All data, including repetitions and cancellations, is stored.
Cancellation instead of deletion, requiring justification.
Consistent
The records are sequential and consistent.
State flow rules, date consistency checks.
Permanent
It remains intact for the required period.
Backup, archiving, recovery testing.
Accessible
Available when needed.
Readable output from the archive, auditor has read-only access.
Requirements for audit permit
A record of every creation, modification, and cancellation operation.
Who, when, old value, new value, and reason for the change.
The registration cannot be closed or modified by the user.
The audit trail needs to be reviewed regularly; it's not enough for the record to simply exist, it needs to be actively examined.
The electronic signature must include identity verification and a statement of the purpose of the signature.
Delegation of responsibilities based on role and periodic review.
Cloud and verification
As laboratory systems move to the cloud, the scope of validation has expanded to include not only the application but also the infrastructure and service provider . The current regulatory approach addresses risk-based validation, supplier auditing, identity and access management, and cybersecurity within the same framework.
The practical implication is this: the system provider's ability to provide verification documentation, change management, and backup proof significantly reduces the customer's verification burden.