</p>
WHAT IS AN AUDIT TRAIL, AND WHY SHOULD A SHIPMENT PROCESS BE TRACEABLE?
A shipment can pass through Sales, Procurement, the supplier, forwarder, customs broker, Finance, Warehouse and several digital systems. When a manifest is wrong, quantities differ, a declaration is delayed, charges are disputed or a post-clearance audit begins, the key question is not only “where is the final document?” It is also who supplied the data, who approved it, when it changed, what evidence supported the decision and how the exception was resolved. Storing only the final PDF makes it difficult to assign responsibility or demonstrate a reasonable process. An Audit Trail reconstructs the shipment’s event sequence and links source data to decisions and outputs.
QUICK FACTS
Definition
A chronological record showing who did what, when, based on which data, and with what result.
Not merely file storage
A folder is not an Audit Trail if versions, actors, timestamps and reasons for changes cannot be identified. Audit Trail is a governance and control concept adapted to shipment operations; it is not a separately defined statutory term in Vietnam’s Customs Law.
Operational value
Supports root-cause analysis, accountability, SLA control, claims and recurrence prevention.
Compliance value
Provides a coherent evidence chain for customs, tax, auditors and sectoral authorities.
SCOPE
This article applies to import and export shipments by sea, air, road or rail and is relevant to trading companies, factories, EPE/FDI enterprises, logistics providers, customs brokers and procurement, finance and warehouse teams.
An Audit Trail may be maintained in a TMS, ERP, WMS, customs system, document-management system, email, ticketing tool, enterprise chat or controlled spreadsheet. The tool itself does not determine quality. The decisive factor is whether events, source evidence and approvals can be linked and reconstructed.
TERMS
| Term | Meaning | Shipment role |
|---|---|---|
| Audit Trail | A chronological set of records used to reconstruct activities leading to an operation or result. | Identifies source data, actors, timing, changes and outputs. |
| Audit Log | A system log of access, operations and data changes. | A technical component of the Audit Trail, but not the complete business evidence. |
| Event | A control-relevant action such as booking receipt, invoice revision, declaration transmission or delivery. | The basic unit of shipment history. |
| Timestamp | Date, time and time zone attached to an event. | Establishes sequence and supports cut-off, SLA and free-time analysis. |
| Version Control | A method for identifying original, revised, reviewed and final records. | Prevents use of obsolete invoices, packing lists, draft bills or technical files. |
| Chain of Custody | A record of who received, held and transferred goods or documents. | Important for seals, originals, samples, high-value cargo and loss claims. |
| Exception Log | A controlled record of deviations, decisions, approvals and corrective actions. | Turns incidents into manageable evidence and learning data. |
HOW AN AUDIT TRAIL WORKS
A useful Audit Trail links three layers: source data → processing decision → output. If a declared quantity is corrected, the company should not retain only the final declaration. The trail should show which packing list was used, who found the discrepancy, who confirmed the actual quantity, when the change was approved and the system result.
Source data
PO, contract, invoice, packing list, booking, catalogue, origin and carrier notices.
Action
Review, approval, revision, filing, trucking, release and delivery.
Actor
Performer, reviewer, approver and source-data provider.
Time
Request, response, completion and version-effective timestamps.
Output
Confirmed booking, accepted manifest, cleared declaration, signed POD or approved invoice.
Exception
Cause, impact, treatment decision, cost and preventive action.
