Explore recent issues of Contract Pharma covering key industry trends.
Read the full digital version of our magazine online.
Stay informed! Subscribe to Contract Pharma for industry news and analysis.
Get the latest updates and breaking news from the pharmaceutical and biopharmaceutical industry.
Discover the newest partnerships and collaborations within the pharma sector.
Keep track of key executive moves and promotions in the pharma and biopharma industry.
Updates on the latest clinical trials and regulatory filings.
Stay informed with the latest financial reports and updates in the pharma industry.
Expert Q&A sessions addressing crucial topics in the pharmaceutical and biopharmaceutical world.
In-depth articles and features covering critical industry developments.
Access exclusive industry insights, interviews, and in-depth analysis.
Insights and analysis from industry experts on current pharma issues.
A detailed look at the leading US players in the global pharmaceutical and BioPharmaceutical industry.
Browse companies involved in pharmaceutical manufacturing and services.
Comprehensive company profiles featuring overviews, key statistics, services, and contact details.
A comprehensive glossary of terms used in the pharmaceutical and biopharmaceutical industry.
Watch in-depth videos featuring industry insights and developments.
Listen to expert discussions and interviews in pharma and biopharma.
Download in-depth eBooks covering various aspects of the pharma industry.
Access detailed whitepapers offering analysis on industry topics.
View and download brochures from companies in the pharmaceutical sector.
Explore content sponsored by industry leaders, providing valuable insights.
Stay updated with the latest press releases from pharma and biopharma companies.
Explore top companies showcasing innovative pharma solutions.
Meet the leaders driving innovation and collaboration.
Engage with sessions and panels on pharma’s key trends.
Hear from experts shaping the pharmaceutical industry.
Join online webinars discussing critical industry topics and trends.
A comprehensive calendar of key industry events around the globe.
Live coverage and updates from major pharma and biopharma shows.
Find advertising opportunities to reach your target audience with Contract Pharma.
Review the editorial standards and guidelines for content published on our site.
Understand how Contract Pharma handles your personal data.
View the terms and conditions for using the Contract Pharma website.
What are you searching for?
Why one of FDA’s most misunderstood rules can help ensure data integrity and compliance, and help in root cause analysis
September 8, 2014
By: Carol Brandt
GMP Compliance Consulting, NNE Pharmaplan
The audit trail is an integral requirement of an electronic record, ensuring the validity and integrity of the record and the link between any electronic signature and the record associated with it. Its regulatory requirements are fairly straightforward, but the benefits it offers are often misunderstood. Audit trail reports can be reviewed to identify system security issues, errors in sequencing of activities, investigation of errors and unexpected events, training issues, and data integrity events. They can also add supportive evidence to a contract vendor audit. Audit trail report reviews can significantly benefit the regulated environment manufacturer, providing detailed accounts of the activities performed on a computer and the status of the electronic records. Before computers were commonly used in the regulated environment, paper records universally documented the activities and events, as they happened, time/date and by whom. In the event that a change is made to the record, Good Documentation Practices (GDP) require that the initial entry be lined out but not obscured, the change entered, signed, dated and in some cases a reason for the change is also documented. The act of storing or saving data/information to media (iincluding disks, flash drives, floppies, and CD’s) constitutes creation of an electronic record, which in the early 1990’s, were unregulated and subject to uncontrolled manipulation. In 1991, the pharmaceutical industry requested that the FDA define the requirements by which paperless systems could be used under the current cGMPs (Good Manufacturing Practices). With the introduction of the routine use of computers in the regulated industry, the Regulatory Agencies became aware that it was possible to create, modify and delete data without the same controls required of paper records. These issues, along with the industry requests, spurred an Agency task force in 1992 and the publication of the final rule to control electronic records, 21 CFR (Code of Federal Regulations) Part 11, “Electronic Records; Electronic Signatures” (Part 11) in 1997.1,2 Industry was Unprepared for Part 11 Response from the industry was that additional time was needed to be able to comply with the ruling, and the FDA (Food and Drug Administration) delayed its enforcement until 1999. Many pharmaceutical manufacturers were unprepared, and rushed to try to understand Part 11 and assess their computers and compliance, by preparing Part 11 Site Plans and executing remediation activities. One of the major issues at that time was that the software vendors hadn’t planned for the ruling either, and although basic security features were built into many software packages, audit trails were not, or if they were, they were not fully compliant with the requirements. Even many of the software vendors provided limited security options such as one User Name/Password for anyone operating the system. “Legacy systems” were defined by the FDA as those in effect before 1997, and were initially exempt from the ruling. However, if changes were made to the systems after the ruling became effective in 1997, those systems were subject to compliance with Part 11. “Certain older electronic systems may not have been in full compliance with Part 11 by August 1997 and modification to