This is a ready-to-use SOP for source data verification (SDV) and source document review (SDR) during clinical monitoring. Replace every <<FILL: ...>> placeholder with your specifics, set your document numbers and dates, and route it through document control. A worked filled specimen follows. Verify each cited regulation against the current source before you rely on it.
Document control header
| Field | Entry |
|---|---|
| Document title | Source Data Verification and Source Document Review |
| Document number | <<FILL: SOP-ID, e.g. SOP-CLIN-018>> |
| Version | <<FILL: version, e.g. 1.0>> |
| Effective date | <<FILL: effective date>> |
| Supersedes | <<FILL: prior version or "New">> |
| Document owner | <<FILL: role, e.g. Head of Clinical Operations>> |
| Applies to | <<FILL: sponsor / CRO monitoring staff>> |
1. Purpose
This procedure defines how monitors at <<FILL: COMPANY / CRO NAME>> verify that clinical database (CRF) data reflects the source accurately and completely (SDV), and review source documents for protocol compliance, safety, and quality (SDR). The objective is a database that can be reconstructed from source, with verification effort concentrated on the data and processes that matter most to subject safety and result reliability.
2. Scope
This procedure applies to on-site and remote monitoring of investigator sites for the studies it governs. The SDV level for each data category is set in the study-specific clinical monitoring plan (CMP) and its risk assessment; this SOP defines how SDV and SDR are performed once that scope is set. It does not replace centralized or statistical data review, governed by <<FILL: SOP-ID>>.
3. Responsibilities
| Role | Responsibility |
|---|---|
| Clinical Research Associate (monitor) | Performs SDV and SDR per the CMP, raises queries, writes visit reports, escalates site issues. Does not enter or correct site data. |
| Site (PI, coordinator) | Owns the data; resolves queries; maintains source; corrects the CRF with the original preserved. |
| Sponsor / CRO clinical lead | Owns the CMP and SDV scope; receives escalations; decides for-cause actions. |
| Clinical QA / GCP QA | Audits SDV adequacy and data integrity independently of monitoring. |
4. Definitions
- SDV: comparing CRF data to source to confirm accuracy, completeness, and consistency.
- SDR: reviewing the source itself for protocol compliance, safety, eligibility, and quality.
- Critical data: variables that drive the primary and key secondary endpoints, eligibility, safety reporting, and informed consent.
- Query: a documented request to the site to resolve a CRF-to-source discrepancy or a data question.
5. Procedure
5.1 Prepare
- Pull the subject list, the CMP, the source data location list, and any open queries.
- Confirm which subjects and which data categories are in scope for this visit, per the CMP’s SDV level.
5.2 Verify informed consent first
For each in-scope subject, locate the signed consent and verify: correct version per the version log; subject and investigator signatures and dates present; consent dated on or before the first study-specific procedure; re-consent on updated versions where required. A consent problem stops everything else for that subject; flag it immediately.
5.3 Verify eligibility
Compare key inclusion and exclusion criteria in the CRF against source (labs, history, prior medications). Confirm the subject genuinely met criteria at enrollment.
5.4 Verify critical data (SDV)
For each in-scope CRF field, find the source per the location list and compare value by value: number, unit, and date match; the entry is attributable, contemporaneous, and legible. Tick each against the source location list.
5.5 Review the source (SDR)
While in the record, look for protocol deviations, unreported adverse events, prohibited concomitant medications, missed assessments, and out-of-window visits. Matching numbers is half the job; the findings that hurt subjects live in the source.
5.6 Check the audit trail for electronic source
Where source is in EDC, ePRO, or an EHR, confirm changes are tracked, corrections did not obscure originals, and a reason for change is captured where required.
5.7 Raise and manage queries
Any CRF-to-source mismatch becomes a query for the site to resolve. Do not correct CRF data yourself. Record queries on the discrepancy/query log and confirm resolution at the next review, with the original entry preserved in the audit trail or by proper paper correction.
5.8 Document and escalate
Record in the monitoring visit report what was verified, for which subjects, the discrepancies found, queries raised, and follow-up. Escalate patterns (repeated transcription errors, systematic late entries, a consent issue across subjects) to the clinical lead; a cluster is a site-level process signal, not a one-off.
5.9 Remote monitoring
Where SDV is performed remotely, review the true source (not a re-typed summary) through a controlled, logged access path, and confirm any copies reviewed are certified where they stand in for an original. Blend remote SDV with central data review, which aims the on-site visits.
6. Acceptance criteria
A clean SDV finding requires all of the following:
- The CRF value equals the source value (same number, unit, date).
- The source is attributable and contemporaneous.
- Any change carries a tracked reason and the original is preserved.
- Discrepancies are queried and resolved, not silently corrected.
- Consent, eligibility, primary endpoint, and SAE data were verified at the level the CMP requires (typically 100%).
7. References
ICH E6(R2) sections 4.9 and 5.18.4; ICH E6(R3) (source data and monitoring expectations). FDA guidance, Oversight of Clinical Investigations: A Risk-Based Approach to Monitoring. FDA guidance, Electronic Source Data in Clinical Investigations. 21 CFR 312.62 (investigator recordkeeping); 21 CFR Part 11 (electronic records).
Confirm the current version and clause numbers of each reference before issue.
8. Records generated
- Monitoring visit report (per visit).
- Discrepancy / data query log.
- Confirmation of consent and eligibility verification per subject.
- Escalation records for site-level issues.
9. Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
10. Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Author | <<FILL>> | ||
| Reviewer (QA) | <<FILL>> | ||
| Approver (Clinical Ops Head) | <<FILL>> |
Filled specimen
The following shows an SDV finding worked through for an example subject. The specifics are illustrative.
- The eCRF reports a Week 4 systolic blood pressure of 138 mmHg for subject 0123. The source location list says vital signs source is the paper vitals worksheet.
- The monitor pulls the Week 4 worksheet: it reads systolic 158, initialed “JM,” dated and timed at the visit. The eCRF says 138.
- This is a transcription error. The monitor does not correct the eCRF. The monitor raises query Q-0123-014: “Week 4 systolic BP eCRF value 138 does not match source worksheet value 158. Please verify and correct.”
- The coordinator confirms the worksheet, corrects the eCRF to 158 with a reason for change captured in the audit trail; the original 138 entry is preserved.
- The monitor confirms the correction at the next review, closes the query, and records the discrepancy in the visit report. Noting subject 0123 has three transcription errors, the monitor escalates a data-entry quality concern for the site.
In this example the monitor stayed on the right side of the line (verify and query, never enter or correct), preserved the original through the audit trail, and treated three errors as a process signal rather than three isolated fixes. That is the behavior an inspector expects to see documented.
Common inspection findings this SOP prevents
- Transcription errors that were never queried, indicating SDV was not done or not done well on critical data.
- Consent verified late or not first, so a consent defect propagated through a subject’s data.
- A monitor correcting CRF entries, crossing into the site’s ownership of the data.
- SDV treated as the only control, with no SDR, so unreported AEs and prohibited meds in the source went unseen.
- A visit report implying full SDV when only critical fields were checked.
How to adapt this SOP
- Set your document number, owner, and effective date, and point section 2 at your CMP and central-review procedures.
- Keep the consent-first and four-categories-at-100% rules; they are the non-negotiable core of SDV scope.
- Add your remote-access and privacy controls to section 5.9 for the systems your monitors use.
- Confirm every regulation in section 7 against the current published version before issue.