How Does ICH E6(R3) Change the Rules for eSource?

ICH E6(R3) changes the rules for eSource in three places. It folds the two older source terms into one, source records. It requires the investigator to define what counts as source, and where each record sits, before the trial starts. It adds a data governance section that governs the system holding the record alongside the record itself.

This guide covers the clauses that apply to electronic source capture and what each asks of a site. It sits inside our wider guide to eSource in clinical trials for UK research sites. The definitions themselves are set out in our guide to what counts as source data in a clinical trial.

E6(R2) governed the record. E6(R3) governs the record and the system that holds it.

What Did ICH E6(R3) Replace in the Source Terminology?

E6(R3) replaces two defined terms with one. The MHRA Inspectorate describes the change directly: source data and source documents are combined into a new term, source records, reflecting trial information that sits across several computerised systems rather than in one paper file.

The ICH E6(R3) glossary defines source records as original documents or data, which includes relevant metadata, or certified copies of those documents or data, irrespective of the media used. Three consequences follow for a site running electronic capture.

  • Metadata sits inside the record. An export of values alone is an incomplete source record, so the audit trail is part of what is retained.
  • Media has no bearing on status. A paper worksheet and an electronic entry are judged by the same test.
  • A certified copy holds the standing of the original. The verification is documented by a dated signature or by generation through a validated process.

What Must a Site Define Before the Trial Starts?

Section 2.12.2 of Annex 1 puts the source declaration ahead of the first participant. The investigator should define what is considered to be a source record, the methods of data capture and their location prior to starting the trial, and should update that definition when needed. The clause adds a further instruction: unnecessary transcription steps between the source record and the data acquisition tool should be avoided.

That instruction gives electronic capture a direct footing in the guideline. A design that records the observation once, in the system that will hold it, satisfies the clause by construction.

  • Name the source per data point, so a duplicated value has one declared original.
  • Record the method of capture, so a reviewer knows whether a value was typed, transferred or participant-reported.
  • Record the location, so a monitor or inspector reaches the original without asking.
  • Version the definition, so it describes the arrangement in use on any given date.

The document that carries this at a UK site is the source data location log, covered in our guide to what a source data location log contains and who signs it off. The order that settles a value held in two systems is set out in our guide to which record is the source when data sits in both the EPR and the trial system.

Also Read: Types of eSource: Direct Data Capture, EHR, EHR-to-EDC and ePRO

What Does the Data Governance Section Require of an eSource Record?

Section 4.2 of Annex 1 follows one value through its life cycle, in eight stages. Each carries a requirement an eSource system either meets in configuration or leaves to the site.

ClauseStageWhat it asks of an eSource record
4.2.1Data captureData captured directly in a computerised system carries relevant metadata, verification of transcribed data follows its criticality, and entry checks are controlled and documented
4.2.2Metadata and audit trailsThe system logs account creation, role and permission changes and user access, documents the initial entry and every change or deletion with a reason where appropriate, and keeps audit trails enabled
4.2.3Review of data and metadataAudit trail review is a planned, risk-based activity with a written procedure
4.2.4Data correctionsEvery correction is attributed to the person or system making it, justified and supported by source records
4.2.5Transfer and migrationValidated processes maintain integrity when the record moves to an EDC system or a replacement platform
4.2.6Finalisation of data setsData sets meet a defined quality standard before analysis
4.2.7Retention and accessRecords are archived and protected from unauthorised access and alteration for the retention period
4.2.8DestructionRecords are destroyed only once regulatory requirements no longer call for them

Clause 4.2.2 carries the sentence a site is most often asked about at inspection. Audit trails, reports and logs are not disabled, and modification is allowed only in rare circumstances with a log and a justification. Each clause maps onto a data integrity attribute, and our guide to whether eSource meets ALCOA+ and the attributes inspectors check makes that mapping for all nine.

Six moments in the life of one eSource entry mapped to the ICH E6(R3) Annex 1 section 4.2 clause that governs each, from data capture at 4.2.1 to archiving at 4.2.7

What Does ICH E6(R3) Require of the eSource System Itself?

Section 4.3 sets out eight requirements for the computerised system. They apply to a site’s source capture system in the same way as to a sponsor’s data acquisition tool.

  • 4.3.1 Procedures. Documented procedures govern how the system is used.
  • 4.3.2 Training. Every user is appropriately trained in the system they use, and the training record is the evidence.
  • 4.3.3 Security. Named controls include user authentication and password management, firewall settings, antivirus software, security patching, system monitoring and penetration testing.
  • 4.3.4 Validation. Validation demonstrates conformance to established requirements for completeness, accuracy and reliability, covering protocol-specific configuration and interfaces as well as standard functionality.
  • 4.3.5 System release. A trial system is released to a site only once the approvals relevant to that site are in place, which ties go-live to the regulatory position.
  • 4.3.6 System failure. Contingency procedures prevent data loss, so an outage during a clinic has a written answer.
  • 4.3.7 Technical support. System issues are documented, managed and reviewed periodically.
  • 4.3.8 User management. Access is limited to authorised users and attributable to an individual, permissions follow a user’s duties and are revoked when no longer needed, access is reviewed periodically, and the user record is retained with the time each permission was granted.

