Source Documents in Clinical Trials: The ALCOA+ Evidence Layer, Certified Copies, and Risk-Based SDV
Most teams can recite a definition of "source document" and reel off examples. Where findings land is one level down: whether a particular record actually qualifies as a defensible source, whether a scan or printout is a legitimate substitute for the original, and how much source data verification (SDV) is enough. This guide reframes the source document not as a list to memorize but as an evidence layer defined by the attributes it must satisfy, and it locates the two judgment calls (certified copies and SDV targeting) that inspectors actually pull threads on.
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
On this page · 11 sections
- 01 At a glance
- 02 Source document vs source data vs CRF: the distinction everyone blurs
- 03 The real definition: reconstruction is the test
- 04 ALCOA+ as the attribute checklist a source record must pass
- 05 Certified copies and originals: when a scan or printout can replace the source
- 06 eSource and EHR-as-source: where the “original” now lives
- 07 Source Document Verification vs Source Data Review: what each catches
- 08 Risk-based / targeted SDV: why 100% SDV is the wrong default
- 09 Anatomy of a source document template / worksheet
- 10 Where teams get it wrong
- 11 Sources
At a glance
- A source document is not a category you memorize from a list (charts, lab reports, diaries). It is any record that passes a test: can an independent reviewer reconstruct and evaluate the trial from it?
- Source data and source documents are not the same thing. Under the FDA eSource guidance, source data are the clinical findings and observations; source documents are the original records (or certified copies) that contain them.
- A record earns “source” status by satisfying attributes: ICH E6(R3) requires source records to be attributable, legible, contemporaneous, original, accurate, and complete, with changes traceable through an audit trail.
- A certified copy can replace the original, but only when it has been verified to hold the same information as the original. Both ICH E6(R3) and FDA define this precisely.
- 100% source data verification is not the regulatory default. FDA’s risk-based monitoring guidance directs you to focus verification on critical data and processes, not to transcription-check every field.
- The investigator owns two decisions reviewers will probe: what counts as the source record for each data point, and (with the sponsor’s monitoring plan) how much SDV is enough.
Most teams can recite a definition of “source document” and reel off examples. Where findings land is one level down: whether a particular record actually qualifies as a defensible source, whether a scan or printout is a legitimate substitute for the original, and how much source data verification (SDV) is enough. This guide reframes the source document not as a list to memorize but as an evidence layer defined by the attributes it must satisfy, and it locates the two judgment calls (certified copies and SDV targeting) that inspectors actually pull threads on.
Source document vs source data vs CRF: the distinction everyone blurs
The single most common conceptual error is treating “source data” and “source document” as synonyms. The FDA eSource guidance separates them cleanly. Source data are all the information in original records and certified copies of clinical findings, observations, or other activities used for the reconstruction and evaluation of the trial; source documents are the original records (or certified copies) that contain that source data. In other words, the data are the content; the document is the container that carries the content and its context.
The case report form (CRF) is a third thing again. ICH E6(R3) defines the CRF as a data acquisition tool designed to record protocol-required information reported by the investigator to the sponsor. The CRF is a transcription or derivation destination, not the source. When a CRF field is filled by hand from a clinic note, the note is source and the CRF is downstream. The exception that trips people up is direct entry: where a data element is keyed straight into an electronic system as its first recording, that electronic record can itself be source. FDA’s eSource guidance treats data initially recorded in electronic format as electronic source data, and direct entry as the initial recording of data into an electronic record.
| Concept | What it is | Where it lives |
|---|---|---|
| Source data | The clinical findings/observations used to reconstruct and evaluate the trial | Inside source documents |
| Source document | The original record (or certified copy) that contains source data | Charts, lab reports, eCRF when directly entered, EHR |
| CRF / eCRF | A data acquisition tool for reporting protocol-required information to the sponsor | Usually downstream of source, unless directly entered |
The real definition: reconstruction is the test
Stop asking “is this on the list of source documents?” and start asking “could an independent party reconstruct the trial from this?” That reframing is not stylistic. The FDA eSource definition of source data is explicitly built around reconstruction and evaluation of the trial. A record qualifies as source to the degree that it carries the evidence a reviewer needs to retrace what happened.
ICH E6(R3) reinforces this by putting the boundary-drawing responsibility on the investigator. The guideline expects the investigator to define what is considered a source record, the methods of data capture, and their location before the trial starts, and to update that definition when needed. That is a deliverable, not a formality: when monitoring or inspection asks “what is your source for this CRF value?”, the answer should already be written down. ICH E6(R3) also frames source records broadly in its glossary, as original documents or data (including relevant metadata) or certified copies, irrespective of the media used.
ALCOA+ as the attribute checklist a source record must pass
ALCOA+ is the practical translation of “defensible source.” ICH E6(R3) states that source records should be attributable, legible, contemporaneous, original, accurate, and complete, and that changes to source records should be traceable, should not obscure the original entry, and should be explained where necessary via an audit trail. That single requirement supplies the core ALCOA attributes plus the traceability that the ”+” extends.
