Skip to main content
Clinical operations professional reviewing essential trial documents on a laptop in a research office
Clinical Solutions

An eTMF your QA team trusts and your inspectors can actually read.

Custom Electronic Trial Master File systems for US sponsors, biotechs, and CROs — one zone-aware, audit-trail-aware evidence spine across studies, sites, and vendors, built around the TMF Reference Model and the way your clinical documentation team actually runs.

One evidence spine
Across studies, sites, and vendors
Inspection-ready every day
Not just rebuilt before an inspection
Built to coexist
With your CTMS, EDC, safety, and QMS stack
Zone-aware filing
TMF Reference Model zones, sections, artifacts
Every document classified, indexed, and filed against TMF Reference Model zones, sections, and artifact types — so completeness is measurable, not guessed.
Continuous completeness view
Expected vs. received per study and site
Live dashboards of expected vs. received essential documents per study, site, country, and zone, replacing reconstruction work in the weeks before inspection.
QC and review off the inbox
Quality checks, reviewer queues, exception handling
A QC and review engine with reviewer queues, exception handling, and re-work loops — so QC stops being a manual triage exercise across email and spreadsheets.
Sponsor & CRO exchange built in
Documented APIs, standard exchange formats
Sponsor-to-CRO and CRO-to-sponsor document exchange handled by the platform via documented APIs and standard formats — not by zipped folders on shared drives.

TMF Reference Model classification & filing

Zone, section, and artifact-aware classification with configurable study templates so each new protocol does not start from a blank folder structure. Expected-document lists are maintained per study and per country.

QC, review & exception handling

Reviewer queues, completeness and legibility checks, metadata validation, and exception workflows with owners, due dates, and escalation — engineered to fit the way your TMF QC team actually triages work.

E-signature & approval workflows

Role-scoped review and approval flows with re-authentication, signed-meaning capture, and tamper-evident records, designed around the practices common in 21 CFR Part 11 and EU Annex 11 environments.

Inspection-readiness dashboards

Live views of expected vs. received documents per study, site, country, and TMF zone, with drill-down to the document, version, and review history — so your QA team can answer inspection questions in minutes, not weeks.

Audit-trail-first document history

Every action — upload, classify, QC, approve, sign, supersede, re-open — logged with actor, timestamp, document, version, and outcome. Immutable history exportable for your QA, sponsor, and inspection reviewers.

Sponsor, CRO & vendor exchange

Documented APIs and standard exchange formats for sponsor-to-CRO and CRO-to-sponsor document handoffs, central lab and IRT vendor packages, and CTMS / EDC / safety system bridges your IT team controls.

Clearer signals for your TMF and QC reviewers

Reviewer queues, completeness views, and exception dashboards that surface the next blocking document per study and site — supporting your QC and QA team instead of replacing their judgement.

Clinical documentation reviewer working through trial document checklists on a laptop

Sponsor and CRO exchange your auditors can follow

Document handoffs between sponsors, CROs, and vendors engineered as part of the platform — with a documented audit trail your QA, sponsor, and inspection reviewers can read years later.

Clinical operations and quality team members reviewing trial documents together on screen
Engineering posture

Engineered with audit-trail, e-signature, and inspection awareness for regulated clinical documentation

Engineering posture aligned with the practices common in TMF Reference Model, ICH-GCP, 21 CFR Part 11, EU Annex 11, HIPAA, and GDPR environments

Audit-trail-aware engineering

Audit logging, e-signature support, and approval gates designed as first-class engineering features. Your QA team executes validation; the platform supplies the engineering evidence and inspection-ready trail.

Zone-aware classification by design

TMF Reference Model zone, section, and artifact awareness is engineered into the data model — not bolted on as a folder convention. Expected-document lists are configurable per study type, phase, and country.

Subject and PHI data treated as first class

Subject and patient data inside essential documents is segmented, access-scoped at the application layer by default, and kept out of dashboards and exchange payloads wherever the work allows.

TMF Reference ModelICH-GCP21 CFR Part 11EU Annex 11HIPAAGDPRHL7 FHIR
How the evidence comes together

One evidence spine for every essential document.

Documents flow in from sponsor, site, vendor, and system sources, move through a zone-aware lifecycle, and flow back out as inspection-ready evidence your QA, sponsor, and inspection reviewers can read at any moment — not just at study lock.

