Request a demo specialized to your need.
Where R3 actually stands right now
Annex 2 of ICH E6(R3) the section covering risk-based quality management and interventional trial design in depth reached Step 4 this summer. ICH adopted it on June 3, 2026. CHMP followed on June 25. It becomes legally effective in the EU on January 15, 2027, which is under six months away as of this writing.
That lands on top of a landscape that's already live. The core E6(R3) Principles and Annex 1 have been in force in the EU since July 2025, Switzerland since August 2025, and Canada as of this past April. The UK's MHRA published its own annotations in January 2026. The FDA published final guidance back in September 2025 technically not legally binding the way the EU regulation is, but sponsors and CROs operating across both jurisdictions are already expected to align with it.
The part worth actually understanding: what changed, and why
Section 4.2.3 is the specific provision reshaping eTMF operations the most. It requires that review of trial-specific data and metadata, including audit trails, be "a planned, risk-based, and documented activity" a deliberate shift away from treating audit-trail review as something done only when an inspection is imminent.
That shift connects to a bigger change in how inspections themselves work. Under the old model, inspectors largely checked for the presence of documentation did the file exist, was the box checked. Under R3, inspectors are trained to assess the quality of the decision-making behind the documentation, not just its volume. A complete-looking TMF with no evidence of why review happened, on what basis, or how risk was actually assessed no longer satisfies the expectation, even if every document technically exists.
ALCOA+ is the framework inspectors use to test whether a record holds up, and it's worth being precise about what it actually covers. The original five principles Attributable, Legible, Contemporaneous, Original, Accurate ask whether you can tell who did what, whether it's readable, whether it was recorded at the time rather than reconstructed later, whether it's the real record rather than a copy, and whether it's correct.
The four additions Complete, Consistent, Enduring, Available ask whether the whole story is there, whether it holds together across systems, whether it survives over time, and whether it can actually be produced on request. An audit trail that only gets reviewed right before an inspection is fragile on several of these at once: it's not contemporaneous, because the review happened long after the events it's reviewing; and it's not really risk-based, because a scramble under deadline pressure isn't a planned methodology.
There's a principle specific to CROs buried in all of this that doesn't get explained often enough. Under GCP, a sponsor can delegate trial-related tasks to a CRO, but the sponsor cannot delegate away its underlying responsibility for trial quality and oversight. E6(R3) sharpens this further, placing more explicit focus on how sponsors govern and monitor the third parties doing the work.
In practice, that means a sponsor's own inspection readiness depends partly on whether its CRO can demonstrate the kind of ongoing, risk-based audit-trail review Section 4.2.3 describes which is exactly the question that tends to get asked of a CRO's eTMF operations team first, well before any inspector arrives.
Where most eTMF operations still fall short
Most eTMF platforms can export a long audit log. Exporting is not the same activity as reviewing. In practice, that log tends to sit untouched during normal operations and only gets real attention once an inspection is scheduled at which point someone has to reconstruct a coherent narrative about how a protocol amendment rolled out, or why a monitoring plan changed twice in one quarter, from a spreadsheet built specifically for that purpose.
That gets harder still when CTMS and eTMF sit on separate platforms, which remains the standard setup at most organizations. Understanding whether a late edit to a risk management plan lines up with something that was happening operationally a deviation, a site performance shift, a change in monitoring cadence means manually cross-referencing two systems that were never built to talk to each other, usually under real time pressure.
What changes with a unified CTMS↔eTMF architecture
A Salesforce-native CTMS↔eTMF setup addresses this by keeping documents, their metadata, and every create, update, and delete event on the same platform as study, country, and site milestones. Inside that environment, the AI eTMF Agent continuously scans audit-trail activity instead of waiting for a periodic export:
- Version churn and late edits get tracked on the document types that matter most protocols, amendments, monitoring plans, risk management plans, key correspondence
- Approvals landing unusually close to a governance cut-off or submission deadline get flagged rather than passing unnoticed
- Access to blinding-sensitive documents that doesn't match normal workflow gets escalated, in a way that still respects privacy constraints
- Document changes get read against CTMS milestones automatically, so a change to a monitoring plan shows up connected to whatever was actually happening operationally at the time
Routine activity is classified and stored, remaining fully available without demanding constant attention. Anything that looks genuinely worth a second look surfaces as a flag or task for a named reviewer, and that review itself becomes part of the same audit trail which is precisely the evidence needed to demonstrate that review was planned and risk-based, not assembled after the fact.
The bottom line, with January 2027 on the calendar
Annex 2 having an actual effective date changes the calculus for CROs specifically, given the accountability that sits between a sponsor's oversight obligations and a CRO's day-to-day execution. Organizations walking into a 2027 inspection with confidence will be the ones where audit-trail review is already a routine property of the system, not an exercise assembled from CSVs the week an inspector is announced.
See how a Salesforce-native CTMS↔eTMF setup with the AI eTMF Agent gets your team ready for what Annex 2 will actually ask.

Subscribe to our Newsletter