data integrity GCP - clinical research laboratory with digital sample trail - QFINITY
QFINITY · Service Areas · Data Integrity (GCP)

Data integrity of GCP‑relevant computerized systems.

Systems and data carry two things at once: the protection of clinical trial participants and the reliability of trial results. ICH E6(R3) and the EMA guideline on computerised systems set the bar. We help sponsors, trial sites, CROs and software vendors put it into practice.

Good Clinical Practice

Process orientation over technology for its own sake.

Data integrity of GCP-relevant computerized systems is achieved when the data of a clinical trial is collected, accessed and maintained securely across its entire life cycle and fulfills the ten ALCOA++ attributes; the bar is set by ICH E6(R3) and the EMA guideline on computerised systems.

We consult across clinical research and development, turning the requirements of the EMA guideline, ICH E6(R3) and Regulation (EU) 536/2014 into processes and quality management systems that hold up.

ICH E6(R3) makes data governance a shared task for sponsor and trial site; the EMA guideline spells out what inspectors expect from computerized systems and electronic data.

Co-authored by QFINITY.

The methodological anchor, the ISPE GAMP Good Practice Guide "Validation and Compliance of Computerized GCP Systems and Data - Good eClinical Practice" (2nd Edition, July 2024), took shape with QFINITY: Frank Henrichmann and Oliver Herrmann as Co-Leads, Jenny Gebhardt and Marcus Schwabedissen on the author team. Oliver Herrmann led the ISPE GAMP R&D and Clinical Systems Special Interest Group (SIG).

ICH E6(R3) EMA guideline Data Governance ALCOA++ Quality by Design Data Acquisition Tools eSource Audit Trail Review
Participant protection and reliable results are achieved together: through process-oriented quality management, practiced data governance and risk-based use of technology.
eClinical technologies

The system landscape of clinical research.

GCP system landscapes are heterogeneous, networked and used around the globe. ICH E6(R3) groups the capture tools as Data Acquisition Tools, from the paper CRF to the wearable; data captured electronically at its origin is eSource. We look at every technology class in its process context, not in isolation.

  • Data Acquisition Tools

    eCRF/EDC (Electronic Data Capture), electronic Clinical Outcome Assessments (eCOA/ePRO) and other capture tools; the R3 umbrella term for anything that records data and metadata from the data originator. Trial-specific capture tools never replace the medical record, and they must not deplete it.

  • IRT / RTSM

    Interactive Response Technology and Randomization and Trial Supply Management: dosage calculations are verified against the approved protocol, with test data sitting right on the dose boundary; where randomization is stratified, every combination of strata belongs in the test. Emergency unblinding needs a backup route and must be demonstrably available before a participant receives investigational product.

  • Digital Health Technologies

    Wearables and sensors as regular data sources. Metadata is part of the record, and losing it means losing integrity.

  • eConsent

    Electronic informed consent, on site or remote, with its own requirements for identity, versioning and evidence.

  • EHR & site source systems

    Electronic Health Records (EHR) and other systems the trial site brings along are assessed for fitness for purpose as early as site selection: data security, user management, audit trails.

  • Safety & pharmacovigilance

    SAE/SUSAR reporting paths from the trial into the safety database. The EMA guideline expressly counts pharmacovigilance databases among the sponsor systems within its scope; alongside it, the pharmacovigilance (GVP) rules apply. What matters: interfaces, reconciliation and reporting deadlines.

  • CTMS & eTMF

    Trial management and the Trial Master File: the eTMF has to tell the story of the trial, ready for inspection, complete, contemporaneous and with an audit trail.

  • Service providers in the network

    Contract Research Organizations (CROs), laboratories, platform and software vendors. Responsibility stays with the sponsor; we assess processes and tools for suitability.

AI is in scope.

The EMA guideline expressly covers the use of AI in clinical trials, from recruitment and eligibility determination to coding and query processes. It deliberately sets no AI-specific requirements initially; those may follow in a future annex. Until then, the general expectations for any system apply. What an AI-specific framework can look like is shown on the GMP side by the Annex 22 draft.

eCOA, ePRO and BYOD

Who controls the device the data is created on?

Trial data increasingly originates on devices owned by neither the sponsor nor the site: a participant's phone, tablet or smartwatch. The EMA guideline gives Bring Your Own Device its own section within Annex 5, because this route moves part of the control to a place where the sponsor cannot exercise it. That belongs in the risk assessment, and with it in the scope of validation.

