An inspection-ready TMF is not assembled at closeout. It is maintained while the trial runs.
At any point, the file should answer four questions: What evidence should exist? What has arrived? Is it the right evidence? Who owns the gap? Seal makes those questions part of trial operations instead of a reconciliation exercise at the end. The result is not simply a repository. It is a living account of how the sponsor, investigators, CROs, laboratories, committees, and vendors conducted the study.
The eTMF has to preserve more than final documents. It has to preserve context: what triggered the record, which study level it covers, which version was effective, who reviewed it, which expectation it satisfies, what it replaced, and whether an unresolved exception remains. That context is what makes a document usable during oversight, audit, inspection, transfer, and long-term retention.
The useful measure is not how many documents are stored. It is whether the trial can be reconstructed—and every exception explained.
Compile the file from the trial
The protocol, countries, sites, vendors, milestones, and delegated responsibilities define the expected file. When the trial changes, its evidence plan changes with it.
Govern the TMF standard model
The CDISC TMF Standard Model provides the common taxonomy: zones, sections, artifact and sub-artifact definitions, standard names, metadata, study levels, milestones, and relationships to GCP expectations. Seal records the model name and version, adoption date, approved extensions, retired classifications, mapping rules, and change history.
A standard-model update is not applied like a folder rename. The study team assesses new, changed, split, merged, and retired artifacts; determines the impact on active and closed studies; approves any migration or crosswalk; and records which model governed each historical filing decision. Earlier evidence keeps the classification and context under which it was accepted.
The standard remains the map. The study remains the record.
Tailor a study TMF plan
The study plan applies that reusable model to one protocol. It defines phase and design, sponsor and delegated parties, countries and sites, committees, products, systems, laboratories, vendors, procedures, key milestones, filing sources, responsible owners, QC strategy, timeliness targets, inspection arrangements, closeout criteria, transfer obligations, and archive approach.
Applicability is decided at the correct level. An artifact can be required globally but not for every country, required for one country but not another, or triggered only when a specific vendor, committee, procedure, or trial design is used. Each exclusion, substitution, waiver, or study-specific addition carries a rationale and approval instead of disappearing from the denominator.
The plan also identifies where essential records live. Some are filed directly in the eTMF. Others remain authoritative in CTMS, EDC, IRT, safety, laboratory, e-signature, quality, or vendor systems. For each source, the plan records ownership, access, edit rights, retention, transfer format, inspection method, and the evidence or reconciliation that belongs in the TMF.
Generate expectations from real events
Nothing is “missing” until the system knows it should exist. Seal creates expected evidence from the events that actually occur:
- A country is added: regulatory and ethics expectations appear with local owners and due dates.
- A site is activated: approvals, qualifications, delegation, training, contracts, and initiation evidence become visible.
- A monitoring visit closes: the report and follow-up letter are expected against the actual visit.
- An amendment becomes effective: impacted countries, sites, consent forms, training, and approvals are traced to the new version.
- The database locks: data-management, reconciliation, approval, and statistics evidence are checked before closeout.
Study start, vendor onboarding, safety events, committee meetings, product shipments, laboratory qualification, protocol deviations, interim analyses, submission, site closeout, and archive can generate further expectations. An expectation records the artifact type, study level, trigger, milestone, owner, due date, applicability, required review, acceptable substitution, escalation rule, and satisfaction state.
Expected, not yet due, overdue, received, awaiting QC, rejected, filed, satisfied, substituted, waived, not applicable, superseded, and missing remain distinct. A status change records who made it, why, and which evidence supported the decision.
One artifact may satisfy several expectations when its scope genuinely covers them. The system records that relationship instead of creating uncontrolled copies or treating the same document as several independent truths.
Give every artifact a chain of custody
Documents arrive from sites, CROs, e-signature tools, CTMS, EDC, safety systems, laboratories, vendors, email, scans, and migrations. Seal keeps the original package and the evidence needed to trust it.
Ingest without flattening provenance
Each intake preserves the source system or party, sender, channel, transfer identifier, original file name and format, checksum, received time, source-created time, document date, author, organization, signature state, source identifier, package manifest, and duplicate candidates. Email messages retain their thread and attachments. Bulk transfers retain the source inventory and validation result. Scanned records retain the certified-copy and scanning evidence where required.
Portal upload, email, e-signature completion, CTMS output, EDC export, safety case, laboratory result, vendor transfer, scan, and migration remain distinguishable. The system can identify likely duplicates without silently deleting one, because apparently identical files may have different provenance, certification, or study scope.
For structured or dynamic source data, Seal records the owning system and retrieves or reconciles the evidence required for the TMF. It does not pretend that every spreadsheet, dataset, audit trail, query history, or system log becomes equivalent when rendered to PDF.
