Which software functions facilitate audit trails, user management and electronic batch records?
Software can effectively support audit trails, user management and electronic batch records. It does not, however, automatically create GMP, FDA or 21 CFR Part 11 compliance. What matters is a risk-based system design, validated functions, clearly regulated workflows, trained users and the regular review of the data actually generated.
An audit trail is a secure, computer-generated, time-stamped record that allows the creation, modification or deletion of an electronic record to be reconstructed. It is intended to make it traceable who changed what, when and, where necessary, why. Important functions are therefore the automatic capture of critical data changes, unambiguous user assignment, time stamps, the display of old and new values, and the justification of changes to defined critical data. The FDA regards audit trails as part of the associated record and recommends that audit trails for changes to critical data be reviewed together with the record before its final release.
An audit trail does not necessarily have to capture every technically possible user action at identical depth of detail. Its scope should be based on data criticality, patient safety, product quality and the risk of manipulation. Typically critical are changes to recipes, setpoints, batch data, test results, user permissions, releases and alarm settings. A very extensive but not meaningfully reviewable audit trail can make data review harder rather than easier. Filter, search and review functions are therefore important, with which quality assurance and the relevant departments can specifically assess relevant changes, exceptions and deviations.
A justification for a change, often referred to as reason for change, can be sensible or required for critical changes. The software should link the justification to the change and store it permanently in the audit trail. It is not sufficient here to allow arbitrary free text. Structured categories, mandatory fields and, where applicable, additional releases are useful so that changes remain traceable, assessable and evaluable.
The term "tamper-proof" should not be equated with a specific technique such as a hash function. Hash-based integrity checks can make manipulation detectable, but they do not replace a secure system architecture. What matters is a combination of access control, separated administrator roles, controlled changes, secured backups, logging, suitable retention, regular review and traceable recovery. A write-once-read-many store, in which data can no longer be altered once written, can be useful within certain archiving concepts, but it is not a general prerequisite for an audit trail.
A uniform time base is important so that events from controllers, laboratory instruments, manufacturing execution systems and other applications can be correctly assessed in their chronological order. Manufacturing execution system, abbreviated MES, refers to software for operational production control, data acquisition and batch documentation. Time synchronisation can be carried out, for example, via the Network Time Protocol, abbreviated NTP. It must be monitored; a one-off technical setup is not sufficient if clocks drift or systems are temporarily disconnected.
User management should implement unambiguous user accounts, role-based permissions and the principle of least privilege. Role-based access control is often abbreviated RBAC. It means that permissions are assigned to a role such as operator, maintenance technician, quality assurance or administrator, rather than giving each user many individual rights. The principle of least privilege means that a person is given only the rights they need for their task. Shared user accounts are unsuitable for GMP-relevant activities because they prevent the unambiguous assignment of actions.
A connection to central identity services, such as Active Directory, Lightweight Directory Access Protocol, abbreviated LDAP, or single sign-on, abbreviated SSO, can simplify user administration. Single sign-on enables logging in to several applications with one centrally managed identity. Nevertheless, this integration must not result in user permissions in GMP-relevant applications being inherited without control or withdrawn too late. The operator needs processes for creating, changing, regularly reviewing and deactivating user accounts.
Multi-factor authentication, abbreviated MFA, combines at least two mutually independent forms of proof, for example a password and a time-based code or a smart card. It is particularly useful for remote access, administrative activities and critical releases. Its implementation must suit the operation: a procedure that is technically cumbersome on the shop floor can lead to unwanted workarounds. Secure session timeouts, lockouts after failed attempts and controlled restoration of access are therefore also important.
Electronic signatures must be unambiguously assigned to a person and document the time as well as the meaning of the signature, for example review, approval or release. They should not rely on a permanently open session or a shared terminal without renewed user confirmation. For critical steps, renewed authentication or a four-eyes principle can be useful. The four-eyes principle means that creation and release are carried out by different authorised persons. A software-side function for segregation of duties can prevent impermissible self-releases, but must be supplemented by suitable roles, processes and organisational responsibilities.
Electronic batch records are often referred to as an electronic batch record, abbreviated EBR. They can replace or supplement paper-based manufacturing and testing documents with guided digital workflows. An EBR should bring together the currently valid manufacturing instruction, recipe, batch ID, raw-material batches, target and actual values, process phases, operator actions, quality checks, deviations, releases and electronic signatures in a reviewable batch history.
