From Regulatory Text to Requirement: How Annex 11 Becomes Testable Audit Trail Specifications
What an audit trail must deliver is set out in Annex 11, 21 CFR Part 11 and the data integrity guidelines. What this means for a specific system is not. How a single regulatory paragraph can be translated into testable user requirements using qualitative content analysis.
Entourage Editorial Team
The audit trail is firmly anchored in the regulatory requirements: Annex 11 of the EU GMP Guidelines, 21 CFR Part 11 of the FDA, the data integrity guidelines of MHRA and PIC/S, and the GAMP works of ISPE describe what it must deliver. What these requirements do not supply is the translation into concrete, testable requirements for a specific system. It is precisely this leap from regulatory text to user requirement that is the real work, and in practice it is often skipped.
The Problem: the Regulatory Text Is Deliberately Open
Regulatory texts formulate a target state, not a specification. They have to apply to the most varied systems and therefore remain general. Anyone who copies them unfiltered into a requirements specification obtains requirements that no one can test, because it remains unclear what counts as fulfilled in the specific system. What is needed is a procedure that systematically condenses the relevant passage down to a testable requirement while demonstrably staying anchored to the source text.
The Method: Qualitative Content Analysis According to Mayring
A proven procedure for this is qualitative content analysis according to Mayring. It distinguishes three basic forms that can be combined for this task: summarisation reduces the material to its core statement without altering it; explication supplements unclear points with explanatory examples; structuring filters out the essentials and reorders them. For the derivation of audit trail requirements, the process can be condensed into four steps: define the material, analyse the material, reduce the material, and check the reduced material against the original statement.
Applied to the Audit Trail Paragraph From Annex 11
Define and analyse the material. At first only the audit trail paragraph from Annex 11 is considered. It requires, on a risk basis, the system-generated recording of all GMP-relevant changes and deletions, the documentation of the reason for a change or deletion, and assurance that audit trails are available, convertible into a generally readable form and reviewed regularly.
Reduce. From this single paragraph, seven core requirements can be distilled: recording of all GMP-relevant changes, recording of all GMP-relevant deletions, recording of the reasons for changes, recording of the reasons for deletions, availability of the audit trail, convertibility into a generally readable form, and regular review.
Check and explicate. The decisive step is the re-check against the source text, combined with the question of where an explanation is needed:
- The recording of changes and deletions needs a definition of what counts as GMP-relevant in the system; the delimitation belongs in an SOP on the audit trail review.
- For the reasons, it must be defined how they are captured, for example via a predefined selection list or a free-text field, and whether the entry is optional or mandatory.
- The term availability must be made precise, for example as displayable at any time on request, from which follow-on requirements such as the printout of a current audit trail arise.
- For the readable form, the export formats must be named, for example PDF, with the specification that the export does not permit any subsequent changes to content and does not require any proprietary software to read.
- For the regular review, the interval and scope must be anchored in an SOP and made testable within the scope of OQ or PQ.
One Paragraph Quickly Turns Into 20 Requirements
This reveals the actual finding: with clean explication, a single regulatory paragraph produces not seven but, on intensive examination and depending on the system, quickly up to 20 concrete requirements. The effort does not lie in reading the requirement, but in relating each reduced statement back to the source text, so that your own wording does not distort the regulatory statement.
How Entourage Supports You
We apply this procedure in a structured way to all requirements and guidelines classified as relevant, from Annex 11 through 21 CFR Part 11 to the data integrity guidelines, and translate the resulting level of detail directly into the draft user requirements. This produces requirements that are robust in an audit, because they were derived comprehensibly from the regulatory text and not reconstructed after the fact.
Relevant for your project?
Similar questions in your current project?
In a first call we clarify what is specifically relevant for your situation, without obligation.
Request a call →Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Regulations & standards considered
- EU GMP Guidelines Annex 11 (Computerised Systems)
- FDA 21 CFR Part 11 (Electronic Records, Electronic Signatures)
- MHRA GxP Data Integrity Guidance
- PIC/S Data Integrity Guidance for Regulated GMP/GDP Environments
- ISPE GAMP 5 and GAMP Data Integrity
Related projects
All case studies →Sources
- EU GMP Guidelines Annex 11: computerised systems (audit trail paragraph, primary text EN and German translation of the Federal Ministry of Health)
- FDA 21 CFR Part 11; MHRA GxP Data Integrity; PIC/S Data Integrity (GMP/GDP); ISPE GAMP 5
- Qualitative content analysis according to Mayring (methodology)
- https://theentourage.de/anforderungen-audit-trail/ (original Entourage article)
Related insights
All insights →Your project
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +39 02 8904 1000
info@theentourage.it
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences




