One could have a signed audit log, and that's fine.
But no matter what you do the CRA has to be able to write to the data, and read from it to give it to third parties, and be able to reset passwords. AFAIK that requires that they have the keys to decrypt the data.
But no matter what you do the CRA has to be able to write to the data, and read from it to give it to third parties, and be able to reset passwords. AFAIK that requires that they have the keys to decrypt the data.