All blueprints

Data integrity.

Review the event in the work that gave it meaning.

Illustration of a seal following successive procedure versions and the version used for a batch.
A contextual pharmaceutical audit-trail review connecting source events to regulated work and decision impact

Contextual audit-trail review

Scroll to explore the full-size diagram.

How to read this diagram

An event becomes reviewable only when its record, method, user, timing and downstream decision are visible together.

Source
Original event and metadata remain in the authoritative system.
Context
Batch, assay, method and time window explain what the event can mean.
Exception
A changed integration is reviewed against the retained result history.
Impact
Only dependent results and release decisions enter the affected scope.

Figure 1. Review of ASSAY-884 for batch TX-410 places the chromatography data system’s audit-trail export beside Seal’s own audit log for the result. An integration change after an OOS result, with its reason entered 47 minutes later, holds the result, opens DI-2026-026 and places the batch on hold.

Summary

The problem
Audit trails are reviewed as large exported logs, often after the result or batch has been approved, and without the context that shows which events matter.
Seal’s approach
Seal’s own audit log for each record, and the vendor audit-trail exports supplied for the same work, are reviewed beside the record and prioritised by criticality. Required review can gate the result or disposition.
What changes
Consequential changes, such as reintegration after an unexpected result, are seen before approval, and an anomaly can be traced to every record and decision it affects.
Where to start
One chromatographic assay followed from acquisition to archival and retrieval. Book a demo.

1Review the evidence while it can still change the decision.

An audit-trail report shows that events were recorded. Data integrity asks more: whether the evidence used for a GxP action is complete, contemporaneous, attributable, preserved in its original context and reviewed at the point where it can still influence the decision.¹

Seal connects the regulated activity, record, source system, audit event, user, role, reason, before-and-after values, review obligation, exception, investigation and final decision. Reviewers assess what changed and what it meant, rather than thousands of isolated technical messages.

1.1Why teams choose Seal for audit trail review

A periodic audit-trail export can leave reviewers facing thousands of technical events from LIMS, MES, QMS, SDMS and equipment systems, read after the result or batch has already been approved. Because the batch, test, method, specification, user, instrument, deviation and disposition are related records in Seal, each record carries its own audit log, and the vendor audit-trail export for the same work, from a chromatography data system for example, is attached and reviewed beside it. A required review can hold the decision until it is done. That addresses two common failures: reviewing an enormous log without context, and approving a record without reviewing the events that matter. The review criteria are themselves versioned configuration, so a site can refine what it treats as critical from its own findings without losing the basis of earlier reviews. If the need is only immutable file storage, an SDMS may be sufficient.

Table 1. Where contextual audit trail review differs from reviewing an exported log.
Exported audit logSeal
Unit of reviewThousands of system messagesEvents grouped by the regulated work and decision they affect
TimingA periodic log review, often after releaseA review gate on the result, batch step or disposition
ContextLooked up separatelyUser, role, record state, reason, related deviation and downstream use shown together
ImpactTraced by handAffected records, batches and decisions found through links

2Map the regulated records and where meaning can be lost.

The programme starts by identifying the manufacturing, laboratory, quality and warehouse records that support product quality or a regulated decision. Each record class has its authoritative system, owner, creation path, static or dynamic form, retention, review requirement and criticality.

For each class, Seal maps acquisition, transfer, processing, calculation, review, approval, reporting, archival and retrieval. Interfaces, local instrument computers, exports, spreadsheets and manual transcriptions are part of that flow. The map shows where metadata can separate from content, where manual intervention occurs and which copies are authoritative; a clean final report does not remove the transformations that produced it.

Validation and periodic review use the same map. A new interface, instrument software upgrade or report configuration identifies the affected records, controls and tests.

3Let criticality set the review design.

Review depth depends on the decision the record supports, the chance of detecting an improper change elsewhere, the opportunity to alter or omit data, the strength of system controls and the consequence for patient or product. The assessment defines which audit trails need event-level review, when, by whom and with what context.

