GCP · Blog
Back to journal

SAE Reconciliation: A Field-Level Discrepancy-Resolution Workflow That Closes Before Lock and Never Lags the SUSAR Clock

Most published SAE reconciliation guidance stops at four verbs: extract, compare, resolve, document. That is the table of contents, not the work. The work is deciding which fields must agree, how close is close enough, who fixes each kind of mismatch, and how often you do it so that nothing surfaces too late to report. This guide reframes reconciliation as that operational workflow, written for the clinical data managers (CDMs) and drug-safety associates running it on an active study, plus the medical monitor signing off on closures.

GCP 10 min read
A

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.

On this page · 9 sections
  1. 01 At a glance
  2. 02 What SAE reconciliation actually verifies
  3. 03 Why the two databases diverge, and what that drift hides
  4. 04 The reconcilable fields: a decision table
  5. 05 Discrepancy classes and ownership
  6. 06 Cadence: ongoing, milestone, and pre-lock, against the reporting clock
  7. 07 Where teams get it wrong
  8. 08 Building the SAE reconciliation plan/SOP
  9. 09 Sources

At a glance

  • SAE reconciliation is not “compare two databases.” It is a field-level discrepancy-resolution workflow: defined reconcilable fields, explicit match tolerances, named owners per discrepancy class, and a cadence that closes before database lock without ever lagging the expedited reporting clock.
  • The clinical/EDC database and the safety/pharmacovigilance (PV) database diverge by design (different entry paths, timing, and coding), so a non-empty discrepancy list is the normal state, not a failure.
  • A “clean” reconciliation can still hide an unreported SUSAR. Reconciliation confirms two systems agree; it does not confirm the expedited clock was met. Those are separate obligations.
  • Ownership matters: investigators and CDM own clinical-source fields, PV owns the safety case and causality assessment, and the medical monitor adjudicates clinical-judgment conflicts. Map each field to an owner before the first reconciliation run.
  • Tie cadence to the calendar that actually binds you: under 21 CFR 312.32, fatal or life-threatening unexpected suspected adverse reactions go to FDA within 7 calendar days and other serious, unexpected suspected adverse reactions within 15 calendar days. Reconciliation runs around that clock, not the other way around.

Most published SAE reconciliation guidance stops at four verbs: extract, compare, resolve, document. That is the table of contents, not the work. The work is deciding which fields must agree, how close is close enough, who fixes each kind of mismatch, and how often you do it so that nothing surfaces too late to report. This guide reframes reconciliation as that operational workflow, written for the clinical data managers (CDMs) and drug-safety associates running it on an active study, plus the medical monitor signing off on closures.

What SAE reconciliation actually verifies

SAE reconciliation verifies that the same serious event is represented consistently across the EDC clinical database and the safety/PV database. It is a consistency check across two independent records of one event, not a re-entry or a re-coding exercise.

Both systems are recording the same underlying reality, and both are governed by the same data-integrity expectations. ICH E6(R3) §2.12.2 requires that source records be attributable, legible, contemporaneous, original, accurate and complete, and that changes be traceable through an audit trail. That ALCOA-C standard is what reconciliation operationalizes downstream: if the EDC and PV records of one SAE disagree, at least one of them is not yet accurate or complete, and the discrepancy points you at which.

It helps to anchor scope on shared definitions. ICH E6(R3) defines a Serious Adverse Event as any unfavourable medical occurrence that results in death, is life-threatening, requires inpatient hospitalisation or prolongation of existing hospitalisation, results in persistent or significant disability/incapacity, or is a congenital anomaly/birth defect. ICH E2A states the same five seriousness outcomes. Reconciliation lives entirely inside that boundary: serious cases. Non-serious adverse events are out of scope for SAE reconciliation, and blurring AE and SAE scope is one of the fastest ways to inflate the discrepancy log with noise.

Why the two databases diverge, and what that drift hides

Divergence is structural, not accidental. The investigator reports SAEs immediately to the sponsor along the clinical path; ICH E6(R3) §2.7.2(b) requires that all SAEs be reported immediately to the sponsor once the investigator becomes aware, with an investigator causality assessment attached. The same event also enters the safety database through the PV intake path on its own timeline. Two intake paths, two clocks, two coding moments: drift follows.

