Building a Practical Audit Trail Strategy for eClinical Data

By Published On: 4th August 202610.2 min read
Categories: CTMS, EDC, ePRO/eCOA

Building a Practical Audit Trail Strategy for eClinical Data

By Published On: 4th August 202610.2 min read
Categories: CTMS, EDC, ePRO/eCOA
Laptop on a desk displaying the maptrial Audit Trail interface with user logs, next to text reading "Building a Practical Audit Trail Strategy for eClinical Data," featuring Catchtrial and Maptrial logos.

Most eClinical platforms used today are capable of capturing a comprehensive audit trail. The greater challenge is often not creating the audit trail itself, but establishing a documented approach for reviewing audit trail records, determining who performs that review, and ensuring it focuses on the study’s identified risks.

Regulatory guidance has increasingly focused not only on what an audit trail should capture, but also on how that audit trail should be reviewed. This is reflected in the EMA Guideline on Computerised Systems and Electronic Data in Clinical Trials, which came into effect in 2023, and the FDA’s finalized guidance on electronic systems published in October 2024. Although closely related, audit trail capture and audit trail review serve different purposes and are best considered separately.

Why Audit Trail Review Has Become More Important

Clinical trial data now originates from an increasingly diverse range of systems, making audit trail review more complex than it was in the past. Electronic Data Capture (EDC), electronic Clinical Outcome Assessment (eCOA), Interactive Response Technology (IRT), eConsent, imaging platforms, and other clinical applications each generate their own audit histories. The EMA guideline also explicitly brings clinical trial management systems (CTMS) and centralized monitoring software within its scope.

As a result, evaluating an eClinical platform increasingly extends beyond asking what information the system records. Organizations also need to consider whether those records can be reviewed efficiently across an entire study and whether the review process itself can be documented appropriately.

The practical takeaway: capturing audit trail data is only one part of the picture. Equally important is ensuring that the information can be reviewed in a practical, risk-based, and well-documented manner throughout the study lifecycle.

Part One: What the Regulations Require for the Audit Trail Itself

The regulatory expectations for audit trail content are well established and form the foundation of trustworthy electronic records.

In the United States, 21 CFR Part 11 Section 11.10(e) requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions that create, modify, or delete electronic records. Changes must not obscure previously recorded information, and audit trail documentation must be retained for at least as long as the associated electronic records and remain available for FDA inspection.

The EMA Guideline on Computerised Systems and Electronic Data in Clinical Trials, adopted by the GCP Inspectors Working Group on 7 March 2023 and effective six months after publication, expands on these expectations. Section 6.2.1 states that an audit trail should capture:

  • the initial entry and every subsequent change, including both the previous and current value
  • what was changed, identified by field and data identifiers
  • who made the change, including username, role, and organization
  • when the change occurred, including date and timestamp
  • why the change was made, where a reason for change is required

The guideline also outlines several structural expectations that help maintain the integrity of the audit trail. Changes should be recorded at the individual field level rather than at page level. The audit trail should remain within the system itself, be retained in a human-readable format, and remain protected from unauthorized modification. Routine users should not be able to disable audit trail functionality, while any administrative deactivation should itself be recorded within the audit trail. Audit trail entries should also be protected against alteration, deletion, or unauthorized changes to access permissions.

Two additional considerations often become relevant during platform evaluation. First, audit trail information should be accessible at the individual data point within the live system. Second, the complete audit trail should be exportable as a dynamic dataset to facilitate systematic review across sites and study participants. The FDA’s October 2024 guidance similarly emphasizes protection against modification or disabling, together with retention in a searchable and sortable format.

Part Two: Audit Trail Review and Where ATR Fits

While audit trails capture what happened, audit trail review focuses on understanding whether those records indicate anything that may require attention.

Section 6.2.2 of the EMA guideline states that organizations should establish procedures for risk-based, trial-specific audit trail review. It also explains that the review process should generally be documented, focus on critical data, and be performed proactively throughout the study unless another approach is appropriately justified. Both manual review and technology-assisted review of larger datasets are recognized as valid approaches.

The guideline also outlines the types of findings that audit trail review is intended to help identify, including:

  • missing data
  • indications of potential data manipulation
  • statistical outliers
  • entries recorded at unexpected or inconsistent dates and times
  • unauthorized access
  • situations where additional user training may be beneficial

The FDA’s October 2024 guidance follows a similar risk-based philosophy, recommending that decisions regarding audit trail review be based on the overall risk assessment for the investigation together with the controls already in place. Likewise, ICH E6(R3), issued by the FDA as final guidance in September 2025, describes the review of both data and metadata as a planned activity whose extent and frequency should be documented and proportionate to study risk.

Choosing a Review Model That Fits the Study

Regulatory guidance does not suggest reviewing every audit trail entry. Instead, it encourages organizations to apply a proportionate, risk-based approach that reflects the characteristics of each study.

Few clinical programs would benefit from performing a detailed forensic review of every recorded change. Instead, many organizations combine multiple review approaches depending on study complexity, critical data, available resources, and identified risks.

