Clinical Trial Management Software for NHS Trusts: 2026 Buyer’s Guide

A clinical trial management system (CTMS) for an NHS trust is the operational system of record for every study the trust hosts: who invited the site, when each set-up milestone was reached, which staff were delegated to which task, how recruitment is tracking, and what evidence exists behind each of those claims. The buying decision inside a trust differs from the sponsor decision in one respect that shapes everything else. A sponsor buys a CTMS to run studies it designed. A trust buys one to run a portfolio it did not design, under national delivery reporting, NHS information governance, and MHRA inspection at the same time.

That triple duty is the whole buying problem. A system that tracks one study well can still leave an R&D office assembling its national figures by hand every month, and still leave an inspector reading a reconstruction rather than a record. This guide sets out what NHS reporting actually asks of the system, what NHS procurement will require the supplier to evidence, what the amended UK Clinical Trials Regulations now expect of computerised systems, and how to tell the two shapes of product apart before a shortlist is drawn.

Key Takeaways for NHS R&D Buyers

  • The three obligations an NHS trust CTMS has to satisfy from one record
  • The national delivery metrics and the six CPMS milestone fields a site must maintain
  • Where a trust’s study record breaks, with the named artefacts involved
  • The assurance pack NHS procurement expects: DSPT, Cyber Essentials, DTAC, DPIA and clinical safety
  • What ICH-GCP E6(R3) requires of trial specific computerised systems from 28 April 2026
  • A supplier question set an R&D office can use before shortlisting

Why Does an NHS Trust Buy a CTMS Differently From a Sponsor?

Three separate audiences read the same trust study record, and each one reads it for a different purpose. National delivery reporting reads it for milestone dates. An MHRA inspector reads it for evidence that the trial ran the way the records claim. NHS information governance reads it for the security and lawful basis under which the data is held at all. A sponsor CTMS answers the first two for its own studies. A trust needs all three answered across a portfolio of studies belonging to many sponsors.

The national picture explains why this now carries weight. The Department of Health and Social Care publishes monthly UK Clinical Research Delivery key performance indicators, and the split in that data is consistent. Regulatory approval runs close to its target. Local set-up lags it by a wide margin. In the release covering data to July 2026, 98% of studies received a combined review decision within 60 days against a 99% target, while 56% of studies opened to recruitment within 60 days of approval against a 90% target. Our breakdown of the UK clinical research delivery KPIs walks all seven indicators in detail.

The gap sits inside the trust. It is made of contract signatures, pharmacy sign-off, capacity confirmation, staff delegation and data entry, and every one of those is a record the trust already holds somewhere. A CTMS earns its place in an R&D office by holding them once.

The approval clock is nearly solved. The local clock is the one a trust can still move.

UK clinical research delivery KPIs: 98% of combined review decisions within 60 days against a 99% target, and 56% of studies open to recruitment within 60 days against a 90% target

What Does National Reporting Require From the System?

Study data reaches the national picture through the Central Portfolio Management System (CPMS), which the NIHR Research Delivery Network owns and manages. Most trusts feed it from a Local Portfolio Management System (LPMS) rather than keying directly. UKCRD has deliberately kept the site-level core to six essential fields, and the guidance is explicit that all six must be completed, in chronological order, for a study to count in the data at all.

FieldWhat the date marksWhy it is easy to get wrong
Date site invitedThe sponsor email providing the near final or final protocolArrives in an individual inbox before any study record exists
Date site selectedThe sponsor asks the site to begin set-up after due diligenceConfused with the expression of interest that preceded it
Non-confirmation statusSponsor declined, site declined, or null responseLeft blank when a study quietly stalls rather than formally stops
Date site confirmedThe last contract signature across all organisations involvedRecorded when the trust signed, rather than when the last party did
Date site ready to startThe sponsor gives green light for the site to recruitSits with the sponsor, so the site learns it by email
First patient first visitThe first study visit of the first participantKnown in clinic days before it reaches the LPMS

Two of those fields changed weight in January 2026. The 60-day site set-up metric now ends at the Date Site Confirmed rather than at Date Site Ready to Start, on the basis that the wait for sponsor green light sits outside site control. The 30-day recruitment metric still starts at Date Site Ready to Start. The consequence is arithmetical and catches R&D offices out: the two site metrics no longer sum to elapsed time. Alongside these sits a separate policy expectation that participating sites complete set-up within 90 days, formed of the 60-day and 30-day parts, inside the government’s 150-day study-level target.

