· CLINICAL RESEARCH / GCP

SDV vs SDR: Source Data Verification & Review

Source data verification (SDV) and source data review (SDR) are the two ways a monitor engages with a site’s source records, and treating them as interchangeable — or treating SDR as a lighter version of SDV — is a genuine and consequential error. SDV checks that what was reported matches the source, field by field; SDR reads the source itself for quality, consistency, and safety. They detect different classes of failure, which is why the shift to risk-based monitoring cannot simply cut SDV and leave SDR undefined. This page separates the two; the data they act on — source data, eSource, direct data capture — is the subject of the [source data & eSource](/topics/esource-and-source-data) explainer.

What an explainer is not

A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 19 LINKS

SDV and SDR are not the same check: source data verification confirms transcription against source, while source data review reads the source itself, so 100% SDV never finds the adverse event that was never entered on the CRF.

06 · QUALITY MATURITY — SDV VS SDR: SOURCE DATA VERIFICATION & REVIEW, REACTIVE TO ADAPTIVE

L1
Reactive

Monitoring means 100% on-site SDV; source data review is undefined, so unreported adverse events in the medical record are never found.

L2
Defined

A plan reduces SDV to cut cost but leaves SDR undefined, so oversight quietly drops rather than becoming risk-based.

L3
Controlled

Targeted SDV on critical data and higher-risk sites is paired with defined source data review and centralised monitoring, each proportionate to risk.

L4
Predictive

The three layers are trended together; discrepancies and unreported-event signals feed queries, risk review, and CAPA before they compound.

L5
Adaptive

Oversight is designed around what each layer uniquely catches; SDV, SDR, and centralised monitoring are calibrated to the actual trial risks.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 2

Derived from the 2 standards SPEQ maps to this subject, across 2 regulatory bodies: ICH, FDA.

RECORDS & OBJECTIVE EVIDENCE

  • A monitoring plan specifying SDV scope, SDR scope, and centralised monitoring, each risk-based
  • SDV records reconciling CRF fields against source for critical data
  • Source-data-review records examining source for completeness and unreported events
  • Centralised-monitoring outputs detecting cross-site anomalies
  • Queries and findings traced from verification/review into risk review and CAPA

COMMON INSPECTION FINDINGS

  • SDV reduced as a cost measure with SDR left undefined
  • Source data review treated as a lighter form of SDV
  • Adverse events in the source never entered on the CRF and never found
  • No documented risk basis for what is verified versus reviewed
  • Monitoring unable to evidence that source records were examined, not just reconciled
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

SDV: a transcription-accuracy check

Source data verification is the comparison of the data reported on the case report form against the source record it came from, field by field. Did the haemoglobin value on the eCRF match the lab report? Does the recorded visit date match the source? SDV answers one narrow, important question: **was the data transcribed accurately from source to CRF?** It is a check of fidelity between two records, and historically it was performed at 100% — every field on every subject verified against source, on site.

That exhaustive model is expensive and, the evidence showed, not where most data-quality risk actually lives. This is what drove risk-based monitoring toward *targeted* SDV: verify the critical data and the higher-risk sites intensively, and verify routine, low-risk fields more lightly, because verifying a benign field for the thousandth time adds little assurance. But reducing SDV only makes sense if you understand what SDV can and cannot catch — which is where source data review becomes essential.

SDR: reading the source itself

Source data review is a different activity: instead of comparing the CRF to the source, the monitor reviews the **source records themselves** for quality, internal consistency, protocol compliance, and safety signals. Are the medical records complete and coherent? Is there evidence the protocol was followed? Is there anything in the source that suggests a safety concern or a problem the site has not surfaced? SDR is a review of the source’s substance, not a reconciliation of two documents.

The critical insight is that **SDR is not a lighter form of SDV — it catches an entirely different class of failure.** The canonical example: an adverse event documented in a patient’s medical record but never entered on the CRF. No amount of SDV will ever find it, because SDV compares CRF entries to source, and there is no CRF entry to compare against — the failure is an *absence*. Only source data review, reading the medical record itself, surfaces the unreported event. SDV verifies what was reported; SDR examines what should have been.

Why reducing SDV forces you to strengthen SDR

These two facts combine into the central discipline of risk-based monitoring: **you cannot reduce SDV and leave SDR undefined without weakening oversight.** If targeted SDV means fewer fields are checked for transcription accuracy, the review of the source for completeness, consistency, and unreported safety events must carry more of the assurance load, not less. A monitoring strategy that cuts on-site SDV as a cost measure while never defining or strengthening SDR has not become risk-based; it has simply reduced oversight and hoped for the best.

This is why a defensible risk-based monitoring plan specifies both: what SDV is performed and on which critical data and sites, and what source data review is performed to catch the failures SDV structurally cannot. Centralised monitoring adds a third layer, detecting anomalies in the accumulating data remotely. The three are complementary — SDV for transcription fidelity, SDR for source substance and unreported events, centralised monitoring for cross-site patterns — and a plan that names all three, proportionate to risk, is what "risk-based" actually means.

Where this sits in the quality system

SDV and SDR are the site-level execution of the sponsor’s oversight duty, and their outputs feed the wider quality machinery. Discrepancies found in verification and issues found in review become queries, findings, and — where they reveal a systemic problem — inputs to the trial’s risk review and to CAPA. The monitoring record is also part of the evidence an inspection reads to judge whether the sponsor actually oversaw the trial, which is why what was verified, what was reviewed, and the risk basis for both must be documented rather than assumed.

The through-line to data integrity is direct: SDR and SDV are how the ALCOA+ attributes are checked at the coalface of a trial — is the CRF data *accurate* against source (SDV), is the source itself *complete* and *contemporaneous* (SDR)? A trial that cannot demonstrate it examined its source records, not just reconciled its CRFs, has an oversight gap that no volume of transcription verification closes.

FREQUENTLY ASKED

What is the difference between SDV and SDR?

Source data verification (SDV) compares the data reported on the case report form against the source record, field by field — a transcription-accuracy check. Source data review (SDR) reads the source records themselves for quality, internal consistency, protocol compliance, and safety signals. SDV checks fidelity between two records; SDR examines the substance of the source itself.

Why is SDR not just a lighter version of SDV?

Because they catch different failures. The classic example is an adverse event documented in a patient’s medical record but never entered on the CRF: 100% SDV will never find it, because there is no CRF entry to compare against — the failure is an absence. Only source data review, reading the source itself, surfaces the unreported event. SDV verifies what was reported; SDR examines what should have been.

Can you reduce SDV under risk-based monitoring?

Yes, but not in isolation. Targeted SDV concentrates transcription checking on critical data and higher-risk sites. Reducing it only stays defensible if source data review and centralised monitoring carry more of the assurance load — cutting SDV while leaving SDR undefined weakens oversight rather than making it risk-based. A sound plan specifies SDV, SDR, and centralised monitoring, each proportionate to risk.

How do SDV and SDR relate to data integrity?

They are how the ALCOA+ attributes are checked in a trial: SDV confirms the CRF data is accurate against source, while SDR confirms the source itself is complete and contemporaneous. A trial that only reconciles CRFs to source, without reviewing the source records for completeness and unreported events, has an oversight gap that transcription verification alone cannot close.

PROFESSIONAL · INSPECTION PLAYBOOK · SPEQ SYNTHESIS

The inspection-readiness playbook for this topic

CHECKING ACCESS

Checking your Professional access…