Audit trail and review

An Audit Trail Designed to Support 21 CFR Part 11

ResearchGuru EDC records who did what, to which field, when and why, in a trail that cannot be edited, and puts queries, source data verification and electronic signatures beside the data.

Regulators and auditors ask the same questions of any electronic record: is it attributable, is it original, and can you show what changed? The audit trail and review module is designed to support the technical controls in 21 CFR Part 11 and good clinical practice. Your own procedures, training and validation complete the picture, and we supply documentation to help with them.

Discuss your study

What the trail records

Every entry, change and deletion, at field level

Each line in the trail says when something happened, who did it and in what role, what the event was, and what changed. The trail starts when the study is protected and stays on for the life of the project.

Field-level history

The original value, the new value, the user and the time are kept for every field, and any field's full history opens from the record.

Reason for change

A saved value cannot be changed without a stated reason, so the trail explains each correction as well as recording it.

Time in UTC and local time

Entries are stamped by the server in UTC and shown in local time, with a running entry number.

Append-only and hash-chained

Each entry contains a SHA-256 hash of itself and of the entry before it. Altering, removing or inserting an entry breaks the chain.

System events

Sign-ins, failed sign-ins, interface access, exports and permission changes are logged alongside the data changes.

Certified copy

The trail can be filtered by record, item, user, event or date, exported as CSV, or produced as a certified copy for inspection.

Review workflow

Queries, verification and signatures in one place

Recording changes is half of the requirement. The other half is showing that the data were reviewed. The same module carries the review steps, and each one is written to the trail.

Review tools

  • Queries raised, answered and closed
  • Edit checks that raise queries automatically
  • Source data verification by field or record
  • Electronic signatures that require the user name and password again
  • Study lock after data cleaning
  • Published eCRF versions, with a flag when the form has changed
  • Double data entry with field-by-field comparison
  • Imports with a stated reason

Controls around the trail

Part 11 also expects the system around the records to be controlled. These pages sit beside the trail and produce their own evidence.

Access and roles

Who may do what, and proof that it was reviewed.

  • Named user accounts, never shared
  • Study roles for investigators, site staff, monitors, data managers and auditors
  • Read-only access for auditors
  • Periodic user access review, signed and stored
  • Every grant and revoke recorded
Integrity and continuity

Evidence that the trail is complete.

  • Verification of the whole hash chain on demand
  • Checkpoints kept off the server and confirmed later
  • Nightly backups of the trail and study data
  • Self-test of the module before it will activate
  • A validation package for your own records

The controls, documentation and responsibilities that apply to each study are confirmed in the service agreement. Sponsors and sites remain responsible for their own procedures and regulatory obligations.

Worked example (dummy data)

The audit trail on a 1,000-record study

A fourteen-minute video walks through the module on our demonstration case-control project: the overview, the audit log, a field's history, a deletion, queries, edit checks, eCRF versions, roles, the integrity check, access review and backups.

The project holds dummy data only, and the addresses in the system log are masked in the recording.

Frequently asked questions

Audit trail and Part 11: common questions

Something else? Get in touch and a senior researcher will answer.

Compliance belongs to a study and its sponsor, not to software alone. ResearchGuru EDC is designed to support Part 11: it provides the technical controls, and we supply system and validation documentation to support your own procedures, training and validation.

The trail is append-only. Entries cannot be edited or removed through the application, and the hash chain shows if the underlying table has been altered. Our procedures require the trail to stay active for the life of the study.

The deletion is recorded as an event in the trail, with the user, the time and the reason, and the record's earlier history stays in the trail.

Yes, where the study requires it. Signing asks for the user name and password again and is recorded in the trail with the record it applies to.

Yes. An auditor role gives read-only access to the trail and review pages for the projects you choose.

The module is designed to support GCP expectations for attributable, contemporaneous and traceable records. As with Part 11, your procedures and oversight are part of meeting them.

Ask us about the controls your study needs

Send us your protocol and study requirements. We'll review them and come back to you with:

Start your enquiry

Or email admin@edcstat.com · call +44 7484 816484

  • An initial database-build assessment
  • Any questions or recommendations
  • A proposed delivery schedule
  • A clear scope of work
  • A project quotation