Clinical Research Data Management Guide

Research

How Clinical Research Data Management Guide approaches evidence — for product research, practice research, and the market analysis we plan to publish as our dataset grows.

Product research

Product profiles are built from a 53-capability taxonomy applied identically to every product. Every factual claim traces to a cited source with a verification date; uncertainty is recorded as unclear or not yet verified rather than guessed; and conflicting sources are preserved and shown to readers rather than silently resolved. The full rules are in our methodology and editorial policy.

Practice research

Our educational articles draw on peer-reviewed research, government sources, standards bodies, and established research organizations — with named citations, precise language about what studies did and did not find, and explicit limitations. We use vendor materials for vendor-specific facts, not to establish general best practices.

Future aggregate analysis

As the number of researched products grows, we plan to publish aggregate market analysis — pricing model distributions, capability prevalence, and commercial packaging patterns. We won't publish statistics based on a handful of products as if they represented the whole market.

Research we're reading

Each entry states what the researchers studied, what they found, and — deliberately — what they did not establish, so narrow findings never quietly become universal recommendations.

Research electronic data capture (REDCap) — A metadata-driven methodology and workflow process for providing translational research informatics support

Harris, P. A., Taylor, R., Thielke, R., Payne, J., Gonzalez, N., & Conde, J. G. (2009). Journal of Biomedical Informatics 42(2): 377–381. DOI: 10.1016/j.jbi.2008.08.010.

What they studied:
The design and deployment of REDCap, a metadata-driven web application for building and managing research databases, developed at Vanderbilt to support investigator-initiated translational research — and the workflow by which informatics staff and research teams iteratively build studies from a single metadata dictionary.
What they found:
A single metadata table driving data entry forms, validation, and exports let small teams stand up secure research databases in days rather than months, without custom programming per study, and the approach spread rapidly through a consortium of academic institutions that has since made REDCap the default academic data capture platform.
What they did not establish:
Comparative effectiveness — this is a design and methodology paper, not an evaluation against commercial EDC systems, and it does not measure downstream data quality. It also predates much of the platform's later functionality, and suitability for regulated trials depends on how an institution configures, validates, and governs its installation, which the paper does not address.
Why it matters:
The paper behind the most widely used academic data capture platform. Its central argument — that study build should be an act of metadata authoring rather than software development — became the default mental model for a generation of research databases, and explains both REDCap's speed and its boundaries.
Technology implications:
Metadata-driven study build is now table stakes: evaluate any EDC on how completely the study definition — fields, codelists, validation rules, and exports — is expressed as reviewable metadata rather than configuration buried inside the application. (Clinical Research Data Management Guide analysis.)

Ecrf design Electronic data capture Metadata and data dictionaries Data export

Original source: Research electronic data capture (REDCap) — A metadata-driven methodology and workflow process for providing translational research informatics support (external link) · reviewed by us September 1, 2026

Good Clinical Data Management Practices (GCDMP)

Society for Clinical Data Management (2000–present). Society for Clinical Data Management (SCDM); chapters revised on an ongoing basis.

What they studied:
A practice-consensus reference rather than a study: chapters written and peer-reviewed by practicing data managers covering the span of the discipline — data management planning, CRF design, edit checks, query management, medical coding, database lock, and vendor and quality management — with recommendations graded by the strength of available evidence.
What they found:
The closest thing clinical data management has to a codified body of knowledge: per-chapter minimum standards and best practices written against regulatory expectations such as GCP and 21 CFR Part 11, intended to be usable across organizations, systems, and study types.
What they did not establish:
Evidence of effect — GCDMP recommendations are professional consensus graded against evidence that is often observational or experiential, not the product of controlled comparisons. Chapters vary in revision date, so individual chapters can lag current technology and regulation; it is a reference to apply with judgment, not a compliance checklist.
Why it matters:
When a data management SOP, job description, or audit response needs an authoritative citation, GCDMP is usually where the profession points. It defines the vocabulary and scope of the role — useful for building a department, training new data managers, or benchmarking practices against the field's consensus.
Technology implications:
GCDMP chapters map naturally onto system capabilities — edit checks, query workflow, coding, database lock, audit trails — and make a serviceable requirements checklist when evaluating whether a platform supports the practices the profession expects. (Clinical Research Data Management Guide analysis.)

