An inspection-ready clinical trial management system (CTMS) for NHS research and development is one where the study record itself is the evidence. Every milestone date, delegation entry, recruitment figure and visit record carries a named author, a recorded time, a visible change history and a retrieval path. An inspector then reads the record the team worked in, rather than a pack assembled after the notification letter arrived.
That distinction decides how a trust experiences an inspection. NHS hospitals sit inside the MHRA’s routine good clinical practice inspection programme in their own right, as sponsors of their own studies and as organisations performing sponsor and investigator functions for others. The test is the same in both positions: the records have to demonstrate what happened, on request, in the room. This guide covers what the MHRA asks a trust to produce, the attributes that make a study management record inspection-grade, where the evidence chain breaks inside an R&D office, what ICH-GCP E6(R3) expects of the systems themselves, and a rehearsal an R&D office can run before any notification arrives.
Key Takeaways for NHS R&D Teams
- Why an NHS trust is inspected in two positions at once, and which records each position owns
- The 30-day dossier the MHRA requests after notification, and the system access expected on site
- The nine data integrity attributes applied to the study management record rather than to clinical data
- A worked example of an evidence chain breaking across four named artefacts
- What ICH-GCP E6(R3) Annex 1 Section 4 expects of computerised systems used in a trial
- An eight-part readiness rehearsal, each part with a target response time
What Does the MHRA Inspect at an NHS Trust?
The MHRA runs a risk-based compliance programme rather than a fixed cycle. Selection draws on clinical trial applications, marketing authorisation applications, previous compliance and inspection history, organisational change and intelligence from outside the agency. NHS hospitals appear by name in the published scope of that programme, alongside pharmaceutical companies, universities, charities, GP practices and laboratories, in the MHRA’s guidance on good clinical practice inspections.
A trust holds two distinct positions, and the records that answer for each sit in different parts of the organisation. R&D offices that treat the two as one set of paperwork discover the split during the inspection itself.
| Position | What the trust is answering for | Records the R&D office must produce |
| Sponsor of its own studies | Trial oversight, protocol compliance, safety reporting, vendor and service provider selection, system suitability | Trial master file, sponsor oversight records, risk assessments, monitoring reports, serious breach records, provider agreements |
| Participating organisation for external sponsors | Investigator site conduct, delegation, training, consent, investigational product handling, source records | Investigator site file, delegation of authority log, training and qualification evidence, pharmacy site file, screening and enrolment logs |
| Both positions together | Quality system, computerised system control, staffing, facilities, archive | Standard operating procedures with version history, system validation evidence, access and permission logs, deviation and CAPA records, archive index |
Notification starts a documented clock. An organisation chosen for inspection has 30 days to submit a GCP inspection dossier and a clinical trials spreadsheet. The dossier covers a list of clinical trials, organisation charts, standard operating procedure lists, contact details, an overview of facilities, service providers and clinical trial activities. The MHRA also states that it may give little or no notice in rare circumstances, which removes the preparation window entirely.
System access is the part R&D offices underestimate. The MHRA guidance is explicit that the host provides any equipment and software needed to access electronic records. The GCP Inspectorate goes further in its published expectations for hosting an inspection, asking for read-only access to trial master file systems and key clinical trial support systems, set up well in advance, with audit trails available and extractable. Inspectors also warn against staffing interviews with senior managers who sit outside day-to-day process, because detailed questions about a specific trial then go unanswered and require follow-up sessions.
Read-only access to the live system is a request, not a courtesy.
Findings carry three grades. A critical finding is a significant and unjustified departure from applicable legislative requirements with evidence that participant rights, safety or wellbeing were compromised or that data are unreliable. A major finding is a significant and unjustified departure with the potential to become critical. An other finding is a departure that is neither. The full inspection report follows roughly 25 working days after the final inspection date, and the corrective and preventive action response is due 25 working days after the report reaches the organisation.
Also Read: MHRA GCP Inspections: What to Expect and the Most Common Findings
What Makes a Study Management Record Inspection-Ready?
Data integrity attributes are usually discussed in relation to clinical data in an electronic data capture system. The same attributes decide whether a study management record survives scrutiny. The MHRA’s GXP data integrity guidance, revision 1 of March 2018, sets out five core attributes and four additions across all GxP areas, and section 3.1 places responsibility for the systems and the data they generate on the organisation itself. The GCP Inspectorate has since confirmed that the guidance introduces no new statutory requirements for clinical trials, so treat the attributes as the vocabulary an inspector uses rather than as a separate rulebook.
