When the Auditor Asks "Who Changed This Record?" —— Five Steps to Ensure Compliance of Electronic Records

By: QTank Published: 9/24/2026 Views: 23
Current rating: ★★★☆☆ Rate this Equivalent to 8 ratings

1. After Going Paperless, Where Does the Evidence Chain Break?

A year after the MES (Manufacturing Execution System) went live in a certain automotive parts company, the workshop no longer filled out paper inspection forms. Inspectors simply tapped "合格" (conforming) and "提交" (submit) on the workstation tablets, and the data went directly into the database. The quality manager could pull up real-time dashboards at any time. In his view, the paperless initiative was complete—no more manual copying, no more double entry, no more end-of-month catch-ups.

However, when a customer conducted a process audit, the auditor picked a batch from three months ago and asked three questions: First, who made this record? Second, what was the original recorded value, and who changed it to the current value and when? Third, which version of the inspection standard was used at the time? The company failed to answer all three questions. The first question was stuck on the account—multiple team members shared a single "IPQC01" account, and the system couldn't trace it back to a specific person. The second question was stuck on the traceability—only the final state was saved in the system, and there was no way to track what changes were made, how many times, or by whom. The third question was stuck on the version—the old version was directly "overwritten" by the new one, and the original document no longer existed. The audit conclusion was: there are systemic defects in the traceability and authenticity of the records, requiring immediate rectification and inclusion in the next round of focused reviews.

This is not an isolated case but a common state in the second phase of paperless initiatives. In the paper record era, signatures, dates, and strikethroughs on a form constituted a visible evidence chain. In the electronic record era, this chain does not automatically continue—it must be re-established in the system in another form. Otherwise, the system does not make records more controlled; it just hides the lack of control deeper. In the paper era, you could immediately see if a form had been altered; in the electronic era, you might not even realize that a record has been changed.

2. Principle: What Are the Essential Elements for Reliable Electronic Records?

ISO 9001 Clause 7.5.3 outlines a set of requirements for the control of documented information, which can be broken down into seven tasks: distribution, access, retrieval and use, storage and protection (against loss and tampering), change control (versioning and identification), retention and disposal. In a paper-based environment, these tasks are achieved through physical means—controlled stamps for distribution, filing cabinets for storage, strikethroughs and stamps for changes, and numbered ledgers for retrieval. In an electronic environment, the physical means disappear, and these tasks must be managed by system functionality design.

The industry often summarizes the reliability of electronic records with five attributes: attributable (can be traced to a specific executor), legible (readable, understandable, and printable), contemporaneous (recorded time matches the actual occurrence time), original (the first true value can be traced), and accurate (no uncontrolled modifications or errors). In an audit scenario, these five attributes translate into one sentence: the auditor must be able to independently trace "who, when, based on what, did what, and what was changed" through the records.

Understanding this point helps clarify the differences between paper and electronic records.

Control Dimension Implementation Method for Paper Records What Electronic Records Must Rely On Common Vulnerabilities
Attribution Handwritten signature / employee ID stamp Real-name account + operator binding + electronic signature Shared accounts, proxy filling, administrator entry
Change Control Strikethrough + stamp + date Audit trail (before and after values, person, time) Direct overwrite, deletion and re-creation
Version Identification Document number + version stamp Version field + effective date + retention of old versions Overwrite in place, old versions lost
Storage Protection Locked filing cabinets, fire and moisture protection Permission levels + tamper protection + backup Everyone can edit, no backup verification
Retrieval Numbering rules + ledgers Multi-dimensional indexing by batch, time, equipment, personnel Only searchable by form number, batch traceability relies on asking people
Retention and Disposal Retention schedule + destruction register Retention strategy + archiving upon expiration + migration plan Backup as archiving, no migration plan
Release and Authorization Hand-signed approval Approval workflow + authorization matrix + no skipping allowed Verbal approval via WeChat, post-event signing

This table is recommended for self-checking: if you can't answer any row, that's where the problem lies.

3. Implementation: Five Steps to Ensure Compliance of Electronic Records

Step One: Separate "system data" from "system records" and create an electronic record checklist first.

Not all data in the system are system records. Screen data based on whether "this data will be used to prove something in the future." At a minimum, identify the following categories: batch, release, concession, and inventory freeze records in ERP; process parameters, inspection judgments, and equipment inspection records in MES; nonconforming product reports, 8D, change, and calibration records in QMS; original data and equipment output files in the laboratory; and scattered forms that are often overlooked—email approvals, "agreements" in WeChat or DingTalk groups, Excel ledgers, on-site photos and videos taken with mobile phones, and scanned documents. Each row on the checklist should clearly state four things: record name, hosting system, responsible person, and retention period and location. This checklist sets the boundaries for all subsequent work; without it, "controlled electronic records" is just a slogan.

Step Two: Real-name attribution—binding accounts, signatures, and executors.

Attribution is the first critical point for electronic records. Three rules must be strictly enforced: one person, one account; real-name accounts; no sharing. If someone is substituting or operating on behalf of another, they must follow the "proxy authorization" process and leave a record, rather than borrowing a colleague's account. The "operator" field in the system should correspond to a unique individual in the personnel ledger. If the system supports electronic signatures, ensure that the signature is strongly bound to the account, not a reusable image. Additionally, address a frequently overlooked aspect: account management for resignations and transfers. Immediately deactivate accounts when employees leave for security reasons, but document the deactivation action—because if an account is reused or deleted, the question "who made this record" will have no answer. The correct approach is to deactivate without deleting, retain historical associations, and record the deactivation time and reason.

