RTSM Trial Supply Planning 2026: How to Turn Registry Flags into a Protocol-Level Supply Decision
TL;DR
Takeaway: Across 125,076 randomized drug trials on ClinicalTrials.gov, 62,979 (50.4%) have exactly two registered design groups and one reported country. An illustrative 1,786-study subset is double-masked with at least three design groups and two reported countries. Those fields are useful triage signals—but neither subset determines the required RTSM configuration. The defensible decision comes from protocol, supply-chain and product facts the registry does not contain.
A randomization list assigns participants to arms. It says nothing about where drug is, in what packaging, in which language, with what expiry, and who can break the blind in an emergency at 2 a.m. Those are supply questions, and they multiply with countries, arms, masking depth and enrollment — not with the statistical design itself. The mistake runs in both directions: a masked nine-country Phase 3 run on a static kit allocation and resupply emails, and a single-site two-arm trial paying for enterprise supply forecasting it cannot use.
The question is unusually live in 2026. ICH E6(R3) — adopted January 2025, applicable in the EU since July 2025 and adopted by FDA in September 2025 — makes proportionality an explicit organizing principle for trial processes [1][2][3]. A defensible supply decision therefore needs two layers: registry flags for early portfolio triage, followed by a protocol-level assessment of sites, visits, dosing, shelf life, packaging, depots, import routes, temperature conditions, enrollment dynamics and resupply consequences.
Three computed facts set the scale, on the 25 July 2026 ClinicalTrials.gov study file joined to AACT calculated values (1 August 2026), restricted to interventional drug studies with randomized allocation (n = 125,076) [4][5][6].
Half sit in one lower-flag registry cell. 62,979 studies (50.4%) have exactly two registered design groups and one reported country. Group counts overall: median 2, p90 4, p99 9, max 63. Reported-country counts: median 1, p90 3, p99 23, max 57; 12,604 records have no country recorded [6].
One high-complexity flag cohort is small and industry-heavy. Double-masked × ≥3 registered design groups × ≥2 reported countries: n = 1,786, median 4 groups, median 7 countries (p90 = 19), median enrollment 267 (p90 = 1,040); 1,723 are industry-sponsored [5][6]. This describes who merits deeper review; it is not a validated RTSM-need rule or competitor benchmark.
Masking is common and operationally relevant. 84,204 of 125,076 (67.3%) carry a masking code other than NONE — DOUBLE 28,926 (23.1%), QUADRUPLE 28,366 (22.7%), TRIPLE 15,352 (12.3%), SINGLE 11,560 (9.2%) [6]. The enum can flag packaging and emergency-unblinding questions; it cannot establish the physical blinding method, kit design or code-access workflow.
This paper is a configuration workpaper, not a "complexity is rising" essay. It measures registry flags, makes their missingness visible, and shows how to convert them into study-specific requirements without pretending that public fields reveal the supply design. Adjacent EClinCloud Deep Research covers protocol complexity and study-build workload (30 August 2026) and cross-registry trial identity (24 August 2026).
One randomization list is not one supply problem
Takeaway: Randomization assigns participants to arms; supply management moves kits through countries, depots and visits. The registry stores the design summary of the first problem and almost nothing about the second — the unit error is treating one as the other.
Start with the registry's own definitions, because the words get used loosely. ClinicalTrials.gov defines allocation as "a method used to assign participants to an arm of a clinical study," with randomized and nonrandomized as the types. An arm is "a group or subgroup of participants in a clinical trial that receives a specific intervention/treatment, or no intervention, according to the trial's protocol." Masking is "a clinical trial design strategy in which one or more parties involved in the trial … do not know which participants have been assigned which interventions," with roles — participant, care provider, investigator, outcomes assessor — selected per study. Enrollment is the number of participants, estimated as the target [4].
Every one of those definitions describes the design. None of them describes a depot, a kit label, a re-supply trigger or an import license. That gap is the subject of this paper.
What connects the two worlds is a clause in ICH E6(R3), the GCP guideline adopted by ICH on 6 January 2025 and applicable in the EU from 23 July 2025, with Annex 2 following on 15 January 2027 [1][2]. Under investigational product management, responsibility for accountability, handling, dispensing, administration and return "rests with the investigator/institution" — but the sponsor "may facilitate aspects of investigational product management (e.g., by providing forms and technical solutions, such as computerised systems, and arranging distribution of investigational product to trial participants)" [1]. That parenthetical is the regulatory birth certificate of every RTSM/IRT system: the sponsor's technical solution for getting the right blinded kit to the right participant. FDA adopted E6(R3) as guidance for industry in September 2025, so the same text now anchors both regions [3].
The record-keeping duty lands in the same section: investigational product records should include "dates, quantities, batch/serial numbers, expiration dates … and the unique code numbers assigned to the investigational product(s) and trial participants" [1]. Read that list again from the supply side. Dates and quantities are inventory. Batch and serial numbers are release and recall. Expiry dates are shelf-life management. Unique code numbers linking product to participant are the randomization cross-reference. One sentence of GCP quietly enumerates the object model of a trial-supply system:
| GCP record field (E6(R3) §2.10.4) | The supply object it names |
|---|---|
| Dates | Receipt, dispensing and return events — the transaction ledger |
| Quantities | Inventory balance per site and depot |
| Batch/serial numbers | Release status, recall scope, QC linkage |
| Expiration dates | Shelf-life rotation, first-expiry-first-out picking |
| Unique code numbers (product × participant) | The randomization cross-reference — allocation ↔ kit |
ICH E6(R3), §2.10.4, read as a data model — EClinCloud analysis [1].
A supply-control problem exists when those objects stop being a log and start being a control loop: when the kit a participant receives next depends on their arm, visit, country and remaining shelf life — decided by a system, within a blind, across borders. That is the difference this paper measures.
So the grain warning before any number is quoted: a ClinicalTrials.gov record is a protocol summary, not a configuration file [4][5]. It tells you the design's shape — and the design's shape is exactly what predicts whether supply is a line item or a subsystem. That is why this paper can answer a configuration question from registry data without ever claiming the registry shows the configuration itself.
The four multipliers and their real distributions
Takeaway: Registered design groups, reported countries, masking and enrollment are useful complexity flags. They are not direct supply objects: design groups are not kits, countries are not depots or languages, enrollment is not demand, and a masking enum is not the blinding specification.
