CAPA Software for NHS Research: Deviations and MHRA Readiness

CAPA software for NHS research is the system that holds the corrective and preventive action record for every clinical trial an NHS organisation runs. It records what went wrong, how the cause was established, what was done about it, and the evidence that the action held. That record answers to the sponsor’s quality management duty under ICH-GCP E6(R3), to the trust’s own research governance, and to the MHRA at inspection.

An NHS trust sits in an unusual position. It is often the site, sometimes the sponsor, and always the organisation that produces the evidence when an inspector asks. One deviation in one clinic therefore creates obligations in several directions at once, and the record that holds it has to survive all of them.

What Does CAPA Software Do in an NHS Research Setting?

A CAPA system takes a quality event from the moment somebody notices it to the moment somebody can prove it was resolved. In a trust the events arrive from every direction: a pharmacy temperature excursion, a consent form signed on a superseded version, a visit performed by a nurse whose delegation entry starts a week later. The system gives each one a single home.

  • It dates the event and the awareness separately, which matters because the statutory reporting clock runs from awareness rather than from occurrence.
  • It grades each event against a written classification, which allows a trust to show why one deviation was reportable and a similar one was not.
  • It holds the root cause analysis in a structured form, which allows repeat causes to be counted across studies rather than described one report at a time.
  • It assigns each action an owner and a due date, which turns an intention into something a research office can chase.
  • It gates closure on recorded verification, which prevents a CAPA closing on a date instead of on evidence.
  • It links the record to the study, site, staff member and document involved, which is how an inspector traces a finding back to the activity that produced it.

The general mechanics sit in our guide to CAPA management in clinical trials. This guide covers what changes once the organisation running the trial is an NHS body.

What Does ICH-GCP E6(R3) Require of the Quality System?

ICH-GCP E6(R3) took effect in the UK on 28 April 2026, alongside the Clinical Trials Regulations as amended by the Medicines for Human Use (Clinical Trials) (Amendment) Regulations 2025. It moves the expectation away from documenting every deviation equally and towards proportionate control of the things that decide whether a trial is reliable. Three of its sections bear directly on the CAPA record.

ProvisionWhat it addressesWhat the record has to show
Section 2.5, Compliance with ProtocolThe investigator documents all deviations, and important deviations require explanation and preventive measuresEvery deviation captured, with the important ones carrying a reason and an action
Section 3.10, Quality managementThe sponsor operates a system to manage quality across the whole trial process, focused on the factors critical to qualityEvents graded against defined criteria rather than judged case by case
Section 3.12, NoncomplianceThe sponsor ensures “appropriate and timely escalation and follow-up of issues to allow the implementation of appropriate actions in a timely manner”A dated escalation trail, written as the issue moved

Section 2.5.4 also sets the boundary for acting first and reporting after. The investigator follows the protocol and deviates only where necessary to eliminate an immediate hazard to trial participants. Everything outside that boundary is a deviation the record has to explain. The full text sits in the ICH E6(R3) guideline published by the EMA.

The guideline asks for timeliness. Timeliness is a property of the system that holds the record.

Also Read: ICH-GCP E6(R3) and CTMS: What Changes for Study Oversight

The Seven-Day Serious Breach Clock

Regulation 29A of the Medicines for Human Use (Clinical Trials) Regulations 2004 requires the sponsor to notify the MHRA of a serious breach within seven days of becoming aware of it. A breach is serious when it is likely to affect to a significant degree either the safety or physical or mental integrity of trial participants, or the scientific value of the trial. The MHRA guidance on notification of serious breaches sets out both the test and the process.

Timeline showing the seven-day serious breach clock starting when the sponsor becomes aware rather than when the event occurred, with the fields the MHRA notification draws from the CAPA record at day zero

Seven days is short. The MHRA does not expect a finished investigation inside it. The guidance states that where the investigation or corrective and preventive action is ongoing at the time of reporting, “it is acceptable to indicate your plans with projected timelines for completion”. The notification therefore draws on a record that already exists, rather than starting one.

