GCP · Blog
Back to journal

TMF vs ISF: An Ownership-and-Reconciliation Contract, Not a Location Table

Almost every explainer you will find stops at "TMF = sponsor, ISF = site." That is true and nearly useless, because it answers the wrong question. The hard question at an inspection is not where a document lives. It is who is accountable for it, whether the same document appears correctly in both files, and whether the two files tell the same story.

GCP 12 min read
A

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.

On this page · 10 sections
  1. 01 At a glance
  2. 02 TMF vs ISF in one sentence: location is the easy half, ownership is the hard half
  3. 03 The ownership matrix: accountable owner vs physical holder
  4. 04 The overlap set: documents that must exist in both files
  5. 05 Why “completeness” is a reconciliation property, not a within-file checklist
  6. 06 ”Site master file” decoded: a GMP term, not the ISF
  7. 07 eTMF and eISF: what digitisation changes about access and timing
  8. 08 Inspection lens: what inspectors test across ISF and TMF
  9. 09 Practical handoffs: who files what, when, and the archiving bar
  10. 10 Sources

At a glance

  • The TMF and the ISF are not two different document sets. They are two repositories of one set of essential records, split by who is accountable for each record, not merely by where it sits.
  • ICH E6(R3) §C.2.3 names both repositories explicitly: the sponsor holds the trial master file (TMF) and the investigator/institution holds the investigator site file (ISF). EU CTR Article 57 says both parties shall keep a clinical trial master file.
  • A large overlap set must exist in BOTH files. EMA’s TMF guideline §3.5.2 requires superseded sponsor-produced documents (protocol, IB, eCRF) to be present in the investigator file so the trial can be reconstructed without reaching into the sponsor TMF.
  • Inspection-readiness is a reconciliation property. The question is not “is the ISF complete?” but “do the ISF and TMF agree on versions, dates, and signatures?”
  • “Site master file” is a GMP/manufacturing term. It is not the ISF and not a clinical-trial document. The keyword surfaces a naming collision, nothing more.
  • The sponsor stays responsible for the sponsor TMF even when its maintenance is delegated. Delegation moves the work, not the accountability.

TMF vs ISF in one sentence: location is the easy half, ownership is the hard half

Almost every explainer you will find stops at “TMF = sponsor, ISF = site.” That is true and nearly useless, because it answers the wrong question. The hard question at an inspection is not where a document lives. It is who is accountable for it, whether the same document appears correctly in both files, and whether the two files tell the same story.

ICH E6(R3) §C.2.3 establishes the vocabulary precisely: essential records “should be maintained in or referred to from repositories held by the sponsor and by the investigator/institution,” and “these repositories may be referred to as a trial master file (TMF),” while “the repository held by the investigator/institution may also be referred to as the investigator site file (ISF).” Read that carefully. The ISF is not a different category of document. It is the investigator’s slice of one essential-records set.

EU CTR Article 57 frames the same split as a shared obligation: “The sponsor and the investigator shall keep a clinical trial master file.” The same Article allows the two halves to differ: “The clinical trial master file kept by the investigator and that kept by the sponsor may have a different content if this is justified by the different nature of the responsibilities of the investigator and the sponsor.” Different content is permitted, but only because the responsibilities differ, not because anyone gets to file casually.

The ownership matrix: accountable owner vs physical holder

Two words get blurred constantly: owner (who is accountable) and holder (who physically keeps the copy). They are not the same. EMA’s TMF guideline §3.1 is blunt about it: even when an institution that is the sponsor delegates maintenance of part of the sponsor TMF to the investigator, “the responsibility for the sponsor TMF remains with the sponsor.” Delegation relocates custody; it never relocates accountability.

With that distinction fixed, here is the accountability map for the common essential-document classes. The EMA guideline §3.1 anchors the segregation rule: some documents are “generated and/or held by the sponsor only” and some “by the investigator/institution only,” and it gives the canonical examples (subject identification code list in the investigator file only; master randomisation list in the sponsor file only).