ICH E8(R1) supplies the frame: quality by design means "the quality of a study is driven proactively by designing quality into the study protocol and processes," through an approach "proportionate to the risks involved" [7]. Supply configuration is a textbook case: the process should be proportionate to the multiplier load, and the multiplier load is measurable before study start.
On 125,076 interventional drug studies with randomized allocation [5][6]:
Registered design groups. Median 2, p75 = 3, p90 = 4, p99 = 9, max 63, mean 2.47. 17,414 studies (13.9%) have four or more groups, while 8,024 have none recorded. A design-group count can signal allocation complexity, but it is not a kit-type lower bound: several groups may share supply, while one group may require multiple strengths, visit packs or titration kits.
Reported countries. Median 1, p75 = 1, p90 = 3, p99 = 23, max 57, mean 2.02 when missing values are retained as zero in the distribution. 93,953 studies (75.1%) report exactly one country, 10,788 (8.6%) report five or more, and 12,604 report none. Country is neither site, depot, import path nor language; it is a prompt to build those separate matrices from the protocol and logistics plan.
Masking. NONE 40,123 (32.1%); DOUBLE 28,926 (23.1%); QUADRUPLE 28,366 (22.7%); TRIPLE 15,352 (12.3%); SINGLE 11,560 (9.2%); 749 blank. Two-thirds of the cohort is registered as masked to some degree. That base rate justifies asking about indistinguishability, code access and emergency unblinding; the label alone does not answer any of those questions.
Enrollment. Phase 2/3 subset (n = 66,085): median 120, p75 = 300, p90 = 616, p99 = 3,154, max 357,716. Enrollment is the multiplier that converts every other multiplier into quantity: arms × visits × subjects is the kit-demand matrix, and overage is priced against it.
Two reading rules for these distributions. First, quote percentiles, not means: the arm mean (2.47) and country mean (2.02) sit far above their medians because a long tail drags them — a supply plan sized to the mean serves almost nobody, and one sized to the median is surprised by every tenth study. Second, the p99 is a planning boundary, not an anecdote: 1,250 studies run in 23 or more countries, and roughly 1,250 have 9 or more arms — those are real procurement conversations happening this year, not theoretical maxima. The maxima (63 arms, 57 countries) are the objects that force randomization and artwork systems to share one source of truth.
A third rule for the buyers in the room: read the mean as a market statement, never as a study plan. The country mean of 2.02 across all randomized drug trials describes the population of trials, in which the single-country majority dominates the denominator; it does not describe the experience of any sponsor portfolio, where late-phase programs concentrate in exactly the tail that pulls the mean up. When a vendor sizes a system, a CRO quotes a service line, or a platform team plans capacity, the population mean is the honest base rate; when a study team configures a protocol, the study's own three fields are the only number that matters. Keeping the two readings apart — base rates for markets, own-fields for protocols — is what keeps this kind of distribution analysis from being misquoted in either direction.
Registered masking on 125,076 randomized drug trials
67.3% carry a masking code other than NONE. Masking is a useful triage flag because it can affect packaging, code access and emergency unblinding, but the registry does not reveal whether comparator matching, kit-level blinding or a particular RTSM configuration is required. BLANK denotes 749 unrecorded values.
The flags can co-occur, but their operational effect is study-specific. A two-group, one-country, open-label record can still describe many sites, frequent visits, short shelf life, temperature-controlled supply and several dose strengths. A four-group, seven-country, double-masked record deserves deeper review, but it does not tell us how many kits, label variants, import paths or depots exist. The bands are therefore a triage map:
| Band (registered design groups × reported countries) | Studies | Share |
|---|---|---|
| 2 groups × 1 country | 62,979 | 50.4% |
| 2 groups × 2–4 countries | 4,270 | 3.4% |
| 2 groups × 5+ countries | 5,755 | 4.6% |
| 3 groups × 1 country | 12,952 | 10.4% |
| 2 groups × country not recorded | 7,612 | 6.1% |
| 3 groups × 2–4 countries | 1,199 | 1.0% |
| 3 groups × 5+ countries | 2,049 | 1.6% |
| 4+ groups × 1 country | 11,943 | 9.5% |
| 3 groups × country not recorded | 1,815 | 1.5% |
| 4+ groups × 2–4 countries | 1,591 | 1.3% |
| 4+ groups × 5+ countries | 2,363 | 1.9% |
| Under 2 groups × 1 country | 6,079 | 4.9% |
| 4+ groups × country not recorded | 1,517 | 1.2% |
| Under 2 groups × 2–4 countries | 671 | 0.5% |
| Under 2 groups × 5+ countries | 621 | 0.5% |
| Under 2 groups × country not recorded | 1,660 | 1.3% |
ClinicalTrials.gov / AACT, randomized drug interventional studies, n = 125,076 — EClinCloud analysis, accessed August 2026 [5][6].
Registered design groups × reported-country bands
Exactly two design groups and one reported country is the largest observed cell (62,979 studies; 50.4%). These fields are early complexity flags, not kit counts or an RTSM prescription. Country is unrecorded for 12,604 studies, and 8,024 have no registered design group, so missingness must remain visible in any portfolio screen.
Read the table as a portfolio-screening map, not a workload or purchasing map. The largest cell provides a base rate; the high-group and multi-country cells justify opening the protocol, pharmacy manual and supply plan. Among phase 2/3 drug studies the reported-country median is 1, p90 is 8 and p99 is 27 [6], which makes early cross-border review particularly valuable without implying that every late-phase study has the same supply architecture.
The simple half — and what it still owes
Takeaway: 62,979 studies — 50.4% of the cohort — have two registered design groups and one reported country. That is a lower-complexity registry flag, not evidence that randomization plus a manual accountability log is sufficient. The protocol-level screen below decides whether the apparent simplicity is real.
The lower-flag cohort deserves its own section because public fields can conceal operational complexity. Before choosing a light configuration, confirm at least: site and pharmacy count; visit and dosing schedule; number of physical presentations; shelf life and retest strategy; temperature conditions; enrollment uncertainty; shipment lead times; depot topology; direct-to-patient or home-health flows; import/release requirements; masking method; emergency-unblinding path; and the consequence of a stock-out. Only after that review can the team decide whether manual controls, IRT without automated supply, or an integrated RTSM control loop is proportionate.
Accountability at the site. The investigator holds responsibility for IP accountability, handling, dispensing and return [1]; the US investigational-drug regulation requires records of disposition — dates, quantities and use [8]. Whether a controlled log is sufficient depends on transaction volume, number of locations, reconciliation latency, integrations and error consequence; the registry does not answer those questions.
