Source data verification is easy to turn into a counting exercise: check every field, document every match, and assume more checking means better quality. That approach can consume a small investigator-initiated trial without controlling its most important risks.
The better question is not, “What percentage should we verify?” It is, “Which errors or process failures could harm participants or make the result unreliable, and what monitoring method is most likely to detect them?”
In an investigator-initiated trial, you usually carry the sponsor responsibilities directly as a sponsor-investigator or work within an institution that serves as the legal sponsor. Confirm which arrangement applies in your regulatory submission, agreements, and institutional records; “investigator-initiated” does not assign the legal role identically in every jurisdiction or pathway.
What source data verification does
Source data verification (SDV) compares data reported for the trial—often in a case report form or electronic data-capture system—with the relevant source record. It tests whether selected reported values accurately reflect the underlying record.
That is useful, but it is narrower than monitoring as a whole. ICH E6(R3) describes monitoring as a broad quality-control activity. It can include source data review, SDV, data analytics, communication with sites, review of trial records, and on-site, remote, or centralized activities. Its aims are participant protection and reliable trial results.
This distinction matters. A perfect match between a source value and a CRF does not prove that:
- informed consent was obtained correctly;
- the participant was eligible;
- an endpoint assessment was performed according to the protocol;
- a safety event was recognized and reported on time;
- the source record itself is complete and attributable; or
- recurring errors across participants or visits have been detected.
SDV can confirm transcription. It cannot carry the entire monitoring program.
The 100 percent SDV claim is the wrong starting point
The original version of this article stated that FDA historically required 100 percent SDV and withdrew that requirement in 2013. That is not an accurate reading of FDA’s guidance.
FDA’s 2013 risk-based monitoring guidance describes 100 percent verification as a historical perception of the agency’s preferred approach. The same guidance notes that the regulations do not prescribe a specific monitoring technique. It encourages monitoring that focuses on critical data and processes and uses centralized methods where appropriate.
FDA also states that, for a particular study, comparing every source value with every CRF field may provide minimal benefit. The monitoring plan should instead identify the quantity and types of source data that need verification or corroboration. Sampling critical data points across selected participants and visits may be sufficient when the study’s risk assessment supports that choice.
This is not permission to do less monitoring by default. Risk-based monitoring redirects effort. A plan that reduces routine SDV should explain what replaces it: targeted checks, central data review, process review, trend analysis, escalation triggers, or additional site activity.
Jurisdiction still matters. FDA guidance applies in its stated U.S. regulatory context. ICH E6(R3) is a harmonized guideline implemented through member regulatory systems. Neither source erases local law, ethics requirements, institutional policy, funding agreements, or the protocol.
SDV, source data review, and centralized monitoring solve different problems
Use the terms precisely:
| Method | Primary question | Example |
|---|---|---|
| Source data verification | Does the reported trial value match the relevant source record? | Compare the recorded visual-acuity value in the CRF with the source worksheet. |
| Source data review | Do the source records and trial processes support safe, protocol-compliant conduct? | Review whether consent, eligibility, endpoint timing, adverse events, and investigator oversight are documented. |
| Centralized monitoring | Do accumulated data reveal site-level or study-level patterns that need action? | Flag unusual distributions, missing assessments, delayed entries, protocol deviations, or inconsistent event reporting. |
These methods can complement one another. ICH E6(R3) states that centralized monitoring can reduce or complement site monitoring and can help identify systemic or site-specific issues. It can also guide targeted site monitoring.
A single-site IIT may not need sophisticated statistical surveillance. It still benefits from a simple central review: missing-data reports, overdue-visit checks, eligibility exceptions, safety-event reconciliation, and a short trend review by visit or participant.
Build a proportionate IIT monitoring plan in six steps
1. Confirm your role and governing framework
Start by confirming whether you are the individual sponsor-investigator or your institution is the legal sponsor. Then identify the applicable intervention pathway and jurisdiction.
Under the U.S. IND framework, 21 CFR 312.50 assigns proper monitoring to whoever serves as the sponsor, and 21 CFR 312.56 requires that person or institution to monitor the investigation’s progress. If you are the individual sponsor-investigator, you carry both sponsor and investigator requirements. If your institution sponsors the trial, it holds the sponsor obligations while you retain your investigator responsibilities.
Do not import an industry-sponsored site workflow without checking which responsibilities you hold directly and which your institution holds.