A structure oriented on ISA-88 can represent batch processes clearly. ISA-88 is a standard for batch control and describes, among other things, recipes, process phases, operations and plant modules. The system can prevent a subsequent step from starting before defined prerequisites are met. This interlock logic should, however, only be used where it makes process sense. A rigidly configured workflow can lead to workarounds or unclear side processes in the case of legitimate exceptions. Controlled exception procedures with justification, assessment, quality-assurance release where applicable, and an audit trail must therefore be provided for deviations.
The automatic transfer of data from controllers, scales, process control systems, laboratory information systems and analytical instruments reduces manual transcription errors. It does not, however, replace review of the interface. Every connection must clearly establish which value is the leading data source, how time stamps are synchronised, how transmission errors are detected, and how data gaps or corrections are handled. OPC Unified Architecture, abbreviated OPC UA, Message Queuing Telemetry Transport, abbreviated MQTT, and web-based interfaces can exchange data, but by themselves they guarantee neither data integrity nor complete batch documentation.
Real-time checks against limit values can make deviations visible at an early stage. They must clearly distinguish between warning, alarm, process lock and documented deviation. Not every exceedance of an internal warning value is automatically a batch deviation, and a software decision must not replace the expert assessment. So-called review by exception can make batch review more efficient by directing attention to deviations, missing steps, critical alarm messages and relevant audit-trail entries. It is only justifiable where the data acquisition, exception detection, configuration and review rules are themselves reliably set up and validated for the intended purpose.
The versioning of master batch records, abbreviated MBR, recipes and manufacturing instructions is indispensable. A master batch record is the approved master template for manufacturing and documenting a batch. The software should traceably document old and new versions, the reason for the change, the assessment, the releases and the point in time when it takes effect. Batches already in progress or completed must remain unambiguously linked to the version that was valid at the time.
The ALCOA+ model is frequently used for data integrity. ALCOA stands for attributable, legible, contemporaneous, original and accurate: data must be attributable, legible, recorded contemporaneously, available as the original or as a reliable copy, and accurate. In practice, the plus mostly stands for complete, consistent, enduring and available. The FDA describes data integrity in particular as completeness, consistency and accuracy, and requires that data be attributable, legible, contemporaneous, available as the original or as a reliable copy, and accurate.
Long-term archiving needs more than PDF exports. While unalterable formats such as PDF/A can be helpful for legible reports, they do not replace the storage of the required electronic raw data, metadata, audit trails and search capability. Archiving and migration concepts must ensure that data remains legible, available, complete and reviewable throughout the defined retention period. The specific duration follows from the applicable product and industry regulations in each case; it cannot be derived uniformly from Part 11, GMP or the software used.
Industry 4.0 integration at amixon® and Beckhoff
amixon® can carry out the automation of mixing plants on a project-specific basis using the user requirement specification, abbreviated URS. The URS is the operator's documented requirement specification and defines, among other things, recipe management, process data, interfaces, user roles, scope of documentation and regulatory requirements. For automation, amixon® states that it works successfully with Beckhoff industrial automation. This collaboration can make it possible to adapt PLC, visualisation and data functions to the respective mixing task as well as to the operator's existing production and IT landscape.
A programmable logic controller, abbreviated PLC, can execute mixing programmes and recipes. Mixing time, speed, dosing sequence, temperature profile, fill level and other process parameters, for example, can be stored in these recipes. Recipe control thus supports the reproducible execution of released procedures. It does not, however, automatically guarantee product quality or regulatory compliance. Recipe limits, mixing quality, raw-material fluctuations, operator interventions and the release strategy must be defined and assessed separately for the specific product and the intended process.
For audit trails, user management and electronic batch records, what matters is not merely that the functions exist technically, but that they are used correctly within the complete system design. With TwinCAT 3 HMI Audit Trail, Beckhoff offers an extension that can chronologically record operator and system events at the visualisation in a database. Among other things, the system supports electronic signatures, renewed authentication for higher-privilege actions, and the export of audit-trail data into formats such as PDF, JavaScript Object Notation, abbreviated JSON, Hypertext Markup Language, abbreviated HTML, or comma-separated values, abbreviated CSV. Beckhoff describes the extension as a basis on which applications can be developed in line with FDA 21 CFR Part 11, Good Manufacturing Practice, abbreviated GMP, and GAMP. The specific compliance of a plant, however, only results from its project-specific configuration, validation, operational organisation and regular review of the audit-trail data.