Distribution topology. One reported country does not mean one depot, one import path or one storage location. A domestic study may have central and local pharmacies, direct-to-site or direct-to-patient lanes, multiple release points and many temperature-controlled shipments. The supply plan must name who confirms receipt, reconciles balances, assesses excursions, authorizes quarantine/release and controls return or destruction. E6(R3)'s traceability language applies regardless of the topology [1].
Expiry discipline requires the team to model visit windows, batch expiry, release timing and the last participant's expected dosing horizon. A one-page check may be sufficient only where demand and replenishment are stable; otherwise scenario forecasting and exception controls are needed.
Blinding controls, if masked. Within this cohort, 40,940 of 62,979 studies (65.0%) carry a masking code other than NONE [6]. The physical presentations may or may not map one-to-one to design groups, but the study still needs documented indistinguishability controls where applicable and a participant-specific emergency-unblinding path. The protocol, pharmacy manual and packaging specification—not the enum—define those controls.
A tested unblinding path. E6(R3) §3.15.3 requires, for blinded trials, a procedure and mechanism for rapid participant-level identification in a medical emergency while protecting other assignments; §2.11 adds readiness to unblind without undue delay [1]. The mechanism may be physical or electronic, but access, availability, testing, escalation and documentation must match the study's risk.
The planning error is treating a low registry flag as zero work. Accountability, labelling, expiry, exception handling and unblinding still need named controls and owners.
For a genuinely low-complexity study, a concise supply-control plan may be proportionate. It should still document presentations and quantities; distribution lanes and receipt; accountability owner and reconciliation timing; expiry and excursion handling; blinding controls if applicable; and the emergency-unblinding procedure. The conclusion that this is sufficient must come from the study-specific risk assessment, not membership in the 50.4% registry cell.
An illustrative high-complexity flag cohort
Takeaway: Double-masked × ≥3 registered design groups × ≥2 reported countries selects 1,786 studies—1.4% of the cohort and 96.5% industry-sponsored. This is a useful high-priority review queue, not a validated population of studies that all require the same supply-control model.
We use the conjunction because it collects records with several plausible complexity signals: masking, multiple design groups and cross-border execution. The definition is deliberately illustrative. It was not trained against stock-outs, wastage, expiry loss, protocol deviations or actual RTSM configurations—none of which is available in the registry.
| Measure | Phase 2/3 randomized drug (n = 66,085) | Illustrative flag cohort (n = 1,786) |
|---|---|---|
| Arms, median | 2 | 4 |
| Arms, p90 | 4 | 6 |
| Countries, median | 1 | 7 |
| Countries, p90 | 8 | 19 |
| Countries, max | 57 | 51 |
| Enrollment, median | 120 | 267 |
| Enrollment, p90 | 616 | 1,040 |
| Industry-sponsored share | 48.9% | 96.5% |
ClinicalTrials.gov / AACT — EClinCloud analysis, accessed August 2026 [5][6].
Illustrative high-complexity registry flags versus the broader cohort
Double-masked studies with at least three registered design groups and two reported countries form an illustrative 1,786-study flag cohort. Its profile supports deeper protocol-level review; it does not establish that every member needs full RTSM supply control or that studies outside it do not.
| Measure | Phase 2/3 randomized drug (n = 66,085) | Illustrative flag cohort (n = 1,786) |
|---|---|---|
| Design groups, median | 2 | 4 |
| Design groups, p90 | 4 | 6 |
| Reported countries, median | 1 | 7 |
| Reported countries, p90 | 8 | 19 |
| Reported countries, max | 57 | 51 |
| Enrollment, median | 120 | 267 |
| Enrollment, p90 | 616 | 1,040 |
| Industry-sponsored | 48.9% | 96.5% |
The profile is clearly more complex on the observed fields: median four groups, seven reported countries and enrollment 267. But none converts mechanically into kit count, label count, depot count or a failure threshold for manual work. It tells the reviewer where to ask for the dose/visit matrix, country activation plan, packaging strategy, depot and import lanes, shelf-life assumptions, enrollment forecast and resupply service levels.
Phase mix: 786 phase 2, 668 phase 3, 178 phase 1, 60 phase 2/3, 50 phase 1/2, 41 phase 4. This is late-phase-weighted but not late-phase-exclusive — 228 phase 1 or phase 1/2 studies already sit in the cohort, which answers a recurring question from operations teams: yes, some first-in-human designs genuinely need supply governance, because multi-part dose-escalation designs with masked comparators create the same kit matrix a Phase 3 does, at smaller scale.
Sponsorship is descriptive: 1,723 of 1,786 (96.5%) are industry. It does not show what systems those sponsors used, what competitors regard as standard, or the size of the RTSM market. The useful implication is narrower: an industry-heavy review queue should be evaluated against sponsor operating model, portfolio reuse, integrations and validation burden—not only per-study license cost.
For procurement, use the cohort only to prioritize evidence collection. Request an architecture that traces each control requirement to a study fact; challenge features that lack a named failure mode; and test whether manual, service-based or automated controls can meet the required response time. Industry sponsorship and median enrollment are not substitutes for that requirements traceability.
A useful boundary warning: 1,786 is not a cliff edge, score threshold or causal class. A two-group, twelve-country vaccine trial may demand more logistics control than a four-group study served from one stable regional chain; a single-country titration trial may have more presentations than its group count suggests. Border cases expose why registry-derived tiers must not become purchasing rules.
Border cases deserve explicit review. A two-group, twelve-country, double-masked vaccine trial sits outside the flag cohort but may have demanding import, packaging, seasonal-enrollment and emergency-unblinding controls. A six-group, one-country dose-finding study may have a large presentation matrix without cross-border logistics. Neither can be configured from the registry row alone; both should proceed through the protocol-level decision record below.
Why each multiplier binds
Takeaway: Each registry flag opens a specific line of inquiry. Countries prompt logistics and labelling review; design groups prompt a presentation-and-visit matrix; masking prompts physical-blinding and code-governance review; enrollment prompts demand and capacity scenarios. The obligation depends on the verified study facts, not the flag itself.
Countries prompt logistics and law review. The EU regulation makes the label-language question explicit: under Regulation (EU) No 536/2014, the language of label information "shall be determined by the Member State concerned," while multi-language labelling is permitted (Article 69), and Annex VI enumerates particulars [9]. A seven-country EU trial therefore requires seven Member-State determinations—not necessarily seven languages or packaging runs. Outside the EU, route-specific import, release and distribution requirements must be confirmed. Article 51(1) supplies the common traceability duty: investigational medicinal products must be traceable and appropriately stored, returned or destroyed [9].
