Written and maintained by CASRAI Editorial Board
Last updated
ICH E6(R3)’s Principles apply a single, risk-proportionate quality-by-design standard to every interventional trial regardless of design or data source — and data governance is where that standard gets the most concrete. Rather than a checklist bolted onto the end of the guideline, E6(R3) treats data governance as a working expectation woven through trial design, conduct, and reporting: who controls data at each stage, how its quality is assured before problems surface, and how a reviewer traces any reported result back to where it originated. This guide is a standalone deep-dive into that expectation specifically — distinct from the site’s ICH E6(R3) Definitions guide, which covers audit, inspection, monitoring, and quality assurance as oversight roles, and from the ICH E6(R3) term, which covers the guideline’s adoption timeline and structural changes broadly.
Where data governance sits in E6(R3)
E6(R3) restructured GCP around a short set of overarching Principles that apply before any annex-level detail, rather than E6(R2)’s section-by-section checklist approach. Data governance is not confined to one clause within that structure — it is an expression of the Principles’ broader quality-by-design and risk-proportionate approach, applied specifically to how trial data is created, controlled, and relied upon. In practice this means a sponsor’s quality management system is expected to identify which factors are critical to the reliability of the trial’s data (critical-to-quality factors) and govern those factors proportionately to their risk, rather than applying uniform, checklist-level controls to every data point regardless of its bearing on participant safety or result reliability.
This is a shift in emphasis from E6(R2), which addressed data handling mostly through source documentation and monitoring requirements written for a paper-and-site-visit model. E6(R3) makes data governance an explicit, planned activity that a sponsor’s quality system has to account for directly, not an inference drawn from monitoring and audit provisions.
Technology-agnostic, media-neutral principles
A defining feature of E6(R3)’s data governance expectations is that they are written to apply the same way whether trial records are paper or electronic — deliberately avoiding a separate, bolted-on “electronic records” annex of the kind older GCP guidance relied on. The practical requirements that follow are still concrete:
- Audit trail review as a planned activity. For electronic systems, E6(R3) describes audit trail review as something that should be planned and documented in advance — not an incidental check performed only if a problem is suspected. Who reviews which audit trails, how often, and what triggers escalation should be defined before the trial starts, not improvised after the fact.
- System documentation addressing version control and data provenance. Documentation for any electronic system used to capture, process, or store trial data should be able to answer two separate questions: which version of the system (and its configuration) was in use at a given point in the trial, and where a given data point actually came from as it moved between systems.
- The same governance obligation regardless of medium. A site or sponsor cannot treat electronic data as inherently more (or less) trustworthy than paper records, or apply governance controls to one medium that it skips for the other. The obligation is the data’s reliability, not the medium it happens to be recorded on.
This connects directly to computerised system validation practice already covered on this site: E6(R3)’s technology-agnostic data governance expectations are the GCP-side counterpart to the validation lifecycle described in the computer system validation (CSV) guide and, for EU GMP-regulated systems specifically, the Annex 11/Annex 15 lifecycle guide. A validated system is the mechanism; E6(R3)’s data governance principle is the reason a sponsor needs one.
The data lifecycle E6(R3) expects to be governed
“Data governance” under E6(R3) is not limited to storage or archiving — it spans the full lifecycle of a trial data point, and the guideline’s risk-proportionate framing applies at each stage:
- Capture. How and where a data point first enters a system — a case report form field, a device reading, a lab result interface — and what controls exist at that point to catch an error before it propagates downstream.
- Processing and transformation. Any step that moves, recalculates, or reformats data (manual transcription, an automated feed between an EDC and a central lab system, a coding or mapping step) is a place where provenance has to be preserved, not just the end result.
- Review and quality control. Risk-based data review — central statistical monitoring, targeted source data verification, or both — applied proportionately to which data points and which sites carry the most risk to participant safety or result reliability, rather than uniform 100% verification regardless of risk.
- Reporting and analysis. The dataset used for statistical analysis and clinical study reporting has to trace back to the source data it was derived from, with any exclusions, transformations, or corrections documented rather than silently applied.
