EDC verification scenarios
Review status
Section titled “Review status”Proposed verification set. A product-manager review should classify every scenario as supported, unsupported, deferred, or requiring a model change. A screen mock-up is not proof of support; the records, actions, rules, evidence, and correction path must be explained.
Executable scenario contracts
Section titled “Executable scenario contracts”These key cases use Given/When/Then form so the expected clinical outcome can later be tested in documentation, acceptance criteria, or software without changing their meaning.
EX-01 — Consent safely gates screening
Section titled “EX-01 — Consent safely gates screening”Given Site 101 is active for EDC with Design Publication 3 and no consent confirmation exists
for the potential participant.
When the site tries to enter eligibility or screening laboratory data.
Then EDC refuses study-specific screening entry with reason Consent confirmation required.
Given the site records the approved consent version, actual consent time, person obtaining
consent, participant/LAR basis, and evidence reference.
When the authorized site user starts screening.
Then EDC creates one Subject, Screening Attempt, and Casebook under Design Publication 3 and
retains the consent confirmation before the first screening datapoint.
EX-02 — Reused item has placement-specific behavior
Section titled “EX-02 — Reused item has placement-specific behavior”Given one Systolic Blood Pressure Item Definition is placed in Screening and Week 4 with
different instructions and requiredness.
When Design Publication 2 is approved.
Then both Item Placements reference the same clinical definition, retain their own contextual
rules, and produce distinct subject datapoints.
EX-03 — Datapoint survives compatible amendment
Section titled “EX-03 — Datapoint survives compatible amendment”Given a submitted Week 4 weight datapoint exists for its exact casebook/event/form/row/item
placement and the casebook uses Design Publication 1.
When the casebook adopts Publication 2, which changes only help text for that placement.
Then the datapoint identity and prior revision remain unchanged; later correction records
Publication 2 as its design context.
EX-04 — Visit decisions remain independent
Section titled “EX-04 — Visit decisions remain independent”Given Week 8 is applicable and displayed, but its availability date has not arrived.
When the site views the casebook.
Then Week 8 appears as expected but cannot be opened. Being displayed does not make it
available, and being outside its window does not by itself mark it not applicable or incomplete.
EX-05 — Query routing and cancellation
Section titled “EX-05 — Query routing and cancellation”Given an open query was routed to the wrong site and an equivalent correct query already exists.
When the data manager reviews it.
Then EDC cancels the duplicate with reason, retains its messages and routing history, and keeps
the original query active with its age and escalation history unchanged.
EX-06 — Whole-study database reopen and relock
Section titled “EX-06 — Whole-study database reopen and relock”Given the whole-study database is locked for final analysis and one subject requires an urgent
safety correction.
When authorized approvers accept a Reopen Authorization limited to that casebook and datapoint.
Then only the authorized correction proceeds; affected checks, query disposition, SDV/DMR,
coding, and Signature Requirement are reassessed; a new whole-study Database Lock and delivery are
created with comparison to the prior lock.
Study build and release
Section titled “Study build and release”EDC-01 — Reuse one CRF at several visits
Section titled “EDC-01 — Reuse one CRF at several visits”The Vital Signs CRF is used at Screening, Baseline, and Week 4. The CRF definition is shared, but each placement and subject occurrence remains distinct. A placement-specific instruction does not create ambiguous data identity.
EDC-02 — Independent CRF variant
Section titled “EDC-02 — Independent CRF variant”Week 4 needs an additional protocol-specific question. The designer detaches/copies the CRF with source history rather than accidentally changing Screening and Baseline.
EDC-03 — Ambiguous repeating-row derivation
Section titled “EDC-03 — Ambiguous repeating-row derivation”A rule says “use adverse-event severity,” but several adverse events exist. Validation refuses publication until an occurrence selector is explicit.
EDC-04 — Site approval after design publication
Section titled “EDC-04 — Site approval after design publication”The design is approved and published globally, but Site 103 lacks a required local approval. The design is available but EDC activation for Site 103 is refused with visible clinical reason.
