NHS R&D site file governance is the trust-level control that keeps every study’s electronic Investigator Site File complete, current, and consistent across the whole research portfolio. A trust runs many studies at once, across many departments, under one legal duty of research governance. The Research and Development office holds that duty. It sets the filing standard, checks that each study meets it, and can produce inspection-ready evidence for any study on any day.
A single study with a tidy site file is not the goal. A trust proves governance when every study, in every department, follows the same structure and stays current together. The UK Policy Framework for Health and Social Care Research places that responsibility on the organisation, not the individual coordinator. This guide explains what an R&D office must govern, how consistency breaks when each study files on its own, and the controls that hold a trust-wide standard across the portfolio.
Key takeaways
- The R&D office owns trust-wide research governance under the UK Policy Framework. Each study inherits one filing standard rather than inventing its own.
- Site file governance fails at the trust level when structure, delegation currency, and archiving differ from study to study.
- Five controls carry a trust-wide standard: site file structure, delegation and training evidence, pharmacy documentation, retention, and data security.
- A single portfolio view shows the R&D office which studies are inspection-ready and which need action, before an inspector asks.
What does an NHS R&D office govern across a trust’s studies?
An NHS R&D office governs the standard, the currency, and the evidence of research documentation for every study the trust delivers. In most NHS research the trust acts as a research site, and sometimes as the sponsor. As a site it employs the research team and remains responsible for the care of participants. The R&D office confirms capacity and capability before a study opens, then holds oversight through delivery and into archiving.
The UK Policy Framework assigns responsibilities to organisations, funders, sponsors, and sites. A trust reads that framework as a duty to run all of its studies to one governed standard. Good clinical practice and ICH-GCP E6(R3) then apply to each study inside that portfolio. The R&D office governs six things across every study:
- The site file standard. One structure for the Investigator Site File, so a monitor finds the same index in Oncology as in Cardiology.
- Delegation and authority. A current record of who is authorised to do what, with an effective date before the work.
- Training and competency. Evidence that each delegated person is trained for the task they perform.
- Pharmacy accountability. Investigational product records held to one standard where the trust dispenses.
- Retention and archiving. One retention rule and a plan to keep records readable for the full period.
- Data security. One assurance standard for the systems that hold participant and trial data.

The office holds this standard from the first confirmation of capacity and capability to the final archive. Each study moves through the same lifecycle, so the R&D team governs a repeatable process rather than a set of one-off arrangements.
Why does site file governance break across a trust’s studies?
Governance breaks when each study team designs its own filing, because the trust then holds as many standards as it holds studies. A coordinator sets up the Oncology site file one way. A different coordinator files Cardiology another way. Both look complete on their own. The R&D office has no single view that confirms either one is current, and no template that a new study inherits by default.
The essential documents that prove a study was run properly then live in different places, in different orders, at different versions. A delegation log lapses when a staff member leaves and the study team forgets to update it. A training certificate expires without a trigger. A monitoring visit surfaces the gap months later, when the visit window for a correction has already passed. The problem is structural, not personal. The person changed. The system did not.
A trust with forty active studies and no common standard is not running forty tidy files. It is running forty separate risks that surface one at a time.
How does study-by-study filing compare to a trust-wide standard?
Study-by-study filing puts the burden on each team to remember the standard. A trust-wide standard puts the structure in place once and lets every study inherit it. The contrast shows up most clearly at a monitoring visit or an inspection, when the difference between a scramble and a routine becomes visible.
| Aspect | Study-by-study filing | Trust-wide governance |
| Site file structure | Each team designs its own layout | One template every study inherits |
| Delegation currency | Checked mainly at monitoring visits | Kept current and visible continuously |
| Portfolio visibility | The office asks each team in turn | One view across every study at once |
| Archiving | Decided study by study | One retention standard applied |
| Inspection | Prepared in a scramble | Evidence available on any day |

