Data management plan · ISO 14155 · study start-up

How to develop an effective data management plan

The data management plan is the first document that decides whether your database lock will be uneventful. It defines how clinical data will be collected, reviewed, validated, coded, reconciled and locked, and it aligns clinical operations, biostatistics, monitoring and data management before the first participant is enrolled.

Ten componentsRoles & responsibilitiesValidation strategyExternal dataLock criteria
Data management plan for a medical device clinical investigation under ISO 14155
Where the plan sits in study start-up
1
Protocol drafted
2
Risk assessment
3
Data management plan
4
eCRF design
5
Database build
6
Validation & UAT
Written after the protocol has taken shape and before the database is frozen. That window is the whole point.
Trusted by medical device teams running clinical investigations in Europe
TerumoMeril Life SciencesNihon KohdenVygonColoplastRegenLabAsahi InteccMolnlyckeTerumoMeril Life SciencesNihon KohdenVygonColoplastRegenLabAsahi InteccMolnlycke
Who manages your clinical data

The team that writes and applies the plan

EUCROF Platinum Award 2026
EUCROF Platinum Award 2026xShare Open Call for Clinical Research, co-funded by the European Union
Sebastien Meier Piantanida

Sébastien Meier Piantanida

Chief Data Officer
Biometrics & Data Systems

30yrs

in clinical data systems, biometrics and statistical reporting

  • Owns data management, biostatistics and EDC architecture across Eclevar studies
  • Vendor-independent on EDC platforms: see data management and eCRF platforms
  • Takes studies from database build to lock and analysis with biostatistics
LinkedIn
Jimmy Andrew Hayek

Jimmy Andrew Hayek

Head of Quality & Compliance
ISO 14155 & data integrity

10+yrs

in quality systems and inspection readiness for device studies

  • Holds the ALCOA+ line: attributable, contemporaneous, traceable data
  • Runs quality control on database validation and lock documentation
  • Prepares studies for audit and inspection under ISO 14155
LinkedIn
Dr Mark Da Costa

Dr Mark Da Costa

Chief Operating Officer · former TÜV SÜD Senior Reviewer

Former reviewer atTUV SUD
25+yrs

in device evaluation and Notified Body review

  • Assessed 400+ medical devices in Europe
  • Brings the reviewer perspective to every dataset we release
  • Oversees delivery across the full evidence program
LinkedIn
The document

What a data management plan actually is

A controlled document describing every process applied to clinical data during the study. It is the operating manual everyone works from, not a formality produced for the trial master file.

It states, in writing

  • How study data will be collected, and from which sources
  • How data quality will be monitored during the study
  • How discrepancies will be raised, tracked and closed
  • How medical coding will be performed and reviewed
  • How data will be reviewed and validated
  • How the database will be locked and archived

What it prevents

  • Two teams applying different definitions to the same variable
  • Edit checks written after the sites have started entering data
  • External vendor data reconciled for the first time at closeout
  • Ambiguity about who closes a query and on what basis
  • A lock date that nobody can defend

Clinical investigations generate thousands of data points from investigators, laboratories, imaging systems, wearables and patient-reported outcomes. Without a structured plan those inconsistencies accumulate quietly, and they surface on the critical path. The plan is one part of the broader clinical data management scope.

Scope, ownership and the lock date all sit in the same document. See how we build a data management plan for a medical device trial as part of end-to-end EDC and data management.

Timing

Draft it during start-up, before the database is finalized

The plan should be drafted once protocol development has progressed and before the EDC database is locked down. Early drafting lets the data strategy influence decisions that are expensive to reverse.

eCRF structure

Which forms exist, what each one collects, and how visits map to them. See eCRF design.

Edit check design

Which checks fire automatically, which discrepancies need a human, and which are not worth a query at all.

Data review workflows

Who reviews what, how often, and what triggers escalation.

External data integration

Transfer frequency, file formats and reconciliation rules, agreed with vendors before the first transfer.

Medical coding requirements

Dictionaries, versions, conventions and who signs off the coded terms.

User roles and permissions

Who can enter, who can query, who can close, who can lock, and what the audit trail records.

Waiting until enrollment has begun means amendments, revalidation and avoidable cost. This is the same reason data management belongs inside study start-up rather than after it.

European delivery

The plan has to survive every country in the study

A data management plan written for one jurisdiction breaks in a multinational investigation. Consent wording, hosting, transfer rules and registry access enter the plan explicitly.

DATA GOVERNANCE ACROSS THE STUDY - EUROPE DATA GOVERNANCE ACROSS THE STUDY · EUROPE NOUKDEFRITES Study dataOne database, one data management plan,country-specific consent wordingWatch: local ePRO language versionsFranceCNIL reference methodology, MR-001 / MR-003Watch: data hosting and HDS certificationNordics & UKNational registry linkage, strong sourcedata availabilityWatch: UK data transfer post-BrexitGermany & AustriaBfArM and BASG expectations, DSGVOWatch: site-level data protection officersSwitzerland, Italy & SpainSwissmedic ClinO-MD, national ethicsreview of the data flowWatch: cross-border transfer outside the EEA

Data protection rules, hosting requirements and registry access vary by country and are settled before the database is built, not after the first patient is enrolled.

