Quanticate Blog

What is Audit Trail Review in Clinical Trials?

Written by Clinical Data Management Team | Tue, Aug 11, 2026

Audit trail review helps clinical trial teams understand how electronic data and associated metadata have changed over time. A useful review process examines relevant activity for patterns, anomalies or process weaknesses that could affect participant protection, data reliability or the interpretation of study results.

An audit trail is a comprehensive log that records all activities, including modifications, additions, and deletions of data, within a clinical trial. Audit trail review is the planned examination of those records and related metadata. Its purpose is to identify activity that may require further assessment, such as repeated changes to critical data, unexpected access patterns, delayed data entry or incomplete reasons for change.

For sponsors, CROs, biotech and pharmaceutical companies, the practical challenge is deciding which audit trail information should be reviewed, when the review should take place, and how findings should be interpreted and documented.

Audit trails are expected to capture the following:

    • Who made the change (user identification).
    • What was changed (data points before and after the modification).
    • When the change occurred (date and time stamp).
    • Why the change was made (reason or justification).

These fields provide the basis for review, but their presence alone does not show that the data is reliable. Reviewers need enough context to understand whether the activity is expected, adequately explained and consistent with the study process.

In Brief

  • Audit trail review is the planned examination of electronic records and metadata to identify activity that may need further assessment.

  • In clinical trials, review scope should reflect data criticality, study risks, existing controls, and whether the review can support a useful decision.

  • Audit trail review can apply across vendor selection, study conduct, database lock, closeout, and retention, with responsibilities defined in advance.

  • Reviewing every audit trail event is rarely practical, and unusual activity should be interpreted in context before it is treated as a finding.

  • A proportionate audit trail review process should define what is reviewed, when reviews occur, who is responsible, and how findings are handled.

What is the difference between trial-level and system-level audit trail review?

Trial-level audit trail review focuses on clinical data and metadata generated during the conduct of a study. It may examine data entry, changes to critical variables, query-related activity, user access and patterns that could indicate process or data-quality concerns.

System-level review focuses on the technical environment. It may cover system configuration, administrative activity, security events, user provisioning and changes that could affect system performance or data integrity.

The two activities are related but have different purposes and may be owned by different functions. Clinical data management teams may lead trial-level review, while system owners, information technology, quality assurance or vendors may oversee technical system review. The audit trail review plan should make this distinction clear.

Which regulations and guidance apply to audit trail review?

Regulatory bodies such as the US Food and Drug Administration (FDA) and the European Medicines Agency (EMA) expect electronic systems used in clinical research to maintain complete and traceable records of relevant data activity.

Regulatory expectations generally focus on ensuring that electronic records and relevant metadata remain attributable, legible, contemporaneous, original, accurate, complete and available throughout the required retention period.

For clinical trials, the regulatory position is broader than simply having an enabled audit trail. Sponsors should be able to explain how they assess relevant metadata, how review activities are prioritised and how identified issues are followed through.

The applicable framework can include 21 CFR Part 11, current good clinical practice guidance, guidance on computerised systems and electronic data, and broader data integrity expectations. These sources do not all carry the same regulatory status or apply in the same way. Organisations should therefore identify which requirements and guidance apply to the trial, system and data under review.

GMP guidance may provide useful data-integrity principles, but it should not be presented as if it automatically defines the clinical trial audit trail review process. The article should distinguish direct clinical requirements from supporting principles drawn from other regulated environments.

How should audit trail review scope be risk assessed?

Reviewing every event in every audit trail is rarely practical and may duplicate controls already performed through data cleaning, monitoring, system validation or security review. A risk-based approach starts by identifying where audit trail review could provide information that is not already available through another control.

Scope may be influenced by:

  • The criticality of the data or process
  • The potential effect on participant safety or trial reliability
  • The type and volume of metadata available
  • Known system or process limitations
  • Previous findings or emerging study risks
  • The effectiveness of existing controls
  • Whether the review can lead to a meaningful action or decision

Data sources should not be included simply because an audit trail exists. Equally, external systems should not be excluded without considering whether relevant metadata can be accessed through vendors, data transfers or contractual arrangements. Any exclusion should have a documented rationale.

What should an audit trail review plan include?

An audit trail review plan should include the following:

System capability and review readiness

Clinical data management systems, electronic data capture systems and other relevant platforms should be assessed to confirm that audit trail and metadata functions are suitable for their intended use. This includes understanding what the system records, whether records can be exported or reported, how timestamps are represented and whether changes can be linked to identifiable users.

System changes should be managed through change control and validation impact assessment. The response should be proportionate to the nature and potential effect of the change rather than assuming that every update requires complete revalidation.

During vendor selection and study set-up, sponsors should confirm that external providers can supply the metadata needed for planned review and that responsibilities are covered in contracts, procedures or study documentation.

Scope, objectives and use cases

The plan should state why audit trail review is being performed, and which risks it is intended to address. Relevant use cases may include:

  • Unexpected or inappropriate user access
  • Repeated changes to critical data
  • Non-contemporaneous or unusually timed data entry
  • Incomplete or inconsistent reasons for change
  • Deletion or overwriting of relevant information
  • Unusual patterns across sites, users or records
  • Concerns arising from monitoring, data review or inspection findings

When should audit trail review take place?

