Skip to content

Document intake and filing

Receiving a file proves only that content arrived. It does not prove what the content is, which study it belongs to, whether it is final, whether it is a duplicate, or whether it is acceptable TMF evidence.

The intake process preserves the received content before classification so that later actions can be reconstructed.

An intake item is content received for possible inclusion in the TMF.

Field Meaning
Received content The original bytes or physical-item reference as received
Source channel Upload, email, scan, integration, transfer package, mobile capture, or physical receipt
Received by and time Who or what received it, using a recorded time zone
Sender or originating system Known source of the content
Original file name, format, size, and checksum Evidence of exactly what arrived
Proposed study context Study, Country, Site, Person, Organization, Product, or Event if supplied
Proposed record type Suggested classification, never treated as confirmed solely because it was supplied
Processing restrictions Blinded/unblinded, confidential, personal data, malware quarantine
Related message or package Email, attachment set, transfer manifest, or scan batch
Received → Safety and readability check → Classification pending → Classified
├────────────────────────────────────→ Quarantined
├────────────────────────────────────→ Rejected from TMF
└────────────────────────────────────→ Duplicate review

The original receipt remains traceable after classification, rejection, or duplicate handling.

Classification may:

  1. create a new TMF Document and its first Document Version;
  2. add a new Document Version to an existing TMF Document;
  3. attach content to a planned Filing Slot while creating the TMF Document;
  4. identify the item as a possible duplicate;
  5. reject the item because it is unrelated, corrupt, unsafe, or not suitable for TMF retention.

Classification prepares the record for review. It may create a proposed filing placement and candidate Filing Slot matches, but it does not authoritatively file the version. Required approval and QC occur against that exact content and classification; the Document Version is then finalized; only after finalization is its filing placement activated and its evidence set accepted.

Field Meaning
Document identifier Stable identity across its versions
Document lineage The Document Versions that belong to this continuing record identity
Related-document lineage Governed translation, certified-copy, rendition-source, attachment, or replacement relationships to other TMF Documents

The TMF Document owns only its stable identity and lineage. It does not own mutable title, classification, dates, scope, language, access, location, or “current version” values.

The product may show a convenient current summary, but every value is derived and labelled with its source. It is not another editable copy of the record.

Summary value Governed source
Current title, originator, dates, language, confidentiality, privacy, and blinding Current metadata revision for the stated subject and as-of time
Current record type and reference mapping Current classification revision
Current filing scope and authoritative location Active Filing Placement or externally held record reference
Responsible record owner Current governed responsibility assignment
Current Document Version Derived for a stated filing scope and as-of time using the rule below

Every displayed summary identifies the source revision or placement and its effective date. A user changes the governed source, never the summary.

“Current” is always evaluated for a stated filing scope and as-of time. There may be no single study-wide current version when countries or sites implement different versions concurrently.

  1. Consider only Document Versions that were Final by the cut-off and had an Active primary Filing Placement for the stated scope at that time.
  2. Exclude versions withdrawn for that scope before the cut-off.
  3. Apply governed supersession decisions using their exact scope and effective time.
  4. If one version remains, it is current for that scope and time.
  5. If none remains, no current version exists.
  6. If more than one remains without an explicit relationship explaining concurrent applicability, report a current-version conflict and require review; do not choose by filename, version number, or upload time.

A draft or merely newer-numbered version never becomes current. The result is a derived summary and does not alter version history.

When the authoritative content remains outside the primary eTMF, the TMF Document and exact Document Version are represented by an externally held record reference. The reference must pass the same clinical acceptance journey and retrieval checks; location alone is not evidence that the record exists or is usable.

Classification answers two different questions:

  • What kind of trial evidence is this? The record type and reference artifact.
  • To what part of the trial does it apply? Study, Country, Site, Person, Organization, Product, Committee, Event, and meaningful date.

Both must be confirmed. A correct record type filed against the wrong site is still misfiled.

Required checks before classification completes:

  • the study is known and the record genuinely belongs to it;
  • country and site identifiers resolve to the intended trial participation, not merely a similar name;
  • the record type matches the content rather than the filename;
  • the meaningful document date and date type are populated;
  • document language, version, and originating party are known where required;
  • participant privacy and blinding are correctly identified;
  • the user may see and classify the content;
  • possible duplicates have been assessed or explicitly left for review.

Automated suggestions may propose values with confidence and explanation. A suggestion is not audit evidence of a human decision unless the approved process permits automatic acceptance and records the rule/model version used.

A classification revision preserves each governed decision about what kind of evidence a TMF Document is. It prevents a later correction from making the original classification disappear.

