The data management plan is the central governing document of clinical data management. It defines, before a single data point is collected, exactly how a trial's data will be captured, cleaned, coded, reconciled, and locked — and who is responsible for each step. If the data management process is the journey from raw observation to locked database, the data management plan is the map agreed before anyone sets off.
A well-written plan is what makes data management auditable and repeatable: it is the documented evidence that the approach was defined up front rather than improvised, and the reference everyone returns to when a question arises mid-trial. This guide explains what a data management plan is, what it contains, who owns it, and how it fits with the other key trial documents.
What is a clinical data management plan?
A clinical data management plan (often abbreviated DMP) is a controlled document that describes how data management activities will be conducted for a specific trial. It translates the requirements of the protocol into concrete data-handling procedures: how the database is built, how data is reviewed and cleaned, how discrepancies are resolved, how terms are coded, and how the database is ultimately locked and delivered.
The plan is created during the set-up stage, as one of the essential deliverables that must be in place before data collection begins, alongside system validation and release documentation, user training records, and vendor agreements. It is trial-specific: while organisations work from templates and standard operating procedures, each plan is tailored to the design, complexity, and data sources of its own study.
Why the data management plan matters
Good Clinical Practice expects data management activities to be planned, documented, and consistently followed. The plan delivers exactly that. It aligns everyone — the data manager, programmers, coders, the medical and safety teams, statistics, and any CRO — on a single agreed approach, so the work proceeds without gaps or contradictions. It also provides the audit trail of intent: during an inspection, the plan demonstrates that data quality was designed in from the start. Trials without a clear, current plan tend to accumulate inconsistent decisions that surface as problems at database lock.
What does a data management plan contain?
Contents vary by organisation and trial, but a well-structured plan typically addresses or references the following areas:
- Study overview — a summary of the protocol, objectives, and design relevant to data handling.
- Roles and responsibilities — who performs and who approves each data management activity, including the split between sponsor and CRO.
- Critical data and risk assessment — which data is defined as critical (patient safety, trial integrity, and endpoint data) and the risk-based focus that follows from it.
- Data flow — how data moves from source through the database to the final dataset, including all external sources.
- Database and eCRF design — the structure of the electronic Case Report Form and the conventions applied to it.
- Data validation and edit checks — the specifications for the automated and manual checks used to clean the data.
- Query management — how discrepancies are raised, routed, and resolved.
- Medical coding — the dictionaries used (such as MedDRA and WHODrug), versions, and coding conventions.
- Reconciliation — how safety, laboratory, and external vendor data will be reconciled against the clinical database.
- External and vendor data handling — transfer specifications, formats, and frequencies for each external source.
- Data review — the plan for ongoing review of the data, including any risk-based approaches.
- Database lock — the criteria and procedure for declaring a clean file and locking the database.
- Quality control and metrics — how data quality is checked and the standards it must meet.
Each of these areas is a subject in its own right, and most have their own dedicated guides. The plan is where they are pulled together into one coherent, trial-specific approach. For how the eCRF and edit checks are actually built and configured, see our complete guide to EDC systems.
Who writes and approves the plan?
The clinical data manager typically owns and authors the data management plan, drawing input from the programmers who build the database, the medical and safety teams, statistics, and any vendors. Because the plan commits multiple functions to a shared approach, it is formally reviewed and approved before data collection begins — and when the work is outsourced, the sponsor reviews and approves it as part of its oversight responsibilities, even though a CRO may have drafted it.
The plan as a living document
A data management plan is not written once and filed away. As a trial evolves — a protocol amendment, a new vendor, a change to the coding dictionary version — the plan is updated under version control to reflect the current approach. Each version is dated and approved, so the document always represents how data management is genuinely being conducted. Keeping the plan current is part of keeping the trial inspection-ready.
How the plan relates to other trial documents
The data management plan sits alongside, and draws from, several other key documents. The protocol defines what the trial measures and how it is designed; the data management plan defines how the resulting data is handled. The statistical analysis plan (SAP) defines how the locked data will be analysed, which shapes how the database must be structured. Where the protocol and SAP define the science and the analysis, the data management plan defines the operational data handling that connects them — making it the operational backbone of the whole data lifecycle.
Frequently asked questions
What is a clinical data management plan?
A clinical data management plan is a controlled document that describes how data management will be conducted for a specific trial. It defines how the database is built, how data is reviewed and cleaned, how discrepancies and coding are handled, and how the database is locked and delivered. It is created during set-up, before data collection begins, and is tailored to each individual study.
What does a data management plan contain?
A comprehensive plan typically covers a study overview, roles and responsibilities, data flow, database and eCRF design, data validation and edit-check specifications, query management, medical coding, reconciliation, external and vendor data handling, data review, database lock criteria, and quality control. Each area is tailored to the trial, and the plan pulls them together into one coherent approach.
Who writes and approves the data management plan?
The clinical data manager usually owns and authors the plan, with input from programmers, the medical and safety teams, statistics, and vendors. It is formally reviewed and approved before data collection begins. When data management is outsourced, the sponsor reviews and approves the plan as part of its oversight responsibilities, even if a CRO prepared it.
When is the data management plan created and updated?
The plan is created during the set-up stage, before data collection begins, as one of the essential deliverables that must be in place to start. It is then maintained as a living document: when the trial changes — through a protocol amendment, a new vendor, or a dictionary version change — the plan is updated under version control so it always reflects the current approach.
What is the difference between the data management plan and the protocol?
The protocol defines what the trial measures and how it is designed scientifically. The data management plan defines how the resulting data is operationally captured, cleaned, coded, reconciled, and locked. The protocol drives the plan, and the statistical analysis plan defines how the locked data will be analysed; the data management plan is the operational link between them.
Learn how to build a plan with TriTiCon
The data management plan is the central deliverable of the set-up stage. TriTiCon's training covers it in detail — what it must contain and how to build one — in The Clinical Data Management Set-up Process, alongside the other set-up documentation and deliverables. You can explore the full TriTiCon course platform to see how the plan connects to the rest of the lifecycle.