Last reviewed: October 31, 2025

Welcome to Part 1 of your CCDM prep. Preparing for the Certified Clinical Data Manager (CCDM) exam requires not only memorizing concepts, but also understanding how they apply in real-world clinical data management. In this first installment of our CCDM preparation series, we cover five fundamental domains.
Here we lay the groundwork—Topics 1–5—that determine whether the rest of your study runs smoothly and your data stand up to analysis and inspection:
- 1 — Foundations: Protocol → Data & CRF
- 2 — EDC & Site Operations
- 3 — Data Engineering & Integration (for CDM)
- 4 — Data Quality & Validation
- 5 — Query & Discrepancy Management
Each section below summarizes the key points of the topic, links them to everyday CDM responsibilities, and highlights best practices drawn from official SCDM references (GCDMP chapters) to align with CCDM exam expectations. Use this as both a study guide and a practical reference for professional practice.
Topic 1 — Foundations: Protocol → Data & CRF
Why it matters. If the protocol is the contract, your CRFs and data specifications are the blueprint. Translating objectives and endpoints into minimal, unambiguous data prevents rework, keeps sites fast and accurate, and sets up downstream mapping and analysis to succeed.
Must‑knows (exam & job).
- Extract endpoints → define the minimal variables & conditions you truly need (avoid “nice‑to‑have” clutter).
- Turn the Schedule of Activities into an expectedness matrix (windows, conditional rules, unscheduled mapping).
- Apply CDASH‑aligned labels/codelists/units at design time; favor atomic fields over free text.
- Write Data Element Specs with name, type/length, codelist, units, null reasons, and edit‑check references.
- Handle licensed instruments (PRO/eCOA) correctly: permissions, exact wording, translations, and vendor workflow.
Process at a glance.
- Endpoint extraction (objective → estimand → endpoint variables).
- SoA → expectedness (windows, conditionality, unscheduled handling).
- CRF design (atomic fields, controlled terms, skip logic, UX for sites).
- Data element & derivation specs (algorithms + versioning).
- Instrument licensing & proof (agreements, versions, translations).
What “good” looks like.
- One‑page Protocol→Data map per endpoint; clean aCRF that shows traceability.
- A living expectedness matrix that drives checks and dashboards.
- Design‑time standards (units/visits/picklists) and signed UAT artifacts.
- Licensing/permission files for any copyrighted instruments.
📘 Chapters & podcast
- Ch. 1 — Protocol → Data Requirements Break protocol text into concrete variables, conditions, and derivations that align with estimands and analysis plans. Read chapter · Listen
- Ch. 2 — Schedule & Expectedness Build the expectedness matrix from the SoA, including windows, conditional visits, and unscheduled rules. Read chapter · Listen
- Ch. 3 — CRF Design Fundamentals CDASH‑aligned naming, atomic fields, controlled terms, and site‑friendly layouts that reduce query load. Read chapter · Listen
- Ch. 4 — Data Element Specs Specify name, type/length, units, codelists, null reasons, and edit‑check links to make builds consistent. Read chapter · Listen
- Ch. 5 — Instruments & Licensing Handle PRO/eCOA instruments without IP risk: permissions, translations, and unchanged wording. Read chapter · Listen
Topic 2 — EDC & Site Operations
Why it matters. Clear role boundaries, access controls, and operating rhythms keep the audit trail clean, speed query closure, and protect lock timelines. Mid‑study changes and upgrades are routine—govern them so nothing surprises safety or stats.
Must‑knows (exam & job).
- RACI clarity: sites enter/correct, DM designs rules & queries, CRA verifies, PV/MM own safety, Stats own analysis needs.
- Access, training & 21 CFR Part 11: provision by role, retrain on change, offboard fast; e‑sig and audit‑trail hygiene.
- Interim capture & go‑live: data currencies, partial builds, and controlled enablement of forms/rules.
- Upgrades/patches: impact assessments, freezes, rollback plans, and validation notes.
- Site performance: conversion, expectedness, entry lag, query aging; governance‑aligned escalation.
Process at a glance.
- Before FPI: data flow, roles/RACI, edit‑check & review plans; access/training ready.