2. Identify critical data and processes
List the errors or failures that could affect participant rights, safety, or the reliability of the primary result. Typical candidates include:
- informed-consent timing and documentation;
- eligibility criteria that protect participants or define the study population;
- investigational-product accountability, where applicable;
- primary and key secondary endpoint data;
- protocol-required safety assessments;
- serious adverse-event recognition and reporting;
- randomization and blinding controls, where applicable; and
- records needed to reconstruct important trial decisions.
Connect this list to your protocol, statistical analysis plan, and case report form. If a field does not support an objective, endpoint, safety requirement, or planned analysis, challenge why you are collecting it. The data-minimization test for IIT CRFs can reduce monitoring burden before the first participant is enrolled.
3. Assess the failure modes
For each critical item, ask:
- What can go wrong?
- How likely is it?
- How serious would the consequence be?
- How detectable is the problem without direct source access?
- Can the process prevent the error before monitoring detects it?
Do not assign numbers merely to make the assessment look rigorous. A short narrative can be enough if it produces a defensible control.
4. Match the method to the risk
Choose the monitoring activity that can answer the risk question.
Use SDV when a source-to-report comparison is necessary. Use source data review when process adequacy or documentation context matters. Use centralized review when patterns across records are more informative than one field at a time. Use targeted on-site or remote activity when a trigger needs follow-up.
ICH E6(R3) says monitoring should be proportionate to identified risks. In your IIT, you and any sponsoring institution should tailor the plan to participant safety, data quality, and trial-reliability risks. Describe the methods, tools, activities, and rationale—not just a percentage.
5. Define scope, timing, and triggers
For each activity, specify:
- which data, processes, participants, and visits are in scope;
- whether review is prospective, periodic, event-triggered, or close-out;
- who performs it and who reviews the finding;
- how findings are documented and communicated;
- what threshold triggers broader review, retraining, correction, or escalation; and
- when the monitoring plan itself will be reassessed.
A trigger should lead to a defined decision. “Review deviations monthly” is incomplete. “If the same eligibility deviation occurs twice, pause enrollment, review all enrolled participants for that criterion, retrain your team, and document your decision” is operational.
6. Adapt the plan using findings
Risk-based monitoring is dynamic. ICH E6(R3) states that monitoring frequency should be modified as appropriate using knowledge gained. Clean early data may support the planned scope. Repeated omissions, late safety reporting, unexplained patterns, or protocol deviations may justify expanded review.
Document both directions. Increasing scrutiny without recording why is hard to reconstruct. Reducing it without evidence is harder to defend.
A single-site IIT example
Consider a small prospective eye-care IIT with a primary visual-function endpoint. You might select:
- 100 percent review of consent before any study procedure;
- verification of key eligibility criteria for every participant;
- targeted SDV of the primary endpoint at baseline and the primary time point;
- centralized checks for missing visits, out-of-window assessments, and unusual value patterns;
- reconciliation of serious adverse events and discontinuations; and
- escalation to broader source review after repeated deviations or inconsistent endpoint documentation.
That is an example, not a universal template. The protocol, risk profile, systems, jurisdiction, and institutional procedures determine the final plan.
Keep responsibility and performance separate
You can assign monitoring activities to qualified people or service providers, subject to the governing framework and documented arrangements. Assigning the work does not automatically transfer the underlying regulatory role or responsibility.
ICH E6(R3) expects roles to be clear and documented and says monitoring should be performed by people not involved in the clinical conduct at the site being monitored. For a small investigator-led program, this independence requirement can expose a real resource gap. The answer is not to let the same person conduct, enter, verify, and approve every critical activity without challenge. Define who can provide qualified, independent review and document the arrangement.
If your institution sponsors the trial, distinguish its oversight obligations from your conduct responsibilities as principal investigator. If you are the individual sponsor-investigator, distinguish your two sets of duties even though you hold both roles.
The decision to make now
Do not begin with an arbitrary SDV percentage. Begin with the participant-protection and result-reliability risks that matter in your trial. Then choose a defensible mix of SDV, source data review, centralized checks, and targeted follow-up.
The strongest monitoring plan is not the longest. It is the one that makes critical risks visible, assigns action, and changes when the evidence changes.
Take the next step
A proportionate monitoring plan should fit your protocol, role arrangement, data systems, and actual operating capacity. Eye-Dea to Impact places this work within the Notice the Insights stage: collect valid, useful, traceable data, then apply controls where failure would matter.
