Industry guide · Internal Tools

IRB and Human Subjects Compliance Software: Protocol Review That Does Not Depend on One Coordinator's Calendar

Irb and Research Compliance software visual showing scroll text, git branch, and calendar sync.
The short answer

If you run a human research protection program with more than roughly 800 active protocols, an FDA regulated portfolio, and reliance agreements with outside institutions, a purpose built system is often faster to deliver than configuring a packaged one. A first release covering smart form submission, review pathway routing, convened meeting management and expiration tracking typically runs $80,000 to $160,000 and ships in 12 to 18 weeks in our delivery experience. A full platform adding reliance agreement handling with scoped external access, reportable new information workflows, conflict of interest integration and links to grants and clinical trial systems runs $200,000 to $500,000 phased over 8 to 14 months. A college running 60 minimal risk social science protocols a year should use IRBNet and spend nothing more.

Why an IRB system failure is the one that stops the whole campus

A study coordinator enrols a participant on a Tuesday. The protocol's approval expired the previous Friday. Nobody noticed because the continuing review reminder went to a principal investigator who had it filtered into a folder, the coordinator assumed approval was current because the study was still listed in the system, and the IRB office had 40 expirations that month across a staff of three. That single enrolment is now unapproved human subjects research. It has to be reported, the study goes on hold, and if the study is federally funded and the pattern looks systemic rather than isolated, the exposure is not one protocol. A determination against a human research protection program can suspend research across an entire institution.

The tools in this space are Huron IRB, IRBNet, Cayuse IRB and Advarra. Advarra is strong on the clinical and commercial side, Huron is the most capable in an academic medical centre context, and IRBNet is the workhorse for smaller programs. All of them are configurable and all of them are configured, at length, by consultants. The recurring complaint we hear from HRPP directors is not that the products are bad. It is that a configuration project to make a packaged system reflect local policy routinely runs longer and costs more than building the thing outright, and ends with a system nobody at the institution can change without a change request.

Problem 1: the smart form is your policy, and that is why configuration keeps failing

An IRB submission form is not a form. It is a decision tree encoding your institution's policy: which questions appear when the study involves children, prisoners, pregnant women or people with impaired consent capacity, when a HIPAA authorisation or a waiver is required, when the study is FDA regulated and therefore carries different obligations, when a device is significant risk, what your local policy adds on top of the federal floor. Change one answer and half the remaining questions change.

What a custom build does: model the form as a versioned decision graph with the branching held as data and the version stamped onto every submission, so a study submitted in 2026 can still be viewed under the form it was submitted against. Ask only what the answers so far make relevant. Then run completeness validation before submission rather than after, which is the single change that most reduces IRB staff workload, because the administrative pre review that consumes your coordinators becomes something the form did on its own. Investigators notice this within a week and it is the reason adoption goes smoothly.

Problem 2: the review pathway determination is judgement, and the system should show its work

Exempt, expedited or full board. That determination drives everything downstream and is made by a person applying the categories in the regulations to a specific study. The revised Common Rule changed the exempt categories and introduced limited IRB review for some of them, and FDA regulated research follows a different set of requirements, so a study can be exempt under one framework and not the other.

What a custom build does: evaluate the submitted answers against the category definitions and propose a pathway with the specific criteria that matched, which the analyst confirms or overrides with a recorded reason. The determination is never automatic, and any developer who offers to automate it does not understand the liability. What automation gives you is consistency and an artefact: every determination carries the criteria and the reviewer's reasoning, so a pattern review across a year is a query rather than a file pull. Where the study is FDA regulated, the system carries both frameworks in parallel rather than forcing one answer, because that dual status is where mistakes concentrate.

Problem 3: convened meetings run on quorum, recusal and a document nobody can assemble

A full board meeting requires quorum including at least one member whose primary concerns are in a nonscientific area, and a member with a conflicting interest may not participate in the vote. Losing quorum mid meeting invalidates subsequent actions. The agenda has to be assembled, packets distributed to members with the right documents, votes recorded per study with counts, and minutes produced that reflect the discussion including the required elements for approvals under the regulations.

