TMF Retention After ICH E6(R3): What Really Changes

Smit Shah
CTBM

Request a demo specialized to your need.

Regulatory affairs and clinical operations leaders navigating a multi-country trial records map with electronic trial master file retention governance, country timelines, document repositories, and archive readiness on a unified digital platform.

 

A reflection on why "retention" in clinical trials quietly stopped meaning what most teams think it means  and two stories about what happens when nobody notices until someone asks the wrong question at the worst time.

Every trial eventually reaches a moment that feels like relief. Database lock. Final documents filed. The trial master file signed off as complete, every zone at 100%, every checklist item ticked. For a long time in this industry, that moment was basically the end of the story. The trial had been "retained." Someone could stop thinking about it.

Then, sometimes years later, someone asks a question the checklist never anticipated.

Not "is the document there." Something harder: "show us why this happened, and show us the version history and context that proves it." An inspector reviewing a safety signal from a trial that ended three years ago. An internal audit sampling a closed-out study before a portfolio-wide filing. A due diligence team, during an acquisition, trying to understand exactly what a specific site did in month fourteen of a study nobody currently at the company was even around for.

That's the moment retention actually gets tested. And it's the moment a lot of "complete" archives quietly fail.

Retention used to be a question about time. Now it's a question about access.

The old version of retention was mostly about duration how long do we have to keep this file, and where does it physically sit until then. ICH E6(R3) reframes the question, and the reframe is subtle enough that a lot of teams haven't fully absorbed it yet.

Appendix C defines essential records not as a fixed list of paperwork, but as whatever documents, metadata, and data actually let you reconstruct what happened in the trial. Section C.2 goes further: it acknowledges these records may legitimately live across multiple repositories — not everything has to sit inside one master file but whatever the location, the records need to stay identifiable, version-controlled, and genuinely available. Section 4.2.7 ties it together by tying retention explicitly to retrieval and readability, not just storage, for the entire length of the retention period.

Read plainly, that's a real shift. It's no longer enough to prove a document exists somewhere. You have to be able to actually get to it, understand it, and trust what you're looking at years after the person who created it has moved to a different company, a different role, or just doesn't remember the details anymore.

Why "archived" and "retrievable" aren't the same thing

Here's the uncomfortable part: a trial can pass every completeness check and still fail this test. A folder transfer can be technically finished while the context needed to actually interpret those folders has quietly evaporated. A provider handoff can satisfy every line in a contract while leaving the sponsor's ability to navigate those records, at 2am, three years from now, entirely dependent on someone remembering where things are.

Multi-country, multi-provider trials make this worse, almost by design. Some records sit in the sponsor's own eTMF. Some live inside a CRO's environment. Some are buried in quality repositories, validation libraries, or regulatory systems tied to country-level submissions. Each of those, on its own, might be perfectly well organized. But the reconstruction a regulator actually asks for rarely respects those boundaries — it usually needs pieces from three of those places at once, connected by context that nobody wrote down because, at the time, it seemed obvious.

Let me walk through the moments where I've seen this play out most clearly.

The folder that arrived complete, and useless

Call it a mid-size oncology trial, closed out on schedule, TMF transferred from the CRO to the sponsor's internal records team exactly as the contract specified. Every required artifact present. The completeness report came back green across every zone.

Six months later, a records manager I'll call David was pulling a sample for an internal audit — standard practice, nothing unusual triggering it. One of the documents he pulled was a protocol deviation report from a site in the trial's second year. The report itself was there, filed correctly, properly named. But it referenced "prior communication" explaining why the deviation had happened and why it hadn't been escalated further at the time.

That prior communication didn't exist anywhere David could find it. It had lived, as far as anyone could tell, in an email thread between a CRA who'd since left the company and a site coordinator who'd since left the site. The document the actual artifact everyone had checked the box for was sitting right where it was supposed to be. The explanation of what it meant was gone.