  • A description of the breach and its nature, taken from the classification already applied to the event.
  • An assessment of the impact on participant safety or on the scientific value of the trial.
  • The status of the investigation at the point of reporting.
  • The corrective and preventive actions planned or already completed.
  • Projected timelines for anything still outstanding.

Follow-up reporting places a second demand on the record. Each follow-up must be labelled as a follow-up. It must carry the GCP identification number issued in the original acknowledgement. It must repeat everything previously submitted and add the new detail, so that each submission stands as a complete record up to that point. A system that overwrites the current state of a CAPA cannot produce that sequence. A system that versions it can.

Why Does an NHS Trust Answer to Four Sets of Expectations at Once?

A commercial sponsor manages a CAPA against its own quality system. An NHS trust manages the same event against four, and they do not share a vocabulary or a deadline.

  1. The sponsor’s quality management duty. Where the trust sponsors the study, sections 3.10 and 3.12 of E6(R3) apply to the trust itself, including the escalation trail and the handling of serious non-compliance.
  2. The organisation’s duty under the UK Policy Framework. Paragraph 9.10(i) requires effective procedures for reporting and for monitoring the research, including its conduct and the continued suitability of the approved protocol.
  3. The statutory reporting duty. Regulation 29A runs its seven-day clock regardless of how busy the research office is, and the clock belongs to the sponsor even where the trust is only a site.
  4. The trust’s own governance and information rules. The record sits inside NHS systems, under NHS access controls, and under the 25-year retention duty that regulation 31A now carries.

The UK Policy Framework for Health and Social Care Research is also explicit about the culture the reporting depends on. Paragraph 9.22 states that “errors can only be rectified and improvements made … if they are reported in a timely way”, and that this requires “a culture of openness and honesty … with a focus on improvement rather than blame”. A system that makes reporting slow or exposing works against that directly.

Also Read: NHS Clinical Research Software and ICH-GCP E6(R3): What the New UK CTR Requires

The Six Stages of a Governed CAPA Record

A CAPA record that holds up under inspection moves through six stages, each of which leaves a dated artefact behind. The stages matter less as a workflow than as a set of things an inspector can ask to see.

Six stage flow of a governed CAPA record from detection through classification, root cause, action plan and verification to closure, with a failed verification reopening the investigation
  1. Detection. The event date and the awareness date are recorded separately. The artefact is a dated entry naming who identified the issue and how.
  2. Classification. The event is graded against written criteria. The artefact is the grading, including the reasoning where a breach was judged not serious.
  3. Root cause. The investigation establishes why the event happened, in a form comparable with other events. The artefact is the analysis, with the contributing conditions named.
  4. Action plan. Corrective actions address the event, and preventive actions address the condition that allowed it. The artefact is the plan with an owner and a due date against each action.
  5. Verification. Somebody tests whether the action held under real operating conditions, after enough time has passed for the test to mean something. The artefact is the dated result, pass or fail.
  6. Closure. The record closes on a recorded pass, signed by somebody other than the action owner. The artefact is the closure entry and the approver’s identity.

Stage five is where most CAPA systems are weakest. A failed verification has to reopen the investigation rather than extend the deadline, because a fix that did not hold means the cause was misidentified. The mechanics of that test are covered in our guide to CAPA effectiveness verification, and a single deviation is followed through all of these stages in our worked CAPA example.

Where the CAPA Record Breaks in a Trust

Consider a realistic case. A research nurse at a trust site performs a study visit on 3 March. Her delegation of authority entry for that procedure carries an effective date of 10 March, because the principal investigator signed the log a week after the training was completed. The monitor spots the mismatch on 2 April during a routine visit.

The event now exists in five places. The visit sits in the study schedule and the delegation entry in the investigator site file. The training certificate sits in a personnel folder, the monitoring finding in a visit report in the sponsor’s system, and the deviation itself in a study-level spreadsheet held by the research office. Nothing links them.

