Skip to main content

Award-Winning eClinical Platform Powered by AI | Clinion

Insights / Blog / EDC

Audit Trail Review in Clinical Trials: From Data Changes to Risk Signals

Audit Trail Review in Clinical Trials | Risk-Based ATR

On this Page

  • Summary
  • What Is Audit Trail Review in Clinical Trials?
  • Why Audit Trail Review Is Becoming More Important
  • What Do Regulators Expect from Audit Trail Review?
  • What Should Be Included in Audit Trail Review?
  • What Can Audit Trail Data Reveal About a Trial?
  • When Does an Audit Trail Change Become a Risk Signal?
  • How Should Common Audit Trail Risk Signals Be Interpreted?
  • How Risk-Based Audit Trail Review Works
  • What Happens When a Potential Risk Signal Is Identified?
  • Who Should Review Audit Trails and How Often?
  • Audit Trail Data Must Be Reviewable Before It Can Be Analyzed
  • How Analytics and AI Can Support Audit Trail Review
  • Building an Effective Audit Trail Review Process
  • How Audit Trail Review Supports Inspection Readiness
  • External References
Google Preferred Source
Google Preferred Source

Summary

Audit trail review (ATR) in clinical trials is the systematic, risk-based examination of audit trail data and relevant metadata to identify changes, patterns, or activities that may require further investigation. 

Clinical trial systems continuously record how data are created, corrected, reviewed, queried and updated. Over the course of a study, this can generate a substantial history of activity across subjects, sites, visits, forms, fields and users. The audit trail preserves that history, but simply having the history available does not tell reviewers which activity matters. A corrected value may be completely routine. The same type of correction occurring repeatedly across critical fields, at one site, or after data have already been reviewed may deserve closer attention.

This is where audit trail review becomes important. The objective is to examine audit activity in context and identify individual events or patterns that may require further review.

What Is Audit Trail Review in Clinical Trials?

An audit trail is the electronic history of activities associated with trial data and computerized systems. It allows the original information and subsequent changes to be reconstructed, including information about who performed an action, when it occurred, and, where applicable, why the change was made.

ICH E6(R3) also places audit trails within the broader concept of trial metadata. It states that audit trails and logs should be interpretable and capable of supporting review, and that procedures should exist for reviewing trial-specific data, audit trails and other relevant metadata.

Audit Trail

Audit Trail Review

Records activity associated with trial data

Examines that activity in context

Preserves initial entries and subsequent changes

Looks for relevant patterns, exceptions, or unusual activity

Provides traceability

Supports investigation and oversight

Helps reconstruct what happened

Helps identify activity that may require further assessment 

Operates continuously within the system

Is performed according to a planned review approach

The distinction is important because clinical data naturally change during a trial. Queries are answered, incorrect entries are corrected, missing information is completed, and data are updated as part of normal study conduct. Audit trail review helps distinguish this expected activity from patterns that may indicate a data quality, process, training, access, or oversight issue.

Why Audit Trail Review Is Becoming More Important

Modern clinical trials generate large volumes of audit trail data across subjects, sites, users, visits, forms, and systems. Reviewing these records individually can quickly become impractical, especially in larger or more complex studies.

The challenge is interpreting that activity in context, particularly as the volume of audit trail data grows. 

For example, a site with more data changes may simply have enrolled more subjects. A user with higher activity may be managing a greater workload. A value changed after review may have been updated for a valid reason, such as new source information or a query response.

This means that the number of changes alone is not enough to determine whether something requires attention.

Effective audit trail review looks at activity alongside factors such as data criticality, timing, site or subject volume, user role, and stage of review. This helps reviewers distinguish expected study activity from patterns that may warrant further investigation.

In other words, ATR is not just about identifying what changed. It is about understanding whether the pattern, timing, or context of those changes suggests that something needs a closer look.

What Do Regulators Expect from Audit Trail Review?

Current regulatory guidance increasingly supports a planned and risk-based approach to reviewing audit trails and related metadata.

ICH E6(R3) states that procedures for reviewing trial-specific data, audit trails, and other relevant metadata should be in place. The review should be planned, with its extent and nature based on risk, adapted to the individual trial, and adjusted as experience is gained during trial conduct.

EMA provides more specific guidance on audit trail review. It states that procedures for risk-based, trial-specific ATR should be established, that review should focus on critical data, and that proactive and ongoing review is generally expected unless another approach is justified. EMA also recognizes that technologies may be used to facilitate review of larger datasets.