The attributes are most useful as a failure checklist. The point is not to recite them but to predict where a record will be challenged.
| Attribute | What it means for a source record | Common failure |
|---|---|---|
| Attributable | You can tell who recorded it and when | Unsigned entries, shared logins, no originator on an electronic field |
| Legible | A reviewer can actually read it now and later | Faded thermal printouts, illegible handwriting, no certified copy made |
| Contemporaneous | Recorded at the time of the observation | Entries written from memory days later |
| Original | The first capture, or a certified copy of it | Working from an uncertified photocopy as if it were source |
| Accurate | Reflects the observation; corrections are honest | Transcription errors carried into the CRF and never caught |
| Complete | Nothing material is missing | Missing source for a CRF data point, dropped pages |
| Traceable (+) | Changes are visible and explained | Overwritten values, corrections that obscure the original, no audit trail |
For electronic records, the audit trail is what makes traceability and reconstruction operational. FDA’s eSource guidance defines the audit trail as a process that captures additions, deletions, or alterations of information in an electronic record without obscuring the original record, and notes that the audit trail facilitates the reconstruction of the course of those changes. Note the alignment with ICH E6(R3): both demand that the original entry survive every correction.
Certified copies and originals: when a scan or printout can replace the source
A scan or printout is not automatically a valid substitute for the original. It becomes one only when it is a certified copy, and the regulations are specific about what that requires. ICH E6(R3) defines a certified copy as a copy (irrespective of media) of the original record that has been verified, by a dated signature or by generation through a validated process, to have the same information as the original, including relevant metadata where applicable. FDA’s eSource guidance is consistent: a certified copy is a copy of original information verified, as indicated by a dated signature, as an exact copy having all of the same attributes and information as the original.
The two definitions align on the essentials and are worth citing together because practitioners often apply only half the rule. Practical criteria a copy must meet to retire the original:
- The copy carries the same information as the original, including relevant metadata where it applies.
- The verification is explicit: a dated signature, or for ICH E6(R3), generation through a validated process.
- It is a true copy of the original record, irrespective of the media used.
If a printout fails any of these, it is a convenience copy, not a certified copy, and the original is still your source. This is exactly the gap auditors exploit when they find a binder of photocopies with no certification and no retained originals.
eSource and EHR-as-source: where the “original” now lives
When data are captured electronically, the “original” often does not live on paper at all. FDA’s eSource guidance is built on the idea that each data element in an eCRF has an authorized data originator: the person, computer system, device, or instrument authorized to enter, change, or transmit that element. Knowing the originator for every field is how you answer “what is the source for this value?” in an electronic study.
The eSource guidance also addresses the EHR, which it describes as an electronic record for healthcare providers, obtainable from multiple sources, shareable, and interoperable. When an EHR feeds the trial, it can be source, but it inherits the same attribute burden, and ICH E6(R3) adds an explicit fitness check: where systems used by the investigator (such as electronic health records or other record-keeping systems) contain source records, the sponsor should assess whether they are fit for purpose, and that assessment should occur during site selection and be documented. A clinical-care EHR is not automatically a qualified trial source until that assessment is done.
One eSource provision is frequently missed. To support accurate case histories, the clinical investigator should review and electronically sign the completed eCRF for each subject before the data are archived or submitted, and if changes are made after signature, those changes should be reviewed and electronically signed again. The signature is the investigator vouching for the record as source; it is not a clerical step.
Source Document Verification vs Source Data Review: what each catches
SDV and source data review are different activities and catch different problems. ICH E6(R3) lists both among monitoring activities, describing monitoring as a broad range of approaches including source data review, source data verification, data analytics, and site visits. SDV is the field-level check that a CRF value matches its source. Source data review is the broader look at whether the source records themselves are sound: are entries contemporaneous, are corrections explained, is anything missing, does the clinical story hang together? You can pass SDV (the numbers match) while failing source data review (the source itself is not defensible). Teams that run only transcription-matching miss this entire second category.
Risk-based / targeted SDV: why 100% SDV is the wrong default
The belief that FDA expects 100% verification of all data is a historical artifact, and FDA’s risk-based monitoring guidance was written specifically to correct it. The guidance states that many sponsors had understood earlier guidances as implying FDA expects frequent on-site monitoring and 100% data verification for all trials regardless of design, and it clarifies that risk-based monitoring, including centralized monitoring, is an acceptable and often preferable approach. FDA recommends that each sponsor design a monitoring plan tailored to the specific human-subject-protection and data-integrity risks of the trial, and encourages greater reliance on centralized monitoring with less emphasis on on-site verification.
