An eSource error becomes a protocol deviation when it shows that the trial was conducted differently from the protocol, and it becomes a corrective and preventive action (CAPA) when its cause is systemic and likely to recur. A value typed wrongly and corrected in the audit trail stays a data error. The same value, wrong because the assessment happened outside its window, is a deviation. The same wrong entry across several participants is a CAPA.
This guide is for UK research sites deciding what an error in an electronic source record triggers. It covers the boundary between a data error and a deviation, the four outcomes one error can have, the test that makes a deviation important, the point at which a CAPA opens, the serious breach threshold, and how the decision is recorded. The wider context sits in our complete guide to eSource in clinical trials for UK research sites.
The error is in the record. The deviation is in the conduct.
What Separates a Data Error from a Protocol Deviation?
A data error is a defect in the record of what happened. A protocol deviation is a difference between what the protocol required and what the site did. One error can be either, and the test is whether the activity itself departed from the protocol.
Two entries make the separation clear. A research nurse records a systolic reading of 1280 instead of 128 and corrects it the same afternoon. The blood pressure was taken at the right visit by delegated staff, so only the record was wrong. A second nurse records the same assessment accurately at a visit held eleven days late. That record is right and the conduct departed from the protocol.
| Aspect | Data error | Protocol deviation |
| What is wrong | The recorded value or its metadata | The activity the protocol required |
| Who resolves it | Delegated site staff, through a correction | The investigator, through documentation and review |
| What closes it | A corrected value with a reason for change | A documented deviation with an explanation |
| Whether the sponsor sees it | Through queries and the audit trail | Through the deviation log, at the agreed frequency |
The correction mechanics sit in our guide to how to correct an eSource entry without breaking ALCOA+. This guide starts after the correction, at what else the error triggers.
Which Four Outcomes Can One eSource Error Have?
One error can end in four places, and each tier adds an obligation to the one below it. Most errors stop at the first tier, and the tiers above are reached by a test rather than by a sense of severity.
- Correction only. The record was wrong, the conduct was right. The audit trail holds the old value, the new value, the author and the reason for change.
- Protocol deviation. The conduct departed from the protocol. The investigator documents the departure and the deviation enters the study’s deviation log.
- Important protocol deviation. The departure may significantly affect the data or the participant. The investigator explains it and puts measures in place to prevent recurrence.
- CAPA, and in rare cases a serious breach notification. The cause is systemic. A formal investigation finds the root cause, and the sponsor decides separately whether the regulator is told.

The tests are cumulative. An error promoted to tier three carries the obligations of tier two, so an important deviation is still logged and the value still corrected.
Also Read: How Does a Visit Schedule Become an eSource Form?
When Does a Protocol Deviation Become Important?
A deviation becomes important when it meets the sponsor’s trial-specific criteria for that classification. ICH E6(R3) section 3.9.3 asks the sponsor to set those criteria, and defines important protocol deviations as a subset that may significantly impact the completeness, accuracy or reliability of the trial data, or may significantly affect a participant’s rights, safety or well-being.
The site applies criteria it did not write. Four points follow.
- The sponsor defines the classification criteria before the study opens, so the site holds them in writing before the first participant.
- Section 2.5.3 places the review on the investigator, who documents all deviations, reviews them, and explains those deemed important together with measures to prevent recurrence.
- Section 2.5.4 allows a deviation without prior agreement only where it removes an immediate hazard to a participant.
- A borderline classification is agreed with the sponsor and recorded with its reasoning, so the grade can be defended at inspection.
An eSource audit trail makes the classification easier to evidence. The trail shows when the entry was made and what changed, so an investigator reviewing a late assessment sees the real interval rather than a remembered one. Our guide to what PI oversight looks like in an eSource audit trail covers the review entries behind that judgement.
When Should an eSource Error Trigger a CAPA?
A CAPA opens when the error has a cause that will produce the same error again. Severity alone is a weak trigger. A severe one-off with a fully understood cause can close on correction, and a minor error repeating across twelve participants points at a form, a permission or a training gap that remains live.
Two questions decide it. The first asks how far the error reaches into the data or the participant. The second asks whether the cause sits in a system or process other participants also run through.

