Verify every record. Visit the sites that need it.
Attestra AI compares source documents against EDC entries field by field and surfaces discrepancies with page-level evidence. Your monitors decide what it means — they just stop reading the 96% that already match.
Built for risk-based monitoring under ICH E6(R3) · 21 CFR Part 11 audit trail · Validated deployment
| FIELD | SOURCE | EDC | Status |
|---|---|---|---|
| VISIT_DATE | 2026-04-14 | 2026-04-14 | Match |
| SYSTOLIC_BP | 128 | 128 | Match |
| HGB_G_DL | 11.4 | 11.4 | Match |
| AE_ONSET | 2026-04-09 | 2026-04-09 | Match |
| CONMED_DOSE | 20 mg (hw) | 20 mg | REVIEW |
| ECOG_STATUS | 1 | 0 | Discrepancy |
Monitoring is the largest controllable cost in a trial, and most of it is spent confirming that correct data is correct.
- 25%
- of trial monitoring spend goes to on-site source data verification
- 97.2%
- of verified fields contain no discrepancy against source
- 28
- discrepancies found per 1,000 fields verified
Industry estimates, risk-based monitoring literature
Pooled analyses of SDV yield across multi-site trials
Derived from the figure above
Figures are industry estimates and vary by therapeutic area, phase and site maturity. Attestra does not publish client data.
Four steps, each one leaves a record.
- 01INGEST
Source documents arrive as scans, native PDFs or exports. Layout and handwriting are handled at the page level.
- 02EXTRACT
Values are located and bound to their EDC field, with a page and region reference retained for every one.
- 03COMPARE
Each field is checked against the EDC record. Matches, mismatches and low-confidence reads are separated.
- 04RANK
Sites are ordered by residual risk so visit planning follows the data.
ECOG_STATUS
- SOURCE
- 1
- EDC
- 0
- CONFIDENCE
- HIGH
- LOCATION
- p.004 / r.4.2
Every flag resolves to a page and a region. Reviewers verify, they do not trust.
Written for the audit, not around it.
- DECISION SUPPORT ONLY
No automated approval, sign-off or query closure. Every discrepancy is resolved by a qualified reviewer.
- FULL AUDIT TRAIL
Every extraction, comparison and reviewer action is logged with user, timestamp and reason. 21 CFR Part 11 aligned.
- VALIDATED DEPLOYMENT
Installation, operational and performance qualification documentation supplied per instance. GxP change control.
- DATA RESIDENCY
Per-tenant isolation. Regional deployment including on-premise. Source documents do not leave the sponsor's boundary.
- NO TRAINING ON CLIENT DATA
Study data is never used to train shared models. Contractually committed.
- TRACEABLE READS
Every extracted value retains its page and region reference. Nothing is asserted without a location.
It sits between the systems you already run.
eSource · scanned charts · lab exports · PDF
ATTESTRA AI
Medidata Rave · Veeva CDMS · Oracle Clinical One · OpenClinica · REDCap
Read access only. Attestra AI writes nothing back to the EDC.
Questions we are asked first
Answers cover accountability, regulatory fit, validation and data handling. Attestra is decision support; a qualified reviewer resolves every discrepancy.
No. It changes what a visit is for. Monitors still travel, but they arrive with a ranked list of fields and sites that warrant attention rather than a sampling plan. Sites with clean verification histories move to reduced-frequency review; sites with unresolved discrepancies move up the schedule.
The sponsor and the CRO, exactly as today. Attestra is decision support: it surfaces candidate discrepancies with a page and region reference, and a qualified reviewer resolves every one. The system does not approve, sign off, or close queries, and accountability does not transfer to the vendor.
E6(R3) expects monitoring effort to follow identified risk rather than a fixed percentage of fields. Applying that in practice requires continuous evidence of where data quality is weak. Attestra produces that evidence at the field level and feeds it into the monitoring plan, so risk assessments are revised on data rather than on assumption.
Installation, operational and performance qualification documentation is supplied per instance, along with a requirements traceability matrix, release notes and change control records. Deployments operate under a documented GxP change management process, and validation packages are available for sponsor and CRO audit ahead of contracting.
Handwritten entries are read at the page level and returned with an explicit confidence indicator; low-confidence reads are routed to a reviewer rather than asserted. Non-English source is supported, with the extracted value bound to the same EDC field and the original text retained alongside it for verification.
Source documents are processed inside the sponsor or CRO boundary, in a dedicated tenant or on-premise. Direct identifiers can be masked before extraction where the protocol permits. Study data is never used to train shared models, and this is a contractual commitment rather than a configuration setting.
Attestra AI is in limited deployment with selected CRO partners.
