Industry guide · Project Management

IRB and Ethics Committee Management Software: What Happens When an Approval Expires Mid-Enrollment

Irb Ethics Review Management software visual showing gavel, calendar clock, and stamp.
The short answer

Expect $80,000 to $160,000 and 12 to 18 weeks for a first IRB release covering submission smart forms, reviewer assignment, expedited and full board paths, the expiration clock and meeting agenda and minutes generation. A full platform adding reliance and ceded review tracking, conflict of interest screening, reportable new information workflows, investigator dashboards, fee billing and accreditation reporting runs $200,000 to $500,000 phased over 7 to 14 months. Build when you review more than roughly 800 submissions a year on institution-specific forms and reliance arrangements. If you run a few dozen studies a year and cede most multi-site work, use IRBNet or an external board and put the money into staff.

Why an IRB office breaks the workflow tool it was given

A study coordinator calls on a Thursday. Enrollment has been stopped because approval expired on Tuesday. The submission for continuing review went in five weeks earlier, sat in pre-review waiting for a missing document, was assigned to a reviewer who was on leave, and nobody was watching the clock because the clock lives in four places: a spreadsheet the analyst maintains, a calendar reminder, the expiration field in the system, and the memory of the coordinator who is now on the phone. The consequences are real and immediate. Research stops. Subjects already enrolled need a decision about continued participation. Somebody has to determine whether this is reportable.

That is the shape of the whole category. An IRB is not a document approval workflow with a committee attached. It is a set of overlapping legal clocks running against different regulatory bases, applied to submissions whose type determines their entire path, reviewed by people whose eligibility to review depends on their disclosed interests and on who else is in the room. Any system that models this as a request queue will be worked around within a year.

Problem 1: the submission type determines everything, and it is not knowable up front

An investigator does not know whether their project is exempt, expedited or requires full board review. Frequently they do not know whether it is human subjects research at all. So the front door cannot be a form picker. It has to be a smart form that asks questions in the order a determination actually requires, branches on the answers, collects only what that path needs, and produces a recommended determination that a staff analyst confirms or overrides.

Huron Research Suite does this seriously and is built for large academic institutions, which also means it is heavy: configuration is a specialist skill and a change to a smart form is a project rather than an afternoon. Advarra CIRBI is excellent if Advarra is your reviewing IRB, because the system is shaped around that service, and correspondingly less natural as the system of record for your own board's local rules. IRBNet is widely used, affordable and genuinely useful at smaller institutions, and it is document routing at heart: thin on branching determination logic, on computed expectedness and on the analytics an accreditation review will ask for. WCG IRB is a review service rather than a platform you operate. None of that is a criticism of the products. It is a statement about which institution they were built for, and whether that is yours.

What a custom build does: it treats the determination pathway as versioned rules that your own HRPP staff can read and change. Your institution's exempt category guidance, your local requirements above the federal floor, your extra questions for studies involving prisoners, children or identifiable biospecimens. When policy changes, the change is made once, versioned, and applied to submissions from an effective date, with old submissions still reconstructable under the rules that governed them.

Problem 2: four clocks, and only one of them is in the system

Initial review has a turnaround expectation your leadership measures you on. Continuing review has an expiration date that is a legal cliff. Amendments have their own review path and can change the expiration. Reportable new information has short internal deadlines and sometimes external ones. Meanwhile the 2018 revisions to the Common Rule removed the annual continuing review requirement for certain minimal-risk studies, while FDA-regulated research still expects periodic continuing review, so a single institution now runs several regimes simultaneously depending on funding and regulatory basis of each study.

The build has to compute, per study, which regime applies and what is due when, then surface that as work rather than as a report. A daily queue for the analyst: expiring in 60 days with nothing submitted, submitted but stalled in pre-review for 14 days, assigned to a reviewer who has not opened it in 10 days, approved but the letter has not gone out. Once that queue exists, lapses stop happening, and that single outcome usually justifies the project to the institutional leadership who funds it.

Problem 3: quorum, eligibility and the meeting that has to be reconstructable

Committee composition is regulated. A convened meeting needs a majority present, including at least one member whose primary concerns are in nonscientific areas, and members with a conflicting interest must not participate in the vote on that study. Minutes must record the vote, including those for, against and abstaining, and the basis for required determinations. Get this wrong and the review is invalid, which is a far worse problem than a late letter.

Model the roster properly: member roles, scientific or nonscientific designation, affiliation status, alternates and who they may substitute for, term dates, expertise tags for consultant assignment. Then the agenda builder is constrained by quorum rather than being a list somebody types. Conflict screening runs against disclosed interests and against the study team roster automatically, so a member is removed from the vote before the meeting rather than after minutes review. And the minutes assemble from structured events, votes, attendance at the time of each vote, determinations made, with staff editing and approving the narrative. That is a legitimate role for language generation, drafting from recorded structured facts and never inventing them, with a human approving before the record is final.

Problem 4: reliance, ceded review and the single IRB world

NIH-funded multi-site research operates under a single IRB expectation, and the practical effect on an institution is that it now spends real effort on studies it does not review. You are either the reviewing IRB for sites you do not employ, or you are a relying site tracking someone else's approvals, local context reviews, ancillary approvals and reporting obligations. Reliance agreements, including those built on the SMART IRB framework, have to be tracked as objects with parties, scope, effective dates and per-study invocations.

This is where packaged systems most often force a spreadsheet, because the institution's obligations as a relying site are administrative rather than deliberative and do not fit the review workflow. The build should carry a ceded study as a first-class record: the external IRB, the approval documents received, the local ancillary reviews still required, the local context requirements, the expiration to watch, and the internal notifications when the external board changes something. Nobody outside an IRB office understands how much time this consumes and how little of it is visible in most tools.