Four signals point at a systemic cause, and any one is enough to open the investigation.
- The same error appears for more than one participant, or for more than one member of staff.
- The error survived a control that should have caught it, such as an edit check or a review step.
- The form or the permission set allowed an entry the protocol does not permit.
- The same finding was raised before and the previous action failed to hold.
ICH E6(R3) section 3.10.1.3 supports this reading. It asks that a deviation beyond a pre-specified acceptable range prompts an evaluation of whether a systemic issue exists and whether action is needed. Section 3.11.1 places quality assurance on identifying causes of serious non-compliance to enable corrective and preventive actions. The investigation, root cause analysis and effectiveness check that follow belong to the site’s CAPA process, and the underlying procedures sit in the quality management system.
A one-off closes on correction. A pattern closes on a cause.
When Does an eSource Error Reach the Serious Breach Threshold?
A serious breach is one likely to affect to a significant degree either the safety or physical or mental integrity of trial participants, or the scientific value of the trial. Regulation 29A of the Medicines for Human Use (Clinical Trials) Regulations 2004 places the duty on the sponsor to notify the licensing authority in writing within seven days of becoming aware of it.

Three practical points govern this tier.
- The notification duty sits with the sponsor, or a person the sponsor has authorised. A site reports the event to the sponsor and does not notify the MHRA itself.
- The clock runs from sponsor awareness, so the site’s escalation timing determines how much of the seven days remains.
- MHRA guidance on serious breach notification treats persistent non-compliance affecting eligibility or dose adjustment as a serious breach, and an isolated incident without a systematic failure as one that does not meet the threshold.
Data integrity failures reach this threshold through the scientific value limb. An audit trail switched off across a study, or entries made under a shared login so authorship cannot be established, puts the whole dataset in question. MHRA GXP data integrity guidance expects data to meet the ALCOA+ attributes across its lifecycle, and our guide to whether eSource meets ALCOA+ maps each attribute to its control.
How Should a Site Record the Decision Itself?
The decision is a record in its own right, and it is the record an inspector asks for when a classification looks generous. A site that files only the outcome leaves the reasoning to memory across a 25 year retention period.
| Element of the decision | Who owns it | Where it is filed |
| The error, with the audit trail entry that shows it | Delegated site staff | The eSource record and its audit trail |
| Whether the conduct departed from the protocol | Principal investigator | The deviation log |
| The classification against the sponsor’s criteria | Principal investigator, with the sponsor | The deviation log, with the reasoning |
| Whether the cause is systemic | QA lead or research manager | The quality record that opens or declines a CAPA |
| Whether the serious breach threshold is met | Sponsor | The sponsor’s own breach assessment record |
Two timing rules keep the record defensible. The classification is made close to the event, because a deviation graded six months later looks like a grade chosen to suit a monitoring visit. A decision to take no further action is written down with its reason, because an absent record reads at inspection as an absent decision. The deviation log and the sponsor’s classification criteria are filed in the investigator site file.
Also Read: What MHRA Expects from Electronic Source Systems Under the 2026 UK Regulations
Which eSource Errors Fall Into Which Category?
The table below works six hypothetical errors at a UK research site through the same two questions. A real classification always runs against the sponsor’s own criteria for that study.
| What happened | Outcome | Why |
| A systolic reading typed as 1280 and corrected the same day | Correction only | The assessment was performed as the protocol required |
| A visit held on study day 34 against a window closing on day 32 | Protocol deviation | The conduct departed from the schedule of events |
| An eligibility assessment recorded after the participant was randomised | Important protocol deviation | The departure affects participant rights and data reliability |
| The same required field left blank across nine participants | CAPA | A form or training cause is producing the same error repeatedly |
| Entries made under a colleague’s login by an undelegated member of staff | CAPA, with a serious breach assessment | Authorship cannot be established, so the scientific value is in question |
| A dose calculated from a weight the site never recorded, across a cohort | Serious breach assessment by the sponsor | Participant safety is likely to be affected to a significant degree |
Row five shows why both questions are asked. The impact question alone might close a single undelegated entry on correction, and the systemic question exposes an access control that lets any user enter data under another name. Access should follow the delegation of authority log.
A site running several studies makes this judgement many times a year, and the effort concentrates in keeping the classification, the deviation log and the quality record tied to one event. AQ is launching eSource soon as part of the AQ platform. Book a live demo to see the AQ platform today.
