Glossary · Document and evidence governance
Audit trail
German: Audit-Trail
In document and evidence governance, an audit trail is a chronological record of changes, approvals, actions and evidence, showing who did what, when and on which version. A usable audit trail is complete, time-stamped and protected against unnoticed alteration.
- Compliance
- Cybersecurity
In one sentence
An audit trail is a chronological, tamper-evident record of changes, approvals, actions and evidence that shows who did what and when.
Example
The audit trail of a safety PLC program shows that the muting timeout was changed from 4 to 6 seconds on March 3, by which engineer, under which change request and after which review.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
How it applies
- Technical documentation: Content management and PLM systems record revisions, but approvals by e-mail or in meetings often escape them. Capture the approval in the same system as the change.
- Integrated systems: Machine parameters, software versions and remote interventions need an audit trail too. For safety-related parameters, the record shows whether a change went through change control.
- Cybersecurity: Entries are only meaningful if actions are tied to authenticated identities and the log itself is protected. Shared accounts break the trail.
- Evidence: Reliable timestamps from synchronized clocks are needed to reconstruct the order of events after an incident.
Audit trail vs. version history
A version history shows how a document changed. An audit trail also shows the surrounding actions: who approved, which evidence was attached, who accessed or released it. For audit readiness, the version history is necessary but not sufficient.