AUDIT TRAIL VS DOCUMENT STORAGE AND TRACKING
| Tool/concept | Main question | Strength | Limitation | When it becomes control evidence |
|---|---|---|---|---|
| Document repository | Where is the file? | Centralises documents. | May not show the version used, actor or change reason. | When version, owner, timestamp and event links exist. |
| Shipment tracker | Which milestone is current? | Shows progress and ETA. | Often lacks decision evidence and document history. | When milestones are supported by evidence and confirmation. |
| System audit log | Who operated the system? | Objective and timestamped. | Does not explain off-system communication or business rationale. | When combined with tickets, approvals and source documents. |
| Audit Trail | What happened, in what sequence and why? | Reconstructs cause, responsibility and evidence. | Requires data standards and update discipline. | When the event chain is complete from input to final output. |
MINIMUM EVENT FIELDS
| Field | Required content | Example | Risk if missing |
|---|---|---|---|
| Shipment ID | Unique identifier linking PO, booking, declaration and delivery. | IMP-2026-00725. | Records cannot be consolidated. |
| Event/Milestone | Name of the action or control point. | Draft B/L approved. | The record has no process meaning. |
| Timestamp | Date, time and time zone. | 20 July 2026, 14:35 GMT+7. | Cut-off and SLA sequence cannot be proven. |
| Actor/Owner | Person and function responsible. | Import Operations. | Accountability cannot be assigned. |
| Source | Evidence used for the action. | PL_v03 and supplier email. | The decision lacks support. |
| Action/Decision | What was done and approved. | Gross weight revised from 8,250 to 8,520 kg. | The change cannot be reconstructed. |
| Output/Status | Result, reference or status. | Manifest amendment accepted. | Completion is uncertain. |
| Exception/Reason | Cause and impact of deviation. | Supplier error; cut-off delayed two hours. | Recurrence cannot be analysed. |
RECORDS TO LINK BY SHIPMENT MILESTONE
| Milestone | Input evidence | Events to retain | Locked output | Main owner |
|---|---|---|---|---|
| Transaction setup | PO, contract, Incoterms and delivery requirements. | Order confirmation, scope and approval. | Shipment brief and ID. | Buyer/Procurement. |
| Booking and pickup | Ready Date, cargo details and booking request. | Booking submission, schedule changes and pickup confirmation. | Booking confirmation and pickup order. | Forwarder/Logistics. |
| Transport documents | SI, draft B/L or AWB, VGM and manifest data. | Draft issuance, revisions and approval. | Accepted B/L/AWB and manifest. | Docs/Carrier/Forwarder. |
| Customs | Invoice, packing list, HS memo, origin and licences. | Data review, filing, channel result and amendments. | Final declaration and customs result. | Importer/Customs Broker. |
| Delivery | Delivery order, trucking order, seal and warehouse slot. | Pickup, seal check, count and damage record. | POD, handover report and photos. | Operations/Warehouse. |
| Cost settlement | Quotation, vendor invoices and charge list. | Scope review, exception approval and allocation. | Approved cost sheet and invoice. | Logistics/Finance. |
| Shipment closure | Final records and exception log. | Reconciliation, closure of open items and retention confirmation. | Master file and closure record. | Compliance/Document Control. |
IMPLEMENTATION PROCESS
- Assign one Shipment ID: use it across PO, booking, customs, warehouse and accounting.
- Define mandatory milestones: retain evidence for material control events rather than every informal message.
- Set RACI ownership: identify data provider, performer, reviewer and approver.
- Standardise event records: each material event needs timestamp, actor, source, action, output and exception.
- Control versions: define Draft, Reviewed, Approved and Final status; prevent overwriting approved versions.
- Reconcile before closure: customs vs accounting vs warehouse; booking vs transport vs delivery; quotation vs invoice vs exception approval.
- Retain and protect: define retention, access, backup, export capability and personal/commercial data safeguards.
