Under 21 CFR Part 11, an audit trail must be computer-generated and time-stamped, record the operator and the action, and keep earlier values rather than overwriting them. EU GMP Annex 11 expects audit trails based on risk, and the 2025 draft revision broadens their scope.
Why it matters for labeling
A useful audit trail for label verification shows which version was compared against which approved master, what deviations were found, how each was resolved, and who signed off, all tied to specific document versions. A trail that only records that a file was opened, or that something was approved, doesn't answer an inspector's real question: was this exact version reviewed?
Common mistakes
- Logging access but not changes
- A trail that users can edit or switch off
- Review evidence spread across email and shared drives, so no single trail exists
- Records that aren't tied to a specific document version