Site, subject, and schedule conduct
Section titled “Site, subject, and schedule conduct”EDC-05 — Screening creates casebook
Section titled “EDC-05 — Screening creates casebook”Site 101 obtains informed consent using the approved consent version. The site confirms consent in EDC, then creates the subject and casebook under the site’s active design before eligibility and screening laboratory CRFs are entered. Later screen failure retains the consent confirmation, screening data, and audit history.
EDC-06 — Rescreen after screen failure
Section titled “EDC-06 — Rescreen after screen failure”The participant returns under the protocol’s rescreen policy. The new attempt and its relationship to the prior failed attempt are visible without merging or duplicating screening history silently.
EDC-07 — Correct subject number
Section titled “EDC-07 — Correct subject number”The site corrects a mistyped subject number. Stable identity, data, queries, coding, signatures, and audit history remain attached; number history records the correction.
EDC-08 — Treatment discontinued, follow-up continues
Section titled “EDC-08 — Treatment discontinued, follow-up continues”The subject stops treatment but remains in survival follow-up. Treatment disposition does not close the casebook or make future follow-up events unavailable.
EDC-09 — Unscheduled visit
Section titled “EDC-09 — Unscheduled visit”The site adds the next permitted unscheduled event. It receives a stable sequence and correct forms without changing the planned-visit definitions.
EDC-10 — Corrected visit anchor
Section titled “EDC-10 — Corrected visit anchor”Actor: Delegated site user correcting Baseline date.
Given: Week 4 is applicable, opened, and has a recorded planned window derived from the prior
Baseline date; the schedule rule and correction policy are effective.
When: the user submits an authorized Baseline-date correction with reason.
Then: EDC retains the prior date/window, records the corrected date, reevaluates Week 4 timing,
and leaves applicability, availability, conduct, and completion unchanged unless their own rules act.
Refuse when: Baseline or Week 4 is locked and no matching Reopen Authorization exists.
Superseded evidence: timing/window evidence based on the old anchor is superseded; unaffected
form review and signature evidence remains current.
Audit: actor, authority, reason, old/new date revisions, schedule-rule version, prior/new window,
timing result, refusal or reopen reference.
EDC-11 — Dynamic form now inapplicable
Section titled “EDC-11 — Dynamic form now inapplicable”Actor: Delegated site user correcting the controlling answer.
Given: the condition made a dynamic form applicable; the form contains submitted data and a
current investigator signature.
When: an authorized correction makes the condition false.
Then: EDC records applicability as not applicable, retains the form and data, and creates an
Applicability Conflict for authorized disposition; it does not delete the occurrence.
Refuse when: the containing scope is locked without Reopen Authorization, or the user attempts
automatic removal of the nonblank form.
Superseded evidence: the prior signature and affected completion/review evidence are flagged or
superseded according to policy; historical applicability remains visible.
Audit: controlling revisions, condition version/evaluations, form contents, signature reference,
actor/reason, conflict decision, and any later re-signature.
Entry, absence, and correction
Section titled “Entry, absence, and correction”EDC-12 — Partial adverse-event date
Section titled “EDC-12 — Partial adverse-event date”Month and year are known but day is unknown. The date is retained structurally without inventing the first day of the month; dependent calculations become determinate or indeterminate by policy.
EDC-13 — Required value unavailable
Section titled “EDC-13 — Required value unavailable”The assessment was attempted but unavailable because equipment failed. The site records a governed missing reason rather than a blank or fabricated value; query behavior follows study policy.
EDC-14 — Invalid input attempt
Section titled “EDC-14 — Invalid input attempt”The user types text into a decimal item. It does not become clinical truth. The accepted correction and any retained invalid-attempt evidence remain distinguishable.
EDC-15 — Imported corrected laboratory result
Section titled “EDC-15 — Imported corrected laboratory result”A central laboratory sends a corrected result. The prior imported revision remains visible, the new revision identifies its correction package, and affected checks/reviews are reconciled.
Checks, queries, and review
Section titled “Checks, queries, and review”EDC-16 — Correct but out of range
Section titled “EDC-16 — Correct but out of range”An edit check opens a query. The site confirms the value is correct without changing it. The query is answered and may be closed while the clinical value and failed-range context remain traceable.