Audit trail review should be considered across the clinical trial lifecycle.

A review may be prospective or retrospective. Prospective review is planned in advance and performed during trial conduct. Retrospective review is usually targeted and may be initiated in response to a specific issue, signal or inspection question.

Review frequency should be based on risk, data criticality, study phase, data volume and previous findings. A fixed schedule may be appropriate for some use cases, while others may be event-driven or triggered by an identified concern.

Vendor selection and sourcing
Assess whether prospective systems and vendors can generate, retain and provide the audit trail information needed for planned review. Confirm ownership, access arrangements and any technical limitations before contracting.

Study conduct
Perform planned reviews at the agreed frequency and carry out targeted reviews when concerns arise. Findings during conduct can support timely training, process correction, site follow-up or further investigation.

Database lock and closeout
Confirm that required reviews have been completed, findings have been assessed and unresolved issues have been addressed or formally accepted. Review documentation should support the rationale for database lock and study closeout decisions.

Database lock is an important review point, but audit trail review should not be treated as an activity performed only at the end of the study. Issues found late may be harder to investigate and may indicate that earlier opportunities for intervention were missed.

Archival and retention
Retain audit trail review records and relevant source metadata in line with the associated clinical records. The retained information should remain accessible and interpretable for inspection or future investigation.

Who should perform and oversee audit trail review?

Reviewers should understand the study, the relevant system, the data being assessed and the purpose of the review. Technical ability to run a report is not enough. Reviewers need sufficient context to judge whether an event is expected, meaningful or potentially misleading. The sponsor retains oversight even where review activity is delegated to a CRO, technology provider or another vendor. Responsibilities should therefore be clear for:

  • Defining scope and use cases
  • Providing access to audit trail data
  • Performing the review
  • Investigating and escalating findings
  • Approving actions and documenting closure
  • Confirming that planned reviews took place

Quality assurance may assess whether the process is defined and followed through broader oversight or audit activity. This does not necessarily mean that each completed audit trail review requires a routine second-person content check. The level of oversight should reflect risk and the organisation’s procedures.

What should reviewers look for in an audit trail?

Audit trails should be protected from unauthorised modification or deletion. Access controls, role management and user provisioning remain important, but trial-level review should focus on activity that could affect the reliability or interpretation of clinical data.

Depending on the defined use case, reviewers may examine:

  • Changes to critical efficacy, safety or eligibility data
  • Repeated edits by the same user or at the same time
  • Data entered or amended long after the relevant visit
  • Changes made outside expected working patterns
  • Records changed without an adequate reason
  • Data created, modified and deleted in rapid succession
  • Activity by inactive, shared or unexpected user accounts
  • Differences between the audit trail and supporting queries, notes or source documentation
  • Missing, inconsistent or difficult-to-interpret metadata

An unusual even is not automatically evidence of misconduct or poor data quality, rather it is a signal that may need context before a conclusion can be reached.

How should audit trail review findings be handled?

Potential findings should first be confirmed against the available context. This may include clinical data, data queries, monitoring records, source documentation, system records, vendor explanations and relevant study communications.

Once confirmed, the finding should be assessed for potential impact on participant safety, data reliability, protocol compliance or the wider study process. The response may range from documenting an acceptable explanation to further investigation, site follow-up, retraining, process correction or corrective and preventive action.

Escalation should be proportionate to the nature, recurrence and potential impact of the issue. Not every anomaly requires a formal root-cause investigation, but significant or repeated findings should not be closed without an adequate explanation.

Review records should show:

  • The scope and period reviewed
  • The system, report or date source used
  • The reviewer and date of review
  • The use cases or criteria applied
  • Findings and supporting evidence
  • Decisions, escalations and actions
  • The rationale for closure
  • Any changes made to future review scope or frequency

Documentation should allow another suitably qualified person to understand what was reviewed, what was found, and how the conclusion was reached.

How can visualisation support audit trail review?

Audit trails can contain a large volume of metadata, particularly in complex or long-running studies. Reports, filters and visualisation tools can help reviewers prioritise activity, compare patterns across sites or users and identify events that warrant closer examination. Automated flags may identify patterns, but a reviewer still needs to determine whether those patterns are expected, explainable, or material.

What are the limitations of audit trail review?

Audit trail review is only as useful as the metadata available and the clarity of the review objective. Common constraints include inconsistent system formats, inaccessible vendor data, unclear timestamps, missing reasons for change and limited links between audit trail events and supporting clinical records.

High data volume can also create a risk of unfocused review. Examining large quantities of low-value activity may consume resources without improving oversight. The process should therefore remain proportionate and should be refined as the study develops.

Teams may begin with a limited number of high-value use cases, assess what the reviews reveal and adjust the scope, frequency or method where justified. This allows the process to respond to emerging risks without becoming a routine exercise that produces little actionable information.

Conclusion

A useful audit trail review process is planned, risk-based and proportionate. It focuses on metadata that can reveal meaningful risks, assigns clear ownership and requires findings to be interpreted in their clinical and operational context.

Quanticate’s clinical data management team can support risk-based audit trail review planning, review execution, and the interpretation and documentation of findings across clinical studies. If you want to explore how we can support your audit trail review approach and wider clinical data management strategy, request a consultation below.