Background image for footer

ISO 14155 and EDC: What Compliance Actually Requires

Share on LinkedIn
ISO 14155 and EDC: What Compliance Actually Requires

ISO 14155 and EDC: What Compliance Actually Requires

ISO 14155 makes your data system part of your device’s clinical evidence. ISO 14155:2026 — the fourth edition of the good clinical practice standard for medical device clinical investigations, published March 23, 2026 — requires sponsors to run validated electronic data systems with audit trails and controlled access, and it replaced the 2020 edition with no transition period. Under EU MDR it is the state-of-the-art benchmark for clinical investigations, which makes EDC selection a compliance decision, not a tooling one.


What is ISO 14155 and who has to follow it?

ISO 14155 is the international standard for good clinical practice (GCP) in clinical investigations of medical devices involving human subjects. It is the device world’s counterpart to ICH E6 — covering investigation design, sponsor and investigator responsibilities, risk management alignment with ISO 14971, safety reporting, and the handling of clinical data end to end. The current edition is ISO 14155:2026, published March 23, 2026. It replaced ISO 14155:2020 immediately — there is no transition period, so investigations starting now are measured against the new edition.

Who it binds, in practice: any sponsor running a pre-market clinical investigation or post-market clinical follow-up (PMCF) study intended to support device conformity in Europe, and any sponsor who wants their device data to hold up in front of a notified body or regulator anywhere. It applies to first-in-human and pilot studies just as it does to pivotal ones — proportionate to risk, but never optional.


What does ISO 14155:2026 require of electronic data systems?

The standard’s expectations for electronic clinical data systems — eCRFs (electronic case report forms), EDC, and connected data sources — reduce to five obligations the sponsor must be able to evidence:

  • Validation. Electronic systems must be validated as fit for purpose before use, with documentation to show it.

  • Audit trails. Changes to data must be traceable — who, what, when — without obscuring the original entry.

  • Access control. System access restricted to authorized, trained individuals, with accountability per user.

  • Data protection and integrity. Records protected against loss and unauthorized alteration across collection, transfer, and retention.

  • Traceable safety data flow. Adverse events and device deficiencies captured, categorized, and reportable on the timelines the standard and MDR demand.


How does ISO 14155 relate to EU MDR and FDA requirements?

Under the EU Medical Device Regulation (MDR), clinical investigations must meet the requirements of Annex XV — and ISO 14155 is the recognized state-of-the-art route to demonstrating it. The 2026 timeline was unusual: on January 28, 2026, Implementing Decision (EU) 2026/193 formally harmonized EN ISO 14155:2020/A11:2024 with the MDR — the first harmonization since the MDR entered into force — and the new 2026 edition superseded it weeks later.

In the US, the FDA recognizes ISO 14155 as a consensus standard, and device trials under an IDE (Investigational Device Exemption) additionally carry 21 CFR Part 11 obligations for electronic records and signatures. For a sponsor running both jurisdictions, the practical read holds: one investigation, one data system, two overlapping evidence sets — choose a system that satisfies the stricter of the two everywhere they overlap.


What changed in ISO 14155:2026 — and what it means for your data system

The 2026 edition doesn’t rewrite GCP for devices — it tightens oversight and design rigor in ways that land directly on the sponsor’s data infrastructure:

  • Estimands (Section 6.4, new Annex K). Investigations must pre-specify the precise treatment effect being measured, borrowing the estimand framework from pharmaceutical trials. That precision has to survive contact with your eCRF design — endpoints, intercurrent events, and analysis populations defined at design time, not reconstructed post-lock.
  • Clinical Events Committees (CECs). The standard formally introduces CECs to standardize adverse event and device deficiency adjudication across sites — and sponsors who forgo one should be prepared to justify it. Operationally, a CEC is a data workflow: blinded review queues, adjudication tracking, and an audit trail of who classified what and when.
  • Data Monitoring Committees (DMCs). Sponsors are now expected to justify the absence of a DMC — reinforcing risk-based safety oversight and, with it, the need for real-time, role-controlled access to accumulating safety data.
  • Restructured risk management. The edition distinguishes risks from the device itself (full ISO 14971 methodology) from risks introduced by non-routine study procedures (descriptive assessment) — and risk assessments must be evaluated against the study’s actual sample size and population.

What should device sponsors look for in an EDC?

Mapping the standard’s obligations to the platform capabilities that evidence them:

ISO 14155 obligation

What to evidence

Platform capability that carries it

Validated systems

Validation documentation, current per release

Vendor-supplied validation, certification & SOP package with every deployment; separate Build/UAT/production environments

Audit trail

Full change history, inspector-readable

Computer-generated, time-stamped audit trails; native eSignature

Access control

Role-appropriate access, provisioning records

Role-based permissions with PHI (Protected Health Information) access management

Safety reporting

AE/SAE capture and notification on required timelines

Safety Gateway — adverse event and serious adverse event collection, tracking, and real-time notification

Device-generated and patient data

Traceable ingestion from source to record

ePRO/eCOA, connected devices and wearables ingestion, EHR/EMR integration


How does REDCap Cloud support ISO 14155 device investigations?

REDCap Cloud is a validated EDC/CDMS (electronic data capture / clinical data management system) whose compliance envelope spans FDA 21 CFR Part 11, HIPAA, GDPR, GxP, ICH GCP E6(R3), and EU Annex 11, backed by SOC 2 Type II, ISO 27001/27017/27018, and HITRUST CSF.

For device investigations specifically, the working parts are the ones in the table above: Safety Gateway for AE/SAE tracking and real-time notification, native ePRO/eCOA with a validated instrument library, connected-device and wearables ingestion, randomization, and validation documentation delivered with every deployment — with EU data-center residency available for MDR-scoped investigations.

Frequently Asked Questions (FAQ)

What is ISO 14155?

ISO 14155 is the international good clinical practice standard for clinical investigations of medical devices involving human subjects. It covers investigation design, sponsor and investigator responsibilities, risk management alignment with ISO 14971, safety reporting, and the integrity of clinical data. The current edition is ISO 14155:2026, the fourth edition, published in March 2026 — it replaced ISO 14155:2020 with no transition period.

Is ISO 14155 mandatory under EU MDR?

EU MDR requires clinical investigations to meet Annex XV, and ISO 14155 is the recognized state-of-the-art means of demonstrating conformity. In practice, notified bodies and competent authorities expect device clinical investigations to follow it.

Does ISO 14155 apply to US medical device trials?

The FDA recognizes ISO 14155 as a consensus standard. US device trials under an Investigational Device Exemption also carry FDA requirements, including 21 CFR Part 11 for electronic records and signatures, so sponsors typically design one data system to satisfy both.

What does ISO 14155 say about electronic data systems and eCRFs?

Electronic systems used in a clinical investigation must be validated as fit for purpose, maintain audit trails that preserve original entries, restrict access to authorized individuals, and protect data integrity across collection, transfer, and retention.

What is the difference between ISO 14155 and ICH GCP (E6)?

Both are good clinical practice frameworks. ICH E6 governs clinical trials of medicinal products; ISO 14155 governs clinical investigations of medical devices, adding device-specific elements such as ISO 14971 risk management alignment, device deficiency reporting, and post-market clinical follow-up.

Clinical Research digital data wave background image

Book a Demo 

Start your journey with REDCap Cloud today – scale for tomorrows novel therapies.