EDC-17 — Data changed but query unanswered
Section titled “EDC-17 — Data changed but query unanswered”Actor: Delegated site user correcting a queried value.
Given: an open query and failing check evaluation target the current datapoint revision.
When: the user corrects the value but sends no query response.
Then: EDC creates a new datapoint revision and reevaluates the check; the finding may resolve,
but the query remains Open until the site answers or an authorized reviewer dispositions it.
Refuse when: the datapoint is frozen/locked without the required unfreeze/reopen authority.
Superseded evidence: the prior current value and check evaluation are superseded; query messages
and aging remain unchanged.
Audit: old/new value, correction reason, check results, query status, actor, timestamps, and any
later response/closure.
EDC-18 — Answer inadequate
Section titled “EDC-18 — Answer inadequate”The site answers without resolving the discrepancy. The reviewer returns/re-queries within the same conversation rather than opening unrelated history.
EDC-19 — Check changed by amendment
Section titled “EDC-19 — Check changed by amendment”A revised check makes an old system finding obsolete. Prior evaluations and query conversation remain visible; current status says why no active discrepancy remains.
EDC-20 — Risk-based SDV override
Section titled “EDC-20 — Risk-based SDV override”A serious adverse event triggers 100% SDV despite the subject’s normal sampled plan. Requirement, review evidence, and later data-change behavior are explainable.
EDC-21 — Reviewed data changed
Section titled “EDC-21 — Reviewed data changed”Actor: Delegated site user correcting previously reviewed data.
Given: the current datapoint revision has completed SDV and is included in completed DMR evidence.
When: an authorized correction creates a new revision.
Then: EDC identifies the exact SDV and DMR evidence affected, applies the study’s material-change
policy, and creates new review requirements where needed; unrelated review remains current.
Refuse when: a freeze/lock prevents correction or required reason/authority is missing.
Superseded evidence: prior SDV/DMR remains readable but is marked superseded or changed-after-
review; any declared immaterial decision retains reviewer and rationale.
Audit: old/new revisions, affected review identifiers, policy version, reassessment outcome,
reviewers, reasons, and completion of renewed review.
Coding and signature
Section titled “Coding and signature”EDC-22 — Coding context changes
Section titled “EDC-22 — Coding context changes”The medication verbatim remains the same but route changes. The coding request becomes Needs Recoding according to configuration because the original decision used that context.
EDC-23 — Dictionary up-version
Section titled “EDC-23 — Dictionary up-version”One approved term remaps uniquely; another has no current equivalent. The first retains remapping history; the second becomes Noncurrent and requires review.
EDC-24 — Coding query
Section titled “EDC-24 — Coding query”The coder cannot distinguish two products from the verbatim. A site query requests clarification; the coding decision waits without overwriting the original verbatim.
EDC-25 — Post-signature correction
Section titled “EDC-25 — Post-signature correction”Actor: Authorized site user; investigator performs later re-signature.
Given: a Signature Requirement is satisfied by a signature covering the submitted form revisions,
and a query has been validly reopened.
When: the site corrects covered data with reason.
Then: EDC retains the old signature, marks it superseded for the changed scope, changes the
Signature Requirement to Needs re-signature, and permits a new signature only after prerequisites pass.
Refuse when: the form is locked without Reopen Authorization, correction exceeds authorized
scope, or the signer lacks current authority.
Superseded evidence: prior signature and any affected review evidence remain readable with the
change that superseded them.
Audit: reopened query, correction, covered-data inventories before/after, attestation versions,
signer authority, old/new signatures, and timestamps.
EDC-26 — Blinded data excluded
Section titled “EDC-26 — Blinded data excluded”The investigator signs a casebook while specified blinded central data are excluded. The signature covered-data inventory and attestation make the exclusion explicit.
Amendment and lock
Section titled “Amendment and lock”EDC-27 — Add form to completed visit
Section titled “EDC-27 — Add form to completed visit”Actor: Authorized study data manager applying an approved Casebook Design Adoption.
Given: a completed visit under Publication 1; Publication 2 adds a required CRF; compatibility
assessment is complete.
When: adoption is authorized and applied.
Then: EDC records the new publication assignment, creates the new CRF occurrence as Not started,
marks visit completion Incomplete, and creates applicable review/signature requirements.