  • The awareness date becomes contested. The facts sat in the trust’s own records from 10 March, and the sponsor learned on 2 April. The seven-day clock depends on which date counts as awareness, and no record settles it.
  • The scope stays invisible. Nobody can say how many other visits that nurse performed in the same window, or whether the same signing delay affected other staff on other studies.
  • The preventive action has no reach. A corrective action fixes this log. A preventive action would change how delegation entries are dated across the portfolio, which requires knowing the portfolio.
  • The verification has nothing to test against. An effectiveness check needs a measurable condition. “Logs will be signed promptly” cannot be tested. “No delegation entry carries an effective date later than the first delegated activity” can.

The nurse followed the process she was given. The principal investigator signed the log in good faith. The failure sits in the arrangement of the records, and it will recur under the next set of people unless the arrangement changes.

Also Read: NHS R&D: Governing Site Files Across a Trust’s Studies

Reactive Handling Compared With a Controlled CAPA Record

Effort separates these two states very little. Research offices working reactively often work harder. The real difference is where the evidence lives at the moment somebody asks for it.

AspectReactive handlingControlled CAPA record
Where an event first landsAn email, a monitoring report, or a study-level spreadsheetOne record, created at detection, with both dates captured
Reportability decisionReached in discussion, documented afterwards if at allGraded against written criteria, with the rationale stored
Seven-day clockStarts when somebody realises it startedStarts at a recorded awareness date and is visible to the research office
Root causeWritten as narrative in the CAPA formStructured, so repeat causes can be counted across studies
Action ownershipHeld by whoever raised it, chased informallyNamed owner and due date, escalated on age
ClosureRecorded when the action is reported completeGated on a dated verification result and independent sign-off
Portfolio viewAssembled by request, study by studyStanding, across every study the organisation runs
Inspection responseReconstruction from several systems and several peopleThe record is produced as it stands

What Do MHRA Inspectors Ask For at an NHS Site?

The MHRA inspects on a risk-based programme and also on trigger. A serious breach notification is one of the triggers listed in the MHRA guidance on GCP inspections, alongside whistleblower reports and regulatory intelligence. The same guidance notes that in rare circumstances the agency may give little or no notice.

  • An inspection dossier within 30 days of the request, including trial lists, organisational charts, SOPs and a facilities overview.
  • Access to electronic systems, including the equipment and software needed to read the records held in them.
  • The trial master file, which the guidance describes as the basis of the inspection.
  • A corrective and preventive action plan submitted in response to the inspection report.

The same guidance grades findings critical, major and other, and sets out what follows a critical one. A critical finding is referred to the GCP Inspection Action Group. The measures available to that group run from periodic reporting and early re-inspection through referral to other agencies, suspension of the clinical trial authorisation, infringement notices and prosecution.

Escalation staircase showing how one graded MHRA inspection finding travels from grading to a CAPA plan, referral to the GCP Inspection Action Group and imposed measures, with the CAPA plan marked as the only step the organisation controls

The grade belongs to the inspector. The quality of the response belongs to the organisation.

The findings inspectors write up most often, and the control that prevents each, are set out in our guide to MHRA GCP inspections and common findings.

How Should a Trust Measure CAPA Readiness Across the Portfolio?

A count of open CAPAs tells a research office very little. Age tells it more. The most useful measure separates the parts of the process that work from the parts that fail. A trust with strong deviation capture and weak verification has one specific problem to fix.

CAPA readiness index for a fictional NHS trust scored across eight domains, showing strong deviation capture and retention against weak serious breach clock discipline and effectiveness verification

The chart above uses fictional data for an illustrative NHS trust. The pattern it shows is common: capture, filing and structure score well, and the domains that depend on follow-through and on records talking to each other score badly. Eight domains are worth scoring separately.

  • Deviation capture. Known events that reached the system at all.
  • Classification defensibility. Events graded with a recorded rationale rather than by custom.
  • Root cause analysis. Investigations that name a condition rather than restate the event.
  • Action plan structure. Actions carrying a named owner and a due date.
  • Effectiveness verification. Closures supported by a dated verification result.
  • Serious breach clock discipline. Notifications made inside seven days of a recorded awareness date.
  • Preventive action reach. Actions applied across the portfolio rather than to the study that raised them.
  • Retention. Records held in a form that survives the 25-year duty in regulation 31A.

