Panorama TMF QC
System
Capabilities.
A structured, evidence-bounded engine for full-file Trial Master File review — every record touched, every finding cited, every claim reconcilable.
- ✓Ten stages, applied to every recordFrom navigating the trial’s structure through packaging the deliverable, the same sequence runs the same way across the whole file.
- ✓Your rules firstCriteria come from your own TMF plan, file plan, and SOPs before any general regulatory benchmark is applied.
- ✓Nine inspection domainsFoundation, trial design, approvals & consent, site readiness, subject management, safety, monitoring & CAPA, data integrity, closeout.
- ✓Evidence-bounded, reconciledEvery finding cites its source; every population count reconciles to a stated denominator.
- ✓Measured performanceWhat a full-corpus review costs in system time, against what the same reading costs in human hours.
Ten thousand documents, two ways to read them.
A reference-scale trial master file — roughly 10,000 documents, about 96,700 pages — completes a full-corpus review in approximately 6 days. Matching that by hand requires roughly 77 people reading 8 hours a day for the same 6 days — the same 458 person-days of reading, compressed. The two distributions below come from 200,000 Monte Carlo trials over measured throughput and a normal spread on document size and reading speed.
Reading time only — excludes audit-trail work, assessment, cross-checking, and finding write-up, so this is a floor, not a full-job estimate. Demonstrated on one completed reference run; a different document mix or hardware configuration will move these numbers.
Full-file coverage.
Every record in a defined TMF export is touched by the review.
- ✓Breadth and depth are reported separatelyThe whole population is screened for metadata, classification, timing, and file availability. Beyond that, documents are opened and read — and the count of what was actually opened is stated on its own, never blended into the screening number.
- ✓Coverage is arithmetic, not adjectiveFiles read plus files that failed equals the total in the extract, with every failure itemized by pointer and reason. A percentage you cannot reconcile is not a coverage claim.
Structured inspection logic.
Rules, thresholds, and dependency checks are applied consistently across every record, inside a defined scope the model does not get to redefine. AI runs inside a bounded workflow, not an open-ended conversation — the same logic, applied the same way, record after record.
- ✓The scope is fixed before the review startsWhat must be examined, in what order, and to what evidence standard is settled up front. The workflow cannot quietly narrow its own remit to finish faster.
- ✓Facts and interpretation stay separateWhat the record says is recorded distinctly from what it is judged to mean, so a reviewer can accept the fact and still challenge the conclusion.
- ✓Silence is never read as complianceAn absent document, an unreadable file, or a question the extract cannot answer is reported as exactly that. Nothing is inferred into place to make a section look clean.
Ten stages, in order.
The review is not one pass over a pile of documents. It is a sequence, and each stage is built on the one before it — so by the time a finding is written, the expectation it failed, the date it should have met, and the evidence behind it were all established earlier and can be traced back.
Navigate. Establish what this trial is, where its records and raw files live, and which documents set the rules.
Expect. Build the catalog of what should exist — per artifact, per level, per active site, country, and vendor.
Sequence. Build the trial chronology, so timing can be tested against events rather than assumed.
Screen. Test the whole population against the expectation and the chronology, producing a counted exception queue.
Prioritize. Order the work by risk, so the highest-risk items surface first — while the rest of the TMF continues through inspection behind them, every site, country, and language in scope from the start.
Read. Open the documents and test whether the content supports the metadata, the version, the entity, and the dates.
Reconstruct. Use the audit trail to rebuild how each record reached its current state.
Assess. Weigh the combined evidence against the ten ALCOA++ attributes, at record and population level.
Expand & classify. Determine whether an issue is isolated or systemic, then classify it against a fixed severity scale.
Package. Assemble, reconcile, and quality-check the deliverable. This stage creates no new findings.
Measured against your own rules first.
A TMF is not judged against a generic checklist. Before any general expectation is applied, the review goes looking for the documents that govern this file — the TMF plan, the file plan, and the sponsor or CRO SOPs that own each process — and turns their requirements into the criteria the file is then measured against.
Your governing set, located and versioned
TMF plan, file plan, monitoring plan, safety management plan, taxonomy or index, and the procedural SOPs behind them — each found, version-identified, and registered as a criteria source for later stages.
Sponsor or CRO — whose rule governs
Where a function is delegated, the responsible party’s SOPs are the criteria for that function. Transfer-of-obligations documentation and vendor agreements are read to establish which party’s rules apply where.
Captured verbatim, with a citation
Filing timelines, QC and completeness expectations, ownership, and TMF scope are extracted word-for-word with their section and page — so a later finding quotes your own sentence, not our paraphrase of it.
