ePSF vs eISF: Why Pharmacy Documentation Needs Its Own File

The pharmacy file is not a folder inside the investigator site file. It is a separately owned, separately held, separately inspected record — and the sites that treat it as a subfolder are the sites that struggle when an MHRA pharmacy inspector arrives.

The confusion is understandable. Both files hold the protocol. Both hold the investigator brochure. Both carry copies of the same ethics and regulatory approvals. On paper they look like two versions of one thing.

They are not. The two files answer to different owners, sit in different physical locations, follow different access rules, and fail in different ways. A trial can have a spotless electronic Investigator Site File and still collect a critical finding because the pharmacy accountability trail did not reconcile.

Key Takeaways

  • The investigator site file (eISF) and pharmacy site file (ePSF) are separate records with different owners, custody, and inspection focus.
  • The pharmacy file stays in pharmacy under the delegated research pharmacist; the ISF stays under investigator control at all times.
  • They overlap only at the top — protocol, investigator brochure, approvals. IMP receipt, storage, dispensing, accountability, and destruction belong to the pharmacy file alone.
  • MHRA GCP inspections read the pharmacy file for accountability integrity and ALCOA+ — a different test from ISF document completeness.
  • AQ keeps ePSF and eISF as distinct but connected files, so pharmacy gaps escalate to CAPA without collapsing the custody boundary.

Sites that keep the two files properly separated — with clear ownership on each side — see the difference at inspection:

  • Pharmacy accountability reconciles on the first pass, not after a reconstruction exercise
  • Temperature excursions are documented, reported, and resolved against the right study
  • Dispensing records match source, participant, and visit without correction-fluid corrections
  • The investigator site file stays under investigator control while the pharmacy record stays under pharmacy control

This guide explains what each file is, why pharmacy documentation earns its own file, and why the separation still matters once both go digital.

What Is the Investigator Site File, and What Is the Pharmacy Site File?

The investigator site file (ISF) is the site-level record of everything required to run the trial and prove it was run correctly. It holds the protocol and amendments, the investigator brochure, ethics and MHRA approvals, signed consent form versions, the delegation of authority log, training records, monitoring visit logs, and site correspondence. Under ICH-GCP E6(R3), these are essential records, and the investigator must retain control of the ISF at all times — even at the point of archiving.

The pharmacy site file (PSF) is the pharmacy-level record of everything required to control the investigational medicinal product (IMP). It holds the pharmacy signature and delegation list, pharmacy-specific dispensing procedures, IMP receipt and shipment records, storage and temperature logs, dispensing and accountability logs, returns, destruction certificates, the randomisation and unblinding procedure, and any Qualified Person (QP) release documentation.

The traditional relationship is where the trouble starts. The pharmacy file has long been described as a section of the ISF that covers IMP management — but it is kept in the pharmacy throughout the trial, maintained by the delegated research pharmacist, and reconciled or archived separately at close-out. It is part of the same evidence chain. It is not part of the same file.

Pharmacy-specific documentation now lives in its own controlled record: the electronic Pharmacy Site File. It follows the same controls as the ISF — structured folders, permissions, versioning, audit trails — but it operates in a separate domain, under separate hands.

Why Does Pharmacy Documentation Need Its Own File?

Four structural realities make the pharmacy record a distinct file. Each one exists whether the file is paper or electronic.

Different custody. The investigator retains control of the ISF. The pharmacy retains control of the pharmacy file. IMP is stored in a designated, secure area accessible only to authorised personnel, and the record that governs it stays with that area. A research pharmacist does not hand their dispensing logs to the coordinator, and a coordinator does not file consent versions in the pharmacy. Merging the files breaks a custody boundary that inspectors expect to see maintained.

Different ownership of responsibility. Under ICH-GCP E6(R3), overall responsibility for IMP management — accountability, handling, dispensing, administration, and return — rests with the investigator. In practice the investigator delegates that responsibility to trained pharmacy staff. The pharmacy file is where that delegation is evidenced: its own signature list, its own delegated authorities, its own training records for the people who touch the drug. This is why pharmacy delegation belongs in the pharmacy record and connects to the site’s broader delegation of authority picture rather than disappearing into it.

