12.4 Medical Coding (MedDRA, WHO Drug), SAE Reconciliation, Data Transfer & Database Lock
Key Takeaways
- Medical coding transforms verbatim text entered by site personnel into standardized, hierarchical medical terminology, enabling aggregated safety surveillance, signal detection, and regulatory submissions.
- MedDRA (Medical Dictionary for Regulatory Activities) is organized into a 5-level structural hierarchy: SOC, HLGT, HLT, Preferred Term (PT), and Lowest Level Term (LLT), with PT serving as the primary standard for statistical safety reporting.
- WHO Drug Global standardizes concomitant and prior medications using the 5-level Anatomical Therapeutic Chemical (ATC) classification system and unique Medicinal Product Identifiers.
- SAE Reconciliation is a mandatory quality control process that systematically matches serious adverse event data between the clinical EDC database and the pharmacovigilance safety database across all core data variables.
- Database Lock (DBL) represents the formal freezing of the trial database following strict criteria (all data entered, all queries resolved, all coding approved, all SAEs reconciled, and all PI electronic signatures applied); post-lock unlocking requires executive and QA sign-off.
Medical Coding (MedDRA, WHO Drug), SAE Reconciliation, Data Transfer & Database Lock
Core Regulatory Standard: Clinical trial data must be transformed from disparate, site-specific verbatim descriptions into standardized, scientifically rigorous datasets before statistical analysis and regulatory submission. Governed by ICH E6(R3) Annex 1 section 3.16, ICH M1 (MedDRA), and global pharmacovigilance standards, medical coding, Serious Adverse Event (SAE) reconciliation, and Database Lock (DBL) are the definitive gatekeeping milestones that guarantee trial data are clean, uncompromised, and submission-ready.
Candidates preparing for the ACRP-CP examination must thoroughly understand the structural hierarchies of MedDRA and WHO Drug Global, the operational execution of SAE reconciliation, the prerequisites for Database Lock, and the strict governance required to execute post-lock database unlocks.
1. Medical Coding Fundamentals & Standardization
Clinical trial sites record adverse events, medical histories, and concomitant medications using natural language (verbatim terms). Because different coordinators and investigators use varying synonyms, colloquialisms, and regional terminology (e.g., "Heart attack", "Myocardial infarction", "Acute coronary syndrome", "Cardiac arrest"), these verbatim entries cannot be statistically aggregated without standardization.
Medical Coding is the process of mapping verbatim clinical text to standardized codes and terms within internationally recognized medical dictionaries. This ensures that safety signals, adverse drug reactions, and therapeutic classes can be accurately analyzed across studies and global regulatory submissions.
2. MedDRA Architecture and Hierarchy (ICH M1)
The Medical Dictionary for Regulatory Activities (MedDRA) was developed under the auspices of the International Council for Harmonisation (ICH M1) and is maintained by the Maintenance and Support Services Organization (MSSO). MedDRA is updated bi-annually (major release X.0 in March, minor release X.1 in September).
┌───────────────────────────────────────────────────────────────────────────┐
│ THE 5-LEVEL MedDRA HIERARCHICAL STRUCTURE │
├───────────────────────────────────────────────────────────────────────────┤
│ 1. SYSTEM ORGAN CLASS (SOC) — 27 Broadest Anatomical/Etiological Classes │
│ ▲ │
│ 2. HIGH-LEVEL GROUP TERM (HLGT) — Broad Physiological/Anatomical Group │
│ ▲ │
│ 3. HIGH-LEVEL TERM (HLT) — Subordinate Grouping of Related Diagnoses │
│ ▲ │
│ 4. PREFERRED TERM (PT) — Distinct Medical Concept (PRIMARY ANALYSIS LEVEL│
│ ▲ │
│ 5. LOWEST LEVEL TERM (LLT) — Granular Verbatim Synonyms & Historical Terms│
└───────────────────────────────────────────────────────────────────────────┘
In-Depth MedDRA Structural Hierarchy Breakdown
| MedDRA Level | Description & Characteristics | Clinical Example 1 | Clinical Example 2 |
|---|---|---|---|
| System Organ Class (SOC) | The highest level; 27 broad categories divided by anatomical site, etiology, or purpose. | Cardiac disorders | Infections and infestations |
| High-Level Group Term (HLGT) | Subordinate group linking related physiological or pathological terms. | Coronary artery disorders | Viral infectious disorders |
| High-Level Term (HLT) | Subordinate group linking specific medical diagnoses and manifestations. | Ischaemic coronary artery disorders | Influenza viral infections |
| Preferred Term (PT) | The primary level used for regulatory safety reporting, summary tables, and signal detection. Represents a distinct, single medical concept. | Myocardial infarction | Influenza |
| Lowest Level Term (LLT) | The most granular level (>80,000 terms); matches verbatim text, historical terms, and colloquial synonyms. Every LLT links to exactly one PT. | Heart attack (Code: 10019218) | Flu symptoms (Code: 10016834) |
Multi-Axiality and Primary SOC Allocation
MedDRA is multi-axial, meaning a single Preferred Term may belong to more than one System Organ Class (e.g., Congenital rubella infection belongs to both Infections and infestations and Congenital, familial and genetic disorders).