Each confirmed lane also has a clock: import authorization, release, quarantine, shipment and site receipt may gate availability. The lead times and responsible actors must be mapped per route. A nineteen-country study is a strong reason to evaluate consolidated visibility and automated control, but country count alone does not prove the number of lanes or the required system.
Depot topology changes lead time, customs/release events, buffer placement, transfer governance and reconciliation. Candidate designs include central, regional and national-pharmacy models, but no country-count rule selects among them. Compare topologies using confirmed routes, enrollment tempo, product temperature/stability, service levels, cost and recovery scenarios, and revisit the choice as country activation changes [9].
Design groups prompt the presentation-and-visit matrix. A group is a participant assignment category, not a kit. Groups can share presentations, and a single group can require several strengths, titration steps, rescue products or visit-specific packs. The operational input is a matrix of treatment group × visit × dose/strength × presentation × country availability × shelf life. The registry count helps prioritize that work; it neither understates nor lower-bounds kit types in a consistent way.
The presentation matrix is where randomization and supply may need to couple. If an assignment can be executed only when an eligible presentation is available at the dispensing location, allocation logic and live inventory need a controlled interface. Whether that requires one integrated system, validated interfaces or a tightly governed service model depends on response time, exception volume and validation requirements.
Masking prompts packaging and code-governance review. Where the investigational products themselves are blinded, Annex VI requires the applicable comparator/placebo naming on both packages, and Article 2(2)(24) includes blinding within packaging and labelling as a manufacturing operation [9]. Other masking designs—for example an independent outcomes assessor—may rely more on role separation and access controls. The protocol roles and actual product presentations therefore determine the physical solution. E6(R3) requires coding/labelling that protects the blind plus processes for inappropriate and emergency unblinding [1]. FDA's electronic-systems guidance covers randomization, product dispensation/accountability and audit-trail information for unblinding [10]. The EMA computerized-systems guideline places IRT within controlled electronic-system expectations [11].
Enrollment prompts demand, overage and expiry scenarios. Enrollment forecasts influence manufacturing overage, site/depot buffers and replenishment. Peterson and colleagues' 2004 simulation compared computer-controlled supply management with traditional forecasting and found better modeled demand coverage at lower overage in its scenarios [12]. That result supports testing responsive logic; it does not prove savings for every protocol or vendor. Expiry, batch release and route lead time can reverse the preferred model. E6(R3) includes expiration and batch information in the required product records [1]. A 2026 failure-mode analysis identified 44 investigational-product-management failure modes, 31 classified high-risk in that setting [13]. Use sponsor-owned scenarios and observed operating data to choose the controls.
The automation layer has an evidence base. Site-interface work found a strong preference for web over telephone IVR in one surveyed setting [14], while integration papers examine the seam between randomization systems and EDC [15]. In the 101,685-record eClinical literature union, 479 records match a fixed trial-supply/IRT query, with 34–57 matches per year through the 2020s [16]. That count is a discovery aid—not a market-size estimate, adoption measure or validation of the illustrative 1.4% flag cohort.
Records matching trial-supply or IRT language, 2010–2026
A fixed text query matches 479 records in the 101,685-record eClinical literature union. This is a literature-discovery signal, not a market-size estimate and not evidence that only a particular registry cohort uses IRT. 2026 is a partial year.
The EU contrast: a descriptive cross-register signal
Takeaway: Public CTIS records are more concentrated in multi-country trials than this ClinicalTrials.gov cohort. Different jurisdictions, inclusion rules, submission systems and study populations prevent a causal reading. Use the contrast to prioritize early EU/EEA country planning, not to assume a multinational architecture for every trial.
On 12,123 public trials in the Clinical Trials Information System (30 July 2026 snapshot): countries per trial median 1, mean 3.18, p75 = 4, p90 = 8, p99 = 16, max 25. 5,336 trials (44.0%) run in two or more countries; 2,873 (23.7%) in five or more [17].
Reported countries per trial: ClinicalTrials.gov versus CTIS
Public CTIS records are more concentrated in multi-country studies than this ClinicalTrials.gov cohort. The two registries cover different jurisdictions, submission regimes and study populations, so the contrast is a portfolio-planning prompt—not proof that the EU framework caused multinational design or that every EU trial needs a particular supply architecture.
Compared with the ClinicalTrials.gov cohort (median 1, p75 1, p90 3), CTIS has the same median but higher upper percentiles. The data do not isolate the effect of the single-application procedure from jurisdiction, transition history, public-availability rules, sponsor mix or trial type, so no causal claim is warranted.
The operational consequence is a planning checklist, not a fixed architecture. For each concerned Member State, confirm the accepted label language(s), Annex VI particulars, release/import route, distribution model and activation timing. Multi-language labelling or shared depots may consolidate work; country-specific requirements may separate it. The authorized country strategy and supply design must remain synchronized through amendments.
The EU also has distinct labelling routes. Authorized IMPs may use the commercial-labelling route with additional trial particulars when the protocol circumstances require them. Articles 66 and 67 do not apply to diagnostic radiopharmaceutical IMPs/auxiliary products, but Article 68 still requires appropriate labelling for subject safety and data reliability [9]. Each route is a protocol- and product-specific determination that can change packaging workload.
The traceability duty also tightens in the EU frame: Article 51(1)'s "stored, returned and/or destroyed as appropriate" is enforced through Member-State inspections under the CTR's GCP regime, and the 2023 EMA computerised-systems guideline puts the IRT that tracks it in scope [9][11].
The configuration framework: three review levels, then a control decision
Takeaway: Registry fields place studies into review queues, not system tiers. The team then verifies protocol and supply facts, names the failure modes and selects the least burdensome controls that meet required response times and traceability.
