Quality Control and Audit Trails in Clinical Data Management

|Anders Mortin

Quality control is how clinical data management proves that its output is good — not just that the data was cleaned, but that the cleaning worked and the resulting dataset meets the required standard. The audit trail is what makes that proof possible: the complete record of who did what to the data, when, and why. Together, quality control and the audit trail are how a trial demonstrates data integrity, the quality that everything else in clinical data management ultimately serves.

This guide explains what quality control involves in clinical data management, how data quality is measured, what the audit trail is and why it matters, and how both connect to the principles of data integrity. It focuses on the data-management quality perspective; the technical detail of how an EDC system records its audit trail, and the regulatory requirements for validating that system, are covered in the linked guides.

What is quality control in clinical data management?

Quality control (QC) is the set of checks that confirm data and deliverables meet defined quality standards. It is distinct from the cleaning itself: data validation finds and fixes problems, while quality control verifies that the data which results is genuinely fit for purpose. It is also distinct from quality assurance (QA) — QC checks the output, while QA provides independent assurance that the processes producing it were sound. In practice QC is woven through the whole data lifecycle, from checking a freshly built database before go-live to confirming a clean file before lock.

How quality control works

Quality control in data management takes several forms, applied at different points:

  • QC of the database build — confirming the eCRF and edit checks behave as specified before data collection begins.
  • QC of the data — reviewing data for accuracy and consistency, either across the whole dataset or on a defined sample, to confirm cleaning has been effective.
  • QC of coding and reconciliation — independent checks that coded terms and reconciled data are correct.
  • QC at database lock — the final confirmation that the clean-file criteria are met before the database is frozen.

Many organisations apply a risk-based approach, concentrating QC effort on the data that matters most — critical variables and safety data — rather than treating every field identically. The aim is not flawless data at any cost, but assurance that the data is reliable for the decisions it supports.

Measuring data quality

Quality is managed through metrics. Common measures include query rates and how quickly queries are resolved, the volume of open and ageing discrepancies, error rates found during QC review, and the time taken to reach key milestones such as database lock. Defined acceptance criteria turn these metrics into a clear standard: a dataset is considered clean when it meets the thresholds agreed in advance. Tracking these measures throughout the trial — rather than only at the end — is what lets a team catch a systemic problem while there is still time to fix it.

The audit trail and data integrity

An audit trail is the secure, time-stamped record of every change made to the data: what was changed, who changed it, when, and why. It means that any data point can be traced back through its entire history to its origin. Two requirements make it trustworthy: it must be tamper-protected — unchangeable even by system administrators — and it must remain available for inspection at all times. An audit trail that could be edited would prove nothing. This traceability is the backbone of data integrity, and it is what an inspector relies on to confirm that the data presented for a decision genuinely reflects what happened in the trial.

Data integrity is most often expressed through the ALCOA principles: data should be Attributable, Legible, Contemporaneous, Original, and Accurate — frequently extended (ALCOA+) to also require that data is complete, consistent, enduring, and available. The audit trail is the practical mechanism that makes most of these principles demonstrable: it provides attribution, preserves the original record alongside any change, and shows that entries were contemporaneous.

The audit trail in this article is treated as a data-integrity concept. The technical detail of what an EDC system captures in its audit trail is covered in our complete guide to EDC systems, and the regulatory requirements for validating that the system records it reliably — including 21 CFR Part 11 — are covered in our guide to EDC validation requirements.

Where quality control fits in the lifecycle

Quality control is not a final gate alone; it runs throughout. It checks the system during set-up, monitors data and metrics during conduct, and provides the final confirmation at close-out that the clean-file criteria are met. Because it is the activity that ultimately vouches for the dataset, completing the required QC is a direct prerequisite for declaring a clean file and locking the database.

Frequently asked questions

What is quality control in clinical data management?

Quality control is the set of checks that confirm data and deliverables meet defined quality standards. It is distinct from data cleaning, which fixes problems, and from quality assurance, which independently assures the process. QC verifies that the resulting data is genuinely fit for purpose, and it runs throughout the lifecycle, from checking the database build to confirming the clean file before lock.

What is the difference between quality control and quality assurance?

Quality control checks the output — reviewing data and deliverables against defined standards to confirm they are correct. Quality assurance provides independent assurance that the processes producing the data were sound, typically through audits and oversight. QC is built into the data management workflow; QA sits independently of it. Both are needed for a trial to demonstrate reliable data.

What is an audit trail in clinical data management?

An audit trail is the secure, time-stamped record of every change to the data: what changed, who changed it, when, and why. It allows any data point to be traced through its full history back to its origin. This traceability underpins data integrity and is what regulators rely on during an inspection to confirm the data reflects what actually happened in the trial.

What are the ALCOA principles of data integrity?

ALCOA states that data should be Attributable, Legible, Contemporaneous, Original, and Accurate. The extended version, ALCOA+, adds that data should also be complete, consistent, enduring, and available. These principles define what trustworthy data looks like, and the audit trail is the main mechanism that makes them demonstrable in a clinical trial.

How is data quality measured in clinical data management?

Quality is managed through metrics such as query rates and resolution times, the volume of open and ageing discrepancies, error rates found during QC review, and time to milestones like database lock. Defined acceptance criteria turn these into a clear standard, and tracking them throughout the trial lets teams catch systemic problems while there is still time to act.

Build quality expertise with TriTiCon

Quality control and data integrity run through every stage of the data management process. TriTiCon's training covers them in context across the lifecycle — from the conduct-stage cleaning and review in The Clinical Data Management Conduct Process to the final checks before lock in The Clinical Data Management Close-out Process. And because quality control is only half the picture, Oversight in Clinical Development takes the quality-assurance side further — the risk-based approach, sponsor oversight, trial-level metrics (KPIs and KQIs), and the QCs and spot checks that keep a trial's data reliable. Explore the full TriTiCon course platform to see how quality is built in at every step.

Anders Mortin

Clinical Data Management Expert

TriTiCon delivers clinical data management training based on extensive hands-on experience from real clinical trials across sponsors, CROs, and life sciences organizations. The training is developed by industry professionals who work directly with clinical data, systems, documentation, and cross-functional trial teams.

30+
Years Experience
50+
Clinical Trials