Hello everyone,
We are currently working on a Totara implementation in a regulated (pharma) environment and have encountered some challenges related to audit trail requirements.
The client requires compliance with 21 CFR Part 11 (specifically audit trail expectations under section 11.10(e)) as well as expectations aligned with EU GMP Annex 11.
We are also aware of Totara’s official documentation regarding Part 11 compliance (electronic records and signatures), which provides useful context on how the platform approaches these requirements:
https://totara.atlassian.net/wiki/spaces/DEV/pages/173244705/Totara+FDA+CFR+Part+11+Compliance+Electronic+signatures
As you know, Totara provides Site Logs that capture system-level changes. However, in our case we are facing a couple of challenges:
The logs are not easily readable from a compliance/audit perspective.
In some areas (e.g. Perform), certain changes are not fully reflected (e.g. additions/removals in competencies).
This has raised concerns during the Operational Qualification (OQ) phase.
At this point, we would really appreciate hearing from others in the community who have worked in similar regulated contexts.
In particular:
Have you successfully passed OQ/PQ using Totara Site Logs as audit trail evidence?
How have you addressed limitations in readability or missing “before/after” values?
Have you implemented any workarounds (technical, reporting, or procedural) to support compliance?
How have auditors or QA teams typically reacted to Totara’s audit trail capabilities?
We understand that interpretations may vary depending on risk-based approaches, so any shared experience or guidance would be extremely helpful.
Thanks in advance!