For quality assuranceUpdated September 29, 2026

Clinical trial software that QA teams can check

Quality assurance needs evidence: who did what, when, why, and whether they were allowed to. Capture records it by design, with an append-only audit trail, re-authenticated signatures and role-based access you can review and export.

  • Append-only audit trail
  • Re-authenticated e-signatures
  • Access by role and site

Free sandbox · No credit card · 21 CFR Part 11 aligned

Weight changed 68.0 to 68.5 kg

Site coordinator · Reason: Transcription error

9f2c…a71e

Query Q-0014 answered on Weight

Site coordinator · Reason: Source checked

4b8d…c203

Vital signs form locked

Data manager · Reason: Visit cleaned

e61a…58f0
Verify chain Intact

What QA teams look for

  • An audit trail that captures user, time, old value, new value and reason for every change, cannot be modified, and can be exported.
  • Electronic signatures linked to the signer, re-authenticated at signing and carrying a statement of meaning.
  • Access control by role and site, with blinded and unblinded separation where needed.
  • Validation support: evidence the vendor tests its system, and a clear split between vendor and sponsor responsibilities.
  • Inspection readiness: records that can be retrieved quickly by participant, site and date.

Audit trail

An audit trail you can actually review

Every EDC claims an audit trail. The questions QA asks are more specific: is it field-level, does it include the reason for change, is it tamper-evident, can it be filtered and exported, and does it cover every module? In Capture, database triggers write the audit trail, one row per changed field. Updates and deletes are blocked, and each entry carries a hash of the one before it, so tampering breaks the chain.

Clinical data is never hard deleted, approved forms are locked for live use, and the audit trail covers EDC, ePRO, eConsent and randomisation in one study. See audit trail software for clinical trials.

Shared responsibility

Part 11 compliance depends on how a system is configured and used, not only on the software. Sponsors usually complete a risk-based validation and user acceptance testing on the vendor's platform. Capture provides documentation to support sponsor validation and UAT on Enterprise plans.

Weight changed 68.0 to 68.5 kg

Site coordinator · Reason: Transcription error

9f2c…a71e

Query Q-0014 answered on Weight

Site coordinator · Reason: Source checked

4b8d…c203

Vital signs form locked

Data manager · Reason: Visit cleaned

e61a…58f0
Verify chain Intact

Evidence

What QA can verify, and where

QuestionEvidence in Capture
Who changed this value, when and why?Field-level audit trail with user, time, old and new value and reason
Can the audit trail be altered?Append-only; updates and deletes blocked; hash chain
Was the signer authenticated?Password re-authentication with a meaning statement
Was consent properly obtained?Signed consent PDF with signature data, timestamps and audit trail
Who could see or change data?Roles with site-level separation; identifying data segregated
Was the blind protected?Blinded roles never receive the treatment arm from the server

Signatures

Signatures that mean something

Investigator signatures require password re-authentication and carry a legal meaning statement. Participant eConsent signatures are verified with an email one-time code after a legal-binding acknowledgement, and each signature is cryptographically linked to the exact document content at signing.

  • Re-authentication at signing.
  • Meaning statements.
  • Signature linked to document content.
Electronic signatures for clinical trials
Electronic signature

Meaning of signature

I have reviewed this adverse event and confirm the assessment of seriousness, severity and causality.

Signer

Dr. A. Ozola, PI

Password

••••••••••

Verified on the serverAutofill blockedSingle-use token
Sign

Review the audit trail yourself

Change a value in the free sandbox and read the record.

Review it in the sandbox

Vendor qualification

Qualifying an EDC vendor

QA usually qualifies a new eClinical vendor with a questionnaire, a documentation review and sometimes an audit. Typical topics are the vendor's quality system, software development and testing, change control, security, hosting, backups, incident management and support. Prepare the questions before the demo, and ask for evidence rather than assurances.

Our vendor security questionnaire guide lists the questions to ask, and the computer system validation guide covers the sponsor side of validation.

QA review

QA evaluation checklist

Audit trail test

Change, correct and query a value; review the record.

Signature test

Sign as an investigator; check re-authentication.

Access review

Compare roles with delegated tasks.

Blinding check

View the same participant as blinded and unblinded users.

Validation documents

What the vendor provides and what you must do.

Retrieval drill

Pull records for one participant and date range.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Can QA review trends across sites?

Yes. Deviation records, the query list and the audit trail can be filtered and exported for trend review.

Can the audit trail be filtered?

Yes, by category, user, participant and date.

Can the audit trail be modified?

No. Updates and deletes are blocked, and each entry carries a hash of the previous one, so tampering breaks the chain.

Does the audit trail include reasons for change?

Yes. Each change records the user, time, old value, new value and reason.

Is validation documentation available?

Documentation to support sponsor validation and UAT is available on Enterprise plans.

How are electronic signatures controlled?

Investigator signatures require password re-authentication and carry a meaning statement.

Is clinical data ever deleted?

Clinical data is never hard deleted; changes are recorded in the audit trail.

Can QA review the system before purchase?

Yes. The free sandbox includes every feature and sample data.

Evidence QA can check

Review the audit trail in the free sandbox.

Review it in the sandbox