The framework below converts the distributions into a Monday-morning triage while preventing false precision. A high registry flag raises review priority; it does not force software. A low flag permits a lighter initial review; it does not pre-approve spreadsheets.
| Review level | Registry trigger | What must be verified | Decision output |
|---|---|---|---|
| A — Baseline review | Any randomized drug study | Presentations, visits/doses, sites/pharmacies, shelf life, storage, accountability and unblinding | Documented manual, service or system controls with owners and reconciliation timing |
| B — Expanded review | Multiple countries/groups, masking, high or uncertain demand, short shelf life, cold chain or decentralized supply | Level A plus route/import/release matrix, label strategy, depot topology, scenario demand and recovery time | Requirements traceability and make/buy/configure decision |
| C — Integrated-control review | Several verified risks interact or a failure cannot be recovered within the required time | Live allocation-inventory coupling, resupply trigger logic, access roles, audit trails, integrations, exception handling and validation | Validated RTSM/IRT architecture or an equivalently controlled operating model |
The 62,979 lower-flag records and 1,786 high-flag records calibrate review priority only. We do not publish a middle-population count because overlapping flags, missing fields and protocol variables prevent a valid subtraction-based tier estimate [5][6].
Three reading rules keep the framework honest.
Rule 1: no conjunction assigns the solution. The 1,786-study definition identifies co-occurring public flags, not an outcome-validated class. One severe constraint—such as ultra-short shelf life or an unrecoverable seasonal enrollment window—can justify integrated control even when the other flags are absent.
Rule 2: masking is read from the protocol and packaging strategy. Registry roles identify intended masked parties [4]; they do not specify physical indistinguishability, code custodians, system permissions or emergency workflow. Trace those requirements separately.
Rule 3: demand can change architecture. Enrollment level, rate uncertainty, visits, dose changes, shelf life and replenishment time jointly determine whether periodic manual forecasting remains safe. A large single-country study may need automation; a small multinational study may use tightly governed service-based controls.
Three worked examples show the framework deciding.
Example 1. A two-group, one-country, open-label Phase 2 in oncology, 80 participants. Start at Level A. If the protocol confirms one stable presentation, predictable visits, adequate shelf life, a simple distribution path and recoverable exceptions, documented manual or service controls may be proportionate. The registry alone cannot reach that conclusion.
Example 2. A two-group, double-masked vaccine efficacy trial in nine countries, 4,000 participants. Begin at Level B and test escalation to Level C. Confirm Member-State language determinations, depot/import routes, seasonal recovery time, physical blinding and the emergency path. Do not assume nine languages, regional depots or that a kit-matrix function is unnecessary until those facts are verified.
Example 3. A four-group, double-masked Phase 3 in twelve countries with titration, 1,040 participants. This warrants a Level C review, not an automatic product purchase. Build the actual presentation/visit matrix, route and label matrix, demand scenarios, exception recovery targets, permissions and integration requirements; then compare a validated RTSM architecture with any proposed service-based alternative.
Example 4 — the operating-model case. An academic cooperative runs a three-group, double-masked, six-country trial in a niche indication with 180 participants. The flags justify an integrated-control review, but the result may be a CRO IRT, a network platform or a deliberately scoped service model. Sponsor type does not change GCP responsibilities; it changes available infrastructure, validation capability and oversight arrangements [1].
What the framework deliberately does not say is which vendor, product or module to buy. Visit-driven forecasting can be a platform function, CRO service or controlled process. The budget decision should compare those operating models against documented requirements, failure recovery time, auditability, validation, integration and lifecycle cost—not against a registry threshold.
The supply-control decision record
The framework becomes useful when it produces one approved decision record. The record should begin with evidence, not a preferred product: protocol version; randomization design and masking roles; physical presentations by visit and dose; planned sites and dispensing locations; country activation sequence; manufacturing batches, release dates and shelf life; storage conditions; shipment lanes and lead times; enrollment scenarios; dropout and replacement assumptions; and emergency-unblinding requirements. Every input needs a source document, owner, effective date and confidence level. "Country count = 7" is weak input; "Poland sites are served from depot X, released by role Y, with Z-day replenishment under the current import route" is a usable one.
Next, write failure modes in operational language. Examples include: a participant cannot receive an eligible presentation at the scheduled visit; a shipment arrives after the acceptable dosing window; an expiring batch becomes stranded in the wrong location; a resupply rule reveals treatment allocation; an emergency user cannot obtain the code; a new country is activated before labels and release status are aligned; or the EDC–RTSM interface repeats or misses a visit event. For each failure, record severity, detectability, recovery time and the latest point at which a manual intervention can still protect the participant and protocol. That turns "complexity" into a control requirement.
Then compare operating models. A manual or service-based model should demonstrate its transaction volume, review frequency, segregation of duties, version control, reconciliation latency, holiday/after-hours coverage and exception escalation. A configurable RTSM model should demonstrate the same controls plus role permissions, audit trails, resupply logic, integration behavior, validation and controlled change. The comparison is not software versus no software; it is whether each proposed model can meet the same documented service and evidence requirements.
The approval page can stay compact:
| Decision-record field | Minimum content |
|---|---|
| Scope and source | Protocol/version, countries/sites, presentations, visits, enrollment scenarios and supply documents |
| Critical failure modes | Participant, blind, product-quality, timeline and data-integrity consequences |
| Required controls | Preventive/detective control, owner, response time, backup and evidence produced |
| Options compared | Manual, CRO/service, IRT/RTSM and integrations, using the same requirements |
| Residual risk | Accepted exception, rationale, approver and planned monitoring |
| Change triggers | Country/site, group/dose, visit, product, shelf-life, masking, integration or vendor change |
Vendor diligence and acceptance testing
Feature lists are poor evidence. Turn the approved record into scenario demonstrations and acceptance tests. Ask the vendor or service team to execute a late country activation, constrained inventory at one site, a quarantined batch, an expiry extension, a participant-specific emergency unblinding, a replacement kit, a failed interface message, a corrected visit and a depot outage. Observe which role can act, what the blind reveals, whether duplicate transactions are prevented, what alert is generated, what audit evidence remains and how reconciliation occurs.
Forecasting claims deserve the same discipline. Require the model's inputs, refresh timing, safety-stock logic, treatment of missing/late visits, handling of recruitment shocks and rules for manual override. Compare outputs against sponsor-owned scenarios, including a slow-enrollment downside, rapid-enrollment upside, site concentration, delayed batch release and a lane closure. A lower simulated overage is not a valid benefit if the model raises stock-out risk or assumes lead times the logistics plan cannot achieve. The Peterson simulation literature establishes that responsive control can outperform static planning in modeled settings, not that any vendor algorithm will do so in this study [12].
