
Audit trail review helps clinical trial teams understand how electronic data and associated metadata have changed over time. A useful review process examines relevant activity for patterns, anomalies or process weaknesses that could affect participant protection, data reliability or the interpretation of study results.
An audit trail is a comprehensive log that records all activities, including modifications, additions, and deletions of data, within a clinical trial. Audit trail review is the planned examination of those records and related metadata. Its purpose is to identify activity that may require further assessment, such as repeated changes to critical data, unexpected access patterns, delayed data entry or incomplete reasons for change.
For sponsors, CROs, biotech and pharmaceutical companies, the practical challenge is deciding which audit trail information should be reviewed, when the review should take place, and how findings should be interpreted and documented.
Audit trails are expected to capture the following:
These fields provide the basis for review, but their presence alone does not show that the data is reliable. Reviewers need enough context to understand whether the activity is expected, adequately explained and consistent with the study process.
Trial-level audit trail review focuses on clinical data and metadata generated during the conduct of a study. It may examine data entry, changes to critical variables, query-related activity, user access and patterns that could indicate process or data-quality concerns.
System-level review focuses on the technical environment. It may cover system configuration, administrative activity, security events, user provisioning and changes that could affect system performance or data integrity.
The two activities are related but have different purposes and may be owned by different functions. Clinical data management teams may lead trial-level review, while system owners, information technology, quality assurance or vendors may oversee technical system review. The audit trail review plan should make this distinction clear.
Regulatory bodies such as the US Food and Drug Administration (FDA) and the European Medicines Agency (EMA) expect electronic systems used in clinical research to maintain complete and traceable records of relevant data activity.
Regulatory expectations generally focus on ensuring that electronic records and relevant metadata remain attributable, legible, contemporaneous, original, accurate, complete and available throughout the required retention period.
For clinical trials, the regulatory position is broader than simply having an enabled audit trail. Sponsors should be able to explain how they assess relevant metadata, how review activities are prioritised and how identified issues are followed through.
The applicable framework can include 21 CFR Part 11, current good clinical practice guidance, guidance on computerised systems and electronic data, and broader data integrity expectations. These sources do not all carry the same regulatory status or apply in the same way. Organisations should therefore identify which requirements and guidance apply to the trial, system and data under review.
GMP guidance may provide useful data-integrity principles, but it should not be presented as if it automatically defines the clinical trial audit trail review process. The article should distinguish direct clinical requirements from supporting principles drawn from other regulated environments.
Reviewing every event in every audit trail is rarely practical and may duplicate controls already performed through data cleaning, monitoring, system validation or security review. A risk-based approach starts by identifying where audit trail review could provide information that is not already available through another control.
Scope may be influenced by:
Data sources should not be included simply because an audit trail exists. Equally, external systems should not be excluded without considering whether relevant metadata can be accessed through vendors, data transfers or contractual arrangements. Any exclusion should have a documented rationale.
An audit trail review plan should include the following:
System capability and review readiness
Clinical data management systems, electronic data capture systems and other relevant platforms should be assessed to confirm that audit trail and metadata functions are suitable for their intended use. This includes understanding what the system records, whether records can be exported or reported, how timestamps are represented and whether changes can be linked to identifiable users.
System changes should be managed through change control and validation impact assessment. The response should be proportionate to the nature and potential effect of the change rather than assuming that every update requires complete revalidation.
During vendor selection and study set-up, sponsors should confirm that external providers can supply the metadata needed for planned review and that responsibilities are covered in contracts, procedures or study documentation.
Scope, objectives and use cases
The plan should state why audit trail review is being performed, and which risks it is intended to address. Relevant use cases may include:
Audit trail review should be considered across the clinical trial lifecycle.
A review may be prospective or retrospective. Prospective review is planned in advance and performed during trial conduct. Retrospective review is usually targeted and may be initiated in response to a specific issue, signal or inspection question.
Review frequency should be based on risk, data criticality, study phase, data volume and previous findings. A fixed schedule may be appropriate for some use cases, while others may be event-driven or triggered by an identified concern.
