Recently, many customers have reached out with confusion: the filter integrity testers we purchased are clearly specified to feature an audit trail function in specification sheets. However, data integrity-related observations were still issued during domestic surprise inspections and FDA audits. What leads to this outcome?
To address this question, we must first clarify a fundamental premise: having an audit trail module embedded in a filter integrity tester is entirely different from maintaining continuous effective operation of the audit trail and ensuring end-to-end compliance of electronic data with the ALCOA+ principles.
When inspectors identify data integrity deficiencies, their focus is not on the accuracy of test values, but whether electronic raw records, audit logs and data lifecycle management can guarantee authenticity, integrity, traceability and tamper resistance. As long as gaps exist in the control chain, compliance deficiencies may arise even if the instrument has a built-in audit trail.
Many enterprises only complete basic instrument setup without establishing supporting control systems. From an inspection perspective, the availability of audit trails in the instrument menu does not equal compliance. An audit trail can deliver compliance value only if it cannot be arbitrarily disabled, fully captures all critical operations, contains complete log attributes, and is supported by relevant personnel and data management procedures. The vast majority of observations fall into four categories: defective audit trail configuration, ineffective access permission management, inadequate raw data lifecycle control, and insufficient computerized system validation (CSV).
This is a common and prevalent source of data integrity deficiencies related to filter integrity testing.
First, the audit trail can be manually turned off. Administrator accounts on some instruments are authorized to suspend or disable audit logs. Even if the function is normally enabled on a daily basis, the existence of such disable privileges creates potential data integrity risks, leaving open the possibility of intentional concealment of operations and missing records.
Second, the scope of log recording is inadequate. Many instruments by default only record test start and test completion. High-risk operations including parameter modification, test abortion, test record deletion, system time adjustment, data export and cache clearing are not logged, making it impossible to fully reconstruct the complete testing process and breaking the traceability chain.
Third, audit logs lack complete required attributes. A compliant audit log must contain four essential elements: operator, timestamp, operation performed, and before/after changes. Common on-site non-conformities include: failure of logs to display operator account; manually adjustable system time; parameter modifications only noted without retaining original pre-change values. In the event of anomalies, full process reconstruction cannot be achieved, violating the attributable and accurate tenets of ALCOA.
The core value of audit trails lies in enabling accountability traceability. Disordered permission management directly undermines the compliance validity of logs. Shared login accounts among multiple operators are a widespread industry issue. When all operations are associated with a single account, the actual operator cannot be identified, invalidating the attributable principle of data. Sufficient log volume alone cannot prevent issuance of inspection observations. Crude permission segmentation is another issue: regular operators are granted administrator privileges, enabling them to delete raw data, erase audit logs and alter local system time. This creates risks of deliberately retaining passing data and hiding failed test records. In addition, inactive accounts and accounts of resigned staff that remain undeactivated over the long term constitute persistent risks of unauthorized data access.
Audit trails only capture the moment of data generation, while data integrity control covers the full lifecycle of generation, storage, export, review, backup and archiving. Back-end management loopholes are easily overlooked. The most typical issue is selective data retention. Operators directly delete raw curves and records of failed or aborted tests, preserving only data and reports from repeated successful testing. Archived records therefore fail to reflect all testing activities. Furthermore, data is stored locally on instruments without a scheduled off-site backup strategy. Instrument hardware failure, maintenance and system upgrades may result in permanent loss of historical electronic records, failing to meet the enduring and available requirements under ALCOA+. Besides, exported reports lack anti-tampering mechanisms and allow unrestricted editing. Most enterprises lack SOP requirements for QA to conduct periodic review of audit trail logs; logs are only retrieved temporarily ahead of inspections, preventing proactive identification of abnormal operations.
During IQ/OQ implementation, many companies only validate testing performance such as bubble point, diffusion flow and water intrusion, without targeted validation of audit trail functionality. Scenarios including record deletion, test abortion, parameter changes and time modification are not simulated to verify whether logs reliably capture all operations. Regulatory standpoint: electronic data generated by insufficiently validated computerized systems lack adequate credibility. The factory-built functionality of equipment alone cannot serve as presumption that audit trails will operate stably and compliantly on an ongoing basis.
Prioritize equipment with audit trails permanently enabled by default, where no accounts (including administrator accounts) possess authority to disable or suspend the function. If existing instruments allow audit trail deactivation, immediate replacement is not mandatory, though this represents an inherent compliance red flag. Enterprises shall first verify whether the instrument logs any activation/deactivation of audit trails. Meanwhile, implement compensatory controls including strict permission restrictions, formal procedural prohibitions, periodic QA log reviews and mandatory full raw data backup, and document formal risk assessments. Such a control framework may support continued short-term use when preparing solely for domestic inspections. However, for companies subject to FDA or EU audits, or if the instrument cannot log audit trail disable events, administrative controls alone rarely gain full regulatory acceptance. A phased replacement roadmap is recommended. For future new equipment procurement, set non-disabling audit trails as a core entry requirement to avoid data integrity deficiencies at the source.
Improve log configuration to ensure high-risk operations including parameter modification, test abortion and record deletion are fully tracked, capturing parameter values before and after changes.
Enforce one account per operator, revoke elevated privileges for regular operators, periodically clean up invalid accounts, and strictly prohibit account sharing.
Mandate via procedures that raw curves and audit logs of all tests (passing, failing and aborted) shall be retained; on-site deletion of raw records within instruments is forbidden.
Establish a scheduled off-site backup mechanism to mitigate risks of local data loss.
Explicitly define within SOPs periodic QA review of audit trail logs, with documented review records maintained.
Deploy a time synchronization server to lock instrument system clocks and prohibit manual local time adjustment.
Cover all audit trail scenarios during OQ execution, and complete full CSV documentation packages.
It must be clarified that an audit trail fitted on a filter integrity tester is merely a functional tool. Data integrity relies on a complete management system: continuous function activation, comprehensive configuration, controlled access permissions, full lifecycle protection of raw data, and periodic log review.
Pharmaceutical companies need to abandon the inertial mindset that "factory-installed audit trails eliminate data integrity deficiencies". As a core control point within aseptic processes, filter integrity testing requires electronic data compliance governance to evolve from simply having available functions toward sustained controllability. Systematically address management gaps to confidently cope with all official regulatory inspections.
18600288605
Address : Room 501,No.2 Building of Ziyuguoji, Yinhe South Street,Shijingshan District, Beijing
TEL : 0086-10-56299356-806 / +86 18610813447 / +86 18600199884 / +86 13520602985
FAX : 0086-10-68705659
Email : lily@neuron-biotech.com / amanda@neuron-biotech.com / peter@neuron-biotech.com
Teams. : shichangbu@neuron-biotech.com / peter@neuron-biotech.com / +86 13581602592
WhatsApp : +86 18600199884 / +86 18610813447 / +86 13520848528
WeChat : +86 18600199884 / +86 18610813447 / +86 13581602592
Facebook : lily@neuron-biotech.com