Append-only, tamper-evident, capturing actor, action, entity, before/after state, and reason codes. Application-level events, not just database timestamps.
Soft deletes, effective-dating, and versioned records let you answer 'what did we know on March 3' — the question disputes and examiners actually ask.
Permission checks logged, approvals recorded with approver identity, and administrative overrides made loud — the override nobody logged is the finding.
Audit data nobody can search satisfies nobody; retention policies, export paths, and reviewer views are part of the requirement, not extras.
Skipping the discipline this article describes until an incident, audit, or stalled project forces it — every practice above is cheaper adopted early than retrofitted under pressure.
Let's discuss how we can help you with designing for auditability.