator may review the relevant electronic records and audit trail to understand what happened.

For a detailed explanation of deviation management, see:

Deviation in Pharmaceutical Industry: Meaning, Types, Investigation and CAPA.

The relationship can be summarized as:

Deviation → Investigation → Evidence Review → Root Cause → CAPA → Effectiveness Check

Audit Trail and Incident Investigation

An incident is another type of quality event where electronic records may be relevant.

For example:

  • HPLC stops during analysis
  • Instrument software generates an error
  • Electronic data are unexpectedly unavailable
  • Computerized system malfunction occurs
  • Unexpected electronic-record behavior is observed

The investigation may require review of system logs, audit trails and other available evidence.

Read more:

Incident in the Pharmaceutical Industry.

Audit Trail and Root Cause Analysis

Finding an unusual audit-trail entry is not necessarily the end of an investigation.

The next question is often:

Why did this happen?

For example:

Problem → Unexpected data reprocessing

Why?

→ Analyst needed to correct integration

Why?

→ Peak integration was incorrect

Why?

→ Processing parameters were not suitable

Why?

→ The method or procedure did not provide adequate instructions

The investigation may therefore identify a system or procedural weakness rather than simply concluding "analyst error."

A detailed guide to this approach is available in:

Root Cause Analysis (RCA) in Pharmaceutical Industry: Meaning, Steps, Tools and Examples.

Audit Trail and CAPA

If an investigation identifies a systemic problem, appropriate CAPA may be required.

For example, an investigation could identify:

  • Inadequate SOP
  • Insufficient training
  • Weak access controls
  • Poor system configuration
  • Inadequate review process
  • Inadequate data-integrity controls

Possible CAPA could include:

  • SOP revision
  • Employee training
  • System configuration improvement
  • Access-control review
  • Additional monitoring
  • Periodic audit-trail review
  • Effectiveness verification

Read more:

CAPA in Pharmaceutical Industry.

CAPA should address the identified cause and should be appropriate to the risk and investigation findings.

Audit Trail and Change Control

Computerized systems may undergo controlled changes.

Examples include:

  • Software upgrades
  • Configuration changes
  • New user roles
  • Method changes
  • Instrument replacement
  • System modifications

Such planned changes should be appropriately evaluated and controlled.

For more information:

Change Control System in Pharmaceutical Industry.

Change control and audit trails serve different purposes.

Change control manages planned changes.

Audit trails provide records of certain activities within computerized systems.

Both can contribute to a controlled pharmaceutical quality system.

Audit Trail and Retention Samples

Retention samples are physical samples kept for possible future examination.

They can become important during investigations involving product quality.

For example, a retention sample may be examined as part of a justified investigation after a complaint or other quality concern.

Read more:

Retention Sample in Pharmaceutical QC.

Although retention samples are physical materials rather than electronic records, their associated documentation and electronic records may both contribute to an investigation.


Common Audit Trail Deficiencies

Some common weaknesses associated with audit-trail management include:

1. Audit Trail Not Enabled

A system may not have an appropriate audit-trail function enabled where it is required.

2. Shared User Accounts

Shared accounts can make user attribution difficult.

3. Inadequate Review

An audit trail may exist but not be appropriately reviewed.

4. No Investigation of Unexpected Changes

Unexpected events may be ignored without assessing their potential impact.

5. Inadequate Documentation

The reason for a legitimate change may not be properly documented.

6. Excessive User Access

Users may have permissions beyond what they need for their job responsibilities.

7. Poor System Configuration

The computerized system may not be configured appropriately for its intended GMP use.

8. Lack of Training

Employees may not understand appropriate data-handling and audit-trail requirements.

Best Practices for Audit Trail Management

Pharmaceutical organizations can strengthen audit-trail management by:

  1. Using unique user accounts.
  2. Controlling user access according to job responsibilities.
  3. Ensuring appropriate audit-trail functionality.
  4. Validating computerized systems according to their intended use.
  5. Establishing written procedures.
  6. Training users.
  7. Defining audit-trail review responsibilities.
  8. Reviewing relevant audit-trail information based on risk.
  9. Investigating unusual activities.
  10. Maintaining original electronic records.
  11. Documenting legitimate changes appropriately.
  12. Periodically reviewing access permissions.
  13. Maintaining system security.
  14. Linking relevant findings to deviation, OOS, CAPA or other quality systems when appropriate.

Audit Trail During Regulatory Inspection

During a regulatory inspection, computerized systems and electronic data may be reviewed depending on the scope of the inspection.