One inspection-ready record
Band 1 · Capture

Where essential documents come from

Sponsor & CRO documents

Protocols, plans, agreements, oversight records

Site essential documents

Investigator file, IRB / EC approvals, training

Vendor & lab documents

Central lab, imaging, IRT, safety vendor records

System-generated artifacts

CTMS, EDC, safety, and QMS export packages

Band 2 · Document lifecycle

Where the eTMF actually runs

Classify & index

Map to TMF Reference Model zone, section, artifact

QC & review

Completeness, legibility, metadata, expected-doc checks

Approve & e-sign

Role-scoped review, re-auth, signed-meaning capture

File & version

Zone-aware filing, superseded-version tracking

Archive & lock

Study-level lock, retention, controlled-access archive

Band 3 · Evidence & outputs

What your QA, sponsor, and inspection teams consume

Zone & artifact completeness

Live view of expected vs. received per study and site

Audit trail

Immutable record per action, user, document, version

Sponsor & CRO exchange

Documented APIs and standard exchange formats

Inspection workspace

Role-scoped reviewer access with traceable activity

TMF Reference ModelICH-GCP21 CFR Part 11EU Annex 11HIPAAGDPR

Designed to sit alongside the CTMS, EDC, safety, QMS, and finance systems your team already runs.

Compliance by design

TMF Reference Model (zone / section / artifact classification)ICH-GCP (Good Clinical Practice)21 CFR Part 11 (electronic records & signatures)EU Annex 11 (computerised systems)HIPAA + HITECHGDPR

Engineering artifacts for your validation work

We structure the build so your QA function has the documentation, traceability, and test evidence they need to execute computer-systems validation (CSV). We do not perform validation, write IQ/OQ/PQ, or accept the system on your behalf.

Audit trail as an engineering default

Every document action — upload, classify, QC, approve, sign, supersede, archive, and re-open — is logged with actor, timestamp, document, version, before / after state, and outcome. Audit records are immutable and exportable for your QA, sponsor, and inspection reviewers.

E-signature support designed for regulated workflows

E-signature flows are engineered with re-authentication, signed-meaning capture, and tamper-evident records — aligned with the practices common in 21 CFR Part 11 and EU Annex 11 environments. Acceptance of those signatures for any specific regulatory purpose is your team’s decision.

Retention, lock, and controlled-access archive

Study-level lock, retention policies, and a controlled-access archive engineered into the platform — so closed studies remain reviewable for retention periods your QA and regulatory teams define, without surfacing inside operational workflows.

Identity & access control

Standards-based identity with enforced MFA, role-scoped access across sponsor, CRO, site, QC, QA, and inspection reviewer users, and session controls designed for regulated clinical environments.

Cloud infrastructure for regulated environments

Hosted on cloud regions and configurations commonly used for sensitive clinical data, with private endpoints, immutable / WORM storage tiers for archived records, and infrastructure defined and reviewed via Terraform.

Audit-ready on day one

Every component is engineered with audit-trail logging, role-scoped access, traceability, and lifecycle artifacts your QA, clinical operations, IT, and regulatory teams can use as inputs into their own computer-systems validation (CSV) and inspection-readiness work. Final validation execution, IQ/OQ/PQ authoring, sponsor acceptance, TMF Reference Model conformance claims, and any regulatory submission remain solely the customer’s responsibility, executed by the customer’s QA and regulatory functions. Sorento Software does not represent, attest, or warrant compliance with the TMF Reference Model, ICH-GCP, 21 CFR Part 11, EU Annex 11, HIPAA, GDPR, or any other regulatory framework on behalf of any customer.

Partner agreements in place

BAADPASLA

Inspection-ready as a daily state, not a project

A continuous view of expected vs. received essential documents — per study, site, country, and TMF zone — replaces the pre-inspection reconstruction sprint your team has lived through before.

One zone-aware evidence spine across studies

TMF Reference Model classification at the artifact level, applied consistently across studies, countries, and sites — so completeness is measurable and reviewable, not a folder convention people forget.

QC and review that scales with the portfolio

Reviewer queues, exception handling, and re-work loops engineered into the platform — so QC capacity scales with study volume instead of forcing your team to swap quality for throughput.

Coexists with the stack your team already runs

Documented APIs and standard data formats let the eTMF sit alongside your CTMS, EDC, safety, QMS, and finance systems — your IT team owns the connectors, and the systems your team already relies on stay in place.

Sponsor and CRO handoffs your auditors can follow

Document exchange between sponsors, CROs, and vendors flows through the platform with a documented audit trail — so handoffs survive vendor turnover and remain reviewable years later.

Our Implementation Process

1
Scoped during discovery

Discovery, scope & engineering framing

We map your TMF Reference Model implementation, current document landscape (shared drives, legacy eTMF, CRO transfer packages), expected-document lists per study type, QC workload, and integration points with CTMS / EDC / safety / QMS; identify the highest-pain workflows; and frame the engineering and integration shape before scoping the build. Validation strategy and sponsor acceptance criteria stay with your team.

