Home/Knowledge hub/What is an audit trail?
GlossaryWhat is an audit trail?
A chronological register of who did what with which document, essential for compliance, audits and disputes.
In short
An audit trail is an automatically maintained, chronological, and immutable record of all actions on a document: who created, opened, modified, approved, or deleted it, including timestamps and user information.
On this page
What is an audit trail?
In M-Files, every document is tracked throughout its entire lifecycle. Every action, from creation to final archiving, is recorded in an immutable log file. You don't need to set anything up for this: it happens automatically..
For organizations that comply with ISO 9001, ISO 27001, or the GDPR, an audit trail is not an option but a requirement. You must be able to demonstrate who had access to which information and when, and what was done with it..
SoftAdvice configures the audit trail in M-Files so that the appropriate actions are tracked, retention periods are respected, and standard reports are ready for your next internal or external audit.
Benefits of an automatic audit trail
Demonstrable compliance
Prove exactly who created, modified or approved a document at every external audit.
Complete history
Every version, status change and access automatically registered.
Fraud prevention
Unauthorised changes immediately traceable. The audit trail is immutable.
Dispute resolution
Provides irrefutable evidence of what happened and when in legal disputes.
ISO and GDPR-proof
Automatically meets ISO 9001, ISO 27001 and GDPR registration requirements.
Less manual work
No more spreadsheets. The audit trail is automatically built up in M-Files.
Implementing audit trail in M-Files
- Step 1
Define scope
Define which documents, systems and actions should be included in the audit trail.
- Step 2
Configure M-Files
SoftAdvice configures the audit trail: which actions are logged and for which document types.
- Step 3
Set retention
Determine how long the audit trail must be retained per your legal requirements.
- Step 4
Set up reports
Establish standard reports for internal reviews and external audits.
- Step 5
Validate and go live
After validating the logging, the audit trail goes live as part of your document management.
Frequently Asked Questions
What is an audit trail?
An audit trail is a chronological overview of all actions on a document: who created, opened, modified, approved, or deleted it, and when. In M-Files, this is automatically tracked without additional configuration.
Is an audit trail mandatory under GDPR
Not explicitly required, but GDPR mandates accountability for how you handle personal data. An audit trail is the most practical way to meet that accountability requirement. For ISO-certified companies, it is a direct requirement.
Can someone manipulate the audit trail?
No. In M-Files, the audit trail is unchangeable. No one, not even the system administrator, can modify or delete the log data afterwards.
How long should an audit trail be retained?
GDPR-related logs are typically retained for 3 to 5 years. Financial and legal documents often have longer retention periods. M-Files applies automatic retention rules per document type.
What is the difference with version control?
Version control keeps track of what content a document had at any given time. The audit trail records who performed which action. Together, they provide a complete picture of the document history.
Our consultants are happy to think along with you.
Plan a conversationSet up an audit trail for your organisation?
Discover how M-Files automatically builds an immutable audit trail for every document in your vault.
Continue learning
Related terms, articles and the M-Files capabilities behind this topic.