Compliance & Integrity Statement
Qualio's audit trail is computer-generated, secure, timestamped, and aligned with GAMP 5, ALCOA+ principles, 21 CFR Part 11 §11.10(e) and §11.300(c)–(d), and EU Annex 11 §12. Every entry is attributable to an individual user via unique credentials. Audit trail entries are immutable - they cannot be modified or deleted, including by administrators, and there is no UI functionality to alter them.
The audit trail generates a list of auditable actions along with:
The user that performed the action
The type of action
The related target (record)
The date and time of the action
The IP address and geo-location of the user that performed the action.
Note: The geo-location of the user who performed the action is approximate, and city-level accuracy will vary depending on several factors outside Qualio’s control.
To view your audit trail, click on the Reports tab and then select Audit trail.
Note: Access to the audit trail for documents requires the Quality User role, which is designed to ensure that only personnel with appropriate permissions can review sensitive activity logs. This role-based restriction supports segregation of duties per GAMP 5 and 21 CFR Part 11.
Retention
Audit trail records are retained within Qualio indefinitely for the lifetime of the customer's system. There is no mechanism for premature deletion of audit trail records, ensuring records remain available for regulatory inspection for at least as long as the associated electronic records - per 21 CFR Part 11 and EU Annex 11.
Data backup and security are managed under Qualio's POL-14 Data Security, Backup & Redundancy.
Audit Trail vs. Document Activity Log
Qualio uses two complementary records to support GAMP 5 data integrity expectations:
Audit Trail: captures system-level actions (who, what, when, where) across the platform.
Document Activity Log: captures document-level before/after value changes, displayed alongside the document's full version history. Superseded versions of documents are retained, and changes between versions are traceable through the activity log and document change history.
Document Activity Log records the previous and new values for field-level changes (e.g., document owner, review date, title) and is accessible from the Activity tab on the document record itself. It complements the audit trail's system-level entries by providing the granular before/after data that GAMP 5 §4.3 and ALCOA+ "attributable and original" principles require for individual record changes.
This separation ensures clarity: the audit trail provides system-wide traceability, while the activity log provides document-specific before/after value capture aligned with GAMP 5's data-integrity expectations.
Security Events in the Audit Trail
The following security-related events are automatically captured in the audit trail:
Password changes (per 21 CFR Part 11 §11.300(c))
Failed login attempts and progressive lockout (per §11.300(d))
Successful logins
SSO / SAML configuration changes
User account creation, deletion, and permission changes
Group membership changes
View Audit Trail entries for:
Documents
Note: The audit trail captures action-level events for documents (listed below). Field-level before/after value changes are recorded separately in the document's Activity Log. See Audit Trail vs. Document Activity Log above.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Tags
|
|
|
|
|
|
Training
|
|
|
|
|
|
|
|
Events
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
User Management
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
1: Modified user account entries include granting Admin or Billing Access and Event permissions.
Suppliers
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Design Controls
Design Controls: Configuration
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
3rd Party Integration with Design Controls
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Design Elements: Requirements, Risks, and Test Cases
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Design Controls: Change Control
|
|
|
|
|
|
Integrations
|
|
|
|
|
|
Compliance Intelligence
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Periodic Review of Audit Trails
GAMP 5 requires periodic review of audit trails as part of ongoing system lifecycle management. Qualio provides the search and export functionality to enable this.
Customers are responsible for establishing their own SOP defining the cadence, scope, and reviewer roles for periodic audit trail review within their own quality management system.
Shared Responsibility (Cloud / SaaS Model - GAMP 5 2nd Edition)
As a cloud-hosted SaaS platform, Qualio operates a shared-responsibility model:
Qualio is responsible for the integrity, security, availability, and immutability of the audit trail at the platform level.
Customers are responsible for defining their internal procedures for audit trail review, training, and the use of audit trail data as evidence within their QMS.
Supplier responsibilities are detailed in the Qualio MSA, DPA, and supporting validation documentation.
For Additional information on the Audit Trail see:
Understanding permission roles in Qualio
Best practices for audit trail review
For validated-system evidence supporting GAMP 5 compliance (IQ/OQ/PQ, validation summary, traceability matrix), contact your Qualio account team to request VAL-17 Qualio System Validation document under NDA.
For further details, consult the Qualio Help Center or contact support for additional guidance.



