
Data integrity of GCP‑relevant computerized systems.
Systems and data carry two things at once: the protection of clinical trial participants and the reliability of trial results. ICH E6(R3) and the EMA guideline on computerised systems set the bar. We help sponsors, trial sites, CROs and software vendors put it into practice.
Process orientation over technology for its own sake.
Data integrity of GCP-relevant computerized systems is achieved when the data of a clinical trial is collected, accessed and maintained securely across its entire life cycle and fulfills the ten ALCOA++ attributes; the bar is set by ICH E6(R3) and the EMA guideline on computerised systems.
We consult across clinical research and development, turning the requirements of the EMA guideline, ICH E6(R3) and Regulation (EU) 536/2014 into processes and quality management systems that hold up.
ICH E6(R3) makes data governance a shared task for sponsor and trial site; the EMA guideline spells out what inspectors expect from computerized systems and electronic data.
The methodological anchor, the ISPE GAMP Good Practice Guide "Validation and Compliance of Computerized GCP Systems and Data - Good eClinical Practice" (2nd Edition, July 2024), took shape with QFINITY: Frank Henrichmann and Oliver Herrmann as Co-Leads, Jenny Gebhardt and Marcus Schwabedissen on the author team. Oliver Herrmann led the ISPE GAMP R&D and Clinical Systems Special Interest Group (SIG).
The system landscape of clinical research.
GCP system landscapes are heterogeneous, networked and used around the globe. ICH E6(R3) groups the capture tools as Data Acquisition Tools, from the paper CRF to the wearable; data captured electronically at its origin is eSource. We look at every technology class in its process context, not in isolation.
The EMA guideline expressly covers the use of AI in clinical trials, from recruitment and eligibility determination to coding and query processes. It deliberately sets no AI-specific requirements initially; those may follow in a future annex. Until then, the general expectations for any system apply. What an AI-specific framework can look like is shown on the GMP side by the Annex 22 draft.
Who controls the device the data is created on?
Trial data increasingly originates on devices owned by neither the sponsor nor the site: a participant's phone, tablet or smartwatch. The EMA guideline gives Bring Your Own Device its own section within Annex 5, because this route moves part of the control to a place where the sponsor cannot exercise it. That belongs in the risk assessment, and with it in the scope of validation.
With its newly finalized Annex 2, ICH E6(R3) explicitly covers decentralized elements, digital health technologies and real-world data; the annex takes effect in the EU on 15 January 2027.
The requirements for clinician reported outcomes match those for ePRO systems; here the data is captured by the investigator, site staff or an independent assessor. Access rights deserve particular attention in that setting so that blinding is preserved.
Sponsor and trial site carry the data together.
The heart of the new GCP rules: data governance is shared responsibility across the entire data lifecycle. The sponsor never controls the captured data alone, and whoever delegates a task remains accountable for it.
The site's own systems are part of this. When selecting a trial site, the sponsor assesses whether those systems suit their use in this particular trial, right down to the audit trail of the electronic medical record; the guideline calls this step site qualification. If the assessment comes out negative, the choice of site itself is on the table, and a system used regardless calls for effective mitigating actions or a documented assessment of the residual risk.
As part of our consulting services, QFINITY supports you in defining responsibilities, control points and contract content between sponsor, trial site and service providers, before an inspector asks. And we test them in practice: with vendor and CRO audits, from the eClinical platform to the SaaS/cloud provider.
Highly complex platforms, validated with focus.
Rather than documenting every module wholesale, we follow the data flow through the eClinical platform, from capture through the interfaces to analysis. ICH E6(R3) calls for risk-based proportionality; the ISPE GAMP eClinical Good Practice Guide shows how to achieve it in practice, a proven methodology rather than a regulation: effort scaled by intended use, data criticality and the impact on the protection of trial participants and the reliability of trial results.
