CTMS vs eTMF: Which System Is the System of Record (and Why GCP Findings Live on That Boundary)
A CTMS is where the team runs the trial: site activation dates, subject accrual, monitoring visit scheduling, milestone tracking. An eTMF is where the team proves the trial was run: the essential documents that, in the words of the EMA TMF guideline, individually and collectively permit evaluation of the conduct of a trial and the quality of the data produced.
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
On this page · 10 sections
- 01 At a glance
- 02 CTMS vs eTMF in one line: operational truth versus regulatory evidence
- 03 The three-system map: what each is the system of record for
- 04 Side-by-side: what each system actually proves
- 05 The overlap trap: facts that live in both, and which one is authoritative
- 06 Where GCP findings actually come from
- 07 Integration: what to sync, what to keep one-directional, what not to duplicate
- 08 Decision guide: one, the other, or both
- 09 GCP failure-mode checklist
- 10 Sources
At a glance
- The useful question is not “what’s the difference” but “which system is the system of record for this specific fact.” A CTMS tracks operational truth (sites, milestones, monitoring); an eTMF holds the inspection-ready essential records; an EDC captures subject-level clinical data.
- A “green” CTMS milestone is operational status, not evidence. Under the EMA TMF guideline, the TMF must at all times contain the essential documents that let an inspector reconstruct the trial, and a tracker showing a task as “done” does not file the document that proves it.
- When the same fact lives in two systems, only one holds the authoritative record. The EMA TMF guideline is explicit: when a static report is generated from CTMS data and uploaded to the TMF, the original dynamic file must be retained in the original system.
- Both systems are computerised systems under ICH E6(R3) and the EMA computerised-systems guideline: each needs validation proportionate to risk, and each needs its own audit trail stored within the system.
- Most boundary failures are self-auditable: duplicated uncontrolled copies, CTMS status mistaken for TMF completeness, and untimely or missing filing. Use the checklist at the end.
- Software enables compliance; it never confers it. The sponsor and investigator/institution remain responsible for completeness, integrity, and timely filing regardless of which tools they buy.
CTMS vs eTMF in one line: operational truth versus regulatory evidence
A CTMS is where the team runs the trial: site activation dates, subject accrual, monitoring visit scheduling, milestone tracking. An eTMF is where the team proves the trial was run: the essential documents that, in the words of the EMA TMF guideline, individually and collectively permit evaluation of the conduct of a trial and the quality of the data produced.
That distinction is not cosmetic. ICH E6(R3) §3.6 requires that essential records be retained securely and be available to regulatory authorities, monitors, auditors and IRBs/IECs upon request so they can evaluate trial conduct and the reliability of results. The CTMS helps you manage; the eTMF is what gets inspected. Confusing the two is the single most common way teams that feel “on top of” their trial discover, at inspection, that their TMF is incomplete.
The three-system map: what each is the system of record for
Before comparing features, fix the boundary. Three systems carry three different kinds of truth, and EDC belongs on the map because teams routinely mislocate clinical data.
| CTMS | eTMF | EDC | |
|---|---|---|---|
| Purpose | Operational management of the trial | Storage of essential records | Capture of subject-level clinical data |
| System of record for | Sites, milestones, monitoring visit scheduling, operational status | Essential documents that prove trial conduct | Source/CRF clinical data points and their audit trail |
| Primary user | Clinical operations, CRAs | TMF/QA, document managers | Site staff, data management |
| What it proves to an inspector | Little on its own; it is a management aid | That the trial was conducted and documented per protocol and GCP | That the reported clinical observations are attributable and reliable |
| Audit-trail requirement | Audit trail for its electronic records, stored in the system | Version control, certified copies, controlled access | Audit trail enabled for original creation and every modification |
The EMA computerised-systems guideline applies its general principles to all computerised systems used in a clinical trial, so none of these three sits outside GCP. But they are the system of record for different things, and that is the line teams blur.
