Ask a clinical trial sponsor when to use a qualified e-signature (QES) instead of a standard e-signature (AES), and you’ll usually get one of two answers: “Wherever it’s mandated” or “Everywhere, to be safe.” Both answers are incomplete, and the second one is often expensive.

QES is the highest bar available for electronic consent. Under eIDAS in the EU, it carries full legal equivalence to a wet-ink signature backed by identity verification through a qualified trust service provider (QTSP) instead of a site staff member checking an ID at the door. That legal weight is exactly why some sponsors default to using it everywhere a study runs. But QES is not a feature you turn on globally. Its use is a decision that has to be made country by country, sometimes even site by site, and getting it wrong in either direction creates real problems: Use too little QES and you risk a regulatory finding; use too much and you add cost, training burden and friction for participants who didn’t need it.

Access deeper industry intelligence

Experience unmatched clarity with a single platform that combines unique data, AI, and human expertise.

Find out more

After watching sponsors work through this question across dozens of global protocols, we’ve found it helps to stop treating “QES or AES” as a single compliance checkbox and instead run it through four dimensions, weighted equally, with one exception: If any single dimension throws up a hard “must-have,” that flag may settle the decision on its own.

1. Country requirements. Start with regulation. Is QES mandated, preferred or simply accepted in each jurisdiction where the study will take place? Mandated means you use QES – this regulatory requirement overrides every other consideration. Preferred isn’t quite so clear-cut, but it tilts the decision toward QES. Accepted means AES is legally sufficient on paper, but that’s not the end of the story. Regulatory expectations can extend beyond what’s formally permitted. Even in jurisdictions where AES is accepted, regulatory bodies may still lean toward, prefer or informally expect QES in practice. Sponsors should therefore evaluate not just the letter of the regulatory requirement but also local authority expectations when determining the appropriate signature approach.

2. Study risk profile. This dimension looks at the study itself. Is this a high-risk indication or subject to significant regulatory scrutiny? Is the protocol likely to be inspected? Are you enrolling an ultra-rare population where losing even one participant or having to recruit a replacement would be especially costly? All these questions point to benefits from QES’s stronger, third-party-verified identity foundation. If someone tries to claim later that a different person signed consent, there’s a high-quality audit trail to prove who was there at the time. If there’s even a remote possibility that such a dispute could arise, counteracting it before the fact with QES is worth the cost. If the risk of an identity dispute is very low, deploying AES may be the more practical choice, because it can reduce costs and avoid additional delays for participants before their first visit.

3. Participant population. We’ve saved the trickiest evaluation for last, because this is where good intentions collide with operational realities. QES requires identity verification to satisfy regulatory requirements, which means a facial recognition scan matched to a government-issued identification for most populations. The scan itself happens inside an app on the participant’s phone.

If you’ve made it this far without striking QES as the obvious choice, congratulations: Your target population can handle that process. It adds roughly 2-5 minutes of participant-facing overhead before they ever see the consent document, and some may encounter difficulties completing the process. This includes remote or low-literacy populations without reliable access to identification documents, or patients who have physical conditions that make it difficult to interface with a camera. For example, patients with Parkinson’s disease taking part in a trial may struggle to hold their phone still enough to pass the facial scan. The ID documents themselves aren’t always uniform, either. Not every eligible person in a country will have a passport, but if your QTSP only accepts passports as ID proof, there is an access gap you’ll need to account for.

4. Operational feasibility. This final question asks whether the sites you’ve chosen to run this study are set up for QES. Site staff will need training on an authentication handoff many have never done before, participants may need help installing and launching the QTSP app, and yes, even the best teams have limits on how many technologies and processes they can manage at once.

None of these four dimensions is meant to be evaluated in isolation, and none of them, apart from a hard mandate, should carry more weight than the others. The right modality for a given country and population sits at the intersection of all four — which is also why “QES everywhere” and “QES nowhere but where it’s mandated” are both shortcuts that skip the actual work.

Turning the framework into a document that study coordinators can use

The framework only holds up operationally if it gets written down before enrollment starts.

1. Document the country-level decision. For every country in the study, document which signature method applies and why, and treat that document as a decision matrix, not a paragraph buried in the protocol. Regulatory affairs and clinical operations should own it jointly, since the decision sits at the intersection of both functions.

2. Translate it into site-level instructions. Once the signature approach has been determined at the study or country level, translate that decision into something a coordinator can use in the moment: a one-page job aid that walks them through exactly how to execute their site’s designated signature method — step-by-step, in plain language — not “See Appendix 2b for signature protocol variations.” Coordinators aren’t deciding between AES and QES at the point of care; that call has already been made upstream. What they need is clarity on how to carry out the selected approach correctly, every time.

3. Configure the technology and define fallbacks. Wherever possible, configure the system itself to enforce the correct modality for each country and population rather than relying on training alone to prevent the wrong choice. Also, establish a documented wet-ink fallback for participants who can’t complete ID verification. In a large enough study, some participants will inevitably encounter this issue, so the fallback process should be defined before, not during, a live consent visit.

Enable what you can in the tech itself. It’s ideal if the system can auto-route participants to the correct modality based on country and block coordinators from attempting the wrong one, but that’s not always possible. If you need to train people to understand exceptions, train them.

    4. Monitor for failures. Have documented contingencies for when tech fails participants. QES doesn’t work for every ID document, and any participant can run into issues during verification. A large global trial is guaranteed to encounter at least a few issues. The fallback should be defined before enrollment begins so that a coordinator does not have to improvise during a live consent visit. Where system configuration cannot handle an exception automatically, provide clear training on how staff should manage it.

      Don’t assume QA catches signature configuration failures. Anyone who’s run a global trial knows systems don’t always bend neatly to country-specific rulesets. If you allow sites to collect informed consent electronically and any of those sites are enrolling participants in jurisdictions that require QES, relying on “QA will catch it” is a dangerous assumption unless that workflow has been configured correctly from the outset. And even when QA does catch a misconfiguration, you’ll probably never know it happened unless you’ve built a process for surfacing and resolving those cases.

      The four-dimension framework is worthless without documentation before enrollment starts. Once participants are coming through the door, all these unresolved design questions become live operational problems.

      Where sponsors most often get this wrong

      The most common mistake is applying QES uniformly without a country-by-country evaluation. That approach treats the highest compliance bar as the safest default, when in most jurisdictions AES is legally sufficient, and QES simply adds cost and friction without a proportionate benefit. A second common mistake is underestimating site training: Coordinators need explicit, hands-on preparation for a QTSP handoff that’s genuinely unfamiliar to them, not a slide deck they saw once during startup. Third, sponsors often fail to plan for participants who cannot complete identity verification. Without a documented fallback, sites are left to determine the next step during a live consent visit, when the consequences of delay or confusion are greatest. Finally, QES should be treated as a strategic decision and not a plug-in feature. Its use should follow a deliberate assessment of country requirements, participant fit, site workflow, training needs and contingency planning.

      There is no universal e-signature strategy, and there shouldn’t be one. The goal isn’t to find the option with the highest compliance ceiling and apply it everywhere; it’s to match the right method to each country and population, document the reasoning and give sites something they can follow under pressure. Sponsors who build that framework before the first participant comes in spend far less time reconstructing it under inspection later.