Clinical Trial Data Management: How Data Is Collected, Cleaned, and Locked
Nobody approves a drug based on a messy spreadsheet. Before a statistician ever sees the data, an army of data managers, monitors, and systems work to collect, clean, and lock every piece of information from a clinical trial. The Clarity Clinical Solutions video "Clinical Trial Data Management: How Data Is Collected, Cleaned, and Locked" walks through that machinery, and it is more interesting than it sounds.
The data life cycle has four stages: capture, verification, cleaning, and lock. Each one has its own tools, rules, and failure modes.
Capture: the electronic case report form
Data is captured at the clinical site and entered into electronic case report forms, or eCRFs. Every protocol-defined data point has a dedicated field. Commercial systems like Medidata RAVE and Oracle Clinical are industry standards, and good form design is the difference between a clean study and a nightmare.
The scale is bigger than most people expect. The video says a typical phase 3 trial has 200 to 500 eCRF pages per patient, capturing 1,000 to 3,000 unique data points. Multiply that by a few thousand patients and you have millions of fields that all need to be right.
Forms use standardized coding systems, most importantly MedDRA for adverse events. MedDRA, the Medical Dictionary for Regulatory Activities, gives every adverse event description a standard code so that "headache," "cephalalgia," and "pain in head" all end up in the same bucket. Without that, safety analysis across sites and trials would be noise.
Verification: source data is the truth
The numbers in the eCRF have to come from somewhere. Source data is where they come from: hospital charts, lab printouts, ECG strips, patient diaries. The video's rule is blunt: the source is the truth.
Source data must meet the ALCOA principles: attributable, legible, contemporaneous, original, and accurate. A modern extension, ALCOA+, adds complete, consistent, enduring, and available. These are the standards that the FDA's guidance on electronic source data in clinical investigations builds on, and they are also reflected in the International Council for Harmonisation's good clinical practice guidelines (ICH E6), which require source data to be accurate, legible, and contemporaneous.
Increasingly, electronic source data from labs and electronic health records flows directly into the eCRF, which eliminates a whole class of manual transcription errors.
Source data verification, SDV, is the process that makes sure what was entered matches the original source. A clinical research associate visits the site and compares each eCRF entry against the medical record. Traditional practice was 100% SDV on everything. Modern trials use risk-based monitoring, with targeted SDV of critical data: primary endpoints, informed consent, serious adverse events, and a sample of the rest. The FDA's risk-based monitoring guidance encourages exactly this kind of targeted approach. It is not just a cost saver. The video notes that SDV accounts for 30 to 40% of monitoring costs, so every point that does not need full verification saves real money.
Cleaning: edit checks and queries
Cleaning is where the database earns its keep. The system runs hundreds of pre-programmed edit checks. Range checks confirm values are biologically plausible, like systolic blood pressure between 50 and 300. Logic checks catch cross-field nonsense, such as a pregnancy test result recorded for a male patient. Date checks make sure visits happened in the right order.
When a discrepancy is flagged, a query is generated and sent to the site. The investigator must respond, either correcting the data or explaining why the original entry was right. The video puts the volume of a phase 3 trial at 5,000 to 20,000 queries, and every single one must be resolved before the database can lock.
Every trial starts with a data management plan, written before enrollment begins. The plan specifies eCRF design, validation rules, coding dictionaries, the SDV plan, and the lock process. It is signed by the lead data manager, project manager, and biostatistician, and it is a living document, updated throughout the trial with version tracking.
Part 11, audit trails, and the ECG fraud case
The clinical database sits inside a regulated environment. Under the FDA's electronic records rule, 21 CFR Part 11, electronic records must be secure, carry audit trails, and support electronic signatures. The FDA's guidance on the scope and application of Part 11 makes clear that the rule applies when electronic records are used instead of paper.
Most clinical databases also use the Clinical Data Interchange Standards Consortium's SDTM standard, which ensures data from different trials can be pooled consistently for regulatory submission. The CDISC SDTM standard is the common language regulators expect.
The audit trail is the quiet watchdog. It captures every change: who made it, what the old value was, what the new value is, when it happened, and why. It cannot be edited or deleted. Regulators inspect audit trails specifically to detect data fraud. The video tells the story of an FDA inspection that caught systematic data fabrication when identical ECG values appeared at identical timestamps across different patients. That is the kind of thing a human might never notice and an audit trail exposes instantly.
Lock: the database goes read-only
Database lock is the final gate before analysis. The four preconditions, per the video: all queries resolved, all SDV complete, adverse events reconciled, coding complete, and protocol deviations identified. Once locked, the database is read-only. No changes without an extraordinary reason.
Lock typically happens four to twelve weeks after the last patient's last visit. The locked database is then exported for analysis, archived, and submitted to regulators. Nothing that happens after lock can quietly change the numbers.
A day in the life of a data manager
The video sketches what this looks like on a normal day. Morning: review overnight queries, prioritize critical data. Midday: data review meetings, quality metrics like query rate per site. Afternoon: user acceptance testing of new eCRF pages or edit checks.
A data manager typically juggles two to four trials at once, with 50 to 500 active patients across 10 to 50 sites. The common pitfalls are predictable: poor eCRF design that manufactures thousands of unnecessary queries, late query resolution that delays lock, inconsistent coding that muddies safety analysis, and untrained sites that generate three to five times more queries than they should. The video's advice on the last one is the most practical sentence in the whole topic: investing in site training is the highest-return data management activity there is.
The bottom line
Data management is not glamorous, and the video says so outright. But without it, the most brilliantly designed trial is just noise. Every drug approval rests on the invisible work of data managers, monitors, and systems: data collected in disciplined eCRFs, verified against source, cleaned through thousands of queries, and locked behind an uneditable audit trail. That is what turns a pile of clinical observations into evidence a regulator can trust.
This article is based on the Clarity Clinical Solutions video "Clinical Trial Data Management: How Data Is Collected, Cleaned, and Locked." Watch it here: Clinical Trial Data Management: How Data Is Collected, Cleaned, and Locked
References
- Clarity Clinical Solutions — "Clinical Trial Data Management: How Data Is Collected, Cleaned, and Locked" (source video; life cycle stages, edit checks, audit trail, and lock criteria). https://www.youtube.com/watch?v=TzbWCWE0IhY
- eCFR — 21 CFR Part 11, Electronic Records; Electronic Signatures (supports the electronic records requirements discussion). https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11
- FDA guidance — Part 11, Electronic Records; Electronic Signatures — Scope and Application (supports the Part 11 discussion). https://www.fda.gov/regulatory-information/search-fda-guidance-documents/part-11-electronic-records-electronic-signatures-scope-and-application
- FDA guidance — Electronic Source Data in Clinical Investigations (supports the ALCOA and source data discussion). https://www.fda.gov/regulatory-information/search-fda-guidance-documents/electronic-source-data-clinical-investigations
- FDA guidance — Oversight of Clinical Investigations — A Risk-Based Approach to Monitoring (supports the risk-based SDV discussion). https://www.fda.gov/regulatory-information/search-fda-guidance-documents/oversight-clinical-investigations-risk-based-approach-monitoring
- CDISC — SDTM Foundational Standard (supports the SDTM discussion). https://www.cdisc.org/standards/foundational/sdtm
- MedDRA — Medical Dictionary for Regulatory Activities (supports the coding discussion). https://www.meddra.org/
- ICH — Efficacy Guidelines, E6 Good Clinical Practice (supports the source data requirements). https://www.ich.org/page/efficacy-guidelines