Skip to main content

Prepare for a regulatory inspection or a sponsor audit

Who answers for what, the documents to pull from Datacapt, how to give an inspector read-only access, and the questions inspectors ask about an EDC

An inspector from ANSM, EMA, FDA or MHRA will ask you to show that your EDC data is attributable, complete and unaltered, and that you controlled the system. Datacapt holds most of the evidence. This guide tells you where, and what stays on your side.


Who answers for what

Topic

Datacapt

You (sponsor, CRO or investigator site)

Validation of the platform (each release)

✔ Validation documentation and release notes

Keep the release notes that cover your study period

Hosting, backups, disaster recovery, security

Keep the contract and the data processing agreement

Validation of your study configuration: forms, edit checks, roles, randomization

✔ Your test plan, test evidence and go-live approval

User access: who had which role, and when

Records it

✔ Review it, and remove leavers

Training of study users

Provides the help center

✔ Keep training records per user

Data entry, corrections, signatures

Records them

✔ The investigator signs; you monitor

💡 Tip: inspectors ask sponsors to show they understand their EDC, per the EMA guideline on computerised systems in clinical trials (2023). "The vendor handles that" is an answer that triggers more questions. Read this page with your quality lead before the inspection.


The documents to pull from Datacapt

Evidence

Where

Blank eCRF, one per version

eCRF Builder › printer icon (Print empty eCRF). See Change an eCRF after the study is Live for version records

Data dictionary with edit checks and conditions

Any eCRF export › Items Dictionary sheet

Complete data, with queries, SDV and missing data

Inclusions list › Export records. The workbook includes the Queries List, SDV and Missing Answers Comments sheets

One subject's casebook as PDF

Export as PDF from the subject's record

Study audit trail

Study › Audit TrailsExport data. Filter by user, action, event or variable first when the inspector asks a targeted question

Changes to the eCRF design

Study › Audit Trails, event type eCRF

Who exported data, and when

Export window › History tab, and audit trail action Viewed/Exported

Logins, failed logins, role changes

Settings › Audit trails (platform level) › export to Excel

Users and roles on the study

Study › Users, and Settings › Roles for the permissions of each role

Randomization and unblinding events

Study audit trail, actions Randomised and Emergency unblind

Signed consents, with version and date

eConsent › records

Platform release history

Help center › Release notes

From Datacapt, on request to your account manager: the validation summary of the releases in your study period, the hosting and security description, the list of sub-processors.


Give the inspector access

Inspectors often ask for direct read-only access instead of screenshots. Create a role for it before the inspection day.

🛠️ Step by step guide

  1. Navigate to Settings › Roles and create a role named "Inspector"

  2. Grant Access (read) on eCRF records, Monitoring, Audit trails, eConsent records and Documents. Grant no Edit, Sign, Lock, Export or Builder permission

  3. Leave Unblind Access off in a blinded study

  4. Invite the inspector to the study with this role, on the centers in scope

  5. After the inspection, remove the user from the study. The audit trail keeps the record of the access

⚠️ Warning: a read-only role still shows what any study role shows, including participant names when the study collects them. When the inspector must not see identifying data, exclude the role from the sections that hold it (Exclude roles on the section) or use Role-Based Visibility on those questions. Do this in Draft or Suspended status, since it is a Builder change.


Questions inspectors ask, and where the answer is

"Show me who changed this value, when, and why."

Open the record, open the question menu, select Audit trails. With Enable GCP on, each change carries its reason.

"How do you know the investigator reviewed the data?"

Signature per visit, with email and password, recorded in the audit trail with a signature ID. A signed visit refuses edits.

"Could someone change data after database lock?"

Status Ended locks all data. Moving back to Live asks for a written reason, and the audit trail keeps it.

"Which version of the eCRF did site 03 use on 12 March?"

Datacapt runs one eCRF at a time for all sites. Your version records (blank PDF per change, with the suspension dates from the audit trail) answer this.

"How were edit checks tested?"

Your validation file: the test subjects you ran in Draft, with screenshots or a signed test script. Datacapt deletes test data at go-live, so export it before.

"Who had access to unblinded data?"

Settings › Roles shows which roles hold Unblind Access and Emergency Unblind; the platform audit trail shows role changes over time.

"How are passwords controlled?"

Minimum 12 characters with four character classes, expiry at 90 days, the last 24 passwords refused, lockout after repeated failures, optional MFA and SSO. See Password rules and expiry.


Before the inspection: a one-hour check

  1. Export the study user list. Remove users who left.

  2. Check that open queries have an owner and an age you can explain.

  3. Check that your version records match the eCRF changes in the audit trail.

  4. Export the test data and validation evidence, if the study is still in Draft.

  5. Create the Inspector role and test it with a colleague's account.


👉🏻 Next step

Did this answer your question?