- Capture: contemporaneous entry by sites with guardrailed permissions.
- Validate: rules and listings; DM opens clear, non‑leading queries.
- Correct: site updates with reasons; audit trail shows who/when/why.
- Govern changes: upgrades with freezes/rollback; site dashboards + weekly cadence.
What “good” looks like.
- DMP with roles/RACI and access standards; training & e‑sig logs.
- Go‑live checklist (forms/rules enabled, smoke tests) and upgrade notes (impact/rollback).
- Site dashboards and a short huddle cadence with interventions and time‑to‑green.
📘 Chapters & podcast
- Ch. 1 — EDC Roles & Responsibilities Who enters/corrects data, who designs rules, who verifies, and how to keep lanes clear in the DMP/SOW. Read chapter · Listen
- Ch. 2 — Access, Training & Part 11 Provisioning, retraining, offboarding, and e‑records/e‑signature expectations for compliant operations. Read chapter · Listen
- Ch. 3 — Interim Capture & Go‑Live Partial builds, enabling forms/rules safely, and first‑week monitoring to catch issues early. Read chapter · Listen
- Ch. 4 — EDC Upgrades & Impact Impact assessment, freezes/rollback, and documenting validation without slowing the study. Read chapter · Listen
- Ch. 5 — Site Performance & Screening Measure conversion, expectedness, entry lag, query aging; coach, surge, or escalate with a playbook. Read chapter · Listen
Topic 3 — Data Engineering & Integration (for CDM)
Why it matters. External data (labs, ECG, PK, eCOA) and standards (SDTM) demand repeatable pipelines. Keys, grain, and controlled terminology are not “programmer problems”—they’re CDM fundamentals that preserve traceability and reduce late surprises.
Must‑knows (exam & job).
- SQL literacy for CDM: joins, window functions, aggregation at the correct grain.
- Keys & de‑duplication: stable identifiers, survivorship rules, and one row per unit.
- Transfer specs & conformance: versioned, machine‑checkable schemas; fail‑closed ingestion.
- SDTM mapping basics: transform (don’t re‑enter), apply controlled terms, document Origin/Algorithm.
- Privacy & exports: minimum necessary data, de‑identification, and secure export controls.
Process at a glance.
- Inventory sources (EDC, vendor files, derivations) and their versions/frequencies.
- Set grain & keys; normalize codes/units/time zones before comparisons.
- Build conformance gate (structure, types, codelists) with clear failure logs.
- Map to SDTM with variable‑level rules and value‑level metadata; validate systematically.
- Control exports (scoped, blinding‑safe, auditable with checksums/manifests).
What “good” looks like.
- Versioned transfer specs; automated conformance with fail‑closed logs.
- Reusable mapping tables with Origin/Algorithm and value‑level rules.
- Controlled blinding‑safe exports and a tidy lineage from source to submission.
📘 Chapters & podcast
- Ch. 1 — SQL Essentials for CDMs Practical joins, windows, and grain setting to compute KPIs and reconcile data correctly. Read chapter · Listen
- Ch. 2 — Keys, Identifiers & De‑dup Subject/visit/form grains, surrogate keys, and survivorship rules that eliminate phantom mismatches. Read chapter · Listen
- Ch. 3 — External Ingestion & Transfer Specs Versioned specs, conformance gates, and immutable as‑received archives. Read chapter · Listen
- Ch. 4 — SDTM Mapping Basics Transform with traceability: domain assignment, controlled terms, value‑level metadata, and validation. Read chapter · Listen
- Ch. 5 — Privacy Controls & Exports Minimum‑necessary exports, de‑identification, blinding protection, and manifest/checksum practices. Read chapter · Listen
Topic 4 — Data Quality & Validation
Why it matters. Clean, analysis‑ready data come from purposeful checks and focused human review—not from throwing every conceivable rule at the database. Balance real‑time vs. batch, programmatic vs. visual review, and keep derivations versioned.
Must‑knows (exam & job).
- Real‑time vs batch checks; design for signal‑to‑noise, not volume.
- Programmatic review vs SDV: complementary roles; SDV is not a replacement for logical checks.