Each attribute converts into a question about the CTMS record, and each question has a demonstrable answer.
| Attribute | What it means for a study management record | Where an R&D office fails it |
| Attributable | Every entry identifies the individual who made it, through an account that belongs to one person | Shared logins on a departmental tracker, or a spreadsheet with no author column |
| Legible | The entry is readable and permanent, including after a correction | Overtyped cells that erase the prior value |
| Contemporaneous | The record captures the time of the event and the time of entry, and the two are visible separately | A month-end catch-up session that records ten milestones on one date |
| Original | The first capture of the fact is retained, or a certified true copy of it | A scanned summary kept after the working file was overwritten |
| Accurate | The entry matches the event it describes, with corrections carrying a reason | A date typed from memory during report preparation |
| Complete | The data must be whole; a complete set, including repeats and corrections | A study closed in the tracker with three milestone fields left blank |
| Consistent | The data must be self-consistent, in sequence and free of contradiction between systems | A recruitment figure in the board report that differs from the local portfolio system |
| Enduring | Durable and lasting throughout the data lifecycle, including the retention period | A departmental drive migrated during an IT change with no archive index |
| Available | Readily available for review or inspection purposes | A record held by one coordinator who has since left the trust |

Three of these carry most of the weight at trust level. Attributable and contemporaneous decide whether a milestone date can be defended at all. Available decides whether it can be produced in the room. A record that satisfies all three sits in a governed system with individual accounts, automatic timestamps and permission-based retrieval. Our guide to inspection readiness in clinical trials sets out the same condition across a research network.
Where Does an R&D Office Lose the Evidence Chain?
The chain breaks through ordinary competent work, and it breaks between systems rather than inside one. Take a hypothetical trust hosting a commercial interventional study. A research nurse joins the team on 4 February and starts consenting participants on 11 February. The delegation of authority log is signed by the principal investigator on 2 March, once the next monitoring visit prompts a review of the file.
Four artefacts now describe that one appointment, and they disagree.
- The delegation of authority log carries a signature dated 2 March against a task first performed on 11 February, which reads as an authorisation gap of 19 days.
- The training record shows protocol training completed on 9 February, so the training was current while the authorisation was absent.
- The consent forms from 11 and 18 February carry the nurse’s signature, which places the activity firmly inside the gap.
- The trust induction record gives a start date of 4 February, which establishes that the person was available and the process was late.

An inspector reading those four artefacts sees a documented finding rather than an administrative lag. The activity was performed by a trained member of staff who was properly employed and properly inducted. The system that should have blocked an unauthorised task at the point of assignment recorded nothing, and the paper log recorded the authorisation on the day someone remembered to ask for it.
The person was qualified throughout. Only the record was late.
The same pattern reaches every artefact an R&D office holds. A visit performed outside its protocol window becomes a deviation with no linked corrective action. A site file version that never matched the sponsor copy becomes a reconciliation exercise during the inspection week. A protocol amendment implemented before the site file was updated leaves consent taken on a superseded version. Each one is recoverable in isolation. Together they establish a pattern, and a pattern is what turns an other finding into a major one. Our worked CAPA example follows a single deviation from detection to verified closure.
What Does ICH-GCP E6(R3) Require of the Systems Themselves?
ICH-GCP E6(R3) gives data governance its own section, at Annex 1 Section 4, and the placement matters. Computerised systems move from an implementation detail to a named area of GCP compliance. Section 4 divides into safeguarding blinding, the data life cycle from capture through to destruction, and computerised systems as a subject in their own right. E6(R3) also replaces the fixed essential documents list with essential records, defined by their function: the records that enable verification of trial conduct and the quality of the data. Our investigator site file essential documents checklist covers that shift in detail.
The computerised systems subsections translate into evidence an R&D office has to hold or obtain from a supplier.
| Requirement area | What E6(R3) expects | What the trust must be able to show |
| Validation | The responsible party owns validation status across the system life cycle, on a risk-based approach | Supplier validation documentation, plus the trust’s own configuration and user acceptance evidence |
| Audit trails and metadata | Initial entry and every subsequent change or deletion documented, with a reason where appropriate | An exportable audit trail for a named milestone or delegation entry, readable without vendor assistance |
| User management | Access controls limit the system to authorised users and ensure attributability to an individual | Logs of account creation, role changes and access, with permissions matched to trial duties |
| Security and procedures | Documented procedures for system use, training on those procedures, and controls against unauthorised access | A current SOP for the system, training records against it, and evidence of periodic access review |
| System failure and support | Arrangements for failure, technical support and controlled system release | A business continuity procedure covering the study record, and a change log for system releases |
| Retention and access | Data and relevant metadata archived so they remain retrievable and readable, protected from alteration | An archive plan naming format, location, custodian and retention period for each record type |
These expectations now carry legal weight in the UK. The Medicines for Human Use (Clinical Trials) (Amendment) Regulations 2025 came into force on 28 April 2026, and compliance with the ICH E6 good clinical practice principles became a legal requirement from that date. The MHRA sets out its position in its guidance on compliance with ICH E6 in the United Kingdom, and our guide to the new UK Clinical Trials Regulations covers the wider change for sites and sponsors.
