UDI · AUDIT TRAIL · CSV / CSA

UDI software: audit trails, data integrity and validation

Who changed the UDI data, who approved it and what was actually submitted? A reliable UDI process must provide traceable answers. An audit trail supports that evidence, but does not make software automatically compliant. Intended use, controlled procedures and appropriate checks within the organisation remain essential.

Trace changes. Assign approvals. Retrieve evidence.

What is an audit trail for UDI data?

An audit trail is a traceable history of relevant system actions and data changes. It helps identify users, timing, affected records and changes. Practical assessment should establish which events are recorded, how records are protected and how they can be reviewed.

SAP Audit Trail App

Existing SAP Audit Trail App view: it shows date, time, user, table/field name, and old and new values. The screenshot evidences this view, not all features of every current version or GSP module.

Assessment question Why it matters
Who made the change? Distinct user attribution instead of indistinguishable shared accounts.
What changed? Record, field and old/new value, or a documented scope of change.
When and in what context? Time, version and connection to approval or submission.
Is the history protected? Assess permissions, retention and access to records.
Is it actually reviewed? Define review, deviation handling and retrieval.

Four different kinds of evidence — not one green tick

Data validation

Does the record satisfy required fields, formats and applicable business rules?

System validation / assurance

Does the configured process work reliably for its intended use?

Audit trail

Which relevant changes and actions are recorded?

Submission evidence

Which version was submitted, and what response was received?

Plan CSV and software assurance according to risk

FDA’s Computer Software Assurance for Production and Quality Management System Software, February 2026, describes a risk-based approach for production and quality-management software. It supersedes the September 2025 version. Assess its specific scope; it does not prescribe identical test documentation for every UDI application.

FDA: Software Assurance, February 2026

GAMP 5, second edition, provides risk-based lifecycle guidance; it is not a regulatory product certificate. The existing V-model illustrates possible documentation and testing relationships. Suitable coverage depends on use, risk and changes.

ISPE: GAMP 5, second edition

Existing V-model illustration: orientation for requirements, testing and evidence, not a fixed mandatory sequence for every system
Existing V-model illustration: orientation for requirements, testing and evidence, not a fixed mandatory sequence for every system.

When is 21 CFR Part 11 relevant?

Applicability depends on the electronic records involved and the underlying FDA requirements. For covered closed systems, § 11.10 addresses validation, access controls and protected, time-stamped audit trails, among other controls. Processing UDI data alone does not make Part 11 applicable.

FDA: Part 11 scope and application · 21 CFR 11.10: controls for closed systems

GDPR, HIPAA and SOX likewise cannot be presented as identical blanket audit-trail obligations for every UDI project. Assess legal basis, data types and organisational context separately.

Software functionality and organisational procedures work together

Europe IT / agreed deliverables

Provide system functionality, data and submission processes and project-specific technical information within the agreed scope. Do not assume an unagreed complete validation-documentation package.

Customer / process owners

Define intended use, requirements, roles, approvals, testing and review within the organisation’s quality management. In the confirmed GSP/GUDI workflow, customers handle data errors and resubmissions.

Authority

Process submitted data according to its own rules and provide responses. Acceptance of a submission does not demonstrate every internal process control.

GUDI and GSP in the right evidence context

GUDI is the SAP solution for UDI data management and authority submission. GSP supports a portal workflow with Excel import, validation and customer-initiated transmission. Available logs, histories, exports and documentation must be checked against the relevant module and agreed scope.

A good project start connects data source, Europe IT solution, technical transfer method and operating model with clear responsibilities. This helps plan evidence without confusing data checks, system validation and authority acceptance.

Discuss your UDI process and evidence →

Frequently asked questions

Is an audit trail automatically an electronic signature?

No. Change logging and electronic signatures are different functions. Determine whether signatures are needed and which requirements apply to the process.

Does an error-free UDI record prove system validation?

No. Successful data checks alone do not establish that roles, approvals, interfaces, error handling and operating procedures have been tested for intended use.

Is a screenshot complete audit evidence?

No. It can document a view. Complete evidence requires the relevant context, record or process and suitable retrievable records.

Sources and further information