Finally, test lifecycle control. Protocol amendments, added countries or groups, new packaging batches, expiry updates and integration releases can all change allocation or supply behavior. The acceptance package should show requirements traceability, configuration review, test evidence, migration/reconciliation, training, deployment approval and rollback. FDA and EMA electronic-systems guidance make electronic integrity and controlled operation relevant to the systems in this space [10][11]; the study team still has to decide which changes are critical and what regression evidence is proportionate.
The output of diligence is a signed fit decision with open risks—not a vendor score detached from the protocol. It should remain linked to the supply-control record so that an amendment automatically reopens the affected requirements and tests.
Cutover, reconciliation and service acceptance
A system can pass configuration testing and still fail at operational cutover. Build the go-live decision around complete business cycles, not screens. Create a test participant through the approved source, randomize under every applicable stratum and blocking condition, dispense each eligible presentation, process a missed/rescheduled visit, replace or quarantine supply, receive and reconcile shipments, update expiry where allowed, execute emergency unblinding under controlled roles and close accountability. Include negative tests: an ineligible participant, exhausted stratum, unavailable kit, duplicate message, stale interface event and unauthorized user.
Reconcile each cycle across its authoritative systems. The randomization list/specification, RTSM transaction, EDC subject/visit event, depot inventory, shipment record and accountability record should agree on identifiers, status, timestamps and version. Define which system is authoritative for participant status, visit eligibility, inventory disposition, expiry and unblinding; then define how conflicts stop or proceed. An integration that retries silently without idempotency can create duplicate visits or allocations, while an integration that fails closed without an after-hours path can delay treatment. Both behaviors require explicit acceptance criteria.
Operational readiness needs people and clocks. Confirm named 24/7 or protocol-matched support coverage, severity definitions, response and recovery targets, country/site escalation, blind-protected troubleshooting and sponsor visibility. Test a real escalation outside the implementation team's working hours. For each critical scenario, preserve the ticket, role/actions, timestamps, audit trail, reconciliation and closure approval. Service-level language is useful only when its measurement starts at an observable event and the remedy protects the participant and trial—not merely when the vendor acknowledges an email.
Before go-live, establish inventory baselines at depots and sites and reconcile all imported/migrated participants, assignments, kits, batches, expiries and statuses. Migration sampling should be risk-based and supplemented by control totals and exception reports; a row count alone cannot show a shifted treatment assignment or invalid kit state. Freeze old transactions at a defined point, record any dual-running rules, approve cutover and retain a rollback or contingency path that does not expose the blind.
Post-go-live review should focus on whether the operating model meets the decision record. Useful measures include randomizations/dispensations reconciled, stock-outs and near misses, shipments outside target, inventory in quarantine or nearing expiry, manual overrides, failed/replayed interface messages, unblinding events by authorized reason, open high-severity incidents and configuration changes with completed regression evidence. Denominators and aging matter: "five alerts" is uninterpretable without transaction volume and closure status.
Do not equate a low stock-out count with efficient supply. A design can suppress stock-outs through excessive overage, and it can reduce overage while creating fragile recovery. Evaluate service, waste and risk together: participant visits served within window, recoverable inventory coverage by verified route/lead time, expiry/destruction, emergency transfers, shipment cost, site burden and exception labor. Definitions belong to the sponsor's plan; public registry data supplies none of these outcomes [5].
Finally, schedule a control review after early enrollment and before major expansion. Compare actual enrollment, discontinuation, visit timing, demand, lead times, release dates and wastage with the approved scenarios. Reforecast and change rules through controlled approval where assumptions break. Adding countries, groups, strengths or visits; changing shelf life, depot routes, randomization or integration; and replacing a vendor all reopen affected requirements. The review protects against the most common lifecycle error: treating the configuration approved before first patient as permanently correct for a protocol that continues to change.
The same review should test manual workarounds. Extract overrides, emergency shipments, inventory adjustments, forced assignments, support interventions and reconciliations; sample the highest-risk transactions back to approval and audit evidence. A workaround can be proportionate during a short disruption, but repeated use may mean the configured rule, route assumption or service capacity is wrong. Set an owner and expiry for every temporary control, then verify removal or formal incorporation through change control.
At closeout, reconcile unused, returned, quarantined, destroyed and lost supply to batches and assignments; close open interface and unblinding exceptions; archive the randomization specification/list under controlled access; and preserve enough configuration and audit evidence to reproduce participant-level decisions. Capture forecast-versus-actual enrollment, shipments, stock-outs, expiry and manual effort using sponsor-defined metrics. Those study outcomes—not the public registry flags—are the evidence that can improve assumptions for the next protocol.
Compare lifecycle cost without inventing an ROI
Price the operating models against the same requirements and scenarios. Separate implementation/configuration; validation and sponsor acceptance; licenses or transaction/site fees; integrations; depot/site/logistics work; support; change orders; training; reconciliation; closeout and archival. For a manual or service model, include sponsor/CRO labor, segregation-of-duties review, out-of-hours coverage, error investigation and the effort to maintain controlled spreadsheets or lists. Do not price software while treating manual control as free.
Model cost drivers as ranges tied to protocol facts. Relevant quantities include participants, visits and randomizations; sites/dispensing locations; countries/routes/depots; presentations and batches; shipments; users/roles; integrations; amendments; support window and trial duration. Then vary enrollment rate, country activation, shelf life, batch release and lane disruption. The registry distributions can show that these inputs vary widely, but they cannot supply vendor prices, labor hours, stock-out probabilities or expected wastage [5][6].
Evaluate economic and quality outcomes together. Candidate measures include total product manufactured and released; units shipped, expired, transferred and destroyed; shipments and urgent shipments; participant visits served within the protocol window; stock-outs/near misses; manual transactions and reconciliations; configuration changes; critical incidents; and sponsor/vendor effort. Define each measure prospectively and preserve denominators. A lower drug overage is not a saving if it increases urgent freight, missed dosing or uncompensated operational burden.
Make the decision transparent with three views. The base case uses approved assumptions. Stress cases test rapid/slow enrollment, delayed release, short shelf life, concentration at a few sites and route outage. A break-even view identifies which input—transaction volume, change frequency, product value, lead time or labor—would change the preferred operating model. Do not publish a percentage ROI unless the sponsor has auditable price and performance data for both alternatives.
Contract structure should follow the risk allocation. Define what is included in initial build, amendments, integrations, environments, validation evidence, after-hours support, data exports, migration and closeout; which events trigger fees; service credits or remedies; and how transition assistance is priced. Require exportability of configuration, transaction/audit history, randomization evidence and inventory status. A superficially cheap model can become expensive if every protocol change is an opaque change order or if exit requires rebuilding the evidence trail.