Clause 4.3.8 binds the eSource user list to the delegation log. An account that can sign data the delegation log does not cover fails the clause on the day it is created. The procedures behind all eight sit in the site’s quality management system.

Who Is the Responsible Party for an eSource System?

E6(R3) assigns the duty per system and asks the sponsor to hold the register. Section 3.16 states that the sponsor should have a record of the important computerised systems used in a clinical trial, covering the use, functionality, interfaces and validation status of each, and describing who is responsible for its management.

The expectation then splits by who deployed it.

Decision branch showing which ICH E6(R3) expectation applies to a clinical trial system, with validation for trial use where the system was deployed for the trial and a fitness for purpose assessment for routine clinical care systems

A trust assesses its EPR for the trial. It validates the system it deployed for the trial.

That split matters at an NHS site using the EPR as source for part of a visit. The assessment, and the mitigations it produces, belong in the investigator site file beside the validation evidence for the trial system.

Also Read: eSource vs EDC: Where Source Data Ends and the CRF Begins

Which Parts of ICH E6(R3) Are Law in the UK?

The GCP Principles carry legal force in the UK, and Annex 1 carries the detail inspectors read against them. MHRA guidance on compliance with ICH E6 GCP in the United Kingdom states that compliance with the ICH E6 GCP Principles, as amended from time to time, and not the entirety of the guideline, becomes a legal requirement on 28 April 2026.

The same guidance expects sponsors to have assessed the principles and Annex 1 to determine the changes their quality management system needs by that date, and expects a documented impact assessment for trials already running. The UK-specific annotations to ICH E6(R3) set out where UK law adds to the ICH text.

The two tiers of ICH E6(R3) in the UK from 28 April 2026, with the ICH E6 GCP Principles as a legal requirement and Annex 1 as the detail inspectors read the principles against

Principle 9 reaches an eSource system directly. Four of its sub-points apply to source capture.

  • 9.2 asks that systems for data capture, management and analysis are fit for purpose, capture the data the protocol requires, and are proportionate to risk and to the importance of the data.
  • 9.3 asks that computerised systems used in trials are fit for purpose, for example through risk-based validation, with critical quality factors addressed in their design.
  • 9.4 asks for record management processes that maintain integrity and traceability and protect personal information.
  • 9.5 asks that essential records are retained securely for the period regulatory requirements set.

Principle 7 sets the dial for all of them. Processes should be proportionate to the risks to participants and to the importance of the data collected, which lets a site argue the depth of its controls from the study in front of it.

What Changes for a Site Between E6(R2) and E6(R3)?

The practical shift is one of scope. E6(R2) governed the adequacy of the record. E6(R3) governs the record, its metadata and the system that produces both.

AspectUnder E6(R2)Under E6(R3)
Source terminologySource data and source documents defined as two termsOne term, source records, with metadata inside the definition
Source declarationHandled through sponsor plans and local practiceRequired by section 2.12.2 before the trial starts, and updated when needed
TranscriptionAddressed through verification of reported dataUnnecessary transcription steps between source record and data acquisition tool should be avoided
Data governanceSpread across investigator and sponsor obligationsOne section covering the data life cycle from capture to destruction
Computerised systemsFramed around the sponsor’s electronic data handlingEight named requirements at section 4.3, applied to the responsible party for each system
Audit trail reviewCarried out as part of monitoringA planned, risk-based activity with its own procedure at section 4.2.3

A site already running electronic source capture meets much of this by configuration. The gaps sit in the written layer: the source definition, the audit trail review procedure, the system register entry and the periodic access review.

Sites building that written layer for a first electronic capture study may be interested that AQ is launching eSource soon as part of the AQ platform. Book a live demo to see the AQ platform today.

Guide
By Ash Mahmud· · · Book a 30 min demo
In this guide
AM
Written by
Ash Mahmud
Co-founder, AQ Trials

Ash has spent over twenty years inside clinical research operations and technology, working alongside NHS Trusts, CROs, sponsors, and academic research organisations. He co-founded AQ Trials to give research teams one connected, inspection-ready operational record.

See the connected platform behind this guide

A 30-minute walkthrough built around your operational priorities — study execution, documentation, quality and pharmacy in one governed record.

Book a 30 min demo →
See the AQ Platform in action — a 30-minute walkthrough for teams like yoursBook a 30 min demo →
Free guides · PDF
Find the right guide for you

Pick a module, your organisation type, or both — we'll match the guides and email them to you.

Most popular guides
Explore
15+ guides

Free guides · PDF

Guides matched to you.

Written for first-in-human & Phase 1 sites

Inspection-ready checklists & templates

Aligned to MHRA, FDA & EU Annex 11