Handling and security Current
Keeping an audit trail of who reviewed and approved a record
A practical description of what an audit trail should capture.
Knowing a record was reviewed isn't the same as being able to show who reviewed it, when, and what they decided. This guide describes what a practical audit trail captures. It reflects Vertical Flows' own operational practice, not a regulator's own checklist.
Action plan
1 Capture who acted and when, not just that something happened An audit trail needs a name and a timestamp attached to every material action.
A useful audit trail records who took each material action on a record and when, not just that the record now shows a particular status. "Reviewed" without a name and date attached is much weaker evidence than a specific, attributed action.
- Record who performed each review or approval action, by name or identifier
- Record when each action occurred
- Avoid status changes with no attributed actor behind them
Done when: Every material review or approval action is attributed to a specific person and time
2 Capture what was actually decided, not just that a decision was made An approval with no reasoning is harder to defend later than one with a brief note attached.
Beyond who and when, a useful audit trail captures what was decided, for example approved, rejected, or escalated, and ideally a brief note on why. This turns the trail into something that can actually explain a past decision, not just confirm one occurred.
- Record the specific outcome of each review, not just that a review happened
- Add a brief reason where the decision wasn't self-explanatory
- Keep this alongside the record it relates to, not in a separate untracked place
Done when: The audit trail captures the specific outcome and reasoning behind each review or approval
See how structured intake and review works3 Keep the trail append-only An audit trail that can be edited after the fact isn't reliable evidence of what actually happened.
An audit trail is only useful as evidence if past entries can't be quietly altered. Add corrections as new entries rather than editing or deleting the original record of what happened.
- Add new entries for corrections rather than editing past entries
- Don't allow past audit-trail entries to be deleted
- Keep the trail retrievable for as long as the underlying record itself is retained
Done when: The audit trail is append-only, with corrections recorded as new entries rather than edits