Field Meaning
TMF Document Record being classified
Revision number and status Draft, Current, Superseded, or Rejected
Record type and artifact mapping Confirmed clinical/TMF meaning under a stated taxonomy version
Proposed filing level Study, Country, Site, or other permitted level
Basis Content examined, source context, and classification guidance used
Decided by and time Human or approved automatic decision with role and rule/model version
Effective from When this classification became current
Replaces Prior classification revision, when correcting or changing it
Reason and review Required explanation and any QC or approval

A TMF Document has exactly one current classification revision and may have many superseded revisions. A final Document Version retains the classification revision used for its QC, finalization, and filing. Changing the current classification after finalization therefore does not rewrite what was previously reviewed; affected placements, matches, and measures must be reassessed.

A metadata revision preserves the governed values used to identify, find, order, protect, and interpret a TMF Document or exact Document Version.

Field Meaning
Subject TMF Document or exact Document Version
Revision number and status Draft, Current, Superseded, or Rejected
Values Title, dates and date types, author/originator, language, version label, scope, confidentiality, privacy, and blinding as applicable
Reason Initial indexing, source correction, confirmed misfile, self-evident correction, or other governed reason
Changed by and time Attribution
Effective from When the values became current
Previous revision Full history link
Review or verification Required review and finding, where applicable

One current metadata revision exists for each governed subject. Material metadata used during QC, finalization, filing, or disclosure is pinned to the exact revision used. A corrected value never appears as though it existed before the correction.

A filing placement states where and why an exact Document Version belongs in the TMF.

Field Meaning
Placement identifier Stable identity for this filing decision and its history
Document Version Exact content being filed
Classification revision Exact approved record type and artifact mapping used
Metadata revision Exact title, dates, scope, access, and other governed values used
Filing scope Exact study/country/site/other context
Placement role Primary placement or controlled cross-reference
Filing Plan Revision Exact approved instructions applied
Status Proposed, Active, Ended, or Rejected
Proposed by and time Who prepared the placement and when
Activated by and filed time Who authoritatively filed it and the filing clock endpoint
Rejected by, time, and reason Why a proposal was not activated and who decided
Ended by and time Who ended an active placement and when
End reason Misfile correction, superseded version, withdrawal, duplicate resolution, custody/location change, or another governed reason
Previous and succeeding placement Required lineage when correcting or replacing a placement
Filing reason Required for unusual placement or cross-reference
Proposed → Active → Ended
└────────────→ Rejected

A proposed placement supports QC but is not authoritative filing. Activation pins exactly one Document Version, classification revision, metadata revision, and Filing Plan Revision. Those pins never move. If any of them changes, reassess the filing and create a succeeding placement where required rather than editing the active placement’s historical meaning.

One authoritative placement normally represents the record. Controlled cross-references may make the same record discoverable in another appropriate location without creating duplicate content or double counting completeness.

One Document Version may have many historical placements and controlled cross-references, but at most one Active primary placement for the same filing scope. Every Ended placement has an end time and end reason. Refiling creates a new placement identity; it does not reactivate or rewrite the old placement.

A duplicate suggestion is not a deletion decision.

Field Meaning
Candidate Document Versions Content being compared
Detection basis Identical checksum, similar content, same metadata, or user observation
Assessment Exact Duplicate, Business Duplicate, Related but Distinct, or Not a Duplicate
Authoritative record Version retained as the primary evidence, if applicable
Filing contexts Whether identical content is legitimately needed in different scopes
Decision-maker, date, and rationale Audit evidence
Disposition Keep, exclude from counts, relate, withdraw, or reject intake item

A checksum match proves identical file content. It does not prove that one of two filing relationships is invalid. Conversely, different checksums do not prove that two records have different business meaning.

Refiling does not rewrite history.

  1. Identify the incorrect classification or scope.
  2. Record a quality finding or permitted self-evident correction.
  3. Approve a new classification revision or metadata revision as applicable.
  4. End the incorrect filing placement.
  5. Create the correct placement against the same Document Version when content is unchanged.
  6. Re-evaluate Filing Slot matches and affected measures.
  7. Verify the correction and retain the before-and-after values, actor, time, and reason.

If the content itself is wrong, refiling is insufficient; a corrected Document Version is required.

Withdrawal means the record must no longer be treated as applicable evidence. It is not deletion.

Required fields include withdrawal reason, decision-maker, date, affected Filing Slots, replacement if any, and whether the content remains visible for reconstruction. A withdrawn version contributes to no current completeness count but remains in history when necessary to explain prior use or conduct.

  • Refuse classification when the study cannot be resolved.
  • Refuse site filing when the site is not part of the stated study or the identity is ambiguous.
  • Refuse final filing when required date, type, scope, privacy, or blinding metadata is missing.
  • Refuse an unblinded placement accessible to blinded staff.
  • Refuse sponsor filing of directly identifying investigator-controlled participant records.
  • Refuse automatic deletion based only on filename, metadata similarity, or checksum.
  • Refuse overwriting an earlier filing placement during reclassification.