FDA's October 2024 guidance on electronic systems and electronic records focuses on ensuring that electronic records used in clinical investigations remain trustworthy, reliable and suitable for regulatory use.

Risk-based audit trail review principles showing planned review, risk-based approach, trial-specific focus, critical data priority, and relevant metadata review.

These expectations support a planned, risk-based approach in which review is focused according to trial-specific risks and the criticality of the data. 

What Should Be Included in Audit Trail Review?

ATR is sometimes treated as though it refers only to changes made to EDC fields. In practice, relevant metadata can be broader.

EMA specifically notes that metadata review may include access logs, event logs, queries and other information in addition to the data-change audit trail. It also highlights access information as particularly relevant in systems containing critical unblinded data.

Depending on the study and the risks being reviewed, relevant activity may include:

  • Changes to clinical data, including their timing and reasons for modification
  • Query creation, response, cancellation, and other query activity
  • User, role, and access-related activity
  • Changes occurring after SDV, data management review, investigator review, or other review milestones
  • Relevant metadata from eCOA/ePRO, RTSM, devices, or other systems contributing important trial data

The scope should be determined by trial-specific risks and by the metadata needed to assess critical data and processes. 

What Can Audit Trail Data Reveal About a Trial?

Audit trail data becomes more useful when it is examined across different dimensions rather than as a chronological list of isolated changes.

Audit trail review patterns showing data changes, timing issues, site and user activity, and safety-critical data signals that can support risk-based clinical trial review.

Data Change Patterns

One of the most obvious uses of ATR is understanding how often data are being modified and where those modifications occur.

Repeated changes to the same fields, unusually high modification rates for particular forms, or frequent updates involving critical data can help reviewers identify areas that deserve closer investigation.

Changes occurring after important review milestones can be especially relevant. For example, if data are repeatedly modified after SDV or data management review, teams may need to understand whether those modifications affect previously completed review activities.

Timing Patterns

When data are entered and changed can provide just as much information as the change itself.

Audit trail analysis may reveal long gaps between an event and its entry into the system, unusually late corrections, clusters of retrospective activity, or delays in investigator review.

EMA explicitly identifies unexpected or inconsistent dates and times of data entry as examples of activity that metadata review may help identify.

Timing therefore adds important context. A routine correction made shortly after data entry may have a very different implication from repeated corrections made weeks later.

Site and User Patterns

Reviewing activity across sites can reveal differences that are difficult to see when subjects are examined individually. These patterns can help reviewers identify sites, users, or processes that warrant closer investigation. 

One site may show a higher rate of late corrections than comparable sites. Another may have unusually high query cancellation activity. A specific user may account for a large proportion of changes to a particular CRF.

These patterns can help reviewers identify sites, users, or processes that warrant closer investigation. Site enrolment, workload, subject complexity, and user responsibilities can then help explain the differences.

Safety and Critical Data Patterns

Audit trail review becomes particularly valuable when activity involves data that have a greater potential impact on participant safety or trial conclusions.

Changes to eligibility criteria, critical endpoint data, safety-related fields, or other important CRFs may therefore deserve different attention from routine administrative corrections.

The same principle applies to timeliness. Repeated delays in adverse event entry, for example, may be more significant than a similar delay affecting a low-risk operational field.

When Does an Audit Trail Change Become a Risk Signal?

A change becomes a potential risk signal when the activity shows a pattern that is unusual, significant, or inconsistent with expected study conduct.

For example, correcting a visit date once may be routine. If the same field is repeatedly corrected across several subjects at one site, however, the pattern may warrant closer review.

The pattern still needs to be interpreted in context. Higher subject enrollment, a protocol amendment, or a training issue could explain the repeated corrections. The audit trail shows what changed and when, but additional study context is needed to understand why the activity occurred.

A risk signal indicates activity that warrants further review. Analytics can surface these patterns, while interpretation depends on the study context. 

How Should Common Audit Trail Risk Signals Be Interpreted?

A useful risk indicator points reviewers toward the context and underlying activity that need to be examined. 