Edit checks Query management Database lock Audit trails Data validation

Original source: Good Clinical Data Management Practices (GCDMP) (external link) · reviewed by us September 1, 2026

ICH E6(R3) Guideline for Good Clinical Practice

International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use (ICH) (2025). ICH; adopted January 2025.

What they studied:
Not a study but the governing international standard: the revised Good Clinical Practice guideline, restructured into overarching principles plus Annex 1 for interventional trials, with a dedicated data governance section setting out the responsibilities of investigators and sponsors across the data life cycle.
What they found:
GCP recast for current trial conduct: media-neutral requirements that apply whatever the mix of paper and electronic systems, explicit expectations for data integrity, traceability, and computerized systems, and quality-by-design and risk-proportionality as organizing ideas rather than add-ons.
What they did not establish:
Operational specifics — E6(R3) states expectations, not procedures. It does not say which systems, SOPs, or review intensities satisfy it; that translation is left to sponsors, sites, and regional regulators, whose implementation timelines and local requirements differ.
Why it matters:
The reference document for every conversation about what "GCP-compliant data management" means. Elevating data governance into the body of GCP makes the data manager's core concerns — provenance, audit trails, access control, protection of blinding — an explicit, shared responsibility of sponsors and investigators.
Technology implications:
Systems should make E6(R3)'s expectations demonstrable: complete audit trails, access controlled by role and site, validation documentation proportionate to risk, and the ability to reconstruct the data life cycle from capture through lock. (Clinical Research Data Management Guide analysis.)

Audit trails Role based permissions Data provenance Validation documentation

Original source: ICH E6(R3) Guideline for Good Clinical Practice (external link) · reviewed by us September 1, 2026

Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers

U.S. Food and Drug Administration (2024). FDA final guidance.

What they studied:
FDA's final question-and-answer guidance on how 21 CFR Part 11 and related requirements apply to electronic records, systems, and signatures in clinical investigations — spanning sponsor and site systems, IT service providers and cloud hosting, real-world data sources, and digital health technologies. It supersedes the 2007 Computerized Systems Used in Clinical Investigations guidance.
What they found:
Current agency thinking in practical form: validation proportionate to risk rather than a uniform burden, expectations for audit trails and record retention, how responsibilities divide between sponsors and technology providers, and acceptable approaches to electronic signatures.
What they did not establish:
Bright-line rules — as guidance it describes FDA's current thinking and is nonbinding, and it does not certify any product as "Part 11 compliant" (no such certification exists). Applying it still requires judgment about a specific system's intended use and risk.
Why it matters:
The document to reach for when a vendor claims Part 11 compliance or an auditor questions a cloud-hosted system. It replaces decades-old references with current, citable answers on system qualification, validation scope, and signature practices.
Technology implications:
Vendor evaluation should trace to this guidance: ask how audit trails, access controls, signature manifestations, and validation documentation line up with its questions and answers rather than with generic compliance marketing. (Clinical Research Data Management Guide analysis.)

Electronic signatures Audit trails Validation documentation Security controls

Original source: Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers (external link) · reviewed by us September 1, 2026

NIH Policy for Data Management and Sharing

National Institutes of Health (2023). NIH (NOT-OD-21-013); effective January 25, 2023.

What they studied:
The federal policy governing data management and sharing for NIH-funded research: applications for research expected to generate scientific data must include a data management and sharing plan covering data types, standards, repositories, timelines, and access and reuse considerations, with compliance a term and condition of the award.
What they found:
Not findings but obligations: plans are required regardless of budget size — replacing the 2003 policy's $500,000 threshold — reasonable data management and sharing costs are allowable, and sharing is expected no later than publication or the end of the award period.
What they did not establish:
Uniform practice — the policy sets expectations, not a single standard for repositories, formats, or de-identification. What a given institute, program, or repository requires varies, and enforcement experience is still accumulating.
Why it matters:
For NIH-funded teams, the study database now has a second audience: the plan written at application time commits the team to standards, repositories, and timelines the data management workflow must actually deliver. Data managers belong in plan writing, not just plan execution.
Technology implications:
Favor systems that make sharing cheap at the end: clean exports with machine-readable data dictionaries, de-identification support, and provenance good enough to document what was collected and how. (Clinical Research Data Management Guide analysis.)

Data export Data de identification Metadata and data dictionaries Data provenance

Original source: NIH Policy for Data Management and Sharing (external link) · reviewed by us September 1, 2026