Actions, rules, and audit evidence
Action catalogue
Section titled “Action catalogue”| Action | Required before the action | Result | Audit evidence retained |
|---|---|---|---|
| Approve a Filing Plan Revision | Responsibilities, locations, timing, QC, access, and archive arrangements decided | Approved revision awaiting or entering effect | Revision, each decision, approver role, date, signature where required |
| Generate Filing Slots | Effective plan and verified trial scope or triggering event | Concrete expected record needs | Source expectation, trigger, scope, due calculation, generator, time |
| Decide applicability | Authorized owner and sufficient study facts | Required, Not Required, or continuing Pending Decision | Prior/new status, rationale, evidence, decider, time |
| Receive content | Source and original content captured safely | Intake item | Source channel, sender, receiver, time, original metadata, checksum |
| Classify a TMF Document | Content reviewed; study and filing scope resolved | Record type and context confirmed | Proposed and confirmed values, actor/rule, confidence if automated, time |
| Revise classification | Corrected record meaning is supported and affected filing is identified | New current classification revision; prior revision superseded | Before/after classification, taxonomy mapping, reason, decision, affected versions and placements |
| Revise metadata | Correct value and correction authority established | New current metadata revision; prior revision superseded | Before/after values, source, reason, actor, time, review or verification |
| File a Document Version | Final version, valid current classification and metadata, accepted required QC, valid scope, permission | Proposed placement becomes Active and, when approved, Filing Slot evidence set is accepted | Placement identifier, exact version/classification/metadata/plan pins, scope, role, activator, filed time |
| End a Filing Placement | Active placement, authorized reason, and any successor placement identified | Placement becomes Ended and cannot be reactivated | Placement identifier, ended by/time, end reason, succeeding placement if any |
| Confirm an externally held version | Exact external version, owner, location, access, retention, finality, and retrieval verified | Externally held record reference eligible for filing and slot matching | External identity, integrity evidence, verifier, retrieval result, restrictions, time |
| Match to a Filing Slot | Exact version is suitable evidence | Proposed or accepted fulfilment | Slot, version, matcher, decision, count contribution, rationale |
| Refile a misclassified version | Incorrect and correct placement identified | Old placement ended; correct placement created | Before/after values, reason, actor, time, QC finding if required |
| Finalize a Document Version | Required components, metadata, approvals, QC, and access controls complete | Final version whose content can no longer be edited and is eligible for filing | Exact content checksum, conditions, decisions, finalizer, time |
| Supersede a Document Version | New final version and replacement reason | Earlier version retained as superseded | Version lineage, reason, effective dates, affected matches |
| Withdraw a version | Authorized decision and impact assessment | Version no longer current evidence | Reason, decision-maker, date, replacement, affected slots |
| Certify a copy | Original and copy compared by approved person/process | Copy eligible to replace original | Method, verifier, fidelity checks, metadata, date |
| Open a QC request | Exact review scope, required criterion versions, owner, and due date are known | Assigned governed review | Requester, basis, scope, criteria, assignee, independence rule, due date |
| Complete a QC round | Exact version/classification/metadata or population fixed; every applicable criterion decided | Accepted, accepted with findings, or rework required | Round number, evidence state, criterion results, reviewer, findings, timestamps |
| Correct a finding | Correction completed and evidence supplied | Ready for verification | Original issue, correction, new version/metadata/placement, actor, time |
| Verify a finding | Authorized verifier confirms resolution | Closed, non-issue, or exception decision | Verification evidence, verdict, rationale, verifier, time |
| Produce a measure snapshot | Scope, cut-off, plan, rule, and population known | Reproducible completeness/timeliness/quality result | Members, exclusions, numerator, denominator, result, producer, time |
| Assess inspection readiness | Defined scope and supporting retrieval, access, quality, and measure evidence | Dated readiness conclusion | Criteria, evidence, limitations, conclusion, assessor, actions |
| Provide inspection access | Authorized request, scope, record set, privacy/blinding review | Time-limited read-only access | Approver, recipient, scope, dates, access and export history |
| Approve archive package | Reconciliation complete and exceptions decided | Package protected for retention | Index, content manifest, checksums, approvals, location, obligations |
| Transfer archive custody | Approved recipient and verified package | Responsibility/location transferred prospectively | Sender, recipient, manifest, verification, discrepancies, acceptance |
| Apply or release a hold | Authorized basis and exact scope | Destruction prevented or hold ended | Authority, reason, scope, actor, dates, release decision |
| Authorize destruction | Retention expired, holds clear, ownership confirmed | Approved records securely destroyed | Eligibility evidence, approvers, manifest, method, certificate |
One authoritative document journey
Section titled “One authoritative document journey”Every record held in the primary eTMF follows the same ordered journey:
- Receive: preserve the intake content and source evidence.