Common, expected sources of drift:

  • Timing lag. The SAE reaches one system before the other; a snapshot taken mid-flight shows a mismatch that is really just sequencing.
  • Source and entry differences. The clinical record is keyed from the CRF; the safety case is built from the SAE report form. Free-text wording, dates, and outcome fields are entered by different people from different artifacts.
  • Coding moment. MedDRA coding happens at different times and sometimes by different conventions, so the verbatim term agrees while the coded term does not (yet).
  • Query lag. An open EDC query has not resolved, so the clinical value is provisional while the safety value is already updated, or vice versa.

What the drift can hide is the point of the whole exercise: a serious event that is sitting in the clinical database but has not been assessed for expedited reporting, or whose causality or expectedness was read differently on the two sides. That is why reconciliation is a safety-reporting control, not just a data-cleaning chore.

The reconcilable fields: a decision table

Reconcile fields, not records. For each field, decide up front whether it demands an exact match or tolerates bounded variance, name the likely cause of a mismatch, and assign an owner. The table below is a defensible starting set; tailor it in your plan.

FieldMatch standardLikely cause of mismatchPrimary owner
Subject/site identifiersExactTranscription errorCDM
SAE verbatim termExact (text)Different source artifact wordingCDM + PV
MedDRA coded term (PT/LLT)Exact codeCoding at different times/conventionsPV (coding)
Onset dateExactDate drift between CRF and SAE formCDM
Seriousness criterion (the qualifying outcome)Exact categoryOutcome update landed in one system onlyPV + medical monitor
Outcome (recovered, fatal, ongoing)Exact, latest valueFollow-up updated one system onlyCDM + PV
Investigator causalityExact categoryAssessment wording differs investigator vs. PVMedical monitor
Expectedness vs. RSIExact categoryRSI reference applied differentlyPV
Action taken / treatmentTolerance (semantic)Free-text granularity differsPV

Two of these rows carry most of the regulatory weight. Seriousness must agree because it is the gate to the entire reporting obligation: ICH E2A defines serious by the five outcomes above, and under 21 CFR 312.32(a) an event is serious if, in the view of either the investigator or sponsor, it meets those outcomes, so if either party calls it serious it is serious. Causality and expectedness must agree because together they determine whether the case is a SUSAR. ICH E6(R3) §3.13.2(b) requires the sponsor to expedite reporting, in accordance with ICH E2A, of all suspected, unexpected, and serious adverse reactions. A reconciliation that leaves seriousness, causality, or expectedness in disagreement is leaving the reportability decision unresolved.

Discrepancy classes and ownership

Every discrepancy belongs to someone before it can be closed. Resolving a coding mismatch is PV’s call; resolving an onset-date conflict is a clinical-source question for CDM and the site; resolving a causality disagreement is a medical-judgment question that belongs to the medical monitor. The audit trail must show who decided and why, consistent with ICH E6(R3) §4.2.4, which requires that data corrections be attributed to the person or system making them, justified, and supported by source records around the time of original entry.

Discrepancy classResolves withOwner
Identifier / date / outcome data errorCorrect against source recordCDM (with site)
MedDRA coding mismatchRe-code or confirm conventionPV / coding
Causality wording conflictAdjudicate clinical judgmentMedical monitor
Seriousness criterion conflictConfirm qualifying outcomePV + medical monitor
Expectedness vs. RSIApply reference safety informationPV

The recurring trap here is reading a causality or coding mismatch as a “data error” and pushing it to CDM to “fix.” It is not a data error; it is a difference in medical or coding judgment, and forcing it into the data-correction lane produces a closure that papers over a genuine disagreement.

Cadence: ongoing, milestone, and pre-lock, against the reporting clock

Cadence has two jobs: keep the discrepancy backlog closable before database lock, and ensure reconciliation never becomes the reason a reportable case surfaces late. Database lock is a deadline, but it is not the binding one. The binding one is the expedited reporting clock.

The clock is explicit. Under 21 CFR 312.32(c), the sponsor must notify FDA and all participating investigators of any serious and unexpected suspected adverse reaction no later than 15 calendar days after determining it qualifies for reporting. For an unexpected fatal or life-threatening suspected adverse reaction, the requirement tightens to no later than 7 calendar days after the sponsor’s initial receipt of the information. ICH E2A sets the same standard: serious, unexpected reactions that are not fatal or life-threatening are filed no later than 15 calendar days after first knowledge, and fatal or life-threatening unexpected ADRs as soon as possible but no later than 7 calendar days, followed by a complete report within 8 additional calendar days. These two in-scope sources align rather than conflict, which is worth stating plainly: the 7/15-day structure is consistent across ICH E2A and 21 CFR 312.32.

