# What to look for in AI ecommerce software for an audit trail | BYOM blog

URL: https://byom.co/blog/ecommerce-ai-audit-trail  
Markdown: https://byom.co/blog/ecommerce-ai-audit-trail.md  
Last updated: 2026-10-02

> What an audit trail is, which UK record keeping rules and chargeback deadlines test it, what Shopify keeps by default, and the questions to put to any AI tool before you rely on it.

By Kina (Checked by the BYOM team). Published 2026-10-13. 9 minute read. Series: In control.

## Key takeaways

- An audit trail is a chronological record that lets someone reconstruct a sequence of events from start to result, not only a list of things that happened.
- UK limited companies keep accounting records for 6 years, VAT registered businesses keep VAT records for at least 6 years, and Stripe gives you one chance to submit chargeback evidence.
- Shopify's store activity log shows at most 250 results and cannot be exported, so a longer trail has to come from somewhere else.

An audit trail is easy to ask for and hard to define. Software vendors call almost any log an audit trail. The people who read them, an accountant at year end, an investor during due diligence, an insurer after a claim, a card network in a dispute, mean something narrower and ask for it at an inconvenient time.

This post starts from the reviewers and works back to the software. It covers a definition from a standards body, the UK record keeping duties a small ecommerce company already has, what the Information Commissioner expects for personal data, what a chargeback demands, and what Shopify keeps by default. It ends with questions to put to any AI tool that changes your store.

## What an audit trail is

The US National Institute of Standards and Technology keeps a glossary that gives three closely related definitions, drawn from its own publications and a national security standard. The most complete reads: an audit trail is a chronological record of system activities that is sufficient to enable the reconstruction and examination of the sequence of events and activities surrounding or leading to an operation, procedure, or event in a security relevant transaction from inception to results.

Three phrases in that definition do the work. Chronological means the order is part of the record, so an entry cannot be moved or merged without it showing. Sufficient to enable reconstruction is the test: a reviewer who was not there should be able to rebuild what happened. From inception to results means the record covers the request, the decision and the outcome, beyond the moment of the write.

Apply that to an AI assistant that edits your catalogue. A line reading product updated at 14:02 is a log entry. An audit trail also holds the instruction that led to the change, the old value and the new, the person who approved it, and whether the store accepted it. If any of those is missing, the reviewer cannot reconstruct the sequence, and they will say so.

## What UK law already makes you keep

No UK rule is written for AI ecommerce software. The rules that exist cover records of money, stock and personal data, and they set how long those records must survive. Those durations are the first thing to compare with any tool's retention.

For a limited company, GOV.UK says your accounting records must show all money received and spent, details of assets, debts the company owes or is owed, and stock held at the end of the financial year. You must also keep supporting documents, including receipts, orders and delivery notes, invoices, contracts, sales books and till rolls. The standard period is 6 years from the end of the last company financial year the records relate to. It runs longer if the records show a transaction that spans more than one accounting period, if the company bought something expected to last more than 6 years, if you sent your Company Tax Return late, or if HMRC has started a compliance check. GOV.UK states the penalty for failing to keep accounting records: a £3,000 fine from HMRC, or disqualification as a company director.

For VAT, HMRC's Notice 700/21 says that, generally, you must keep all business records for VAT purposes for at least 6 years. It also says all VAT registered businesses must keep and preserve certain records digitally and keep their accounts within functional compatible software. The electronic account has to hold, for each supply, the time of supply, the value and the rate of VAT charged. The notice adds that data transfer or exchange within and between software programs must be digital where the information forms part of the electronic account.

None of this says your assistant's change history is an accounting record. A product title edit is not. A price change sits closer to the line, because the price on the day of an order explains the figure in your sales records. The sensible reading is that you may be asked why a number in your accounts is what it is, and the trail of changes behind it is how you answer. A tool that keeps its own history for 30 days cannot answer a question asked in year three.

- **6 years** standard retention for company accounting records (GOV.UK, running a limited company, 2026)
- **£3,000** fine or director disqualification for not keeping accounting records (GOV.UK, running a limited company, 2026)
- **250** most results the Shopify store activity log displays (Shopify Help Center, activity logs, 2026)

## What the ICO expects for personal data

An assistant connected to your store will read customer names, addresses and order history. That is processing personal data, and the UK GDPR's accountability principle expects you to be able to show how. The ICO's guidance on documentation says controllers and processors each have their own documentation obligations.

Organisations with 250 or more employees must document all processing activities. Smaller ones have a limited exemption: they need to document only processing that is not occasional, that could result in a risk to people's rights and freedoms, or that involves special categories of data or criminal conviction data. An ongoing connection between your store and an AI service is not occasional, so a small merchant should assume it belongs in the record.

The ICO lists what the record includes: the name and contact details of your organisation, the purposes of the processing, the categories of data and of recipients, any international transfers and the mechanism for them, retention schedules, and a description of security measures. It also points to records of consent, contracts between controllers and processors, data locations, impact assessments and breach notifications.

The practical questions for an AI vendor follow from that list. Where is the data held? Who are the recipients? How long is it kept, and what is the schedule? A vendor that cannot answer those has left a gap in your own record.

## What a chargeback demands, and by when

A chargeback is the quickest way for an audit trail to be tested by an outsider with a deadline. Stripe's documentation says that when you receive a dispute you have a limited window to respond, usually 7 to 21 days depending on the card network, and that if you do not respond before the deadline you automatically lose the dispute and cannot retrieve the funds.

