Audit Trail Review In Pharma Is The New FDA Finding, Not Existence
FDA inspectors now ask who reviewed the audit trail, not just whether one exists, here's what's driving Audit Trail Review In Pharma citations.


The Shift Nobody Announced
For years, having an audit trail was treated like a badge of compliance. If a system generated one, quality teams assumed the box was checked. That assumption no longer holds.
FDA investigators are not asking, "Does your system record changes?" They are asking, "Who looked at those records, how often, and what did they do when something looked wrong?" A functioning audit trail that nobody reviews is now treated the same as no audit trail at all — sometimes worse, because it shows the company had the information and did not act on it.
This is a quiet but real change in inspection behaviour, and it is showing up directly in warning letters.
Existence vs Review: Why the Difference Matters
Audit trail existence means the system technically captures who did what and when within an electronic record. Most validated GxP systems have had this capability for years under 21 CFR Part 11 and EU GMP Annex 11.
Audit trail review means a trained person, on a defined schedule, opens the log, checks it against expected activity, and documents any unusual activity, including deleted results, reprocessed runs, backdated entries, or repeated failed logins.
The gap between the two is where the most recent citations are landing. A company can pass a system validation audit and still fail an inspection because no one in the quality unit ever looked at the trail that the validated system was faithfully producing.
What the Enforcement Data Shows
FDA's Centre for Drug Evaluation and Research (CDER) issued 303 warning letters to drug and biologics manufacturers in fiscal year 2025 (FY2025), compared with 190 in FY2024 — a roughly 59% year-over-year increase, confirmed by both FDA officials and independent trackers of the FDA warning letter database. This is one of the sharpest single-year jumps in recent memory.
Data integrity citations remain tied to this trend. Industry analyses of FY2025 letters put data integrity findings at around 15% of all letters overall, but this climbs sharply by geography — roughly 60% for sites in India, versus about 21% for China and 10% for U.S. sites. Within these citations, audit trail review (not generation) is increasingly named as the specific gap.
A simple way to read this: the record-keeping technology has largely caught up across the industry. The review discipline around that technology has not.
Audit trail review is just one piece of the bigger warning letter surge, see the broader causes and prevention strategies pharma teams need.
→ Read: FDA Warning Letters: Causes, Risks & Prevention
Real Findings That Prove the Pattern
Recent warning letters describe a consistent story, even across different companies and product types:
- A manufacturer's production and quality unit was expected to review electronic raw data and audit trails for filter integrity testing. They did not. Only passing results were printed and retained; failing runs were not recorded.
- An OTC manufacturer's lab software allowed only a single "System Administrator" role, with shared logins and no independent audit trail review at any defined interval.
- Out-of-specification results were repeatedly set aside without formal investigation, while the audit trail that could have shown the pattern sat unreviewed.
In each case, the system was capable of producing a complete, accurate audit trail. The failure was organisational: no one was assigned to look at it, on what schedule, or with what escalation path.
Existence vs Review at a Glance
Aspect | Audit Trail Existence | Audit Trail Review |
|---|---|---|
What it proves | The system can log user actions, timestamps, and changes | Someone actually checked those logs and acted on findings |
Regulatory basis | 21 CFR Part 11, EU GMP Annex 11 (system design) | GMP quality oversight expectations (211.22, 211.68, Annex 11 review clauses) |
Typical evidence | Validation report, system specification, IQ/OQ/PQ | Review SOP, review logs, sign-offs, and deviation records tied to trail anomalies |
Common failure mode | Rare — most modern systems capture this by default | Frequent — no defined cadence, no assigned owner, no documented outcome |
Inspector's question | "Does the system record this?" | "Who reviewed this, when, and what did they find?" |
Consequence of missing | System non-conformance, remediation | Systemic quality unit failure — treated as a control gap, not a paperwork gap |
Why AI and Digital Systems Raise the Stakes
As pharma manufacturing and lab environments adopt AI-assisted tools for batch record review, deviation triage, or automated anomaly flagging, audit trail review becomes even more central, not less.
A few reasons this matters for the AI & Digital pillar specifically:
- AI output is not automatically a controlled record. If an AI tool suggests a conclusion or flags an anomaly, that output still requires a documented human review before it becomes part of the official quality record. Regulators have already cited this gap in at least one recent warning letter involving AI-generated documentation.
- More digital systems mean more audit trails, not fewer. Electronic batch records, LIMS, environmental monitoring systems, and AI-assisted QC tools each generate their own trail. Without a coordinated review cadence across systems, gaps multiply rather than shrink.
- Automation can mask review gaps. A dashboard showing "audit trail: enabled" can create false confidence. Enabled is not the same as reviewed.
- The practical implication: digital transformation projects in pharma need a review governance plan built in from day one, not bolted on after a system goes live.
Audit trails are only as strong as the validated systems generating them, CSV and CSA both shape whether review actually holds up under inspection.
→ Read: Computer System Validation (CSV) vs Computer Software Assurance (CSA)
Building a Real Audit Trail Review Program
Use this as a starting checklist for a quality unit self-assessment:
- A written SOP defines what "audit trail review" means for each GxP system in use
- Review frequency is defined and risk-based (not "as needed")
- A specific role — not "IT" or "whoever is free" — owns each system's review
- Reviewers are trained on what an anomaly looks like in that specific system
- Review outcomes are documented, even when nothing unusual is found
- Anomalies trigger a formal deviation or investigation, with a closed-loop CAPA
- Shared logins and generic admin accounts are eliminated wherever possible
- AI-assisted outputs have a documented human review and sign-off step
- Review records are retrievable quickly during an inspection, not reconstructed afterwards
- A quality unit that can answer "show me the last three audit trail reviews for this system, and what happened as a result" is in a fundamentally different position than one that can only say the system logs everything.
Key Takeaways
- Warning letters rose sharply in FY2025, and data integrity remains one of the most-cited categories.
- The specific citation language has shifted: inspectors increasingly name the absence of review, not the absence of the trail itself.
- Most GxP systems already generate complete audit trails — the gap is organisational discipline, not technology.
- AI and digital tools raise the bar further, since they add more systems to review and introduce new categories of output needing human sign-off.
- A documented, risk-based review cadence with clear ownership is now a baseline expectation, not a best practice.
FAQs
Q1. What is the difference between audit trail existence and audit trail review?
Existence means the system technically records user actions and changes. Review means a trained person regularly checks those records and documents the outcome.
Q2. Why did FDA warning letters increase so much in FY2025?
CDER issued 303 warning letters in FY2025, up from 190 in FY2024, a jump linked to an expanded inspection focus, unapproved drug products, and ongoing data integrity gaps across sites.
Q3. Is audit trail review required under 21 CFR Part 11?
Part 11 sets requirements for how electronic records and signatures must be captured and secured. The expectation to actively review those records comes from broader GMP quality oversight requirements, not Part 11 alone.
Q4. Does having a validated system protect against audit trail findings?
No. Validation confirms the system works as designed. It does not confirm that anyone is reviewing what the system captures, which is where most recent citations occur.
Q5. How often should audit trails be reviewed?
There is no single fixed interval in regulation. Review frequency should be risk-based, documented in an SOP, and consistently followed — with evidence that it happened.

Reporting on the science, business and regulation shaping the pharmaceutical industry.



Discussion