Classify with context and visible uncertainty
Classification covers artifact type and sub-artifact, zone and section, study, country, site, investigator, committee, vendor, product, system, subject scope where permitted, milestone, document date, effective dates, version, language, author, organization, confidentiality, and the expectation the artifact may satisfy.
Seal can propose those values from the document and its operational context. The proposal retains its confidence, source evidence, model version, and reason for the match. Low-confidence, conflicting, unusual, or high-risk classifications are routed to a reviewer. Automation cannot conceal uncertainty or overwrite an approved classification without a controlled change.
Separate QC, approval, execution, and filing
Quality control asks whether the correct and complete artifact is usable: all pages are present and readable; required signatures and dates exist; the version is correct; metadata and filing location match the content; study scope is correct; duplicates and replacements are understood; redactions and translations are authorized; certified copies are supported; and an inspector could retrieve and interpret the record.
QC is not the same as author review, business approval, electronic execution, wet-signature certification, regulatory approval, or final filing. A document can be approved but filed against the wrong country. It can be correctly classified but still lack an execution signature. Seal keeps these states, roles, decisions, and timestamps separate.
A failed review retains the finding, severity, return route, responsible party, correction, resubmission, comparison to the rejected version, reviewer, and final outcome. The rejection does not vanish when a corrected file arrives.
Keep versions and replacements in one family
Draft, final, approved, executed, corrected, translated, certified copy, redacted copy, superseded version, amendment, addendum, duplicate, and replacement are relationships—not file-name conventions. The artifact family preserves every member and the reason one became effective.
Effective state resolves by scope and date. A country-specific consent can replace an earlier country version without erasing the master template or a site’s previously effective copy. A corrected monitoring report can supersede the rejected submission while retaining both records and the QC history between them.
Prove the system itself is controlled
An eTMF is evidence only if the system and its configured processes are trustworthy. Seal links intended use, risk assessment, requirements, configuration, traceability, testing, deviations, acceptance, release, training, and change control to the functions that create or preserve essential records. Validation covers the actual sponsor workflow, integrations, roles, reports, exports, and archive—not merely a vendor certificate for the underlying product.
Every production change records its reason, impact assessment, affected requirements and records, approvals, test evidence, release, rollback plan, and effective date. Periodic review considers incidents, access, audit trails, integrations, configuration drift, outstanding deviations, supplier changes, backup and restore evidence, business continuity, and whether the validated state still matches current use.
Audit trails remain attributable, time-stamped, intelligible, retained with the record, and available for review and export. They distinguish content changes from metadata corrections, automated actions from human decisions, and routine access from actions that affect record state. Electronic signatures retain the signer, meaning, date and time, signed content, signature manifestation, and durable link to the exact record version. Neither an administrator nor an integration can silently rewrite the history.
Turn completeness into work
A percentage without its denominator and exceptions is decoration. Seal calculates completeness from applicable expectations and exposes the records underneath it.
Calculate the denominator explicitly
Completeness begins with applicable expected evidence, not the number of uploaded files. The calculation accounts for study level, milestone due date, received content, QC outcome, approval or execution requirement, filing state, supersession, accepted substitutions, approved waivers, and not-applicable decisions.
The result can roll up by study, zone, section, country, site, vendor, milestone, artifact type, responsible function, or owner. Every numerator and denominator remains inspectable. A user can move from “Country GB is 91% complete” to the exact missing and rejected expectations that produced 91%.
Different views can answer different questions without changing the underlying truth: operational completeness today, milestone completeness at site activation, final completeness at closeout, or inspection completeness for a defined authority and scope.
Measure the interval that actually failed
Timeliness can begin from an event date, document date, availability date, or agreed deliverable date. It can end at receipt, submission, QC start, QC completion, approval, or final filing. Seal stores the governing interval and target rather than calculating every metric from one upload timestamp.
Event, availability, receipt, QC start, rejection, corrected resubmission, QC completion, approval, and filing timestamps reveal whether the delay arose in creation, transmission, intake, review, correction, or filing. Approved pauses and exceptions carry dates, reasons, and authority so they do not silently improve a metric.
Make quality trends actionable
QC findings, rejections, incorrect metadata, wrong study level, duplicates, missing signatures, wrong versions, unreadable scans, unauthorized redactions, late documents, filing corrections, and repeated replacements become analyzable records.
Trends can be grouped by artifact, zone, country, site, vendor, CRO team, owner, source system, reviewer, finding type, age, root cause, or recurrence. The system links recurring issues to actions, quality events, CAPAs, training, vendor oversight, or process changes and retains the effectiveness decision.
The goal is not a prettier dashboard. It is to identify the party and mechanism creating weak evidence while the trial is still running.