- Data flow and data integrity analysis as the basis of the validation strategy
- Trial-specific configuration and customization as verification items in their own right
- Interfaces and data transfers are verified end to end along the clinical data lifecycle
Two case studies show how such validation plays out: the implementation of an investigator notification system (safety notifications, validated end to end) and the replacement of a drug safety solution with pharmacovigilance and E2B. The underlying rationale is set out in our book chapter on validating computer systems in clinical trials.
The path to a validated system landscape.
Risk-based and process-oriented: that is how even a highly complex eClinical environment gets validated without burning resources. And stays validated: through operation, migration and decommissioning.
- 1
Process and data flow analysis
We map the GCP-relevant processes and systems and chart the data flow from source data to analysis, including interfaces and data criticality.
- 2
Provider assessment & agreements
Assessing and selecting service providers, with agreements in place before services start: data access, audit rights, subcontractors.
- 3
Risk assessment & validation strategy
Risks to trial participants and data integrity set the scope and depth of validation, scaled to the actual risk rather than to blanket documentation.
- 4
End-to-end verification
Standard functionality, trial-specific configuration and interfaces are verified along the clinical data lifecycle and stay traceable back to the requirement.
- 5
Access & user management
Access is granted only once the protocol and the agreements are in place, is verified at suitable intervals and withdrawn in good time; privileged accounts stay independent of the conduct of the trial, and shared accounts are ruled out.
- 6
Operation, changes & reviews
Change control and periodic review maintain the validated state: the review weighs infrastructure, application, configuration, deviations, security incidents and provider agreements together; a change to an eCRF or eCOA form names the protocol amendment and reaches the investigator along with the date it took effect. Audit trail review runs as a planned, risk-based activity.
- 7
Migration & decommissioning
Migration runs as a validated process with reconciliation, archives are read-only, decommissioning ends with a certified copy and a defined recommissioning path in case data must be available in the system again; dynamic data stays dynamically usable.
What do the ten ALCOA++ criteria mean in the GCP context?
ALCOA++ is the GxP convention for data integrity: the EMA guideline uses exactly these attributes, and ICH E6(R3) demands them in substance. Security and reliability of data come on top as a data governance concern, not as an eleventh criterion.
| Criterion | Group | Examples in the GCP context |
|---|---|---|
| Attributable | ALCOA | Every entry is attributable to the person or system that generated it; how far traceability extends to the individual device follows from the criticality of the data. |
| Legible | ALCOA | Study data stays legible throughout the retention period; compression or encryption must be fully reversible. |
| Contemporaneous | ALCOA | Data is captured at the time of the observation, not after the fact; date and time are set automatically by an external time source, not by the device. |
| Original | ALCOA | Source records are preserved, either as the first record or as a certified copy; dynamic data stays dynamically usable. |
| Accurate | ALCOA | Clinical data is correct, safeguarded by edit checks and source data verification. |
| Complete | + | All visits, queries, metadata and the EDC audit trail are present. |
| Consistent | + | Definition, capture and management of data stay consistent across the entire life cycle, migration included; contradictions are detected or avoided in the first place. |
| Enduring | + | Study data endures in the GCP-compliant archive throughout the retention period. |
| Available when needed | + | Data is accessible at any time for monitoring, audit and inspection. |
| Traceable | ++ | Every change to a record can be traced end to end through the audit trail. |
Clinical data whose integrity you can demonstrate.
The benchmark is clear: the EMA guideline on computerised systems, anchored in EudraLex Vol. 10 and globally harmonized through ICH E6(R3). Inspectors expect direct read-only access to systems, data and audit trails, even after decommissioning. We assess against exactly that benchmark, using the methodology QFINITY co-defined in the ISPE GAMP eClinical Good Practice Guide.
Good Clinical Practice, supported in practice.
Data integrity has many contexts.
Your eClinical landscape with demonstrable validation.
We build a risk-based end-to-end validation strategy with you along the EMA guideline and ICH E6(R3), from data flow analysis to documented verification. It starts with a free intro call on your system landscape and on where measures have the strongest impact on your data integrity.
Book an intro call


