An audit trail review that flags exceptions but keeps no traceable record of what happened to each one leaves the same gap it was meant to close: nobody can prove the exception was resolved rather than quietly ignored. This running log tracks every flagged exception from detection to closure. It is the thread an inspector follows when they ask “you found this exception, what did you do about it?” Replace every <<FILL: ...>> placeholder, keep the log under document control, and retain it per your records schedule. Field definitions, a filled specimen, and the retention rules follow. Verify each cited regulation against the current source before you rely on it.
Why this log exists (regulatory basis)
Both record-level and periodic audit trail review generate exceptions that must be reviewed and dispositioned, with quality-relevant ones escalated to a deviation or investigation. The MHRA GxP Data Integrity guidance and PIC/S PI 041 expect each exception to be reviewed and its conclusion recorded; EU GMP Annex 11 section 9 expects GMP-relevant changes to be documented and reviewable. This log is the single place that makes the detection-to-closure thread traceable in both directions, from an exception to its deviation and back.
Field definitions
| Field | Format | Required | Who enters | When |
|---|---|---|---|---|
| Exception ID | <<FILL: prefix>>-YYYY-NNN | Yes | Reviewer | At detection |
| Date flagged | Date | Yes | Reviewer | At detection |
| System / record | Text | Yes | Reviewer | At detection |
| Source of detection | Record-level / Periodic / Triggered | Yes | Reviewer | At detection |
| Exception rule / trigger | Rule ID or description | Yes | Reviewer | At detection |
| Event detail | Who, when, what changed | Yes | Reviewer | At detection |
| Initial assessment | Free text | Yes | Reviewer | At detection |
| Data held pending resolution? | Yes / No / N/A | Yes | Reviewer | At detection |
| Disposition | Acceptable-with-rationale / Escalated | Yes | Reviewer | At closure |
| Rationale or deviation ref | Text or deviation number | Yes | Reviewer | At closure |
| Closed by / date | Name + date | Yes | Reviewer | At closure |
| QA oversight / date | Name + date | Yes | QA | At closure |
Log
| Exception ID | Date flagged | System / record | Source | Rule / trigger | Event detail | Initial assessment | Data held? | Disposition | Rationale / deviation ref | Closed by / date | QA / date |
|---|---|---|---|---|---|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
Instructions for use
- Open a row the moment an exception is flagged, whether by record-level review, periodic review, or a triggered review. Do not wait for disposition to log it; the detection date must be the real date.
- If the exception is quality-relevant or unexplained, hold the affected data (do not release or use it) and record “Yes” under data held.
- Disposition every exception with either “Acceptable” plus a recorded rationale, or “Escalated” plus the deviation or investigation number. An exception is never closed blank.
- QA reviews and signs the closure. The person who generated the data being questioned must not be the sole closer of the exception about it.
- Review open rows at each data governance review so no exception ages silently.
Acceptance criteria
- Every flagged exception has a row; the log count reconciles with the exceptions cited on the review records.
- Every row reaches a disposition; no row is closed without a rationale or a deviation reference.
- Escalated rows trace to a real deviation/investigation, and that record traces back to the Exception ID.
- Data-held decisions are recorded, and no affected data was used before the exception was resolved.
- Closure carries both the reviewer and QA signatures with dates.
Retention
Retain this log for not less than <<FILL: retention period, aligned to the associated GMP records>>, and at least as long as the batch or result records whose audit trails it references. Store it so it remains legible, attributable, and retrievable for the full period.
Filled specimen
Two illustrative rows show how the log reads when one exception is acceptable and one is escalated.
| Exception ID | Date flagged | System / record | Source | Rule | Event detail | Initial assessment | Data held? | Disposition | Rationale / deviation ref | Closed by / date | QA / date |
|---|---|---|---|---|---|---|---|---|---|---|---|
| DI-EXC-2026-047 | 08 Jul 2026 | CDS / HPLC-07-2207-031 | Record-level | R-02 reprocess | analyst_jr reprocessed std curve, reason “wrong calibration level assigned” | Original retained, both visible, correction plausible | No | Acceptable | Scientifically justified, second-person verified; no deviation | A. Patel, 08 Jul 2026 | R. Gomez, 09 Jul 2026 |
| DI-EXC-2026-048 | 08 Jul 2026 | CDS / HPLC-07-2207-031 | Record-level | R-06 reason quality | analyst_jr entered reason for change as “x” | Reason non-meaningful, cannot confirm change is proper | Yes | Escalated | DEV-2026-0142 opened; result held | A. Patel, 08 Jul 2026 | R. Gomez, 09 Jul 2026 |
The two rows show the log doing its job: the acceptable exception carries a real rationale, the escalated one carries a deviation number and a data-hold, and both are closed with QA oversight. An inspector can pick either Exception ID and follow it to its conclusion, or start from DEV-2026-0142 and land back on this row.
Common inspection findings this log prevents
- Exceptions flagged during review but no evidence of what was done about them.
- An escalated exception with no deviation number, so the thread dead-ends.
- A quality-relevant exception where the affected data was used before the exception closed.
- Exceptions closed as “acceptable” with no recorded rationale.
- The data generator closing the exception about their own data with no independent oversight.
How to adapt this log
- Set your Exception ID prefix and align retention to the GMP records the exceptions reference.
- Point the rule/trigger field at your validated exception rule set specification so IDs match.
- Wire closure into your deviation SOP so escalated rows always carry a real deviation number.
- Add the log to your data governance review agenda so open rows are actively worked.
- Confirm the referenced regulations against their current published versions before issue.