Published trust-level performance shows how wide the spread is. In the UKCRD trust-level set-up report cut on 3 August 2026, University Hospital Southampton NHS Foundation Trust recorded 100% of eight studies set up within 90 days, and Liverpool University Hospitals NHS Foundation Trust recorded 100% across five. The Newcastle upon Tyne Hospitals NHS Foundation Trust combined the highest volume in the cohort with strong performance, at 81% across 21 studies and a median of 46 days. Across the rest of the distribution, most trusts sit well below the target, and the operational difference is rarely clinical capacity. It is how quickly the trust can see where a study has stopped.

Also Read: CPMS and LPMS: What Sites Must Enter and When

Where Does the Study Record Break Inside a Trust?

The failure is a copying failure, and it happens in the ordinary course of a competent week. Take a hypothetical multi-site commercial study at an NHS trust. The last contract signature lands on 14 March. That single event then enters four records at four different moments, and each entry is defensible on its own terms.

  • The research nurse notes 14 March in the study folder on the day it happens.
  • The LPMS entry is keyed on 25 March, once the countersigned copy circulates.
  • The R&D study tracker already carries 27 February, filled in when the local information pack went out.
  • The quarterly board report is compiled from the tracker, so it carries 27 February onward.

The national metric is calculated from the LPMS entry, which reports the study eleven days slower than it was. The board reads the spreadsheet, which reports it fifteen days faster than it was. Nobody made an error. The record was simply kept in four places, and four places is four answers.

The same contract signature date recorded four times at a hypothetical NHS trust: site study folder, LPMS entry, R&D study tracker and quarterly board report

The same pattern reaches the artefacts an inspector asks for. A delegation of authority log signed in April, covering a task performed in March, produces a documented gap in authorisation. A visit recorded outside its protocol window becomes a deviation with no linked CAPA. A site file version that never matched the sponsor’s copy becomes a reconciliation exercise during the inspection itself. Our guide to MHRA GCP inspections and the most common findings covers what inspectors write up most often, and the control that prevents each one.

Every entry was defensible. Only one of them was the event.

What Must a Supplier Evidence Before NHS Procurement Clears It?

NHS assurance is a stack rather than a checklist, and the layers belong to different parties. A supplier holds some of it. The trust holds the rest, and cannot delegate its own layer to a vendor. R&D offices lose weeks by discovering that split late.

NHS assurance stack showing supplier certificates (DSPT, Cyber Essentials), the DTAC v2.0 assessment, and the trust's own duties (DPIA, DCB0160, G-Cloud call-off)
Assurance itemWhat it establishesWho holds itPublished pass condition
Data Security and Protection ToolkitAnnual information governance self-assessment against the National Data Guardian standardsSupplier and trust submit separatelyStandards Met or Standards Exceeded, published by 30 June each year
Cyber EssentialsFive technical controls: firewalls, secure configuration, update management, user access control, malware protectionSupplierValid certificate, 12-month validity, verifiable on the IASME database
DTAC v2.0Clinical safety, data protection, technical security, interoperability, usabilitySupplier completes, trust assessesSections C1 to C4 must pass; D1 is scored to compare products
Data Protection Impact AssessmentLawful basis and risk mitigation for processing participant dataTrust, as controller, informed by the supplier’s own DPIACompleted in advance of processing under UK GDPR
DCB0129 and DCB0160Clinical risk management for health IT, manufacturer side and deploying organisation sideSupplier and trust respectivelyApplicability decided by NHS England’s six-step test
G-Cloud call-offCompliant route to contract for cloud softwareTrustDirect award only; 36 months plus an optional 12-month extension

Four points inside that stack repay attention during a procurement.

