Audit Trail
A chronological, immutable record of every action taken within a system. Audit trails document who did what, when, and why, creating the evidence base that auditors and regulators rely on.
Why it matters
Without audit trails, compliance claims are unverifiable. When an auditor asks how you know a control was tested, or when a regulator investigates an incident timeline, the audit trail is your proof. Immutability is the key property: if records can be altered after the fact, they have no evidentiary value. Every major framework, from ISO 27001 to SOC 2, expects demonstrable audit logging.
In practice
Audit trails capture state changes across your GRC operations: risk assessment updates, control effectiveness reports, incident response actions, policy approvals, and user access changes. In vucavoid, every operation produces an immutable trail. Effectiveness reports, risk assessments, and incident timelines are recorded with timestamps and user attribution, feeding directly into your Compliance ID as verifiable, external-facing proof.