ICH E6(R3) changes the rules for eSource in three places. It folds the two older source terms into one, source records. It requires the investigator to define what counts as source, and where each record sits, before the trial starts. It adds a data governance section that governs the system holding the record alongside the record itself.
This guide covers the clauses that apply to electronic source capture and what each asks of a site. It sits inside our wider guide to eSource in clinical trials for UK research sites. The definitions themselves are set out in our guide to what counts as source data in a clinical trial.
E6(R2) governed the record. E6(R3) governs the record and the system that holds it.
What Did ICH E6(R3) Replace in the Source Terminology?
E6(R3) replaces two defined terms with one. The MHRA Inspectorate describes the change directly: source data and source documents are combined into a new term, source records, reflecting trial information that sits across several computerised systems rather than in one paper file.
The ICH E6(R3) glossary defines source records as original documents or data, which includes relevant metadata, or certified copies of those documents or data, irrespective of the media used. Three consequences follow for a site running electronic capture.
- Metadata sits inside the record. An export of values alone is an incomplete source record, so the audit trail is part of what is retained.
- Media has no bearing on status. A paper worksheet and an electronic entry are judged by the same test.
- A certified copy holds the standing of the original. The verification is documented by a dated signature or by generation through a validated process.
What Must a Site Define Before the Trial Starts?
Section 2.12.2 of Annex 1 puts the source declaration ahead of the first participant. The investigator should define what is considered to be a source record, the methods of data capture and their location prior to starting the trial, and should update that definition when needed. The clause adds a further instruction: unnecessary transcription steps between the source record and the data acquisition tool should be avoided.
That instruction gives electronic capture a direct footing in the guideline. A design that records the observation once, in the system that will hold it, satisfies the clause by construction.
- Name the source per data point, so a duplicated value has one declared original.
- Record the method of capture, so a reviewer knows whether a value was typed, transferred or participant-reported.
- Record the location, so a monitor or inspector reaches the original without asking.
- Version the definition, so it describes the arrangement in use on any given date.
The document that carries this at a UK site is the source data location log, covered in our guide to what a source data location log contains and who signs it off. The order that settles a value held in two systems is set out in our guide to which record is the source when data sits in both the EPR and the trial system.
Also Read: Types of eSource: Direct Data Capture, EHR, EHR-to-EDC and ePRO
What Does the Data Governance Section Require of an eSource Record?
Section 4.2 of Annex 1 follows one value through its life cycle, in eight stages. Each carries a requirement an eSource system either meets in configuration or leaves to the site.
| Clause | Stage | What it asks of an eSource record |
| 4.2.1 | Data capture | Data captured directly in a computerised system carries relevant metadata, verification of transcribed data follows its criticality, and entry checks are controlled and documented |
| 4.2.2 | Metadata and audit trails | The system logs account creation, role and permission changes and user access, documents the initial entry and every change or deletion with a reason where appropriate, and keeps audit trails enabled |
| 4.2.3 | Review of data and metadata | Audit trail review is a planned, risk-based activity with a written procedure |
| 4.2.4 | Data corrections | Every correction is attributed to the person or system making it, justified and supported by source records |
| 4.2.5 | Transfer and migration | Validated processes maintain integrity when the record moves to an EDC system or a replacement platform |
| 4.2.6 | Finalisation of data sets | Data sets meet a defined quality standard before analysis |
| 4.2.7 | Retention and access | Records are archived and protected from unauthorised access and alteration for the retention period |
| 4.2.8 | Destruction | Records are destroyed only once regulatory requirements no longer call for them |
Clause 4.2.2 carries the sentence a site is most often asked about at inspection. Audit trails, reports and logs are not disabled, and modification is allowed only in rare circumstances with a log and a justification. Each clause maps onto a data integrity attribute, and our guide to whether eSource meets ALCOA+ and the attributes inspectors check makes that mapping for all nine.