“Promptly” is a plan defect
An unquantified filing timeline cannot govern anything. It is recorded verbatim as a defect in the plan, and the review falls through to the named regulatory clock — with that substitution disclosed, not hidden.
No governing document is itself a finding
If no plan or procedure can be produced, the review says so on the record, applies the regulatory baseline in its place, and carries the absence forward as an inspection-readiness observation.
Your naming and filing conventions.
Naming and indexing expectations are pulled out of your governing plan alongside filing timelines and QC rules, then turned into tests that run across the whole population — because a document that cannot be found by the convention it was filed under is, for inspection purposes, a document that is not there.
- ✓The convention comes from your planNaming and indexing expectations are captured at source, from the same governing documents that define your filing timelines and completeness checks. The standard being enforced is yours.
- ✓Names tested against metadataFile naming inconsistent with the record’s own metadata is screened across the entire population — a routine source of documents that exist but cannot be retrieved under inspection conditions.
- ✓Classification consistencyTaxonomy and classification values are screened for inconsistency and misfiling, including records sitting in the wrong family or filed at the wrong level of the structure.
- ✓Index reconciliationWhere a TMF index exists it is treated as the file’s north star: its entries are crosswalked against actual records and the result is reported as mapped versus unmapped, not asserted as clean.
- ✓Duplicates and conflicts reconciled by identityDuplicate, conflicting, and ambiguous records are resolved against record identity, so a document legitimately filed once and shared across levels is never counted twice — or reported as missing somewhere it was never separately expected.
- ✓Your structure is the spine, not a templateThe review is built on the taxonomy and families your file actually declares. A published industry reference model is held as a completeness cross-check only — never overlaid on your structure as though it were the requirement.
Lineage, tracked and traced.
Guiding documents change throughout a trial. The review builds a version-by-version picture of every controlled family — protocol and amendments, informed consent and participant materials, the Investigator’s Brochure and reference safety information, the monitoring, safety, data-management and statistical plans, and the TMF plan and taxonomy themselves — and records which version governed which period.
- ✓Which version, which windowEvery version carries its issue, approval, effective, and superseded dates and the entities it applies to. Overlaps, gaps, and two-versions-current conflicts are recorded as named limitations rather than smoothed away.
- ✓Approved is not implementedEach applicable site carries its own row: evidenced distribution, receipt, or implementation dates — or the absence of that evidence, recorded as such. Trial-level approval never stands in for site-level adoption.
- ✓Every revision creates obligationsAn amendment is expanded into what it obliges: regulatory and ethics submissions and approvals, updated consent and participant materials, site communication, retraining, and updated operational and safety documents — each screened against what was actually filed, and when.
- ✓Approved-but-never-filed, filed-without-approval, used-before-approvedThree counted populations, each with citations on both sides, produced by reconciling what the approvals enumerate against what the file actually holds and what the dates show was in use.
- ✓Judged against the version in force thenA safety assessment is tested against the reference safety information in force on its own assessment date — not against the current version. Timing is evaluated in the trial’s own past tense.
- ✓Superseded, not vanishedSupersession, replacement, and withdrawal are tracked as lifecycle events, so the file can still show what the prior state was and when it changed.
Every record’s own history.
Underneath document versions sits a second lineage: what happened to each individual record inside the system. The audit trail is used to rebuild that history and to judge whether it is attributable and complete enough to withstand an inspector asking how the record got this way.
- ✓Creation, upload, and filingWhen the record entered the file, by whom, and how that sits against the event it documents and the filing timeline your plan sets.
- ✓Version, status, and file replacementSupersession, re-approval, and status changes in sequence — including whether the underlying file was swapped, and what it replaced.
- ✓Reclassification and reassignmentTaxonomy changes and moves between site, country, vendor, or trial level are treated as first-class events, because they move a record between cells of the completeness picture and can create or resolve an apparent gap.
- ✓Deletion, restoration, withdrawal, archiveIncluding the changes that matter most to an inspector: those made after final, after approval, after closeout, or after archive.
- ✓Who actedActing accounts are inventoried and classified as human, service, or administrative, with the evidence for that classification cited — because attribution is only as good as the account behind it.
- ✓Prior states — and where the trail runs thinWhat the record looked like before each change, and an explicit statement where the audit history is too sparse to reconstruct it. Insufficient history is a reported outcome, not a blank.
Foundation.
The structural baseline — how the file is organized, whether its metadata holds up, and which documents set the rules everything else is measured against.
- ✓Filing model and category inventoryThe file’s own structure, taxonomy, and document families are mapped and become the spine of the review — the levels in use, and whether this is a sponsor TMF, an investigator site file, or both.