- Identify: create or select the TMF Document and create the exact Document Version.
- Classify and index: approve or prepare the classification revision and metadata revision.
- Prepare filing: propose the filing placement and candidate Filing Slot matches.
- Review: complete required content approval and the required QC Round against that exact content, classification revision, metadata revision, and proposed placement.
- Finalize: prevent further content editing after all blocking conditions pass.
- File: activate the placement for the final Document Version.
- Fulfil: accept one evidence set for each Filing Slot that the filed version legitimately satisfies.
Steps 1–4 may be repeated during preparation. Steps 6–8 occur in order. A filed placement cannot be active for a non-final version, and a Filing Slot cannot be fulfilled by a version whose filing placement is merely proposed. If required review later fails because classification or metadata changed, affected filing and fulfilment decisions return to review without altering the historical finalization evidence.
An externally held version uses the same clinical gates, while its responsible source system supplies the native finality evidence and the eTMF records the governed external filing reference.
Exception decision
Section titled “Exception decision”An exception decision records an authorized choice to proceed despite a stated TMF requirement that is not met. It does not change the underlying fact. A late document remains late; a missing document remains missing; a failed criterion remains failed.
| Field | Meaning |
|---|---|
| Exception identifier | Stable identity |
| Affected subject | Filing Slot, Document Version, quality finding, milestone, readiness assessment, archive item, or other exact scope |
| Requirement not met | Filing Plan Revision rule, QC criterion, due date, archive condition, or other governed requirement |
| Facts and reason | Observable condition and why normal correction is not currently possible or proportionate |
| Impact assessment | Participant protection, trial reliability, compliance, reconstructability, privacy, blinding, and operational impact |
| Proposed controls | Corrective action, additional evidence, restricted access, monitoring, or time limit |
| Requested by and time | Attribution |
| Required decision roles | TMF, functional, quality, privacy, archive, or other accountable roles based on risk |
| Decision | Approved, Rejected, or More Information Required |
| Effective period | Start, expiry, and review date for a temporary decision |
| Follow-up | Owner, due date, completion, and verification |
| Closure | Resolved, Expired, Revoked, or Permanently Accepted with authority and reason |
Status journey:
Draft → Under review → Approved → Resolved │ ├────→ Expired │ └────→ Revoked ├────────────→ Rejected └────────────→ More information requiredAn affected item may have several historical exception requests but at most one current approved decision for the same unmet requirement and effective period. Approval is refused if the scope, requirement, impact, responsible approver, controls, or expiry/review treatment is missing. An exception never deletes a Quality Finding or changes historical measure snapshots.
| Action | Required before the action | Result | Audit evidence retained |
|---|---|---|---|
| Request an exception | Exact unmet requirement, subject, facts, impact, controls, and proposed period identified | Exception ready for accountable review | Requester, time, requirement, evidence, impact, proposed controls |
| Decide an exception | All required roles decide with sufficient evidence | Approved, rejected, or returned for information | Each decision, role, rationale, conditions, effective period |
| Close or revoke an exception | Resolution, expiry, changed risk, or withdrawal established | Historical decision closed without changing underlying facts | Closure reason, evidence, actor, time, affected measures/findings |
Rules that must always hold
Section titled “Rules that must always hold”Filing plan and expectation rules
Section titled “Filing plan and expectation rules”- Every Filing Slot traces to the Filing Plan Revision and Document Expectation that created it.
- Only one Filing Plan Revision governs a study at a given time.