Most IRB offices do this with a mix of the system's meeting module, a shared drive, a Word template for minutes and one coordinator who knows how it all fits. Minutes are frequently written from handwritten notes days later, and the required documentation of controverted issues and their resolution is the piece most often found thin during an audit.

What a custom build does: track membership with roles and expertise categories, compute quorum live during the meeting including the nonscientific member requirement, and warn the chair the moment a departure or a recusal breaks it. Conflicts are declared against studies in advance and the member is automatically excluded from that vote with the recusal recorded. Minutes assemble from structured actions taken during the meeting, with the discussion captured as it happens rather than reconstructed, and the required elements for each approval prompted rather than remembered. The output is a document that stands up when OHRP or a sponsor's auditor reads it two years later.

Problem 4: reliance agreements mean outsiders need real access to one study and nothing else

Single IRB review for multi site research is now the default for NIH funded domestic studies and is embedded in the cooperative research provision of the revised Common Rule. That means your IRB is either reviewing for institutions you do not control, or relying on someone else's and needing to track local context, local investigator credentials and local reporting obligations for sites that are not yours.

What a custom build does: external institutions get scoped accounts that see exactly one study and the documents for their site. Local context forms, local investigator training verification and site specific consent language live as site records under the parent study, so the approved version per site is unambiguous. Reliance agreements themselves are tracked as objects with an execution date, a scope and an expiry, and the SMART IRB style workflow is modelled rather than lived in email. When a reportable event happens at site seven, the system knows which sites are affected and what each one's institution requires.

Problem 5: expirations, modifications and reportable events are three clocks running at once

The revised Common Rule removed the continuing review requirement for many minimal risk studies, which sounds like relief until you realise your portfolio now has studies on three different regimes at once: those still requiring annual continuing review because they are FDA regulated or the IRB determined it necessary, those requiring only a status check, and those requiring nothing. Meanwhile modifications arrive and must be approved before implementation, and reportable new information including unanticipated problems has its own timeline.

The failure mode is always the same: a person is the clock. When that person is on leave, expirations slip.

What a custom build does: every study carries its own review regime derived from its determination, so the system knows which clock applies to which study without a coordinator remembering. Escalation is layered rather than a single reminder, moving from the coordinator to the principal investigator to the department chair on a schedule you define, and finally to an automatic administrative hold that prevents further approvals against a lapsed study. Modifications are versioned against the approved protocol so the currently approved document set is never ambiguous, which matters enormously when a monitor visits and asks which consent form was in use in March. Reportable new information gets a triage path with severity, a required assessment of whether the event meets the unanticipated problem definition, and the reporting obligations to sponsors and to federal agencies generated as dated tasks rather than remembered.

What this costs and how long it takes

Across the 2,000-plus projects Digital Heroes has delivered, this is the honest shape for an IRB and human subjects platform. A first release covering the versioned smart form with pre submission validation, pathway determination with recorded reasoning, convened meeting management with live quorum, and the expiration and modification engine runs $80,000 to $160,000 and ships in 12 to 18 weeks. A full platform adding reliance agreements with scoped external access, reportable new information workflows, conflict of interest integration, and links to grants, the animal care committee and clinical trial billing runs $200,000 to $500,000 phased over 8 to 14 months.

What drives price up specifically: an FDA regulated portfolio, because dual framework tracking and device risk determinations add real logic. Reliance volume, since external access and site level records are a substantial subsystem. Integration with an electronic health record or a clinical trial management system if you are an academic medical centre, which is usually the largest single line. Part 11 considerations if your electronic signatures need to support FDA regulated records, which is a design decision made at the start and not retrofitted. And the number of local policies that exist as practice rather than as written policy, because writing them down is discovery work and it is where the schedule actually goes.

