eSource in a clinical trial is used by seven roles: the research nurse who records the observation, the principal investigator who oversees and endorses it, the site data manager who resolves queries on it, the clinical trials pharmacist who records dispensing against it, the monitor who reviews it, the QA lead who audits it, and the sponsor who receives the reported data. Each role touches the same record, and each leaves a different mark on the audit trail.
This guide sits in our series on eSource in clinical trials. It covers what each role does with an electronic source record, which of them may change data and which may only read it, the ICH E6(R3) clauses that set each duty, and the record that authorises every user.
Every entry has one author. The rest of the study reads it.
Who Creates an eSource Record and Who Only Reads It?
Four of the seven roles create or change data in the system. Three of them read the record and act on what they find. That boundary is the practical division of labour in electronic source capture, and the delegation log is what places each user on one side of it.
| Role | What the role does with the eSource record | Record that authorises it |
| Research nurse or practitioner | Records visit observations and assessments as they happen | Delegation log entry for data entry |
| Principal investigator | Oversees the record, reviews and endorses the reported data | ICH E6(R3) section 2 investigator duties |
| Site data manager or coordinator | Checks completeness, answers queries, corrects with a reason | Delegation log entry for data management |
| Clinical trials pharmacist | Records receipt, dispensing and product accountability | Delegation log entry and pharmacy procedures |
| Monitor | Verifies source data within scoped read access | Monitoring plan and site access arrangement |
| QA lead or auditor | Audits the trail, the corrections and the access list | Site quality management system |
| Sponsor | Receives the reported data and analyses it | Protocol and clinical trial agreement |
Three data originators sit outside that list, and each one still produces source data the site answers for. FDA guidance on electronic source data calls them authorised data originators and expects each data element to be associated with one.
- The participant, where the study collects symptom scores or diaries through ePRO on a device.
- The hospital laboratory or imaging system, which issues a result the site never retypes.
- The electronic patient record, where clinical staff record the observation as part of routine care.
Our guide to the types of eSource covers what each route captures, and the source data location log declares which system holds the original for each data point.
What Does a Research Nurse Do in an eSource System?
A research nurse creates most of the record. The entry is made in the system at the time of the observation, which is the point that makes it source data rather than a copy.
- Enters vital signs, assessments and visit dates during the visit, so the system stamps the time instead of the user typing one.
- Works from forms built to the protocol schedule of events, which keeps the visit window visible at the moment of entry.
- Enters only the data types the delegation log covers, which keeps every value attributable to an authorised person.
- Gives a reason for any later change, so the first value stays visible in the audit trail.
The attributes at stake are attributable and contemporaneous, and our guide to whether eSource meets ALCOA+ maps each attribute to the control that evidences it.
Also Read: What Counts as Source Data in a Clinical Trial?
What Is the Principal Investigator Responsible For?
The principal investigator holds the responsibility the record has to evidence. Delegation moves the task, and it leaves the accountability where it started.
| Duty | ICH E6(R3) clause | What it looks like in an eSource system |
| Retain responsibility for delegated activities and keep oversight of them | 2.3.1 | A review queue the investigator works through, rather than a signature at the end |
| Maintain a record of the persons to whom activities are delegated | 2.3.3 | A delegation log that matches the system’s user list, role by role |
| Ensure the accuracy, completeness, legibility and timeliness of reported data | 2.12.5 | Endorsement of the reported data at the milestones the protocol sets |
| Hold overall responsibility for trial-related medical care and decisions | 2.7.1 | Clinical significance and eligibility decisions recorded under the investigator’s account |
Our guide to how ICH E6(R3) changes the rules for eSource covers the data governance and computerised system clauses that sit behind these duties.
Who Resolves Queries and Checks Completeness at the Site?
The site data manager or study coordinator keeps the record complete between the visit and the monitoring review.
- Reviews entries for missing or out-of-range fields after each visit, which shortens the query cycle.
- Answers monitor queries inside the system, so the question and the answer stay attached to the record.
- Corrects data under the same reason-for-change rule as the person who first entered it.
- Keeps the source data location log current when a study adds or changes a data source.
The limit on this role is the delegation log. A coordinator may correct a transcription error in a visit form, and a clinical assessment stays with the clinician who made it.
What Does a Clinical Trials Pharmacist Record?
The clinical trials pharmacist records the movement of the investigational product. ICH E6(R3) places responsibility for product management with the investigator and institution at section 2.10.1, and section 2.10.2 states that a delegated individual should be under the oversight of the investigator or institution.
- Receipt and inventory of each delivery, which starts the accountability chain.
- Dispensing records for each participant against the prescription, completed at the time of dispensing.
- Storage conditions, including each temperature excursion and the action taken.
- Return, destruction or other disposition of unused product, as section 2.10.4 requires.
Pharmacy records usually sit in their own file and often in their own system. A study using electronic source at the clinic and paper in the pharmacy holds two originals for one participant visit. Our guide on why pharmacy documentation needs its own file covers that separation, and the electronic pharmacy site file is where those records are held.
What Does a Monitor See in an eSource System?
A monitor sees the fields in scope for the study and nothing beyond them. ICH E6(R3) places monitoring with persons who take no part in the clinical conduct of the trial at section 3.11.4, and asks at section 3.11.4.5.3 for verification of the accuracy, completeness and consistency of reported data against the source records.
- Read access to the source entries the monitoring plan covers at that site.
- The audit trail behind each entry, which shows the entry time and every change since.
- A query function recording the question, the responder and the resolution date.
- No write access to clinical data, so the record stays the site’s own.
Access arrangements for monitors who work remotely, and the information governance approvals an NHS trust applies to them, form a separate subject. The planning of the monitoring visits themselves belongs to the site’s clinical trial management system.
What Does a QA Lead Check?
A QA lead tests whether the record can prove itself without help from the people who made it. The audit is a comparison between four artefacts that should agree.
- The system user list against the delegation log, checked on a date in the past rather than today.
- A sample of corrections against the reason recorded for each one.
- Training records against the accounts that were active at first patient in.
- Validation and user acceptance testing evidence held in the investigator site file.