Different access rules. The ISF is visible to the site team, the monitor, and the inspector. The pharmacy file governs a controlled-access environment where not everyone who can read the ISF should be able to see — or edit — dispensing and stock records. A file structure that cannot restrict pharmacy folders to pharmacy users cannot hold a pharmacy record safely.

Different reviewers and different failure modes. The ISF is reviewed for documentation completeness. The pharmacy file is reviewed for accountability integrity — receipt, storage, dispensing, reconciliation, return, destruction, end to end. An investigator site file gap looks like a missing document. A pharmacy file gap looks like a stock count that does not add up on dispensing visit 47. They are found by different people looking for different things.

What Goes in Each File?

The contents overlap at the top and diverge sharply below it. A compact view:

RecordInvestigator Site File (eISF)Pharmacy Site File (ePSF)
Protocol, amendments, investigator brochureYesYes (working copies)
Ethics / MHRA / R&D approvalsYesCopies as required
Signed consent form versionsYesNo
Delegation of authority logYes (site-wide)Pharmacy signature/delegation list
Training recordsSite staffPharmacy staff
IMP receipt and shipment recordsNoYes
Storage and temperature logsNoYes
Dispensing and accountability logsNoYes
Returns and destruction certificatesNoYes
Randomisation / unblinding procedureReference onlyYes (operational)
QP release documentationNoYes

The shared documents at the top are exactly what makes people assume the files are one. The rows below are exactly why they cannot be.

Where the Two Files Fail When They Are Merged

Merging pharmacy records into the investigator site file does not save effort. It moves the effort to inspection week, and it adds risk.

Handover breaks first. A new research pharmacist starts. The handover document references “the dispensing record” without specifying which record for which study, because the pharmacy detail was never structured as its own file.

Weak setup: pharmacy records folded into the general site file, owned by whoever set up the study. Two weeks in, the new pharmacist signs off a dispensing record for the wrong version, and the log does not show when authorisation actually transferred.

Strong setup: a distinct pharmacy file with its own signature list and its own delegation history, so the transfer of authority is dated, named, and visible before the first dispensing.

Reconciliation breaks next. Three studies are open in pharmacy. IMP-014 sits in one accountability log, IMP-027 in another, IMP-031 on paper. When the totals are reconciled for the monthly QP review, a discrepancy surfaces on a dispensing visit that no one had flagged. A merged file hides this until someone goes looking. A dedicated pharmacy file with completeness tracking surfaces the gap in daily operations.

Inspection breaks last, and hardest. The MHRA pharmacy inspector asks for the complete accountability trail on one IMP — receipt date, storage conditions over time, dispensing records, return reconciliation, destruction certificate. If that chronology is scattered across a site file structured for documents rather than for drug accountability, the team spends hours reconstructing what should have been a single, ordered record.

What Inspectors Actually Check in the Pharmacy File

IMP management is a recurring finding area in MHRA GCP inspections. The pharmacy file is where those findings land, and the pattern is consistent.

Inspectors and monitors check the accountability logs for missing entries, balance errors, and discrepancies against source. They check that dispensing entries were made at the time of the activity — a retrospective entry is a data-integrity violation, not a tidying-up exercise. They check temperature monitoring records to confirm storage stayed within range, and that any excursion was reported to the sponsor and resolved. They check that correction fluid was never used on an accountability form.

Every one of these checks is an ALCOA+ check: attributable, legible, contemporaneous, original, accurate, and — the ones pharmacy files fail most often — complete and consistent. A record that cannot show who dispensed what to which participant at what time, contemporaneously, is a finding waiting to be written.

None of these are ISF checks. They are pharmacy checks, run against a pharmacy record, by a reviewer looking specifically at drug accountability. That is the clearest argument for a separate file: the questions are different, so the file has to be built to answer them.

Read also: What is ePSF in Clinical Trial Data Management? — a step-by-step view of what a pharmacy site file manages across a study. For the other side, electronic Investigator Site Files covers the ISF in the same depth.


Does Going Digital Remove the Need for a Separate File?

Digitising both records does not merge them. It makes the separation cleaner — and it is why AQ builds the pharmacy file as its own module rather than a folder inside the eISF.

