Audit trail review is the planned evaluation of changes recorded in an audit trail and other relevant metadata during an ongoing clinical trial. ICH E6(R3) requires procedures for this that are based on the risk of the individual study in terms of scope and nature, and are adapted based on experience during the course of the study. The focus is thus on the control activity, not the technical log itself.
From Event Log to Professional Assessment
An audit trail documents which action occurred in a system, who triggered it, and when it took place; for data changes, the reason may also be visible. The audit trail review takes these entries as a starting point and assesses their plausibility within the study context. For example, a correction to a primary endpoint shortly before database lock requires a different level of attention than the correction of a non-critical administrative field.
The review does not only look at individual value changes. It can also capture repeated changes by the same role, retrospectively recorded visits, or unusual access to sensitive data sets. For the findings to be robust, the audit trail, user roles, queries, source documents, and relevant system messages must be readable in context. A mere export from the EDC without a study-related assessment does not fulfill this function.
Planning Based on Data Risk and Study Phase
ICH E6(R3) requires established procedures for the review of study-specific data, audit trails, and other relevant metadata. The plan must determine which types of events are included, which data areas are prioritized, who performs the evaluation, and how findings are communicated. The selection may include, for example, critical safety data, authorization changes, unblinding information, or retrospective corrections.
The intensity may be adjusted over time. If an initial evaluation shows frequent changes after specific training or in an interface, the review can be focused on this constellation or intensified in terms of timing. Conversely, an unremarkable period does not justify a permanent cessation of the control if the risk remains. Results and follow-up measures must remain linked to the evaluated set of events.
Distinction Between the Audit Trail and the Audit
The audit trail is the record of system events. The audit trail review is the activity of evaluating this record against the requirements and the course of the study. Only this distinction makes it clear why a correctly configured audit trail function does not indicate whether suspicious changes were identified and processed in a timely manner.
A quality audit is also not to be equated with the review. An audit can examine whether the procedure for the audit trail review is appropriately implemented and effective. The ongoing review, on the other hand, analyzes specific data entries and metadata in the study. Both activities may use the same documents but pursue different control objectives.
The effectiveness of the procedure also depends on the representability of the data. If a system can only output old and new values, the reason for change, or timestamps in difficult-to-read raw files, a risk-based review can hardly be carried out reliably. Therefore, it should be determined during system configuration which reports must be generatable for the intended review scenarios. The review then does not check the technical existence of an export, but rather whether the events visible there are compatible with the permissible conduct of the study.
A documented result should indicate the reviewed population or period, the criteria applied, and the assessment of findings. If exceptions are accepted, the justification must refer to the specific process. This ensures it remains traceable why a change was closed without further action or escalated to monitoring, data management, or quality assurance.
Relevance for clinical trials
Audit trail review connects data management and quality management where a change may become relevant to the reliability of the results. Without a pre-defined focus on critical events, systemic patterns are easily lost between individual queries or monitoring visits. Furthermore, with decentralized data sources and multiple integrated systems, it must be clear which trail is authoritative for which change.
Full-service CROs like Mediconomics provide support in risk-based review planning, the definition of review criteria and escalation paths, and the consolidation of EDC, ePRO, and authorization logs. Data Management, Monitoring, and Quality Assurance can jointly evaluate suspicious changes, trigger documented inquiries to investigative sites, and track corrective actions through to completion.
Frequently Asked Questions (FAQ)
Does every audit trail entry have to be checked manually?
ICH E6(R3) requires a planned, risk-based scope, not necessarily the identical individual case review of all entries. Which events are prioritized must fit the specific study.
Can a query replace the audit trail review?
No. A query typically clarifies a specific data question. The review additionally assesses the course, circumstances, and, if applicable, patterns of system changes.
Who is permitted to perform the review?
The study must define responsibilities and procedures. It is essential that the person performing the review has access to the required metadata and the professional context for the assessment.
Regulatory References
- ICH E6(R3), Good Clinical Practice – requires planned, risk-based procedures for reviewing audit trails and metadata.
- EMA/INS/GCP/112288/2023 – explains requirements for electronic study data and traceable system events.
- EudraLex Volume 4, Annex 11 – requires available audit trails that are to be reviewed regularly.