An electronic data capture (EDC) system holds the data a clinical trial collects about its participants. A clinical trial management system (CTMS) holds the conduct of the trial that produced that data. The EDC records what the reading was. The CTMS records whether the reading was taken by a delegated person, at a visit inside its protocol window, under the protocol version in force at that site on that date.
That distinction decides where evidence sits at inspection. A question about a laboratory value is answered from the EDC. A question about why participant 014 attended on day 96 of an 84-day window is answered from the clinical trial management system. A team holding only one of the two systems can answer half of what an inspector asks.
This guide sets out what each system holds, routes fifteen common study records to the system that owns them, shows what a separated pair costs at inspection, covers what the UK rules in force since 28 April 2026 require of each, and answers whether a study needs both.
What Does Each System Hold?
Both systems are validated, both carry audit trails, and both are opened during an inspection. Their scope separates at the level of the unit of record. An EDC organises around the participant and the case report form. A CTMS organises around the study, the site, the visit and the milestone. The table below sets the two side by side on the six attributes that decide which one a question belongs to.
| Attribute | Clinical trial management system (CTMS) | Electronic data capture (EDC) |
| Question it answers | Was the study conducted as approved? | What did the study observe? |
| Unit of record | The study, the site, the visit and the milestone | The participant and the case report form field |
| Daily users | Research managers, study coordinators, monitors, R&D offices | Data managers, investigators, coordinators, statisticians |
| Content it carries | Site status, recruitment, visit schedules and windows, delegation, contracts, monitoring visits, IMP accountability | Eligibility data, efficacy and safety values, adverse events, queries, locked datasets |
| What an inspector opens it for | Evidence of controlled conduct | Evidence of data integrity |
| What it cannot show on its own | The clinical result | The authority and the conditions behind the result |
Four attributes of any single data point sit outside the EDC entirely. Each one is a field the CTMS carries and the case report form has no place for.
- Authority. The delegation log records who was permitted to perform the assessment on that date, which lets a reviewer confirm the reading was taken under delegated authority.
- Timing. The visit diary measures the actual attendance against the protocol window, which turns an out-of-window visit into a recorded deviation at the point of booking rather than a discovery at monitoring.
- Version. The site record holds the protocol version live at that location on that date, which allows a reviewer to test the assessment against the document that governed it.
- Consent state. The study record holds the consent version each participant signed and the date they signed it, which shows the data was collected under a current consent.
An EDC proves what the reading was. A CTMS proves the reading was allowed.

Also Read: What Is a CTMS? The Complete Guide to Clinical Trial Management Systems
Which Records Belong in Which System?
The routing test is practical. Ask what the record proves. A record that proves an observation about a participant belongs in the EDC. A record that proves the study was run under control belongs in the CTMS. A record that proves the trial was authorised and governed belongs in the trial master file. The fifteen records below cover most of what a study produces in a year.
| Study record | Owning system | What it proves |
| Randomisation assignment for a participant | EDC or the randomisation system feeding it | Allocation concealment held |
| Blood pressure reading taken at visit 3 | EDC | The observed value |
| Adverse event term, grading and outcome | EDC | The safety observation |
| Query raised on an implausible value and its resolution | EDC | Data review took place |
| Locked analysis dataset | EDC | Data finalised before analysis |
| Date visit 3 happened, against its protocol window | CTMS | The visit met the schedule |
| Reason a visit fell outside its window | CTMS | The deviation was identified and handled |
| Staff member delegated to perform the assessment on that date | CTMS delegation record | The task was performed under authority |
| Protocol version live at the site on the visit date | CTMS site record | The assessment followed the current protocol |
| Screening, consent and recruitment counts by site | CTMS | Recruitment performance and portfolio reporting |
| Monitoring visit report and follow-up letter | CTMS | Sponsor oversight was exercised |
| Site contract, budget and payment milestone | CTMS | The site was engaged on agreed terms |
| IMP receipt, dispensing and accountability | Pharmacy site file | The product chain is complete |
| Signed protocol, ethics approval, insurance certificate | eTMF and investigator site file | The trial was authorised |
| Training record against the SOP version in force | Quality management system | Staff were qualified for the task |
Three of those rows cause most of the arguments. Recruitment counts appear in both systems and diverge, because the EDC counts participants with a completed enrolment form while the CTMS counts participants consented. Protocol deviations appear in both, because a data-driven deviation surfaces in the EDC and a conduct-driven deviation surfaces in the CTMS. Visit dates appear in both, because the EDC records the date on the form and the CTMS records the date against the window. Each pair needs one system named as the source of truth before the study opens.
What Goes Wrong When the Two Systems Sit Apart?
Separation shows up as a question nobody can answer from a single screen. The following scenario is hypothetical and built on a fictional NHS site, Northgate General NHS Foundation Trust, running an interventional study across three locations.
A monitor reviews an ECG result recorded against participant 014 at visit 3. The value sits in the EDC with a clean audit trail, a user ID and a timestamp. The monitor then asks the question the EDC has no field for: was the person who performed that ECG delegated to perform it on that date? The answer sits in a delegation log held elsewhere. The log shows the staff member was added to the study eleven days after the visit. The data point is sound. The authority behind it is missing. The finding lands against the conduct of the trial, and the EDC audit trail offers nothing that answers it.