Essential-document classAccountable ownerTMF (sponsor)ISF (site)Shared / in both
Protocol and amendmentsSponsorYesYes (received/approved copy)Yes
Investigator’s BrochureSponsorYesYesYes
Signed informed consent formsInvestigatorNoYesNo
Subject identification / enrolment logInvestigatorNoYesNo
EC/IRB approvals and correspondenceShared (each files own)YesYesYes
Form FDA 1572 / delegation log / training recordsInvestigatorNoYesNo
IP accountability at siteInvestigatorNoYesPartly (sponsor oversight)
Master randomisation listSponsorYesNoNo
Monitoring reportsSponsorYesNoNo
Safety reports (SAE to sponsor; SUSAR to authorities; safety info to investigators)SharedYesYesYes

ICH E6(R3) §C.2.10 confirms the asymmetry: some records are “typically maintained and retained only by the sponsor (e.g., those related solely to sponsor activities such as data analysis) or only by the investigator/institution (e.g., those that contain confidential participant information),” while “some records may be retained by the sponsor and/or the investigator/institution.” That third bucket is the overlap set, and it is where this article earns its keep.

A note on the “owner” column for consent: the investigator/institution owns the executed consent forms because §C.2.10 keeps confidential participant information on the site side, and ICH E6(R3) §2.12.11 (investigator control of records) gives the investigator control of essential records the site generates. The sponsor never files the signed ICFs; it files evidence that consent materials and the consent process were correct.

The overlap set: documents that must exist in both files

This is the substance every competing page skips. A defined group of documents must reconcile across the TMF and the ISF, and that group is where inspection findings actually originate.

EMA’s TMF guideline §3.5.2 states the requirement directly for superseded documents: “Superseded versions of sponsor-produced documents (e.g., trial protocol, IB and eCRF) should be present in the investigator/institution TMF in a manner to enable reconstruction without the need to access the sponsor TMF, with evidence of date of receipt, review and/or approval (when necessary) and date of implementation by the investigator/institution.” That single sentence is the heart of TMF/ISF reconciliation. The site file is not allowed to hold only the current protocol. It must carry the version history, with the site’s own receipt and implementation dates, so an inspector standing at the site can reconstruct the trial without phoning the sponsor.

ICH E6(R3) §C.2.8 explains why the overlap exists at all: “In order to fulfil their responsibilities in the conduct of the trial, the sponsor and investigator/institution may need access to or copies of one another’s relevant essential records before and during the conduct of the trial,” and “at the end of the trial, each party should retain their essential records.” The example given is a SUSAR report the investigator accesses through a sponsor portal that must still be retained in the site file at trial end. Access during the trial is not retention. If the site only ever viewed a safety report through a portal, the site file is short a record it is required to keep.

The overlap/shared-set checklist, the documents that must reconcile across both files:

  • Protocol and every amendment, including superseded versions, with site receipt/implementation dates (EMA §3.5.2)
  • Investigator’s Brochure and updates (ICH E6(R3) §C.2.10 shared bucket)
  • EC/IRB approvals and favourable opinions for each version (each party files its own copy)
  • Sample consent materials and information given to participants (the site holds executed ICFs; the sponsor holds approved templates)
  • Safety reports the investigator received from the sponsor, retained at the site, not merely viewed (ICH E6(R3) §C.2.8)
  • Sample data acquisition tools / eCRF the sponsor provided to the site

Why “completeness” is a reconciliation property, not a within-file checklist

Here is the stance: a file that is individually “complete” against a checklist can still fail inspection if it disagrees with its counterpart. Completeness is a relationship between the two files, not a count of documents inside one of them.