Control correspondence, partners, and access
Some of the most important trial evidence does not begin as a formal document. Decisions are made in correspondence, work is delegated across organizations, and records move through systems the sponsor does not operate.
File correspondence because it is essential—not because it is email
Relevant correspondence records the message or thread, participants, date, subject, decision, commitment, follow-up, attachments, confidentiality, filing rationale, artifact type, study scope, and relationship to formal evidence. A committee decision, safety escalation, protocol interpretation, vendor commitment, or documented oversight action can become essential even when no signed form exists.
The eTMF should not ingest every mailbox. Seal preserves why a communication matters, who made the decision, what action followed, and which later artifact completed the story.
Make vendor delivery accountable
The TMF plan records the sponsor, CRO, site, laboratory, imaging provider, safety vendor, central reader, eCOA provider, and other partner responsibilities. For each party it defines expected deliverables, transfer schedule, content and metadata format, quality checks, rejection process, resubmission target, access model, escalation, reconciliation, final transfer, acceptance, and archive obligations.
Submissions, rejected packages, corrections, late content, incomplete metadata, acceptance decisions, and unresolved discrepancies remain attributable. Oversight shows both the current health and whether the partner’s process is improving.
Make sponsor oversight visible
Delegating TMF activity does not delegate sponsor accountability. Seal connects the agreement, quality plan, responsibility matrix, service levels, training, access, issue route, governance cadence, metrics, decisions, corrective actions, and escalation thresholds to the studies and evidence they govern.
Oversight reviews use inspectable populations rather than slide-deck summaries: expected versus delivered artifacts, aging gaps, timeliness by process interval, first-pass QC, recurring classifications or signature failures, unresolved reconciliations, access exceptions, transfers, and overdue actions. The review records attendees, source data cutoff, questions, decisions, owners, due dates, follow-up, and effectiveness. A sponsor can therefore show what it knew, when it knew it, what it challenged, and whether the response worked.
When performance deteriorates, the record connects the signal to increased sampling, retraining, process correction, CAPA, contractual escalation, replacement, or accepted rationale. When performance recovers, the evidence supporting reduced oversight is preserved too.
Scope access to the work
Access can be limited by sponsor or CRO role, study, country, site, zone, section, artifact type, confidentiality, blind, action, and time. Create, classify, review, approve, file, view, download, export, administer, and inspect are separate permissions.
Each grant records the principal, justification, approver, start, expiry, periodic review, changes, use, and revocation. Site and vendor contributors see the content and actions they need without gaining broad visibility into the sponsor TMF. Unblinded, subject-sensitive, legally privileged, or otherwise restricted evidence remains separately controlled.
Let inspectors inspect
EMA guidance expects the TMF to remain current, readily available, directly accessible, and traceable. An inspection should not begin with an export project.
Treat readiness as live state
Readiness combines the inspection scope, applicable expectations, completeness, overdue content, failed QC, unresolved findings, unapproved or unexecuted artifacts, active substitutions and waivers, access readiness, authorized redactions, translations, audit trails, retrieval tests, open actions, owners, and readiness decisions.
Teams can run retrieval exercises before notice: locate a specified artifact across studies; compare two versions side by side; show its source and audit trail; export the relevant metadata; prove which version was effective at a site on a date; and identify who viewed or changed it.
Provide direct, usable access
MHRA inspection guidance makes the operational requirement concrete: the complete TMF can span several electronic systems, and inspectors may require direct access to each. The experience must support fast search, browsing by TMF structure, clear document identification, opening and comparing records, metadata review, and audit-trail access without dependence on a super-user.
Seal creates a read-only inspection role against the live, authorized record. Training and navigation are deliberately brief. Inspectors can see full-size legible content, search across the permitted scope, open related versions, inspect metadata and provenance, and request exports without entering operational workflows.
Run the inspection as a controlled workspace
The workspace records authority, inspection type, studies, countries, sites, date range, content scope, approved artifacts, exclusions, redactions, translations, inspector identities, access dates, and expiry. It separates prepared explanatory material from source evidence without obscuring either.
Requests, searches, views, downloads, exports, questions, responses, additional evidence, decisions, and access removal are timestamped. The sponsor knows exactly what was exposed; the inspector retains direct access to the evidence within scope; and the inspection history remains part of the governed record.
Reconcile systems without creating a shadow archive
CTMS owns sites, milestones, visits, and operational oversight. EDC owns subject data, queries, cleaning, and database lock. Safety, IRT, laboratories, e-signature, vendors, and quality systems each retain their authoritative records.
Map the complete TMF across systems
The complete TMF is not necessarily one application. Seal maintains an inventory of essential records and data across the eTMF, CTMS, EDC, IRT, safety, laboratories, e-signature, quality systems, sponsor repositories, investigator systems, CRO platforms, and vendor archives.