Review model Typical focus Considerations Alignment with regulatory expectations
Review near database lock Retrospective assessment of audit history before analysis Opportunities for corrective actions at sites may be more limited Less closely aligned with the emphasis on ongoing review
Manual sampling during monitoring visits Selected participants and forms reviewed during scheduled monitoring Coverage depends on sampling strategy and visit frequency Appropriate where the rationale is documented
Risk-based review of critical data Critical variables, endpoints, safety data, and higher-risk sites Depends on a documented risk assessment Closely aligned with current regulatory expectations
Technology-assisted review of exported audit trails Pattern identification across participants and sites Relies on complete exports and suitable analytical capabilities Specifically encouraged for larger datasets

Consider a hypothetical multi-country medical device study where data entry timestamps begin clustering during unusual overnight hours at two participating sites. A review performed shortly before database lock might still identify the pattern, although opportunities for investigation and site-level remediation may be more limited by that stage. By comparison, an ongoing review using exported audit trail data may allow similar patterns to be recognized earlier, when additional training or operational follow-up can still be implemented if appropriate.

The practical takeaway: there is rarely a single review model that suits every study. A documented, risk-based combination of review methods will often provide the flexibility needed to reflect study-specific risks and operational requirements.

How Catchtrial EDC+ and Maptrial CTMS+ Can Support Audit Trail Management

An effective audit trail strategy generally combines two complementary capabilities: reliable capture of audit trail data within the EDC and practical oversight across the broader study.
Within Catchtrial EDC+, the Case Report Form (CRF) module maintains a detailed audit log of patient data modifications and system login activity. Audit trail entries record the username, date and time, affected area, and a description of the action performed.

Regulatory expectation How the platform is designed to support it
Traceable creation and modification Catchtrial EDC+ audit log records user, timestamp, affected area, and action description
Data point level visibility Contextual field menu includes audit trail, SDV, lock, freeze, DMR, and query history
Export for cross-site pattern analysis Audit trail, audit log, lock and freeze history, and SDV/DMR reports can be exported and filtered by site and subject
Integrity of corrections and deletions Power Data Eraser and Restore Form functionality are designed to retain both actions within the historical record
Controlled investigator sign-off Electronic signatures support investigator sign-off in accordance with 21 CFR Part 11
User access governance Role and privilege management across preview and production environments, together with access reporting

On the operational side, Maptrial CTMS+ is designed to support monitoring and study management activities. It includes role-based assignment of freeze and lock actions, exportable audit histories, configurable query permissions at both the role and user level, and scheduled report distribution to defined user groups.

Together, the EDC and CTMS capabilities described above are intended to help organizations maintain both the audit trail itself and the documentation surrounding its review.

Practical Next Steps

Developing an audit trail review strategy often begins with understanding study risk rather than selecting technology.

A practical starting point is to identify the protocol’s critical data, determine which systems generate and maintain that information, and confirm the audit trail capabilities available within each system. From there, organizations can select review checks that reflect their documented risk assessment, drawing on industry resources such as the ATRA recommendations where appropriate.

Equally important is documenting the review process itself, including the review procedure, planned frequency, findings, and any resulting actions. Regulatory guidance consistently emphasizes that performing audit trail review is only part of the expectation; demonstrating that the review took place is also an important component of inspection readiness.

If audit trail capabilities and review readiness are important considerations in your eClinical platform evaluation, we would be pleased to demonstrate how Catchtrial EDC+ and Maptrial CTMS+ are designed to support both aspects. Contact our team for more information or request a demo to explore how these capabilities could fit your clinical trial processes.

Frequently Asked Questions

What is the difference between an audit trail and audit trail review?
An audit trail is the record of changes made to electronic data, while audit trail review is the process of evaluating those records. Regulations such as 21 CFR Part 11 define what an audit trail should capture, including who made a change, what changed, when it occurred, and, where applicable, why. EMA Section 6.2.2 and ICH E6(R3) separately describe the expectation that these records should be reviewed using a documented, risk-based approach focused on critical data.

How much of the audit trail should be reviewed?
Regulatory guidance supports a risk-based approach rather than complete review of every audit trail entry. The FDA’s October 2024 guidance recommends determining the extent of review based on the study’s risk assessment and the controls already in place. Similarly, the EMA guideline emphasizes ongoing review of critical data while allowing organizations flexibility to justify an approach that reflects the characteristics of each study.

What should organizations ask an eClinical vendor about audit trails?
Several practical areas are worth discussing during platform evaluation. These include the information captured for each audit trail entry, whether audit trail records are available at the individual data-point level, how audit trails can be exported for cross-site analysis, and how the system protects audit trail information from modification or deactivation. It is also helpful to understand how the platform manages blinded studies to reduce the likelihood of metadata revealing treatment allocation.

Do CTMS platforms fall under the same audit trail expectations as EDC systems?
Yes, although expectations should be applied proportionately to each system’s intended use. The EMA guideline includes clinical trial management systems (CTMS), pharmacovigilance databases, document management systems, statistical software, centralized monitoring platforms, eCRF, eCOA, and IRT systems within its scope. The extent of audit trail controls and review should generally reflect the criticality of the data managed by each system.

What types of findings are commonly identified during audit trail review?
The EMA guideline identifies several categories that audit trail review is intended to help detect. These include missing data, indications of potential data manipulation, statistical outliers, entries recorded at unexpected or inconsistent times, incorrect system processing, unauthorized access, device or system malfunction, and situations where additional user training may be appropriate. Review may also help identify cases where protocol-defined direct data capture procedures are not consistently being followed.

Primary Regulatory Sources

Go to Top