ICH E6(R3) §C.2.6 sets the standard each party must meet: “The sponsor and investigator/institution should retain the essential records in a way that ensures that they remain complete, readable and readily available and are directly accessible upon request by regulatory authorities, monitors and auditors,” and “alteration to the essential records should be traceable.” EMA’s TMF guideline §2 raises the bar past a checklist: the documentation “should be sufficient to adequately reconstruct the activities undertaken in conducting the trial,” and the records “should collectively permit confirmation of compliance with the protocol and GCP and the integrity of data collected without the need for additional explanation from the sponsor, CRO or investigator/institution staff.” Reconstruction without additional explanation is the test. If protocol v3 is implemented in the sponsor TMF but the site file still shows participants screened under v2 with no evidence of when v3 reached the site, no within-file checklist saves you. The two files do not reconcile, and that is the finding.

The recurring real-world failure is exactly this drift: a protocol amendment or a consent version that is current in one file and stale in the other, plus “who files it” ambiguity at the site. The amendment lands in the sponsor TMF the day it is approved; the site files its copy weeks later, or never logs the implementation date, and the version histories diverge.

”Site master file” decoded: a GMP term, not the ISF

The keyword set drags in “site master file in clinical trial,” and it needs one clear sentence of disambiguation. A Site Master File is a Good Manufacturing Practice document describing a manufacturing facility. It is not the investigator site file, it is not part of the TMF/ISF vocabulary, and it does not belong in a discussion of essential clinical-trial records. If you are setting up study files, you want the ISF (investigator site file), not a Site Master File. That is the entire overlap between the two terms: they share three words and nothing else. We are not teaching GMP facility documentation here; we are only clearing the naming collision so the right file gets built.

eTMF and eISF: what digitisation changes about access and timing

Going electronic changes the controls, not the responsibilities. EMA’s TMF guideline §4.1 requires that “access to the TMF should be based on a role and permission description that is defined by the sponsor and/or investigator/institution,” and that blinding-sensitive content (randomisation codes, unblinded adverse-event data) be controlled by storage separation or role-based permissions. In an eTMF/eISF world this is where the sponsor’s read access to the site file is governed: not “the sponsor can see everything,” but a defined, role-based permission scope.

Digitisation also sharpens the contemporaneous-filing duty. EMA’s TMF guideline §3.5.4 reads Article 57’s “at all times” requirement to mean “the TMF should have all documentation added in a timely manner during the trial,” and it directs that “the timelines for submission and filing of all documents to the TMF in procedural documents or TMF plans should be defined.” An eTMF makes a late filing timestamp-visible, which is precisely why timely filing must be planned rather than assumed. ICH E6(R3) §C.2.1 adds the metadata backbone digitisation depends on: records “should be identifiable and version controlled (when appropriate) and should include authors, reviewers and approvers as appropriate, along with date and signature.” Version control and signature metadata are what make cross-file reconciliation checkable at all.

On when the sponsor gets access to the ISF: there is a tension worth stating plainly rather than smoothing over. ICH E6(R3) §2.12.11 gives the investigator/institution control of all essential records it generates, and EMA §3.1 affirms the investigator “is responsible for all essential documents generated by the investigator/institution and should therefore have control of them at all times.” The site owns and controls its file. Yet EMA §3.1 also requires role-based permissions to be established for activities being undertaken, and the broader monitoring duties assume the sponsor can verify site records. The reconciliation in practice: the sponsor gains defined, role-scoped access for monitoring and oversight, but investigator control of the site’s records is not surrendered. Both demands hold at once; an eISF must encode both.

Inspection lens: what inspectors test across ISF and TMF

Inspectors do not grade the ISF and TMF separately and average the scores. They test whether the two reconcile. EU CTR Article 57 tells you why the files exist: the master file “shall at all times contain the essential documents relating to that clinical trial which allow verification of the conduct of a clinical trial and the quality of the data generated,” and it “shall be readily available, and directly accessible upon request, to the Member States.” Article 78 then empowers Member States to appoint inspectors “to perform inspections in order to supervise compliance with this Regulation.” Verification is the job; reconciliation is the method.

