The timeline
ICH E6(R3) Step 4 was adopted by the ICH Assembly in January 2025. The European Medicines Agency implemented it as mandatory for all new clinical trial applications from 23 July 2025. The FDA adopted it in late 2025. Organisations with existing clinical trial applications or ongoing trials are expected to transition their quality systems to E6(R3) on a risk-proportionate basis — in practice, this means SOP updates are expected before the next relevant inspection.
ICH E6(R3) is not a minor update to E6(R2). It is a structural rewrite that reorganises the guideline, introduces new concepts that had no equivalent in R2, and — critically for CDM — creates a new data governance framework that did not exist under the previous version.
What is genuinely new in E6(R3)
Risk-Based Quality Management — §3.10 (new concept, mandatory requirement)
ICH E6(R2) introduced risk-based monitoring as a concept. E6(R3) §3.10 goes much further: it mandates a documented Quality Management System that includes prospective identification of Critical-to-Quality factors, definition of Key Risk Indicators and Quality Tolerance Limits, and documented monitoring and escalation procedures throughout the trial.
Under R2, many sponsors had some form of risk monitoring. Under R3, that process must be formally documented in a SOP, and the evidence of its implementation — signed CtQ factor lists, active Risk Registers, QTL breach investigation records — must be available at inspection. This is the single largest change for CDM quality systems.
CDM SOP impact: CDM-SOP-005 (RBQM) is required. Most existing CDM SOP libraries do not have an RBQM SOP that addresses CtQ factors, KRIs, and QTLs explicitly.
Data governance — §4 (new dedicated section)
ICH E6(R2) addressed data quality in scattered sections of the guideline. E6(R3) introduced §4 as a dedicated data governance framework — covering the entire data lifecycle from collection through archiving. Section 4 addresses data integrity (§4.1), source data (§4.2.1), direct data capture and eSource (§4.2.1), audit trails and metadata (§4.2.2), and data corrections (§4.2.3).
The creation of §4 as a standalone section signals that regulators now view data governance as a distinct compliance domain — not simply an aspect of monitoring or trial conduct. Inspectors are increasingly asking specifically about data governance documentation, separate from general GCP compliance.
CDM SOP impact: SOPs for data entry (ALCOA+), source data management, audit trail management, query management, and data cleaning all require review and update against §4.
Audit trail metadata — §4.2.2 (substantially enhanced)
E6(R2) required audit trails for electronic records. E6(R3) §4.2.2 specifies that relevant metadata — including audit trail data — must be preserved as part of the trial record. Annex 1 specifies UTC timestamps as the expected standard for multi-site international trials. The requirement for periodic documented review of audit trail records, while not stated with that precise phrasing in the guideline text, is now a consistent inspection expectation derived from §4.2.2 and the overall data governance framework of §4.
CDM SOP impact: Audit trail SOPs must be updated to include UTC timestamp configuration, periodic review procedures with signed reports, and anomaly investigation procedures.
Source data and eSource — §4.2.1 (substantially enhanced)
E6(R2) defined source data and source documents. E6(R3) §4.2.1 introduces the concept of the Source Data Agreement more explicitly — requiring that the nature of the source data (whether it is the original or a certified copy, whether the EDC system is the source of record) is defined and documented for each data type in the study.
E6(R3) also addresses eSource systems — EDC systems designated as the source of record — with specific requirements for access control, audit trail, and ALCOA+ compliance that go beyond what R2 addressed.
CDM SOP impact: Source Data Management SOPs must include Source Data Agreement framework, eSource designation procedures, and EHR-as-source requirements.
What changed significantly (vs new)
Risk-based SDV — §3.11.4 (elevated from guidance to requirement)
ICH E6(R2) introduced risk-based monitoring as an alternative to 100% on-site monitoring. E6(R3) §3.11.4 goes further: it explicitly states that source data verification should be risk-proportionate, and that 100% SDV is not the expected standard. Organisations whose SDV SOPs still specify 100% source data verification as the default are non-compliant with E6(R3).
CDM SOP impact: Source data management SOPs must be updated to include a risk-based SDV scope table with defined tiers of verification intensity.
Roles and responsibilities — §3.2, §3.3 (more specific)
E6(R3) §3.2 and §3.3 are more specific than their R2 equivalents about the documentation required for delegation of trial-related duties. The written agreement between sponsor and investigator, the clear allocation of responsibilities, and the evidence that delegated individuals are qualified — all are now stated more explicitly than in R2.
CDM SOP impact: CDM Roles and Responsibilities SOPs should include study-specific RACI matrix requirements and the documentation standard for delegated activities.
Systems and IT requirements — §3.16 (consolidated and expanded)
E6(R3) §3.16 consolidates the requirements for computerised systems — validation, access control, audit trails, change management — into a more coherent framework than the scattered references in R2. The risk-proportionate approach to validation is explicitly endorsed: Class A commodity systems (like standard EDC platforms) do not require the same depth of validation as custom-built data management systems.
CDM SOP impact: Electronic Systems Validation SOPs should reflect the 3-tier risk classification approach aligned to §3.16.1.
What did not change
The core ALCOA+ principles (Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, Available) remain the foundation of data integrity requirements. The investigator's responsibility for source data and site data entry did not change. The requirement for database lock, archiving, and retention did not change substantively. ICH E2A adverse event reporting requirements are unchanged — SAE timeliness and causality assessment standards remain as they were.
The Annex 2 watch — decentralised trials
ICH E6(R3) Annex 2 addresses decentralised clinical trials and real-world data. The consultation period closed in February 2025 and finalisation is expected in late 2025 or 2026. When finalised, Annex 2 will introduce specific requirements for eSource in decentralised settings, wearable and remote monitoring data, and EHR integration. CDM SOPs for decentralised studies will need another update cycle when Annex 2 is finalised.
"Most organisations that reviewed their SOPs for E6(R3) compliance found that the structural changes — RBQM, data governance, source data — required new SOPs rather than updated ones. The existing SOP library simply had no document for RBQM, and no document that addressed §4 as a whole. That is the gap that most CDM teams are working to close."— Sarah Huntley, 25+ years CDM experience
CDM Library
ICH E6(R3) Readiness Pack — 6 SOPs
The six SOPs that address the highest-priority E6(R3) changes for CDM: RBQM (CDM-SOP-005), Audit Trail Management (CDM-SOP-022), Source Data Management (CDM-SOP-024), Data Privacy (CDM-SOP-039), Data Security (CDM-SOP-040), and eTMF Filing (CDM-SOP-044). All written against ICH E6(R3) Step 4, January 2025.
Free resource
ICH E6(R3) CDM Readiness Checklist
12 questions across four categories — RBQM, data governance, audit trails, access and privacy. One page, free download, no signup required.
Download free checklist →Related articles: What Is RBQM? ICH E6(R3) §3.10 Explained · Audit Trail Requirements in Clinical Trials · CDM SOPs for Small Biotechs