IRB and Ethics Committee Management Software: What Happens When an Approval Expires Mid-Enrollment
Expect $80,000 to $160,000 and 12 to 18 weeks for a first IRB release covering submission smart forms, reviewer assignment, expedited and full board paths, the expiration clock and meeting agenda and minutes generation. A full platform adding reliance and ceded review tracking, conflict of interest screening, reportable new information workflows, investigator dashboards, fee billing and accreditation reporting runs $200,000 to $500,000 phased over 7 to 14 months. Build when you review more than roughly 800 submissions a year on institution-specific forms and reliance arrangements. If you run a few dozen studies a year and cede most multi-site work, use IRBNet or an external board and put the money into staff.
Why an IRB office breaks the workflow tool it was given
A study coordinator calls on a Thursday. Enrollment has been stopped because approval expired on Tuesday. The submission for continuing review went in five weeks earlier, sat in pre-review waiting for a missing document, was assigned to a reviewer who was on leave, and nobody was watching the clock because the clock lives in four places: a spreadsheet the analyst maintains, a calendar reminder, the expiration field in the system, and the memory of the coordinator who is now on the phone. The consequences are real and immediate. Research stops. Subjects already enrolled need a decision about continued participation. Somebody has to determine whether this is reportable.
That is the shape of the whole category. An IRB is not a document approval workflow with a committee attached. It is a set of overlapping legal clocks running against different regulatory bases, applied to submissions whose type determines their entire path, reviewed by people whose eligibility to review depends on their disclosed interests and on who else is in the room. Any system that models this as a request queue will be worked around within a year.
Problem 1: the submission type determines everything, and it is not knowable up front
An investigator does not know whether their project is exempt, expedited or requires full board review. Frequently they do not know whether it is human subjects research at all. So the front door cannot be a form picker. It has to be a smart form that asks questions in the order a determination actually requires, branches on the answers, collects only what that path needs, and produces a recommended determination that a staff analyst confirms or overrides.
Huron Research Suite does this seriously and is built for large academic institutions, which also means it is heavy: configuration is a specialist skill and a change to a smart form is a project rather than an afternoon. Advarra CIRBI is excellent if Advarra is your reviewing IRB, because the system is shaped around that service, and correspondingly less natural as the system of record for your own board's local rules. IRBNet is widely used, affordable and genuinely useful at smaller institutions, and it is document routing at heart: thin on branching determination logic, on computed expectedness and on the analytics an accreditation review will ask for. WCG IRB is a review service rather than a platform you operate. None of that is a criticism of the products. It is a statement about which institution they were built for, and whether that is yours.
What a custom build does: it treats the determination pathway as versioned rules that your own HRPP staff can read and change. Your institution's exempt category guidance, your local requirements above the federal floor, your extra questions for studies involving prisoners, children or identifiable biospecimens. When policy changes, the change is made once, versioned, and applied to submissions from an effective date, with old submissions still reconstructable under the rules that governed them.
Problem 2: four clocks, and only one of them is in the system
Initial review has a turnaround expectation your leadership measures you on. Continuing review has an expiration date that is a legal cliff. Amendments have their own review path and can change the expiration. Reportable new information has short internal deadlines and sometimes external ones. Meanwhile the 2018 revisions to the Common Rule removed the annual continuing review requirement for certain minimal-risk studies, while FDA-regulated research still expects periodic continuing review, so a single institution now runs several regimes simultaneously depending on funding and regulatory basis of each study.
The build has to compute, per study, which regime applies and what is due when, then surface that as work rather than as a report. A daily queue for the analyst: expiring in 60 days with nothing submitted, submitted but stalled in pre-review for 14 days, assigned to a reviewer who has not opened it in 10 days, approved but the letter has not gone out. Once that queue exists, lapses stop happening, and that single outcome usually justifies the project to the institutional leadership who funds it.