- Visual/manual review: targeted listings and plots to see patterns automation misses.
- Derivations: versioned algorithms with validation, test cases, and change control.
- Measurements & devices: calibration/position/state variables that affect values (e.g., posture for BP).
Process at a glance.
- Risk‑based rule set (critical data/critical processes).
- Operationalize: thresholds, windows, cross‑form checks, and owner routing.
- Visual review loop with a log of decisions and candidate rules.
- Derivation governance: freeze versions, test before promotion, publish change notes.
- Trend & refine based on false positives and impact.
What “good” looks like.
- A right‑sized edit‑check library with clear owners; low‑noise dashboards.
- Visual review logs with decisions and evidence; candidate rule register.
- Frozen derivation versions with validation packs.
📘 Chapters & podcast
- Ch. 1 — Real‑Time vs Batch Checks When to fire instantly vs nightly; keep noise down and actionability high. Read chapter · Listen
- Ch. 2 — Programmatic Review vs SDV What automation finds vs what SDV confirms; design complementary coverage. Read chapter · Listen
- Ch. 3 — Manual & Visual Review Listings/plots to spot sequences, outliers, and cross‑domain patterns; log decisions. Read chapter · Listen
- Ch. 4 — Derivations & Versioning Freeze algorithms, validate changes, and annotate outputs so analysts can trust them. Read chapter · Listen
- Ch. 5 — Operator & Device Measurements Design CRFs and checks for posture, calibration, and device settings that shift values. Read chapter · Listen
Topic 5 — Query & Discrepancy Management
Why it matters. A crisp state machine turns disagreement into decisions. The exam leans on the distinction between workflow states and resolution types; inspectors care about consistency, neutral wording, and auditable rationale.
Must‑knows (exam & job).
- Workflow states (e.g., New → Answered → Closed) vs resolution types (Corrected, Confirmed, Not Applicable, Data Not Available).
- One issue per query, neutral language, evidence attached; route to the true owner.
- Aging metrics: median age, %>14 days, critical backlog = zero for lock.
- Reopen sparingly with rationale; maintain a query log you can defend.
Process at a glance.
- Detect (rules, listings, recon) → Create (scoped, neutral).
- Assign (site/vendor/internal) with SLAs.
- Respond/Review with evidence; pick a resolution type.
- Close (audit trail reason) or reopen (exceptional, with rationale).
- Trend & improve (aging, owner segmentation, writing style).
What “good” looks like.
- A shared state model and resolution taxonomy in DMP/SOPs.
- Owner‑segmented dashboards (site/vendor/internal) with aging and %>14 days.
- Examples/templates for clear, non‑leading queries.
📘 Chapters & podcast
- Ch. 1 — Query Lifecycle & States The end‑to‑end state machine with ownership, transitions, and evidence expectations. Read chapter · Listen
- Ch. 2 — Writing Effective Queries Neutral wording, one issue per query, and requests that lead to fast, correct fixes. Read chapter · Listen
- Ch. 3 — Resolution Types & QC Distinguish states from resolution types; verify correctness before closure. Read chapter · Listen
- Ch. 4 — Aging Metrics & Performance Median age, %>14 days, and owner segmentation that drives action, not blame. Read chapter · Listen
- Ch. 5 — Escalation & Governance Capacity, surge, and a procedural escalation ladder aligned to study governance. Read chapter · Listen
What’s next (Part 2 preview)
In Part 2, we move from foundations to operational control—Reconciliation & Traceability, Standards & Coding, Database Lock & Inspections, Safety & Endpoint Management, and Study Communications & Dashboards.
Consolidated sources (selected)
Standards & guidance
- Good Clinical Data Management Practices (GCDMP) — Full compendium. CRF design, edit checks, external data, query management, safety data, study metrics, database closure/lock, and inspection readiness chapters. (scdm.org)
- ICH E6 (R2/R3) & E8 (R1). Quality by design, risk‑based approaches, roles, and documentation expectations that inform how CDM plans and validates systems and data.
- CDISC CDASH & SDTM (with CT). Collection and tabulation standards that drive CRF structure, mappings, and submission traceability.