FDA 21 CFR Part 11 Part11.AuditTrail: Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
Section 11.10(e) audit trail requirement: USE OF SECURE + COMPUTER-GENERATED + TIME-STAMPED AUDIT TRAILS to independently record the date and time of operator entries and actions that create + modify + or delete electronic records. Record changes must not obscure previously recorded information. Audit trails must be maintained for as long as required for the subject records (typically following the underlying record-retention requirement which can be 2 years (clinical) + 5 years (medical device) + or longer depending on the regulated activity) + must be AVAILABLE FOR AGENCY REVIEW AND COPYING. Audit trails must include: WHO (user identity); WHAT (action - create + modify + delete + view as appropriate); WHEN (computer-generated time stamp - server-side clock + synchronized to authoritative time source NTP); WHERE (system + module + record); BEFORE / AFTER VALUES (for modification audit); WHY (reason for change where applicable + commonly required by company SOP). The 'WHO + WHAT + WHEN + WHERE + WHY' acronym (5W) is industry-standard for Part 11 audit trail design. FDA inspectors routinely review audit trails for QC + clinical + manufacturing systems + focus on operator-action coverage + tamper-evidence + time-source integrity.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 94 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132 Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni)