A source data location log is the site’s written record of where the original of every data point in a study is held, and the principal investigator signs and dates it, or a person the investigator has formally assigned that task. The log is prepared before the trial starts at the site, agreed with the sponsor, and updated whenever the way a value is captured changes.
This guide is written for UK research sites that need the document itself to stand up at inspection. It covers what belongs in the log, how specific each entry has to be, who signs it off and when, where it is filed and who holds a copy, how versions are controlled, and the failure modes inspectors write up. The wider context sits in our complete guide to eSource in clinical trials.
The log is the one document that tells a stranger where to look.
What Is a Source Data Location Log?
The log is an index. It lists each data point the protocol collects and names the record that holds the original, so a monitor, auditor or inspector can find the source without asking a member of staff. Sites and sponsors also call it a source data location list, a source document location list or a source data agreement, and the name on the template changes nothing about its function.
The duty behind it is an investigator duty. ICH E6(R3) states at section 2.12.2 that the investigator should define what is considered to be a source record, the methods of data capture and their location prior to starting the trial. The EMA guideline on computerised systems and electronic data in clinical trials puts the same requirement in operational terms at section 6.1, asking that the location of all source data is specified prior to the start of the trial and updated during its conduct where applicable.
Three neighbouring documents are often confused with it:
- The protocol states which data the study collects. The log states where each of those values is recorded first.
- The delegation of authority log states who may perform each task. The source data location log states which record their entry lands in.
- The monitoring plan states how often the sponsor checks the data. The log tells the monitor which record to open when they arrive.
The decision recorded in the log is a separate question from the document. Our guide to which record is the source when data sits in both the EPR and the trial system covers how a site reaches that decision for a duplicated value.
What Goes in a Source Data Location Log?
Each row covers one data point and answers six questions about it. The row is complete when a reader who has never visited the site could open the right record from it.
| Column | What it records | Worked entry |
| Data point | The assessment as it is named on the schedule of events | Full blood count, visit 3 |
| Source record | The system or document holding the original, named to the screen or form | Trust laboratory information system, authorised FBC report |
| Who may create it | The role or device authorised to make that original | Hospital pathology laboratory |
| Copies held elsewhere | Any second record carrying the value, and which record it is reconciled against | Visit 3 eSource form, reconciled against the laboratory report |
| Format and retrieval | Whether the original is electronic or paper, and how it is retrieved | Electronic, retrieved by participant identifier and sample date |
| Effective from | The date the arrangement applies from | 14 September 2026 |
Coverage is the harder half of the job. A log that lists laboratory results, vital signs and adverse events, then stops, leaves the fields that generate the most queries undeclared. Eligibility decisions, consent, concomitant medications, investigational product dispensing, participant-reported outcomes and device output each need their own row, because each has a different originator. Our guide to what counts as source data in a clinical trial sets out the usual original for each data type.

How Specific Does Each Entry Need to Be?
An entry is specific enough when it names the record a reader can open, and no looser than that. The Danish Medicines Agency makes the point directly in its guidance on source data lists, stating that the list must be sufficiently detailed to make it easy to locate the data and that an entry such as “medical record” is too vague. Its own example goes down to the specific chart within the patient record where dispensing and administration are written.
The same field gets sharper across three levels of entry:
- Too vague: “medical record”. The reader learns only that the value exists somewhere in the hospital.
- Closer: “EPR”. The reader knows the system and still has to hunt through it for the right module.
- Usable: “EPR, inpatient observations chart, recorded by the ward nurse at the visit”. The reader opens the record on the first attempt.