- ✓Metadata completeness and quality signalsWhich fields genuinely identify a document, version, site, status, or date — and where those fields are empty, ambiguous, or contradict each other.
- ✓Record universe and coverage ledgerOne counted population of records, raw-file pointers, and audit history, so every later figure has a denominator that can be checked.
- ✓The registers everything else runs onTrial identity, protocol and amendment register, country, site, investigator, vendor and system registers, first milestones, and the criteria documents later stages will cite.
- ✓What could not be establishedMissing sources, broken pointers, unreadable files, absent data dictionaries, signs of a truncated export — each typed, recorded at the moment it is found, and carried through to the final report.
Trial Design Control.
Whether the trial’s design is fully represented in the file and stays traceable through every change it went through.
- ✓Protocol and amendment lineageEvery version and amendment placed on a timeline with the period it governed, so later work can ask which design was in force on any given date.
- ✓Downstream obligations and impact areasEach amendment expanded into the approvals, consent updates, communications, and retraining it triggers, then screened against what the file actually holds.
- ✓Design-to-document traceabilityWhether an individual document can be tied to the version of the design it belongs to — per country and per site, not only at trial level.
- ✓Version conflicts surfaced, not resolved by preferenceGaps, overlaps, and two versions simultaneously marked current are reported as named conflicts. The review does not pick a winner on the sponsor’s behalf.
Approvals & Consent.
Whether approvals and consent are present, correctly timed, and aligned to the right versions — at the level and in the language each site and country actually required.
- ✓Approval matrices and timingWhich body approved what, when, and for which enumerated versions — per country, per site, per submission — with approvals reconciled against the versions the file actually holds.
- ✓Consent inventories and version alignmentConsent and participant materials inventoried by version and by language, with each required local language version treated as an expected record in its own right.
- ✓Cross-checks against design changesWhether the consent in use at a site matched the design in force at the time, and whether approval preceded the activity it was meant to authorize.
Site Readiness.
Whether each site was ready and authorized before it acted — and whether it stayed that way for as long as it was active.
- ✓Startup and activation evidenceSelection, initiation, and green light: whether the record shows the site was authorized ahead of first participant activity, not simply that the paperwork exists somewhere.
- ✓Investigator qualification and delegationCredentials, licensure, the signed investigator agreement or regulatory form, financial disclosure, and the delegation log — each tested against the dates it had to precede.
- ✓Training coverage, per person, per dutyTraining tested against the tasks actually delegated, with certificate-stated expiry honored where present and a refresh benchmark applied — and disclosed as a benchmark — where it is absent.
- ✓Continuity across the whole active periodNo interval in which an active delegated duty at a site sits with nobody currently qualified, currently trained, and currently licensed holding it.
Form FDA 1572.
For FDA-regulated drug trials the signed Form FDA 1572 (21 CFR 312.53(c)) — and for device trials the signed investigator agreement (21 CFR 812.43(c)) — is an expected record at every enrolling site, and is never written off as not applicable. The review treats it as a load-bearing document, not a filed page.
- ✓Expected at every enrolling siteThe form is carried as an expected record per enrolling site from the outset, and its status is tracked per named investigator alongside the investigator, monitor, and vendor rosters.
- ✓Opened and read, not just countedWhen the file is opened, the investigator, site, dates, and signature block are confirmed against the metadata and against the expectation the record is supposed to satisfy.
- ✓It sets other expectationsThe signatories listed on the form drive how many financial disclosures are expected at that site — recomputed per version of the form, so a signatory added by a later version raises the expectation rather than slipping past it.
- ✓A change of investigator is a triggerA PI change obliges a new form or agreement, ethics notification, an updated delegation log, and training updates. Each becomes a downstream expectation screened against the file.
- ✓Part of a wider precedence testThe form sits inside the qualification chain: qualified before delegated, trained before first performance, with the counts reconciled against the delegation entries for that site.
- ✓Signature integrityReused or identical signature blocks appearing across distinct staff, sites, or documents are flagged for human attention wherever they are encountered in site-startup records.
Subject Management.
Whether the subject record holds together across consent, eligibility, and flow — examined strictly at the documentary level a TMF extract supports.
- ✓Consent timingWhether consent to the correct, approved version preceded the activity it was meant to authorize, tested against the version in force at that site on that date.
- ✓Eligibility coherenceWhether the eligibility record is internally consistent and consistent with the protocol version governing the period.
- ✓Subject-flow and evidence consistencyWhether the documented progression through the trial agrees across the records that describe it, including the safety and deviation records that reference it.
