ICH E6(R3) - Good Clinical Practice
ICH E6 Annex 1 - Electronic Systems

ICH E6(R3) - Good Clinical Practice ICH-E6-Annex1-ElectronicSystems-CSV-eSig-Audit-ALCOA-DataIntegrity: ICH E6(R3) Annex 1 - Computer Systems + Computer System Validation (CSV) + Electronic Signature + Audit Trail + ALCOA+ Data Integrity

ICH E6(R3) Annex 1 (Computer Systems Used in Clinical Trials) is the new section consolidating data integrity + electronic systems + computer system validation (CSV) - replacing scattered E6(R2) provisions. Scope: all computer systems used to collect + process + store + transmit clinical trial data and supporting documentation. Computer System Validation (CSV): GAMP 5 (Good Automated Manufacturing Practice) risk-based approach + USP/IPEC validation strategy + ICH Q9 quality risk management; fit-for-purpose validation; lifecycle (planning + URS + functional spec + design + implementation + testing + IQ/OQ/PQ + release + change control + retirement); risk-based scope (system criticality + complexity + customisation). Electronic Signatures (eSig): unique + biometric or PIN + timestamp + meaning of signature + audit trail of signatures + 21 CFR Part 11 + EU CTR + ICH E6 Annex 1; user authentication + identity proofing + workflow approval. Audit Trail: complete + contemporaneous + attributable + chronological + tamper-evident + protected + retained per study lifecycle; review process; audit trail report capability. ALCOA+ Data Integrity (Attributable + Legible + Contemporaneous + Original + Accurate + Complete + Consistent + Enduring + Available) per FDA 21 CFR Part 11 + EU CTR + EMA GxP Data Integrity Guidance + MHRA GxP Data Integrity + WHO Annex 5 Guideline on Data Integrity. Data Migration: from legacy + acquired system + EHR; validation + verification + data integrity preservation. Access Control: role-based + segregation of duties + periodic review + offboarding. Coordinates with 21 CFR Part 11 + GAMP 5 + ISPE + IPEC + WHO + EU CTR + JPMA + MHRA + PIC/S Annex 11. ICH E6 + Annex 1 + CSV + eSig + Audit Trail + ALCOA+ applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 121 controls across 55 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CTR-Art.28 General rules on subject protection (Article 28)
  • CTR-Art.29 Informed consent (Article 29)
  • CTR-Art.41_42 Adverse-event and SUSAR reporting (Articles 41-42)
  • CTR-Art.43 Annual safety reporting (Article 43)
  • CTR-Art.47 Compliance with the protocol and Good Clinical Practice (Article 47)
  • CTR-Art.48 Monitoring (Article 48)
  • CTR-Art.57_58 Clinical trial master file and archiving (Articles 57-58)
  • CTR-Art.80_81_82 EU portal, EU database and functionality (Articles 80-82) - CTIS
  • ACQS-3-1 Safe and Effective Care
  • ACQS-8-2 Clinical Governance
  • ACQS-8-3 Continuous Improvement
  • ACQS-8-4 Risk Management

SWIFT CSCF · 4 controls

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • SWIFTCSCF-3 Physically Secure the Environment (Objective 3)
  • SWIFTCSCF-4 Prevent Compromise of Credentials (Objective 4)
  • SWIFTCSCF-7 Plan Incident Response (Objective 7)

BSI IT-Grundschutz · 3 controls

  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

Bahrain PDPL · 3 controls

HITECH Act · 3 controls

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
  • HITECH-Enforcement-CMP-Tiers-StateAGs-OCR HITECH 4-Tier Civil Monetary Penalty Structure, State AGs Enforcement and HHS OCR Settlements
  • HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors
  • CA-10 Selects and Develops Control Activities
  • CA-12 Deploys Through Policies and Procedures
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-EffectiveDate-Small-Institution Effective Date, Small Institution Exemption and Sectoral Coordination (16 CFR 314.5, 314.6)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • GGAP-IFA-CropsBase-Production-PPP-IPM GLOBALG.A.P. IFA v6 Crops Base (CB): Propagation, Soil, Water, IPM, PPP, Fertilizer and Harvest
  • IATF16949-Clause10-Improvement-Nonconformity-CorrectiveAction-Problem-ErrorProof IATF 16949 Clause 10 - Improvement + Nonconformity + Corrective Action + Problem Solving + Error Proofing + Continual Improvement
  • IATF16949-Clause4-Context-Scope-CustomerSpecific-ProductSafety IATF 16949 Clause 4 - Context of Organization + QMS Scope + Customer Specific Requirements + Product Safety
  • AQAP2110-7 Production, Special Processes, Inspection, Testing, and Records
  • AQAP2110-8 Internal Audit, Management Review, Corrective Action, CofC, and Continual Improvement

PCI DSS 4.0 · 2 controls

  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 2.1.2 2.1.2 Requirement 2 roles and responsibilities assigned
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement
  • 2.1.3 Food Safety and Quality Culture
  • 2.5.2 Verification Activities
  • AIGF-1.3 Data Management
  • AIGF-3.3 Repeatability and Traceability
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • TEFCAREC-2 Privacy, Security, Minimum Necessary
  • 58.49 Laboratory Operation Areas

API 1164 · 1 control

  • API1164-18 Field Device Security
  • AS9100D-10.2 Nonconformity and Corrective Action
  • AL-DPA-7 Right of Access
  • BB-DPA-22 Sections 70-75 - Commissioner Functions

FDA 21 CFR Part 11 · 1 control

  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
  • CAT-D3-2 Detective controls

FISMA · 1 control

  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • FSSC-Additional-Requirements-v6 FSSC 22000 Additional Requirements v6 (Food Defense + Food Fraud + Allergen + Environmental + Culture)

FedRAMP Rev 5 · 1 control

  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • GAMP5-Risk-CriticalThinking Risk-Based Approach, Critical Thinking and 5 Key Concepts

GHG Protocol · 1 control

  • GHG-Suite-Corporate-Principles GHG Protocol Suite, Corporate Standard and 5 Reporting Principles
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • 60601-1.12 Accuracy of controls and instruments
  • 62351-14 Cyber security event logging

ISO/IEC 27011:2024 · 1 control

  • 27011-8.4 Logging and monitoring

ISO/IEC 27014:2020 · 1 control

  • 27014-5.6 Continuous improvement

India DPDP Act · 1 control

  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness

MITRE D3FEND · 1 control

OWASP ASVS · 1 control

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • UAEVARA-1 Activity Licensing (Advisory, Exchange, Custody, Broker-Dealer, etc.)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 121 it maps to, and the evidence behind each claim, over MCP and REST.