GCP · Blog
Back to journal

Choosing an eTMF System That Survives a GCP Inspection: A Sponsor's Defensibility Framework

The SERP for "best eTMF systems" is saturated with vendor-authored listicles that rank platforms by brand and feature count. That is the wrong instrument. An inspector does not audit your feature grid. They audit whether your essential records are present, filed on time, traceable, and retrievable, and whether the system holding them is validated and controlled. This guide reframes eTMF selection as a GCP-defensibility decision and gives you the criteria to evaluate candidates against the duties that ICH E6(R3), 21 CFR Part 11, and EMA's TMF archiving guidance actually impose.

GCP 10 min read
A

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.

On this page · 10 sections
  1. 01 At a glance
  2. 02 eTMF vs paper TMF vs document management system: what the system actually has to do under GCP
  3. 03 The sponsor still owns the TMF: why “is the vendor compliant” is the wrong question
  4. 04 The GCP-defensibility scorecard: completeness, contemporaneity, traceability
  5. 05 21 CFR Part 11 controls your eTMF must enforce
  6. 06 EMA TMF expectations: archiving, retention, and audit-trail integrity
  7. 07 Validation is your job, not the badge: CSV/CSA, vendor audit, and the qualification you must document
  8. 08 The eTMF RFP: questions that separate inspection-ready systems from feature lists
  9. 09 Where teams get it wrong
  10. 10 Sources

At a glance

  • Stop scoring eTMF systems on a feature grid. Score them on the duties an inspector actually opens: TMF completeness, contemporaneous (timely) filing, audit-trail integrity, and end-of-trial archiving.
  • A vendor “GCP compliant” or “Part 11 compliant” badge is a claim, not proof. Under ICH E6(R3), accountability for the conduct of the trial and the integrity of trial data stays with the sponsor even when work is delegated to a service provider.
  • 21 CFR Part 11 §11.10 names the specific control set your system must enforce: validation, copies for inspection, retention, access limits, secure time-stamped audit trails, operational and authority checks.
  • EMA expects the TMF, including the eTMF audit trail, to be archived so it remains complete, legible, and directly accessible for at least 25 years after the end of the trial, with read-only access preserved.
  • Validation (CSV/CSA) is the sponsor’s documented job. The fact that a vendor validated its own product does not discharge your obligation to validate the system for its intended use in your trial.
  • Use the scorecard, Part 11 checklist, and RFP question set below to make eTMF selection a defensibility decision your QA function can stand behind at inspection.

The SERP for “best eTMF systems” is saturated with vendor-authored listicles that rank platforms by brand and feature count. That is the wrong instrument. An inspector does not audit your feature grid. They audit whether your essential records are present, filed on time, traceable, and retrievable, and whether the system holding them is validated and controlled. This guide reframes eTMF selection as a GCP-defensibility decision and gives you the criteria to evaluate candidates against the duties that ICH E6(R3), 21 CFR Part 11, and EMA’s TMF archiving guidance actually impose.

eTMF vs paper TMF vs document management system: what the system actually has to do under GCP

An electronic trial master file is not “a folder in the cloud” and it is not a generic document management system (DMS) with clinical labels. ICH E6(R3) Appendix C frames the TMF as the repository of essential records that “permit and contribute to the evaluation of the conduct of a trial” and that are used during inspections to assess trial conduct and the reliability of results. The eTMF is the system that has to make those records identifiable, version-controlled, searchable, and retrievable.

That distinction matters because a DMS optimizes for collaboration and storage, while an eTMF must satisfy regulatory record-keeping duties. ICH E6(R3) §C.2.4 requires that the storage system used during the trial and for archiving provide for appropriate identification, version history, and search and retrieval of trial records. A consumer-grade file store can hold documents; it cannot necessarily demonstrate, on demand, the version history and traceability an inspector expects. When you evaluate a candidate, the first question is not “how does it look” but “can it discharge the Appendix C record-management duties.”

Two of those duties dominate inspection findings: completeness and contemporaneity. ICH E6(R3) §C.2.5 requires that the sponsor and investigator ensure essential records are collected and filed in a timely manner, and §C.2.6 requires that records remain complete, readable, and readily available, directly accessible upon request by regulatory authorities, monitors, and auditors. Late and missing essential documents are among the most common TMF findings in practice, so a system that makes timely filing easy to enforce and easy to evidence is worth more than one with a longer feature list.

The sponsor still owns the TMF: why “is the vendor compliant” is the wrong question

This is the stance the rest of the framework rests on. ICH E6(R3) §10.2 states that where activities have been transferred or delegated to service providers, the responsibility for the conduct of the trial, including the quality and integrity of the trial data, resides with the sponsor. That accountability is non-delegable. You can outsource the operation of the eTMF; you cannot outsource the consequence of it failing at inspection.

