The electronic audit trail sits at the center of laboratory compliance, and AI is quietly raising the stakes around it. AI-assisted systems can generate, modify, and act on data faster than any manual audit trail was designed to follow, which means the data integrity controls that regulated labs already rely on now have to cover behaviour those controls were never built for. This guide explains what the FDA expects from audit trails and data integrity, where AI introduces new gaps, and what a lab manager or quality lead can do to close them before an inspector finds them first.
It is written for regulated environments specifically. If your starting point is the operational side of data, data quality as a lab manager's responsibility is the companion piece; this article is about the compliance face of that same discipline.
Key Takeaways
|
What Is ALCOA+, and Why Does It Matter for AI?
Data integrity is not an abstract aspiration; regulators assess it against a defined standard known as ALCOA+, and they take it seriously. By one analysis of FDA data, data integrity was cited in 61 percent of FDA warning letters issued in 2021, and it remains among the most frequently cited categories in drug GMP enforcement. ALCOA+ is the framework inspectors apply, and every element of it is testable.
The ALCOA+ principles, and what each one demands when AI is involved:
Principle | What It Requires | What AI Puts at Risk |
Attributable | Every action is traceable to a person or system | An AI action with no clear, recorded actor |
Legible | Records are readable and permanent | Opaque model outputs that cannot be explained later |
Contemporaneous | Recorded at the time of the activity | Batch or delayed logging of AI-driven changes |
Original | The first record, or a true certified copy | Derived or model-transformed data treated as source |
Accurate | Free from error, reflecting the true result | Confident AI outputs built on flawed input data |
+ (Complete, Consistent, Enduring, Available) | Nothing omitted; retained and retrievable on demand | Gaps where AI actions or rationale are not captured |
AI does not rewrite these principles. It just makes some of them harder to satisfy, because a system that acts on its own and adapts over time strains the assumptions of attribution, contemporaneousness, and originality that ALCOA+ was written around.
What Does FDA Expect From an Audit Trail?
Under 21 CFR Part 11, the audit trail is the mechanism that makes electronic records trustworthy. FDA's expectations are well established, and AI-assisted systems are held to the same bar as any other regulated system. A compliant audit trail is expected to do the following:
- Capture the essentials: who performed an action, what the action was, when it occurred, and, for changes, the previous value and the reason. This is the irreducible core of an audit trail.
- Be secure and tamper-evident: computer-generated, time-stamped, and protected so that records cannot be altered or deleted without a trace.
- Be contemporaneous: generated at the time of the activity, not reconstructed after the fact.
- Be reviewed, not just generated: FDA expects audit trails to be reviewed as part of the record review process. An audit trail that exists but is never examined is one of the most common deficiencies cited in inspections.
- Be retained and retrievable: available for the full retention period and producible on demand during an inspection.
Validation underpins all of this. FDA's risk-based Computer Software Assurance approach, finalized in 2025, focuses validation effort where patient and product risk is highest, which is directly relevant to deciding how much rigor an AI feature warrants.
An audit trail that is generated but never reviewed is not compliance. It is a record of problems no one looked at, and inspectors know exactly where to find it.
Where Does AI Introduce New Audit Trail and Data Integrity Risks?
The compliance challenge with AI is not that it is unregulated; it is that it behaves in ways traditional audit trails were not designed to capture. AI data integrity compliance has to account for three dynamics in particular.
- Non-human actors. When a system reroutes a sample, recalculates a result, or flags and holds a batch, the audit trail needs to attribute that action to the system, identify what triggered it, and record any human review. A blank where the actor should be is an attributability failure.
- Models that change over time. An adaptive model that is retrained or updated may behave differently from the version that was validated, often without an obvious version change. Without change control, the audit trail cannot show which model produced a given result.
- Speed and volume. AI can generate and modify data faster than manual review can keep pace, so problems propagate before anyone notices. The audit trail may be complete and still be useless if no review process can realistically cover the volume.
These risks are why claimed AI capability deserves the same scrutiny in a regulated lab as anywhere else. When evaluating AI features in lab software, the compliance questions, what the model does, what it logs, and how it is monitored, matter as much as the operational ones.
Configuring AI-Assisted Systems for Data Integrity
Most data integrity failures are preventable through configuration and process rather than technology. The goal is to make the compliant path the default, so that integrity does not depend on individual diligence under time pressure. The practical controls:
- Capture AI actions in the audit trail. Ensure the system logs AI-driven actions and changes with the trigger, the outcome, and any human review, to the same standard as a human action.
- Enforce access and authority controls. Unique user accounts, no shared logins, and role-based permissions. Shared credentials are among the most frequently cited Part 11 violations because they destroy attributability.
- Apply change control to models. Treat model updates and retraining as change-control events. Establish with the vendor how and when models change, and whether a change requires revalidation.
- Validate proportionate to risk. Use a risk-based approach to focus validation effort on the AI functions that affect product quality and patient safety, documenting the rationale.
- Keep a human review step. For any AI action that affects a reportable result or a regulated decision, retain a human review and approval point. Do not remove the human from decisions that carry regulatory weight.
- Build audit trail review into the routine. Define who reviews the audit trail, how often, and how that review is documented. The review is the control; generating the log is only the prerequisite.
Much of this is what a well-configured, Part 11-aligned LIMS or informatics platform is designed to support, which is why data integrity belongs in the system selection conversation rather than being retrofitted afterward.
The Most Common Audit Trail and Data Integrity Findings
The violations that show up in FDA warning letters and 483 observations are remarkably consistent, which means they are also predictable and preventable. The recurring patterns and the AI-era twist each one now carries:
Common Finding | What It Looks Like | The AI-Era Twist |
Audit trail not reviewed | Logs generated but never examined | Higher data volume makes meaningful review harder |
Shared or generic logins | Multiple users on one account | AI actions added to an already unattributable trail |
Audit trail disabled or alterable | Trail switched off or editable | Model or config changes left untracked |
Records not contemporaneous | Data recorded after the fact | Delayed or batch logging of AI-driven changes |
Inadequate validation | System not validated for intended use | Adaptive models are never revalidated after updates |
None of these is exotic, and none requires AI to occur, but AI raises the consequences of each by adding volume, autonomy, and change. Treating data integrity as the compliance expression of good data quality, rather than a separate box-ticking exercise, is what keeps a lab ahead of them.
What This Means for Your LabIn a regulated lab, AI does not lower the compliance bar; it raises the demands on the controls you already have. Hold AI-assisted systems to the same ALCOA+ and Part 11 standard as everything else, make sure the audit trail captures what the AI does and not just what people do, and confirm these controls during system evaluation rather than discovering a gap during an inspection. Keep a human in the loop for decisions that affect reportable results, apply change control to models, and review your audit trails as a matter of routine. Treated as the compliance face of sound data management rather than a separate burden, data integrity becomes something your systems enforce by default. For the broader picture of deploying AI responsibly across the lab, see the AI and automation guide. |
This article was produced under Lab Manager’s AI Editorial Guidelines








