When an FDA investigator arrives, the questions about your data are predictable: can you show who entered it, who changed it and why, who signed it, and that it matches the source. This checklist covers what gets reviewed and how to have the answers ready.
Free sandbox · No credit card · 21 CFR Part 11 aligned
Ready
9 / 12
Open queries
4
Days to visit
6
Key points
The inspection
FDA conducts clinical trial inspections under compliance programs that describe what investigators should review. For clinical investigators the focus is on whether the investigator conducted the study according to the protocol and regulations, protected participants' rights and welfare, and produced records that accurately reflect what happened. Sponsor and CRO inspections focus on oversight: monitoring, safety reporting, data management and vendor control.
In both cases data integrity sits at the centre. An inspector will select participants and trace their data from source documents through the case report form to the submitted datasets, looking for discrepancies, unexplained changes and gaps. The questions follow the ALCOA+ principles: is each record attributable, legible, contemporaneous, original and accurate, and also complete, consistent, enduring and available? The ALCOA+ data integrity checklist goes through each principle.
Inadequate or inaccurate case histories are among the most frequent clinical investigator findings: CRF entries that do not match source, missing source documents, or changes without explanation. Close behind are failures to follow the protocol (including enrolling ineligible participants), consent that was not obtained or documented correctly, and adverse events not reported as required. Each maps to something your data system can make visible before the inspector finds it.
Weight changed 68.0 to 68.5 kg
Site coordinator · Reason: Transcription error
Query Q-0014 answered on Weight
Site coordinator · Reason: Source checked
Vital signs form locked
Data manager · Reason: Visit cleaned
Site checklist
| Area | What the inspector checks | Evidence to have ready |
|---|---|---|
| Informed consent | Every participant consented before any study procedure, with the approved version | Signed consent records with timestamps and version; re-consent after amendments |
| Eligibility | Each enrolled participant met every criterion | Eligibility forms with investigator sign-off, supporting source values |
| Source vs CRF | CRF values match source documents | SDV records, query history, source document locations |
| Data changes | Every change attributable, dated and explained | Field-level audit trail with old value, new value, user, time and reason |
| Adverse events | All AEs recorded, SAEs reported on time | AE log, SAE timelines, investigator sign-off |
| Protocol deviations | Deviations identified, documented and reported | Deviation log with assessments |
| Delegation and training | Only trained, delegated staff performed study tasks | Delegation log, training acknowledgements |
| Investigational product | Receipt, storage, dispensing and return reconcile | Accountability records |
System checklist
Sponsors and sites should be able to answer these about any system that holds trial data. Capture's answers are shown where they are product features; procedures remain your responsibility.
| Question | What a good answer shows | In Capture |
|---|---|---|
| Who can access the data? | Role-based access, individual accounts, access reviews | Role matrix per study and site; site staff see only assigned sites |
| Can changes be traced? | Complete, tamper-evident audit trail | One audit row per changed field, SHA-256 hash chain with a verify check |
| Can the audit trail be altered? | No edits or deletes | Append-only; updates and deletes blocked in the database |
| Are signatures valid? | Re-authentication, meaning, link to the record | Password re-entry verified on the server, meaning stored with each signature |
| Are timestamps reliable? | Server-set, not user-set | Set by the server, not the browser |
| Is deleted data recoverable? | No hard deletes of clinical data | Soft deletes kept in the audit history |
| Was the system fit for purpose? | Validation evidence for intended use | Your validation, supported by vendor documentation; see CSV guide |
Evidence on demand
The difference between a stressful inspection and a routine one is often how quickly records can be produced. In Capture the audit trail is always exportable, with readable descriptions and filters by category, user, participant and date, and every data export is itself logged with the user, time, filters and row count.
| SUBJ | ECGPERF_CODE | ECGPERF_LABEL |
|---|---|---|
| 01-001 | Y | Yes |
| 01-002 | ND | Not done |
Change a value, sign a form and export the audit trail in the free sandbox.
Preparation
Notice periods vary, and for-cause inspections may come with little warning, so the most reliable preparation is continuous. Still, a structured review in the weeks before a known inspection catches the issues most likely to become observations.
Pick a handful of participants, including any with SAEs, deviations or re-consent, and trace their data from source through the eCRF to the latest export. Every discrepancy you find is one the inspector will not.
Resolve open queries, complete outstanding SDV on critical fields, and make sure investigator sign-offs are current. Do not backdate or recreate documents: an explained gap is far better than an unexplained correction, and the audit trail will show when things were done.
Identify who will answer questions about the data system, who can run exports during the inspection, and who owns each area of the checklist. Practise pulling an audit trail for a specific participant and field.
An inspection under FDA's Bioresearch Monitoring program, which covers clinical investigators, sponsors, CROs and monitors, IRBs and others, to verify data integrity and participant protection.
The form on which FDA investigators record inspectional observations at the end of an inspection. It lists conditions the investigator believes may violate regulations.
Inadequate or inaccurate records, protocol deviations such as enrolling ineligible participants, informed consent problems and failures in adverse event reporting.
Who has access, how changes are tracked, whether the audit trail can be altered, how electronic signatures work, how timestamps are set, and how the system was validated for its intended use.
Yes. The audit trail is always exportable and can be filtered by participant, user, category and date.
It provides the technical controls. Inspection readiness also depends on your procedures, training, validation and how the study was actually conducted.
Keep exploring
Audit-ready clinical trial data
Readiness built in from day one.
21 CFR Part 11 compliance checklist
The electronic records requirements.
ALCOA+ data integrity checklist
The principles inspectors apply.
Protocol deviation tracking
A frequent inspection finding.
What is source data verification?
How CRF data is checked against source.
What is GCP?
The standard behind inspections.
Tamper-evident audit trail, verified signatures and exports on demand. Free sandbox.