Skip to content

EDC verification scenarios

Proposed verification set. A product-manager review should classify every scenario as supported, unsupported, deferred, or requiring a model change. A screen mock-up is not proof of support; the records, actions, rules, evidence, and correction path must be explained.

These key cases use Given/When/Then form so the expected clinical outcome can later be tested in documentation, acceptance criteria, or software without changing their meaning.

Given Site 101 is active for EDC with Design Publication 3 and no consent confirmation exists for the potential participant.
When the site tries to enter eligibility or screening laboratory data.
Then EDC refuses study-specific screening entry with reason Consent confirmation required.

Given the site records the approved consent version, actual consent time, person obtaining consent, participant/LAR basis, and evidence reference.
When the authorized site user starts screening.
Then EDC creates one Subject, Screening Attempt, and Casebook under Design Publication 3 and retains the consent confirmation before the first screening datapoint.

EX-02 — Reused item has placement-specific behavior

Section titled “EX-02 — Reused item has placement-specific behavior”

Given one Systolic Blood Pressure Item Definition is placed in Screening and Week 4 with different instructions and requiredness.
When Design Publication 2 is approved.
Then both Item Placements reference the same clinical definition, retain their own contextual rules, and produce distinct subject datapoints.

EX-03 — Datapoint survives compatible amendment

Section titled “EX-03 — Datapoint survives compatible amendment”

Given a submitted Week 4 weight datapoint exists for its exact casebook/event/form/row/item placement and the casebook uses Design Publication 1.
When the casebook adopts Publication 2, which changes only help text for that placement.
Then the datapoint identity and prior revision remain unchanged; later correction records Publication 2 as its design context.

EX-04 — Visit decisions remain independent

Section titled “EX-04 — Visit decisions remain independent”

Given Week 8 is applicable and displayed, but its availability date has not arrived.
When the site views the casebook.
Then Week 8 appears as expected but cannot be opened. Being displayed does not make it available, and being outside its window does not by itself mark it not applicable or incomplete.

Given an open query was routed to the wrong site and an equivalent correct query already exists.
When the data manager reviews it.
Then EDC cancels the duplicate with reason, retains its messages and routing history, and keeps the original query active with its age and escalation history unchanged.

EX-06 — Whole-study database reopen and relock

Section titled “EX-06 — Whole-study database reopen and relock”

Given the whole-study database is locked for final analysis and one subject requires an urgent safety correction.
When authorized approvers accept a Reopen Authorization limited to that casebook and datapoint.
Then only the authorized correction proceeds; affected checks, query disposition, SDV/DMR, coding, and Signature Requirement are reassessed; a new whole-study Database Lock and delivery are created with comparison to the prior lock.

EDC-01 — Reuse one CRF at several visits

Section titled “EDC-01 — Reuse one CRF at several visits”

The Vital Signs CRF is used at Screening, Baseline, and Week 4. The CRF definition is shared, but each placement and subject occurrence remains distinct. A placement-specific instruction does not create ambiguous data identity.

Week 4 needs an additional protocol-specific question. The designer detaches/copies the CRF with source history rather than accidentally changing Screening and Baseline.

EDC-03 — Ambiguous repeating-row derivation

Section titled “EDC-03 — Ambiguous repeating-row derivation”

A rule says “use adverse-event severity,” but several adverse events exist. Validation refuses publication until an occurrence selector is explicit.

EDC-04 — Site approval after design publication

Section titled “EDC-04 — Site approval after design publication”

The design is approved and published globally, but Site 103 lacks a required local approval. The design is available but EDC activation for Site 103 is refused with visible clinical reason.

Site 101 obtains informed consent using the approved consent version. The site confirms consent in EDC, then creates the subject and casebook under the site’s active design before eligibility and screening laboratory CRFs are entered. Later screen failure retains the consent confirmation, screening data, and audit history.

The participant returns under the protocol’s rescreen policy. The new attempt and its relationship to the prior failed attempt are visible without merging or duplicating screening history silently.

The site corrects a mistyped subject number. Stable identity, data, queries, coding, signatures, and audit history remain attached; number history records the correction.

EDC-08 — Treatment discontinued, follow-up continues

Section titled “EDC-08 — Treatment discontinued, follow-up continues”

The subject stops treatment but remains in survival follow-up. Treatment disposition does not close the casebook or make future follow-up events unavailable.

The site adds the next permitted unscheduled event. It receives a stable sequence and correct forms without changing the planned-visit definitions.

