
Protos II 4400 Audit Trails: FDA 21 CFR Part 11 Compliance to Field Level, Without Losing Data
Audit trails in regulated manufacturing tend to stop at the control room. The historian records who changed a setpoint on the SCADA screen, and that record satisfies an inspector looking at the process overview. But the measuring point itself, where a technician recalibrates a pH probe or connects a replacement sensor, is often invisible to that trail. If someone changes a calibration offset in the field and the system never logged it, you have a data-integrity gap that no DCS audit can close.
The Protos II 4400 with its FW4400-081 audit-trail extension takes FDA 21 CFR Part 11 and EU GMP Annex 11 compliance all the way down to the transmitter, recording every meaningful action at the measuring point, retaining those records even when the fieldbus drops, and enforcing role-based access so every entry is attributable to a named, authenticated user. At DP-Flow, when we specify instrumentation for regulated processes, this is the answer to the field-level blind spot.
Why the measuring point is a compliance risk
A process transmitter in a pharmaceutical or biotech plant is not a passive recorder. Calibrations are adjusted, sensors are swapped, configuration parameters are changed, and firmware is updated, all out at the line, sometimes by operators working alone. Each of those actions has the potential to alter a measurement that feeds a batch record. Under 21 CFR Part 11 and EU GMP Annex 11, any action that could affect a regulated data record must be attributable, contemporaneous, accurate and preserved: the ALCOA++ framework. A DCS audit trail that never receives data from the transmitter cannot satisfy those requirements for actions that happen below the fieldbus.
The practical question is not whether you need field-level audit records; in a regulated plant you do. The question is how the transmitter generates and preserves them.
What FW4400-081 records automatically
The audit-trail functional extension for the Protos II 4400 builds a logbook directly in the transmitter. No configuration is required to start capturing events: the extension records automatically from the moment it is active. The events captured include user login and logout (including auto-logout after inactivity), configuration changes, manual calibration, automated calibration runs triggered by the cCare system, firmware updates, communication module installation, time synchronisation changes, and sensor connect and disconnect events. cCare cleaning program runs are logged as well, so the full maintenance history of the measuring point is in one place.
Each record carries a consecutive sequence number, a date and time stamp, the measuring point TAG, and a plain-text UTF-8 description in the user's configured language. Sequence numbers are issued in strict order, so any gap is immediately visible; there is no mechanism to delete or reorder entries. That structure is what allows the logbook to satisfy the ALCOA requirement for originality and the Annex 11 requirement that audit-trail records cannot be altered or deleted.
Multi-level access and two-factor authentication
An audit trail is only as meaningful as its attribution. If every user logs in under a shared account, the record of who made a change is worthless. The Protos II 4400 avoids that problem through a central user database that manages individual user IDs, roles and permissions. Rights are assigned across a hierarchy from read-only through operator, maintenance and engineer levels to full administrator access. Each level determines which device functions that user can reach: a read-only role can view process values and logbook entries but cannot change configuration or initiate calibration; an administrator has full access to all functions and to user management itself.
Authentication uses two factors: the user ID and password from the central database, with an optional four-digit confirmation key delivered by SMS or email. For an unattended measuring point in a production area, that second factor is a practical deterrent against a colleague logging in on someone else's credentials. Every login attempt, successful or not, is entered in the audit trail, so the attribution chain is complete.
Role-based access also means you can give your QA team read-only visibility into calibration records and logbook entries without giving them the ability to alter anything. That separation of duties is a standard expectation in a Part 11 audit, and it is built into the transmitter rather than added on top.
512-record buffering: no data lost when the network drops
In a production environment, fieldbus communication is not guaranteed to be available at every moment. A network reconfiguration, a planned outage, or a transient fault can interrupt the connection between the transmitter and the control system for minutes or hours. During that window, the measuring point does not stop being operated: calibrations still happen, sensors are still swapped. If the audit trail only existed in the DCS historian, those records would simply not exist.
The Protos II 4400 buffers up to 512 audit-trail records on-device, for an unlimited period, regardless of whether the fieldbus is active. When communication resumes, the records are retrieved automatically in sequence. The buffer is large enough to cover extended outages in most plant environments, and the sequence-numbered structure means the receiving system can confirm that no records are missing. This is the mechanism that makes field-level compliance practical rather than theoretical: the records exist at the transmitter whether or not the network is available, and they reach your system intact once it is.
For how those records are retrieved and integrated into your control system over fieldbus, see our article on CalLog and full calibration protocols over fieldbus.
The standards it satisfies
The FW4400-081 extension is designed to satisfy FDA 21 CFR Part 11 and EU GMP Annex 11 in combination. Both regulations require that electronic records be accurate, attributable, legible, contemporaneous, original and accessible throughout their retention period. The ALCOA++ framework used in pharmaceutical quality systems adds consistency and completeness. The logbook structure in the Protos II 4400, consecutive sequence numbers, timestamped UTF-8 entries, no delete function, buffered retention during communication loss, and role-based attribution, maps directly to those requirements.
It is worth being precise about what this covers. The audit trail records actions at the transmitter and sensor: calibration, configuration, access and maintenance events. It does not replace your DCS historian or batch record system; it feeds into them. The combination of a Part 11-capable transmitter with a ProfiNET or Profibus communications module gives the control system access to the complete field record, closing the gap between the control room and the measuring point.
Two-factor authentication and access control in practice
Implementing role-based access on a transmitter does require some initial setup: user IDs, roles and permissions need to be defined in the central database before the system goes live. For plants moving an existing process into regulated production, that setup is part of the commissioning and validation work. For new installations, it is designed into the specification from the start. Either way, the architecture is in the hardware; you are configuring it, not adding it after the fact.
Remote access to calibration and configuration is handled through the same role-based system, so an engineer accessing the transmitter over the network is subject to the same authentication and logging as one standing at the panel. For details on how remote login and two-factor authentication work across measuring points, the Protos II 4400 remote login and 2FA article covers that in full.
Where this fits in the Protos II 4400 platform
The audit-trail extension is one functional module within a broader platform. The Protos II 4400 supports multiparameter measurement, automated sensor maintenance via cCare, fieldbus communication, and the CalLog calibration record system, all within the same transmitter housing. If you are specifying for a regulated process, you are likely to need several of these capabilities together rather than any single one in isolation. The Protos II 4400 platform overview sets out how the modules combine and what a fully specified regulated measuring point looks like.
Specifying for a regulated process
The right specification depends on the specific regulatory environment, the fieldbus infrastructure already in place, and the number and type of measuring points involved. A plant running Profibus and a plant running ProfiNET will arrive at different module choices; a process moving from development into GMP production may need the audit-trail extension added to an existing transmitter population, or the whole measuring point redesigned. The way to know what is needed is to look at your specific process, your network architecture, and your regulatory submission requirements together. At DP-Flow, that is the conversation we have at the start of a specification, not at the end.