- The Primary SOC Rule: To prevent double-counting of adverse events in regulatory summary tables, each Preferred Term is assigned exactly ONE Primary SOC by the MSSO. Secondary SOC links are used for comprehensive medical search queries.
3. WHO Drug Global & Anatomical Therapeutic Chemical (ATC) Classification
WHO Drug Global, maintained by the Uppsala Monitoring Centre (UMC), is the international standard dictionary for coding prior, concomitant, and investigational medications. It categorizes drugs using the Anatomical Therapeutic Chemical (ATC) classification system.
┌───────────────────────────────────────────────────────────────────────────┐
│ WHO DRUG ATC CLASSIFICATION HIERARCHY │
├───────────────────────────────────────────────────────────────────────────┤
│ LEVEL 1: Anatomical Main Group (14 Main Groups, e.g., 'C' Cardiovascular)│
│ ▲ │
│ LEVEL 2: Therapeutic Main Group (e.g., 'C09' Renin-Angiotensin Agents) │
│ ▲ │
│ LEVEL 3: Therapeutic / Pharmacological Subgroup (e.g., 'C09A' ACEI Plain)│
│ ▲ │
│ LEVEL 4: Chemical / Therapeutic Subgroup (e.g., 'C09AA' ACE Inhibitors) │
│ ▲ │
│ LEVEL 5: Chemical Substance / Active Ingredient (e.g., 'C09AA05' Ramipril│
└───────────────────────────────────────────────────────────────────────────┘
Medications with multiple therapeutic indications may have multiple ATC classifications (e.g., Aspirin has ATC codes for analgesia, antipyresis, and cardiovascular antiplatelet aggregation). The Data Management Plan defines standard conventions for assigning ATC codes based on the recorded indication.
4. Serious Adverse Event (SAE) Reconciliation
In clinical research, adverse event safety data is captured in two separate, parallel databases:
- The Clinical EDC Database: Maintained by Clinical Data Management; captures all routine trial data entered by site staff.
- The Safety / Pharmacovigilance (PV) Database: Maintained by Drug Safety / PV; captures expedited SAE reports (MedWatch 3500A, CIOMS I forms), clinical narratives, and regulatory SUSAR transmissions.
┌───────────────────────────────────────────────────────────────────────────┐
│ THE SAE RECONCILIATION PROCESS │
├───────────────────────────────────────────────────────────────────────────┤
│ CLINICAL EDC DATABASE SAFETY / PV DATABASE │
│ (Managed by Data Management) (Managed by Pharmacovigilance) │
│ │ │ │
│ └───────────────> RECONCILIATION <────────┘ │
│ │ │
│ CORE VARIABLES MATCHED: ▼ │
│ • Subject Identifier (USUBJID) • Seriousness Criteria (All 6 criteria) │
│ • Event Verbatim Term & MedDRA • Severity / Toxicity Grade │
│ • Event Start & Stop Dates • Causality Assessment (Related/Unrelated)│
│ • IP Action Taken (Dose Chg) • Event Outcome (Recovered, Fatal, etc.) │
└───────────────────────────────────────────────────────────────────────────┘
Reconciliation Execution & Discrepancy Resolution
- Frequency: SAE reconciliation is executed on an ongoing basis (e.g., monthly) and culminates in a mandatory 100% final reconciliation prior to database lock.
- Discrepancy Resolution: If an SAE onset date in EDC is
2026-08-10but the Safety Database records2026-08-12, CDM and Safety coordinate with the site monitor (CRA) to verify source medical records. The erroneous database is updated with documented audit trail justification. - Regulatory Sign-Off: Both the Lead Clinical Data Manager and the Head of Safety must execute a formal SAE Reconciliation Sign-Off Document certifying zero discrepancies before the database can be locked.
5. Blind Data Review Meeting (BDRM) & Pre-Lock Data Cleaning
Prior to locking the database and breaking the study blind, the sponsor conducts a formal Blind Data Review Meeting (BDRM) involving Clinical Data Management, Biostatistics, Clinical Operations, and the Medical Monitor.
┌───────────────────────────────────────────────────────────────────────────┐
│ KEY OBJECTIVES OF THE BLIND DATA REVIEW │
├───────────────────────────────────────────────────────────────────────────┤
│ 1. Protocol Deviation Review: Classify deviations into Major vs. Minor. │
│ 2. Analysis Population Allocation: Formally assign subjects to analysis │
│ populations (Intent-to-Treat [ITT], Modified ITT, Per-Protocol [PP], │
│ and Safety Population) while blinded to treatment assignment. │
│ 3. Outlier & Anomaly Evaluation: Review statistical outliers, extreme lab│
│ values, and missing primary endpoint data. │
│ 4. Imputation Rules: Finalize statistical missing-data handling rules. │
│ 5. Medical Coding Sign-Off: Final review of all MedDRA and WHO Drug terms│
└───────────────────────────────────────────────────────────────────────────┘
6. Database Lock (DBL) Procedures: Soft Lock vs. Hard Lock
Database Lock (DBL) is the formal action of freezing the clinical database to prevent any further data entry, modifications, or deletions, signaling that the data is clean and ready for unblinding and primary statistical analysis.