Actor: Delegated site user correcting Baseline date.
Given: Week 4 is applicable, opened, and has a recorded planned window derived from the prior Baseline date; the schedule rule and correction policy are effective.
When: the user submits an authorized Baseline-date correction with reason.
Then: EDC retains the prior date/window, records the corrected date, reevaluates Week 4 timing, and leaves applicability, availability, conduct, and completion unchanged unless their own rules act.
Refuse when: Baseline or Week 4 is locked and no matching Reopen Authorization exists.
Superseded evidence: timing/window evidence based on the old anchor is superseded; unaffected form review and signature evidence remains current.
Audit: actor, authority, reason, old/new date revisions, schedule-rule version, prior/new window, timing result, refusal or reopen reference.

Actor: Delegated site user correcting the controlling answer.
Given: the condition made a dynamic form applicable; the form contains submitted data and a current investigator signature.
When: an authorized correction makes the condition false.
Then: EDC records applicability as not applicable, retains the form and data, and creates an Applicability Conflict for authorized disposition; it does not delete the occurrence.
Refuse when: the containing scope is locked without Reopen Authorization, or the user attempts automatic removal of the nonblank form.
Superseded evidence: the prior signature and affected completion/review evidence are flagged or superseded according to policy; historical applicability remains visible.
Audit: controlling revisions, condition version/evaluations, form contents, signature reference, actor/reason, conflict decision, and any later re-signature.

Month and year are known but day is unknown. The date is retained structurally without inventing the first day of the month; dependent calculations become determinate or indeterminate by policy.

The assessment was attempted but unavailable because equipment failed. The site records a governed missing reason rather than a blank or fabricated value; query behavior follows study policy.

The user types text into a decimal item. It does not become clinical truth. The accepted correction and any retained invalid-attempt evidence remain distinguishable.

EDC-15 — Imported corrected laboratory result

Section titled “EDC-15 — Imported corrected laboratory result”

A central laboratory sends a corrected result. The prior imported revision remains visible, the new revision identifies its correction package, and affected checks/reviews are reconciled.

An edit check opens a query. The site confirms the value is correct without changing it. The query is answered and may be closed while the clinical value and failed-range context remain traceable.

EDC-17 — Data changed but query unanswered

Section titled “EDC-17 — Data changed but query unanswered”

Actor: Delegated site user correcting a queried value.
Given: an open query and failing check evaluation target the current datapoint revision.
When: the user corrects the value but sends no query response.
Then: EDC creates a new datapoint revision and reevaluates the check; the finding may resolve, but the query remains Open until the site answers or an authorized reviewer dispositions it.
Refuse when: the datapoint is frozen/locked without the required unfreeze/reopen authority.
Superseded evidence: the prior current value and check evaluation are superseded; query messages and aging remain unchanged.
Audit: old/new value, correction reason, check results, query status, actor, timestamps, and any later response/closure.

The site answers without resolving the discrepancy. The reviewer returns/re-queries within the same conversation rather than opening unrelated history.

A revised check makes an old system finding obsolete. Prior evaluations and query conversation remain visible; current status says why no active discrepancy remains.

A serious adverse event triggers 100% SDV despite the subject’s normal sampled plan. Requirement, review evidence, and later data-change behavior are explainable.

Actor: Delegated site user correcting previously reviewed data.
Given: the current datapoint revision has completed SDV and is included in completed DMR evidence.
When: an authorized correction creates a new revision.
Then: EDC identifies the exact SDV and DMR evidence affected, applies the study’s material-change policy, and creates new review requirements where needed; unrelated review remains current.
Refuse when: a freeze/lock prevents correction or required reason/authority is missing.
Superseded evidence: prior SDV/DMR remains readable but is marked superseded or changed-after- review; any declared immaterial decision retains reviewer and rationale.
Audit: old/new revisions, affected review identifiers, policy version, reassessment outcome, reviewers, reasons, and completion of renewed review.

The medication verbatim remains the same but route changes. The coding request becomes Needs Recoding according to configuration because the original decision used that context.

One approved term remaps uniquely; another has no current equivalent. The first retains remapping history; the second becomes Noncurrent and requires review.

The coder cannot distinguish two products from the verbatim. A site query requests clarification; the coding decision waits without overwriting the original verbatim.