these so called “legacy systems” may take more time. Part 11 does not grandfather legacy systems and FDA expects that firms using legacy systems are taking steps to achieve full compliance with Part 11.”3 Besides regulations around the use of the audit trail in electronic records, Part 11 details requirements for the electronic signature, and validation of the computer system. The industry had a difference of opinion on how to deal most effectively with Part 11; some took a risk-based approach and tried to comply with their Site Remediation Plan over time; where they could, others discontinued the use of electronic signatures and records, and reverted to a paper solution. The operational benefit of validating computer systems has been realized and accepted by the industry, however, general fear of the regulation and how to comply still exists in the pharmaceutical industry today, because the audit trail requirements are largely misunderstood. Even to date, there are numerous firms that are unable to readily print audit trails from their GMP computer systems and have never looked at the audit trail reports. Audit Trail Requirements “Audit Trail means…a secure, computer generated, time-stamped electronic record that allows reconstruction of the course of events relating to the creation, modification, and deletion of an electronic record.”4 FDA’s “Guidance for Industry—Computerized Systems Used in Clinical Trials,”4 summarizes the audit trail requirements: 1. “Section 21 CFR 11.10(e) requires persons who use electronic record systems to maintain an audit trail as one of the procedures to protect the authenticity, integrity, and, when appropriate, the confidentiality of electronic records. a. Persons must use secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records. A record is created when it is saved to durable media, as described under “commit” in Section II, Definitions. b. Audit trails must be retained for a period at least as long as that required for the subject electronic records (e.g., the study data and records to which they pertain) and must be available for agency review and copying. 2.Personnel who create, modify, or delete electronic records should not be able to modify the audit trails. 3.Clinical investigators should retain either the original or a certified copy of audit trails. 4. FDA personnel should be able to read audit trails both at the study site and at any other location where associated electronic study records are maintained. 5. Audit trails should be created incrementally, in chronological order, and in a manner that does not allow new audit trail information to overwrite existing data in violation of §11.10(e).”4 Title 21 CFR Part 11, Subpart B “Electronic Records”, §11.10 (e) Controls for Closed Systems, describes the requirements for the audit trail as follows: “Use of secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records. Record changes shall not obscure previously recorded information. Such audit trail documentation shall be retained for a period at least as long as that required for the subject electronic records and shall be available for agency review and copying.”1 Therefore, the audit trail applies not only to events recorded in the electronic record, but events associated with electronic signatures that are applied to the electronic record in the appropriate sequence (review, approval, signature, time/date). This is no different than the paper record requirements described in the History Section above. Changes, deletions, signatures and time/date stamps are applied securely to the electronic record just as they would be to the paper record, which is the purpose of the audit trail. Audit Trail Use and Benefits Software vendors supplying packages to the regulated industry are, for the most part, now providing Part 11 “compliance capable” software. This means the system contains the code to make the software configurable to be Part 11 compliant, not that it’s automatically compliant. For instance, the basic “off the shelf” software has to be configured for certain end-user security access level requirements and to require electronic signatures based on the function. If system access isn’t limited by design, i.e. the manner in which the user configures it, and the User ID and password aren’t both unique to the individual, the system is not compliant. For some more complex systems, such as ERP (Enterprise Resource Planning) systems that manage finances, warehousing, product release, etc., the audit trail can be enabled or disabled for individual transactions (functions) and associated data tables, by customizing the software configuration. If the audit trail is disabled for any GMP functions or for a function requiring electronic signatures (such as product release), the system is not Part 11 compliant. The audit trail can provide important information to the pharmaceutical firm to track system access, what activity occurred, sequence of events, by whom, and by when. (For a flow chart showing a typical audit trail, see Figure 2). Ensuring data Integrity Data integrity is the foundation of regulatory compliance, and often found lacking in FDA 483’s and Warning Letters. However, it can be established by the history in the audit trail. Firms that have implemented a routine review of audit trail reports benefit from having evidence that procedures are being followed and data integrity confirmed. For computer systems capable of producing an audit trail report (also required by Part 11), a routine review of the report can identify security, training and integrity issues immediately. For example, Figure 1 is an example of a lab audit trail report which identifies several flaws in the analysis performed. Potential issues with the assay are:
Enter your account email.
A verification code was sent to your email, Enter the 6-digit code sent to your mail.
Didn't get the code? Check your spam folder or resend code
Set a new password for signing in and accessing your data.
Your Password has been Updated !