- Retention and archiving. Trial data and the metadata needed to interpret it (audit trails, system documentation, data dictionaries) are retained together, since a data point without its provenance record loses much of its evidentiary value in an inspection.
This lifecycle view is why E6(R3)’s data governance principle reads as an extension of ICH E8(R1)’s quality-by-design approach to study design specifically into trial conduct — E8(R1) asks a sponsor to identify critical-to-quality factors during protocol design; E6(R3) then carries that same risk-based, factor-driven logic into how the resulting data is governed once the trial is running.
Traceability from source to reported result
The practical test of E6(R3) data governance is whether a specific value in a clinical study report can be traced back to where it came from, through every intermediate step, with each step’s authorship, timing, and any change documented. This is the same underlying expectation the ALCOA+ data integrity principles describe (attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring, and available) — E6(R3) does not restate ALCOA+ by name, but its data governance expectations and ALCOA+ describe the same reliability outcome from two different angles: one from the regulatory-guideline side, one from the data-integrity-practice side.
Traceability depends on the mechanics covered elsewhere on this site:
- Source data verification (SDV) — confirming reported data against the original source, applied risk-proportionately under E6(R3) rather than exhaustively.
- 21 CFR Part 11 — the FDA electronic records/signatures framework that underpins much of the audit-trail and system-control expectation for US-regulated trials.
- Trial master file and essential documents — where the governance evidence (validation records, audit trail review logs, data management plans) actually has to live and be retrievable for inspection.
What this means in practice
For a sponsor, CRO, or site translating E6(R3)’s data governance expectations into working procedures, the checklist looks like:
- Write (or update) a data management plan that names the critical-to-quality data points for the specific trial, not a generic template applied unchanged across studies — see the clinical data management guide for the CDM workflow this plan sits inside.
- Define audit trail review as a scheduled activity in the monitoring or data management plan, with named responsibility and a defined frequency, rather than leaving it to be performed reactively.
- Confirm system documentation actually supports provenance questions — can the current system documentation show which configuration was live on a given date, and where a specific field’s value came from, without a manual investigation each time it’s asked?
- Apply risk-based, not uniform, data review — document the rationale for which data receives closer verification, consistent with the risk-based monitoring approach E6(R3) generalizes.
- Retain governance evidence alongside the data itself in the trial master file, not in a separate system an inspector would have to be pointed to separately.
None of this requires a new regulatory submission or a new system by itself — for most sponsors already running risk-based quality management, it is closer to documenting and formalizing practices already partly in place than building something from scratch. The gap E6(R3) closes is between doing this informally and being able to show, on request, that it was planned rather than improvised.
Frequently asked questions
Does ICH E6(R3) create a separate “data governance” section or annex?
No. Data governance is not a standalone numbered section or annex — it is an expression of the guideline’s overarching Principles (quality by design, risk-proportionate quality management, technology-agnostic requirements) applied specifically to trial data. It runs through the Principles and Annex 1 rather than sitting in one place.
How is this different from the ICH E6(R3) Definitions guide on this site?
The Definitions guide covers audit, inspection, monitoring, and quality assurance as distinct oversight roles — who performs each one and what authority it carries. This guide covers a different question: what E6(R3) expects a sponsor or site to actually do to govern trial data itself, across its lifecycle, independent of who is later checking that work.
Does E6(R3) require new technology to meet its data governance expectations?
No. The requirements are explicitly media-neutral — they apply to paper records and electronic systems alike. What changes is the expectation that governance (audit trail review, provenance documentation, risk-based review) is planned and demonstrable, regardless of which medium a given trial or site uses.
Who is accountable for data governance under E6(R3) — the sponsor or the investigator?
Both, at different points in the lifecycle. The sponsor’s quality management system is expected to govern data at the trial level (system validation, risk-based monitoring design, central statistical review); the investigator/site is responsible for the reliability of data as it is first captured and for maintaining source documentation. E6(R3)’s risk-proportionate framing applies to how each party’s oversight is scaled, not to whether oversight exists.