Step Three: Traceability and tamper protection—audit trails are the electronic equivalent of "strikethroughs and stamps."

This step is where audits often deduct the most points. Check the following specific items: whether the system has audit trails enabled, whether it records before and after values, the operator, and timestamps; whether records can be deleted without a trace, and whether deletion actions are recorded; whether key fields (inspection values, judgment conclusions, release status) are locked after submission; whether there are permission levels to prevent "anyone can modify"; and whether timestamps come from a unified server time, not local device time (local time can be manually adjusted, and any time discrepancies will undermine the credibility of the records). One point that business departments often resist is traceability, which can expose real work repetitions. It's important to clarify in advance—audit trails are not for blaming employees but for proving the reliability of the records. Without traceability, if a customer questions the data, the company has no way to defend itself.

Step Four: Readable, usable, and long-lasting.

One risk of electronic records that paper records don't have is their readability depends on technology and systems. Three actions must be taken: separate backup from archiving—backup ensures "the system can be restored if it fails," while archiving ensures "the record can still be retrieved as evidence ten years later." The two cannot replace each other; regular recovery drills must be conducted for backups, as unverified backups are essentially useless. format and migration—records provided externally should be output in formats that do not depend on specific software (such as PDF) and ensure they print clearly and completely. When upgrading systems, switching systems, or when a supplier discontinues service, a migration or read-only retention plan for historical records must be planned in advance to avoid "the old system is decommissioned, and three years of records disappear." retain both raw data and processed results—for any data that has been calculated, rounded, or had anomalies removed (such as SPC raw measurement points, original test curves), the raw data must be retained in the records. Saving only the processed conclusions directly discards the "originality" attribute.

Step Five: Searchable and demonstrable—turn retrieval into a rehearsal.

One of the ultimate uses of records is to "be readily available." Design two dimensions: search dimensions should cover the ways customers actually ask—by batch number, time period, equipment, personnel, and type of nonconformity; demonstration scripts should be pre-rehearsed—when a customer conducts a surprise audit, the goal is to present "original records + judgment conclusions + authorized signatures + modification traces" within a few minutes, not "wait for IT to help me export it." The most common issue exposed during rehearsals is not the inability to find records but finding a bunch of records that don't match each other—MES shows conforming, ERP shows concession release, and the nonconforming product report in QMS has no corresponding number. This "record contradiction between systems" is the most damaging in an audit, as it directly questions the authenticity of the records. It is recommended to conduct a quarterly cross-system sample comparison to resolve contradictions before customers discover them.

12-Point Self-Check for Electronic Records (can be used as a checklist): ① Is there an electronic record checklist and retention schedule? ② Are there any shared accounts? ③ Can the operator be traced to a unique individual? ④ Are audit trails enabled and cover key fields? ⑤ Are before and after values and operation times complete? ⑥ Are key records locked after submission? ⑦ Are permissions tiered, and is unauthorized access prevented? ⑧ Do timestamps come from a unified server time? ⑨ Have backups been tested for recovery? ⑩ Is there a migration plan for historical records when systems are replaced? ⑪ Are raw data and processed results retained simultaneously? ⑫ Has a complete retrieval rehearsal been conducted?

4. Five Common Misconceptions

Misconception One: Equating "data in the system" with "controlled records." The existence of data does not equal the reliability of records. Data is a technical product, while records are a management product. The former is the responsibility of IT, and the latter must be defined by the quality department. These two tasks are often disconnected in many companies—this is why the first and second steps must be led by the quality department.

Misconception Two: Locking only the result, not the process. Many people believe that "the final judgment value cannot be changed" is enough. In reality, audits focus on the process: how this value was derived, whether it was changed, and the basis for the change. An electronics company was once questioned by a customer about the abnormal fluctuation in a batch of parameter records, and it was discovered that the operator had "rounded off" the readings from the equipment alarms when manually entering them into the system. There was no trace in the system, but when the customer compared the system data with the built-in logs of the equipment, the discrepancy was immediately apparent.

Misconception Three: Using screenshots and chat records as records. "This batch can be released" in a WeChat group, casually taken photos, and approval comments in chat windows are all unattributable, untraceable, and editable. Including such media in the formal record system is equivalent to voluntarily giving up the credibility of the records. The correct approach is to move approvals back into the system forms, using chat records only as clues, not as evidence.

Misconception Four: Treating backup as archiving. Backup is for "recovery" and is typically rolling, with a short retention period. Archiving is for "evidence" and requires long-term retention according to the retention schedule and cannot be casually modified. Using a rolling backup to serve the archiving function often results in records being overwritten when needed after three years.

Misconception Five: Implementing without governance. The most vulnerable moment for electronic records is not the day they go live but two years later: after a round of personnel changes, several process modifications, a few standard upgrades, and numerous system patches. Without annual reviews, rules will gradually become ineffective without notice. Writing "electronic record compliance checks" into the annual internal audit plan is the most cost-effective way to ensure compliance.

5. One Sentence Summary

Going paperless is not about moving paper to the screen but about redesigning signatures, traceability, and retrieval as system functionalities—records must be reliable to qualify for paperless status.


The bottom line of going paperless is that records must still be traceable and verifiable.

Knowledge code: 2.3.1

Version: v20260924

Author: QTank QTank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping companies continuously improve their quality capabilities.