Audit Trail Reconstruction: Rebuilding a Complete Record of Data Changes
An investigation, customer dispute, or Regulator enquiry arrives and the change history is incomplete, truncated, or never existed. "We do not know who changed that record" is not an answer under POPIA or commercial litigation.
We reconstruct a defensible compliance trail from the debris of logs and backups.

Sound Familiar?
These are the exact issues compliance officers, legal leads, and CFOs describe when the trail is already gone:
- An investigation, dispute, or audit arrives and the change history is truncated, purged, or was never logged
- Compliance is reconstructing who edited a record from email threads, screenshots, and partial database dumps
- Cloud and SaaS audit logs retained only 90 days, so the period under review returns empty
- "We do not know who changed that record" is the answer counsel and the Information Regulator would get today
- External forensic firms quote emergency rates once a litigation hold or enforcement notice lands
Incoming audits, litigation holds, and customer disputes do not wait for perfect logs. Globally, record-keeping failures have drawn hundreds of millions in regulatory fines, and incomplete trails routinely double forensic and counsel spend. In South Africa, POPIA accountability and commercial discovery expect you to prove processing history, not shrug.
What Audit Trail Reconstruction Actually Does
Mine debris → correlate events → document gaps → deliver a defensible change history. Data forensics, not spreadsheet archaeology alone.
Inventory the Debris
Database logs, app events, backups, and secondary archives are catalogued by date range and completeness
Mine & Correlate
Change events are extracted, ordered, and cross-matched against backup checkpoints and secondary systems
Gap Register
Unprovable periods are documented with evidence used and treatment applied for counsel and auditors
Defensible Pack
A source-tagged compliance trail of who changed what and when is handed to your legal and compliance team
Everything Needed for a Defensible Change History
Database Log Mining
We extract change evidence from transaction logs, trigger history, and admin journals so deleted or never-exported audit rows can still be reconstructed.
Application Event Correlation
App events, webhooks, and secondary system trails are ordered and matched so a single edit is proven across sources, not guessed from one incomplete log.
Backup Snapshot Diffing
Point-in-time backups become checkpoints. We compare successive snapshots to prove what changed between them when live audit retention already expired.
Defensible Timeline Packs
Counsel and compliance receive a source-tagged change history with user, timestamp, before/after values, and residual gaps documented honestly.
Gap & Assumption Register
Every period we cannot fully prove is logged with evidence used and treatment applied, so regulators see reconstruction method, not silence.
Forward Logging Handover
Once the trail is rebuilt, we leave you with retention and export practices so the next dispute does not start from debris again.
Sources We Mine for Change History
From 240 Hours of Archaeology to an 18-Hour Evidence Pack
How a regional insurer reconstructed 14 months of missing policy-change history before a customer dispute and Information Regulator enquiry escalated.
The Broken Trail
- SaaS audit retention had aged out past 90 days; the dispute window stretched 14 months
- Compliance and outside counsel rebuilt timelines from email, tickets, and screenshots
- Two external forensic quotes assumed incomplete records and warned of a 2× cost uplift
- Counsel could not answer who changed premium, beneficiary, or contact fields on key dates
- Litigation-hold spend and internal overtime were climbing with no defensible pack in sight
The Reconstructed Trail
- Database logs, backup diffs, and secondary CRM events were mined into one change timeline
- Source-tagged packs named user, timestamp, and before/after values for disputed fields
- Gap register documented the few days that remained unprovable, with method disclosed
- Counsel answered the dispute from evidence instead of recollection
- Forward retention and export practices were left so the next enquiry starts from a trail
Before vs After Reconstruction
How It Works
From first conversation to a counsel-ready pack in three to six weeks for a focused matter.
Scope the Missing Trail
Which systems, date range, and dispute or Regulator deadline you are racing, and what fragments still exist.
Evidence Inventory Call
30-minute call with compliance, legal, or the CFO to list logs, backups, and secondary sources before anyone retypes history.
Reconstruct & Validate
We mine logs and backups, build the change timeline, and walk counsel through the gap register before sign-off.
Hand Over the Pack
Defensible trail and exports land with your team, plus guidance so future changes keep an answerable history.
Frequently Asked Questions
How is this different from implementing a new audit trail going forward?
Forward-looking audit builds stop the problem tomorrow. This engagement reconstructs what already happened: mining database logs, application events, and backup snapshots to prove who changed what and when after the trail is missing, truncated, or never existed. Many clients need both: a forensic rebuild for the open matter, then immutable logging so the next enquiry is answerable.
How long does audit trail reconstruction take?
A focused matter covering one system and a six-to-eighteen-month window typically lands in three to six weeks once sources are available. Multi-system reconstructions, sparse retention, or court-driven deadlines take longer. We give you a dated plan after the evidence inventory, not a vague promise.
What if our SaaS audit logs only kept 90 days?
That is common. HubSpot and many cloud admin trails expose roughly 90 days in the interface. We pull what remains, then lean on database logs, backups, secondary applications, email, and tickets to cover older months, and we document residual gaps in the register so counsel can argue from facts, not silence.
Will a reconstructed trail satisfy POPIA accountability?
POPIA expects responsible parties to demonstrate how personal information was processed and safeguarded. Administrative fines reach R10 million. We produce a source-tagged change history plus a gap register so you can show how incomplete periods were reconstructed. Your legal adviser sets the policy position; we make the evidence pack exist.
Will reconstruction disrupt live systems?
No. Work runs against exports, read-only log access, and offline backups. Live CRM, ERP, and finance systems stay available. We only publish reconstructed history after compliance and counsel validate the timeline and gap treatments.
How much does forensic audit trail reconstruction cost?
Scoped reconstructions typically range from R55,000 to R120,000 depending on months missing, log quality, and systems involved. Against outsourced forensic examination rates of roughly R5,700 to R9,000 per hour, emergency premiums that can double the bill when records are missing, and POPIA fines up to R10 million, most clients recover the fee inside one dispute or Regulator cycle.
Stop Answering Audits With "We Do Not Know"
If your change history is incomplete and a dispute, litigation hold, or Regulator enquiry is already in motion, every week of archaeology raises counsel and forensic cost.
Tell us which systems hold fragments, which months are missing, and what deadline you are racing. We will show you whether a defensible trail can be rebuilt from the debris you still have.