A single flat document repository would technically hold both files. It would also reproduce every problem above in electronic form: pharmacy records visible to people who should not edit them, accountability gaps buried in a document tree built for completeness rather than reconciliation, and no structural line between investigator custody and pharmacy custody.

AQ splits ePSF from eISF for the same reasons the paper files were always separate, and adds the connection the paper files never had:

  • Pharmacy-only structure and access. The pharmacy file has its own folder templates — IP accountability, storage and temperature, dispensing, destruction — and its own role-based permissions. Restricted pharmacy folders stay invisible to unauthorised users, so the custody boundary holds inside the system.
  • Accountability tracking built for drug, not document. Completeness indicators surface a missing receipt log or an overdue reconciliation as an operational signal, before it becomes an inspection finding.
  • Connection without collapse. Pharmacy documentation aligns with site records in the eISF instead of being absorbed by them. Accountability gaps escalate into CAPA. Study, sites, and milestones flow in from the CTMS. The files stay distinct; the evidence stays connected.

Multi-site delivery makes this sharper still, where one pharmacy supports several studies across a network. AQ’s own multi-site documentation governance case shows the eISF and ePSF operating as separate files under one connected record.

How AQ ePSF Supports Pharmacy Documentation Control

The point of a dedicated electronic pharmacy site file is not to replace the pharmacist’s judgement. It is to give pharmacy documentation a structure that matches how inspectors read it and how pharmacy teams actually work.

AQ ePSF gives each study a structured pharmacy file generated from a reusable template — IP accountability, receipt logs, storage and temperature, dispensing diaries, destruction certificates — so the file is consistent across studies and sponsors rather than rebuilt by whoever set it up. Records are uploaded, versioned, locked, and restored within that structure, with a full, exportable audit trail on every action. Dispensing and authorisation activity links to named pharmacy users. Completeness indicators show which records are filed, missing, or awaiting sign-off across every active study. Approvals run through controlled review workflows with 21 CFR Part 11 electronic signatures, and true-copy certification captures a SHA-256 hash against a downloadable certificate.

The system does not reconcile the drug count for you. Physical stock still has to match the record, and that verification remains a pharmacy task — the ePSF surfaces the discrepancy and holds the evidence, but a person confirms the count. The system does not decide who may dispense; it enforces the access and delegation the pharmacy defines. And it does not remove the pharmacist’s responsibility for contemporaneous entry — it timestamps and attributes every action, which makes contemporaneous recording easy to evidence and retrospective entry easy to spot.

What it does remove is the reconstruction exercise. IMP accountability stays structured and accessible throughout the study, aligned to the eISF and connected to quality workflows, so the pharmacy stays close to inspection-ready every day rather than the week before an inspection is announced. Records in the UK must be retained for at least 25 years after the trial ends; a controlled digital file is built to carry that retention without the file degrading into a box no one can navigate.

The investigator site file and the pharmacy site file were never the same record. They were always two files, owned by two teams, answering two sets of questions. Keeping them distinct — and connected — is what keeps both ready when someone asks to see the trail.

See how AQ keeps the eISF and ePSF as separate, connected files — book a 30-minute product tour.

Guide
By Ash Mahmud· · · Book a 30 min demo
In this guide
AM
Written by
Ash Mahmud
Co-founder, AQ Trials

Ash has spent over twenty years inside clinical research operations and technology, working alongside NHS Trusts, CROs, sponsors, and academic research organisations. He co-founded AQ Trials to give research teams one connected, inspection-ready operational record.

See the connected platform behind this guide

A 30-minute walkthrough built around your operational priorities — study execution, documentation, quality and pharmacy in one governed record.

Book a 30 min demo →
See the AQ Platform in action — a 30-minute walkthrough for teams like yoursBook a 30 min demo →
Free guides · PDF
Find the right guide for you

Pick a module, your organisation type, or both — we'll match the guides and email them to you.

Most popular guides

Explore

15+ guides

Free guides · PDF

Guides matched to you.

Written for first-in-human & Phase 1 sites

Inspection-ready checklists & templates

Aligned to MHRA, FDA & EU Annex 11