Problem 3: quorum, eligibility and the meeting that has to be reconstructable
Committee composition is regulated. A convened meeting needs a majority present, including at least one member whose primary concerns are in nonscientific areas, and members with a conflicting interest must not participate in the vote on that study. Minutes must record the vote, including those for, against and abstaining, and the basis for required determinations. Get this wrong and the review is invalid, which is a far worse problem than a late letter.
Model the roster properly: member roles, scientific or nonscientific designation, affiliation status, alternates and who they may substitute for, term dates, expertise tags for consultant assignment. Then the agenda builder is constrained by quorum rather than being a list somebody types. Conflict screening runs against disclosed interests and against the study team roster automatically, so a member is removed from the vote before the meeting rather than after minutes review. And the minutes assemble from structured events, votes, attendance at the time of each vote, determinations made, with staff editing and approving the narrative. That is a legitimate role for language generation, drafting from recorded structured facts and never inventing them, with a human approving before the record is final.
Problem 4: reliance, ceded review and the single IRB world
NIH-funded multi-site research operates under a single IRB expectation, and the practical effect on an institution is that it now spends real effort on studies it does not review. You are either the reviewing IRB for sites you do not employ, or you are a relying site tracking someone else's approvals, local context reviews, ancillary approvals and reporting obligations. Reliance agreements, including those built on the SMART IRB framework, have to be tracked as objects with parties, scope, effective dates and per-study invocations.
This is where packaged systems most often force a spreadsheet, because the institution's obligations as a relying site are administrative rather than deliberative and do not fit the review workflow. The build should carry a ceded study as a first-class record: the external IRB, the approval documents received, the local ancillary reviews still required, the local context requirements, the expiration to watch, and the internal notifications when the external board changes something. Nobody outside an IRB office understands how much time this consumes and how little of it is visible in most tools.
Problem 5: the investigator experience determines your submission quality
Most of your pre-review delay is incomplete submissions. Every hour an analyst spends emailing an investigator for a missing document is an hour not spent on review. The lever is the front door: validation at submission, contextual help written in your institution's language, templates for consent documents that carry required elements, and a pre-submission completeness check.
That completeness check is the second honest use of a model here. Read the submitted package and flag what a human would flag: a consent form that omits a risk described in the protocol, a study team member without current human subjects training, a procedure in the protocol that has no corresponding item in the consent, a recruitment advertisement whose claims exceed the protocol. It does not make determinations. It produces a checklist for the analyst and, more usefully, for the investigator before they submit. In our experience this is where submission turnaround improves most, because the delay was never the review, it was the round trip.
What this costs and how long it takes
A first release with branching submission smart forms, determination pathways, reviewer assignment, expedited and convened review, the clock queue and agenda and minutes generation runs $80,000 to $160,000 and ships in 12 to 18 weeks, based on Digital Heroes delivery experience. A full platform adding reliance and ceded review, conflict of interest screening against disclosures, reportable new information workflows, investigator and department dashboards, industry study fee billing and accreditation reporting runs $200,000 to $500,000 phased over 7 to 14 months.
What drives price up specifically in an IRB build: integration with your grants and research administration systems, since the link between a protocol and its funding is where institutions want reporting and where identifiers rarely match. Conflict of interest, if you want live screening against an existing disclosure system rather than an annual import. Migration of historical protocols, which matters because auditors ask about studies approved years ago. Multi-committee support, if you also run an IBC, IACUC or radiation safety committee and want one platform. And accreditation evidence, if you are pursuing or maintaining AAHRPP status and want the reporting to be a query rather than a project. What keeps it down: launching with new submissions only and keeping legacy studies in the old system until they close naturally.
Build versus buy, and when buying is the honest answer
Buy if you review a few dozen studies a year, cede most multi-site work, and have no local requirements above the federal floor. IRBNet or an external board will cost less than any build and free your staff for the work that actually protects subjects. Buy also if you are already deep in Huron for grants and awards, because the integration value of one research administration suite is real and should not be given up lightly.
