Template Detail

Audit trail review checklist

A working checklist for the audit trail review discipline of Part 11 §11.10(e), Annex 11 clause 9 and the MHRA GxP DI guidance.

Enabling an audit trail is the easy half; regulators increasingly test the review half — who looked at it, how often, on what risk basis, and where the record of that review lives. This checklist walks a review cycle from scope and frequency justification through change review, anomaly checks and follow-up, producing the review record itself as you go.

See the validation pack
Free · Excel workbook · unlocks in seconds
Audit trail review checklist — the Excel workbook you download, showing its phases and columns
Audit trail review checklist — the Excel workbook you download, showing its phases and columns

What the checklist covers

The workbook walks 12 review checks across three phases — SETUP (decided once, revisited at periodic review), REVIEW (executed each cycle) and FOLLOW-UP (closing the loop) — each with evidence-reference, reviewer, date and status columns, a Pass / Finding / N-A dropdown, an Instructions tab and a worked example row.

  • Scope and risk-based frequency justification per system
  • Changes and deletions on critical data, with reason-for-change quality
  • Unusual patterns, account anomalies and time-stamp integrity
  • Audit trail availability across the whole period
  • Anomaly disposition, the review record itself, and trend input

Frequently asked questions

How often should audit trails be reviewed?

At a risk-based frequency you can justify — the MHRA GxP guidance expects frequency proportionate to data criticality. Release-critical data is commonly reviewed per batch; supporting data periodically. The checklist's setup rows make you document that justification, which is exactly what an inspector asks for.

What should an audit trail review actually look for?

Changes and deletions on critical data with adequate reasons, unusual edit patterns, activity from generic or disabled accounts, and time-stamp anomalies. Reviewing means examining those specifics — not scrolling the log and filing it unread.

Do we need to keep a record of each review?

Yes — a review that left no record is treated as not performed. The completed checklist is designed to be that record: what was examined, by whom, what was found, and how findings were dispositioned.

Continue Exploring

Explore related topics, modules, and compliance resources for a deeper understanding of your quality system.

21 CFR Part 11 readiness checklist workbook
Related

21 CFR Part 11 Readiness Checklist

Explore this topic in more depth to build a complete picture of your quality and compliance operations.

Explore
Deviation investigation checklist workbook
Related

Deviation Investigation Checklist

Explore this topic in more depth to build a complete picture of your quality and compliance operations.

Explore
Inspection readiness checklist workbook
Related

Inspection Readiness Checklist

Explore this topic in more depth to build a complete picture of your quality and compliance operations.

Explore

See this discipline running in a governed eQMS

Complere connects these records end to end — with an immutable, database-enforced audit trail on the audit-trail tables and inspection-ready retrieval.