Actor: Authorized site user; investigator performs later re-signature.
Given: a Signature Requirement is satisfied by a signature covering the submitted form revisions, and a query has been validly reopened.
When: the site corrects covered data with reason.
Then: EDC retains the old signature, marks it superseded for the changed scope, changes the Signature Requirement to Needs re-signature, and permits a new signature only after prerequisites pass.
Refuse when: the form is locked without Reopen Authorization, correction exceeds authorized scope, or the signer lacks current authority.
Superseded evidence: prior signature and any affected review evidence remain readable with the change that superseded them.
Audit: reopened query, correction, covered-data inventories before/after, attestation versions, signer authority, old/new signatures, and timestamps.

The investigator signs a casebook while specified blinded central data are excluded. The signature covered-data inventory and attestation make the exclusion explicit.

Actor: Authorized study data manager applying an approved Casebook Design Adoption.
Given: a completed visit under Publication 1; Publication 2 adds a required CRF; compatibility assessment is complete.
When: adoption is authorized and applied.
Then: EDC records the new publication assignment, creates the new CRF occurrence as Not started, marks visit completion Incomplete, and creates applicable review/signature requirements.
Refuse when: the casebook is locked without Reopen Authorization or required conflicts are unresolved.
Superseded evidence: prior visit-completion and signature evidence is retained and marked affected; unaffected datapoints preserve identity.
Audit: publications, assessment, actor/authority, created CRF placement, affected requirements, refusal/conflicts, and adoption time.

Actor: Authorized study data manager applying an amendment.
Given: the target publication removes a CRF whose subject occurrence contains data, queries, and review evidence.
When: compatibility assessment evaluates that casebook.
Then: EDC creates a destructive-change conflict and requires an approved retain-as-inactive or other explicit resolution; no record is deleted.
Refuse when: adoption is attempted without conflict resolution or against a locked casebook.
Superseded evidence: evidence remains attached to retained records; current expectedness changes only after approved resolution.
Audit: removed placement, contained record inventory, conflict, decision maker, reason, chosen resolution, and final adoption result.

EDC-29 — Locked casebook blocks adoption

Section titled “EDC-29 — Locked casebook blocks adoption”

Actor: Authorized study data manager running an approved adoption plan.
Given: selected casebooks passed compatibility review except one with an applicable Scoped Lock.
When: adoption runs.
Then: eligible casebooks adopt the target publication; the locked casebook remains on its prior publication with a visible Not applied result and required next action.
Refuse when: any attempt is made to bypass the lock or report the plan as fully complete.
Superseded evidence: none for the skipped casebook; adopted casebooks reassess only affected evidence.
Audit: per-casebook prior/target publication, applied/skipped/failed result, lock reference, actor, batch/adoption identifier, and later resolution.

EDC-30 — Database-lock readiness failure

Section titled “EDC-30 — Database-lock readiness failure”

Actor: Database-lock lead requesting whole-study final-analysis lock.
Given: one coding request is incomplete and one required external reconciliation remains open.
When: Lock Readiness Assessment is evaluated.
Then: readiness records both failures and Database Lock is not authorized.
Refuse when: the lead attempts to lock without completing them or obtaining exceptions explicitly allowed and approved by policy.
Superseded evidence: an older passed readiness result is stale if later data or reconciliation changes occurred.
Audit: readiness-policy version, each check/result/source time, exceptions requested/approved or rejected, actor, and lock refusal.

Actor: Authorized site user corrects data after sponsor-authorized reopening.
Given: the whole-study database is locked for final analysis and an urgent source-supported safety correction is identified for one datapoint.
When: required approvers authorize reopening limited to that casebook/datapoint and the correction occurs.
Then: EDC permits only the authorized change, reassesses affected check/query/review/coding/ signature evidence, repeats whole-study readiness, creates a new Database Lock, and produces a new delivery compared with the prior one.
Refuse when: approval, source evidence, exact scope, or impact assessment is missing, or attempted changes exceed authorization.
Superseded evidence: prior Database Lock remains historical; affected evidence is marked with its replacement/current status; unrelated evidence remains current.
Audit: request, approvals, scope, reason, old/new value, all reassessments, prior/new lock, delivery difference inventory, actors, and times.

A data cut that cannot be changed is produced while data entry continues. It remains reproducible and is not misrepresented as final database lock.

After correction and relock, a new delivery package is produced. Its included-record inventory explains every difference from the original locked package and retains both deliveries.

  1. Which clinical records exist before the action?
  2. Who may take the action, and on what authority?
  3. Which business rule permits or refuses it?
  4. What becomes current afterward?
  5. What prior information remains visible?
  6. Which checks, queries, reviews, codes, signatures, freezes, or locks are affected?
  7. Which external product receives or supplies a fact?
  8. What would a monitor, data manager, investigator, auditor, or inspector see later?