Participant identifiers are never transcribed into findings. Where participant-level evidence supports a conclusion, it is cited by location so a reviewer can open it — never reproduced in an output.
Safety Documentation.
Whether safety information was controlled, reported on time, and had its downstream effects honored across the file.
- ✓IB and reference safety information controlWhich version was in force when — and whether each expectedness assessment was made against the version in force on its own date rather than the latest one.
- ✓The case chain, end to endPer case: assessment, submission to each concerned authority and ethics body against computed due dates, distribution to the sites active on the distribution date, and inclusion in the covering periodic report. Every missing link is counted and cited.
- ✓Downstream approval and consent impactsWhether a safety update produced the investigator letter, ethics and regulatory submission, consent revision, and training it obliges — and whether those reached the sites that needed them.
Monitoring, Deviations & CAPA.
Whether oversight actually happened, was evidenced the way your plan says it should be, and carried its issues through to closure.
- ✓Oversight coverage by visit classEvery class of visit your plan describes — selection, initiation, interim, closeout — with its confirmation letter, report, and follow-up letter, plus evidence the sponsor reviewed and followed up on each report.
- ✓Logs reconciled entry-for-entryDeviation, issue, and visit logs are compared line by line against filed records, so an issue that exists only as a row in a tracker becomes visible as exactly that.
- ✓Recurrence patterns and CAPA linkageWhether issues were carried to closure — plan, root cause, action evidence, closure, effectiveness check — and whether the same issue keeps recurring across sites or periods.
- ✓Monitor changes as a controlled handoffA CRA change obliges a transition record with pending items closed off and signed, training completed before the role is assumed, and a timely team-list update — assessed per the responsible sponsor’s or CRO’s SOPs.
Data Integrity.
Every reviewed record weighed against ten data-integrity attributes, evaluated across metadata, the raw file, and the audit trail together.
- ✓Three sources, one judgmentMetadata, the raw file, and the audit trail are weighed as a single body of evidence per record — an attribute is not passed on metadata alone.
- ✓Population as well as recordComplete, Consistent, and Available are judged per artifact, per level, and per active entity — so a gap at one site is not hidden behind coverage at another.
- ✓Cited, or explicitly flaggedEvery conclusion ties to evidence a reviewer can open. Where a record cannot be trusted, that is the stated result — a documented concern, never a silent pass.
Closeout & Readiness.
Whether the file can stand on its own at the finish line — and, if it cannot yet, exactly what is standing in the way.
- ✓Open gaps and unresolved risksWhat remains open, counted, with every exception reconciled from the first screen through to its final status. Nothing is quietly dropped between stages.
- ✓Reconstructability assessmentWhether the file as it stands would let an inspector reconstruct the conduct of the trial — the question behind the whole review.
- ✓Inspection-readiness conclusionA verdict computed by rule from the run’s own results — Ready, Ready with Limitations, or Not Ready — with the reasons behind it and the conditions that would move the file toward ready.
- ✓Your file versus our input, separatedWhere a concern is driven by the quality of the extract we were given rather than the state of your TMF, it is labeled as such and reported alongside a deficiency-only view.
Evidence-bounded findings.
Every finding ties back to the record, metadata, or audit event that produced it. Nothing is asserted without a citation a reviewer can open and check, so findings stay reviewable, challengeable, and remediable — not delivered as unexplained AI commentary.
- ✓A finding shows its workingCriteria, the requirement reference behind them, the condition observed, the evidence from each source, the affected population, and the reasoning — a finding that only says what is wrong is not accepted as complete.
- ✓The criteria are yours or they are namedEach finding cites either your own governing document or the specific regulatory clause it rests on. A finding whose criteria resolve to no recorded source does not ship.
- ✓Isolated or systemic, decided by countScope is established against a stated denominator drawn from your own structure — same family, same level, same country, same site, same vendor — not asserted from impression.
- ✓Confidentiality holds inside the evidencePersonal identifiers are never transcribed into findings, and blinding-sensitive content is cited by location only — never reproduced in outputs.
Numbers that have to add up.
A population you cannot count is a population you cannot defend. Coverage and scope are stated as arithmetic, and the arithmetic is checked before anything is delivered — a package whose figures do not reconcile does not pass its own quality gate.
- ✓Affected + unaffected + not determinable = the denominatorExactly. The portion of a population that could not be determined is carried as its own number rather than folded into either side.
- ✓Read + failed = total filesEvery file that could not be read is itemized individually by pointer and reason — empty pointer, inaccessible, unreadable, incomplete — so coverage is auditable rather than asserted.
