Consent Forms for Research Participants: Record-Keeping That Survives an Audit — Herarx Blog

Consent Forms for Research Participants: Record-Keeping That Survives an Audit

An auditor does not ask whether you took consent. They ask you to prove which version each participant signed, when, and what they agreed to. Here is how to keep that proof.

June 11, 2024
Consent Forms for Research Participants: Record-Keeping That Survives an Audit
Back to blog

Most study teams take consent properly. Far fewer can prove it quickly. When a monitor, ethics committee or funder audits a study, the questions are specific: which version of the consent form did participant 047 sign? Was that version approved at the time? Did they opt in to the optional data sharing? Who took the consent, and were they trained to? If answering takes a day of searching through binders and shared drives, the record-keeping has failed even if the consent was sound.

Version control comes first

Consent forms and information sheets change during a study. Each approved version needs a version number and date printed on the document itself, a record of when it was approved and when it came into use, and a record of when it was retired. Never edit an approved form in place. When a participant signs, the signed copy must show the version, so there is no argument later about which text they saw.

One consent record per participant

Keep a consent log, one row per participant, with at least:

  • Participant ID (not name, where the design allows).
  • Consent form version signed.
  • Date and, where relevant, time of consent.
  • Person who took consent.
  • Each optional item and the participant's answer: future contact, sample storage, data sharing, recordings.
  • Location of the signed form.
  • Any re-consent or withdrawal, with dates.

The optional items are where audits find problems. A participant who declined recording must not have a recording on file; a participant who declined future contact must not be on the follow-up mailing list. The log is how you check.

Keep identity and data apart

Signed consent forms carry names and signatures; your study data should not. Store the signed forms, and the key linking names to participant IDs, separately from the research data, with tighter access. The people analysing data rarely need to see who the participants are. Name the stored files consistently, using the participant ID and version, following the approach in file naming conventions people actually follow.

Re-consent and withdrawal

When a new version of the form is approved mid-study, decide and document whether existing participants must re-consent. If they must, track it per participant until everyone is either re-consented or recorded as not continuing. For withdrawal, record the date, what the participant asked for (stop taking part, or also remove their data), and what you did about it. Whether data already collected can be kept after withdrawal depends on what the form said and on the law where you work, so check your jurisdiction and your approval conditions.

Electronic consent

Electronic consent is widely accepted, but the same proof is needed: which version was shown, when the participant agreed, how they were identified, and a copy of what they signed that cannot be altered afterwards. Keep the audit record the platform produces alongside the signed document.

How long to keep it

Consent records usually have to outlive the study, sometimes by many years, because they are the evidence that the data was collected lawfully. Put them in your retention schedule as their own class, with the period set by your ethics approval, funder and local law.

A quick self-audit

Pick five participant IDs at random. For each, find the signed form, confirm the version was approved on the signing date, and check that every optional choice matches how their data is being handled. If that takes more than ten minutes, fix the log before someone else asks.