Select Page

Computerized Systems in Clinical Trials have become integral to modern clinical research. Electronic data capture systems, electronic case report forms, electronic patient-reported outcomes, electronic trial master files, interactive response technologies, electronic informed consent and other systems may be used to create, process, transfer, review or retain clinical trial information.

Regulations governing computerized systems in clinical trials are intended to help ensure that these technologies are fit for their intended purpose and that electronic records remain reliable, secure, traceable and available throughout their required lifecycle.

Computerized Systems in Clinical Trials

Clinical trial computerized systems may be used by sponsors, investigators, contract research organizations, laboratories, technology providers and trial participants.

Examples include:

  • Electronic Data Capture (EDC) systems
  • Electronic Case Report Forms (eCRFs)
  • Clinical Trial Management Systems (CTMS)
  • Electronic Trial Master Files (eTMF)
  • Electronic Clinical Outcome Assessments (eCOA)
  • Electronic Patient-Reported Outcomes (ePRO)
  • Interactive Response Technology (IRT)
  • Electronic informed consent systems
  • Safety databases
  • Electronic source-data systems
  • Digital health technologies and wearable devices

The regulatory expectations applying to a system depend on factors such as its intended use, the applicable regulations, the importance of the data or activities it supports and the risks associated with the system.

Regulatory Framework for Computerized Systems

There is no single worldwide regulation governing every computerized system used in clinical trials.

Organizations need to consider the regulatory requirements applicable to the jurisdiction, trial, records and systems involved.

Important frameworks and guidance include:

  • FDA requirements applicable to clinical investigations
  • 21 CFR Part 11 for applicable electronic records and electronic signatures
  • FDA guidance on electronic systems, electronic records and electronic signatures in clinical investigations
  • ICH E6 Good Clinical Practice
  • European Union clinical-trial requirements
  • EMA guidance on computerised systems and electronic data in clinical trials
  • Applicable data-protection and privacy requirements

Organizations should therefore determine which requirements apply rather than assuming that compliance with one technical standard automatically establishes compliance with every regulatory framework.

21 CFR Part 11

Title 21 of the Code of Federal Regulations Part 11, commonly known as 21 CFR Part 11, addresses electronic records and electronic signatures within its regulatory scope.

Part 11 applies to certain records in electronic form that are created, modified, maintained, archived, retrieved or transmitted under FDA record requirements and to certain electronic records submitted to FDA.

Part 11 should be considered together with the underlying FDA regulations that require the records. These underlying requirements are sometimes referred to as predicate rules.

Part 11 is therefore not simply a general software certification standard.

FDA provides additional guidance on electronic systems, electronic records and electronic signatures in clinical investigations.

Electronic Records

Electronic records used in regulated clinical investigations should be managed so that they remain trustworthy, reliable and appropriate for their intended purpose.

Important considerations may include:

  • Accuracy and completeness
  • Record availability
  • Appropriate retention
  • Traceability
  • Protection against unauthorized alteration
  • Access controls
  • Audit trails where applicable
  • Appropriate backup and recovery
  • Security
  • Ability to provide records for regulatory inspection

Controls should be proportionate to the importance of the records and the risks associated with the system and its use.

Electronic Signatures

Electronic signatures may be used in regulated clinical-trial processes when applicable regulatory requirements are satisfied.

Controls should help ensure that electronic signatures are attributable to the individual who executed them.

Signed electronic records should appropriately identify information such as:

  • The name of the signer
  • Date and time of signature
  • Meaning associated with the signature, where applicable

Electronic signatures should also be appropriately linked to their respective electronic records so that the relationship between the signature and record is maintained.

Authentication mechanisms and controls should prevent inappropriate use of another individual’s electronic signature.

System Validation and Fitness for Intended Purpose

Computerized Systems in Clinical Trials should be fit for their intended purpose and appropriately controlled according to their intended use and associated risks.

Validation should provide documented assurance that a system can consistently perform according to its intended use and applicable requirements.

The nature and extent of validation should be based on factors such as:

  • Intended use
  • System functionality
  • Importance of the supported processes
  • Importance of the data
  • Risks to trial participants
  • Risks to data reliability and integrity
  • System complexity
  • Configuration and customization

A risk-based approach allows validation activities to focus on functions and processes that are important to participant protection and reliable trial results.

Validation should not be treated merely as producing documentation. The objective is to establish confidence that the system is appropriate for its intended regulated use.

User Access and Security

Access to computerized systems should be restricted to appropriately authorized users.

Organizations should establish suitable controls for:

  • User identification
  • Authentication
  • Access privileges
  • Role-based permissions where appropriate
  • Account creation and modification
  • Account deactivation
  • Periodic review of access
  • Prevention and detection of unauthorized access

Access rights should reflect the responsibilities assigned to individual users.

Shared accounts should generally be avoided when they would prevent activities from being reliably attributed to individual users.

Audit Trails

Audit trails provide an important mechanism for maintaining traceability of activities involving electronic records.

Where applicable, audit trails should capture relevant information about the creation, modification or deletion of data and records.

Audit-trail information may include:

  • What was changed
  • Who performed the action
  • When the action occurred
  • Previous and revised values
  • Reason for change where required

Importantly, changes to electronic data should not erase or obscure the previously recorded information. The history of relevant changes should remain traceable.

This corrects an important error in older descriptions of Part 11, which can mistakenly suggest that changed information should be erased.

Audit-Trail Review

Simply generating an audit trail is not always sufficient.

Organizations should determine when and how audit trails need to be reviewed based on the importance of the data, the process and associated risks.

Audit-trail review can help identify:

  • Unauthorized changes
  • Unusual data modifications
  • Process deviations
  • Data-integrity concerns
  • Inappropriate user activity

The review approach should be proportionate and defined according to the intended use and risk of the system.