Globally anchored since June 2026.

With its newly finalized Annex 2, ICH E6(R3) explicitly covers decentralized elements, digital health technologies and real-world data; the annex takes effect in the EU on 15 January 2027.

  • What the sponsor does not steer

    Operating system updates and other apps on a private device are outside the sponsor's control. The answer is a minimum specification, covering supported OS versions and available security patches, plus evidence that data quality holds across every accepted device model.

  • Nobody gets excluded

    Participants who cannot or will not use their own device must not drop out of the trial for that reason. An alternative capture route, usually a sponsor-provided device, is part of the trial design from the outset.

  • Access control inside the application

    Private devices get lost, and whether they are locked at all is the participant's decision. Access control therefore belongs in the application itself. When participation ends, access and capture are closed out in an orderly way, and the application can be removed at any time without leaving residues.

  • Data minimization and consent

    Only what the protocol calls for is collected. Camera, photos or location data need a justification in the protocol and a description in the informed consent. Some providers' licensing terms permit data sharing that conflicts with ICH E6; in that case the application is not suitable.

Clinician reported outcomes follow the same logic.

The requirements for clinician reported outcomes match those for ePRO systems; here the data is captured by the investigator, site staff or an independent assessor. Access rights deserve particular attention in that setting so that blinding is preserved.

Shared responsibility

Sponsor and trial site carry the data together.

The heart of the new GCP rules: data governance is shared responsibility across the entire data lifecycle. The sponsor never controls the captured data alone, and whoever delegates a task remains accountable for it.

The site's own systems are part of this. When selecting a trial site, the sponsor assesses whether those systems suit their use in this particular trial, right down to the audit trail of the electronic medical record; the guideline calls this step site qualification. If the assessment comes out negative, the choice of site itself is on the table, and a system used regardless calls for effective mitigating actions or a documented assessment of the residual risk.

  • Sponsor & trial site

    The sponsor owns the trial's systems and processes, the site owns its source data, and both own integrity across the lifecycle together.

  • No sole control

    At no point does the sponsor hold sole control; the site keeps an independent certified copy including the audit trail, for the full retention period.

  • Service provider oversight

    Delegation does not discharge responsibility: oversight scales with risk and explicitly covers subcontractors; that includes audit rights and inspection access.

  • Agreements & evidence

    Contracts settle data access, responsibilities and evidence before services start. A provider's evidence counts only after documented assessment.

We set these roles up with you.

As part of our consulting services, QFINITY supports you in defining responsibilities, control points and contract content between sponsor, trial site and service providers, before an inspector asks. And we test them in practice: with vendor and CRO audits, from the eClinical platform to the SaaS/cloud provider.

End-to-end validation

Highly complex platforms, validated with focus.

Rather than documenting every module wholesale, we follow the data flow through the eClinical platform, from capture through the interfaces to analysis. ICH E6(R3) calls for risk-based proportionality; the ISPE GAMP eClinical Good Practice Guide shows how to achieve it in practice, a proven methodology rather than a regulation: effort scaled by intended use, data criticality and the impact on the protection of trial participants and the reliability of trial results.

  • Data flow and data integrity analysis as the basis of the validation strategy
  • Trial-specific configuration and customization as verification items in their own right
  • Interfaces and data transfers are verified end to end along the clinical data lifecycle
End-to-end validation of highly complex eClinical platforms in clinical research
In practice.

Two case studies show how such validation plays out: the implementation of an investigator notification system (safety notifications, validated end to end) and the replacement of a drug safety solution with pharmacovigilance and E2B. The underlying rationale is set out in our book chapter on validating computer systems in clinical trials.

Approach

The path to a validated system landscape.

Risk-based and process-oriented: that is how even a highly complex eClinical environment gets validated without burning resources. And stays validated: through operation, migration and decommissioning.

  1. 1

    Process and data flow analysis

    We map the GCP-relevant processes and systems and chart the data flow from source data to analysis, including interfaces and data criticality.

  2. 2

    Provider assessment & agreements

    Assessing and selecting service providers, with agreements in place before services start: data access, audit rights, subcontractors.

