Regulatory guide · EMAUpdated October 8, 2026

EMA guideline on computerised systems and electronic data: what EDC buyers need

The EMA guideline sets out what GCP inspectors in the EU expect from any system that holds trial data, from EDC and ePRO to eConsent and IRT. This guide summarises it and turns it into a checklist for choosing a system. General information, not legal advice.

  • In effect since September 2023
  • Includes a buyer checklist
  • Not legal advice

Free sandbox · No credit card · 21 CFR Part 11 aligned

Guideline structure
EMA-INS-GCP-112288-2023.pdf9/9 complete
  1. 4

    Principles: data integrity, ALCOA++, criticality, e-signatures, validation

    Complete
  2. 5

    Computerised systems: procedures, training, security, timestamps

    Complete
  3. 6

    Electronic data: capture, audit trail review, sign-off, cloud, migration, archiving

    Complete
  4. A1

    Agreements with service providers

    Complete
  5. A2

    Computerised systems validation

    Complete
  6. A3

    User management

    Complete
  7. A4

    Security

    Complete
  8. A5

    eCOA and ePRO, IRT, electronic informed consent

    Complete
  9. A6

    Clinical systems at sites

    Complete
Section titles paraphrased from the guideline's table of contents.

Key points

  • Not legal advice. This page summarises the guideline. Read the full text and agree your approach with your QA and regulatory advisers.
  • The Guideline on computerised systems and electronic data in clinical trials (EMA/INS/GCP/112288/2023) was adopted by the GCP Inspectors Working Group on 7 March 2023 and came into effect in September 2023. It replaced the 2010 reflection paper on electronic source data.
  • It applies to every system used in a trial, whether installed on site or bought as cloud or SaaS, and to sponsors, investigators and service providers alike.
  • It expands ALCOA+ into ALCOA++ and expects risk-based, ongoing audit trail review, not just an audit trail that exists.
  • The sponsor stays responsible for validation. You may rely on vendor documentation only after assessing it, often through an audit.

Scope and principles

What the guideline covers

The guideline is written by EU GCP inspectors and describes what they expect to see. Its scope is computerised systems, including instruments, software and services, used to capture electronic clinical data or to control processes that could affect participant protection or data reliability in a trial of investigational medicinal products. The list includes electronic medical records, eCRFs, eCOA and ePRO (including bring-your-own-device apps), wearables and sensors, temperature loggers, lab and imaging systems, eTMFs, eConsent and IRT. Its keywords even include artificial intelligence. It applies regardless of whether the system is built in-house, bought, free or provided as a service.

Its data integrity principles are the backbone. ALCOA++ lists ten attributes: attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, available when needed and traceable. The guideline gives each a concrete meaning, for example that accurate date and time should be captured automatically and set by an external standard, and that changes should not obscure the original value. The ALCOA+ data integrity checklist applies these attributes to daily data handling; this page focuses on what the guideline expects of the system itself.

Audit trail review and investigator sign-off

Section 6.2.2 asks for procedures for risk-based, trial-specific audit trail review, focused on critical data and carried out on an ongoing basis unless justified. Review can find missing data, outliers, entries at odd hours, unauthorised access and device faults. Section 6.3 expects investigators to sign off their data at predefined milestones set by the sponsor; one signature just before database lock will rarely be enough, and signing workbooks in batches undermines the review.

Cloud, migration and decommissioning

For cloud solutions, the responsible party should qualify the provider, set detailed contracts covering GCP topics and data jurisdiction, and, if it validates the system itself, have access to a test environment identical to production. Migration validation deserves as much attention as system validation, and data, context and audit trail should not be separated.

The annexes

Validation, users and specific systems

Annex 2 says systems should be validated whether they are custom, commercial, free or a service. You can rely on a vendor's validation documentation if you have assessed it and it covers your intended use, and inspectors may ask to see that assessment. Where a SaaS vendor releases updates at short notice, you should evaluate its release process and not use new functions until you have assessed them. Our computer system validation guide covers proportionate approaches.

Annex 3 expects an overview of current and past users, roles and permissions to be available from the system at any time, periodic user reviews, timely removal of access, segregation of duties, least privilege and individual accounts. Annex 4 lists security controls including vulnerability management, penetration testing, inactivity logout and protection against back-end changes.