Side-by-side: what each system actually proves
The eTMF is the evidence locker. The EMA TMF guideline states that the clinical trial master file shall at all times contain the essential documents relating to that clinical trial, and that TMF documentation should be sufficient to adequately reconstruct the activities undertaken in conducting the trial, along with the decisions and justifications made. “At all times” and “reconstruct” are the operative words: completeness is a continuous obligation, not an end-of-study cleanup.
The CTMS, by contrast, is a planning and oversight aid. It can tell you a monitoring visit was scheduled and marked complete. It does not, by existing, file the monitoring visit report. That report becomes essential evidence only when it lands in the TMF as a controlled record.
The EDC sits underneath both. Source records, per ICH E6(R3) §3.3, should be attributable, legible, contemporaneous, original, accurate and complete, the ALCOA principles the EMA computerised-systems guideline extends to ALCOA++. The EDC is the system of record for the clinical data point, not for operational tracking and not for essential-document evidence.
The overlap trap: facts that live in both, and which one is authoritative
The hard cases are facts that legitimately appear in two systems. Here the rule is not “pick a favourite tool” but “name the authoritative copy and protect it.”
The EMA TMF guideline gives the governing example directly: monitoring visit reports generated from CTMS datasets, or shipping reports generated from IRT datasets, might be uploaded to the primary TMF system, but if so, the original dynamic file should be retained in the original system. The static PDF in the eTMF is the filed evidence; the live record in the CTMS remains the source. You do not get to delete the dynamic original because you printed a copy.
That principle generalises through the certified-copy rule. The EMA TMF guideline requires that any copy in the eTMF that irreversibly replaces an original be a certified copy: verified by a dated signature or generated through a validated process to produce an exact copy preserving content, context and structure, including metadata. A plain scan or print that does not meet those criteria is not suitable to replace an original. So when a document exists in both places, you must know which instance is the authoritative original and whether the other is a certified copy or merely a convenience copy.
| Data point | Authoritative system | What to avoid |
|---|---|---|
| Monitoring visit report generated from CTMS | CTMS holds the dynamic original; eTMF holds the certified static copy | Deleting the CTMS dynamic file once the PDF is uploaded |
| Site activation / milestone date | CTMS for operational tracking; the underlying signed document in the eTMF | Treating the CTMS date field as the essential-document evidence |
| Signed delegation log / Form FDA 1572 | Wet-ink original at the investigator/institution; certified copy in eTMF | Storing only a CTMS status flag and no filed signed document |
| Subject-level clinical data | EDC (with its audit trail) | Re-keying values into a CTMS or TMF note as if authoritative |
The EMA computerised-systems guideline reinforces why this matters: the location of source documents and the associated source data they contain should be clearly identified at all points within the data capture process, and the location of all source data should be specified before the trial starts and updated as it changes. If you cannot say which system holds the authoritative copy of a given fact, you have a data-governance gap, not a tooling preference.
Where GCP findings actually come from
Three boundary failures account for most of the inspection pain.
First, CTMS status mistaken for TMF completeness. A milestone marked complete is operational reassurance, not filed evidence. Because the EMA TMF guideline requires the TMF to contain the essential documents at all times and to support full reconstruction, a “green” tracker with the corresponding document missing from the TMF is an incomplete TMF, full stop. The guideline expects sponsors and investigators/institutions to run risk-based QC checks to ensure the TMF is kept up to date and that all essential documents are appropriately filed; a CTMS dashboard is not that QC check.
Second, duplicate and uncontrolled copies. The EMA TMF guideline explicitly says unnecessary duplication of documentation in the TMF should be avoided, and that documents applicable to multiple trials do not need to be duplicated across several TMFs. Duplication is not just clutter: two copies invite version drift, and version drift breaks reconstruction.
Third, untimely or missing filing. Because the obligation is continuous, documents that exist somewhere in the operational flow but never reach the TMF, or reach it late, are findings waiting to happen. The CTMS may show the activity occurred; the TMF must hold the evidence.
Integration: what to sync, what to keep one-directional, what not to duplicate
Integration helps, but only if it respects the system-of-record boundary rather than dissolving it.