For each source it records the relevant record classes, responsible organization, system owner, authoritative location, access and edit rights, validation state, audit-trail availability, export format, inspection method, retention basis, decommissioning plan, and transfer obligation. This makes the distributed TMF visible instead of pretending everything has been centralized.
Reconcile operational truth to expected evidence
CTMS sites, milestones, monitoring visits, issues, and closeout states are compared with their expected TMF artifacts. EDC subjects, data-review milestones, reconciliation, freeze, and lock events are compared with data-management evidence. Safety cases and reports, IRT shipments and accountability, laboratory qualifications and transfers, vendor inventories, quality events, training, and committee records are reconciled in the same way.
Each comparison retains the source population and cutoff, matching rule, matched items, missing evidence, extra evidence, metadata discrepancy, version conflict, pending item, accepted difference, reviewer, action, and completion decision. A later reconciliation does not overwrite the earlier result.
Preserve dynamic data and metadata
The EMA guideline on computerised systems and electronic data is explicit that data, contextual information, and audit trails should not be separated. Static PDFs of dynamic datasets, audit trails, query histories, or application records may not preserve the functionality needed for inspection.
Seal therefore distinguishes a filed representation from the authoritative dynamic record. It keeps the source location, data and metadata inventory, audit-trail relationship, export and restore method, software dependency, access path, and decommissioning decision. Where a system will be retired, the plan proves that the retained format can be searched, interpreted, and—where required—restored with its relevant metadata and functionality.
Close the study once—and prove it later
Closeout is a controlled transition, not an instruction to upload the remaining files.
Complete before accepting closeout
The closeout plan defines the final expected population and cutoff across the sponsor, investigator, CRO, sites, committees, laboratories, and vendors. It evaluates missing and rejected evidence, unresolved substitutions or waivers, open QC findings, incomplete approvals or signatures, pending correspondence, late transfers, unreconciled source inventories, and open quality actions.
Exceptions that cannot be resolved receive a documented impact assessment, accountable owner, approval, and retained explanation. The final completeness and quality decision references the actual exception population instead of asserting that the file is “100%” by administrative closure.
Control transfer and change of ownership
Every internal or external transfer has a sender, recipient, authority, inventory, package, content count, metadata set, checksums, encryption, transmission evidence, validation results, discrepancies, correction cycle, acceptance, and retained transfer record. The receiving party proves it can retrieve and interpret the content before the sender’s access or system is removed.
When a CRO contract ends, a vendor changes, a marketing authorization transfers, or a sponsor entity changes, the record shows which party owns each obligation, what moved, what remained, who retains direct access, and how ongoing retention and inspection support continue.
Archive for the full retention period
The archive records the final inventory, manifest, checksums, file formats, metadata, audit trails, system dependencies, retention basis, legal holds, authorized users, read-only state, archive location, transfer and receipt, integrity checks, readability review, restore method, restore test, migration history, ownership, and destruction authority.
Retention depends on jurisdiction, product, study, and record type; the system applies the approved basis rather than one global deletion date. Access remains limited and reviewable throughout the period. Destruction cannot occur while a longer requirement, submission dependency, investigation, inspection, litigation hold, or ownership obligation remains.
Archive migration is validated and documented. The before-and-after inventory, checksums, metadata mapping, audit-trail continuity, exceptions, readability, and restore test prove that the move preserved the record. The archive is accepted only when the trial can still be reconstructed after the live systems and original teams are gone.
Start with one site and the hardest exceptions
The first implementation should prove a real lifecycle, not a configured taxonomy. Choose one protocol, one country, one site, and the connected sponsor, CRO, laboratory, and vendor responsibilities.
- Adopt the TMF model and approve the study-specific plan, applicability, owners, source-system inventory, quality controls, and timeliness rules.
- Generate activation expectations from the country and site setup, then ingest representative records from a portal, email, e-signature, CTMS, EDC, and one vendor transfer.
- Classify, review, reject, correct, approve, file, supersede, and reconcile evidence through initiation, amendment, monitoring, safety correspondence, and database lock.
- Run an inspection drill with direct read-only access, search, version comparison, provenance, audit trail, request handling, export history, and revoked access.
- Complete final reconciliation, transfer the accepted inventory, remove operational access, archive the study, and prove an independent restore.
Include the cases that expose weak systems: a wrong-country filing, a missing signature, a translated replacement, a late vendor transfer, a duplicate artifact, an approved substitution, expired inspector access, and a restore test.
Success is not a scripted happy path. The system must show what was expected, what satisfied it, what failed, what changed, who decided, and why—without reconstructing the answer in a spreadsheet.