The retention duty deserves particular attention. The Medicines for Human Use (Clinical Trials) (Amendment) Regulations 2025 were made on 28 April 2025 and came into force on 28 April 2026. They amend regulation 31A to require the trial master file to be retained for 25 years from the conclusion of the trial. A CAPA record is part of the evidence of how the trial was run, so it inherits that horizon.

What Does NHS Procurement Ask of the Software Itself?

A CAPA system in an NHS organisation is assessed twice: once as a research tool and once as an NHS digital product. The second assessment usually runs through the NHS Digital Technology Assessment Criteria. Adopting organisations review a supplier’s completed DTAC during procurement to assess whether the technology meets minimum baseline standards. DTAC covers five areas.

  • Clinical safety. The supplier’s safety case for the product in a care setting.
  • Data protection. How personal data is handled, on what lawful basis, and under whose control.
  • Technical assurance. The security and resilience position of the platform.
  • Interoperability. How the system exchanges information with what the organisation already runs.
  • Usability and accessibility. Whether the people expected to use it can.

Research software adds a requirement DTAC does not cover. The system has to be validated for its intended use and kept validated through change, which is a separate discipline from information governance. Our guide to GAMP 5 and computerised system validation covers that evidence, and eISF for NHS Trusts applies the same assurance questions to the site file.

What Does a Trust Risk Without a Connected CAPA Record?

The exposure in a trust is rarely one missed action. It is the state of the record at the moment somebody outside the organisation asks to see it.

  • A missed statutory deadline. The seven-day clock passes while the event is still being discussed in email.
  • An indefensible classification. A decision that a breach was not serious, with no recorded rationale behind it.
  • Repeat findings. The same cause recurring across studies because nothing counted it the first three times.
  • Closure without evidence. CAPAs marked complete on the strength of an assurance rather than a test.
  • A reconstruction exercise at inspection. Staff assembling from memory and from several systems what the record should already hold.
  • Escalation the organisation did not choose. A critical finding referred onward, with measures set by somebody else.

CAPA Inside the AQ Platform

AQ holds CAPA as a module inside one connected platform rather than as a separate quality database. The value of a CAPA record in a trust comes from what it is attached to.

  • The CAPA module records the event date and the awareness date as separate fields, which supports a defensible start point for the seven-day clock.
  • Each record links to the study, site, staff member and document it arose from, which allows an inspector’s question to be traced in one direction instead of assembled from several systems.
  • Closure is gated on a recorded verification result, which keeps a CAPA open until somebody has tested the fix rather than reported it.
  • The QMS module holds the SOPs and training the actions refer to, so a preventive action that changes a procedure can be carried through to the controlled document in the same system.
  • The CTMS supplies the study, visit and delegation context, which helps turn a single deviation into a countable pattern across a portfolio.
  • The eISF holds the site file the corrective action usually touches, so the document and the action supporting it stay in the same system.

AQ is designed for organisations that run research inside NHS governance, and the platform’s position for NHS hospital research teams is set out separately. AQ is available through G-Cloud, with its security posture described in the assurance documentation supplied for procurement review.

The most useful test of any CAPA system is one question asked cold: show me every open action older than 60 days across every study this organisation runs, and who owns each one. Book a live demo to see how AQ answers it.

Guide
By Ash Mahmud· · · Book a 30 min demo
In this guide
AM
Written by
Ash Mahmud
Co-founder, AQ Trials

Ash has spent over twenty years inside clinical research operations and technology, working alongside NHS Trusts, CROs, sponsors, and academic research organisations. He co-founded AQ Trials to give research teams one connected, inspection-ready operational record.

See the connected platform behind this guide

A 30-minute walkthrough built around your operational priorities — study execution, documentation, quality and pharmacy in one governed record.

Book a 30 min demo →
See the AQ Platform in action — a 30-minute walkthrough for teams like yoursBook a 30 min demo →
Free guides · PDF
Find the right guide for you

Pick a module, your organisation type, or both — we'll match the guides and email them to you.

Most popular guides
Explore
15+ guides

Free guides · PDF

Guides matched to you.

Written for first-in-human & Phase 1 sites

Inspection-ready checklists & templates

Aligned to MHRA, FDA & EU Annex 11