Because that clock starts on the sponsor’s determination or receipt, reconciliation cannot be the gate that triggers a reporting assessment. If a serious case appears in the clinical database, the reportability evaluation runs on its own immediately; reconciliation then confirms the two systems agree. A sensible cadence:

  • Ongoing. Reconcile new and updated SAEs on a rolling basis (for example, monthly, or event-driven for high-enrolling or high-event studies) so discrepancies never accumulate.
  • Milestone. Reconcile at protocol milestones and before interim analyses, so any data feeding an analysis is consistent.
  • Pre-lock. Run a final, full reconciliation with documented closure as part of finalising data sets. ICH E6(R3) §4.2.6(b) names reconciliation of relevant databases among the activities undertaken to finalise data sets prior to analysis, and §4.2.5 calls for reconciliation as part of validated data transfer between computerised systems. Pre-lock reconciliation is where this becomes auditable: ICH E6(R3) lists SAE reconciliation among the essential records expected for the trial.

Where teams get it wrong

A clean reconciliation that still missed a SUSAR. The classic failure: the EDC and PV records agree perfectly, the reconciliation report shows zero open discrepancies, and the case was still never reported on time. Reconciliation checks consistency between two systems; it does not check that the expedited clock under 21 CFR 312.32 and ICH E2A was respected. If both systems agree on a serious, unexpected, causally-related case that nobody expedited, reconciliation will happily call it “clean.” Treat agreement and timeliness as two separate confirmations, and have the case meet both.

Causality wording read as a data error. Investigator and PV causality language often differs (“possibly related” vs. “cannot be ruled out”). ICH E2A notes that many causality terms are in use and that a case qualifies as an ADR when either the reporting health professional or the sponsor judges a reasonable suspected causal relationship. So a wording difference is not automatically a discrepancy to “correct,” and where it changes the reportability conclusion it belongs to the medical monitor, not the data-correction queue.

AE-vs-SAE scope creep. Pulling non-serious AEs into SAE reconciliation inflates the log and buries the cases that carry reporting consequences. Hold the line on the seriousness definition.

Coding mismatches read as data errors. A verbatim term that matches while the coded MedDRA term differs is usually a coding convention or timing issue for PV, not a transcription error for the site.

Building the SAE reconciliation plan/SOP

Put the decisions above in writing before the first run. A defensible plan/SOP covers:

  • Scope. Serious events only; state explicitly that non-serious AEs are out of scope and name any protocol-defined SAEs (for example, endpoint events) handled differently.
  • Fields and tolerances. The reconcilable-fields table, with each field marked exact-match or tolerance and a stated rationale.
  • Roles. The discrepancy-ownership matrix, naming CDM, PV, and medical-monitor responsibilities, consistent with the attribution requirement in ICH E6(R3) §4.2.4.
  • Frequency. Ongoing, milestone, and pre-lock cadence, with the explicit statement that reconciliation never gates the 7/15-day expedited assessment.
  • Discrepancy log. A standing log with class, owner, status, and resolution, kept as an essential record.
  • Closure criteria. What “closed” means per class (corrected against source, re-coded, adjudicated), and the pre-lock condition that every discrepancy is either resolved or documented with justification.

Quick SOP checklist:

  • Scope fixed to serious events; AE/SAE boundary stated.
  • Reconcilable-fields table with match standard per field.
  • Ownership matrix mapping each discrepancy class to CDM / PV / medical monitor.
  • Cadence defined (ongoing + milestone + pre-lock) and decoupled from the reporting clock.
  • Discrepancy log template with class, owner, status, resolution.
  • Closure criteria per class, including pre-lock “resolved or justified.”
  • Audit-trail expectation: every correction attributed, justified, source-supported.
  • Cross-check step confirming every reconciled SUSAR also met its 7/15-day clock.

Related topics in this collection cover SAE/SUSAR expedited reporting timelines, adverse event coding with MedDRA, database lock readiness, and source data verification, and they sit alongside the broader clinical safety reporting and pharmacovigilance pillar. Use them to go deeper on the pieces this workflow depends on.

A word on scope and stance: reconciliation enables compliant safety reporting; it does not by itself make a study compliant. The sponsor remains responsible for the underlying reporting obligations under ICH E6(R3), ICH E2A, and 21 CFR 312.32. Reconciliation is the control that makes those obligations verifiable, which is exactly why it deserves a field-level plan rather than a four-verb summary.

Sources

A

Written by

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.