Five failure modes follow the same shape. Each one costs staff hours that reach no invoice.
- Reconciliation repeats at every monitoring visit. Two systems hold overlapping counts, so a coordinator produces a manual comparison before each visit, and the comparison expires the day after it is signed.
- Out-of-window visits reach the data before they reach the study team. The EDC accepts the date on the form, and the deviation surfaces at monitoring rather than at booking.
- Delegation lapses are found retrospectively. A staffing change updates one system and leaves the other holding an authority position that expired weeks earlier.
- Protocol modifications land unevenly. The EDC build is updated on one date and the site visit schedule on another, which leaves a period where the two systems describe different studies.
- Recruitment reporting contradicts itself. A national return, a sponsor report and a data listing draw from different sources, so the same study reports three numbers in the same week.
None of these failures is caused by a careless individual. Each one is a condition created by two systems holding half a record with no shared key between them. The person changed. The system did not.
Also Read: CTMS vs eTMF: What Is the Difference?
What Do the UK Rules in Force Since April 2026 Require of Each System?
The amended UK Clinical Trials Regulations took effect on 28 April 2026. The MHRA guidance states that compliance with the ICH E6 GCP principles became a legal requirement in the UK on 28 April 2026. The legal requirement attaches to the principles rather than to the whole guideline. Regulation 28 of the amended regulations carries that obligation, and the principles apply proportionately to the risks to participants and to the importance of the data collected. Sponsors of trials already running on that date document an impact assessment and justify any procedure they keep unchanged.
ICH E6(R3) places data governance in its own section covering the full data life cycle, from capture and metadata through review, corrections, transfer, finalisation, retention and destruction. A separate section on computerised systems requires validation before use, access permissions assigned by duty and revoked when they are no longer needed, and a documented reason for every data change. Those requirements apply to the CTMS and the EDC equally. The table below maps each obligation to what a system has to produce.
| Obligation | What a system has to produce | Where the evidence sits |
| GCP principles apply as a legal requirement from 28 April 2026 | Proportionate procedures, evidenced across conduct and data | Both systems |
| Computerised systems validated before use, with access assigned by duty | A validation package and a user access history per role | Both systems |
| Every data change carries a documented reason | An audit trail holding the change, the reason and the author | Both systems |
| Registration of the trial and publication of a summary of results | A reliable trial end date and a milestone history | CTMS |
| Modifications classified and tracked to the day | A version history showing which document was live at each site on each date | CTMS |
| Essential documents retained for at least 25 years | Readable records, audit trails and metadata surviving the contract | eTMF, site file, and the archived data set |
Retention is the requirement most likely to outlive the software that created it. MHRA guidance on archiving states that the trial master file, including investigator site files, and the medical files of trial participants are retained for at least 25 years beginning the day after the conclusion of the trial. Data supporting a UK marketing authorisation application at the end of that period is held for a further two years after authorisation. The sponsor names an individual responsible for archiving. A three-year EDC subscription and a five-year study sit inside a twenty-five-year obligation, so the exit and extraction terms in both contracts matter more than the feature list.

Validate the system for the study. Plan the records for the archive.
Does a Study Need Both a CTMS and an EDC?
An interventional trial needs both functions. The practical question is how many systems deliver them and how the join between the two is governed. Small observational studies sometimes run the operational record in a spreadsheet alongside a data tool, and that arrangement holds until the first inspection request or the first staffing change. A named-product comparison of the same boundary appears in the guide to where data capture ends and study management begins.
Both systems are configured during study set-up, and both sit on the critical path to first participant. UK set-up performance is measured against published targets, so the build sequence has a delivery consequence as well as a quality one. The UK clinical research delivery KPIs track where that time is spent, and most sites still miss the 90-day set-up target at the local stage rather than the approval stage.
Seven questions test whether a proposed pairing holds together. Put them to each supplier in writing and keep the answers with the quotation.
- Which system is the source of truth for the visit date? One answer per study, agreed before the first participant.
- Which system is the source of truth for recruitment counts? The national return and the sponsor report should draw from the same place.
- How does a delegation change reach the other system? A manual step here becomes a standing reconciliation task.
- What does the integration cost to build, and what does it cost to maintain? Build cost is quoted and maintenance rarely is.
- What happens to the join when the protocol is modified? Two builds updated on two dates create a window where the systems disagree.
- What validation evidence does each supplier provide, and what does your team write? The GAMP 5 approach to computerised system validation sets out the deliverables involved.
- Who holds the records at contract end, in what format, and at what cost? The retention obligation runs for 25 years and the contract does not.
Also Read: What Is Clinical Research Software and How to Choose the Right One?
How Does AQ Connect Study Management and Data Capture?
AQ builds the conduct layer of a study. The clinical values stay in the EDC a study already uses, and the evidence of how those values were produced sits in one place. The modules of the AQ Platform share one access model, one audit trail and one study record, which removes the transfers and manual matches that separate operational systems create. The features and comparison page sets out what sits inside the platform.

- AQ CTMS holds study set-up, sites, recruitment and the visit diary, and the diary measures every booking against the protocol window at the point of booking, which prevents the deviation instead of documenting it.
- AQ Digital DoA records delegated roles, qualifications and effective dates, which lets a reviewer confirm the authority that existed on the date of any assessment.
- AQ eTMF and AQ eISF hold sponsor and site documentation in one structure, which lets a monitor open the site file and the trial master file against the same index.
- AQ ePSF holds the IMP chain from receipt to destruction, which ties each dispensing entry to the visit that generated it.
- AQ QMS and AQ CAPA link SOP versions and training records to the findings raised against them, which shows a reviewer the state of the system on the day of the event.
AQ is aligned with Good Clinical Practice, UK GDPR and 21 CFR Part 11, and supplies validation, data security and governance evidence for NHS and sponsor procurement. Assurance covers G-Cloud, DSPT and Cyber Essentials.
Book a live demo and the walkthrough runs on your protocol structure, your site set-up and your module requirements. Bring the seven questions above and use the session to test where each record would sit.