So a vendor’s “GCP compliant” badge does not transfer risk to the vendor. It cannot, because the regulation does not let it. A badge is a marketing claim about the product’s design. Your obligation is to verify that the system, configured and used in your trial, meets the requirements, and to document that verification. EMA’s TMF guidance reinforces the point on the records side: even where a CRO holds parts of the TMF, the arrangement should ensure the sponsor retains the full set of documents and makes it readily available and accessible for inspections.

Practically, treat every compliance badge as a hypothesis you test in the RFP and during validation, not a box you tick on a vendor slide. The question is never “is the vendor compliant,” it is “can I demonstrate that this system, as I use it, supports my compliance obligations, and where is that evidence.”

The GCP-defensibility scorecard: completeness, contemporaneity, traceability

Score candidates on what an inspector tests, not on what a sales deck emphasizes. The criteria below map directly to corpus duties.

CriterionWhat good looks likeGrounding duty
CompletenessStructured content list / expected-document model so missing essential records surface as gaps, not silencesICH E6(R3) §C.3.1 (a structured content list may prospectively identify essential records)
ContemporaneityTimeliness tracking and reporting that evidences filing “in a timely manner”ICH E6(R3) §C.2.5
Identification & version historyRecords identifiable, version-controlled, with authors/reviewers/approvers and datesICH E6(R3) §C.2.1, §C.2.4
Audit-trail integritySecure, computer-generated, time-stamped trail of create/modify/delete that does not obscure prior entries21 CFR Part 11 §11.10(e); ICH E6(R3) audit-trail definition
Access controlSystem access limited to authorized individuals with role-based permissions21 CFR Part 11 §11.10(d), (g)
Copies for inspectionGenerate accurate, complete copies in human-readable and electronic form for agency review21 CFR Part 11 §11.10(b)
Archiving & retentionPreserves completeness, legibility, and direct accessibility through the full retention periodEMA TMF guidance (§6)
Validation evidenceSystem validated for intended use; documentation available to youICH E6(R3) §C.3.1(h); 21 CFR Part 11 §11.10(a)
Exit / exportRecords and metadata retrievable as usable datasets if you leave the vendorEMA TMF guidance (eTMF metadata, §5)

The scorecard is deliberately weighted toward control and retrievability rather than convenience. A platform that aces collaboration but cannot evidence contemporaneous filing or produce inspection copies fails where it counts.

21 CFR Part 11 controls your eTMF must enforce

For records the system holds that are required by FDA-regulated trials, 21 CFR Part 11 §11.10 sets out the controls for closed systems. These are requirements on the records and the system, and they translate into a concrete checklist you can put into an RFP:

  • Validation. 21 CFR Part 11 §11.10(a) requires validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records.
  • Copies for inspection. §11.10(b) requires the ability to generate accurate and complete copies of records in both human-readable and electronic form suitable for inspection, review, and copying by the agency.
  • Retention and retrieval. §11.10(c) requires protection of records to enable their accurate and ready retrieval throughout the retention period.
  • Access control. §11.10(d) requires limiting system access to authorized individuals.
  • Audit trail. §11.10(e) requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions that create, modify, or delete records, and the regulation specifies that record changes shall not obscure previously recorded information.
  • Operational system checks. §11.10(f) requires operational system checks to enforce permitted sequencing of steps and events, as appropriate.
  • Authority checks. §11.10(g) requires authority checks so that only authorized individuals can use the system, sign a record, alter a record, or perform the operation at hand.

Electronic signatures carry their own controls. 21 CFR Part 11 §11.70 requires that electronic signatures be linked to their records so they cannot be excised, copied, or transferred to falsify a record. 21 CFR Part 11 §11.100(a) requires that each electronic signature be unique to one individual and not be reused or reassigned. When a vendor claims “Part 11 e-signatures,” the verifiable question is whether the implementation enforces uniqueness, identity verification, and signature/record linking, not whether the word “Part 11” appears in the datasheet.

EMA TMF expectations: archiving, retention, and audit-trail integrity

EMA’s TMF guidance is explicit on the back end of the lifecycle, where vendor listicles go quiet. Under Article 58 of the Regulation, as restated in the guidance, unless other Union law requires longer, the sponsor and investigator shall archive the content of the clinical TMF for at least 25 years after the end of the clinical trial. Your eTMF decision is therefore a 25-year decision, not a study-duration decision. Ask how the system, or the archived export from it, will remain readable and accessible for that horizon.