An audit trail is a secure, computer-generated, time-stamped record that makes it traceable who carried out which relevant change, when. Depending on the risk, it should, for example, capture changes to recipes, setpoints, batch data, user permissions, releases, critical parameters or alarm limits. For important changes, the system should document old and new values, user identity, time and, where applicable, the reason for the change. An audit trail, however, is only genuinely useful where its entries are reviewed regularly, on a risk basis, and by suitably qualified persons. A large volume of unstructured logs does not replace effective data review.
User management should implement unambiguous, personal user accounts and a role-based permission concept. Role-based access control is often referred to as RBAC. Here, permissions are assigned to roles such as operator, maintenance technician, recipe owner, quality assurance or administrator. The principle of least privilege means that each person is given only the rights they need for their task. Shared user accounts are unsuitable for GMP-relevant actions because they do not allow the unambiguous assignment of actions.
Critical activities can require renewed user confirmation or an electronic signature. These include, for example, recipe releases, changes to critical parameters, the handling of deviations or batch release. For sensitive functions, a four-eyes principle can be useful. It separates creation and release between two different, authorised persons. Whether and which measures are required must be established in the operator's risk concept. The software used can technically support these procedures, but does not take over the expert decision or the regulatory responsibility.
An electronic batch record, also called an EBR, can bring together recipe, raw-material identification, target and actual values, process phases, operator interventions, quality data, deviations, audit-trail entries and releases in batch-related documentation. Through the project-specific control system, the connection of scales, feeders and sensor technology, as well as interfaces to higher-level systems, amixon® can provide the required process data. A complete EBR additionally needs data from raw-material storage, weighing, the laboratory, quality assurance, packaging and logistics. It is therefore generally part of a more comprehensive MES or quality management architecture rather than solely a function of the mixing plant.
Integration into a manufacturing execution system, abbreviated MES, or an enterprise resource planning system, abbreviated ERP system, can be provided for on a project-specific basis. An MES supports operational production control, batch documentation and the recording of production data. An ERP system supports materials management, order management, planning and logistics. Barcode scanners can identify raw materials, containers, recipe versions and batches. For reliable batch traceability to result, the data model, time stamps, leading data sources, recipe versions, roles and permissions, and the handling of communication interruptions must be clearly defined and tested.
For regulated production environments, amixon® can provide qualification-relevant documentation and support with Design Qualification, abbreviated DQ, Installation Qualification, abbreviated IQ, and Operational Qualification, abbreviated OQ. DQ documents the suitability of the plant concept for the specified requirements. IQ confirms proper installation. OQ demonstrates that the plant functions correctly within the intended operating range. amixon® describes its assistance on request with DQ, IQ and OQ, as well as an alignment of documentation and execution with EU-GMP and FDA 21 CFR Part 11. The integration follows the operator's validation concept from the URS through to commissioning.
The requirements of 21 CFR Part 11 do not automatically apply to every digital machine function. They are relevant where electronic records or electronic signatures are created, maintained, retained, retrieved or transmitted on the basis of other applicable FDA regulations. The operator must therefore establish which data is GMP- or FDA-relevant, which functions must be validated, and how data integrity is ensured over the entire retention period. Nor does an audit-trail module or an electronic signature function replace system validation.
Besides the data and software architecture, the mixing process and the design of the plant remain essential foundations for robust batch data. In the amixon® pilot plant, mixing time, fill level, energy input, product protection, discharge and cleanability, for example, can be investigated with the original product. amixon® operates pilot-plant sites in Germany, the United States, China, Japan, India, Thailand and South Korea. Pilot-plant trials can help to define critical process parameters and meaningful data-capture points. They do not, however, replace the performance assessment of the complete production line, nor qualification or validation at the operator's site.
Centralised manufacturing in Paderborn, together with documented component and quality records, can support technical traceability, maintenance, spare-parts supply and later change control. For audit trails, user management and electronic batch records, however, the digital system architecture is decisive: clear responsibilities, controlled software versions, secured data interfaces, personal accounts, risk-based audit-trail review and data that remains available in the long term.