EN-GUIDE-08 · PHARMACEUTICAL COMPUTERISED SYSTEMS

Data Integrity, Audit Trail, Backup, Restore & Review Evidence

A value on an HMI, a row in a database or a completed backup job does not by itself prove a complete, consistent and accurate GMP record. Fix the record and system boundary, preserve the first evidence and metadata, reconcile time and interfaces, review relevant audit trails, prove recovery and place the final decision with named system, record and quality owners.

  • Reviewed: 23 July 2026
  • Audience: quality · CSV · IT/OT · automation · production
  • Output: reviewable record and recovery evidence package
Pharmaceutical computerised-system evidence chain from record identity and source data through time, access, audit trail, interfaces, backup, restore and accountable review
Explanatory evidence structure, not a customer system, validation protocol, universal retention period or batch-release decision.

Conditions that require record-path evidence—not a screen check.

Hold changes, deletion, reset or return to use when evidence may be lost or misattributed.

Record boundary unknown

System, instrument, record, product, batch, process step, equipment, time window or owner cannot be fixed.

Original evidence at risk

A reset, overwrite, migration, restore, service action or log rotation could obscure source data, metadata or audit trail.

Identity or authority unclear

Shared credentials, unknown sessions, unmanaged privileges or absent approval prevent action attribution.

Time cannot be reconciled

Clock source, offset, zone, sequence resolution or interface delay is unknown and event order would be inferred.

Recovery unproven

Backup content, restore method, dependencies, licenses, keys, configuration or data reconciliation are incomplete.

Review authority absent

Exceptions, deviations, affected batches, restrictions or acceptance authority remain outside the review package.

Stop means preserve the available evidence and controlled state.

Protect source records and configuration, maintain the authorized hold, document any unavoidable preservation action and return the next decision to the named site authority. This guide does not authorize access, deletion, data correction, restore, electronic signature, validation approval or batch disposition.

Fix the record-generating boundary before asking whether the data are trustworthy.

CollectMinimum evidenceWhy it matters
Record identitySite, system/instrument, record type and ID, product/batch/process, equipment, event window, status and ownersPrevents evidence from different records or batches being merged.
Source and metadataOriginal entry, raw signal/file, units, method, user, timestamps, sequence, context, calculations and transformationsSupports reconstruction from generation to reported result.
Access and audit trailAccounts, roles, privileges, sessions, administrator actions, relevant create/modify/delete events, reasons and reviewConnects actions to authorized identities and exceptions.
Interfaces and timeSource/destination tags, queues, acknowledgements, retries, failures, clocks, offsets, zones and sequence resolutionShows whether transfer or time handling changed meaning or completeness.
Backup and restoreScope, schedule, success evidence, configuration, application/data versions, dependencies, retention, restore method and test resultSeparates file existence from recoverable and reconciled operation.
Review and decisionReview scope, exception criteria, deviations, affected records/batches, reviewer, restrictions, approval and residual ownershipMakes the accountable final decision visible.

Follow one relevant record from generation to accountable review.

Six computerised-system evidence gates for record identity, source data and metadata, identity and time, audit trail and interfaces, backup and restore, and quality review with as-left control
The gates organize evidence and ownership; they do not create a universal audit-trail review frequency, retention period or acceptance criterion.
GateRequired evidenceHold when
1. Record identityRecord, system, product/batch/process, equipment, time window and owners describe the same activity.Boundary or responsible owner is missing.
2. Source & metadataOriginal or verified true-copy evidence retains context, units, method, user, time and transformations.Only a transcription, screenshot or unexplained export remains.
3. Identity & timeUnique user/role, authorization, session and clock provenance support attribution and sequence.Shared access or unreconciled time makes attribution uncertain.
4. Audit trail & interfacesRelevant changes, deletions, repeats, failures and transfers are reviewed with reasons and affected records.Relevant exceptions sit outside review scope.
5. Backup & restoreApproved content can be restored with dependencies, metadata and interface/data reconciliation.Backup success is the only recovery proof.
6. Review & controlDeviations, affected batches, restrictions, validation status, decision and residual owners are recorded.Technical completion is treated as quality acceptance.

Test the integrity of the record path without changing the evidence first.

  1. Fix the record and system identity.

    Name the record, source device/application, product/batch/process, equipment, time window, current status and responsible owners.

  2. Preserve source data and metadata.

    Secure the original or controlled true copy, context, units, method, configuration, raw files, logs and export method before resets or corrections.

  3. Reconcile user, role and privilege.

    Map each relevant action to a unique identity, authorized role, session and approval; preserve privileged and administrator activity.

  4. Establish time provenance.

    Record clock source, synchronization state, offset, zone, daylight-saving handling, event resolution and known interface delay.

  5. Review relevant audit trails and exceptions.

    Use an approved, risk-based scope that includes create/modify/delete, reason, repeated or aborted runs and unexplained gaps—not only a final report.

  6. Trace interfaces end to end.

    Compare source and destination identity, value, units, quality, timestamp, acknowledgement, retry, failure and reconciliation evidence.

  7. Prove backup and restore.

    Restore the approved scope in an authorized test boundary and verify configuration, metadata, permissions, dependencies, interfaces and record completeness.

  8. Review, disposition and hand over.

    Connect findings to deviations, affected records/batches, validation status, restrictions, quality decision, as-left state and residual ownership.

Questions that prevent a convenient record from becoming unsupported evidence

Transfer the evidence, limitations and authority that actually remain.

Identity and ownership

System/instrument, record, product/batch/process, equipment, time window, system owner, record owner and quality authority.

Source and provenance

Original/true copy, metadata, user/role, clock evidence, audit trail, interface path, calculations and transformations.

Recovery and verification

Backup scope, versions, dependencies, restore method, actual test, reconciliation, exceptions and validation status.

Decision and residual control

Deviations, affected records/batches, restrictions, monitoring, approval, open items and accountable follow-up owners.

Use the same record path in review and recovery.

The PDF preserves the collection table, six gates, procedure, application limits and handover package.

Download the PDF guide

Apply each source only within its jurisdiction and approved site framework.

Jurisdiction and approval boundary

Confirm the country, predicate rules, product authorization, pharmacopoeia, AHJ, site quality system, approved SOPs, validation/qualification plan, data-retention schedule, cybersecurity policy, OEM support and qualified reviewers. This page supplies no universal review frequency, retention duration, validation acceptance value or batch-release authority.

Connect the record path to shared terminology, controlled change and Korean evidence.