Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Clinical & GCP

Checklist: Clinical Database Lock

A plug-and-play database lock checklist for a clinical trial: every pre-lock condition with owner, evidence, and sign-off, plus the hard-lock steps and the unlock-under-change-control rule, with a filled specimen and the regulations it satisfies.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use clinical database lock checklist. It confirms every pre-lock condition is met, records the evidence and the functional sign-offs, and defines the hard-lock steps and the unlock rule, so the dataset the biostatistician analyzes is fixed, traceable, and identical to what the clinical study report and submission report. Replace every <<FILL: ...>> placeholder, set your document numbers, and route through your normal review. A filled specimen follows. Confirm each cited regulation against the current source before you rely on it.

Document control header

FieldEntry
Document titleDatabase Lock Checklist, Study <<FILL: protocol number>>
Document number<<FILL: CL-ID, e.g. DBL-ABC201>>
Version<<FILL: version, e.g. 1.0>>
Governing DMP<<FILL: DMP-ID>>
Lock type<<FILL: interim / final>>
Planned lock date<<FILL: date>>

1. Pre-lock conditions

Every item must be Complete (or explicitly Not Applicable with rationale) before the hard lock. A single open critical item blocks the lock.

#ConditionStatusOwnerEvidence
1All expected CRF pages entered (expected vs received = 0 missing)<<FILL: Complete/Open/NA>><<FILL: CDM>><<FILL: missing-pages report + date>>
2All critical-variable queries closed<<FILL>><<FILL: CDM>><<FILL: open-query report = 0>>
3Remaining non-critical queries dispositioned/justified<<FILL>><<FILL: CDM>><<FILL>>
4Medical coding complete and medically reviewed<<FILL>><<FILL: Coder/Medical>><<FILL: coding sign-off>>
5Central laboratory data reconciled<<FILL>><<FILL: CDM>><<FILL: recon report, 0 unresolved>>
6ePRO/eCOA and IRT/IWRS data reconciled<<FILL>><<FILL: CDM>><<FILL>>
7SAE reconciliation (clinical vs safety database) complete<<FILL>><<FILL: CDM/PV>><<FILL: recon memo signed>>
8Protocol deviations reviewed and classified<<FILL>><<FILL: Clinical>><<FILL: deviation log version>>
9Data review / listings review complete<<FILL>><<FILL: CDM>><<FILL>>
10SDTM/ADaM conformance run, findings resolved or explained in the reviewer’s guide<<FILL>><<FILL: Stat Programming>><<FILL: conformance report>>
11Dictionary and CT versions match submission metadata<<FILL>><<FILL>><<FILL>>
12Audit trail reviewed for the period, risk-based<<FILL>><<FILL: CDM/QA>><<FILL>>

2. Functional sign-offs

The lock is authorized only when the defined functions sign.

FunctionNameSignatureDate
CDM Lead<<FILL>>
Biostatistics<<FILL>>
Medical / Clinical<<FILL>>
Quality Assurance<<FILL>>

3. Hard-lock steps

  1. Confirm all section 1 items Complete or justified and all section 2 sign-offs obtained.
  2. Revoke edit permissions in the production EDC (verify no account retains write access).
  3. Take the locked snapshot/export of the database.
  4. Record the lock in the EDC audit trail and complete the lock memo (date, database version, who locked, checklist reference).
  5. Generate the final extract for SDTM/ADaM and statistical analysis.

4. Lock memo

FieldEntry
Lock date/time<<FILL>>
Database version / snapshot ID<<FILL>>
Locked by<<FILL>>
Checklist reference<<FILL: this document + version>>
StatementAll pre-lock conditions met or justified; functional sign-offs obtained; write access removed; locked snapshot retained.

5. Unlock and re-lock control

If an error is found after lock, the database is unlocked only under formal change control: a documented request, an impact assessment, a tightly scoped change to the specific records, re-lock, and a record of exactly what changed and why. Uncontrolled or undocumented unlocks are a serious finding. See change-control-validated-systems and deviation-management.

6. References

ICH E6(R2)/E6(R3), Good Clinical Practice. 21 CFR Part 11; EudraLex Volume 4, Annex 11 (audit trail, controlled access, accurate copies). ICH E2A/E2B (safety), for the SAE reconciliation basis.

Confirm the current version of each reference before issue.

7. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Filled specimen (excerpt)

The following shows the pre-lock conditions completed for an illustrative final lock. Details are illustrative.

Study: ABC-201, final lock. Planned lock: 15-Mar-2026.

#ConditionStatusOwnerEvidence
1All CRF pages enteredCompleteCDMMissing-pages report, 0 missing, 14-Mar
2Critical-variable queries closedCompleteCDMOpen-query report = 0, 14-Mar
4Coding complete and reviewedCompleteCoder/MedicalCoding sign-off, 13-Mar
5Central lab reconciledCompleteCDMRecon report, 0 unresolved, 14-Mar
7SAE reconciliation completeCompleteCDM/PVRecon memo signed, 14-Mar
8Deviations classifiedCompleteClinicalDeviation log v3, 13-Mar
10SDTM/ADaM conformanceCompleteStat ProgConformance report; residual findings explained in SDRG

Lock memo: locked 15-Mar-2026 14:20, snapshot DBL-ABC201-FINAL, locked by CDM Lead, write access removed and verified. Two weeks later a lab-unit error was found in three records; the database was unlocked under CR-2026-088, the three records corrected, and the database re-locked with a documented scope, rather than edited ad hoc.

Common inspection findings this checklist prevents

  • The database locked with open critical queries or incomplete reconciliation.
  • SAE reconciliation gaps: serious events in the clinical database not matching the safety database at lock.
  • Write access not actually removed, so the “locked” database was still editable.
  • No lock memo, so the locked version and its approvers cannot be identified.
  • An uncontrolled post-lock edit with no change-control record, scope, or re-lock.

How to adapt this checklist

  1. Add or remove conditions to match your data sources (drop rows that do not apply, mark them NA with a reason rather than deleting silently).
  2. Set the functions that must sign in section 2 to your study’s governance.
  3. Verify write-access removal technically, not just on paper, at the hard lock.
  4. Reference your real change-control procedure for the database unlock and re-lock path.
  5. Confirm the references in section 6 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.