Skip to content
Menu
Patent pending

Regulayer  /  The 143 laws  /  Pharma & life sciences

FDA · Data integrity and CGMP Q&A

Audit-trail review and data-governance expectations.

Instrument: Regulatory guidance, nonbindingApplies to: Drug manufacturing under CGMP (US).

What the signed record shows

That the audit trail exists, was reviewed, and records who did what and when.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: Data Integrity and Compliance With Drug CGMP, Questions and Answers, December 2018

In the same family

What to do about it

Keep the evidence this asks for, as the work happens.

A consequential AI-proposed action is checked against the human authority in force at that moment, and the decision leaves a signed record that a third party can verify independently, offline, without Regulayer. It runs inside your own environment and nothing has to leave it.

Life sciences: how the control worksOr verify a real record, free →

Part of the Regulayer proof catalogue: 143 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the guidance answers

FDA, Data Integrity and Compliance With Drug CGMP: Questions and Answers, final guidance, December 2018. The document behind a recurring class of inspection findings:

Audit trails, and reviewing them
The guidance addresses not only whether an audit trail exists but whether it is reviewed, and by whom. An audit trail that is enabled and never read is a documented finding pattern, not a technicality.
Who may make changes
Expectations attach to restricting the ability to alter records to authorised individuals, and to being able to show which individual acted.
Shared logins
Where credentials are shared, actions cannot be attributed to a person. Attribution is the first requirement, so this defeats the record at its foundation.
Data governance as a system
The expectations are framed as a governance system rather than as properties of any single piece of software.

Guidance rather than regulation: it explains how FDA reads the existing CGMP requirements. It is included because the failure patterns it addresses, unreviewed audit trails and unattributable actions, are the ones that recur in enforcement.

Built against the primary text published by FDA. Verified 17 August 2026.

This is the duty on the business. For what a lawyer in Europe must disclose about using AI in a filing, see Europe: the EU AI Act, the CCBE guides, and what Germany tells its lawyers.