OSF Pre-Registration · International Audit Trial · WP73B Extension

Independent External Evaluation of Post-Export
Clinical Research Package Integrity

Independent multi-site custody-boundary hash-only verification (WP73B Extension).

  • QA certification is correct
  • QA certification is a point-in-time event
  • Exported evidence subsequently crosses custody boundaries
  • Existing systems do not provide independent post-export verification

A new verification framework was constructed. The framework was validated. It can now be evaluated against established scientific standards.

How: Software hash-only mathematical audit without access to source data or identifiers.

Participating institutions download hash-only packets from a public pre-committed repository: Telles, Fernando (2026), “Stage V Pre-Registration and Stage IV Multi-Site Replication: Hash-Only Verification Packets for International Blinded Challenge Trial of Post-Export Clinical Trial Evidence Verification (WP73B Amendment)”, Mendeley Data, V1. Packets contain no raw files, no filenames, no clinical content (SHA-256 / Evidence Set Fingerprints).

Independent investigators use Mode A of QMSAuditor v5 to run paired comparisons under blinded, pre-registered commit-reveal (Bitcoin-anchored) conditions. For each comparison, the software generates a machine-deterministic HVT-A report containing: the binary MATCH / MISMATCH verdict; enumerated divergences (files and ESF membership mismatches, if any). Non-clinical, non-interventional. No transfer of participant data outside institutional controls. No regulatory approval, clearance, or endorsement is claimed or implied.

Disclosure policy: Aggregate-only; no institutional attribution or endorsement.

Mode: Zero-Custody · Human-Verified · Machine-Deterministic. Anchoring System: AuditLog.AI. Auditing System: QMS Auditor (v5).

Canonical references

See also Regulatory Scope and Proof-of-Unchanged.

1. The problem

Validated trial and registry systems generate high-fidelity records during data capture. After export, however, integrity is generally assumed rather than verified. There is currently no established, system-independent method to determine whether an exported clinical research package remains unchanged between export and later use — pre-analysis curation, statistical analysis, manuscript preparation, archive, or submission.

2. Purpose of the audit trial (research questions)

Reproducibility must be measurable and tested, not just aspirational. Stage V registration is open for independent blinded verification.

Data integrity is a recognized problem. Regulators document it. Existing systems cannot solve it outside their walls.

Regulatory inspections routinely rely on evidence that has been exported from validated systems and subsequently retained, transformed, or re-used. The critical inspection question is:

Can exported digital evidence be independently verified after leaving the validated environment without source data transfer?

Operational examples of validated systems warranting post-export integrity assurance:

  • CROs: eTMF extracts, EDC exports, or database-lock snapshots.
  • Research institutions: validated registry exports, or clinical trial data at point of hand-off across institutions for multi-site studies.

The practical question is whether exported evidence from these systems can be deterministically verified as unchanged at a later inspection timepoint — often months or years after export, when original personnel, systems, or logs may no longer be available and reconstructive investigation is costly or infeasible.

This audit trial evaluates whether Proof-of-Unchanged, a custody-boundary verification methodology, can function as a system-independent, institution-agnostic verification primitive applicable to audit contexts under independent, external governance conditions.

Research questions
  1. Generalizability (multi-site): Can custody-boundary cryptographic verification executed by independent investigators and governance environments using hash-only export packets — with no access to, or transfer of, source data, filenames, or identifiers — produce reproducible, deterministic outcomes?
  2. Determinism: Under blinded pre-committed conditions across graded tamper severity tiers from unintentional error to selective omission, misconduct and fraud (human and/or AI-generated), does hash-only verification correctly classify all unchanged corpora as MATCH; and all tampered corpora as MISMATCH with accurate enumeration of all tampered evidence files and their folder-memberships?
  3. Regulatory-grounded, mechanism-agnostic detection: Does cryptographic custody-boundary verification correctly detect the integrity failure classes documented in regulatory inspection findings and research misconduct literature — including unintentional human error, selective omission, adverse-effects suppression, consent backdating, primary outcome manipulation, and allocation falsification — as instantiated across graded tamper severity tiers in the FICTI-PDA corpus; and is detection mechanism-agnostic, operating correctly whether modifications are introduced manually or via AI-assisted execution under human directives, without requiring knowledge of the tamper mechanism, tools used, or identity of modified files?
  4. Stage IV international multi-site replication without source data disclosure: When independent operators at international institutions run QMSAuditor Professional against the publicly archived Stage IV hash-only verification summaries, do they reproduce the single-site Stage IV findings — 100% detection sensitivity, 0% false-positive rate, and complete inter-operator agreement (Cohen's κ = 1.0) — without access to the underlying evidence files, filenames, or institutional identifiers?
  5. Verification effort and scalability (optional, post blind-reveal): Does human verification time for unchanged (MATCH) corpora remain constant and independent of corpus size across independent governance environments, confirming that routine proof-of-unchanged imposes a fixed, predictable verification effort regardless of evidence package scale; and does verification effort in MISMATCH corpora scale with tamper burden rather than corpus size, translating deterministic integrity guarantees into directly communicable cost, risk, and resource implications for sponsors, regulators, and research institutions?

