· INTERSECTION

EDC × Data Integrity

When trial data lives in an EDC, "original" becomes a governance decision, attribution runs through a delegation log, and the audit trail must defend a record that is designed to change.

All 20 intersections →

What this page does not claim

An intersection covers what happens only where two axes overlap. It does not restate what either parent page says, and it is not a substitute for reading them.

WHAT MEETS HERE

WHAT ONLY EXISTS IN THE OVERLAP

  • ALCOA+ assumes an identifiable original. In a trial, the original may be a site medical record, a direct eSource entry, or a transfer from a system the site has never seen — and which one it is must be decided per data element, in writing, before the first subject is enrolled.
  • Laboratory data-integrity instinct says trustworthy data does not change. Clinical data management is a process of deliberately changing data through queries and corrections. Integrity in the EDC is preserved not by immutability but by a trail that shows every version, every reason, and every actor.
  • Attribution in a GMP system means the person logged in did the work. In an EDC, a coordinator enters data, a monitor reviews it, a data manager queries it, and an investigator signs for all of it — attribution runs through a delegation log that the system's access model must mirror exactly.
  • The same audit trail can satisfy a GMP reading and fail a GCP one. Secure, computer-generated, and time-stamped is necessary; GCP scrutiny adds whether changes after investigator signature invalidated the attestation, and whether the sponsor could ever alter site data.
  • Integrated streams — central labs, eCOA, IRT — deliver data no site transcribed and no monitor can source-verify. Their integrity rests entirely on validated transfer and reconciliation, which only the overlap of EDC architecture and data-integrity governance can own.

Who holds the original when the record is an eCRF

The Original in ALCOA+ presumes you can point at the first durable capture of an observation. An EDC scatters that presumption. In the classic model the eCRF is a transcription — the original sits at the site, in medical records or worksheets, and source data verification checks the copy against it. Under eSource designation, direct entry into the eCRF is the first capture, and there is no site-held original at all. For a central-lab result or an eCOA response, the original was created in another organisation's system and arrived by transfer. Three routes, three different answers to "where is the original" — coexisting within one casebook.

The integrity consequence is that originality stops being a property you can inspect and becomes a decision you must govern. The trial's data-governance documentation has to state, per data element, where source resides — because every downstream control depends on the answer. Source data verification of an eSource field is meaningless; skipping verification of a genuinely transcribed field is a gap. Retention obligations attach to the original, so the site must keep what it holds and the sponsor must ensure connected systems keep theirs. An inspector's first data-integrity question in a trial is not "show me the audit trail"; it is "show me where you decided what source is" — and a trial that cannot produce that decision has already conceded the rest of the argument.

A record that is designed to change

A chromatography data file that has been repeatedly modified is a red flag. An eCRF that has never been modified is a different kind of red flag — it suggests the cleaning process did not run. Clinical data management exists to challenge and correct entered data: edit checks fire, queries are raised, sites answer, values change. The trial's conclusions rest on the corrected record, not the first keystroke. This is the point where practitioners trained on manufacturing data-integrity doctrine misread the clinical database: change is not the enemy here. Untraceable change is.

ICH E6(R3) states the standard precisely for this context: any change or correction to trial data must be traceable, must not obscure the original entry, and must be explained where explanation is needed. The audit trail is therefore not a security afterthought but the instrument that makes legitimate change legitimate — it preserves the superseded value, the actor, the timestamp, and the reason. The integrity failure modes are correspondingly specific: reasons for change that are all the same generic phrase, corrections clustered suspiciously after a monitoring visit, values toggled until an edit check passes, or a site answering every query with immediate agreement. None of these is a modification problem; all of them are pattern problems, visible only to someone who actually reads the trail.

Attribution runs through the delegation log

Attributable, in a single-organisation system, means the account that made the entry belongs to the person who did the work. A trial adds a second requirement: the person must also have been delegated that task by the investigator, in writing, at that site, during that period. The EDC's access model and the delegation log are two representations of the same authority, and integrity requires them to agree. An entry made by a coordinator who joined the study team a week before appearing on the delegation log is attributable in the Part 11 sense and indefensible in the GCP sense — the system knows who typed; the trial cannot show they were authorised to.

The investigator's electronic signature compounds this. It is not a workflow approval; it is an attestation that the casebook data are accurate and complete — data the investigator largely did not enter personally. That is the designed shape of clinical attribution: entry is delegated, accountability is not. It works only if the system enforces its consequences — data changed after signature must invalidate the signature and require re-signing, and the trail must show which version of the data each signature attested to. Access retirement is the quiet failure mode at this junction: a departed coordinator's live account, or sponsor-side write access to site data, collapses attribution for every record it could have touched, which is why user-access history is itself a core integrity record.