Vendor selection and sourcing
Assess whether prospective systems and vendors can generate, retain and provide the audit trail information needed for planned review. Confirm ownership, access arrangements and any technical limitations before contracting.
Study conduct
Perform planned reviews at the agreed frequency and carry out targeted reviews when concerns arise. Findings during conduct can support timely training, process correction, site follow-up or further investigation.
Database lock and closeout
Confirm that required reviews have been completed, findings have been assessed and unresolved issues have been addressed or formally accepted. Review documentation should support the rationale for database lock and study closeout decisions.
Database lock is an important review point, but audit trail review should not be treated as an activity performed only at the end of the study. Issues found late may be harder to investigate and may indicate that earlier opportunities for intervention were missed.
Archival and retention
Retain audit trail review records and relevant source metadata in line with the associated clinical records. The retained information should remain accessible and interpretable for inspection or future investigation.
Reviewers should understand the study, the relevant system, the data being assessed and the purpose of the review. Technical ability to run a report is not enough. Reviewers need sufficient context to judge whether an event is expected, meaningful or potentially misleading. The sponsor retains oversight even where review activity is delegated to a CRO, technology provider or another vendor. Responsibilities should therefore be clear for:
Quality assurance may assess whether the process is defined and followed through broader oversight or audit activity. This does not necessarily mean that each completed audit trail review requires a routine second-person content check. The level of oversight should reflect risk and the organisation’s procedures.
Audit trails should be protected from unauthorised modification or deletion. Access controls, role management and user provisioning remain important, but trial-level review should focus on activity that could affect the reliability or interpretation of clinical data.
Depending on the defined use case, reviewers may examine:
An unusual even is not automatically evidence of misconduct or poor data quality, rather it is a signal that may need context before a conclusion can be reached.
Potential findings should first be confirmed against the available context. This may include clinical data, data queries, monitoring records, source documentation, system records, vendor explanations and relevant study communications.
Once confirmed, the finding should be assessed for potential impact on participant safety, data reliability, protocol compliance or the wider study process. The response may range from documenting an acceptable explanation to further investigation, site follow-up, retraining, process correction or corrective and preventive action.
Escalation should be proportionate to the nature, recurrence and potential impact of the issue. Not every anomaly requires a formal root-cause investigation, but significant or repeated findings should not be closed without an adequate explanation.
Review records should show:
Documentation should allow another suitably qualified person to understand what was reviewed, what was found, and how the conclusion was reached.
Audit trails can contain a large volume of metadata, particularly in complex or long-running studies. Reports, filters and visualisation tools can help reviewers prioritise activity, compare patterns across sites or users and identify events that warrant closer examination. Automated flags may identify patterns, but a reviewer still needs to determine whether those patterns are expected, explainable, or material.
Audit trail review is only as useful as the metadata available and the clarity of the review objective. Common constraints include inconsistent system formats, inaccessible vendor data, unclear timestamps, missing reasons for change and limited links between audit trail events and supporting clinical records.
High data volume can also create a risk of unfocused review. Examining large quantities of low-value activity may consume resources without improving oversight. The process should therefore remain proportionate and should be refined as the study develops.
Teams may begin with a limited number of high-value use cases, assess what the reviews reveal and adjust the scope, frequency or method where justified. This allows the process to respond to emerging risks without becoming a routine exercise that produces little actionable information.
A useful audit trail review process is planned, risk-based and proportionate. It focuses on metadata that can reveal meaningful risks, assigns clear ownership and requires findings to be interpreted in their clinical and operational context.
Quanticate’s clinical data management team can support risk-based audit trail review planning, review execution, and the interpretation and documentation of findings across clinical studies. If you want to explore how we can support your audit trail review approach and wider clinical data management strategy, request a consultation below.
Bring your drugs to market with fast and reliable access to experts from one of the world’s largest global biometric Clinical Research Organizations.
© 2026 Quanticate