Targeting is the whole point, and the RBM guidance tells you what to aim at. Sponsors should identify the critical data and processes to be monitored, generally including data critical to the reliability of study findings (those supporting primary and secondary endpoints), data critical to subject safety (such as serious adverse events and events leading to discontinuation), and the processes that underpin data integrity (such as blinding). Monitoring activities should focus on these critical measurements and on preventing the likely sources of error in their collection. The guidance frames the choice explicitly as comprehensive (100% data verification) versus targeted or random review (less than 100%), with the extent depending on factors weighed during risk assessment, including study complexity.
A workable targeting model that follows the guidance:
- Verify first what is critical to endpoints (primary, then secondary).
- Verify what is critical to safety (SAEs, discontinuations, eligibility for the at-risk population).
- Cover integrity-protecting processes (blinding, adjudication referrals).
- Scale intensity to study complexity and to signals surfaced by centralized monitoring.
- Let triggers escalate SDV at a site when data analytics flag anomalies, rather than starting everyone at 100%.
There is a tension worth stating plainly rather than smoothing over. ICH E6(R3) requires that source records be accurate and complete and that the investigator maintain adequate source records for every participant, an obligation that applies to all data. FDA’s RBM guidance simultaneously directs that verification effort concentrate on critical data rather than every field. These are not contradictory once you separate the two layers: the source records must be complete and accurate everywhere, but the verification effort spent confirming them is risk-weighted. Conflating “the record must be complete” with “every field must be 100% SDV’d” is precisely the error RBM was issued to dispel.
Anatomy of a source document template / worksheet
A source worksheet exists to guarantee a contemporaneous, attributable, complete source for protocol-required assessments, so a CRF field never has to be filled from memory. Map each element back to an ALCOA+ attribute:
- Subject and visit identifiers, plus protocol/version reference (attributable, traceable to the right context).
- A field for each protocol-required assessment at that visit (complete; no CRF field without a source).
- Recorder name and signature, date, and time of the observation (attributable, contemporaneous).
- A correction convention: single-line strike-through, initials, date, reason, original still legible (traceable; original not obscured, per ICH E6(R3)).
- For pre-printed normal ranges or checkboxes, a place to record the actual value, not just a tick, so the record stays original and accurate.
- For electronic worksheets, a captured originator and an audit trail per field, consistent with FDA’s eSource expectations.
Where teams get it wrong
The recurring findings cluster tightly:
- Pre-printed normals treated as observations. A box that says “WNL” with no recorded value is not a contemporaneous, original observation; it cannot be reconstructed.
- Late entries that are not contemporaneous and are not flagged as late, undercutting the contemporaneous and traceable attributes ICH E6(R3) requires.
- Copy-paste and convenience photocopies used as source. Without certification meeting the ICH E6(R3) and FDA criteria, these are not certified copies and the original remains the source of record.
- Missing source for a CRF field. A value in the CRF with no corresponding source fails the completeness expectation and breaks reconstruction.
- Corrections that obscure the original or have no audit trail, which both ICH E6(R3) and the FDA eSource audit-trail definition specifically prohibit.
- 100% SDV as a reflex instead of a risk-based plan, spending verification effort uniformly when FDA’s RBM guidance asks you to concentrate it on critical data and processes.
None of this certifies anyone as compliant. Source documentation tooling, worksheets, and an eSource system enable the attributes the regulations require, but the investigator and sponsor remain responsible for defining the source, certifying copies correctly, and justifying how much verification is enough. The defensible move is the same one ICH E6(R3) asks for up front: write down what your source is, prove your copies are certified, and target your SDV at what actually matters. Readers working the adjacent ALCOA+ data integrity, eSource and electronic records, risk-based monitoring, and essential documents/TMF topics will find those siblings pick up where this one leaves off.
Sources
- ICH E6(R3) Good Clinical Practice, version r3 (ICH, effective 2025-01-06). https://www.ich.org/page/efficacy-guidelines
- FDA Guidance: Electronic Source Data in Clinical Investigations, version 2013 (FDA, September 2013).
- FDA Guidance: Oversight of Clinical Investigations — Risk-Based Monitoring, version 2013 (FDA, August 2013).
Written by
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
Continue reading
Quality by Design in Clinical Trials: A Critical-to-Quality (CtQ) Identification Workflow, Not a Philosophy Lecture
Most "Quality by Design" explainers stop at the slogan and then list the ICH E8 CtQ categories as if naming them were the work. The work is the opposite: deciding which handful of factors actually matter for your protocol, and then deliberately not engineering controls around the rest. This guide tr...
ReadThe Living Data Management Plan: A Risk-Based DMP Template That Survives Database Lock and Inspection
A Data Management Plan that passes internal review but falls apart at database lock is the most common failure mode in clinical data management (CDM). It usually happens because the team treated the DMP as a document to produce, not a control system to operate. This guide hands you an annotated temp...
ReadQuery Management in Clinical Data Management: A Closure-Clock Playbook for One-Round Resolution
Most query guides hand you two definitions (manual versus system-generated) and a four-box lifecycle, then stop. That is the part of query management that does not actually cost you anything. What costs you is the re-query loop: a vague query goes to the site, the coordinator answers the wrong thing...
Read