One audit trail, two inspectorates

A trail that satisfies the letter of Part 11 — secure, computer-generated, time-stamped, original values preserved — can still fail a GCP inspection, because the two readings interrogate different things. A GMP-shaped review asks whether the record could have been altered without trace. A GCP review asks who was allowed to alter it, and what the alteration did to accountability: could sponsor or CRO staff ever modify site-entered data, even with a trace? Did post-signature changes re-trigger the investigator's attestation? Can the trail reconstruct the casebook as it stood at interim analysis, at signature, at lock? A trail can answer the first family of questions perfectly and the second not at all.

The boundary between organisations is the sharpest edge. In manufacturing, everyone in the audit trail works for the company being inspected. In a trial, the trail records actors from the site, the sponsor, the CRO, and the platform provider — and the integrity claim depends on what each was structurally unable to do. Site data must be changeable only by the site; queries may challenge a value but never replace it; the sponsor's reach must stop at the question. Demonstrating this is a validation activity, not an assertion: the role-permission matrix is tested so that the impossible is evidenced, because a GCP inspector who finds a sponsor role with write access to eCRF data has found a finding no clean audit trail will offset.

Audit-trail review itself also changes character in the overlap. MHRA's data-integrity expectations apply to the clinical database exactly as to a laboratory one, but nobody can eyeball the trail of a hundred-thousand-page casebook. Review becomes a designed, risk-based activity — targeted at high-risk fields, unusual change patterns, and site-level behaviour — with its scope documented and its execution evidenced. An SOP that promises audit-trail review the sponsor never performs is a finding an inspector assembles in minutes.

Data no site ever touched

A growing share of the clinical database is never entered by anyone: central-laboratory results, eCOA responses, randomisation strata, device readings, all arriving by integration. For these, the transcription-checking machinery of the trial has nothing to check — there is no site record to verify the transfer against, and the receiving eCRF field is the first time a human could see the value. Integrity for this data is manufactured upstream or not at all: the sending system's own audit trail and controls, a validated transfer with reconciliation of counts and content, and mapping specifications maintained under change control on both ends.

The characteristic failure is the silent one. An upstream format change — a renamed field, a changed unit, a new code list — that the mapping was never revisited for does not raise an error; it delivers plausible, wrong values for months. This is why integration mappings sit inside the validated scope and why periodic reconciliation is an integrity control rather than a data-management courtesy. The maturity signature of the overlap is visible here: organisations at the low end verify each integration once and trust it for the life of the trial; organisations at the high end treat every upstream release as a change event against their own database, because they have understood that for integrated data, the transfer is the record's entire provenance.

FREQUENTLY ASKED

Is the eCRF the source record?

Only if the trial says so, element by element. In the default model the eCRF is an entered copy — source sits at the site in medical records, instrument output, or worksheets, and source data verification checks the transcription. Where the trial designates direct entry as eSource, the eCRF field is the first capture and therefore the original; where data arrives from central labs or eCOA by validated transfer, source lives in the sending system. The governing requirement is that the trial's data-governance documentation states where source resides for each data element, because verification, retention, and every ALCOA+ argument depend on that designation.

Does correcting data through a query violate the "Original" in ALCOA+?

No — correction is the designed behaviour of a clinical database, and ALCOA+ accommodates it. The Original attribute requires that the first entry is preserved and never obscured, not that it is never superseded. A compliant correction keeps the prior value visible in the audit trail, records who changed it and when, and carries a meaningful reason for change. What does breach integrity is the pattern around corrections: identical boilerplate reasons across thousands of changes, values adjusted until an edit check passes, or corrections that follow a monitoring visit so closely that the trail reads as coached. Inspectors assess the process the changes describe, not the existence of change.

Who is accountable for eCRF data integrity — the site or the sponsor?

Both, for different parts of one record. The investigator is accountable for the accuracy and completeness of the data the site enters, and the electronic casebook signature is the formal attestation of exactly that. The sponsor is accountable for providing a system fit for purpose — validated, access-controlled, audit-trailed — for the integrity of integrated data streams, and for a cleaning process that challenges data without being able to change it. The structural rule that keeps the split honest: sponsor and CRO roles may query site data but must be technically incapable of editing it. When that boundary holds, each party's accountability is legible in the trail.

Why would an audit trail that satisfies a GMP inspector fail a GCP one?

Because GCP asks questions the GMP reading never reaches. A trail can be secure, computer-generated, and time-stamped — the Part 11 essentials — and still be unable to show whether data changed after the investigator signed, whether the signature was invalidated and re-required, which casebook version an attestation covered, or whether sponsor-side roles were structurally prevented from altering site data. GCP inspection also reads the trail across organisations: site, sponsor, and CRO actions must be distinguishable, and the sponsor's reach must demonstrably stop at the query. A trail built to prove "no undisclosed change" without proving "no unauthorised actor" answers only half the clinical question.