- Superseding a plan never erases earlier instructions or decisions.
- Not Required and exception outcomes require a complete, named, dated Exception Decision or applicability decision as appropriate.
- Operational events create expectations or make them due; they do not create acceptable TMF evidence automatically.
- A replacement Filing Plan Revision cannot become effective until every old/new expectation and open Filing Slot has a stated reconciliation treatment.
Document and version rules
Section titled “Document and version rules”- Every filed item has a known TMF Document and exact Document Version.
- Each TMF Document has exactly one current classification revision; governed metadata has exactly one current revision for its subject.
- A finalized version retains the exact classification and metadata revisions used for review and filing.
- Final content cannot be edited; a content correction creates another Document Version.
- Superseded final versions remain when needed to reconstruct conduct.
- Filing corrections preserve the incorrect placement and correction history.
- A rendition remains linked to the exact source version and does not silently replace it.
- A copy replacing an original has explicit certification evidence.
- Directly identifying investigator-controlled records do not become sponsor-controlled TMF content.
Fulfilment and measure rules
Section titled “Fulfilment and measure rules”- A Filing Slot is fulfilled only by its one accepted evidence set containing one or more exact Document Versions.
- Each repeated occurrence has its own Filing Slot; quantity is never hidden inside one slot.
- Draft, rejected, withdrawn, illegible, and excluded duplicate versions do not contribute to current completeness.
- Additional evidence never improves completeness and is not a Filing Slot status; it requires reconciliation.
- Late filing may restore completeness but never erases lateness.
- Every reported measure retains scope, cut-off, plan, rule, population, numerator, denominator, and exclusions.
- Operational milestone completion does not imply TMF completeness or inspection readiness.
- An Exception Decision never changes the underlying missing, late, failed, or inaccessible fact.
Quality and access rules
Section titled “Quality and access rules”- A QC result applies only to the exact Document Version, classification revision, metadata revision, criterion versions, and scope reviewed.
- One QC Request retains every QC Round; a successful later round never erases failed earlier rounds.
- Corrected and verified are separate outcomes.
- A closed finding retains its original observation, correction, verification, and decision history.
- Access requires study scope, responsibility, confidentiality, privacy, and blinding permission.
- Archived and inspection access is read-only and attributable.
Archive rules
Section titled “Archive rules”- Archive approval requires a reconciled index, content, metadata, audit evidence, Exception Decisions, and integrity manifest.
- Transfer changes responsibility prospectively and preserves prior custody history.
- A failed archive retrieval test creates a quality issue and recovery obligation.
- Destruction requires expiry of all obligations, release of all holds, ownership confirmation, authorization, and a certificate.
Refusal catalogue
Section titled “Refusal catalogue”The product must clearly explain why it refuses to:
- approve a filing plan with unowned records or inaccessible locations;
- mark a Filing Slot Not Required without a reason and responsible decision-maker;
- count an upload before classification, QC acceptance, and exact version matching;
- finalize incomplete, illegible, unsigned, misclassified, or improperly exposed content;
- overwrite a final Document Version;
- silently move matches from a superseded version to a replacement;
- delete content merely because it appears duplicated;
- claim that a scan is certified without certification evidence;
- allow blinded users to see unblinded content;
- allow sponsor access to directly identifying investigator-controlled records;
- close a blocking finding without required verification;
- report a measure with a hidden denominator or changed historical rule;
- claim inspection readiness without retrieval, access, audit-history, and quality evidence;
- archive an unreconciled TMF without declared exceptions;
- destroy content under an active retention obligation or hold.
Minimum audit statement
Section titled “Minimum audit statement”For each material action, retain:
- who or what acted and the clinical/TMF role used;
- date, time, and time zone;
- the exact Study, Filing Plan Revision, Filing Slot, TMF Document, and Document Version affected;
- previous and new values or statuses;
- reason and supporting evidence;
- required review, approval, or signature;
- automatic rule/model/procedure version when automation participated;
- resulting relationships, findings, measures, exports, or disclosures.
The audit evidence must allow reconstruction without relying on application logs that have lost the clinical meaning of the action.