COMMON RISKS AND ERRORS
| Error | Cause | Impact | Control |
|---|---|---|---|
| Only the final file is kept | No version rule. | The origin of wrong data is unknown. | Retain revisions and approval reasons. |
| Private chat is the main source | No official process channel. | History disappears when staff leave or delete messages. | Move material decisions into email, tickets or the system. |
| Inconsistent timestamps | Multiple time zones or manual entries. | Cut-off and SLA disputes. | Record time zone and synchronise systems. |
| Approver not recorded | Only the operator is logged. | Execution and authority cannot be separated. | Separate actor, reviewer and approver. |
| Old data is overwritten | Direct editing is allowed. | Original evidence is lost. | Lock approved data; revise through versions/amendments. |
| Too much unindexed storage | Email and files are dumped into folders. | Slow search and incomplete reconstruction. | Index by Shipment ID, milestone and document type. |
| Weak data protection | Broad access and public links. | Pricing, contacts and legal records may leak. | Role-based access, access logs and retention controls. |
LEGAL BASIS AND SOURCES
| Source/instrument | Authority/effect | Relevance | Application note |
|---|---|---|---|
| NIST CSRC Glossary – Audit Trail / Security Audit Trail | National Institute of Standards and Technology (NIST). | It compiles technical definitions centred on chronological reconstruction of activities and traceability from transactions to records and reports. | It is a technical reference, not a Vietnam logistics-law definition. Shipment use must connect documents, approvals, changes and operational events. |
| Consolidated Customs Law 54/VBHN-VPQH (2026) | Office of the National Assembly; issued 23 March 2026. | Declarant responsibility, customs-record retention and post-clearance audit. | Article 18 requires core customs records to be retained for five years from declaration registration; Articles 77–80 govern post-clearance audit. |
| Decree 08/2015/NĐ-CP, amended by 59/2018/NĐ-CP and 167/2025/NĐ-CP | Government; Decree 167/2025 effective 15 August 2025. | Detailed customs procedures, inspection and supervision. | The record trail should reflect the actual procedure type and customs status. |
| Accounting Law 88/2015/QH13 | National Assembly; effective 1 January 2017. | Requirements for accounting documents, books and retention. | Accounting retention periods may differ from customs periods. |
| Law on Electronic Transactions 20/2023/QH15 | National Assembly; effective 1 July 2024. | Framework for data messages, electronic transactions and electronic information retention. | Systems should preserve accessibility, integrity and evidential value where applicable. |
| Personal Data Protection Law 91/2025/QH15 | National Assembly; issued 26 June 2025, effective 1 January 2026. | Applies to personal data that may appear in emails, contact information, documents and user logs. | Audit Trail design should define purpose, access, security and an appropriate retention period; it does not justify retaining every data item or log indefinitely. |
FAQ
1. Is a complete shipment folder already an Audit Trail?
Not necessarily. It must also identify which version was used, who acted, when, why a change was made and what result followed.
2. Is specialist software mandatory?
No. A company may start with controlled DMS, ERP, tickets or spreadsheets. As volume increases, automatic logging and access controls become more important.
3. Can email be evidence?
Yes, when sender, recipient, time, content and attachments can be identified. Material decisions should still be copied into the official master record.
4. When should the Audit Trail begin?
At the transaction or RFQ/PO stage, not only at customs filing. Many risks begin with quotation scope, Incoterms, Ready Date and booking data.
5. Can Audit Trail records be corrected?
Yes through a controlled correction or amendment. The old record, person making the change, timestamp and reason should remain visible.
6. Who is responsible?
The cargo owner controls its master file; each department and service provider is responsible for its data and actions. A designated owner should govern the complete record.
7. Can an Audit Trail reduce logistics cost?
It does not reduce freight rates directly, but it helps identify causes of detention, document amendment, waiting, missed cut-off and out-of-scope charges, supporting prevention and claims.
Tiếng Việt
中文 (中国)
NEED TO REVIEW IMPORT PROCEDURES OR A SHIPPING PLAN?
Send us the product name, shipping route, current dossier, or implementation request in advance so we can suggest a suitable approach that is practical, focused, and aligned with your shipment.
Cargo Damage at a Port or Warehouse: An Immediate Response Checklist
What Is General Average? How Cargo Interests Should Respond to a GA Notice
When should businesses photograph or video container stuffing and opening?
When Can Cargo Insurers Reject or Reduce a Claim?
Risks of Failing to Inspect a Container Before Cargo Stuffing
Risks of Failing to Inspect a Container Before Cargo Stuffing
What Documents Are Required for a Cargo Insurance Claim?
What Information Should a Cargo Damage Survey Record Contain?
Total Loss vs Partial Loss in Cargo Insurance: What Is the Difference?
Cargo Dented, Wet or Missing Packages: What Should a Business Do?
Who Must Arrange Insurance under CIF and CIP?
Export Process: From Purchase Order to Final Document Set
How Is Cargo Insurance Value Determined?
How Do ICC-A, ICC-B and ICC-C Cargo Insurance Conditions Differ?
When Should a Business Buy Separate Cargo Insurance?