Specificity has a practical cost at an NHS trust, where one value can sit in several EPR modules. The log entry should describe the module a member of research staff would actually open, and the site confirms that description against the live system rather than against the template it inherited.
Who Signs Off a Source Data Location Log?
The principal investigator signs and dates it. The Danish Medicines Agency states the position plainly for the source data list, requiring that it is signed and dated by the principal investigator or by a person the principal investigator has assigned the task, and that it is prepared before the trial is initiated. The investigator keeps the accountability either way, because ICH E6(R3) places the definition of source records and their location with the investigator.
Four sign-off conditions make the signature meaningful:
- The signature is dated before the first participant is enrolled at the site, so the arrangement predates the data.
- A delegated signatory appears on the delegation log for that task, with an effective date that covers the day they signed.
- The sponsor has agreed the content, usually at or before the site initiation visit, so the monitor verifies against the record the site named.
- The staff who capture the data have read the version in force, which is what turns a signed document into daily practice.
Sponsor agreement matters for a specific reason. ICH E6(R3) requires at section 3.16.4 that the protocol or another documented agreement specifies that the investigator provides direct access to source records for monitoring, audit and inspection. The log is where that access becomes concrete, naming the systems a monitor will need and, at an NHS trust, the ones that need local information governance approval first.
Where Is the Log Filed and Who Holds a Copy?
The signed log is filed in the investigator site file, and the sponsor holds a copy in the trial master file. The Danish Medicines Agency guidance states both locations for the source data list, at the investigator site and with the sponsor. Each reader uses the same document for a different purpose.

- Site staff read it to know which record their entry belongs in.
- The investigator reads it to see the scope of the data under their oversight.
- The monitor reads it before verification, to locate the source for each reported field. The site’s clinical trial management system holds the schedule and the record of that visit.
- The sponsor reads it to confirm the reported data trace to declared originals.
- An inspector reads it first, then tests whether practice matches it.
Retention follows the rest of the site file. Every version stays retrievable for the statutory period, which MHRA archiving and retention guidance sets at a minimum of 25 years for trials applied for from 28 April 2026.
How Is the Log Version Controlled?
Each issue of the log carries a version number, an effective date and a reason for the change, and the superseded version stays in the file. A visit conducted in March is judged against the arrangement in force in March, so a single current version with no history leaves the earlier data unexplained.
| Version | Effective from | Reason for change | Signed by |
| 1.0 | 14 September 2026 | Initial issue before first participant | Principal investigator |
| 1.1 | 2 November 2026 | Laboratory results moved to a new pathology system | Principal investigator |
| 2.0 | 19 January 2027 | Protocol amendment 2 added an imaging assessment | Principal investigator |
| 2.1 | 6 April 2027 | Paper vital signs worksheet replaced by an electronic form | Delegated research manager |
A change to the log is a change to a controlled document, so it follows the site’s own procedure rather than an email. The procedures for document control, periodic review and staff notification sit in the site’s quality management system. A site part-way through a move from paper to electronic capture will hold two arrangements at once, and the log is where the cut-over date for each group of fields is written down. The evidence each format produces is compared in our guide to eSource versus paper source worksheets.
What Goes Wrong With a Source Data Location Log?
Most problems are document problems rather than data problems. The log exists, and it fails to do the one job it was written for.
- A sponsor template is filed unchanged, so it names systems the site does not run.
- Entries stop at the system name, so the monitor still has to ask where a value lives.
- The signature carries no date, or a date after the first participant was enrolled.
- The signatory has no delegation for the task on the date they signed.
- Only the current version is in the file, so visits conducted under earlier arrangements cannot be assessed.
- A data type added by a protocol amendment never reaches the log.
- The log describes one practice and the staff describe another, which turns a documentation gap into a data integrity finding.
Each of these is a system condition rather than a personal failing. The MHRA GXP data integrity guidance expects data to satisfy the ALCOA+ attributes across its whole lifecycle, and a value whose original nobody can locate fails on originality before the number itself is examined. The MHRA also notes that this guidance introduces no new statutory requirements for clinical trials, so the control belongs inside the quality system a site already runs.
A log that nobody can navigate is a log that has already failed.
Sites keeping this log current across several studies usually find the effort sits in the updates rather than the first issue. AQ is launching eSource soon as part of the AQ platform. Book a live demo to see the AQ platform today.