┌───────────────────────────────────────────────────────────────────────────┐
│ SOFT LOCK vs. HARD DATABASE LOCK │
├──────────────────────────────────┬────────────────────────────────────────┤
│ SOFT LOCK (Interim / Staged) │ HARD LOCK (Final Database Lock) │
├──────────────────────────────────┼────────────────────────────────────────┤
│ • Temporary restriction of site │ • Permanent removal of all write/edit │
│ data entry access │ permissions for all users │
│ • Allows final data cleaning, │ • Formally authorizes unblinding and │
│ interim statistical analysis, │ execution of final statistical runs │
│ or DMC safety reviews │ • Unlocking requires executive and │
│ • Administrative edits permitted│ QA authorization │
└──────────────────────────────────┴────────────────────────────────────────┘
The Mandatory Database Lock Checklist
A clinical database can only be locked when all 8 pre-lock criteria are completely satisfied:
- 100% of subject visits completed, and all eCRFs fully entered.
- 100% of automated and manual data queries resolved and closed.
- 100% of medical coding (MedDRA and WHO Drug Global) approved and locked.
- 100% of external vendor data (central lab, PK, ECG, imaging) reconciled and loaded.
- 100% of SAE reconciliation between EDC and Safety Database completed and signed off.
- Protocol deviations finalized and analysis population allocations locked.
- 100% of Principal Investigator electronic signatures executed on all eCRFs.
- Formal Database Lock Approval Form signed by Lead CDM, Lead Biostatistician, Medical Monitor, and Project Director.
7. Post-Lock Database Unlocking Procedures
Unlocking a locked clinical database—especially after the study blind has been broken—is an exceptional event that introduces severe regulatory scrutiny.
┌───────────────────────────────────────────────────────────────────────────┐
│ POST-LOCK UNLOCKING GOVERNANCE │
├───────────────────────────────────────────────────────────────────────────┤
│ 1. JUSTIFICATION: Permitted ONLY for critical errors that fundamentally │
│ impact subject safety or primary efficacy endpoints. │
├───────────────────────────────────────────────────────────────────────────┤
│ 2. FORMAL APPROVAL: Requires written sign-off from the Head of Data │
│ Management, Head of Biostatistics, Medical Monitor, and Head of QA. │
├───────────────────────────────────────────────────────────────────────────┤
│ 3. SCOPE CONTROL: System access is unlocked ONLY for the specific fields │
│ and subjects requiring correction; all other records remain locked. │
├───────────────────────────────────────────────────────────────────────────┤
│ 4. FULL AUDIT TRAIL: Complete documentation of the unlock reason, changes│
│ made, and impact assessment filed in the Trial Master File (TMF). │
├───────────────────────────────────────────────────────────────────────────┤
│ 5. RE-LOCK: Immediate execution of all reconciliation and re-lock checks.│
└───────────────────────────────────────────────────────────────────────────┘
8. Realistic Clinical Scenario: Managing SAE Reconciliation Discrepancies and Database Lock Gatekeeping
Clinical Scenario: Sarah Jenkins is the Lead Clinical Data Manager for a pivotal Phase III oncology trial. The planned Database Lock is scheduled in 48 hours. During the final pre-lock SAE reconciliation run, Sarah discovers a discrepancy for Subject 502:
- In the EDC Database, an adverse event of "Pneumonia" is recorded as Moderate in severity, Non-Serious, and onset date
2026-06-15.- In the Safety Database, the same event is recorded as a Serious Adverse Event (SAE) with onset date
2026-06-14because the subject was hospitalized for 3 days for IV antibiotic therapy.Gatekeeping Actions & Resolution:
- Immediate Lock Freeze: Sarah immediately halts the database lock countdown. Under GCP and SOP rules, a database cannot be locked with an unresolved SAE discrepancy.
- Investigation: Sarah contacts the CRA, who inspects the hospital source records. The source notes confirm the subject was admitted to the hospital on
2026-06-14with lobar pneumonia, fulfilling the regulatory SAE seriousness criterion (Inpatient Hospitalization).- Site Correction: The study coordinator corrects the eCRF: updates the onset date to
2026-06-14, checks "Serious = Yes", selects "Inpatient Hospitalization", documents the Part 11 reason for change, and the Principal Investigator re-signs the eCRF.- Reconciliation Completion: CDM re-runs the reconciliation algorithm. EDC and Safety databases now match 100% across all variables.
- Lock Execution: CDM and Safety execute the reconciliation sign-off document, and the formal Database Lock is authorized.
In the 5-level MedDRA dictionary hierarchy, which hierarchical level represents a distinct, single medical concept and serves as the primary standard level used for statistical safety reporting and regulatory summary tables?
What is the primary operational objective of Serious Adverse Event (SAE) reconciliation conducted prior to clinical database lock?
Following final Hard Database Lock and unblinding in a Phase III trial, a data manager discovers that a subject's primary efficacy lab value was entered incorrectly. What procedure is required before the database can be unlocked to correct the error?