Inspectors may be interested in whether:

  • Electronic records are reliable
  • Data can be attributed to individual users
  • Changes are traceable
  • Audit trails are available where appropriate
  • Data are reviewed appropriately
  • Access is controlled
  • Original records are maintained
  • Investigations are scientifically supported

Therefore, audit-trail management should be treated as part of the overall pharmaceutical data-integrity system rather than as an isolated IT activity.

Audit Trail vs Raw Data

These terms should not be confused.

Raw Data

Raw data are the original records or information generated during an activity that are necessary to reconstruct and evaluate the activity.

Audit Trail

An audit trail records certain actions or changes occurring within a computerized system.

Therefore:

Raw data = Evidence of the activity

Audit trail = History of relevant system activity

Both may be important during an investigation.

Audit Trail vs Electronic Record

An electronic record is the electronic information maintained by a computerized system.

An audit trail is a record associated with certain activities or changes involving the system or records.

Therefore, the audit trail is generally part of the broader electronic-record environment and should not be treated as a replacement for the underlying data.

Practical Example: Audit Trail During an OOS Investigation

Suppose an HPLC assay produces the following result:

Specification: 95.0%–105.0%

Initial result: 93.7%

The analyst reports the result according to the applicable procedure.

During the investigation, the team reviews:

  • Sample preparation
  • Standard preparation
  • Calculations
  • System suitability
  • Chromatogram
  • Instrument status
  • Processing method
  • Audit trail
  • Previous relevant results

The audit trail indicates that the chromatogram was reprocessed after the original result.

The investigation should then determine:

  1. Why was the chromatogram reprocessed?
  2. Who performed the activity?
  3. What changed?
  4. Was the change justified?
  5. Was the original result retained?
  6. Did the change affect the reported result?
  7. Was the activity performed according to the approved procedure?

The audit-trail information becomes part of the evidence used to reach a scientifically supported conclusion.

Audit Trail Interview Questions

1. What is an audit trail?

An audit trail is a chronological record of certain activities performed within a computerized system that can help reconstruct relevant electronic-data history.

2. Why is audit trail important in pharmaceutical QC?

It helps provide traceability of relevant electronic activities and supports data-integrity controls and investigations.

3. What is audit-trail review?

It is the examination of relevant audit-trail information to determine whether electronic activities are consistent with approved procedures and whether unexpected events require investigation.

4. Is an audit trail the same as raw data?

No. Raw data and audit trails serve different purposes, although both may be important for reconstructing an activity.

5. Can audit trails support OOS investigations?

Yes. Relevant audit-trail information may provide evidence during an OOS investigation.

6. Can audit trails support deviation investigations?

Yes. They can provide information about relevant activities performed within a computerized system.

7. What is the relationship between audit trail and data integrity?

Audit trails are one component of a broader data-integrity control system.

8. What should be done when an unusual audit-trail event is found?

The event should be evaluated using appropriate evidence and procedures. If necessary, it should be investigated through the applicable quality system.

Conclusion

Audit trails are an important component of computerized-system and data-integrity controls in pharmaceutical QC.

They can help provide traceability of relevant electronic activities and may become valuable evidence during OOS investigations, deviation investigations, incident investigations, audits and regulatory inspections.

However, an audit trail should not be considered a replacement for the original electronic record or the complete investigation process.

Effective audit-trail management requires appropriate computerized-system controls, unique user accounts, controlled access, suitable procedures, trained personnel, proper review and scientifically justified investigation of unexpected events.

For QC professionals, understanding audit trails is particularly important because modern laboratory testing increasingly depends on computerized systems.

A useful way to remember the concept is:

Electronic Record → Audit Trail → Review → Investigation → Root Cause → CAPA → Effectiveness Check

When these elements work together, they can strengthen data integrity and support a reliable pharmaceutical quality system.

References

  1. U.S. Food and Drug Administration (FDA), Data Integrity and Compliance With Drug CGMP: Questions and Answers.
  2. U.S. Food and Drug Administration (FDA), Guidance for Industry: Part 11, Electronic Records; Electronic Signatures.
  3. European Commission, EudraLex Volume 4, EU Guidelines for Good Manufacturing Practice, Annex 11: Computerised Systems.
  4. World Health Organization (WHO), guidance on good data and record management practices.
  5. ICH Q9(R1), Quality Risk Management.
  6. ICH Q10, Pharmaceutical Quality System.

Disclaimer

The information provided in this article is for educational and informational purposes only. Pharmaceutical companies should always follow their approved SOPs, applicable GMP requirements, regulatory requirements and validated computerized-system procedures.

Post a Comment

0Comments

Have a question, suggestion, or feedback? Feel free to leave a comment below. Please keep your comments respectful and relevant to the topic.

Post a Comment (0)