Skip to content

Amendments, external data, and exports

Included in the proposed model: Amendment Design, Change Classification, Amendment Adoption Plan, Casebook Compatibility Assessment, Adoption Conflict, External Data Source, Transfer Package, Import Result, Reconciliation, Data Cut, Extract Specification, Extract Run, and Delivery Package.

Open: supported destructive-change classes, source-specific reconciliation ownership, certified copy format, and authoritative end-of-study package.

A published design is never edited in place. Change proceeds as:

Published design
→ Amendment draft
→ Validate and approve new design
→ Publish new design
→ Assign prospectively to sites
→ Assess existing casebooks
→ Resolve conflicts
→ Adopt per authorized scope
→ Re-run affected rules and finalization work

Publication makes a version available. Prospective site assignment decides what new casebooks use. Retrospective adoption decides how each existing casebook changes.

Class Example Expected treatment
Presentation-only Correct help text without clinical meaning change May preserve entered data and review evidence after assessment
Additive Add new CRF or item Create new expected records; collect missing information as required
Compatible constraint expansion Increase text length or repeat maximum Preserve existing data; apply to later entry
Meaning-affecting Change question, condition, derivation, check, codelist meaning Assess data, queries, review, coding, signature, and export impact
Structurally destructive Remove/move a form, group, item, or event containing records Never silently delete; retain/inactivate or require manual resolution
Incompatible datatype/precision Text to date, reduce precision, disallow prior partial date Cannot automatically reinterpret historical data

Every change records clinical intent, affected definitions, compatibility, subject/site scope, and expected operational consequences.

Fields:

  • source and target published designs;
  • reason/protocol amendment;
  • selected sites and casebooks;
  • change classifications;
  • per-casebook compatibility results;
  • conflicts and chosen resolution;
  • treatment of collected, reviewed, signed, frozen, or locked data;
  • rule rerun plan;
  • validation and approval evidence;
  • planned/effective adoption time; and
  • completion summary and exceptions.
  • preserve compatible existing occurrences and values;
  • create newly expected visits/forms/items as unentered;
  • retain obsolete occurrences as inactive/no longer expected with history;
  • reopen affected submitted forms;
  • flag or supersede affected SDV/DMR/coding/signature evidence;
  • refuse locked casebooks pending authorized reopen;
  • create queries/findings for data that no longer conform; and
  • retain different design assignments temporarily with visible status.

External data can originate from laboratories, imaging vendors, eCOA, devices, EHRs, RTSM, safety, and other approved systems.

Field Meaning
Source identity and type Accountable external origin
Study purpose Clinical data supplied and how they are used
Subject/site matching Approved identifiers and ambiguity policy
Data contract Fields, codes, units, time semantics, and version
Transfer schedule Expected cadence and cutoff behavior
Blinding classification Who may see imported values
Correction model Replacement, delta, cancellation, or new-version semantics
Reconciliation owner Team responsible for resolving discrepancies

A Transfer Package retains source, package identifier, sequence, produced/received time, contract version, file/message integrity, data cutoff, record counts, and correction indicator.

An Import Result retains:

  • accepted, rejected, duplicated, and quarantined records;
  • subject/event/item matching results;
  • unit/terminology validation;
  • import warnings and errors;
  • created datapoint revisions and their origin;
  • whether the package had already been processed and the original result was safely reused; and
  • accountable review/disposition.

Replay of the same package must not create duplicate clinical revisions.

Reconciliation compares records that should agree across sources, such as:

  • EDC serious adverse events versus the safety system;
  • EDC treatment/randomization facts versus RTSM;
  • EDC laboratory forms versus central-laboratory transfers;
  • EDC visit dates versus eCOA assessment timing; and
  • EDC disposition versus external follow-up sources.

Retain the comparison definition/version, compared records, result, discrepancy, owner, query or external issue, resolution, accepted exception, reviewer, and time. Reconciliation does not transfer ownership of the source record into EDC.

A Data Cut is a reproducible view of included data at a declared point.

Fields include purpose, as-of/cutoff time, receipt cutoff, included sites/subjects/sources, design versions, blinding profile, selection rules, requested/authorized by, generated time, and data inventory that cannot be changed. An interim cut may exist while the live casebook continues to change.

Specification Run/delivery evidence
Purpose and audience Requester, authorization, generation time
Format and version Exact software/mapping version
Included clinical/audit records Data cut or exact live-data inventory at the stated time
Terminology and units File/row counts and checksums
Mapping/transformation rules Warnings, rejected records, exclusions
Blinding and privacy profile Delivered-to identity and acknowledgement
Naming and packaging conventions Relationship to prior/regenerated package

Separate operational listings, raw clinical-data extracts, ODM exchange/archive packages, SDTM deliveries, audit exports, annotated CRFs, casebook PDFs, investigator copies, and end-of-study archives. They have different purposes and completeness rules.

ODM structures such as MetaDataVersion, StudyEventDef, FormDef, ItemGroupDef, ItemDef, CodeList, ClinicalData, SubjectData, StudyEventData, FormData, ItemGroupData, ItemData, and AuditRecord are exchange structures. The operational EDC model maps to them deliberately; it does not adopt them as its internal ownership model.

  1. Every casebook always identifies its exact design assignment and amendment history.
  2. Adoption never silently deletes collected or audit-relevant records.
  3. Locked casebooks require controlled reopen before an affecting amendment.
  4. Amendment completion records casebooks applied, skipped, failed, and conflicted.
  5. Imported values retain source, package, contract, originator, and receipt evidence.
  6. Duplicate/replayed packages do not create duplicate revisions.
  7. Source corrections create traceable superseding revisions; they do not rewrite prior import history.
  8. Reconciliation retains both source identities and does not invent one shared record.
  9. Every data cut and extract can be reproduced from its included-record inventory and versions.
  10. Regeneration creates a new delivery package and never replaces prior delivery evidence.
  11. Exports protect blinding and privacy according to the declared audience.
  12. Investigator copies include readable data and relevant audit/signature context under the agreed retention process.
  • A removed form already contains signed data.
  • A codelist value is retired after use.
  • A new required item is added to completed visits.
  • One locked casebook cannot adopt the amendment.
  • An external package arrives out of sequence or is corrected later.
  • Subject identifiers do not match confidently across EDC and laboratory data.
  • An imported unit is valid but differs from the CRF’s preferred unit.
  • An extract is requested across subjects on different design versions.
  • A blinded extract accidentally requests treatment-identifying fields.
  • A relock package must be compared with the original locked delivery.