Build versus buy, and when buying is the right call

Buy, and do not call us, if you review under about 200 protocols a year, almost all minimal risk social and behavioural research, with no FDA regulated studies and no reliance relationships. IRBNet is inexpensive, adequate and the right answer at that scale. Configuring anything more ambitious will cost more than the risk it removes.

Build when two or more of these are true. First, your configuration project for a packaged system has already exceeded its timeline, which is the single most common trigger we see. Second, you carry FDA regulated research alongside Common Rule research and your system forces one framework. Third, you are the reviewing IRB for multi site studies and external sites currently reach you by email. Fourth, your submission form asks everyone everything because the conditional logic could not be expressed. Fifth, expiration management depends on one person's reminders.

Our position, stated plainly: this is one of the few categories where building can genuinely be cheaper and faster than buying, and the reason is that the product you are buying is mostly a configuration shell. When the configuration is the project, you are already paying for a build. You are just paying for one you will not own and cannot change without a change request. If your consultant's configuration estimate is over about $250,000, get a build quote before you sign it.

How to choose a developer for IRB and research compliance software

Ask them to explain the difference between exempt with limited IRB review and expedited review, and how the same study can be exempt under the Common Rule while remaining FDA regulated. If they cannot, they will learn 45 CFR 46 during your build and the mistakes will be in your determinations.

Ask how they will version the smart form and whether an old submission can still be rendered under the form version it was submitted against. If the answer is no, your historical record becomes unreadable the first time policy changes, which for a compliance system is disqualifying.

Ask who owns the code and get it in writing before kickoff. You should own the repository, the infrastructure accounts and the right to hire anyone else. At Digital Heroes the code is yours from the first commit. Your IRB records are the evidence in any future federal inspection, and they should never be inside a system you cannot access or modify on your own authority.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. McKinsey found that tech debt can amount to 20-40% of the value of a company's entire technology estate before depreciation, and CIOs report that 10-20% of the budget for new products is diverted to resolving tech-debt issues. Source: McKinsey & Company (2020) →
  2. Companies in the top quartile of McKinsey's Developer Velocity Index had 2014-18 revenue growth four to five times faster than bottom-quartile peers, showing that software-building capability is a driver of business performance, not just a support function. Source: McKinsey & Company (2020) →
  3. WordPress powers 41.5% of all websites and holds 59.2% of the market among sites running a known content management system, making it by far the most-used CMS on the web. Source: W3Techs (2026) →
  4. SHRM's 2025 benchmarking data puts the average cost-per-hire at $5,475 for nonexecutive roles and $35,879 for executive roles - executive hires are on average nearly 7x more expensive than nonexecutive hires. Source: SHRM (Society for Human Resource Management) (2025) →
Jordan P. · Senior Growth Strategist · New York

