Tamper-evident audit log
A tamper-evident audit log records who did what and when in a way that makes any later change, deletion or reordering of its entries detectable.
A tamper-evident audit log is a record of actions (who did what, to which record, and when) built so that any later alteration, deletion or reordering of its entries can be detected. The usual mechanism is a hash chain: each entry stores a cryptographic hash of the entry before it, so changing one entry breaks every link after it, and anyone recomputing the chain finds the break. The property is detection, not prevention. As computer scientists Scott Crosby and Dan Wallach put it, "tamper-resistance for such a system might be impossible," but "tamper-detection should be guaranteed in a strong fashion" (Efficient Data Structures for Tamper-Evident Logging, USENIX Security 2009). Their tree-based design lets an auditor confirm that a given event is still present, and that today's log is consistent with an earlier copy, without replaying the whole chain.
Regulated recordkeeping has moved toward the same idea. In October 2022 the SEC amended Rule 17a-4 so that broker-dealers can keep electronic records either in write-once, read-many (WORM) storage or in a system that maintains "a complete time-stamped audit trail" of modifications and deletions, so the original record can be re-created (Release No. 34-96034). WORM storage stops a record from being overwritten; an audit trail lets the record change while proving what it said before.
Compliance teams rely on such a log for evidence. A dismissal logged with a reason, an obligation reassigned, a deadline moved: each persuades an examiner only if nobody could have quietly edited it afterward. RegWatch keeps a hash-chained, append-only audit log for this reason. When comparing tools, ask how tampering would be detected, who can run the check and whether the log can be exported. Role-based access control sets the permissions, the log proves how they were used, and a credible regulatory change log depends on that record.
This entry is general information, not legal advice.
Sources
- Crosby and Wallach, Efficient Data Structures for Tamper-Evident Logging (USENIX Security Symposium, 2009) accessed 30 Sep 2026
- SEC, Release No. 34-96034, Electronic Recordkeeping Requirements for Broker-Dealers, Security-Based Swap Dealers, and Major Security-Based Swap Participants (12 October 2022) accessed 30 Sep 2026