What Does ICH E6(R3) Require of the eSource System Itself?
Section 4.3 sets out eight requirements for the computerised system. They apply to a site’s source capture system in the same way as to a sponsor’s data acquisition tool.
- 4.3.1 Procedures. Documented procedures govern how the system is used.
- 4.3.2 Training. Every user is appropriately trained in the system they use, and the training record is the evidence.
- 4.3.3 Security. Named controls include user authentication and password management, firewall settings, antivirus software, security patching, system monitoring and penetration testing.
- 4.3.4 Validation. Validation demonstrates conformance to established requirements for completeness, accuracy and reliability, covering protocol-specific configuration and interfaces as well as standard functionality.
- 4.3.5 System release. A trial system is released to a site only once the approvals relevant to that site are in place, which ties go-live to the regulatory position.
- 4.3.6 System failure. Contingency procedures prevent data loss, so an outage during a clinic has a written answer.
- 4.3.7 Technical support. System issues are documented, managed and reviewed periodically.
- 4.3.8 User management. Access is limited to authorised users and attributable to an individual, permissions follow a user’s duties and are revoked when no longer needed, access is reviewed periodically, and the user record is retained with the time each permission was granted.
Clause 4.3.8 binds the eSource user list to the delegation log. An account that can sign data the delegation log does not cover fails the clause on the day it is created. The procedures behind all eight sit in the site’s quality management system.
Who Is the Responsible Party for an eSource System?
E6(R3) assigns the duty per system and asks the sponsor to hold the register. Section 3.16 states that the sponsor should have a record of the important computerised systems used in a clinical trial, covering the use, functionality, interfaces and validation status of each, and describing who is responsible for its management.
The expectation then splits by who deployed it.

A trust assesses its EPR for the trial. It validates the system it deployed for the trial.
That split matters at an NHS site using the EPR as source for part of a visit. The assessment, and the mitigations it produces, belong in the investigator site file beside the validation evidence for the trial system.
Also Read: eSource vs EDC: Where Source Data Ends and the CRF Begins
Which Parts of ICH E6(R3) Are Law in the UK?
The GCP Principles carry legal force in the UK, and Annex 1 carries the detail inspectors read against them. MHRA guidance on compliance with ICH E6 GCP in the United Kingdom states that compliance with the ICH E6 GCP Principles, as amended from time to time, and not the entirety of the guideline, becomes a legal requirement on 28 April 2026.
The same guidance expects sponsors to have assessed the principles and Annex 1 to determine the changes their quality management system needs by that date, and expects a documented impact assessment for trials already running. The UK-specific annotations to ICH E6(R3) set out where UK law adds to the ICH text.

Principle 9 reaches an eSource system directly. Four of its sub-points apply to source capture.
- 9.2 asks that systems for data capture, management and analysis are fit for purpose, capture the data the protocol requires, and are proportionate to risk and to the importance of the data.
- 9.3 asks that computerised systems used in trials are fit for purpose, for example through risk-based validation, with critical quality factors addressed in their design.
- 9.4 asks for record management processes that maintain integrity and traceability and protect personal information.
- 9.5 asks that essential records are retained securely for the period regulatory requirements set.
Principle 7 sets the dial for all of them. Processes should be proportionate to the risks to participants and to the importance of the data collected, which lets a site argue the depth of its controls from the study in front of it.
What Changes for a Site Between E6(R2) and E6(R3)?
The practical shift is one of scope. E6(R2) governed the adequacy of the record. E6(R3) governs the record, its metadata and the system that produces both.
| Aspect | Under E6(R2) | Under E6(R3) |
| Source terminology | Source data and source documents defined as two terms | One term, source records, with metadata inside the definition |
| Source declaration | Handled through sponsor plans and local practice | Required by section 2.12.2 before the trial starts, and updated when needed |
| Transcription | Addressed through verification of reported data | Unnecessary transcription steps between source record and data acquisition tool should be avoided |
| Data governance | Spread across investigator and sponsor obligations | One section covering the data life cycle from capture to destruction |
| Computerised systems | Framed around the sponsor’s electronic data handling | Eight named requirements at section 4.3, applied to the responsible party for each system |
| Audit trail review | Carried out as part of monitoring | A planned, risk-based activity with its own procedure at section 4.2.3 |
A site already running electronic source capture meets much of this by configuration. The gaps sit in the written layer: the source definition, the audit trail review procedure, the system register entry and the periodic access review.
Sites building that written layer for a first electronic capture study may be interested that AQ is launching eSource soon as part of the AQ platform. Book a live demo to see the AQ platform today.
