Source data verification (SDV) and source documents
Source data verification (SDV) is the process by which a sponsor's monitor compares the data recorded in the case report form with the source documents, the original records in which trial data were first recorded, such as hospital medical records, laboratory reports, pharmacy dispensing logs, participant diaries and imaging, to confirm that the trial data are accurate, complete and verifiable. ICH E6 GCP defines source data and source documents and requires that trial data be traceable to them (ALCOA+ principles); the CTR requires the investigator to grant direct access to source documents for monitoring, audit and inspection (Art. 47 and Annex I).
Traditionally, monitors performed 100% SDV on site. Following FDA (2013) and EMA (2013) guidance on risk-based monitoring and ICH E6(R2) and (R3), sponsors now combine targeted SDV of critical data, centralised statistical monitoring and source data review (checking quality and protocol compliance rather than transcription), which reduces cost and focuses on data that matter for participant safety and trial results. Remote SDV, in which monitors access site records through secure portals or redacted copies, expanded during the pandemic and is now addressed by national guidance, with acceptance varying across EU Member States.
SDV is the moment at which the sponsor's representatives see directly identifying health data of participants, which the sponsor otherwise receives only in pseudonymised form. The GDPR conditions for this access should be secured in advance: the informed consent form must inform participants that monitors, auditors and inspectors will access their medical records under confidentiality; the clinical trial agreement must frame the access, state that no identifiable data may be copied or removed and address remote access modalities; monitors must be bound by confidentiality and trained; and monitoring reports must describe findings without recording names or identifiers. For remote SDV, the DPIA should assess the platform used, the redaction process, access logging and whether the arrangement creates a transfer where monitors sit outside the EEA. Site staff personal data in delegation logs and training records reviewed during monitoring also needs to be covered by the site-staff information notice.
