ComplyMyImport guide
Compliance audit trails for product records
An audit trail explains how a compliance conclusion was reached and what changed afterward. It should connect actions to a user, product, source, time, and reason rather than merely recording that a file exists.
Events worth recording
- Document uploads, replacements, and deletions
- Extracted fields, confidence, and source locations
- Applicability rule-pack results
- Evidence acceptance, rejection, and conflicts
- Reviewer overrides and rationale
- Supplier and laboratory assignments
- Certificate drafts, approvals, and supersession
- Product Registry submissions and responses
- Broker-package exports and corrections
- Authentication, authorization, and break-glass access
Preserve immutable approvals
Once an authorized representative approves a certificate, preserve that exact version and its evidence snapshot. Later edits should create a new version rather than rewriting history.
Make events useful
Store structured event types and relevant identifiers, not sensitive document contents in free-form logs. Include tenant and product scope, actor, timestamp, prior and new state where appropriate, and the reason for a manual decision.
Support investigation and renewal
Audit history helps answer which report supported a citation, when a laboratory scope was checked, which certificate identifiers were sent to a broker, and whether a change occurred before a shipment. It also supports periodic reviews and supplier accountability.
Limit access
Audit logs can expose sensitive business activity. Apply role and product authorization, monitor administrative access, and avoid accepting tenant identifiers from the browser as authority.
ComplyMyImport records key evidence, approval, export, assignment, and access events while keeping certificate issuance under authorized human control.
This guide is general educational information, not legal advice.