3. Trial design overview

3.1 Design type

  • Stage V is an international, multi-site, blinded challenge trial using a hash-only verification design. Participating institutions perform zero-custody post-export mathematical audits using provided software and public hash-only datasets, with no transfer of source raw data, filenames, or identifiers. Dataset 1 contains six pre-committed hash-only packets (reference state Tk plus five blinded corpus variants: NC01, NC02, T1, T2, T3); dataset 2 contains 12 audit-arms of the Stage IV study under a new blinding map (labelled A, vs blinded QMSv5_01 and 02 in randomized order).
  • Institutions run QMSAuditor software to generate paired-comparison HVT-A reports. Reports are uploaded to a designated repository by the institution. All corpora are independently blinded to tamper status at the time of verification; blinding maps and tamper keys are released post-reveal for interpretive analyses.
  • No clinical diagnosis or therapy support. Software does not inform medical decisions.
  • No PHI / PII ingestion. Proof-only, hash-based zero-custody data flow.
  • Eligibility:
    • Accredited academic or research institutions
    • Contract Research Organizations (CROs)
    • Qualified data management, regulatory affairs, quality assurance, or audit professionals within any organisation with custodial responsibility for clinical, regulated, inspectable, or compliance-relevant evidence

    No geographic restriction. No minimum operator count. No dedicated infrastructure is required beyond a computer running the provided verification software (Windows).

3.2 Verification methodology

The method performs a paired comparison of two frozen, time-anchored evidence states (typically 1–10,000 files per state) and verifies:

  • Evidence integrity: whether individual file bytes are unchanged.
  • Membership integrity: whether the grouping of files within a package is unchanged.

Outputs are machine-deterministic audit artefacts (HVT-A) for human verification, showing either:

  • MATCH: proof-of-unchanged.
  • DIVERGENCE: altered / missing / extra items enumerated for review.

These can be re-executed at any time with reproducible results.

3.3 Submission

Each institution uploads respective HVT-A reports to a designated repository using the institution's pseudonymous site identifier (e.g., QMSIND01) as the folder name. No additional data, identifiers, or institutional information is submitted. The trial assesses post-export evidence verification only. PASS reduces reconstructive effort; divergence bounds proportional human review toward the minimal delta set. The methodology establishes integrity facts only — it does not evaluate clinical meaning, statistical validity, compliance, intent, or root cause. No claim of regulatory classification, clearance, endorsement, or procurement suitability is made or implied.

3.4 Important — no PHI / PII transfer; no filename / path transfer required

Anchoring software operates locally; no source data or identifiers are transmitted. The only data transmitted is the institution's pseudonymous ID (e.g. QMSIND01), hash fingerprint and anchoring transaction ID for each completed session.

4. System characteristics and definitions

Zero custody

Software execution is performed locally. No raw data, filenames, directory paths, or study metadata leave the local environment. Only the following proof-only artefacts are transmitted or retained by AuditLog.AI:

  • cryptographic digest (SHA-256 / RIPEMD-160) of an evidence state's provenance log, which is then anchored to Bitcoin mainnet via OP_RETURN;
  • public anchoring receipts (Bitcoin TXID, block height);
  • UTC timestamps associated with the anchoring event; and
  • pseudonymous session identifiers (non-reversible meta-IDs) used solely to correlate verification events.

Session-level cryptographic commitments are blockchain anchored solely to establish existence at time. OpenTimestamps proofs are optionally implemented at the evidence level.

No personal identifiers, study identifiers, file names, directory structures, content metadata, or contextual attributes are transmitted, retained, or processed.

