You Can Delegate the Work, Not the Accountability: Vendor Qualification and Oversight under ICH E6(R3)
The sponsor’s duty to qualify and oversee its DHT vendors — distinct from who holds the economic-operator role.
A sponsor can transfer all the work of building and running a DHT; ICH E6(R3) s.3.6.6 keeps ultimate responsibility for data reliability with the sponsor.
A vendor’s certifications describe the vendor; they do not discharge that duty for this study — and a DHT vendor changes during the study. Qualify for this use before reliance, set a risk-proportionate monitoring cadence, contract for notification, flow-down, audit and exit, and record every re-assessment.
Oversight reaches six areas, and each needs its own evidence over time
| Area | What oversight checks | Evidence / monitoring method |
|---|---|---|
| Validation | Validated for this intended use, not “validated” in the abstract | Use-specific validation report; re-review on material change |
| Data integrity | Audit trail, access control and device-side integrity | Audit-trail review; periodic access-control and integrity checks |
| Security | Security posture and incident handling for the trial data held | Security assessment review; incident-notification clause and log |
| Change control | How releases and updates affecting the validated state are managed | Release notes and change log; impact assessment per release (QPP-07) |
| Subcontractors and sub-processors | The vendor’s own connectivity, hosting and analytics suppliers | Sub-processor list in contract; flow-down evidence (GDPR Art. 28(4)) |
| Continuity | Data export, retention and what happens if the relationship ends | Export / retention terms and a tested exit plan |
Four positions that separate “certified” from “overseen”
E6(R3) s.3.6.6 keeps ultimate responsibility with the sponsor; ss.3.6.7–3.6.8 require suitability assessment and access to procedures and metrics; 21 CFR 312.52 retains the rest.
E6(R3) s.3.6.9 extends oversight to activities the provider subcontracts further; GDPR Art. 28(2) and 28(4) require written authorization and flow-down. Annex 2 repeats the duty for DCTs.
A certificate shows general capability, not that this system, configured for this protocol, is fit for purpose or stays so. At inspection, “the vendor handled that” is not an answer.
In qointa’s assessment, the “validated once” fallacy, OS dependency on uncontracted platform vendors, hosting and connectivity sub-vendors and release pace mean a one-time check misses all four.
Six actions that turn a selection gate into continuous oversight
- 1Qualify for the use before reliance — validation, data integrity, security, change control, sub-processors and continuity.
- 2Set a monitoring cadence proportionate to criticality — event-driven on releases, OS or connectivity changes, sub-processor moves.
- 3Put oversight into the contract — release and sub-processor notification, flow-down (GDPR Art. 28(4)), audit rights, export and exit.
- 4Run an impact assessment on each relevant release (QPP-07) and specify and monitor the device / OS range.
- 5Test the exit plan before it is needed where the vendor holds the only copy of source data.
- 6Record each qualification and re-assessment in the Trigger Register (QPP-08); file the evidence in the quality system and TMF.
ICH E6(R3) ss.3.6.6–3.6.9, 3.10 and Annex 2 · EMA/INS/GCP/112288/2023 (Annex 1, A2.1) · GAMP 5 (second edition) · GDPR Art. 28(2), 28(4) · 21 CFR 312.52 · FDA DHT guidance · EU AI Act · Regulation (EU) 2026/1744 · NIS2
© qointa 2026 – Public – Uncontrolled when printed · Not legal advice; this summary does not classify any device.
sales@qointa.com · qointa.com
More from the library
Digital Health Technologies in Clinical Trials — A Regulatory Position-Paper Series
One device, several perimeters: a framework for assessing the regulatory impact of the technologies a trial relies on.
Read more →Who Is the Manufacturer? Economic-Operator Roles in DHT Supply Chains
How provisioning, importing, kitting and modifying a device assign manufacturer, importer and distributor duties — often by operation of law.
Read more →The Trigger Register: A Controlled Instrument for Digital-Trial Compliance
Turning the per-stakeholder assessment into a living, inspection-ready artefact in the technical file, the validation plan and the TMF — grounded in the risk-based quality management GCP already expects.
Read more →Talk to a specialist
Bring one device and one protocol — a wearable, a sensor, an app, anything. We will tell you which regulatory perimeters it opens and what it takes to close them.
Book a 15-minute call