Skip to content

eTMF domain model

The eTMF is the controlled body of essential records used to manage a clinical trial and to show how the trial was conducted. It must allow a monitor, auditor, or inspector to understand the trial without depending on the memory of the original study team.

The model must answer practical TMF questions:

  • What evidence should exist for this study, country, or site?
  • Why is it expected, when is it due, and who is responsible for it?
  • Is the correct final version filed in the correct place?
  • Is it complete, readable, approved where necessary, and filed on time?
  • Where is the authoritative record if it is kept outside the primary eTMF?
  • What remains missing, questionable, or inaccessible?
  • Can the records, decisions, and sequence of trial conduct be reconstructed for inspection?

The eTMF records evidence of clinical operations. It does not own the visit, approval, safety report, training, shipment, or data-management activity that produced that evidence.

The six meanings that must remain separate

Section titled “The six meanings that must remain separate”
Term Meaning in TMF operations Example
Reference Model Release A published taxonomy of types of trial records The release that defines the artifact for a site initiation visit report
Filing Plan Revision The approved study-specific decision about what will be filed, by whom, where, and when Revision 3 adds expectations created by Protocol Amendment 2
Document Expectation A rule saying when a kind of record is required Expect a monitoring report for every completed monitoring visit
Filing Slot One concrete record need for a particular study, country, site, person, organization, product, or event The report for the 12 May monitoring visit at Site DE-014
TMF Document The identity of the actual trial record Site DE-014 Monitoring Visit Report, 12 May
Document Version One exact edition whose content cannot be edited after finalization Final version 1.0, followed later by corrected version 2.0

A Reference Model Release does not make every artifact applicable to every study. A Document Expectation does not prove that the record exists. An uploaded file is not automatically an acceptable TMF Document. A newer Document Version must not erase the version that governed earlier conduct.

One repeated occurrence creates one Filing Slot. A slot has at most one accepted evidence set, which normally contains one exact Document Version and may contain several only when the evidence is genuinely composite and explicitly reviewed.

Choose a Reference Model Release
↓
Approve a Filing Plan Revision
↓
Create Document Expectations
↓
Generate Filing Slots for the actual study, countries, sites, and events
↓
Receive content; create and classify the TMF Document and Document Version
↓
Prepare proposed filing placement and candidate Filing Slot matches
↓
Complete required approval and QC against that exact version and classification
↓
Finalize the Document Version so its content can no longer be edited
↓
Activate its filing placement and accept its Filing Slot evidence set
↓
Measure completeness, timeliness, and quality with stated denominators
↓
Demonstrate inspection readiness
↓
Reconcile, archive, retain, transfer, export, and eventually destroy lawfully

This is the single record journey used throughout the eTMF model. Classification and candidate matches may be prepared before finalization, but a Document Version is not authoritatively filed and cannot fulfil a Filing Slot until finalization is complete. Effectiveness is a separate clinical date—for example, when a protocol amendment begins to govern conduct—and is not a substitute for filing.

One clinical trial has one overall TMF, usually comprising a sponsor-maintained portion and investigator/institution-maintained portions commonly called investigator site files. These portions have different record ownership and access rules.

  • The sponsor remains responsible for oversight of sponsor TMF activities delegated to service providers.
  • The investigator/institution retains control of investigator-generated records and directly identifying participant records.
  • Sponsor oversight does not create unrestricted access to investigator-controlled records.
  • Essential records may remain in a declared source system, but their location, responsible party, retention, access, and retrieval must be known.
  • The primary eTMF is not necessarily the physical home of every essential record.
  1. Reference model and filing plan — taxonomy adoption, study-specific planning, responsibilities, locations, and revision control.
  2. eTMF roles and permissions — feature visibility and exact actions for planning, contribution, classification, QC, finalization, inspection and archive.
  3. Expected TMF content — Document Expectations, Filing Slots, applicability, counts, milestones, and fulfilment.
  4. Document intake and filing — receipt, classification, metadata, filing, duplicate assessment, refiling, and withdrawal.
  5. Versions, renditions, and certified copies — protected final versions, dynamic content, signature pages, supersession, and copy certification.
  6. Quality control and findings — record-level and TMF-level review, findings, corrections, verification, and approval.
  7. Completeness, timeliness, and quality — reproducible measures with exact populations, dates, and exceptions.
  8. Inspection readiness — readiness assessment, controlled access, active-study inspections, and disclosed record sets.
  9. Archive, retention, and export — closeout reconciliation, custody, holds, retrieval, transfer, export, and destruction.
  10. Actions, rules, and audit evidence — what users may do, when it must be refused, and what evidence remains.
  11. Clinical scenarios and product decisions — adversarial walkthroughs and decisions requiring TMF product review.

This is a product-manager review candidate. It describes the clinical meaning and required behaviour of TMF operations. It does not prescribe how a software team must implement them. Open choices are preserved in the decision ledger rather than hidden in generic document terminology.

The model is grounded in: