The obligation comes first
Before a software vendor designs a screen, a regulator has already decided what the screen must be able to prove. In most jurisdictions, financial records are subject to rules that predate computing by centuries: the principle of double-entry bookkeeping assumes that every transaction leaves a permanent mark, and that mark cannot be quietly erased. When accounting software arrived, it inherited that assumption. The audit trail — the timestamped, user-attributed log of who changed which record and when — is not a feature that vendors added to please enterprise buyers. It is the minimum condition for the records to be legally meaningful.
The practical consequence is architectural. A system that allows a line in the general ledger to be overwritten without leaving a trace of the original value is, in most regulatory environments, not compliant accounting software — it is a liability. SEC Rule 17a-4, which governs records retention for broker-dealers in the United States, requires that electronic records be preserved in a non-rewriteable, non-erasable format. Similar principles run through the UK's Companies Act and the EU's accounting directives. The software has to enforce immutability because the law demands it, and that shapes every design decision downstream.
Before the software, the deadline. The close is older than every system that serves it.
Thraex picture desk
What the log must contain
A useful audit trail is not simply a backup. It records the state before a change, the state after, the identity of the user who made it, the timestamp to the second, and — in better implementations — the business reason attached to the transaction. The difference matters enormously when an auditor or an investigator is working backward through a disputed period. A log that says a figure changed on a given date is less useful than one that shows it changed from £142,000 to £98,000, under the credentials of a named account, at 11:47 on the last day of the quarter.
Chronology
- Double-entry bookkeeping principleestablished centuries before computing; audit trail obligation inherited directly
- SEC Rule 17a-4US broker-dealer records retention rule requiring non-rewriteable electronic records (current regulation, ecfr.gov)
- Post Office Horizon Inquirychaired by Sir Wyn Williams; findings concerning defects in Horizon's audit integrity
That last detail — the last day of the quarter — is where audit trail requirements intersect with the mechanics of the period close. The close is the moment when entries are meant to stop, and systems enforce it by locking prior periods. But the pressure to adjust figures before the lock is intense, and the audit trail is the only independent record of what happened in those final hours. In documented cases of financial misstatement, the trail through the ERP's change log has been the primary evidence: not the filed accounts, but the internal log that showed what the accounts looked like before someone adjusted them.
The Post Office Horizon scandal is the extreme illustration of what happens when a system's audit trail is both present and contested. Horizon generated transaction logs that the Post Office used as evidence of shortfalls in subpostmasters' accounts. The Inquiry chaired by Sir Wyn Williams found that the system had defects, and that those defects were not disclosed when the logs were presented as reliable evidence in prosecutions. The scandal demonstrates that an audit trail can be formally present — records exist, timestamps exist — while the underlying integrity of the system is compromised. The log proves nothing if the system generating it cannot be trusted.
Distribution in the 1980s: one program, one machine, one box.
Thraex picture desk
The vendor's constraint
For vendors, audit trail requirements create a ceiling on flexibility. A customer who wants to edit a posted journal entry cannot simply be given that ability; the edit must itself become a record, visible to anyone who looks. This is why reversals exist as a formal accounting mechanism: you do not delete the wrong entry, you post a correcting entry against it, and both remain in the ledger. The software enforces the paper trail that the regulator requires.
This also explains why migrating financial data between systems is so technically and legally fraught. A new system must import not just current balances but the history of how those balances were reached — every adjustment, every reversal, every approval. A migration that carries figures forward without their history produces records that satisfy no auditor and may not satisfy the law. The audit trail, in other words, is not separable from the data. It is the data.