Database lock · ISO 14155 · study closeout

Preparing for database lock: a complete guide for medical device studies

Database lock is the point at which all clinical data has been reviewed, verified and approved for statistical analysis. After it, nothing changes without a controlled unlock. It is never a single event at the end of a study: it is the result of months of continuous review across data management, clinical operations, biostatistics, medical monitoring and the sites.

Readiness criteriaQuery closureCoding completeExternal reconciliationSponsor approval
Preparing for clinical database lock in a medical device investigation
What has to be true before the database closes
1
Data entry complete
2
Queries resolved
3
Coding finalized
4
External data reconciled
5
Quality control passed
6
Sponsor approval
Lock preparation begins during study start-up. By the time the last participant completes follow-up, most of the work should already be behind you.
Trusted by medical device teams running clinical investigations in Europe
TerumoMeril Life SciencesNihon KohdenVygonColoplastRegenLabAsahi InteccMolnlyckeTerumoMeril Life SciencesNihon KohdenVygonColoplastRegenLabAsahi InteccMolnlycke
Who manages your clinical data

The team that gets your database to lock

EUCROF Platinum Award 2026
EUCROF Platinum Award 2026xShare Open Call for Clinical Research, co-funded by the European Union
Sebastien Meier Piantanida

Sébastien Meier Piantanida

Chief Data Officer
Biometrics & Data Systems

30yrs

in clinical data systems, biometrics and statistical reporting

  • Owns data management, biostatistics and EDC architecture across Eclevar studies
  • Vendor-independent on EDC platforms: see data management and eCRF platforms
  • Takes studies from database build to lock and analysis with biostatistics
LinkedIn
Jimmy Andrew Hayek

Jimmy Andrew Hayek

Head of Quality & Compliance
ISO 14155 & data integrity

10+yrs

in quality systems and inspection readiness for device studies

  • Holds the ALCOA+ line: attributable, contemporaneous, traceable data
  • Runs quality control on database validation and lock documentation
  • Prepares studies for audit and inspection under ISO 14155
LinkedIn
Dr Mark Da Costa

Dr Mark Da Costa

Chief Operating Officer · former TÜV SÜD Senior Reviewer

Former reviewer atTUV SUD
25+yrs

in device evaluation and Notified Body review

  • Assessed 400+ medical devices in Europe
  • Brings the reviewer perspective to every dataset we release
  • Oversees delivery across the full evidence program
LinkedIn
The milestone

What locking actually means

Database lock is the formal closure of the clinical database once all required data management activities are complete. It is what allows everyone downstream to work from the same verified dataset.

Once locked

  • Clinical data becomes read-only
  • Analysis datasets can be finalized
  • The clinical study report can be prepared
  • Regulatory submission activities can begin
  • Any later change requires a documented unlock

It confirms that

  • Data collection is complete
  • Outstanding discrepancies have been resolved
  • Medical coding has been finalized
  • External data has been reconciled
  • Quality control activities are complete
  • The database reflects the investigation as conducted

Everything that makes this straightforward was decided earlier: the data management plan, a workable eCRF design, meaningful edit checks and continuous cleaning throughout the study. All of it sits inside clinical data management.

The checklist

What has to be complete before you lock

Each of these is verified and documented. A lock recommended without them is a lock that gets reopened.

Complete data entry

Scheduled and unscheduled visits, adverse events, device deficiencies, laboratory data, imaging assessments, device accountability and end-of-study forms. Missing forms are investigated, not assumed.

Queries resolved

Answered by the sites, responses reviewed, corrections verified, unnecessary queries closed, remaining issues escalated. Open queries are the most common cause of a delayed lock.

Medical coding complete

Adverse events, medical history and concomitant medications coded against approved versions of MedDRA and WHO Drug, with consistency verified before lock.

External data reconciled

Central laboratories, imaging vendors, ECG systems, ePRO platforms, wearables and randomization systems, each reconciled against the clinical database.

Protocol deviations reviewed

Classified, with missing assessments explained and the impact on study endpoints evaluated. This is regularly needed during analysis and regulatory review.

Device accountability verified

Device identifiers, serial numbers, lot or batch numbers, implantation and explantation records, deficiencies and device returns. Traceability has to be reconstructible.

European delivery

Closeout does not run at the same speed everywhere

Query response times, vendor delivery calendars, site staff availability and national end-of-study obligations differ by country, and together they decide how long the last month of the study takes.

