[ HOW-TO GUIDE ]

How to Perform Source Data Verification

Check reported data against its origin without turning monitoring into transcription checking.

What a how-to is not

A how-to is SPEQ’s practitioner method, not a procedure. It does not replace your own SOP, it is not a validated approach, and the judgement calls in it belong to your quality unit.

Source data verification compares what was reported against the record where it first appeared. It used to mean checking everything; under a risk-based approach it means checking what matters, on a sample sized by risk, with the effort released spent on the things full verification never caught — process errors, systematic misunderstanding, missing data nobody entered. The hard part is defining source before you start looking for it.

THE STEPS
  1. 1

    Define what source is for each data point before the first visit

    For every critical variable, name the record where it first appears and who holds it. Where data are captured directly into an electronic system with no prior record, that system is the source and there is nothing to compare it against — that must be agreed and documented in advance, not discovered during monitoring.

  2. 2

    Set the sampling plan from the risk assessment

    Critical variables — eligibility, primary endpoint, consent, safety reporting — warrant verification at a depth that non-critical variables do not. A plan that verifies everything to the same depth is not thorough; it is undirected, and it will run out of time before it reaches the things that matter.

  3. 3

    Verify against the attributes that make data trustworthy

    Check that the entry is attributable to a person, legible, contemporaneous with the observation, original or a certified copy, and accurate. A value that matches the source but was recorded weeks later fails on contemporaneity even though verification passed.

  4. 4

    Treat a discrepancy as a question about the process

    Ask why it happened, not only what the right value is. A single transposition is an error; a systematic offset across a site is a misunderstanding of the definition, and correcting the values without correcting the understanding guarantees the next batch is wrong too.

  5. 5

    Check for the data that were never reported

    Verification compares what was reported against source. It is structurally blind to what the site observed and never entered, so review the source record independently for events and assessments that never reached the case report form. Under-reporting is invisible to comparison alone.

  6. 6

    Document what was checked and what was not

    Record the scope, the sample, the findings and the resolution. A monitoring report that says verification was performed without saying against what and how much cannot demonstrate that the plan was followed, which is the thing being assessed.

USE THE TEMPLATE
Source Data Verification Plan
Skip the blank page — start from SPEQ’s structured, regulator-aligned template for this procedure. Open the template →
COMMON PITFALLS
  • !Source undefined until monitoring starts, so direct-capture data are treated as having a source that never existed.
  • !Uniform verification depth, which exhausts the visit before the critical variables are reached.
  • !Discrepancies corrected value by value with no cause analysis, so the systematic error repeats.
  • !Nothing looking for unreported events, because comparison cannot see data that were never entered.

How to Perform Source Data Verification: frequently asked questions

Common questions on perform source data verification.

Does risk-based monitoring mean less verification?

It means differentiated verification. Critical variables may be checked more thoroughly than under a uniform hundred-percent approach, while low-impact fields are sampled or left to centralised checks. The total effort is redirected, not simply reduced, and a plan that only reduces is a cost decision wearing a methodology label.

What is source when data are entered directly into an electronic system?

The electronic record is the source, provided that is defined and agreed in advance and the system supports attribution and an audit trail. There is then nothing to verify against, which is why the definition has to exist before monitoring rather than being settled when a monitor asks for the paper.

Can verification detect under-reporting?

Not by itself. Comparing reported data against source finds errors in what was reported and is structurally blind to what was never reported at all. Detecting under-reporting requires reading the source record independently — reviewing notes and results for events that never reached a form.