Buying an e-signature or eTMF platform for a clinical trial usually gets treated as a software decision. Someone checks the feature list, someone else asks for IQ/OQ/PQ protocols, and the contract gets signed. Clinical trial vendor qualification is a different, and separate, exercise. It's not asking "does this software do what it claims." It's asking "is this organization one we can hand a piece of our GCP responsibility to, and can we prove that decision was reasoned."
ICH E6(R3), the current Good Clinical Practice guideline, is explicit that the two questions don't collapse into one. It puts real, specific obligations on a sponsor before and during a service provider relationship, and it deliberately never uses the word "vendor." This post works through what ICH E6(R3) actually requires for clinical trial vendor qualification, how it differs from the system validation work most teams already do, and what a documented vendor qualification assessment needs to contain.
Key Takeaways
- ICH E6(R3) doesn't use the word "vendor." It uses "service provider," defined as "a person or organisation (commercial, academic or other) providing a service used by either the sponsor or the investigator to fulfil trial-related activities," with a CRO named as one type of service provider.
- Section 3.6.7 puts the assessment and selection decision directly on the sponsor: "The sponsor is responsible for assessing the suitability of and selecting the service provider to ensure that they can adequately undertake the activities transferred to them."
- Section 3.6.8 requires access to the vendor's own governance evidence, not just its product: "SOPs and performance metrics."
- Vendor qualification (assessing the organization) and computerized system validation (assessing the software under Section 4.3) are two distinct obligations in the guideline. Passing one doesn't satisfy the other.
- ICH E6(R3) was adopted by the ICH Assembly on 6 January 2025. FDA finalized it as a Level 1 guidance for industry in September 2025, per a Federal Register notice published September 9, 2025.
ICH E6(R3) Calls It a "Service Provider," Not a Vendor
Before getting into what the guideline requires, it's worth being precise about terminology, because a lot of secondary commentary on this topic slips into calling the guideline's obligations "vendor requirements" as if that were the document's own language. It isn't. ICH E6(R3)'s glossary defines the term it actually uses:
"Service Provider: A person or organisation (commercial, academic or other) providing a service used by either the sponsor or the investigator to fulfil trial-related activities."
The same glossary cross-references the more familiar acronym directly: "Contract Research Organisation (CRO): See Service Provider." A CRO, an eTMF host, an e-signature platform, a central lab, and an imaging core lab are all, in the guideline's own structure, the same category of thing: a service provider. That matters for this post because it means the obligations below apply to an e-signature or eTMF platform the same way they apply to a CRO. There's no separate, lighter-touch category in the guideline for "just a software vendor."
What the Sponsor Has to Do Before Selecting One
Section 3.6 of ICH E6(R3), on Agreements, sets out the sponsor's obligations for service providers directly and in sequence. Section 3.6.7 states plainly where the selection responsibility sits:
"The sponsor is responsible for assessing the suitability of and selecting the service provider to ensure that they can adequately undertake the activities transferred to them. The sponsor should provide the service providers with the protocol where necessary as well as any other documents required for them to perform their activities."
That's the qualification obligation in one sentence: assess suitability, then select. Not the other way around. Section 3.6.8 then specifies what "assessing suitability" has to be able to draw on:
"The sponsor should have access to relevant information (e.g., SOPs and performance metrics) for selection and oversight of service providers."
This is the part a pure feature-and-pricing evaluation misses. SOPs and performance metrics describe how the vendor runs its own organization: how it manages change control, how it handles incidents, what its own quality management process looks like, how it's performed for other regulated customers. None of that shows up in a product demo. A vendor qualification assessment has to actually request it.
Selection Doesn't End the Obligation. Oversight Is Ongoing.
ICH E6(R3) treats vendor qualification as a starting gate, not a one-time approval that clears the sponsor of further responsibility. Section 3.6.9 requires continuing oversight after the relationship starts, and extends it past the immediate vendor:
"The sponsor should ensure appropriate oversight of important trial-related activities that are transferred to service providers, including activities further subcontracted by the service provider."
That last clause is worth sitting with. If an e-signature vendor uses a subcontracted cloud hosting provider, a subcontracted identity-verification service, or a subcontracted support desk, the sponsor's oversight obligation follows the activity down that chain, not just to the vendor's own front door. Section 3.9.5, in the broader discussion of sponsor oversight, states the same principle from the sponsor's side of the relationship:
"The range and extent of oversight measures should be fit for purpose and tailored to the complexity of and risks associated with the trial. The selection and oversight of investigators and service providers are fundamental features of the oversight process. Oversight by the sponsor includes quality assurance and quality control processes relating to the trial-related activities of investigators and service providers."
And Section 3.6.6 is explicit that transferring an activity doesn't transfer accountability for it: "the ultimate responsibility for the sponsor's trial-related activities, including protection of participants' rights, safety and well-being and reliability of the trial data, resides with the sponsor. Any service provider used to perform clinical trial activities should implement appropriate quality management and report to the sponsor incidents that might have an impact on the safety of trial participants or/and trial results." An incident-reporting commitment from the vendor is something a qualification assessment should confirm exists, in writing, before the relationship starts, not something to discover the first time an incident happens.
Vendor Qualification Is Not the Same Thing as System Validation
This is the distinction that gets collapsed most often, and ICH E6(R3) keeps them structurally separate. Vendor qualification, under Section 3.6, is about the organization: is this a service provider the sponsor can reasonably rely on. Computerized system validation, under Section 4.3, is about the software: does this specific system perform reliably for its intended use. Section 4.3.4 states the validation standard on its own terms:
"The responsible party is responsible for the validation status of the system throughout its life cycle. The approach to validation of computerised systems should be based on a risk assessment that considers the intended use of the system; the purpose and importance of the data/record that are collected/generated, maintained and retained in the system; and the potential of the system to affect the well-being, rights and safety of trial participants and the reliability of trial results."