The guidance also sets eTMF control expectations during the trial: the primary eTMF should contain user accounts, secure passwords, a mechanism for locking or protecting individual documents or the entire eTMF, an audit trail capturing date, time, and user details for creation, uploading, deletion, and changes to a document, and role-based permissions including restricted access to sensitive files. For archiving, EMA expects that the TMF including the eTMF audit trail be archived so the trial data and metadata can be retrieved as usable datasets, and that the dynamic character of the audit trail be preserved where applicable. After the trial, the guidance describes granting read-only access to an archived eTMF in a suitably restricted area, with an audit trail recording that access.

Where ICH and EMA align, say so plainly: both require that records remain complete, legible, and readily/directly accessible, ICH E6(R3) §C.2.6 for the trial period and EMA for the archiving period. They are not in tension here; they are two regulators describing the same record-keeping spine, and a defensible eTMF satisfies both at once.

Validation is your job, not the badge: CSV/CSA, vendor audit, and the qualification you must document

A vendor validating its own software is necessary but not sufficient. ICH E6(R3) §C.3.1(h) treats documentation that a trial-specific computerised system is validated, and that non-trial-specific systems are assessed as fit for purpose, as an essential record in its own right. In other words, the regulation expects your validation evidence to live in the TMF. If you cannot produce it, the gap is yours, not the vendor’s.

This is where computer system validation (CSV) or the risk-based computer software assurance (CSA) approach earns its place. Build your validation around intended use in your trial: define requirements and specifications, test the critical functionality, and retain the documentation. A vendor audit and the vendor’s own validation package feed your assessment, but the documented qualification of the system for your use is the artifact an inspector asks to see. Treat “the vendor is validated” the same way you treat “the vendor is compliant”: a useful input, never the conclusion.

The eTMF RFP: questions that separate inspection-ready systems from feature lists

Lift these into procurement. Each is written so a “yes” must be evidenced, not asserted.

  • Completeness: Does the system support a structured expected-document model so missing essential records surface as gaps? Show us the gap report.
  • Contemporaneity: How does the system track and report filing timeliness against expected milestones? Show us the metric an inspector would see.
  • Audit trail: Is the audit trail secure, computer-generated, and time-stamped, and does it prevent changes from obscuring prior entries? Provide a sample export.
  • Access and authority: How are access and signing rights limited to authorized individuals and enforced by role? Provide your permissions model.
  • Copies for inspection: Can the system produce accurate, complete, human-readable and electronic copies for agency review on demand? Demonstrate it.
  • E-signatures: How is each signature kept unique to one individual, identity-verified, and linked to its record so it cannot be transferred?
  • Validation: What validation documentation will you provide, and what remains our responsibility to validate for intended use?
  • Archiving and retention: How will the eTMF, including the audit trail, remain complete, legible, and accessible, and exportable as usable datasets, for at least 25 years after end of trial?
  • Exit: On contract termination, in what format do we receive records and metadata, and how is read-only archival access preserved?

On pricing, keep the thesis: do not let cost questions displace control questions. Pricing typically scales with study volume, document volume, user seats, and storage or archival duration, and a longer mandatory retention horizon is itself a cost driver. A cheaper system that cannot evidence contemporaneity or produce inspection copies is not cheaper; it is a deferred finding.

Where teams get it wrong

Three failure patterns recur. First, buying the badge: teams treat “Part 11 compliant” on a vendor page as the end of the inquiry, when ICH E6(R3) §10.2 leaves the integrity of the data, and therefore the inspection risk, with the sponsor regardless of what the badge says. Second, skipping validation: teams accept the vendor’s self-validation and never produce their own intended-use validation evidence, which ICH E6(R3) §C.3.1(h) expects to be in the TMF. Third, ignoring the exit: teams sign without an export and read-only archival plan, then discover at the 25-year horizon that the audit trail and metadata EMA expects to remain retrievable are trapped in a system they no longer license.

The through-line is the same. The eTMF is a system for discharging non-delegable sponsor duties. Choose it the way an inspector will read it: by whether the records are complete, timely, traceable, retrievable, and archived, and by whether you can prove it. Sibling guidance on TMF completeness and essential documents, on Part 11 and computer system validation, and on inspection readiness goes deeper on each leg of this framework.

A final caution on language. No system “makes you compliant.” A well-controlled, validated eTMF enables you to meet your obligations and to evidence that you did. The accountability stays with the sponsor. The right system simply makes that accountability defensible.

Sources

  • ICH E6(R3) Good Clinical Practice (ICH, version r3) — https://www.ich.org/page/efficacy-guidelines
  • 21 CFR Part 11 Electronic Records; Electronic Signatures (FDA, version 2026-04)
  • EMA Guideline on content management and archiving of the clinical trial master file (EMA, version 2018)
A

Written by

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.