What no registry field will tell you
Takeaway: Registry fields identify the cohort; they do not describe the supply system. Depot counts, resupply cadence, overage rates and unblinding-log design are invisible, and nothing in this paper licenses a claim from registry data about any trial's operational quality.
The boundaries of this analysis are the boundaries of the register, and they need to be said plainly.
Registry arm counts are design groups, not kit types. A two-arm study with three dose levels runs more kit types than a four-arm study with shared packaging. The registry cannot see dose variants, titration steps or factorial run-splits; arm counts are the floor, not the ceiling.
Country counts are not depot counts, site counts or import paths. The register lists countries where the trial happens, not how supply reaches them — central pharmacy versus direct-to-site, one EU depot versus three regional depots, and which countries are served cross-border.
The masking enum is not the masking role list in AACT extract form, and neither is the protocol's actual blinding architecture. Two studies both coded DOUBLE can differ in whether the assessor is masked, whether supplies are identical in weight and texture, and whether emergency unblinding is an envelope or a system permission. The role list exists in the registry record; our extract works at enum grain, and the article has quoted it at that grain deliberately.
Most fundamentally: nothing in this dataset measures whether a trial's supply actually performed. No stock-out, expiry-loss, overage-percentage or unblinding-event field exists in the analyzed public records. A high-flag study may have immaculate controls or poor ones; a low-flag study may still carry severe product or distribution risk. The register prioritizes questions and never certifies the response.
What would close the gap is protocol- and depot-level data — the layer that lives in TMF reference manuals, IP manufacturing documentation and vendor audit reports, none of it public. For a specific study, three documents answer what the registry cannot: the pharmacy manual (depot structure, resupply triggers, quarantine paths), the IP manufacturing and packaging plan (kit architecture, batch strategy, blinding method), and the randomization specification (allocation logic, blocking, emergency-unblinding design). An operations lead who wants to apply the tier framework to a live protocol should read those three against the tier obligations — that is the intended workflow, and the registry numbers here are the calibration, not the verdict. The cross-registry identity paper (24 August 2026) maps the adjacent problem of joining public registers; the supply layer underneath has no public mirror at all.
Frequently asked questions
When is randomization configuration alone enough?
Only after protocol-level review confirms stable presentations and demand, adequate shelf life, a simple and recoverable distribution model, proportionate accountability volume and a tested unblinding path where applicable. Two groups and one reported country is a screening flag, not sufficient evidence [1][8].
How many countries before we need depot and resupply logic?
There is no evidence-based country threshold. A second country triggers a new jurisdiction review, but shared languages, depots and routes may consolidate work while product-specific import or release rules may intensify it. Decide from the confirmed route matrix, shipment lead time, demand uncertainty and recovery target—not from 2, 5 or 10 countries [9].
Does every masked trial need identical blinded packaging?
No. The supply and its coding/labelling must protect the study's intended masking, but the physical solution depends on which parties are masked and how the products differ. A participant- and investigator-masked comparator study may require matching, over-encapsulation or double-dummy controls; an outcomes-assessor-only mask may rely mainly on role separation and access controls. Read the protocol roles and product presentation before designing packaging [1][9].
What does emergency unblinding governance actually require?
Three things are central: rapid participant-level identification in a medical emergency, protection of other assignments, and appropriate integrity/auditability for electronic unblinding information [1][10]. Select and test the mechanism against availability, access, escalation and documentation requirements; do not assign it from a tier label.
Do Phase 1 studies need RTSM?
Phase is not the trigger. Dose escalation, sentinel dosing, cohort decisions, multiple strengths, short stability, masking and rapid configuration changes can create substantial RTSM requirements at small enrollment. The 178 phase 1 and 50 phase 1/2 records in the illustrative flag cohort show that early phase appears in the review queue; they do not prove the actual supply configuration.
Is the EU configuration different?
EU planning must confirm Member-State label-language determinations, Annex VI particulars and applicable import/release/distribution routes [9]. CTIS records are more multi-country than the comparison cohort [17], but the cross-register difference is descriptive and does not justify a default system tier.
What does an RTSM system own versus an EDC?
In a common architecture, RTSM/IRT handles randomization and supply transactions while EDC captures clinical data. Product boundaries vary by platform and operating model; specify ownership of each data object and transaction rather than relying on acronyms. Subject/visit data feeding supply logic creates a controlled integration surface [15].
RTSM, IRT, IVRS — are these different things?
Three words for overlapping generations of one function. IVRS (interactive voice response) named the telephone systems of the 2000s; IRT (interactive response technology) added the web interfaces that site users now strongly prefer [14]; RTSM (randomization and trial supply management) is the current name that finally says what the system does — both halves of the coupling this paper measures. In procurement documents all three still appear; the useful move is to specify by obligation (allocation logic, inventory control, resupply triggers, unblinding governance) rather than by acronym, because the acronyms carry vendor-history baggage, not functional boundaries.
Can a study need different controls mid-trial?
Yes. Country, group, dose, visit, enrollment, shelf-life, packaging or masking changes can alter requirements. Re-run the study-level risk assessment and convert the delta into controlled configuration, validation, training, inventory and rollout work. Re-deriving a tier from three registry fields is not enough.
How should we size manufacturing overage?
The public evidence base gives direction, not a universal percentage. Simulation work shows that responsive computer-controlled supply can outperform static forecasting in modeled scenarios [12], while FMEA literature maps failure modes [13]. Size overage through study-specific simulation using enrollment rate and uncertainty, randomization ratio, visits, dropout, shelf life, release/shipping lead times, minimum packs, depot topology and target stock-out risk. A percentage without that model is folklore.
Methodology and limitations
Takeaway: All figures are computed from two public registers at fixed snapshots, with denominators, filters and joins documented here — and every limitation that bounds the conclusions.
Data. ClinicalTrials.gov study records, 25 July 2026 snapshot (595,630 studies), filtered to INTERVENTIONAL studies with a DRUG value in the intervention-types field and allocation = RANDOMIZED: n = 125,076 [5]. Joined to the AACT relational copy, 1 August 2026 pipe-delimited files (designs, design_groups, countries, calculated values) for masking enums, arm counts and country rows [6]. CTIS public summary records, 30 July 2026 snapshot, 12,123 trials, country counts from the trial-countries list [17]. Literature counts: 101,685-record eClinical union of Europe PMC records, 1 August 2026, title/abstract phrase matching [16].