Build when two or more of these are true. You process more than roughly 800 submissions a year. Your smart forms encode institution-specific policy that you change more than once a year and currently cannot change without a vendor. You serve as reviewing IRB for external sites and your reliance tracking lives in a spreadsheet. You run several committees and want one submission front door for investigators. Or your last accreditation or audit cycle produced a finding you could not evidence your way out of because the data was spread across systems. The tipping point is that your determination rules and reliance arrangements are institutional policy, and policy you cannot change on your own schedule is policy someone else owns.
How to choose a developer for IRB and ethics committee software
Ask them to whiteboard the clock model before you sign. A partner who has done this draws study, submission, review, determination and expiration as separate objects, and asks immediately how an amendment affects the expiration date. A partner who draws a request with a status field has built a helpdesk.
Ask how quorum and conflict eligibility are enforced at agenda build, not at minutes review. Ask how the system reconstructs which policy version governed a submission approved two years ago, because that is the question an auditor asks and it is not answerable by a system that only holds current rules.
Ask what happens when your institution updates its exempt category guidance. If the answer is a change request, you have bought the same problem in a new colour. Then confirm in writing before kickoff that you own the repository, the infrastructure accounts and the data export path. At Digital Heroes that belongs to the client from the first commit, and any partner hedging on it is building a dependency into an office whose job is independence.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Across more than 5,400 IT projects studied by McKinsey and the University of Oxford BT Centre, large IT projects ran on average 45% over budget and 7% over schedule while delivering 56% less value than predicted. Source: McKinsey & Company / University of Oxford (BT Centre for Major Programme Management) (2012) →
- Per the Standish Group CHAOS 2020 report (reviewed at this URL), across tens of thousands of software projects roughly 31% end successfully, about 50% are 'challenged', and roughly 19% fail outright; small projects succeed far more often than large ones, and Agile approaches succeed at markedly higher rates than Waterfall. Source: The Standish Group (2020) →
- A study (led by Prof. Pak-Lok Poon, published in Frontiers of Computer Science, 2024) reviewing decades of spreadsheet-quality research found that about 94% of spreadsheets used in business decision-making contain errors, illustrating the hidden risk of manual spreadsheet workarounds that custom software is built to replace. Source: Central Queensland University / phys.org (Prof. Pak-Lok Poon et al.) (2024) →
- Technology 'Leaders' grow revenue at more than twice the rate of 'Laggards'; laggards surrendered 15% in foregone annual revenue in 2018 and stood to miss out on as much as 46% in revenue gains by 2023 if they did not change their enterprise technology approach. Based on a survey of more than 8,300 organizations across 20 industries and 20 countries. Source: Accenture (2019) →
Lachlan heads mobile design at Digital Heroes, covering iOS and Android work from first flows through to handoff specs the engineering leads can build against. He spends a lot of time on the unglamorous parts: navigation, empty states, permissions. Readers get the design side of what makes an app feel finished.
View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.
Frequently asked questions
How much does custom IRB management software cost for an academic medical center?
Is Huron Research Suite or IRBNet enough for our IRB office?
How do you stop IRB approvals from lapsing and stopping enrollment?
Does every study still need annual continuing review?
How should software handle quorum and conflicts of interest at a convened meeting?
Can software track reliance and ceded review under the single IRB requirement?
Where does AI actually help an IRB office?
How long does it take to implement and migrate to a new IRB system?
Can one system serve the IRB, IACUC and biosafety committees?
How big a team does it take to build a project management platform?
How much should a small business budget for its first custom app or website?
What security features does custom project management software need?
How do I vet a software agency before hiring them to build a PM tool?
How much does it cost to build a custom project management tool for my company?
Can we migrate years of data out of our current system into new custom software?
What are the biggest mistakes first-time software buyers make?
How small can the first version of my software be and still be worth building?
How many SaaS seats do we need before building custom becomes cheaper?
What's the most common mistake companies make when building their own PM tool?
Does it matter which tech stack the agency wants to use?
Who can build a custom project management software system?
Digital Heroes builds custom project management software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other project management software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.