Risk-based does not mean optional. It means the review obligation and its depth are justified against the actual record and process.

4Review audit trails beside the record, in context.

A batch step, analytical sequence, calculation, specification decision or disposition should be reviewed with its relevant audit trails, as the rest of the record is reviewed.² Seal presents the executed record and its history together, with critical changes surfaced before approval. Completing the required review can be configured as a gate on the result or decision, so a generic monthly log is not signed while the batch is released elsewhere.

Context separates normal work from consequential change. Reprocessing chromatography after an approved method update differs from changing integration after an unexpected result; voiding a duplicate sample differs from deleting the only failing preparation. Seal resolves the user, role, record state, workflow step, reason, related deviation, result history and downstream use. Rules can prioritise changes to results, calculations, specifications, methods, identities, timestamps and permissions.

5Keep the original and every consequential version visible.

Before-and-after values, timestamps, electronic signatures, reasons and source references are preserved, and signatures stay linked to the records they sign.³ Where the source system produces its own audit trail, that trail stays authoritative in the source system; the exported report is attached to the Seal record and reviewed beside it.

Reprocessing, reintegration, recalculation, repeat testing, result invalidation and report regeneration remain distinguishable, so the complete data behind a reported result can be reconstructed.⁴ A current value does not obscure how the record reached that state.

Attributable
The named user, API key or trigger on each entry.
Legible
The original file, kept and previewed in the record.
Contemporaneous
The capture time, recorded with each entry.
Original
The source file and its source reference.
Accurate
Each change as a new version, linked to the earlier ones.
+ Complete, consistent, enduring, available
The audit log and change history on the record.
Figure 2. ALCOA+ applied to what Seal keeps with each record: the user, API key or trigger behind each entry, the original file, the capture time, the source reference and each change as a linked version

Dynamic records stay dynamic. Chromatograms, spectra, images and configurable calculations can need more than a PDF. The plan identifies which native data, metadata, methods and viewing capability must remain available to reconstruct the activity. Static renditions can support inspection and long-term access, labelled as renditions and linked to the authoritative record.

6Triage exceptions, then investigate without losing the original concern.

Rules can classify expected system events, events requiring review, known technical noise and potential integrity signals. Suppression rules are versioned, justified, tested, approved and periodically challenged against the events they omit. The review queue records why each event was accepted, linked, escalated or found not applicable, and repeated low-severity exceptions can form a trend even when no single event warrants investigation.

An integrity investigation starts with the signal and the systems, users, records, time window, products and decisions potentially affected. Access logs, source files, backups, interviews and configuration attach without replacing the original concern, and scope changes keep their evidence and approval. The conclusion distinguishes data error, procedural failure, control weakness, intentional behaviour, system defect and inconclusive evidence, without treating “human error” as an endpoint.

A single anomalous event can propagate through records, batches, reports and released decisions unless impact is traced through relationships
Figure 3. A single anomalous event can propagate through records, batches, reports and released decisions unless impact is traced through relationships

7Test access and the control system periodically.

Access review asks what a role can do, not what its name implies. Accounts, privileges, administrator activity, shared-account exceptions and service accounts connect to systems and regulated functions. Conflicting abilities, such as executing and approving, or administering and reviewing audit trails, can be identified and assessed; emergency access has a bounded duration and a retrospective review.

Time and identity must survive system boundaries. Audit evidence records the time source, time zone, originating system and transferred identity, so reviewers can distinguish when an event occurred, arrived and was committed. A transfer by a service account keeps the person or upstream process responsible for the source action.

Periodic review combines access certification, audit-trail completion, exception patterns, deviations, backup and restore evidence, interface failures, configuration changes and archival retrieval. It asks whether the data flow and control design remain valid and whether the actual volume can be reviewed with the assigned resources. Migration and archival are treated as regulated transformations: record counts alone do not show that content and meaning survived, and retrieval is demonstrated with representative difficult records.