Sync metadata and status one-directionally where it reduces manual re-keying: let the CTMS surface whether an expected document has been filed, without making the CTMS the holder of that document. Keep authoritative records in one place. The EMA computerised-systems guideline requires that the process of data transfer between systems be validated to ensure the data remain accurate, including associated metadata and audit trail, and may require preserving the original context. ICH E6(R3) §3.4 makes the same demand: validated or otherwise appropriate processes such as reconciliation should ensure that electronic data, including relevant metadata, transferred between computerised systems retains its integrity. An unvalidated CTMS-to-eTMF push is itself a finding.
Do not duplicate the authoritative copy. Following the EMA TMF guideline’s dynamic-file rule, a generated report can be filed in the eTMF while its live source stays in the originating system; that is one authoritative original plus one certified copy, not two competing records.
Decision guide: one, the other, or both
You almost always need both, plus an EDC, but for different reasons. A sponsor or CRO running multi-site trials needs the CTMS to manage operations and the eTMF to hold inspection-ready evidence; the eTMF is non-negotiable because the essential-records obligation under ICH E6(R3) §3.6 and the EMA TMF guideline attaches to the documents, not to whether you happen to use a tracker. A site (investigator/institution) must control its own essential records: ICH E6(R3) §2.10 requires the investigator/institution to have control of all essential records it generates, which is why uploading the only copy of investigator-generated documents into a sponsor-controlled eTMF, with no independent investigator copy, is itself a risk the EMA TMF guideline flags.
No CTMS replaces an eTMF, and no eTMF replaces a CTMS. One tracks the trial; the other proves it. Buying either does not make you compliant; it gives you a place to do the work that the sponsor and investigator remain accountable for.
GCP failure-mode checklist
Self-audit against these. A “no” is a boundary problem.
- Can you name, for every fact that appears in two systems, which system holds the authoritative copy?
- Does every CTMS-generated report filed in the eTMF retain its dynamic original in the source system?
- Are eTMF copies that replace originals certified (validated process or dated verification), not plain scans?
- Is TMF completeness checked by a risk-based QC process, not inferred from CTMS milestone status?
- Is the location of all source data specified before the trial and updated as it changes?
- Is every cross-system transfer (CTMS to eTMF, EDC out) covered by a validated or reconciled process that preserves metadata and audit trail?
- Does each system have its own audit trail, stored within the system, for creation and modification of its records?
For deeper treatment of the adjacent questions, see our sibling pieces on TMF completeness and the essential-documents list, and on computerised-system validation.
Sources
- ICH E6(R3) Good Clinical Practice, version r3 (ICH) — https://www.ich.org/page/efficacy-guidelines
- EMA Guideline on the content, management and archiving of the clinical trial master file (paper and/or electronic), version 2018 (EMA/INS/GCP/856758/2018)
- EMA Guideline on computerised systems and electronic data in clinical trials, version 2023 (EMA/INS/GCP/112288/2023) — https://www.ema.europa.eu/en/documents/regulatory-procedural-guideline/guideline-computerised-systems-and-electronic-data-clinical-trials_en.pdf
Written by
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
Continue reading
Choosing an eTMF System That Survives a GCP Inspection: A Sponsor's Defensibility Framework
The SERP for "best eTMF systems" is saturated with vendor-authored listicles that rank platforms by brand and feature count. That is the wrong instrument. An inspector does not audit your feature grid. They audit whether your essential records are present, filed on time, traceable, and retrievable, ...
ReadScreen Failure in Clinical Trials: How to Calculate the Rate, Document It Under GCP, and Read It as a Critical-to-Quality Signal
A high screen-failure rate gets framed as a recruitment cost to "reduce." That framing misses the two things an inspector actually cares about: whether every screened subject is documented, and whether consent preceded every procedure. This guide defines the term honestly, gives you a rate formula y...
ReadThere Is No FDA IND Database: What You Can Actually Look Up, and How the Form-1571 IND Clock Really Works
If you searched for an "FDA IND database," you were probably expecting something like ClinicalTrials.gov: a public registry where you type a drug or a company and pull up the application. That database does not exist, and it does not exist for a specific, deliberate regulatory reason. This guide doe...
Read