UAT is where the people who will use the study database check that it does what the protocol and data management plan say. Capture gives you a free sandbox with every feature, no credit card and no time limit, so you can build the study, run your scripts and sign off before you pay to go live.
Free sandbox · No credit card · 21 CFR Part 11 aligned
Scripts passed
38 / 44
Open defects
3
Sign-off
Pending
EDC UAT in brief
Free
sandbox with every feature
0
credit cards needed, no time limit
Audit trail
field-level, tested like production
EU + US
hosting in Frankfurt or N. Virginia
The concept
There are two things to validate when you use an EDC. The first is the software itself: does the platform do what the vendor says, reliably, with controls that meet 21 CFR Part 11 and similar expectations? That is the vendor’s validation, and the sponsor typically reviews it as part of vendor qualification. The second is your configuration: do the forms, edit checks, visit schedule, roles and exports in this study match the protocol and the data management plan? That is what UAT covers, and it is the sponsor’s or the study team’s responsibility, even where a CRO or the vendor builds the database.
The distinction matters because most real defects are configuration defects. A range check entered as 40 to 140 instead of 140 to 40, a visit anchored to the wrong event, a skip rule that hides a field that should stay visible, a role that sees more than it should. None of these is a software bug, and none will be caught by the vendor’s validation. They are caught by someone who knows the protocol using the database like a site would. The computer system validation page covers the wider validation picture, and 21 CFR Part 11 compliant EDC lists the controls to test.
The scale of the testing is risk based. A short observational registry needs less than a pivotal trial with randomisation, unblinded roles and expedited safety reporting. Write the proportionality down in the data validation plan and the reasoning will carry you through an inspection. A starting document is the data validation plan template, and the data management plan template shows where UAT fits in the plan.
The process
List what is in the build: forms, edit checks, calculated fields, visit schedule and windows, roles, notification rules, eConsent, randomisation, safety forms and exports. Tie each item to a protocol section or a data management plan requirement.
One script per requirement: the steps, the data to enter, and what should happen. Include negative tests, such as an out-of-range value or an ineligible participant, as well as the happy path.
A data manager, a site coordinator, an investigator, a monitor and, where relevant, a blinded and an unblinded user. Testing as the role finds permission problems that a builder account never sees.
Record actual results, pass or fail, who ran it and when. Failed items go in a defect log with severity, the fix and the retest result.
Rerun the failed script and anything the fix could have touched. Do not accept a verbal “fixed”.
The study lead and data manager sign the UAT summary: scripts run, defects open and closed, deviations accepted, and a statement that the build is fit for use. Sign-off precedes go-live.
What to test
Examples of what to cover, one row per area. Add rows for what your protocol includes.
| Area | Example scripts | Who tests |
|---|---|---|
| Forms and field types | Every required field enforced, formats accepted, repeating tables add and remove rows | Data manager, site user |
| Skip logic | Selecting “female” shows pregnancy fields; selecting “male” hides them | Data manager |
| Edit checks | Out-of-range vital sign raises an auto-query; correcting the value closes it | Site user, data manager |
| Calculated fields | BMI, QTc and eGFR values match a hand calculation, and read-only in entry | Data manager, statistician |
| Visit schedule | Anchors, windows and enforcement mode behave on early, on-time and late dates | Study coordinator |
| Roles and blinding | Blinded users never see arm values; sites see only their own participants | Data manager, unblinded user |
| Signatures | Investigator sign-off and countersignature need re-authentication | Investigator |
| Safety | SAE raises an alert, acknowledgement is logged, PI sign-off is recorded | Safety contact, investigator |
| Audit trail | A changed value shows old value, new value, user, time and reason | Data manager, QA |
| Exports | Data dictionary matches the forms; blinded export stays blinded | Data manager, statistician |
In Capture
Sign up, build the study or upload a protocol and let the AI study builder draft visits and forms, and test everything with every feature switched on. There is no credit card and no time limit, so UAT can follow your own pace rather than a trial clock. You pay only once you go live with real participants. Review AI-drafted forms before use, since nothing is saved without human review.
| Skip logic | Edit check | Audit trail | Role view | |
|---|---|---|---|---|
| Demographics | ||||
| Vital signs | ||||
| Adverse events | ||||
| Concomitant meds |
Build a test study, run a script as a site user and read the audit trail. Free sandbox, every feature, no credit card.
Documentation
The UAT record is a trial master file document. Keep the test plan, executed scripts with results, the defect log, the sign-off and the version of the study build that was tested. When the build changes after go-live, a change request records the reason, the impact assessment and the retest, and the audit trail keeps the evidence that the change was made through the controlled route. The platform’s own records support this: forms move through a draft to approved lifecycle, approved forms are locked for live use, and only approved forms appear in the casebook.
Enterprise customers get documentation to support sponsor validation and UAT, along with dedicated support channels, training and implementation assistance. For academic teams and smaller sponsors the free sandbox is usually enough to run a proportionate UAT. If you are moving from another system, the migration guides, for example moving from Excel spreadsheets, cover the data side that UAT should also test. For the whole launch plan, see the fastest way to launch a clinical trial.
Capture does not replace your validation judgement. It does not certify your study build or sign the UAT for you, and Part 11 compliance remains a shared responsibility between the software and your own validated use of it.
Go-live checklist
Scripts executed, defects closed or accepted, sign-off by the study lead and data manager.
Only approved forms are live; draft changes go through change control.
Sandbox sample data is not carried into the live study.
Named accounts, delegation log matched to access, blinded roles checked.
Site staff trained and the training log filed; see the delegation log template.
SAE alerts and query notifications reach the named contacts.
A dry-run export with data dictionary reviewed by the statistician.
Approved consent version loaded and the signing flow tested.
Testing of the finished study database by the people who will use it, against written requirements from the protocol and data management plan, before real data is entered. It checks forms, edit checks, visit schedules, roles and exports, and ends with a signed outcome.
Yes. Capture’s free sandbox includes every feature, with no credit card and no time limit. You can build a full study, enter sample data and test skip logic, edit checks, e-signatures and the audit trail, and pay only when you go live with real participants.
The sponsor, or the study team on its behalf. The vendor validates the platform. The sponsor validates that this study’s configuration matches its protocol, even where a CRO or the vendor builds the database.
Enterprise customers receive documentation to support sponsor validation and UAT, along with dedicated support, training and implementation assistance. Capture does not sign off your UAT for you.
It depends on the risk and complexity. Write one script per requirement, including negative cases, and scale the number to the study. A short registry needs far fewer than a randomised study with blinding and expedited safety reporting. Record the reasoning in the data validation plan.
No. Use sample data in the sandbox or a test copy, then carry only the approved build into the live study. Do not carry sandbox sample data into the live study.
Follow change control: record the reason, assess the impact, make the change, retest what is affected and file the evidence. Approved forms are locked for live use, and the audit trail records changes.
They can enter UAT as drafts. The AI study builder drafts visits and forms from a protocol, but nothing is saved without human review, and the reviewed forms must be tested like any others.
Build the study, run your UAT scripts and read the audit trail in the free sandbox. No credit card, no time limit; you pay only when you go live with real participants.