  • DSPT status wording matters. “Approaching Standards” means the organisation published a Standards Not Met assessment and had a remediation plan approved. Ask which status a supplier holds and for which assessment year, since the toolkit runs on a 30 June annual cycle. NHS trusts themselves moved to the CAF-aligned toolkit for 2024-25; IT suppliers remain on their own evidence set.
  • Cyber Essentials sits inside DTAC. Question C3.1 of DTAC v2.0 requires a valid Cyber Essentials certificate to pass technical security. The NHS Standard Contract mandates the DSPT, so treat Cyber Essentials as an assessment requirement rather than a contractual one.
  • The DPIA stays with the trust. DTAC states that the manufacturer’s DPIA should be used by the NHS organisation when completing its own, as controller. A supplier DPIA is an input, and the trust’s obligation survives it.
  • Clinical safety applicability is settled by a published test. NHS England’s decision guidance turns on whether the product is used to influence, support or manage real-time or near-real-time direct care. A supplier who considers DCB0129 inapplicable must supply a written rationale, and DCB0160 clause 2.5.1 still puts the confirming duty on the deploying organisation. Both standards are currently under NHS England review, with a public consultation open until 11 September 2026.

One procurement mechanic catches teams out repeatedly. G-Cloud is a direct award framework. Running a mini-competition, RFP, RFQ or ITT through it breaches the terms of the agreement, and prices and terms are fixed at the point of tender. A trust that wants a competitive evaluation should shortlist on published service definitions and award directly, or use a framework designed for competition.

Also Read: NHS R&D: Governing Site Files Across a Trust’s Studies

What Does ICH-GCP E6(R3) Now Require of the System Itself?

The amended UK Clinical Trials Regulations, made as SI 2025 No. 538, came into force on 28 April 2026. From that date, compliance with the ICH E6 good clinical practice principles is a legal requirement in the UK under Regulation 28, and the MHRA has been specific that the principles rather than the entire guideline carry legal force, with the annexes standing as relevant guidance that cannot be ignored.

One clause changes the software conversation directly. Regulation 28(1B) confirms that the functions of the sponsor include functions in relation to the development and maintenance of trial specific computerised systems, and the selection and oversight of a laboratory. System selection is now named regulatory territory rather than an IT preference.

  • The system holds a validated audit trail, which lets a trust show when a milestone date was recorded and by whom rather than asserting it.
  • Delegation is checked at the point a task is assigned, which prevents a signature dated after the activity it authorises.
  • Risk signals surface against the live record, which supports the risk-proportionate oversight E6(R3) expects instead of a periodic manual review.
  • Validation evidence is available on request, which shortens the trust’s own assurance work at DTAC and DPIA stage.

Trials that started before 28 April 2026 need a documented impact assessment of the GCP updates rather than an automatic transition, and a trust’s system should be able to evidence which of its studies fall on each side of that line. Our guides to the new UK Clinical Trials Regulations and to ICH-GCP E6(R3) and CTMS oversight cover the wider change. The MHRA’s own position is published in its guidance on compliance with ICH E6 in the United Kingdom.

Which Kind of System Is the Trust Actually Buying?

Two axes separate the products on a shortlist. The first is scope: one study at a time, or the whole trust portfolio. The second is what the system leaves behind: stored information that somebody assembles into evidence later, or evidence available on demand. Most disappointing purchases are a mismatch on the second axis, because both kinds of product demonstrate well.

DimensionStudy-by-study recordPortfolio-wide governed record
Where a milestone date livesIn the study’s own tracker, keyed again into the LPMSRecorded once, read by the LPMS export and the board report
Answering “which studies are past 60 days?”A manual sweep by whoever maintains the trackerA live view, available to any authorised user
Delegation currencyReviewed at the next monitoring visitEnforced when the task is assigned
What an inspector seesA reconstruction assembled from several sourcesThe record the team actually worked in
Effect of a staff changeLocal knowledge leaves with the personThe record stays, permissions move
Information governance positionAssessed per system and per studyAssessed once, at platform level
Pharmacy and site file linkageHeld in separate files, reconciled on requestLinked to the same study record

A trust that hosts a handful of studies can run the left-hand column well. A trust reporting monthly against national metrics across dozens of studies cannot, because the reconciliation cost scales with the portfolio while the R&D team does not. Our comparison of CTMS versus spreadsheets for capacity planning shows the same effect on the staffing side.

Decision quadrant comparing study spreadsheet, single-study CTMS, portfolio tracker and trust-wide connected CTMS across scope and evidence availability

What Should an R&D Office Ask Before Shortlisting?

The questions below separate the two shapes of product quickly, because each one has a demonstrable answer rather than a positioning answer. Ask for the answer to be shown in the product during the demonstration.