Contents

The ten sections a complete plan carries

Every study is different, but a plan missing one of these will be found out at some point in the study, usually late.

1. Study overview

Title, protocol number and version, sponsor, objectives, investigation type, participating countries and sites. Everyone works from one context.

2. Roles and responsibilities

Sponsor, clinical data manager, CRA, investigator, statistician, medical monitor, database programmer, coding specialist. A responsibility matrix settles this once.

3. Data collection strategy

eCRFs, external laboratory data, imaging, device-generated data, ePRO, wearables and the transfer specifications for each.

4. Database design

Visit schedule, forms, variables, controlled terminology, edit checks, dynamic logic, user roles and audit trails.

5. Data validation

Automatic edit checks, manual review, cross-form consistency, missing data detection, range and logical validation.

6. Query management

Generation criteria, review process, investigator responsibilities, response timelines, closure and escalation.

7. Medical coding

Dictionaries such as MedDRA and WHO Drug, coding conventions, version management, review process and responsibilities.

8. External data reconciliation

Central laboratories, ECG providers, imaging vendors, randomization systems, device telemetry, electronic diaries.

9. Quality control

Peer review, database testing, validation documentation, data review meetings and metrics monitoring, documented throughout.

10. Database lock

The conditions required before locking, who authorizes it and how the documentation is archived. See database lock.

A plan that is consulted, not filed
A plan that is consulted, not filedA practical, study-specific document that the team actually opens is worth more than a forty-page template nobody reads after approval.
Risk

The plan says where the review effort goes

Applying the same level of review to every variable is a decision, and usually the wrong one. The plan documents the risk assessment and what it changes.

Identify critical dataSet review intensityDesign edit checksTarget query generationFocus quality control

Critical efficacy endpoints, patient safety variables, primary analyses and key protocol data get enhanced oversight. Lower-risk information is handled through automation and targeted review. The reasoning and the method are set out on the risk-based data management page.

Regulatory

What the plan has to support

Requirements differ by region, but the principle does not: regulators expect a sponsor to demonstrate that clinical data is accurate, complete and traceable across the study lifecycle.

The frameworks in scope

  • ISO 14155, clinical investigation of medical devices
  • EU MDR 2017/745
  • ICH Good Clinical Practice E6
  • 21 CFR Part 11 where applicable
  • ALCOA+ data integrity principles

Common mistakes to avoid

  • A generic plan that was never tailored to the study
  • Responsibilities left implicit
  • Edit checks created because the system allows them
  • External data reconciliation left out entirely
  • Approval delayed until after study initiation
  • The plan never updated when the protocol changes

Teams that want the underlying framework rather than a document review can start with our ISO 14155 training, or with the clinical evaluation chain the data eventually feeds.

In practice

Aligned with the protocol and the analysis plan

The data management plan, the clinical protocol and the statistical analysis plan have to agree on the population, the endpoint definitions and the handling of missing data. When they do not, the disagreement is discovered during analysis, at the point where it costs the most to resolve.

Statistical analysis planning alongside clinical data management
Coming soon
FAQ

Questions teams ask about the plan

Who writes the data management plan?

The clinical data manager owns it, drafting with clinical operations, biostatistics, medical monitoring and regulatory. The sponsor approves it. A plan written by one function alone tends to be unworkable for the others.

When does it need to be approved?

Before the database goes live and before the first participant is enrolled. Approving it later means the database was built against assumptions rather than an agreed plan.

How long should it be?

Long enough to answer the ten questions above for this study, and no longer. A practical study-specific plan beats a comprehensive document that is never consulted.

Does it need to be updated during the study?

Yes, whenever a process changes: a protocol amendment affecting data collection, a new external vendor, a change to the coding dictionary version, a revised review strategy. Each version is controlled and the rationale documented.

Can you review a plan we have already written?

Yes. A gap review against ISO 14155, the protocol and the analysis plan, focused on the parts that usually break: validation scope, external data reconciliation, coding conventions and lock criteria.

What is the relationship with the statistical analysis plan?

The two documents have to agree on population definitions, endpoint derivations and missing data handling. The data management plan describes how the data arrives clean, the analysis plan describes what is done with it.

Start the conversation

Want your data management plan reviewed before the database is built?

Send us the protocol and the current draft. We come back with a gap review against ISO 14155 and the analysis plan, and the list of decisions that need settling before the database is frozen.

Your documents are reviewed confidentially. An NDA can be put in place before we receive any technical or clinical information. You can also reach the team through the contact page.

Reforming Clinical Evaluation of Medical Devices in Europe