Also Read: Clinical Trial Management Software for NHS Trusts: 2026 Buyer’s Guide
How Should an R&D Office Rehearse an Inspection?
Readiness is measurable before an inspection is announced, and the measure is time. Pick one active study and one closed study, then work through the requests below with a stopwatch and no advance warning to the team. Record how long each answer takes and how many people were needed to produce it. The target times reflect what a governed record supports, and a gap between the two columns is the size of the reconstruction risk.
- Show the delegation status of every person on this study on a named past date. Target: under five minutes, from the system, without opening a paper file.
- Produce the audit trail for a milestone date that was later corrected. Target: under ten minutes, showing the original value, the new value, the author and the reason.
- List every study in the portfolio with an open deviation older than 30 days. Target: one screen, with no manual collation.
- Give an inspector read-only access to the study record. Target: same working day, with a named role that grants read access and no editing rights.
- Show which staff held current GCP training on the date of the first participant visit. Target: under ten minutes, linked to the delegation record rather than held separately.
- Retrieve the protocol version in force on a named date, and the consent form version used with it. Target: under ten minutes, with version history intact.
- Produce the pharmacy accountability record for one investigational product batch. Target: under fifteen minutes, from receipt through to destruction or return.
- Open a record from a study archived four years ago. Target: under one working day, in a readable format, without a former employee’s account.
Run the same eight requests against any platform on a shortlist, using a demonstration study rather than a slide. Each request has a demonstrable answer, so a product either performs it in the session or it does not.
What Are the Risks of a Record That Stores Without Evidencing?
- Inspection preparation becomes a project, because evidence exists in fragments that have to be assembled under a fixed 30-day clock alongside normal delivery.
- Authorisation gaps surface at monitoring rather than at assignment, which converts a preventable control into a documented finding.
- Corrections overwrite the original value, which removes the trust’s ability to explain a discrepancy it has already reported nationally.
- Read-only inspector access requires a manual export, which delays the first day of the inspection and shapes the impression that follows.
- Study knowledge concentrates in individuals, so staff turnover removes the ability to answer questions about historic studies at all.
- Isolated findings accumulate into a pattern, and a pattern raises the grade of the finding rather than the count.
- Archived records outlive the system that produced them, which puts retrieval and readability at risk across a retention period of at least 25 years for trials with applications submitted on or after 28 April 2026.
Also Read: NHS R&D: Governing Site Files Across a Trust’s Studies
How Does AQ Support Inspection-Ready NHS R&D?
AQ CTMS holds the trust’s studies as one operational record, so a milestone is entered once and carries its author, its timestamp and its change history from that moment. The surrounding modules attach the artefacts an inspector asks for to that same record, which is what turns a portfolio view into an evidence position. Our work with NHS and hospital research teams is built around both trust positions, sponsor and participating organisation.
- AQ Digital DoA records delegation with effective dates mapped to training and qualification evidence, which closes the authorisation gap at the point a task is assigned.
- AQ eISF holds essential site documents with version history, which lets a monitor or an inspector read the current file without a reconciliation exercise.
- AQ ePSF keeps investigational product accountability in a separately owned pharmacy file, which preserves the separation inspection expects while linking it to the study.
- AQ QMS carries controlled documents and training with approval history, so an SOP version in force on a past date is retrievable.
- AQ CAPA links a deviation to root cause, action and verified closure, which answers the pattern question directly.
- AQ eTMF is built on the DIA TMF Reference Model, which gives sponsor-side and site-side records a shared structure.

Access is permission-based across all seven modules of the AQ platform, so a read-only role can be issued for an inspection without an export. University Hospitals of Liverpool Group launched AQ eISF across a 150+ study portfolio, and Royal Free London brought controlled documents, training and CAPA into one quality system used by 300+ people. AQ is available through G-Cloud, submits the Data Security and Protection Toolkit, holds Cyber Essentials, and provides validation, data protection and governance evidence to trust teams as an assurance pack.
Run the eight rehearsal requests against your own studies and see where the answers come from. Book a live demo and bring one active study and one you closed three years ago.