  1. Show me every study in the portfolio past its 60-day set-up point, right now. A portfolio-level view answers in one screen. A study-level product answers by export.
  2. Where do the six CPMS milestone fields live, and how do they reach our LPMS? Establish whether the dates are entered once or twice.
  3. Show me the audit trail for a milestone date that was later corrected. This tests the record rather than the interface.
  4. What happens when an unauthorised staff member is assigned a delegated task? A control that blocks at assignment differs from a report that flags it afterwards.
  5. Which DSPT status do you hold, for which assessment year? Ask for the published entry rather than a statement.
  6. Provide your Cyber Essentials certificate and your completed DTAC v2.0 form. Both are documents, so they can be requested before a shortlist rather than after.
  7. Provide your product DPIA and your validation documentation. These feed the trust’s own DPIA and its DCB0160 work.
  8. How does the site file and the pharmacy file connect to the study record? Separate systems mean separate reconciliations at every monitoring visit.

What Are the Risks of Buying the Wrong Shape of System?

  • National figures are compiled by hand each month, so the reported position lags the operational one and improvement work targets stale data.
  • Milestone dates differ between the LPMS, the study tracker and the board report, which makes performance discussions a debate about the numbers.
  • Delegation gaps surface during monitoring rather than at assignment, which converts an avoidable control into an inspection finding.
  • Each additional system carries its own DPIA, its own DSPT dependency and its own access review, which multiplies governance overhead across the portfolio.
  • Inspection preparation becomes a project, because the evidence exists in fragments that have to be assembled under time pressure.
  • Study knowledge concentrates in individuals, so staff turnover removes the ability to answer questions about historic studies.

Also Read: Why NHS Sites Miss the 90-Day Set-Up Target and How to Close It

How Does AQ Support NHS Trust Research Delivery?

AQ CTMS holds the trust’s study portfolio as one operational record, so a milestone date is entered once and read everywhere it is needed. Set-up milestones, recruitment, visit scheduling and site status sit in the same place, which gives an R&D office a live portfolio position instead of a monthly reconstruction. Our work with NHS and hospital research teams is built around that reporting duty.

The surrounding modules close the artefacts an inspector asks for, against the same study record.

  • AQ eISF holds essential site documents in a controlled electronic investigator site file, which lets a monitor review between visits rather than only during them.
  • AQ ePSF keeps pharmacy accountability in its own separately owned file, which preserves the separation MHRA inspection expects while linking it to the study.
  • AQ Digital DoA records delegation with effective dates mapped to training and qualification evidence, which stops authorisation gaps forming.
  • AQ QMS and AQ CAPA carry controlled documents, training and corrective action, which links a deviation to the action that closed it.
  • AQ eTMF is built on the DIA TMF Reference Model, which gives sponsor and site a shared structure to reconcile against.

On the procurement side, AQ is available through G-Cloud, submits the Data Security and Protection Toolkit, holds Cyber Essentials, and provides validation, data protection and governance evidence to trust teams as an assurance pack. University Hospitals of Liverpool Group launched AQ eISF across a 150+ study portfolio, and Royal Free London brought controlled documents, training and CAPA into one quality system used by 300+ people.

See how the portfolio view, the site file and the delegation record behave against your own studies. Book a live demo and bring the questions from the shortlisting list above.

Guide
By Ash Mahmud· · · Book a 30 min demo
In this guide
AM
Written by
Ash Mahmud
Co-founder, AQ Trials

Ash has spent over twenty years inside clinical research operations and technology, working alongside NHS Trusts, CROs, sponsors, and academic research organisations. He co-founded AQ Trials to give research teams one connected, inspection-ready operational record.

See the connected platform behind this guide

A 30-minute walkthrough built around your operational priorities — study execution, documentation, quality and pharmacy in one governed record.

Book a 30 min demo →
See the AQ Platform in action — a 30-minute walkthrough for teams like yoursBook a 30 min demo →
Free guides · PDF
Find the right guide for you

Pick a module, your organisation type, or both — we'll match the guides and email them to you.

Most popular guides
Explore
15+ guides

Free guides · PDF

Guides matched to you.

Written for first-in-human & Phase 1 sites

Inspection-ready checklists & templates

Aligned to MHRA, FDA & EU Annex 11