A vendor can pass a rigorous qualification assessment (strong SOPs, clean performance history, documented incident response) and still have a specific system configuration that fails validation for your trial's intended use. The reverse is also true: a well-validated system doesn't tell you anything about whether the organization behind it has a functioning quality management process. Our guide on validating an e-signature system through IQ/OQ/PQ covers the system-level side of this. Vendor qualification is the layer that has to happen first, or at minimum in parallel, not as a substitute.
Section 3.16.1(x) makes the same organization-versus-system split concrete for systems the investigator, rather than the sponsor, deploys. For systems used or deployed by the investigator/institution, the sponsor's obligation is to:
"Assess whether such systems, if identified as containing source records in the trial, (e.g., electronic health records, other record keeping systems for source data collection and investigator site files) are fit for purpose or whether the risks from a known issue(s) can be appropriately mitigated. This assessment should occur during the process of selecting clinical trial sites and should be documented."
Note the timing requirement built into that sentence: the assessment happens during site selection, and it has to be documented then, not reconstructed later if a question comes up during an inspection.
A Vendor Qualification Assessment, Built From the Text Above
Pulling the sections above together, a clinical trial vendor qualification assessment for an e-signature, eTMF, or eCOA platform should be able to produce documented answers to:
- Suitability and selection basis: what specifically made this service provider adequate to undertake the activities being transferred, per Section 3.6.7, documented before the agreement is signed.
- SOPs and performance metrics: has the sponsor actually reviewed the vendor's own SOPs and performance history, per Section 3.6.8, rather than relying on marketing claims about compliance.
- Quality management fit for purpose: per Section 3.6.10, does the vendor's existing quality management process, even if not designed specifically to be GCP-compliant, hold up as fit for purpose in the context of this trial.
- Subcontractor visibility: per Section 3.6.9, what activities does the vendor itself subcontract, and does the oversight plan reach those subcontracted activities too.
- Incident reporting commitment: per Section 3.6.6, has the vendor agreed in writing to report incidents that could affect participant safety or trial results, before those incidents happen.
- Ongoing oversight cadence: per Section 3.9.5, what oversight measures are planned after selection, proportionate to the complexity and risk of the trial, not just a one-time due diligence pass.
None of this replaces the technical validation and Part 11 controls covered in our guides on Part 11 audit trail requirements and the e-signature vendor evaluation checklist. Those cover the system. This is the organization behind it, which the guideline treats as a separate thing the sponsor has to actually assess, not assume.
Where This Guidance Actually Stands Right Now
Status matters here, because ICH guidelines move through a multi-step process before they're binding anywhere, and the dates are easy to get wrong. ICH E6(R3)'s title page and document history record final adoption "by the Regulatory Members of the ICH Assembly under Step 4" on 6 January 2025. That's the international harmonized guideline itself.
FDA's own adoption came later and separately. The agency announced the availability of its "E6(R3) Good Clinical Practice" guidance for industry in a Federal Register notice published September 9, 2025, finalizing a draft guidance of the same title that had been issued in 2023. It's a Level 1 guidance from CDER and CBER, meaning it represents current FDA thinking on the topic without itself creating legally enforceable obligations beyond the underlying statute and regulations, the same nonbinding-recommendation framing FDA guidance documents generally carry. If you're building a vendor qualification program against this text, use the FDA-finalized September 2025 version, not the 2023 draft it replaces.
Klyverity documents the vendor side of this relationship directly: SOC 2 posture, incident response commitments, subprocessor disclosure, and IQ/OQ/PQ validation evidence are all available for a sponsor's own qualification file, not just a features page. If you're building a vendor qualification assessment for an e-signature platform, request a demo and we'll walk through what a documented assessment actually needs from us.
FAQ
Does ICH E6(R3) use the word "vendor"?
No. The guideline's glossary defines "Service Provider" as "a person or organisation (commercial, academic or other) providing a service used by either the sponsor or the investigator to fulfil trial-related activities," and separately notes "Contract Research Organisation (CRO): See Service Provider." An e-signature or eTMF platform falls under this same service provider definition.
Who is responsible for qualifying a clinical trial technology vendor?
The sponsor. Section 3.6.7 states: "The sponsor is responsible for assessing the suitability of and selecting the service provider to ensure that they can adequately undertake the activities transferred to them." Section 3.6.6 adds that transferring the activity doesn't transfer the underlying responsibility: it "resides with the sponsor."
Is vendor qualification the same as system validation?
No. Vendor qualification, under Section 3.6, assesses the service provider organization, its SOPs, performance metrics, and quality management. Computerized system validation, under Section 4.3, assesses whether the specific software system performs reliably for its intended use, based on a risk assessment. A vendor can be well qualified and still deploy an unvalidated or misconfigured system, and a validated system can still sit behind an unqualified vendor.
Does vendor oversight extend to a vendor's own subcontractors?
Yes. Section 3.6.9 requires "appropriate oversight of important trial-related activities that are transferred to service providers, including activities further subcontracted by the service provider." A qualification assessment should ask what the vendor itself subcontracts and how that activity is overseen.
Is ICH E6(R3) currently in effect for FDA-regulated trials?
ICH E6(R3) was adopted by the ICH Assembly on 6 January 2025. FDA published its own finalized "E6(R3) Good Clinical Practice" guidance for industry via a Federal Register notice on September 9, 2025, as a Level 1 guidance from CDER and CBER. Like other FDA guidance documents, it reflects current agency thinking and is framed as nonbinding recommendations rather than an independently enforceable regulation.