Potential Signal

What Reviewers Are Seeing

Context That May Matter

What Review Examines 

High modification rate

Repeated changes within a site, subject, form, or field

Enrolment, form volume, data-cleaning activity

Which forms, fields, users, or subjects account for the pattern

Late changes

Long interval between initial entry and modification

Visit timing, query history, reason for change

Why the change occurred later in the data lifecycle

Changes after review

Data modified after SDV, DM review, or another review activity

Type of review and importance of the affected data

Whether previously completed review needs to be reconsidered

Critical-field changes

Changes involving higher-impact variables

Source information, user, timing, reason for change

Whether critical data remain reliable and appropriately reviewed

AE entry delay

Delay between the event and entry into the system

Event date, awareness date, site workflow

Whether the pattern suggests a process or timeliness issue

Unusual user activity

Higher or different activity associated with one user

Role, workload, site volume, permissions

Whether the activity is consistent with expected responsibilities

Query pattern

Unusual cancellation, repetition, or response activity

Query type and study workflow

Whether a process, training, or data-quality issue is contributing

Investigator review lag

Data remaining unsigned or awaiting review

Study milestones and site workload

Whether medical oversight is occurring as expected

The same indicator can lead to different conclusions in different trials. That is why the ability to move from an aggregate signal into the underlying audit records is so important.

How Risk-Based Audit Trail Review Works

Risk-based ATR begins with the study rather than the technology.

Teams first need to understand which data and processes are important to participant safety and to the reliability of trial results. Eligibility, safety information, critical endpoints, treatment-related data, and other important protocol requirements may therefore receive greater attention.

The next step is to determine what audit trail activity could provide useful evidence about those areas. For one study, late changes to endpoint fields may be especially relevant. In another, delayed safety entry or post-review modifications may deserve more attention.

Review criteria can then be defined around the risks being monitored. These criteria may involve timing, frequency, rates, exceptions, changes after review, or comparisons across sites and users.

ICH E6(R3) specifically states that the extent and nature of data and metadata review should be adjusted based on experience during the trial.

If a previously unknown pattern begins to appear at a site or around a particular process, the review strategy can become more focused on that area.

What Happens When a Potential Risk Signal Is Identified?

A signal generally starts the investigation rather than finishing it.

Reviewers first examine the underlying activity to determine whether the pattern is meaningful. A high change count, for example, may need to be assessed against subject enrollment, while a timing anomaly may need to be compared with relevant study events.

If the initial review supports further investigation, reviewers can examine the associated subjects, forms, fields, users, dates, queries, and individual audit records to identify what is driving the pattern. 

Additional clinical and operational context may then be needed to determine why the activity occurred. This may include query history, study milestones, protocol requirements, source information, or site workflows.

The investigation should lead to a documented conclusion based on the available evidence. Depending on the findings, this may result in corrective action, such as addressing a training or process issue, or a determination that the activity was appropriate.

The key is that the evidence, reasoning, and conclusion can be traced and documented where required.

Who Should Review Audit Trails and How Often?

There is no single review frequency that is appropriate for every clinical trial. The appropriate timing depends on the study's risks, the criticality of the data, the systems involved and the purpose of the review.

EMA states that audit trail review should generally be proactive and ongoing unless another approach is justified. ATR should therefore be integrated into trial oversight rather than treated solely as an end-of-study activity. 

Prospective review can help teams identify emerging patterns during study conduct, when there may still be an opportunity to correct a process or provide additional training.

Retrospective review also has an important role. When a known issue emerges, the audit trail can help reconstruct how the activity developed, determine its scope, and assess whether other subjects, sites, or data may have been affected.

Responsibility for review should likewise reflect the nature of the data and the issue being examined. Data management, clinical operations, medical teams, quality functions, and other roles may become involved depending on the signal and the trial.

Audit Trail Data Must Be Reviewable Before It Can Be Analyzed

Dashboards and AI-assisted analysis depend on the quality and usability of the underlying metadata.

If audit information exists only as a difficult-to-navigate chronological log, it may technically preserve traceability while still being cumbersome for systematic review.

EMA states that the complete audit trail should be exportable in a dynamic format that supports the identification of systematic patterns across trial participants or sites. The guideline also expects audit trails to remain understandable and accessible for review.

ICH E6(R3) similarly states that audit trails and logs should be interpretable and able to support review.

For practical ATR, reviewers need to be able to filter, group, compare, and investigate audit activity. An aggregate visualization may show that a site behaves differently from others, but reviewers still need access to the individual records responsible for that difference.

The analytical layer and the underlying audit history therefore need to remain connected.

How Analytics and AI Can Support Audit Trail Review

The main role of analytics in ATR is to make large volumes of audit activity easier to interpret.

Instead of requiring reviewers to manually search thousands of individual records, analytics can organize activity by site, subject, user, visit, form, field, or time period. Trends and unusual concentrations of activity can then become easier to recognize.

