How to Perform Source Data Verification
Check reported data against its origin without turning monitoring into transcription checking.
What a how-to is not
A how-to is SPEQ’s practitioner method, not a procedure. It does not replace your own SOP, it is not a validated approach, and the judgement calls in it belong to your quality unit.
Source data verification compares what was reported against the record where it first appeared. It used to mean checking everything; under a risk-based approach it means checking what matters, on a sample sized by risk, with the effort released spent on the things full verification never caught — process errors, systematic misunderstanding, missing data nobody entered. The hard part is defining source before you start looking for it.
- 1
Define what source is for each data point before the first visit
For every critical variable, name the record where it first appears and who holds it. Where data are captured directly into an electronic system with no prior record, that system is the source and there is nothing to compare it against — that must be agreed and documented in advance, not discovered during monitoring.
- 2
Set the sampling plan from the risk assessment
Critical variables — eligibility, primary endpoint, consent, safety reporting — warrant verification at a depth that non-critical variables do not. A plan that verifies everything to the same depth is not thorough; it is undirected, and it will run out of time before it reaches the things that matter.
- 3
Verify against the attributes that make data trustworthy
Check that the entry is attributable to a person, legible, contemporaneous with the observation, original or a certified copy, and accurate. A value that matches the source but was recorded weeks later fails on contemporaneity even though verification passed.
- 4
Treat a discrepancy as a question about the process
Ask why it happened, not only what the right value is. A single transposition is an error; a systematic offset across a site is a misunderstanding of the definition, and correcting the values without correcting the understanding guarantees the next batch is wrong too.
- 5
Check for the data that were never reported
Verification compares what was reported against source. It is structurally blind to what the site observed and never entered, so review the source record independently for events and assessments that never reached the case report form. Under-reporting is invisible to comparison alone.
- 6
Document what was checked and what was not
Record the scope, the sample, the findings and the resolution. A monitoring report that says verification was performed without saying against what and how much cannot demonstrate that the plan was followed, which is the thing being assessed.
- !Source undefined until monitoring starts, so direct-capture data are treated as having a source that never existed.
- !Uniform verification depth, which exhausts the visit before the critical variables are reached.
- !Discrepancies corrected value by value with no cause analysis, so the systematic error repeats.
- !Nothing looking for unreported events, because comparison cannot see data that were never entered.
How to Perform Source Data Verification: frequently asked questions
Common questions on perform source data verification.
Does risk-based monitoring mean less verification?
It means differentiated verification. Critical variables may be checked more thoroughly than under a uniform hundred-percent approach, while low-impact fields are sampled or left to centralised checks. The total effort is redirected, not simply reduced, and a plan that only reduces is a cost decision wearing a methodology label.
What is source when data are entered directly into an electronic system?
The electronic record is the source, provided that is defined and agreed in advance and the system supports attribution and an audit trail. There is then nothing to verify against, which is why the definition has to exist before monitoring rather than being settled when a monitor asks for the paper.
Can verification detect under-reporting?
Not by itself. Comparing reported data against source finds errors in what was reported and is structurally blind to what was never reported at all. Detecting under-reporting requires reading the source record independently — reviewing notes and results for events that never reached a form.