EMA’s TMF guideline §6 (archiving) adds a gate that catches drift at the end: “archiving should be undertaken after the investigator/institution and sponsor have reviewed that their filed TMF documentation is complete.” That review is the last reconciliation checkpoint before the file is locked for the retention period.

The inspection-reconciliation checklist, the cross-file checks that decide findings:

  • Version match: the protocol/IB/consent version current in the ISF matches the version current in the TMF, and superseded versions are present in both (EMA §3.5.2)
  • Date and signature match: receipt, approval, and implementation dates for shared documents agree across files; signatures and version metadata are present (ICH E6(R3) §C.2.1)
  • Presence in both: every overlap-set document required in both files is actually in both, including safety reports retained at site (ICH E6(R3) §C.2.8)
  • Traceable alteration: changes to essential records are traceable in each file (ICH E6(R3) §C.2.6; EU CTR Article 58)
  • Archiving review: both parties have reviewed their filed documentation as complete before archiving (EMA §6)

Practical handoffs: who files what, when, and the archiving bar

Three handoffs cause most reconciliation findings, and each maps to a corpus duty.

First, contemporaneous filing. ICH E6(R3) §C.2.5 directs that “the sponsor and investigator/institution should ensure that the essential records are collected and filed in a timely manner.” Pair that with EMA §3.5.4’s instruction to define filing timelines in advance. The fix for ISF/TMF drift is a written rule for who files each shared document and by when, applied to both files, not a heroic reconciliation at the end.

Second, original-record custody. ICH E6(R3) §C.2.7 sets a default that resolves a lot of “who files it” arguments: “The original records should generally be retained by the responsible party who generated them.” The site generated the consent forms, so the site keeps the originals; the sponsor generated the monitoring reports, so the sponsor keeps those.

Third, the archiving bar. EU CTR Article 58 requires that “the sponsor and the investigator shall archive the content of the clinical trial master file for at least 25 years after the end of the clinical trial,” that the content “be archived in a way that ensures that it is readily available and accessible, upon request, to the competent authorities,” and that “any alteration to the content of the clinical trial master file shall be traceable.” Article 58 also requires the sponsor to “appoint individuals within its organisation to be responsible for archives” with access “restricted to those individuals.” The investigator file faces the same 25-year availability standard; reconciliation does not end when recruitment does.

A closing word on what regulations do and do not buy you: ICH E6(R3), the EMA TMF guideline, and EU CTR 536/2014 tell you what your files must contain and how the two must relate. They do not certify that a given TMF or ISF is compliant. An eTMF/eISF system can enable contemporaneous filing, version control, and role-based access, but the sponsor and investigator remain accountable for whether the two files actually reconcile. Good software makes the reconciliation visible; it does not perform it for you.

For the document-by-document naming of the shared set, practitioners commonly use the TMF Reference Model. That is an industry artifact, not a regulation, and it is cited here as a reference, not a regulatory source.

Sources

  • ICH E6(R3) Good Clinical Practice (ICH), version r3, https://www.ich.org/page/efficacy-guidelines — Appendix C (Essential Records), §C.2 management of essential records, §2.12.11 investigator control of records.
  • EMA Guideline on content management and archiving of the clinical trial master file (EMA), version 2018 — §2 (purpose/reconstruction), §3.1 (sponsor vs investigator TMF/ISF), §3.5.2 (superseded documents in both files), §3.5.4 (contemporariness), §4.1 (access/role-based permissions), §6 (archiving).
  • Regulation (EU) No 536/2014 on Clinical Trials (European Parliament and Council), version 2014, https://eur-lex.europa.eu/eli/reg/2014/536/oj — Article 57 (clinical trial master file), Article 58 (archiving), Article 78 (Member State inspections).
  • TMF Reference Model, industry reference for the shared/overlap document set; not a regulation.
A

Written by

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.