Growth strategy at an agency means figuring out which lever actually moves revenue before anyone spends on it. Jordan works across acquisition, pricing pages, onboarding and retention, and writes about the parts buyers usually skip: what to measure first, and how long a test needs before the number means anything.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does it cost to build custom IRB software for a research university?
A first release with a versioned smart form, pathway determination, convened meeting management and the expiration engine typically runs $80,000 to $160,000 and ships in 12 to 18 weeks, based on Digital Heroes delivery experience. A full platform adding reliance agreements with external access, reportable new information workflows and integrations with grants and clinical systems runs $200,000 to $500,000 over 8 to 14 months. An FDA regulated portfolio and high reliance volume are the two largest cost drivers.
Is it really cheaper to build than to configure Huron IRB or Cayuse?
Sometimes, and this is one of the few categories where that is genuinely true. The packaged products are largely configuration shells, so a configuration project for a complex program can exceed the cost and timeline of a purpose built system while leaving you unable to change anything without a change request. Our rule of thumb: if a consultant's configuration estimate exceeds roughly $250,000, get a build quote before signing. Below that, configure.
How do you stop protocols from expiring without anyone noticing?
Derive the review regime from each study's own determination so the system knows which clock applies, then layer escalation rather than sending one reminder. Notices move from coordinator to principal investigator to department chair on a schedule you define, ending in an automatic administrative hold that blocks further approvals against a lapsed study. The failure mode to eliminate is a human being the clock, because that fails predictably during leave and turnover.
Can software determine whether a study is exempt, expedited or full board?
It should propose, never decide. The system evaluates submitted answers against the category definitions and surfaces the specific criteria that matched, and an analyst confirms or overrides with a recorded reason. That gives you consistency across reviewers and an artefact showing why a determination was made, which is what an auditor asks for. Any developer offering fully automated determinations has not understood where the regulatory liability sits.
How should an IRB system handle single IRB review for multi site studies?
External institutions need scoped accounts that see exactly one study and only their own site documents, rather than emailing materials to your coordinator. Local context forms, local investigator training verification and site specific consent language live as site records under the parent study, so the approved version per site is never ambiguous. Reliance agreements themselves are tracked as objects with execution date, scope and expiry rather than as PDFs in a folder.
Does convened board meeting management really need custom software?
It needs software that computes quorum live, including the requirement for a member whose primary concerns are nonscientific, and warns the chair the moment a departure or recusal breaks it. Conflicts are declared in advance and the member is excluded from that vote automatically with the recusal recorded. Minutes should assemble from actions captured during the meeting rather than being written days later from handwritten notes, because thin documentation of controverted issues is a common audit finding.
What happens to our historical records when IRB policy changes the submission form?
This is the question to ask any vendor or developer before you commit. The form should be a versioned decision graph with the version stamped onto every submission, so a study submitted three years ago still renders under the form it was actually submitted against. Systems that mutate the current form in place make your historical record unreadable after the first policy change, which is disqualifying for a compliance system.
How long does an IRB system take to build if we already have one?
A first release usually ships in 12 to 18 weeks, and the schedule risk is not engineering. It is the number of local policies that exist as practice rather than as written policy, since those have to be discovered and documented before the form logic can be built. Programs with a current written policy manual and documented determination criteria move noticeably faster than those relying on institutional memory.
Who owns the code if we hire an agency to build our IRB system?
You should own the repository, the cloud infrastructure accounts and the unrestricted right to hire another firm to continue the work, written into the contract before kickoff. At Digital Heroes the client owns the code from the first commit. IRB records are the evidence in any federal inspection of your human research protection program, and they must never sit inside a system you cannot access or modify on your own authority.
How long does it take to build an internal tool from scratch?
A working first version typically ships in 4 to 8 weeks, and larger multi-module tools run 10 to 16 weeks. Across Digital Heroes internal tool projects the schedule splits into roughly one week of process mapping, 3 to 6 weeks of build, and 1 to 2 weeks of testing with your actual staff. The most common delay is not development but waiting on the client for sample data and workflow decisions, so name one internal owner before kickoff.
How much should a small business budget for its first custom app or website?
For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.
How much does a custom internal tool cost to build?
Most custom internal tools cost $8,000 to $40,000 to build, based on Digital Heroes delivery data across 2,000+ client projects. A single-purpose tool like an approval dashboard or inventory tracker sits at the low end, while a multi-department platform with role-based access and several integrations pushes past $40,000. The three biggest cost drivers are the number of user roles, the number of systems the tool must connect to, and custom reporting requirements.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
At what point does Retool cost more than building a custom tool?
The crossover usually lands between 25 and 50 daily users. At Retool's published Business rates of $50 per standard user and $15 per end user monthly, a 40-person deployment with a typical seat mix runs roughly $9,000 to $15,000 per year, every year, while a comparable custom tool built once for $20,000 to $30,000 carries no per-seat fees and costs about 15 to 20 percent of the build price annually to maintain. On a three-year horizon, custom comes out ahead for most growing teams in Digital Heroes engagements.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
How many SaaS seats do we need before building custom becomes cheaper?
The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.
Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?