The procedures behind those checks belong to the site’s quality management system, which holds the SOPs for correction, periodic access review and system validation. The MHRA sets out the expectations these checks test against in its GXP data integrity guidance.
What Does the Sponsor Receive, and Where Does Its Control Stop?
The sponsor receives the reported data and analyses it. Control of the source record stays with the site, and ICH E6(R3) states the limit directly at section 3.16.1: the sponsor should not have exclusive control of data captured in data acquisition tools, in order to prevent undetectable changes.
| Sponsor duty | Effect at the site |
| Give the investigator timely access to the data collected under the protocol | The site reads its own study data throughout the trial |
| Hold no exclusive control of data captured in data acquisition tools | The site keeps a copy or an independent route to the record it created |
| Keep a record of authorised users, their roles and their permissions | Every account traces back to an approval |
| Obtain direct access to source records through the site agreement | Monitoring and inspection reach the original record itself |

The boundary between the source record and the case report form decides what the sponsor holds. Our guide to where source data ends and the CRF begins sets out that boundary, including the case where the electronic case report form is itself the source.
How Does Access Follow the Delegation Log?
Access follows delegation through four links, and each link has to hold for a value to be defensible. The chain runs from the delegated task to the audit trail entry that proves who performed it.
- The investigator delegates a task to a named person, effective from a stated date.
- The delegation of authority record holds that task, that person and that date.
- The system grants a role whose permissions match the delegated task, and no more.
- The audit trail attributes each entry to that account, with the date and time of entry.

Consider a hypothetical study at an NHS trust. A nurse receives system access on 2 March, completes her first visit form on 9 March, and has her delegation log entry signed on 20 March, dated from that day. The audit trail now shows eleven days of entries by a person the log places outside the study, and the failure is a sequencing condition in the process.
Each link breaks in a way an inspector can see: a leaver keeps an active account, a role grants write access to data the person was never delegated, or a log entry is signed weeks after the work. Our guide to which record is the source covers the declaration that sits alongside these access decisions.
Also Read: Delegation of Authority Logs: Why Effective Dates Matter More Than Signatures
Seven roles reading and writing one record is a governance question before it is a software question. AQ is launching eSource soon as part of the AQ platform, so that the delegation record and the access a user holds over source data stay on one footing. Book a live demo to see the AQ platform today.