Data Integrity

Data integrity is fundamental to computerized systems used in clinical research.

Clinical trial data should remain reliable throughout their lifecycle, including collection, creation, processing, review, transfer, correction, analysis, retention and retrieval.

Important data-integrity characteristics include information being attributable, legible, contemporaneous, original and accurate, together with appropriate expectations for completeness, consistency, endurance, availability and traceability.

Controls should preserve both the data and relevant metadata needed to understand the data and its history.

Data Changes and Corrections

Changes to electronic clinical trial information should be controlled and traceable.

Corrections should not obscure the original information.

Systems should preserve sufficient information to determine what changed, who made the change and when it occurred.

Where required by the process or system, the reason for the change should also be documented.

These controls support reconstruction and evaluation of important trial activities during monitoring, audits and regulatory inspections.

Electronic Data Transfer and Migration

Clinical trial information is frequently transferred between systems.

Examples include transfers from laboratories, electronic health records, eCOA platforms, safety systems and other external sources into sponsor or data-management environments.

Organizations should ensure that transfers and migrations preserve:

  • Data accuracy
  • Completeness
  • Meaning
  • Metadata where relevant
  • Traceability
  • Security
  • Confidentiality

Transfer and migration processes should be appropriately tested and controlled according to risk.

System Changes and Configuration

Computerized systems can change during a clinical trial because of software updates, configuration changes, defect corrections or changes to trial requirements.

Changes should be appropriately controlled.

Change-control activities may include:

  • Assessment of the proposed change
  • Evaluation of potential impact
  • Testing
  • Approval
  • Documentation
  • Deployment controls
  • Verification following implementation

The level of control should reflect the risk and potential effect of the change on trial processes and data.

Backup, Recovery and Business Continuity

Appropriate mechanisms should be established to protect important electronic clinical trial information against loss or unavailability.

Depending on system risk and intended use, this may involve:

  • Backup procedures
  • Recovery processes
  • Disaster recovery arrangements
  • Business continuity planning
  • Testing of recovery capabilities

The objective is to ensure that important records and trial processes remain appropriately protected and recoverable.

Record Retention and Archiving

Electronic records should remain accessible, readable and retrievable throughout the applicable retention period.

Organizations should consider risks associated with:

  • Technology obsolescence
  • Software retirement
  • Data migration
  • Changes in file formats
  • Loss of metadata
  • Vendor discontinuation
  • System decommissioning

Archiving should preserve the information required to understand and reconstruct relevant trial activities.

Service Providers and Cloud-Based Systems

Modern clinical trials frequently rely on external technology and service providers.

Use of a vendor does not eliminate the responsibilities of the sponsor or investigator for activities under their respective responsibilities.

Organizations should apply appropriate qualification and oversight to service providers based on risk.

Considerations may include:

  • System capabilities
  • Validation documentation
  • Security
  • Data ownership
  • Data access
  • Backup and recovery
  • Incident management
  • Subcontractors
  • Business continuity
  • Data export
  • System termination
  • Record retention

Contracts and documented responsibilities should support appropriate control throughout the service lifecycle.

European Regulatory Expectations

European clinical trials are also subject to regulatory expectations for computerized systems and electronic data.

The European Medicines Agency’s guidance on computerised systems and electronic data in clinical trials addresses areas such as:

  • System validation
  • User management
  • Security
  • Data capture
  • Audit trails
  • Electronic signatures
  • Data transfer
  • System interfaces
  • Archiving
  • Service providers
  • Electronic clinical outcome assessments
  • Interactive response technologies
  • Other computerized processes used in clinical trials

The validation effort should be proportionate to the system’s intended use, its importance to participant protection and the importance and integrity of the clinical trial data it supports.

GAMP guidance may be useful to organizations developing lifecycle approaches for computerized systems, but it should not be described as an EMA regulation or as the European equivalent of 21 CFR Part 11.

ICH E6(R3) and Computerized Systems

ICH E6(R3) modernizes Good Clinical Practice for an environment in which technology and electronic data are integral to clinical research.

Its broader quality principles support:

  • Fit-for-purpose systems
  • Proportionate approaches
  • Risk-based quality management
  • Appropriate data governance
  • Reliable trial information
  • Clear roles and responsibilities
  • Appropriate oversight of service providers
  • Protection of participant confidentiality
  • Secure and reliable computerized processes

Technology should support the objectives of the trial without introducing unnecessary complexity or unmanaged risk.

Regulatory Inspections

Computerized systems and electronic records may be evaluated during regulatory inspections.

Inspectors may assess areas such as:

  • System validation
  • Procedures
  • User access
  • Audit trails
  • Data changes
  • Electronic signatures
  • Security
  • Data transfers
  • Record retention
  • Vendor oversight
  • Training
  • System documentation

Organizations should therefore be able to demonstrate not only that appropriate controls exist, but also that those controls are effectively implemented and maintained.

Conclusion

Computerized Systems in Clinical Trials have become increasingly important as clinical research has become more digital and data-driven.

21 CFR Part 11 remains an important U.S. requirement for applicable electronic records and electronic signatures, but regulatory compliance extends beyond Part 11 alone. Current FDA guidance, ICH Good Clinical Practice and European requirements all emphasize reliable electronic records, fit-for-purpose systems, appropriate validation, data integrity, security, traceability and risk-based controls.

Modern computerized-system compliance should therefore focus on the complete data and system lifecycle rather than treating regulatory compliance as a one-time software-validation exercise.

For additional learning resources in clinical data management, explore the Clinical Data Management Knowledgebase.

Professionals interested in structured training can also explore ClinSkill’s Diploma in Clinical Data Management.

For practical software training, explore the Oracle Clinical Fundamentals program and available Oracle Clinical software access options.

You may be interested in…