Hash-only, offline, independent verifiability

Verification relies exclusively on dual-hash cryptographic digests of evidence files (SHA-256 and RIPEMD-160(SHA-256)) — not the raw data itself. Verification can be repeated locally from retained exports, or hash-only export packets can be generated locally by the Verification System for independent off-site verification without disclosure of sensitive data. Verification does not require ongoing system participation. The Verification System automates verification at scale; however, independent auditors may recompute hashes using open-source tools without vendor access.

Human governance

All critical system actions — particularly the anchoring of data to a public ledger — require explicit operator confirmation under controlled institutional authentication. Human primacy is enforced through a layered authorization model:

  • (i) institutional authenticated account (enterprise identity; unique login and password); and
  • (ii) unique user account (username + password and optional 2FA), where approval is bound to the specific record via record-linking fields including the reviewer's unique user meta-ID, UTC timestamp, meaning of signature, and the SHA-256 digest of the approved material.

Fail-closed architecture

Runtime execution is governed by Compliance Management Enforcement (CME) rules, including a 300-second execution threshold. If process integrity constraints are violated, the system rejects the session rather than producing an unreliable result.

For detailed regulatory mapping, see C12 — AuditLog.AI Global Compliance Matrix.

5. What is provided to independent institutions

Registered institutions receive unrestricted access to the anchoring and verification software for methodology evaluation, including initial setup and ongoing support during trial conduct. Software access and induction are provided by Cardiovascular Diagnostic Audit & AI Pty Ltd (Melbourne, Australia).

6. Local operational requirements

  1. Software download and registration. The Anchoring System has been designed in alignment with global regulatory standards (FDA / EMA / TGA; C12 — AuditLog.AI Global Compliance Matrix). Institutional authentication registration is required for provenance logs (provenance logs remain local; not exported).
  2. Operating computer (local). The methodology runs on standard modern workstations. For larger datasets (5,000+ files per state), increased specifications / RAM improves hashing throughput. The Anchoring System copies and freezes evidence states locally for long-term reproducibility (local data storage; frozen protections against accidental modification only).
  3. Internet connection. Required for blockchain timestamping.
  4. Processing time. Anchoring an evidence state takes approximately 15 minutes. Verification is typically near-instantaneous. Both depend on data size and workstation specifications.

7. Current status

A single-site study comprising five audit stages with increasing difficulty has been completed. In the current blinded, multi-operator proof-of-concept, 230,253 evidence files and 21,966 evidence-set fingerprints were deterministically verified, with 100% sensitivity, no false positives. Human effort required to verify software outputs quantified, showing strong positive association with tamper burden (r=0.91, p<0.0001) but no association with corpus size when evidence was unchanged (r=−0.01, p=0.93).

8. Regulatory and assurance framework references

This methodology is positioned under electronic records and audit documentation frameworks. Detailed clause-level mapping is provided in C12 — AuditLog.AI Global Compliance Matrix. Referenced frameworks include:

  • FDA 21 CFR Part 11 — electronic records and electronic signatures;
  • EMA Annex 11 + GCP Guideline Integration (2023) — computerized systems and data integrity;
  • TGA / PIC/S PE 009-17 — harmonized GMP computerized systems;
  • PCAOB AS 1105 / AS 1215 (including AS 1105.10A — external electronic information reliability evaluation, effective for fiscal years beginning on or after December 15, 2025);
  • ISA 230 / ISA 500 / ISA 240 (Revised 2025) — international audit documentation and evidence standards.

These references reflect methodological alignment and evidence mapping, not regulatory acceptance or certification. No regulatory authority has reviewed, classified, or endorsed this methodology.

This methodology is not clinical decision support, is not a medical device, and does not provide patient-level treatment recommendations.

Conflict of interest disclosure

Cardiovascular Diagnostic Audit & AI Pty Ltd (ABN 19 638 019 431) is the developer of the software under independent evaluation. This relationship is disclosed to all participants prior to registration. The trial evaluates methodology verifiability, not commercial suitability. Participation does not constitute vendor onboarding, procurement evaluation, or commercial engagement, and creates no licensing, purchase, or endorsement obligation.

Contact

Fernando Telles, MD — Fernando.Telles@AuditLog.AI

Methodology Lead for AuditLog.AI Research Initiative · Director, Cardiovascular Diagnostic Audit & AI Pty Ltd · Melbourne, Australia.

This protocol describes a methodology evaluation. It does not constitute regulatory advice, legal opinion, or a determination by any regulatory authority. Final classification and regulatory acceptance rest with the applicable authorities (FDA, EMA, TGA, PCAOB, or other competent body).