Also Read: eISF vs Paper Site Files: Closing the Monitoring Visit Gap.
What must a trust standardise across every study’s site file?
Five controls carry a trust-wide standard. Each one turns a study-level habit into a governed rule the R&D office can check across the portfolio.
| Control | What a trust-wide standard looks like | Where it lives |
| Site file structure | One ISF template, same zones and index for every study | eISF |
| Delegation and authority | Every task authorised with an effective date before the work | Digital DoA |
| Training and competency | Each delegated person trained for the task, dated before delegation | QMS |
| Pharmacy documentation | Accountability and storage records held to one standard | ePSF |
| Retention and archiving | One retention rule and a readable-media plan | eISF and eTMF |
- Site file structure. One template applies the same zones and index to every study, which means a monitor or inspector navigates any file without a guided tour.
- Delegation and authority. A Digital Delegation of Authority record ties each task to an authorised person and an effective date, which closes the gap an effective date rather than a later signature is meant to prove.
- Training and competency. A quality management system holds training and competency evidence dated before delegation, which lets an auditor join the delegation log to the training record without a manual search.
- Pharmacy documentation. An electronic Pharmacy Site File holds accountability and storage records to one standard, which keeps investigational product evidence consistent wherever the trust dispenses.
- Retention and archiving. One retention rule and a readable-media plan keep every study’s records available for the full period, which removes the study-by-study guesswork at close-out.
Data security sits underneath all five. A trust evidences it through the NHS Data Security and Protection Toolkit, which applies one assurance standard to the systems and staff that handle participant and trial data across the portfolio.

How does an R&D office prove readiness across the whole portfolio?
The R&D office proves readiness through one view that scores every study against the same controls. A study-by-study check finds a gap only when someone opens that study’s file. A portfolio view surfaces the weak study before an inspector does, because it grades each domain and flags the studies that fall below the standard.
This is the difference between holding files and holding oversight. A red-amber-green score across the portfolio turns a pile of separate site files into a single readiness picture. Inspection readiness then becomes a daily condition rather than a project the trust starts when the MHRA gives notice. The office acts on the flagged study while the correction window is still open, and the rest of the portfolio stays current in the background.
Also Read: What is a Clinical Research Delivery Centre and How Does Multi-Site Research Oversight Work?
Who owns each part of site file governance in a trust?
Governance works when responsibility is explicit. The R&D office sets and checks the standard, and delivery sits with named roles in each study. A clear split stops a control from falling between the office and the study team, which is where most gaps form.
| Role | Responsibility in site file governance |
| R&D office | Sets the standard, checks currency across the portfolio, holds the organisational duty |
| Principal Investigator | Signs the delegation log and confirms each delegate is authorised and competent |
| Research coordinator | Files essential documents and keeps the site file current day to day |
| Research pharmacy | Maintains investigational product accountability and storage records |
| Quality and audit | Runs internal audit, tracks CAPA, and confirms the standard holds in practice |
The R&D office remains accountable for the standard the trust applies, even where named roles perform the individual tasks. A governed quality management system gives each role one place to record its part, so the office reviews a single trail rather than chasing five separate ones.
What are the risks of leaving governance to each study team?
- Inconsistent evidence. Two studies present the same essential document in different places, so an inspector reads variation as a control weakness across the trust.
- Lapsed delegation. A staff change breaks a delegation log that no trigger updates, which leaves work performed without a current authority.
- Hidden gaps. A missing document stays invisible until a monitoring visit, by which point the correction window has often closed.
- Archiving drift. Each study decides retention on its own, which risks records becoming unreadable or unaccounted for years later.
- Scramble at inspection. The trust rebuilds evidence under time pressure rather than presenting it, which raises the chance of a finding.
How does AQ support trust-wide site file governance?
AQ gives an NHS R&D office one connected environment for every study’s documentation, so the trust governs to a single standard instead of many. The electronic Investigator Site File applies one structure to every study. The Digital Delegation of Authority keeps authority current and dated. The quality management system holds training and competency evidence, and CAPA escalates a persistent gap into a tracked action. Where the trust dispenses, the electronic Pharmacy Site File holds accountability to the same standard. The connected platform then presents one portfolio view across every study.
AQ structures the record and surfaces the gap. The R&D office still owns the judgement, the sign-off, and the accountability the UK Policy Framework assigns to the organisation. A digital site file does not fix a poor filing habit on its own. One governed structure, applied to every study and checked from a single view, is what holds the standard. AQ is built for NHS hospital research that runs a portfolio this way.
See how AQ governs site files across a trust’s whole portfolio. Book a 30-minute product tour.