- ✓Reported counts triangulatedWhere several documents report the same count, the values are compared period-aligned. Disagreements are surfaced verbatim with both figures and their sources — never averaged, never resolved by preference.
- ✓Expectations recomputed from primary recordsWhere a count should be derived, it is derived from the underlying documents. A system-stated completeness metric is treated as something to reconcile against — never as the denominator.
- ✓Limitations are never clean passesWhat could not be determined is reported as not determinable, with the reason and the impact — and disclosed in the final package rather than absorbed into a pass rate.
Defined-extract workflow.
From a defined export to a reviewer-ready package, the engagement runs in four steps — and never needs a credential to your live system.
Extract
Start from a defined TMF export — metadata, audit trail, and the raw files. No live-system access required.
Inspect
The workflow touches every record, applying rules, thresholds, and dependency checks against your criteria first.
Evidence
Findings are tied back to records, metadata, and the logic that produced them, with counted populations behind each.
Review
Your team inspects, challenges, accepts, or remediates — human review stays in control.
Security & confidentiality by design.
Panorama works from a defined export, inside an isolated environment. Data is never sent to the cloud and never shared with third parties.
Isolated environment
All work runs in an isolated environment. We never send your data to the cloud and never share it with third parties.
No live-system access
Assessment runs on a defined TMF export. Panorama never needs credentials to your live eTMF.
Participant data protected
Personal identifiers are never transcribed into findings; participant-level evidence is referenced by location, not reproduced.
The trial blind respected
Blinding-sensitive content is treated as restricted and cited by location only — never exposed in outputs.
Auditable by design
Every conclusion is tied to the record, metadata, or audit event behind it, and stays human-reviewable.
Distribution under your control
The delivered report can be packaged as an encrypted archive before it leaves your hands, so onward distribution stays a decision you make.
Reviewer-ready outputs.
Structured outputs that clinical operations, quality, compliance, and inspection-readiness teams can actually use — organized so a reviewer can follow the review from source evidence through to conclusion.
- ✓Record universe and coverage ledgerWhat was in the extract, what was screened, what was opened and read, and what failed — stated as reconciling counts.
- ✓Expected-record matrixWhat should have existed, per artifact, level, and active entity, with its applicability decision, criteria source, risk tier, and observed status.
- ✓Trial chronology and version availabilityThe dates the review ran on, and which controlled version governed which period at which site.
- ✓Finding packagesOne evidence package per concern — criteria, condition, evidence from each source, denominator and affected count, scope conclusion, and traceability references.
- ✓Systemic themes and expansion resultsWhere the same issue crosses families, sites, vendors, systems, or periods, with the populations it was tested against.
- ✓Limitations and follow-up areasWhat the extract could not answer and what needs a source outside it — sponsor, investigator, vendor, archive, or live-system access.
- ✓A traceability index and a final QC recordFinal statements linked back to the evidence behind them, plus the record of the checks the package itself had to pass.
The report your team reads first.
One narrative document written for a quality and regulatory audience — no runtime vocabulary, no internal identifiers — with the full step-by-step evidence record attached beneath it as an appendix for anyone who wants to drill in.
A readiness verdict, computed
Ready, Ready with Limitations, or Not Ready — decided by rule from the run’s own results, with the reasons stated and the conditions that would move the file toward ready.
The shape of your file, up front
The index that drove the review, the protocol and amendment footprint, and the family taxonomy — so the reader sees the file before the findings.
What we could and could not establish
The load-bearing scope limits stated before the findings, so every conclusion that follows is read in the right frame.
An area-by-area walk-through
All ten areas narrated in the order they ran, naming the specific documents examined in each — never skipping an area, and marking honestly any the run did not reach.
Attention and escalation, separated
What needs review, what needs a decision before reliance, and every open question a human must resolve — each with the documents it concerns.
One consolidated actionable-items table
Everything to act on in a single table ordered by criticality, with the affected fraction against its population and where it concentrates by family and site.
The method, answered against itself
Every question the methodology poses to a file, posed and answered from this run’s own results — so you can audit the method, not only the narrative.
Severity rubric, glossary, attestation
What each severity means, what the terms mean, document-control identifiers, and a printed sign-off line — the report is machine-assembled and says so.
Descriptive, never prescriptive
The report makes no regulatory determination, assigns no root cause, and writes no CAPA. Those decisions stay with your organization.
Human review stays in control.
Panorama assesses structure, metadata, traceability, lineage, and reconstructability — against your own plans and SOPs first — then returns structured findings your team can review, challenge, accept, or remediate. Built for sponsors, CRO oversight, clinical operations, quality & compliance.
← Back to recenix.com