Skip to content
AMPthilly home
Get started
Compliance & audit

What Is an Audit Trail?

Plain-English definition of an audit trail in asset management, with a worked example, what auditors ask for, how long to keep one, and how to keep yours intact.

AMPthilly Updated

An audit trail is a chronological record of every change made to an asset or record, showing who did what, when, and what the value was before and after.

An audit trail is a chronological record of every change made to an asset or record - who did what, when, and what the value was before and after. In asset management it is the running history behind each line in the register: every checkout, transfer, repair, and edit, in order, with a name and a timestamp attached. It is the evidence layer a fixed asset audit leans on, the backbone of an asset’s chain of custody, and the foundation of genuine audit readiness.

What an audit trail records

The useful unit is the event, and a complete event has four parts: the actor, the timestamp, the action, and the before-and-after values. For a single laptop, a healthy trail might read: purchased and registered in January, assigned to a named employee in February, status changed to “in repair” with a ticket attached in October, returned to storage with condition notes the following spring, transferred to a new starter a week later.

Anything that changes the record belongs in the trail: ownership and location changes, status changes, edits to fields like purchase price or serial number, attached documents, approval decisions, and maintenance entries. An entry that only says “record updated” is a gap wearing a timestamp.

A worked audit trail example

Definitions are easier to trust once you can see one. Here is the trail for a single monitor, asset MN-0117, read top to bottom - each line is one event, and each event carries the four parts above:

  • 12 Jan, 09:14 - Priya Shah created the record. Status set to “in storage”; purchase price €189 entered from the supplier invoice (attached).
  • 03 Feb, 11:02 - Priya Shah checked the monitor out to Tomas Lind, Sales. Status: in storage → in use. Location: HQ store → Desk 4-12.
  • 19 Aug, 16:40 - Tomas Lind reported an issue: “flickering, bottom-left corner”. Ticket #4471 opened, photo attached. Status: in use → in repair.
  • 02 Sep, 10:20 - Marco Reyes resolved ticket #4471 (“panel replaced under warranty”, invoice attached). Status: in repair → in use.
  • 14 Nov, 08:55 - System flagged the checkout as overdue after Tomas Lind left the company.
  • 15 Nov, 09:30 - Priya Shah transferred the monitor to a replacement starter, Ines Haddad. Owner: Tomas Lind → Ines Haddad. History preserved.

Read as a whole, those six lines answer every question an auditor, a manager, or an insurer might ask: who has it now, who had it in March, whether the repair was covered, and whether anything was quietly changed. That is the difference between a register (which only shows the last line) and a trail (which shows all of them).

Audit log vs audit trail

The terms get used interchangeably, but there is a worthwhile distinction. A log is what the system writes - a raw, system-wide stream of events. A trail is what you can follow - the reconstructable history of one specific asset or transaction. Logs are the raw material; the trail is the path through them. A system that records plenty but cannot show you everything that ever happened to asset LT-0042, in order, has logs but no trail.

Put another way: logs are generated automatically as a by-product of the system running, while a trail is the review-ready view built for governance - searchable, tied to a record, and readable without a database query. Relying on raw logs alone means someone has to reconstruct the timeline by hand every time a question comes up; a proper trail has already done that work.

Why an audit trail matters

The register tells you what is true now. The trail tells you how it became true - and that history does real work:

  • Accountability. Every action is tied to a named person under their own login, so responsibility is never in doubt. When people know actions are recorded, careless handling and quiet misuse drop - the trail is a deterrent as much as a record.
  • Fraud and error detection. An unbroken history makes unauthorised changes and unusual patterns visible, and lets you trace a mistake back to the moment it was made and correct it, rather than guessing.
  • Dispute resolution. “I returned that months ago” and “that monitor was already damaged when I got it” are settled by evidence, not memory - usually before anyone senior gets involved.
  • Insurance, theft and offboarding. Claims, police reports, and clean handovers of a leaver’s equipment all rest on a documented history of who held what, and when.
  • Compliance. Auditors and regulators want to see not just the current position but proof of how you got there. A trail is what turns “trust us” into “here is the record”. It also underpins the internal controls auditors test - segregation of duties and approvals only mean something if they are recorded.

Why auditors ask for one

An auditor’s job is to test claims: this asset exists, it is assigned to this person, it was disposed of when the books say it was. A register only states the current position; the trail substantiates how it got there. The same evidence settles everyday disputes long before any auditor arrives, and underpins insurance claims, theft reports, and clean offboarding when a leaver’s equipment is handed back.

Without a trail, your register is a snapshot. It can tell you who has a device today, but not who had it in March, which is usually the question that matters.

Audit trail requirements and how long to keep one

Whatever the framework, the requirements rhyme. A trail that will hold up needs to be:

  • Complete - every entry carries who, when, what action, and the before-and-after values, with nothing that matters happening off the record.
  • Attributable - each event ties to an individual identity, not a shared “admin” account.
  • Tamper-evident and append-only - history can be added to but never silently overwritten or deleted, so a reader can trust that what they see is what happened.
  • Time-accurate - timestamps reflect when the event occurred, not when someone got around to typing it in.
  • Retrievable - you can filter to one asset or person and export the history when asked, without a developer in the loop.

How long to keep it is set by the strictest rule that could reach back to the record. As a rough guide, financial-reporting regimes such as the Sarbanes-Oxley Act (SOX) commonly expect around seven years, health records under HIPAA about six, and PCI DSS at least twelve months of readily available history. The safe default is the longest period any regulation, contract, or litigation hold requires - and, crucially, to keep a retired asset’s trail for that whole window. That is why disposed assets should be marked as retired rather than deleted: removing the record throws away exactly the history the retention rule is asking you to keep.

What breaks an audit trail

  • Editable history - in a spreadsheet, any cell can be overwritten silently, so there is no before-and-after, only the latest claim.
  • Shared logins - if every action was taken by “admin”, the who column is decorative.
  • Side channels - handovers agreed in chat or by a nod in the corridor never enter the record.
  • Deleting instead of retiring - removing a disposed asset’s record destroys its history; the trail should outlive the asset.
  • Batch back-filling - entering a month of events in one sitting produces timestamps that describe the data entry, not the events.

Audit trails in practice

The pattern that holds up: every change goes through a system that records it automatically, everyone acts under their own login, and records are retired rather than deleted. Then a physical inventory count or asset reconciliation becomes a comparison against evidence rather than against memory. In AMPthilly, checkouts, returns, transfers, status changes, field edits, tickets, and approvals are logged automatically into a filterable timeline on each asset, with a system-wide admin view and CSV export for auditors.

Free to start, no card required

Put your register to work

AMPthilly gives every asset an owner, a location, and a history - checkouts, printable QR labels, service desk, and audit trail in one place. The free plan covers 3 users and 25 assets, with SSO and MFA included.