Computations. Group counts are distinct registered design groups per study. Country counts are non-removed country rows; zero therefore includes 12,604 records with no reported country. The illustrative flag cohort is double-masked × ≥3 groups × ≥2 reported countries. It was not validated against actual supply configurations or outcomes. Percentiles use the stated denominators; the corrected band table preserves missing-country cells rather than folding them into multi-country bands.
Limitations. Four, beyond the register boundaries stated in the limitations section: the masking extract works at enum grain (the role list is in the registry record but not in this analysis); DRUG filtering by intervention type misses trials labeled only BIOLOGICAL or another class even when supply logic may be similar; the CTIS country distribution covers only the public trials and country lists visible in the fixed extract; and literature phrase-matching is a presence measure, not a relevance classification.
What this paper is not. Not a vendor evaluation, not a compliance audit instrument, and not a source of operational performance claims about any trial or sponsor. The registry identifies the design surface; the operational response to it is documented in systems and files this analysis does not see.
Conclusion
Takeaway: Three public fields can prioritize review; they cannot size the supply machinery. The decision requires a study-level trace from protocol and product facts to failure modes, controls, owners, response times and evidence.
Three things to carry out of this paper.
The review queue is computable on Monday morning. Pull masking, design groups and reported countries to prioritize protocols. Then collect the presentation/visit matrix, distribution routes, shelf life, demand scenarios, blinding controls and exception-recovery targets. That second step—not the public cohort—supports a proportionate control decision under E8(R1) [7].
Masking remains important even in lower-flag records. Two-thirds of the cohort and 65% of the two-group/one-country cell carry a masking code. That warrants physical-blinding and emergency-access review, but neither enum depth nor country count determines the control design.
The register finds questions, never performance or product need. Use the flags to triage; use protocol evidence, simulations, validation and oversight data to decide and judge. EClinCloud RTSM and professional services can implement a requirements-driven design when the assessment supports one [18][19]. The registry analysis provides base rates; the study facts control the decision.
Sources
1. International Council for Harmonisation, E6(R3) Guideline for Good Clinical Practice, Step 4 final guideline, adopted 6 January 2025 — proportionality principles; §2.10.1 investigational product management and the sponsor's "computerised systems"; §2.10.4 IP records; §3.15.2(a) blinding-protective coding and labelling; §3.15.3 emergency unblinding; §2.11 unblinding without undue delay.
2. European Medicines Agency, ICH E6 Good clinical practice — Scientific guideline — principles and Annex 1 came into effect in the EU on 23 July 2025; Annex 2 comes into effect 15 January 2027.
3. U.S. Food and Drug Administration, E6(R3) Good Clinical Practice (GCP), guidance for industry, September 2025 — FDA adoption of ICH E6(R3).
4. U.S. National Library of Medicine, Protocol Registration Data Element Definitions for Interventional and Observational Studies — allocation, arm and arm type, masking and masking roles, intervention model, enrollment.
5. U.S. National Library of Medicine, ClinicalTrials.gov — publicly downloadable study records. EClinCloud analysis of the 25 July 2026 snapshot: 595,630 unique NCT rows filtered to 125,076 interventional drug studies with randomized allocation (study type, intervention types, allocation, phase, sponsor class, enrollment), accessed August 2026.
6. Clinical Trials Transformation Initiative, AACT Database — publicly available relational copy of ClinicalTrials.gov. EClinCloud analysis of the 1 August 2026 pipe-delimited files (designs, design_groups, countries, calculated values) joined to the 25 July 2026 study file: masking enums, arm counts, non-removed country rows, phase and enrollment percentiles, accessed August 2026.
7. International Council for Harmonisation, E8(R1) General Considerations for Clinical Studies, Step 4 final guideline, adopted 6 October 2021 — §3.1 quality by design, proportionate to the risks involved.
8. U.S. Code of Federal Regulations, 21 CFR 312.62(a) — Investigator recordkeeping and record retention — investigator disposition records for investigational drugs (dates, quantities, use).
9. European Union, Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use — Chapter X (Articles 66–70) labelling; Annex VI particulars including comparator naming in blinded trials and the emergency-unblinding contact; Article 2(2)(24) blinding as manufacturing; Article 51(1) traceability; Article 69 Member-State label languages.
10. U.S. Food and Drug Administration, Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers, guidance for industry, October 2024 — electronic systems for randomization and medical product dispensation, administration and accountability; audit-trail retention for unblinding information.
11. European Medicines Agency, Guideline on computerised systems and electronic data in clinical trials (EMA/INS/GCP/112288/2023, GCP Inspectors Working Group, 2023) — computerised-system expectations covering eCOA, IRT, CRF and audit trail.
12. Peterson M, Byrom B, Dowlman N, McEntegart D. Optimizing clinical trial supply requirements: simulation of computer-controlled supply chain management. Clinical Trials 2004;1(4):399–412 (PMID 16279278).
13. Zhang B, Song M, Wang Z, Zhou Y, Pang X. Use of failure mode and effects analysis for risk analysis of investigational drug products management in clinical trials. American Journal of Health-System Pharmacy 2026 (PMID 41208414) — 44 failure modes identified, 31 high-risk.
14. Saarela AL, Walzer A, Juppo AM. Use of telephone and web interfaces of interactive response technology at clinical investigator sites in clinical trials. Clinical Trials 2019 (PMID 30813773) — 98% of surveyed site respondents preferred the web interface.
15. Schrimpf D, Haag M, Pilz LR. Possible combinations of electronic data capture and randomization systems: principles and the realization with RANDI2 and OpenClinica. Methods of Information in Medicine 2014 (PMID 24514764).
16. Europe PMC — bibliographic database of life-science literature. EClinCloud analysis of a 101,685-record eClinical union (1 August 2026 snapshot): 479 title/abstract records matching trial-supply and IRT phrases; 34–57 per year through the 2020s, accessed August 2026.
17. European Medicines Agency, Search clinical trials and reports (CTIS public portal) — public information on EU/EEA clinical trials submitted through CTIS. EClinCloud analysis of 12,123 public summary records (30 July 2026 snapshot; trial-countries list length), accessed August 2026.
18. EClinCloud, RTSM — Randomization and Trial Supply Management — the product surface relevant to the protocol-level control decision; product scope, not a performance claim.
19. EClinCloud, Study Build professional services — protocol review, requirements/configuration and implementation support across RTSM and other study systems.