  3. 3

    Risk assessment & validation strategy

    Risks to trial participants and data integrity set the scope and depth of validation, scaled to the actual risk rather than to blanket documentation.

  4. 4

    End-to-end verification

    Standard functionality, trial-specific configuration and interfaces are verified along the clinical data lifecycle and stay traceable back to the requirement.

  5. 5

    Access & user management

    Access is granted only once the protocol and the agreements are in place, is verified at suitable intervals and withdrawn in good time; privileged accounts stay independent of the conduct of the trial, and shared accounts are ruled out.

  6. 6

    Operation, changes & reviews

    Change control and periodic review maintain the validated state: the review weighs infrastructure, application, configuration, deviations, security incidents and provider agreements together; a change to an eCRF or eCOA form names the protocol amendment and reaches the investigator along with the date it took effect. Audit trail review runs as a planned, risk-based activity.

  7. 7

    Migration & decommissioning

    Migration runs as a validated process with reconciliation, archives are read-only, decommissioning ends with a certified copy and a defined recommissioning path in case data must be available in the system again; dynamic data stays dynamically usable.

ALCOA++ in clinical research

What do the ten ALCOA++ criteria mean in the GCP context?

ALCOA++ is the GxP convention for data integrity: the EMA guideline uses exactly these attributes, and ICH E6(R3) demands them in substance. Security and reliability of data come on top as a data governance concern, not as an eleventh criterion.

CriterionGroupExamples in the GCP context
AttributableALCOAEvery entry is attributable to the person or system that generated it; how far traceability extends to the individual device follows from the criticality of the data.
LegibleALCOAStudy data stays legible throughout the retention period; compression or encryption must be fully reversible.
ContemporaneousALCOAData is captured at the time of the observation, not after the fact; date and time are set automatically by an external time source, not by the device.
OriginalALCOASource records are preserved, either as the first record or as a certified copy; dynamic data stays dynamically usable.
AccurateALCOAClinical data is correct, safeguarded by edit checks and source data verification.
Complete+All visits, queries, metadata and the EDC audit trail are present.
Consistent+Definition, capture and management of data stay consistent across the entire life cycle, migration included; contradictions are detected or avoided in the first place.
Enduring+Study data endures in the GCP-compliant archive throughout the retention period.
Available when needed+Data is accessible at any time for monitoring, audit and inspection.
Traceable++Every change to a record can be traced end to end through the audit trail.
The inspectors' benchmark

Clinical data whose integrity you can demonstrate.

The benchmark is clear: the EMA guideline on computerised systems, anchored in EudraLex Vol. 10 and globally harmonized through ICH E6(R3). Inspectors expect direct read-only access to systems, data and audit trails, even after decommissioning. We assess against exactly that benchmark, using the methodology QFINITY co-defined in the ISPE GAMP eClinical Good Practice Guide.

EMA guideline (since 09/2023) EudraLex Vol. 10 Annex III ICH E6(R3) PIC/S PI 011 Direct read-only access Certified Copy
Our service

Good Clinical Practice, supported in practice.

Consulting on data governance and data integrity for GCP-relevant systems
Building and improving quality management systems (QMS)
Risk-based validation strategies along the ISPE GAMP eClinical Good Practice Guide
Data flow and data integrity analyses
Consulting on data integrity and governance for Real-World Data / Real-World Evidence (RWD/RWE)
Audit trail review concepts: planned, risk-based, documented
Role and control models: no sole control by sponsor, certified copies
Service provider oversight: agreements, vendor assessment, tool selection
Vendor and service provider audits: CROs, software vendors, SaaS/cloud providers, including on site
User and access management: least privilege, segregation of duties, individual accounts, periodic user reviews
eCOA/ePRO and BYOD: device policy, minimum specification, alternative capture route
eConsent process design
Blinding and unblinding governance
Electronic signatures: concepts along eIDAS and Part 11
Backup and restore testing, IT security requirements
Migration planning and concepts, including reconciliation
Decommissioning and retention strategies
Training, workshops and hands-on support for validation activities
More from the service areas

Data integrity has many contexts.

Your eClinical landscape with demonstrable validation.

We build a risk-based end-to-end validation strategy with you along the EMA guideline and ICH E6(R3), from data flow analysis to documented verification. It starts with a free intro call on your system landscape and on where measures have the strongest impact on your data integrity.

Book an intro call