August 18, 2026

How to Handle E-Signatures for UK Clinical Trial Consent Forms

Summary · 11 min read

How to handle e-signatures for UK clinical trial consent forms: MHRA and HRA expectations, UK GCP, UK GDPR, eIDAS, audit trails, and a practical workflow.

Electronic signatures are accepted for informed consent in UK clinical trials, provided the signing process meets the same legal and Good Clinical Practice (GCP) standards as wet ink. Sponsors, CROs, and investigator sites can run fully electronic consent (e-consent) workflows, but inspectors will test identity verification, audit trails, consent versioning, and re-consent handling just as rigorously as they test paper processes. This guide explains the regulatory frame, what MHRA inspectors actually look for, a practical implementation workflow, and how to evaluate an e-signature vendor for UK trials. It is educational information, not legal advice; confirm specifics with your regulatory affairs and quality teams.

E-consent in the UK sits at the intersection of several rule sets. None of them mandates wet ink for trial consent, and all of them allow electronic methods when the underlying safeguards are preserved.

UK GCP and the Clinical Trials Regulations. Clinical trials of investigational medicinal products (CTIMPs) in the UK are governed by the Medicines for Human Use (Clinical Trials) Regulations 2004, as amended, which require that a participant gives informed consent and that consent is documented before any trial-specific procedure begins. The regulations and the associated UK GCP framework are technology-neutral on how that documentation is produced: what matters is that consent is freely given, informed, recorded, and attributable to the individual.

HRA and MHRA joint guidance. The Health Research Authority (HRA) and the Medicines and Healthcare products Regulatory Agency (MHRA) have issued joint guidance confirming that electronic methods of seeking and recording consent can be acceptable in UK research, including CTIMPs and non-CTIMP studies, provided the validity of consent is not compromised. In practice this means the e-consent process must still deliver the required information, allow questions, confirm understanding where appropriate, and capture a clear, dated expression of agreement.

ICH E6 GCP. UK GCP expectations align with ICH E6. The R2 revision already accommodated computerized systems in trial conduct, and ICH E6(R3), finalised in 2025, goes further by explicitly accommodating electronic and remote consent processes, with risk-proportionate expectations for system validation, data integrity, and participant protection. For multi-country programmes, designing your e-consent process to ICH E6(R3) principles keeps the UK arm consistent with global standards.

UK GDPR and health data. Trial consent documents and signature records contain health-related information, which is special category data under Article 9 of the UK GDPR. Note an important distinction sponsors often miss: consent to participate in a trial is a legal and ethical safeguard under GCP; it is not automatically the lawful basis for processing personal data. Many UK trials rely on other lawful bases (such as legal obligation or task in the public interest, combined with Article 9 conditions and Data Protection Act 2018 research provisions) precisely because GDPR consent must be as easy to withdraw as it is to give. Your e-consent platform therefore needs clear data mapping, retention controls, and processes for data subject requests. If your team handles erasure or access requests, our guide on handling GDPR right to be forgotten requests covers the operational side.

eIDAS and UK eIDAS. After Brexit, the UK retained eIDAS-derived rules as "UK eIDAS", which continues to recognise three signature levels: simple (SES), advanced (AES), and qualified (QES) electronic signatures. Section 7 of the Electronic Communications Act 2000 also provides for the admissibility of electronic signatures as evidence in legal proceedings. For most trial consent forms, a well-implemented simple or advanced electronic signature with strong attribution and audit evidence is sufficient in practice; an advanced electronic signature as a business standard adds signer-unique linking and tamper detection that inspectors find reassuring. Where a protocol, ethics committee, or another jurisdiction demands the highest assurance level, a qualified electronic signature may be specified — see our UK QES certificate cost guide for what that involves commercially.

During a GCP inspection, the consent process is almost always sampled. Inspectors assess the system, not just individual signature images.

Identity verification and attribution. Each signature must be attributable to a specific, identified participant. Inspectors will ask how the signer was authenticated at the point of consent: in-person ID checks captured in the audit trail, verified email or phone possession, one-time passcodes, or stronger identity proofing for remote consent. Multi-factor methods such as SMS OTP signer verification are a common, proportionate control for remote participants.

Audit trail. The system must produce a time-stamped, tamper-evident record of every event: who viewed the consent form, when, which version, what they signed, from which device or location, and any subsequent changes. The audit trail must be retained for the life of the trial records and be exportable in human-readable form on request.

Consent version control. Consent forms change as protocols are amended. The platform must bind each signature to the exact document version signed, prevent signing against superseded versions, and show which version each participant consented to. Version drift — participants signing an outdated form — is a classic inspection finding.

Re-consent handling. When new safety information emerges or the protocol changes materially, affected participants may need to re-consent. Inspectors look for a defined trigger process, tracking of who has and has not re-consented, and evidence that continued participation without re-consent was escalated.