Source systems remain authoritative for native evidence: instrument software for acquisition data and vendor audit trails, historians for dense process history, identity systems for authentication. Seal governs the record map, review obligations, context, exceptions, investigations and impact across them, with source links and verified copies explicit.

8Prove one difficult record end to end.

Start with a chromatographic assay and follow it from sample and sequence through acquisition, processing, reintegration, calculation, result review, audit-trail review, OOS assessment, batch disposition, archival and later retrieval.

Include a deleted injection, a trial sequence, a changed processing method, clock drift, a shared-account concern, a late reason entry and a migrated historical record. The programme is credible when each event can be interpreted in context and every affected decision can be found.

References

  1. 1FDA, Data Integrity and Compliance With Drug CGMP: Questions and Answers, guidance for industry (2018): complete, consistent and accurate data should be attributable, legible, contemporaneously recorded, original or a true copy, and accurate (ALCOA). FDA
  2. 2FDA, Data Integrity and Compliance With Drug CGMP: Questions and Answers, guidance for industry (December 2018), questions 7 and 8: personnel responsible for record review under CGMP should review the audit trails that capture changes to data associated with the record as they review the rest of the record, at the review frequency CGMP sets for that data or, where none is specified, at a frequency set by risk assessment. FDA
  3. 321 CFR 11.70, Signature/record linking: electronic and handwritten signatures executed to electronic records must be linked to those records so they cannot be excised, copied or otherwise transferred to falsify a record. eCFR
  4. 421 CFR 211.194, Laboratory records: laboratory records must include complete data derived from all tests necessary to assure compliance with established specifications and standards. eCFR

AOperating model

Included in this blueprint

  • Contextual audit trail review
  • Risk-based review rules
  • Access and privilege certification
  • Impact and investigation

Connected across Seal

BCapabilities

Table B.1. What the Pharmaceutical Data Integrity and Audit Trail Review blueprint covers. Linked capabilities are blueprints of their own.
CapabilityWhat it covers
Regulated record inventoryRecord classes, source systems, transformations, owners, retention, criticality and review obligations form one controlled data map.
Contextual audit trail reviewCritical events appear beside the batch, test, method, calculation, specification and decision they can affect.
Risk-based review rulesVersioned rules define event populations, priority, context, timing, suppression, escalation and required approval by record class.
Integrity exception triageUnexplained changes, omitted data, disabled controls, access anomalies, late actions and overdue reviews enter one queue for assessment.
Access and privilege certificationAccounts, roles, conflicting capabilities, administrator actions, emergency access, service identities and dispositions remain reviewable.
Impact and investigationSignals expand through systems, records, users, batches, reports and release decisions with evidence-backed scope changes.
Migration and archival assuranceMappings, transformations, counts, exceptions, integrity tests and retrieval checks show that content and meaning were preserved, and the approval is recorded.
Inspection reconstructionStart from a result, record, user, instrument, batch or decision and retrieve its original evidence, history, reviews and actions.