AI can extend this further by helping users interrogate large audit datasets, summarize patterns, generate visualizations, or investigate specific questions using natural language.

For example, analytics or AI-assisted review may help teams explore questions such as:

  • Which sites have the highest rate of changes after review?
  • Are late modifications concentrated around particular CRFs?
  • Are adverse event entry delays occurring more frequently at specific sites?
  • Which users or roles account for unusual change activity?

AI can surface and prioritize activity for review, while determining what that activity means requires appropriate clinical, operational, and data-management context.

Building an Effective Audit Trail Review Process

A strong ATR process starts with questions rather than dashboards. Teams should understand which risks they are trying to detect and which audit trail information could provide useful evidence about those risks. This prevents review from becoming a collection of metrics that are interesting to look at but difficult to act on.

Responsibilities also need to be clear. Reviewers should know who examines potential signals, who investigates them, when an issue needs escalation, and how conclusions are documented.

Blinding deserves particular attention. EMA warns that information capable of jeopardizing blinding should not be visible in audit trails accessible to blinded users. Appropriate permissions and reviewer roles therefore need to be considered when designing ATR workflows.

Finally, review criteria should evolve with the study. As teams learn which patterns are normal and which are meaningful, thresholds and areas of focus can be refined. ATR should become more informed as study experience grows, rather than remaining a static checklist created before the first subject is enrolled.

How Audit Trail Review Supports Inspection Readiness

Inspection readiness requires more than producing an audit trail when requested.

The audit trail provides traceability. Reviewers and inspectors may also need evidence of how significant activity was identified, assessed, and followed up during the trial.

A mature ATR process should show how potential issues were investigated, what evidence was reviewed, what conclusion was reached, and what follow-up resulted from that assessment.

This demonstrates how audit trail information was used as part of ongoing oversight and provides a documented basis for the decisions made during review.

It also supports data integrity by preserving the traceability and context needed to understand how clinical trial data were generated, changed, reviewed, and managed over time.

Conclusion

Effective audit trail review connects audit activity with the study context needed to interpret it. By examining patterns across sites, subjects, users, fields, timing, and review milestones, teams can identify activity that warrants investigation and trace the evidence behind their conclusions.

A risk-based ATR process therefore combines defined review criteria, accessible audit data, appropriate clinical and operational context, and documented follow-up. Analytics and AI can make this process more scalable by helping reviewers identify and investigate relevant patterns across large datasets.

External References

Abriti Rai

Abriti Rai writes on the intersection of AI, automation, and clinical research. At Clinion, she develops content that simplifies complex innovations and highlights how technology is shaping the next generation of data-driven clinical trials.

Article by

Abriti Rai

FAQS

Frequently Asked Questions

Not necessarily. ICH E6(R3) supports a planned, risk-based approach in which the extent and nature of data and metadata review are adapted to the individual trial. The objective is to focus review according to trial risk rather than assume that every audit entry requires the same level of manual inspection.

An audit trail records the history of actions and changes associated with electronic trial data. Audit trail review examines that information to identify patterns, exceptions, or activities that may require further investigation.

There is no universal frequency for every study. Review timing should be determined by trial-specific risk, data criticality, study phase, and the purpose of the review. EMA generally expects proactive and ongoing review unless a different approach is justified.

Clinical data review focuses primarily on the clinical data and whether they are complete, consistent, and suitable for use. Audit trail review examines the metadata surrounding those data, including how and when they were entered, changed, reviewed, or otherwise processed.

AI can support ATR by helping organize large volumes of audit activity, identify patterns, prioritize areas for attention, generate summaries, and support investigation. However, identifying an unusual pattern is not the same as determining that a clinical, compliance, or data-integrity issue exists. Human review remains necessary to interpret the context.

Both approaches use risk to focus oversight on areas that can materially affect trial quality. ATR can contribute additional evidence by revealing patterns

Still have questions?

Explore how Clinion AI can accelerate your trial – reach out to our team.


Unlock the Future of Clinical Trials with Clinion.

Cut your trial costs by 35% and accelerate your time-to-market by 30%

Compliance

Fully Compliant with Global Standards

Clinion global compliance badges including FDA 21 CFR Part 11, HIPAA, ISO, ICH, GDPR, and EU compliance
ich ,gdpr ,eu compliant logos
Clinion’s adherence to global regulatory standards including FDA 21 CFR Part 11, HIPAA, ISO 9001:2015, ISO 27001:2013, ICH, GDPR, and EU Annex 11.