Nothing about that failure would show up on a completeness dashboard. The zone was populated. The file existed. But the whole reason Appendix C cares about "essential records" instead of just "essential documents" is exactly this gap: a document without its context doesn't actually let you reconstruct what happened. It just proves that something, at some point, was written down.

This isn't about one CRA forgetting to file an email

It would be easy to read that story and think the fix is a better handoff checklist, or a reminder to archive emails properly. Both true, in a narrow sense. But that framing misses the structural problem: nobody had decided, while the trial was live, that this kind of context was itself a record worth preserving deliberately. It got created informally, lived informally, and disappeared informally — the way it would on almost any trial run the same way.

Retention failures like this one almost never start at closeout. They start months or years earlier, in small, individually reasonable decisions — a version control gap here, an undocumented access arrangement there, a piece of context that felt too minor to formalize at the time. By the time someone goes looking for it, the gap has had years to become permanent.

The question nobody could answer fast enough

The second story is less about a single missing document and more about speed — because under R3, how fast you can produce something matters almost as much as whether you can produce it at all.

A quality lead I'll call Elena got a request during a routine inspection, tied to a study that had locked its database more than two years earlier. The inspector wanted to see the essential records and version history behind a specific country-level decision — not just the final approved version of a document, but the trail showing who had reviewed it, what had changed, and how that lined up with a particular operational milestone around the same time.

Every piece of that existed. It just didn't exist together. The document lived in the eTMF. The version history behind it was partly in the eTMF and partly in an email chain confirming a change that had never been formally logged. The operational milestone it was supposed to align with lived in a completely separate system that had never been cross-referenced against it in the first place. Elena's team could answer the question — eventually. It took the better part of three days, a handful of people pulled off other work, and enough back-and-forth that the inspector's confidence in the trial's overall record-keeping took a visible hit, independent of whether the underlying science was ever in question.

That's the part that's easy to underestimate. An inspector doesn't just evaluate whether you eventually produced the right answer. They're evaluating how much confidence they should have in everything else you tell them, based on how much friction it took to get there.

What retention actually requires, if you take R3 seriously

None of this gets fixed by keeping records longer, or by being more careful during the handoff at the end of a trial. The pattern in both stories is the same: retention health is decided while the trial is live, not at archive time.

A few things genuinely separate teams who handle this well from teams who don't regardless of which specific systems they use to do it.

They treat context and metadata as part of the record itself, captured at the moment something is created, not reconstructed later from memory. A deviation report isn't "done" the moment it's filed; it's done when the reasoning behind it is attached in a form someone else can find without knowing who to ask.

They decide access and continuity questions early, not at closeout. If a CRO or vendor is going to hold records for any period, the question of who can still reach them and how needs an answer at the point the relationship starts, not the point it ends.

They treat retrieval speed as an actual, ongoing measure of health, the same way a fire drill tests a plan nobody hopes to need. Could this team produce a defensible, contextualized record from a trial that ended two years ago, inside 48 hours, right now? Most organizations have never actually asked themselves that question outside of a real inspection which means the first time they find out the answer is the worst possible time to find out.

And maybe most fundamentally, they stop treating retention as an event that happens once, at the end, and start treating it as a property of how the trial is run the entire time it's active. A record that's well-organized on day one and orphaned by year three was never actually "retained" in any way that matters. It was just stored.

Why this is getting harder to ignore

Trials are more distributed than they used to be more countries, more providers, more systems touching the same study at different points in its life. Every one of those trends multiplies the number of places an essential record can end up, and multiplies the number of handoffs where context can quietly get left behind.

The expectations haven't softened, though. Regulators are still going to ask, years after a trial ends, for a coherent account of what happened and why not just a folder that technically contains the right file names. The organizations that treat retention as a design decision, made continuously while a trial is running, are the ones who'll still be able to answer that question calmly, years from now, instead of scrambling to reconstruct it from whoever's left who remembers.

An archive isn't really a filing cabinet. It's a promise that you'll still be able to explain yourself, to someone who wasn't there, long after everyone who was there has moved on. Retention was never really about how long you kept the file. It was always about whether you could still stand behind it.