Vulnerable participants and capacity. For minors, adults lacking capacity, or emergency research, consent may come from a legal representative. The e-consent workflow must support representative signatures, document the relationship, and record capacity assessments. Purely self-service remote flows are rarely appropriate here.

Wet-ink fallback and accessibility. Systems fail, and some participants cannot or will not sign electronically. A documented fallback (paper consent scanned and indexed into the same tracking system) prevents a connectivity issue from becoming a compliance breach.

Requirements table: what to evidence and how

RequirementWhat inspectors expectHow to evidence it
Identity verificationSigner uniquely identified and authenticated before signingAudit-trail entries showing authentication method, verified contact details, ID check records
Signature attributionSignature linked to one individual, under their sole controlUnique signer credentials, no shared accounts, device/session logs
Audit trail integrityComplete, time-stamped, tamper-evident event historyExported audit report per consent; cryptographic sealing or hash verification
Version bindingEach consent tied to the exact IRB/REC-approved form versionDocument version IDs embedded in the signed record and certificate of completion
Re-consent managementTriggered, tracked, and completed re-consent after amendmentsRe-consent workflow logs, outstanding-consent reports, escalation records
Representative consentLegal representative consent where capacity is absentRepresentative signature fields, relationship documentation, capacity assessment references
Data protectionUK GDPR-compliant handling of special category dataDPIA, retention schedule, data residency information, processor agreements
Fallback processContinuity when electronic signing is unavailableDocumented SOP for paper fallback and reconciliation into the tracking system

A practical implementation workflow

A defensible UK e-consent rollout typically follows these steps:

  1. Map the consent journey. Identify every consent touchpoint — initial consent, optional sub-studies, re-consent triggers, withdrawal — and who signs (participant, legal representative, investigator countersignature where used).
  2. Confirm REC/ethics approval. Submit the e-consent process description, screenshots, and information sheets to the Research Ethics Committee as part of the application or amendment; RECs expect to see how electronic consent preserves information quality and voluntariness.
  3. Select the signature level. Default to a well-evidenced simple or advanced electronic signature; escalate to AES or QES only where the protocol, a co-sponsor, or another participating country requires it.
  4. Configure identity assurance. Match authentication strength to risk: in-person ID verification for site-based consent, verified email plus OTP for remote consent, stronger proofing for high-risk or fully decentralised trials.
  5. Build version-controlled templates. Load REC-approved consent forms as locked templates with mandatory version IDs, and configure automatic blocking of superseded versions.
  6. Validate the system proportionately. Document intended use, configuration, and testing in line with a risk-based computerised systems validation approach; sponsors with US-facing programmes commonly use FDA 21 CFR Part 11 controls as a benchmark even for UK-only trials.
  7. Train sites and participants. Write a short SOP covering signing, fallback, and re-consent; give participants a clear "how signing works" explanation inside the information sheet.
  8. Monitor and reconcile. Run periodic checks that every enrolled participant has a complete, correctly versioned consent record, and reconcile any paper fallbacks into the same register.

How to evaluate an e-signature vendor for UK clinical trials

Not every e-signature tool is suitable for regulated consent. When shortlisting vendors, test these points:

  • GxP-oriented controls: tamper-evident audit trails, per-user accounts, e-signature manifestations on the signed document, and support for Part 11-style requirements as a widely used benchmark. Our comparison of GxP-compliant e-signature platforms for life sciences shows how vendors differ on these controls.
  • Identity assurance options: OTP, verified contact channels, and stronger identity proofing for remote or decentralised designs.
  • Version and template governance: locked templates, forced versioning, and the ability to retire outdated forms instantly across all sites.
  • Data residency and transfers: where consent records and health data are stored, and how the vendor handles UK GDPR international transfer requirements.
  • Retention and export: consent records must remain retrievable for the long retention periods applicable to trial documentation, in a format you can hand to an inspector without the vendor's help.
  • Accessibility and fallback: support for representative signatures, assisted signing, and a clean paper fallback path.
  • Validation support: documentation packs, audit support, and change control that reduce your computerised systems validation burden.

Nota Sign is FaDaDa's global e-signature platform, built on infrastructure ranked #1 in China's e-signature software market by IDC for consecutive years, with legal coverage across 100+ countries and regions. For clinical research teams, that translates into signature levels matched to your protocol risk profile — SES, AES, and QES — strong signer authentication, tamper-evident audit trails, template and version governance, and regional data centers that support data residency requirements, alongside APAC-specific trust services such as iAM Smart and Singpass where trials extend into those markets.

On commercial fit, Nota Sign charges no per-seat fees, which keeps rollout friendly for site-heavy trials and smaller research teams; mid-market sponsors, CROs, and enterprise programmes can discuss tailored plans aligned to study volume and validation needs. Positioning rather than a price promise — the fastest way to get accurate numbers and a compliance walkthrough is to contact the Nota Sign team with your trial scenario.

FAQ

Nota Sign helps businesses build compliant agreement workflows, and our content follows strict editorial guidelines.

Discover a better way to e-sign your documents

Start for Free
Contact Sales