CConnected records

Entity hierarchy
What it records
Kind
Regulated Record Class
Authoritative system, data flow, dynamic content, criticality, retention and review obligation.
entity
Chromatography Record Class
Sequence, injections, methods, raw files, processing, results, metadata and audit-trail pattern.
template
ASSAY-884 / TX-410
Dynamic assay record containing original and reprocessed evidence for batch TX-410.
record
Source System
Application, instrument, controller, interface, archive or service producing or transforming evidence.
entity
Audit Event
Action, actor, time, record, before-after state, reason, signature and native source reference.
entity
Review Rule
Risk-based event scope, timing, context, prioritisation, suppression and escalation logic.
entity
Result-Critical Event Rule
Prioritises changes to sequences, processing, integration, calculations, results and reportable state.
template
ATR-LAB-07 v04
Effective laboratory review rule applied before result approval.
record
Audit Trail Review
Population, events, context, reviewer determinations, exceptions, evidence and approval.
entity
Pre-Approval Audit Review
Record-linked review population, critical events, determinations, exceptions and signature.
template
ATR-ASSAY-884
Completed review retaining a reintegration exception and approved rationale.
record
Integrity Exception
Unexplained, unauthorised, anomalous, incomplete or overdue event requiring assessment.
entity
Integrity Investigation
Concern, scope, evidence, causal analysis, affected records, conclusions and actions.
entity
Laboratory Integrity Investigation
System, user, record, time, product, impact, root cause, CAPA and retrospective scope.
template
DI-2026-026
Investigation into an integration change after an OOS result, with its reason entered late, and the affected result population.
record
Access Certification
Accounts, roles, privileges, conflicts, administrator activity, review and disposition.
entity
Quarterly Privileged-Access Certification
System scope, effective entitlements, conflicts, administrator actions, reviewer independence, exceptions and closure.
template
ACCESS-LAB-Q2-2026
Certification that removed one orphaned administrator account before quarter close.
record
Data Migration
Population, mappings, transformations, tests, reconciliation, exceptions and approval.
entity
GxP Record Migration
Field and metadata mapping, transformation, verification, exception, approval and retrieval pattern.
template
Figure C.1. Record types, templates and the relationships between them in this blueprint.

DQuestions and answers

What is pharmaceutical data integrity software?

It governs how GxP records are created, changed, reviewed, preserved, investigated and used. The aim is that each decision can be reconstructed from evidence that is attributable, contemporaneous, original, accurate, complete and available.

What is audit trail review?

It is the documented assessment of relevant record changes and system events in the context of the regulated work they affect. The review records the reviewer’s determination, any exceptions and escalation, and approval.

Does every audit trail event require manual review?

No. The review design should be justified by record criticality, control strength, ability to detect change elsewhere, and product or patient consequence. Required events and frequencies remain explicit and approved.

How does Seal avoid overwhelming reviewers?

Review is organised around the batch, test, method, result, workflow state and downstream decision, not a single exported log. Seal’s audit log sits on each record, vendor audit-trail exports are attached beside it, and the versioned review rules set what is prioritised and are periodically challenged.

Does Seal replace instrument audit trails?

No. Vendor systems retain native acquisition data and audit trails. Seal preserves source references or verified copies and adds regulated context, review workflow, exceptions, impact and approval.

Can audit trail review gate result or batch approval?

Yes. A required review can be attached to a laboratory result, production record, master-data change or disposition and configured so it must reach an acceptable state before the dependent decision.

How are reintegration and reprocessing handled?

The original data and result remain visible. Each later processing version retains method, parameters, user, time, reason, authorisation, output, review and relationship to the reportable result.

Can Seal manage periodic user-access review?

Yes. Accounts, roles, effective privileges, conflicts, administrator activity and employment or role state can be certified by system and function. Reviewer decisions, removals and exceptions are retained.

How are data-integrity investigations scoped?

Scope begins with systems, users, records, times, products, studies and decisions potentially affected. Every expansion or reduction retains evidence, rationale, uncertainty and approval.

Does Seal support data migration validation?

Yes. It manages source and target populations, field and metadata mappings, transformations, sampling or full verification and reconciliation. Exceptions, approval and representative retrieval tests are recorded with the migration.

What does ALCOA+ mean in the system?

Each ALCOA+ principle becomes a testable control: attribution, legibility, contemporaneous capture, preservation of originals, accuracy, completeness, consistency, endurance and availability. The processes that verify those controls are recorded too.

What should the first implementation prove?

Follow one difficult dynamic laboratory record through acquisition, changes, contextual audit review, exception, investigation, batch impact, archival and retrieval—including technical and procedural failure paths.

See your process in Seal.

Bring a procedure or a recurring problem. See how your team can use Neil to build the workflow, investigate the results and improve the next version.

Book a demo