STUDY CLOSEOUT - EUROPE STUDY CLOSEOUT · EUROPE NOUKDEFRITES CloseoutExternal vendor data arriving ondifferent national calendarsWatch: last laboratory batch before lockFranceSite archiving obligations, CNIL retentionWatch: signature circuits in AugustNordics & UKRegistry linkage available forlong-term follow-up after lockWatch: UK transfer agreementsGermany & AustriaStrong source documentation culture,Watch: site staff availability for queriesSwitzerland, Italy & SpainMulti-region ethics closeout reportingafter the database is lockedWatch: local end-of-study notifications

Query response times, vendor delivery calendars and national closeout obligations differ by country, and they decide how long the last month of the study takes.

Final review

What the data manager checks before recommending lock

Automated edit checks have already run for months. This pass looks for what they structurally cannot find.

  • Missing data review across critical variables, not just overall completeness
  • Trend analysis by site and over time, looking for patterns rather than individual errors
  • Cross-form consistency where no automated check exists
  • Endpoint verification against the protocol definitions
  • Safety review alongside medical monitoring
  • Visit completeness and eligibility confirmation for every participant

Independent quality control then confirms the activities were performed: query metrics, database validation records, coding verification, external reconciliation review, documentation checks and audit trail review. Many sponsors require this review by someone outside the study team before approving the lock.

Biostatistics comes to the table before the lock, not after
Biostatistics comes to the table before the lock, not afterAnalysis populations, endpoint completeness, derived variables and data listings are reviewed together while there is still time to act on what they show.
Approval and execution

Who signs, and what happens next

The lock takes place only after formal sponsor approval, following the organization standard operating procedures.

The approval confirms

  • Data management has completed all activities
  • Clinical operations agrees study conduct is complete
  • Medical monitoring has completed safety review
  • Biostatistics is ready to begin analysis
  • Outstanding issues are documented and accepted

The lock itself

  • Data entry disabled
  • User permissions restricted
  • Audit trails archived
  • Lock documentation generated
  • Approval signatures recorded

After lock come statistical analysis, generation of analysis datasets, the clinical study report, regulatory submission preparation and publication planning, all working from one frozen dataset. The results feed the clinical evaluation report and, where the program continues, post-market clinical follow-up.

What goes wrong

The five things that delay a lock

They are predictable, which means they are manageable if you look for them early enough.

Delayed data entry

Late entry at sites creates unnecessary pressure during closeout and hides problems until there is no time to fix them.

Excessive open queries

Usually a symptom of insufficient ongoing review rather than poor data. The volume was always there, it just was not addressed.

Poor communication

Clinical operations, data management and investigators working from different priority lists during closeout.

Incomplete external data

A missing laboratory or imaging batch prevents final reconciliation, and it usually arrives from outside your control.

Late protocol amendments

Changes introduced near the end may require database modifications and revalidation, on the critical path.

No owned lock date

Without a tracked readiness view, the date moves quietly. Continuous cleaning and risk-based prioritization are what keep it honest.

Practice

The habits behind a lock that lands on time

Start preparing during study start-up. Clean continuously rather than at closeout. Track open query rate, missing data, entry timeliness and reconciliation status. Focus on critical data. Hold regular meetings between data management, clinical operations, biostatistics and medical monitoring. Document everything as you go, because reconstructing it afterwards is what turns a two-week closeout into a two-month one.

Study closeout coordination between data management and clinical operations
Coming soon
FAQ

Questions sponsors ask about locking

What is the difference between database freeze and database lock?

A freeze is a temporary restriction on changes while data is reviewed, and corrections can still be made if necessary. A lock is the formal closure of the database, and changes after it require a documented unlock procedure with appropriate approvals.

Can a database be unlocked after it has been locked?

Yes, but only under controlled circumstances. Any unlock follows documented procedures, includes sponsor approval and maintains a complete audit trail explaining why the change was necessary.

Who approves database lock?

The sponsor, after confirmation from data management, clinical operations, medical monitoring and biostatistics that all required activities are complete.

How can sponsors shorten the time to database lock?

Start cleaning early, resolve queries continuously, monitor the key quality metrics, reconcile external data throughout the study rather than at the end, and apply a risk-based approach so the critical data is clean long before closeout.

How long does database lock usually take?

It depends almost entirely on how much cleaning was left undone. A study with continuous review and current reconciliation can lock within weeks of the last visit. One that deferred cleaning can take several months.

Can you take over a study that is close to lock?

Yes. It starts with a readiness assessment: open query age, missing critical data, coding status, reconciliation state and validation documentation, then a remediation plan with a defensible date.

Start the conversation

Is your database actually ready to lock?

Send us the study details and the current metrics. We come back with a readiness review covering open query age, missing critical data, coding progress, external reconciliation and documentation, plus a lock date you can defend.

Your documents are reviewed confidentially. An NDA can be put in place before we receive any technical or clinical information. You can also reach the team through the contact page.

Reforming Clinical Evaluation of Medical Devices in Europe