Refuse when: the casebook is locked without Reopen Authorization or required conflicts are unresolved.
Superseded evidence: prior visit-completion and signature evidence is retained and marked affected;
unaffected datapoints preserve identity.
Audit: publications, assessment, actor/authority, created CRF placement, affected requirements,
refusal/conflicts, and adoption time.
EDC-28 — Remove populated form
Section titled “EDC-28 — Remove populated form”Actor: Authorized study data manager applying an amendment.
Given: the target publication removes a CRF whose subject occurrence contains data, queries, and
review evidence.
When: compatibility assessment evaluates that casebook.
Then: EDC creates a destructive-change conflict and requires an approved retain-as-inactive or
other explicit resolution; no record is deleted.
Refuse when: adoption is attempted without conflict resolution or against a locked casebook.
Superseded evidence: evidence remains attached to retained records; current expectedness changes
only after approved resolution.
Audit: removed placement, contained record inventory, conflict, decision maker, reason, chosen
resolution, and final adoption result.
EDC-29 — Locked casebook blocks adoption
Section titled “EDC-29 — Locked casebook blocks adoption”Actor: Authorized study data manager running an approved adoption plan.
Given: selected casebooks passed compatibility review except one with an applicable Scoped Lock.
When: adoption runs.
Then: eligible casebooks adopt the target publication; the locked casebook remains on its prior
publication with a visible Not applied result and required next action.
Refuse when: any attempt is made to bypass the lock or report the plan as fully complete.
Superseded evidence: none for the skipped casebook; adopted casebooks reassess only affected evidence.
Audit: per-casebook prior/target publication, applied/skipped/failed result, lock reference,
actor, batch/adoption identifier, and later resolution.
EDC-30 — Database-lock readiness failure
Section titled “EDC-30 — Database-lock readiness failure”Actor: Database-lock lead requesting whole-study final-analysis lock.
Given: one coding request is incomplete and one required external reconciliation remains open.
When: Lock Readiness Assessment is evaluated.
Then: readiness records both failures and Database Lock is not authorized.
Refuse when: the lead attempts to lock without completing them or obtaining exceptions explicitly
allowed and approved by policy.
Superseded evidence: an older passed readiness result is stale if later data or reconciliation
changes occurred.
Audit: readiness-policy version, each check/result/source time, exceptions requested/approved or
rejected, actor, and lock refusal.
EDC-31 — Correct one subject after lock
Section titled “EDC-31 — Correct one subject after lock”Actor: Authorized site user corrects data after sponsor-authorized reopening.
Given: the whole-study database is locked for final analysis and an urgent source-supported safety
correction is identified for one datapoint.
When: required approvers authorize reopening limited to that casebook/datapoint and the correction occurs.
Then: EDC permits only the authorized change, reassesses affected check/query/review/coding/
signature evidence, repeats whole-study readiness, creates a new Database Lock, and produces a new
delivery compared with the prior one.
Refuse when: approval, source evidence, exact scope, or impact assessment is missing, or attempted
changes exceed authorization.
Superseded evidence: prior Database Lock remains historical; affected evidence is marked with its
replacement/current status; unrelated evidence remains current.
Audit: request, approvals, scope, reason, old/new value, all reassessments, prior/new lock,
delivery difference inventory, actors, and times.
EDC-32 — Interim analysis cut
Section titled “EDC-32 — Interim analysis cut”A data cut that cannot be changed is produced while data entry continues. It remains reproducible and is not misrepresented as final database lock.
EDC-33 — Relock delivery comparison
Section titled “EDC-33 — Relock delivery comparison”After correction and relock, a new delivery package is produced. Its included-record inventory explains every difference from the original locked package and retains both deliveries.
Acceptance questions for every scenario
Section titled “Acceptance questions for every scenario”- Which clinical records exist before the action?
- Who may take the action, and on what authority?
- Which business rule permits or refuses it?
- What becomes current afterward?
- What prior information remains visible?
- Which checks, queries, reviews, codes, signatures, freezes, or locks are affected?
- Which external product receives or supplies a fact?
- What would a monitor, data manager, investigator, auditor, or inspector see later?