You then get one chance. Stripe states that you have only one opportunity to submit your response, that it goes straight to the issuing bank, and that you cannot edit it or add files afterwards. Evidence is organised by type, you can submit only one file per type, so several files of one type must be combined, and the combined size is capped at 4.5 MB. For Mastercard the combined length is capped at 19 pages.

Stripe also warns that banks evaluating a dispute will not review external content. It says not to include audio or video files, requests to call or email for more information, or links to click for further information, such as file downloads or tracking links. A trail that lives behind a login in someone else's dashboard is therefore no use in a dispute until you have exported it into a document that can be attached.

Stripe advises keeping a record of all communication with the customer, because it provides evidence to submit. For fraud disputes with Visa's 10.4 card absent code, Stripe automatically checks your transaction history for eligibility under Visa Compelling Evidence 3.0 and, where the dispute qualifies, populates much of the evidence itself. The history that makes you eligible is the order and customer record. What your store told the customer at the time of purchase, including the product description and policies, belongs to the same file.

Stripe describes an earlier stage too. An inquiry is a pre dispute step, usually raised when an account owner does not recognise a transaction, and responding at that stage can stop a formal dispute, which Stripe says saves time, fees and your rating with the card networks. If an inquiry becomes a chargeback you must submit a second response. If you counter a dispute, a dispute countered fee applies on top of the dispute received fee, and the bank can take up to 3 months to decide.

Put together, the dispute process asks for a complete, exportable, plain document inside a window of 7 to 21 days, and it allows no second attempt. That is a fair description of what any reviewer wants from an audit trail, with the deadline made explicit.

## What Shopify keeps by default

Shopify's store activity log shows the date and time of recent actions by the owner or a user, with the name of the person, app or channel behind each. Three limits sit on it. It displays a maximum of 250 results, so the time span depends on how active the store is. It is view only, with no way to expand an individual event. And the information cannot be exported.

The order timeline is richer. Shopify says it holds detailed histories for orders, draft orders, customers and transfers, with notes and comments for staff that customers cannot see. Comments can be edited only for 5 minutes after you post them, a small limit on rewriting that most merchants do not know about.

| Question a reviewer asks | Activity log | Order timeline |
| --- | --- | --- |
| Who did it | Person, app or channel named | Staff comments carry a name |
| How far back | Up to 250 results, then gone from view | Held with the order |
| Can you export it | No, Shopify says it cannot be exported | Not stated on the help page |
| Old and new value | Individual events cannot be opened | Order history only, not product fields |

> **A habit worth having.** Because the activity log cannot be exported and shows only the latest 250 results, copy what matters before it scrolls away: a monthly screenshot, or a note kept next to your accounts. It is crude, and it is better than nothing in year three.

For orders you have a reasonable history. For products, which are what an assistant most often edits, the log tells you something happened and not what the old text said.

## Questions to put to any AI tool before you rely on it

- Does every entry name a person who approved it, or only the assistant that made it?
- Does it hold the old value and the new value, so a reviewer can see the change without guessing?
- Can you export one change, or a date range, into a file that can be attached to a dispute or handed to an accountant?
- How long is the record kept, and is that at least as long as the 6 years that apply to your accounting and VAT records, or can you export it to keep it yourself?
- Does it say when a record was written at the time and when it was reconstructed afterwards?
- Does an unfinished or declined change show as unfinished or declined, rather than as a success?
- Where is the data stored, and who are the recipients, so you can complete your ICO record?

The fifth and sixth questions catch the most common weakness. A record built after the fact from a summary is a different thing from one written when the change happened, and a reviewer will treat them differently. A system that marks everything it attempted as done will fail the first dispute where it was not.

The most reliable test costs nothing. Make one real change on a test product, decline another, and then ask the vendor to produce the record of both as a file. Read it as the reviewer would: could someone who was not in the room say who decided, what moved, and what the store answered? If the file needs a conversation to explain it, it is not yet an audit trail.

## Where BYOM fits

An audit trail in AI ecommerce software is who said yes, what changed, and whether you can put it back. A change receipt records what changed, who approved or declined it and when, the note they left, the evidence, and whether it can be undone. A receipt never says executed until your store says so. Your data is stored in the UK, including your approvals, records and memory.

Related: [See trust](https://byom.co/trust), [See receipts](https://byom.co/receipts), [See approvals](https://byom.co/approvals), [What BYOM is](https://byom.co/blog/what-byom-is).

## Sources

- [US National Institute of Standards and Technology, glossary, audit trail, 2026](https://csrc.nist.gov/glossary/term/audit_trail)
- [GOV.UK, running a limited company, company and accounting records, 2026](https://www.gov.uk/running-a-limited-company/company-and-accounting-records)
- [GOV.UK, HMRC, record keeping for VAT, Notice 700/21, 2026](https://www.gov.uk/guidance/record-keeping-for-vat-notice-70021)
- [ICO, guide to accountability and governance, documentation, 2026](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/documentation/)
- [Stripe, respond to disputes, 2026](https://docs.stripe.com/disputes/responding)
- [Shopify Help Center, activity logs in the Shopify admin, 2026](https://help.shopify.com/en/manual/shopify-admin/activity-logs)
- [Shopify Help Center, timeline, 2026](https://help.shopify.com/en/manual/shopify-admin/timeline)
