Resource · Validation · 10 min read

EDC validation checklist (21 CFR Part 11)

The exact checklist our QA lead runs before signing off any Clinera study. Print it, mark it up, send it to your CRO — it's yours.

1. Plan & risk (Pre-build)

  • Validation plan approved by QA
  • GAMP 5 categorization recorded
  • Risk assessment covers patient safety, data integrity, regulatory exposure
  • Intended use and assumptions documented
  • Roles & responsibilities matrix signed

2. Requirements

  • User Requirement Spec (URS) traceable to protocol sections
  • Functional Requirement Spec (FRS) mapped 1:1 to URS
  • Configuration spec lists every edit check and derivation
  • Integration requirements list source, direction, frequency, PHI scope
  • Non-functional requirements: performance, availability, retention

3. Build evidence

  • Build performed in a controlled environment with change log
  • Peer-review evidence for edit checks and derivations
  • Code-list and dictionary versions pinned (MedDRA, WHODrug, LOINC)
  • Sandbox-to-prod promotion procedure documented
  • Configuration baseline frozen before UAT

4. IQ / OQ / PQ

  • IQ confirms environment, accounts, network and integrations
  • OQ exercises each configured function with positive and negative tests
  • PQ runs a representative subject through the entire visit schedule
  • Each script executed with timestamp, tester ID and evidence (screenshot or export)
  • Deviations logged, justified and approved by QA

5. Traceability

  • Forward trace: URS → FRS → test → evidence → defect (if any)
  • Backward trace: every test traces to a requirement
  • Coverage report shows 100% requirement coverage
  • Untestable requirements justified in writing

6. Part 11 controls

  • Unique user accounts with periodic access reviews
  • Password policy and inactivity timeout per SOP
  • Audit trail captures who/what/when/why for every change
  • Electronic signatures show signer, date/time, reason and meaning
  • Audit trail review SOP with sampling plan and reviewer log
  • Record retention and legal hold procedure documented

7. Security & HIPAA alignment

  • Role-based access enforces least privilege
  • PHI boundary documented (where PHI lives, where it doesn't)
  • Encryption at rest and in transit confirmed
  • Backup, restore and DR tested with evidence
  • Vendor BAAs in place for every PHI-touching system

8. Operational readiness

  • Cutover runbook with rollback path
  • Site training delivered and attested
  • Incident and change-control SOPs active
  • Hypercare on-call schedule published
  • Periodic review cadence scheduled (annual minimum)
Want this as a Word doc with sign-off blocks? Ask us — we'll send the editable template. Or see our Validation service.
Free discovery call

Need help running this checklist?

Our validation team will execute it on your Clinera study with full evidence — typically 1–2 weeks.

  • ✓ Senior engineer reviews your inquiry
  • ✓ Reply within 1 business day
  • ✓ US-based, HIPAA-aware
  • ✓ Scoped plan in 48 hours

No spam. We reply within 1 business day. HIPAA-aware, US-based team.