Annex 5 adds detail for specific systems. For ePRO, timestamps should record the time of entry, not just transmission; participants should usually be able to see their own recent entries; data should move to a durable server early by a validated procedure; investigators should get timely access to their participants' data; and there should be a documented route for correcting participant data. For eConsent, alternatives should exist for people who cannot or will not use electronic methods, and sole use of eConsent should be justified in the protocol. Related reading: ePRO software for clinical trials and eConsent software.

Check a system against the guideline yourself

Open the free sandbox, enter test data, change a value and read the audit trail entry it creates. No credit card; pay only when you go live.

Start free in the sandbox

Buyer checklist

Questions for any EDC or ePRO vendor, mapped to the guideline

Ask for a demonstration, not a yes. Note what each vendor shows you.

Audit trail content (6.2.1)

Does every change record who, when, the old and new value and the reason? Can anyone, including administrators, edit or delete audit entries?

Audit trail review (6.2.2)

Can you filter and export the audit trail by site, form, user and date range for a risk-based review? Can investigators see the trail for their own data?

Investigator sign-off (6.3)

Can the investigator sign data at milestones you define, with the signature linked to the data it confirms?

User management (Annex 3)

Can the system list current and past users with their roles at any time? Are there individual accounts and role separation between site and sponsor?

Security (Annex 4)

Is there inactivity logout, multi-factor authentication and encryption at rest and in transit? How are back-end changes prevented and logged?

Validation (Annex 2)

What validation documentation can the vendor share, how are releases controlled, and is there a test environment matching production?

Cloud and contracts (6.7, Annex 1)

Where is data hosted, and does the contract cover GCP duties, inspection access and data jurisdiction?

Export, archive, exit (6.11, 6.12)

Can you export all data with metadata and audit trail in a readable form for archiving and decommissioning?

Where Capture fits

How Capture maps to the guideline

Capture is a self-serve platform for EDC, ePRO and eConsent in one system with one audit trail. Every change to study data is recorded at field level with the user, timestamp, old value, new value and reason. The trail is written by database triggers, is append-only (the database blocks updates and deletes on audit rows) and each row is SHA-256 hash-chained to the previous one; it cannot be modified through the interface and is always exportable. Clinical data are soft-deleted only. Technical events go to a separate system log.

Access is role-based, with row-level security at the database layer, participant names visible only to site coordinators and coded IDs for researchers, and blinded roles never receive treatment-arm values. Staff can use authenticator-app two-factor sign-in and sessions end after inactivity. Data are hosted in the EU (Frankfurt) or the US (N. Virginia), with AES-256 at rest and TLS in transit, and we review the app against the OWASP Top 10. Exports cover CSV and Excel with a data dictionary and CDISC SDTM with Define-XML. eConsent uses a two-step participant signature with email one-time code and investigator countersignature with re-authentication. Enterprise customers get documentation to support sponsor validation and UAT, and the free sandbox lets you test the configured study first. These are 21 CFR Part 11 aligned controls; see the 21 CFR Part 11 checklist and audit trail software pages. Your procedures, risk-based review and validation complete compliance.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

When did the EMA computerised systems guideline take effect?

The guideline (EMA/INS/GCP/112288/2023) was adopted on 7 March 2023, published in March 2023 and came into effect six months after publication, in September 2023.

Does the guideline apply to SaaS EDC systems?

Yes. It applies whether a system is installed at a site or sponsor, or provided as a cloud service. Section 6.7 adds expectations on provider qualification, contracts, data jurisdiction and test environments.

What is ALCOA++?

Ten data integrity attributes: attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, available when needed and traceable. The guideline defines each in terms of data and metadata.

Is audit trail review mandatory?

The guideline expects procedures for risk-based, trial-specific audit trail review focused on critical data, done on an ongoing basis unless justified, with the review documented.

Can a sponsor rely on the vendor's validation?

Partly. You may rely on vendor documentation if you have assessed it, often by audit, and it covers your intended use. You remain responsible and may need additional validation.

How does it differ from 21 CFR Part 11?

Part 11 is a US regulation on electronic records and signatures. The EMA guideline is EU GCP inspector guidance covering the whole data life cycle, including audit trail review, sign-off, cloud, migration and specific systems such as ePRO and eConsent.

Does Capture meet the EMA guideline?

Capture provides technical controls the guideline looks for, such as a field-level append-only audit trail, role-based access and exports. Meeting the guideline also depends on your procedures, validation and review.

Test the audit trail before you buy

Build a study in the free sandbox, change data and inspect every entry. No credit card; pay only when you go live.

Start free in the sandbox