Compliance
An audit trail that survives an inspection
5 min read
Most organisations discover the quality of their audit trail on the day someone asks to see it. By then it is too late to reconstruct who approved what, because the people involved have left and the emails have been archived under a different subject line.
A trail that survives inspection is not a log file. It is a case history a stranger can read.
What they actually ask for
An inspector, an auditor, or a court is asking a simple question in several forms: how was this decided, who decided it, what did they see, and can you show that the record has not been edited since? If any of those answers require a person to remember, the trail is already incomplete.
- The decision and the policy it was made under
- The evidence attached at the time, not reconstructed later
- The identity of the person who approved, with a timestamp
- A record that cannot be quietly rewritten
Generated, not assembled
The reliable way to produce this is to make it a by-product of doing the work. When a reviewer clears a screening hit, the clearance is the record. When a contract is signed, the signature event is the record. Nothing extra has to be written down afterwards, which is fortunate, because afterwards is when it does not get written down.
A note someone remembered to add is not an audit trail. It is a diary.
Readable by a stranger
Technical logs fail this test even when they are complete. A sequence of API events is not something an auditor can sit with for an hour and understand. The case itself — states, actions, attachments, names — has to be the thing you open.
Have a system exactly as you envision it
Let's talk. It's time to make a better version of your business.