Document landscape map, TMF Reference Model gap review, QC workflow map, integration outline, prioritized roadmap, engineering and integration framing document
2
Phased per engagement

Architecture & validation-aware engineering plan

Design the data model, classification schema, audit-trail architecture, role-scoped access model, QC and review engine, e-signature workflow, and integration topology, alongside your IT, security, QA, and clinical operations stakeholders. Documents are produced as inputs into your computer-systems validation work.

Architecture document, data model, classification schema, audit-trail design, security architecture, integration outline, validation-input package
3
Phased per engagement

Build & iterate

Iterative full-stack development of the platform — capture, classification, QC, approval, e-signature, filing, inspection-readiness, audit-trail, and exchange modules — with engineering artifacts (test coverage, traceability matrices, change logs) captured as part of the build rather than reverse-engineered at the end.

Working platform, engineering artifact set, audit-trail dashboards, configurable study templates, integration hooks
4
Phased per engagement

Integration & handoff to your QA / clinical operations function

Connect to your existing CTMS, EDC, safety, QMS, and finance systems via documented APIs and standard data formats, run end-to-end UAT with your TMF, QC, and clinical operations teams, and assemble the engineering documentation your QA function uses as inputs into IQ/OQ/PQ and CSV.

Integration runbooks, UAT sign-off, security test report, engineering documentation set for QA / CSV intake
5
Defined per engagement

Deployment, hypercare & lifecycle operations

Phased rollout to study teams, TMF QC reviewers, sponsors, and CRO partners with an initial hypercare period covering filing stability, change-control reviews, and adoption support — so the platform stays in a known state as studies progress and document volume grows.

Production deployment, monitoring dashboards, change-control playbook, hypercare support, training materials

Frequently Asked Questions

Will this eTMF replace our CTMS, EDC, safety, or QMS system?

No. The eTMF we build is designed to coexist with the CTMS, EDC, safety, QMS, and finance systems you already run, using documented APIs and standard data exchange formats. It is the inspection-ready evidence spine for essential documents — capture, classification, QC, approval, e-signature, filing, and archive — and it hands off to your operational and validated upstream / downstream systems through connections your IT and integration teams own.

Will the platform satisfy a sponsor or FDA / EMA inspection?

We are a software engineering partner. We engineer the platform with the audit-trail, e-signature, role-scoped access, and traceability practices that are common in TMF Reference Model, ICH-GCP, 21 CFR Part 11, and EU Annex 11 environments, and we deliver an engineering artifact set your QA team can use as inputs into computer-systems validation (CSV) and inspection-readiness reviews. Final validation execution, IQ/OQ/PQ authoring, sponsor acceptance, TMF Reference Model conformance claims, and inspection responses are owned by your QA, clinical operations, and regulatory functions. We do not represent compliance with any framework on your behalf.

How is TMF Reference Model classification handled?

Zone, section, and artifact awareness is engineered into the data model — not added as a folder convention on top of a generic document store. Expected-document lists are configurable per study type, phase, and country, and completeness views show expected vs. received per study, site, and zone in real time. Your TMF and QA teams define and maintain the classification scheme; the platform enforces and reports against it consistently across studies.

How do you handle PHI and access control across sponsor, CRO, and site users?

Subject and patient data inside essential documents is segmented, access-scoped at the application layer, and kept out of dashboards and exchange payloads wherever the work allows. Role-scoped access spans sponsor, CRO, site, QC, QA, and inspection reviewer users — each role sees only the documents and metadata their work requires. Every access and action is logged with actor, timestamp, document, and outcome. The engineering practices are aligned with what customers in regulated clinical environments typically expect; we make no compliance certifications on your behalf.

How does sponsor-to-CRO and CRO-to-sponsor document exchange work?

Document exchange is engineered into the platform via documented APIs and standard exchange formats — not as zipped folders on a shared drive. Transfer manifests, source-of-record metadata, and audit trails travel with each exchange so the receiving organization can verify completeness and reviewers on either side can follow handoff history years later. Your IT and integration teams own the connectors to specific sponsor or CRO endpoints.

What does a typical engagement look like, and how do you scope it?

Scope, timeline, and investment vary by program and are defined during discovery — we do not quote fixed durations, fixed costs, or fixed inspection outcomes on a public page. Discovery is where we map your TMF Reference Model implementation, current document landscape, expected-document lists, QC workload, and integration points, then frame the engineering and integration shape before any production-bound code is written. After discovery, the build is typically phased so the highest-priority capability goes live first and your clinical documentation and QA teams can review the platform before later phases land.

Bringing your trial master file onto one evidence spine?

Book a free 30-minute discovery call. We will review your TMF Reference Model implementation, current document landscape, QC workload, and integration constraints, then outline a realistic engineering and integration shape. Validation, sponsor acceptance, and regulatory decisions remain with your team.