Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Log Plug-and-play starting point Cell & Gene Therapy

Log: Instrument Audit Trail and Access Capability Register

A plug-and-play register of each GxP instrument's real audit-trail and access-control capability: whether it captures field-level changes with prior values, supports named accounts, and where the gaps and compensating controls are, with a filled specimen and the regulations it satisfies.

Document type: Log

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use register of what each GxP instrument’s software can actually do for data integrity, as opposed to what a slide claims. Instrument software for ddPCR, flow cytometry, sequencing, and plate reading was often built as a scientific tool first and a compliant records system second, so the audit-trail and access capability varies widely and is where partial-audit-trail and shared-login findings originate. Replace every <<FILL: ...>> placeholder, keep one row per instrument, and maintain it under document control. A filled specimen follows. Verify each cited regulation against the current source. Pair with the Checklist: Advanced Therapy Data Integrity Readiness.

Register header

FieldEntry
Register number<<FILL: ID>>
Program / site<<FILL>>
Owner<<FILL: role>>
Last review / by<<FILL>>

Field definitions

FieldFormatRequiredNotes
Instrument / IDName, asset IDYesThe physical unit
Software / versionPackage and versionYesCapability is version-specific
GxP useWhat decision it supportsYesTies to criticality
Audit trail enabledYes / NoYesOff is an immediate gap
Field-level with prior valueYes / Partial / NoYesThe key capability; “modified” without prior value is Partial
Metadata in trailYes / NoYesMethods, thresholds, gating, sequences
Trail user-disableableYes / NoYesYes is a gap
Named accountsYes / NoYesNo means shared-login exposure
Privilege separationYes / NoYesAdmin vs routine
Gap / compensating controlTextIf any gapWhat mitigates the shortfall
Remediation / CAPAReference, dateIf any gapUpgrade or replacement plan

The register

Instrument / IDSoftware / versionGxP useAT enabledField-level + prior valueMetadataDisableableNamed acctsPriv. sep.Gap / compensating controlCAPA
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

Add one row per GxP instrument. The register is the evidence behind Section A of the readiness checklist and the input to the risk-based prioritization of which instruments to remediate or replace first.

How to assess a “Partial” audit trail

An audit trail is Partial (not Pass) when it records that a change occurred but not enough to reconstruct the prior state: a “value modified” entry with a timestamp but no old value, or a trail that captures result changes but not the method, threshold, gating, or sequence changes where manipulation actually hides. Partial is a real gap: it must be documented, risk-assessed, given a compensating control (for example a contemporaneous second-person check of the parameter setting), and scheduled for upgrade or replacement.

Acceptance criteria

  • Every GxP instrument is listed with its actual, version-specific capability, not an assumption.
  • Any instrument with audit trail off, user-disableable, or without named accounts on a GxP-critical path has an open CAPA.
  • Every Partial or No entry has a documented, risk-assessed compensating control.
  • The register is reviewed on a defined cycle and after any software upgrade (capability can change with version).

References

21 CFR Part 11.10(d) (limited access, unique accounts), 11.10(e) (audit trail), 11.10(g) (authority checks). 21 CFR 211.68 (equipment controls). FDA Data Integrity and Compliance With Drug CGMP Q&A (final, Dec 2018). EU Annex 11 (audit trail, security). Pending draft Annex 11 revision and new draft Annex 22 (consultation closed 7 October 2025, draft as of mid-2026); confirm final text before citing.

Confirm each reference against the current source before issue.


Filled specimen

Illustrative extract across a small advanced-therapy analytical suite. The variation in capability is the realistic picture and the reason the register exists.

Instrument / IDSoftware / versionGxP useAT enabledField-level + prior valueMetadataDisableableNamed acctsPriv. sep.Gap / compensating controlCAPA
ddPCR-01Vendor v<<FILL>>VG titer releaseYesPartial (no prior value on threshold edits)PartialNoYesYesContemporaneous second-person check of threshold; gap loggedCAPA-2026-0132 (upgrade)
Flow-07Vendor v<<FILL>>Transduction, identityYesYesYesNoYes (moved off shared login 06/2026)YesNoneClosed
NGS-02Pipeline v<<FILL>>Off-target, editing outcomeYesYes (pipeline params versioned)YesNoYesYesNoneN/A
Plate-04Vendor v<<FILL>>Cell-based potencyYesPartial (curve-fit params not in trail)PartialNoYesNoSecond-person review of curve fit; privilege separation gapCAPA-2026-0140
Balance-11Firmware v<<FILL>>Formulation weightsNoNoNoN/ANo (single admin)NoStandalone; move to networked balance with named accountsCAPA-2026-0151 (replace)

The balance is the worst case and the most common one: a cheap standalone unit with no audit trail and a single admin account, feeding GxP-critical weights. It is not ignored, it is documented, risk-assessed, given an interim compensating control, and scheduled for replacement. The ddPCR and plate reader show the realistic Partial case that a compensating control holds while an upgrade is pending.

How to adapt this register

  1. Walk the bench, not the asset list; the instruments that get missed are the small standalone units.
  2. Re-assess capability after every software or firmware upgrade, because it can change silently with version.
  3. Use the register to rank remediation: audit-trail-off and shared-login on release-critical paths first.
  4. Confirm each reference against the current source, including the pending Annex 11 revision, before use.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.