Problem 5: the investigator experience determines your submission quality

Most of your pre-review delay is incomplete submissions. Every hour an analyst spends emailing an investigator for a missing document is an hour not spent on review. The lever is the front door: validation at submission, contextual help written in your institution's language, templates for consent documents that carry required elements, and a pre-submission completeness check.

That completeness check is the second honest use of a model here. Read the submitted package and flag what a human would flag: a consent form that omits a risk described in the protocol, a study team member without current human subjects training, a procedure in the protocol that has no corresponding item in the consent, a recruitment advertisement whose claims exceed the protocol. It does not make determinations. It produces a checklist for the analyst and, more usefully, for the investigator before they submit. In our experience this is where submission turnaround improves most, because the delay was never the review, it was the round trip.

What this costs and how long it takes

A first release with branching submission smart forms, determination pathways, reviewer assignment, expedited and convened review, the clock queue and agenda and minutes generation runs $80,000 to $160,000 and ships in 12 to 18 weeks, based on Digital Heroes delivery experience. A full platform adding reliance and ceded review, conflict of interest screening against disclosures, reportable new information workflows, investigator and department dashboards, industry study fee billing and accreditation reporting runs $200,000 to $500,000 phased over 7 to 14 months.

What drives price up specifically in an IRB build: integration with your grants and research administration systems, since the link between a protocol and its funding is where institutions want reporting and where identifiers rarely match. Conflict of interest, if you want live screening against an existing disclosure system rather than an annual import. Migration of historical protocols, which matters because auditors ask about studies approved years ago. Multi-committee support, if you also run an IBC, IACUC or radiation safety committee and want one platform. And accreditation evidence, if you are pursuing or maintaining AAHRPP status and want the reporting to be a query rather than a project. What keeps it down: launching with new submissions only and keeping legacy studies in the old system until they close naturally.

Build versus buy, and when buying is the honest answer

Buy if you review a few dozen studies a year, cede most multi-site work, and have no local requirements above the federal floor. IRBNet or an external board will cost less than any build and free your staff for the work that actually protects subjects. Buy also if you are already deep in Huron for grants and awards, because the integration value of one research administration suite is real and should not be given up lightly.

Build when two or more of these are true. You process more than roughly 800 submissions a year. Your smart forms encode institution-specific policy that you change more than once a year and currently cannot change without a vendor. You serve as reviewing IRB for external sites and your reliance tracking lives in a spreadsheet. You run several committees and want one submission front door for investigators. Or your last accreditation or audit cycle produced a finding you could not evidence your way out of because the data was spread across systems. The tipping point is that your determination rules and reliance arrangements are institutional policy, and policy you cannot change on your own schedule is policy someone else owns.

How to choose a developer for IRB and ethics committee software

Ask them to whiteboard the clock model before you sign. A partner who has done this draws study, submission, review, determination and expiration as separate objects, and asks immediately how an amendment affects the expiration date. A partner who draws a request with a status field has built a helpdesk.

Ask how quorum and conflict eligibility are enforced at agenda build, not at minutes review. Ask how the system reconstructs which policy version governed a submission approved two years ago, because that is the question an auditor asks and it is not answerable by a system that only holds current rules.

Ask what happens when your institution updates its exempt category guidance. If the answer is a change request, you have bought the same problem in a new colour. Then confirm in writing before kickoff that you own the repository, the infrastructure accounts and the data export path. At Digital Heroes that belongs to the client from the first commit, and any partner hedging on it is building a dependency into an office whose job is independence.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Across more than 5,400 IT projects studied by McKinsey and the University of Oxford BT Centre, large IT projects ran on average 45% over budget and 7% over schedule while delivering 56% less value than predicted. Source: McKinsey & Company / University of Oxford (BT Centre for Major Programme Management) (2012) →
  2. Per the Standish Group CHAOS 2020 report (reviewed at this URL), across tens of thousands of software projects roughly 31% end successfully, about 50% are 'challenged', and roughly 19% fail outright; small projects succeed far more often than large ones, and Agile approaches succeed at markedly higher rates than Waterfall. Source: The Standish Group (2020) →
  3. A study (led by Prof. Pak-Lok Poon, published in Frontiers of Computer Science, 2024) reviewing decades of spreadsheet-quality research found that about 94% of spreadsheets used in business decision-making contain errors, illustrating the hidden risk of manual spreadsheet workarounds that custom software is built to replace. Source: Central Queensland University / phys.org (Prof. Pak-Lok Poon et al.) (2024) →
  4. Technology 'Leaders' grow revenue at more than twice the rate of 'Laggards'; laggards surrendered 15% in foregone annual revenue in 2018 and stood to miss out on as much as 46% in revenue gains by 2023 if they did not change their enterprise technology approach. Based on a survey of more than 8,300 organizations across 20 industries and 20 countries. Source: Accenture (2019) →
Lachlan R. · Director of Mobile Design · Sydney

Lachlan heads mobile design at Digital Heroes, covering iOS and Android work from first flows through to handoff specs the engineering leads can build against. He spends a lot of time on the unglamorous parts: navigation, empty states, permissions. Readers get the design side of what makes an app feel finished.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom IRB management software cost for an academic medical center?
A first release with branching submission smart forms, determination pathways, reviewer assignment, expedited and convened review, the expiration clock queue and agenda and minutes generation runs $80,000 to $160,000 and ships in 12 to 18 weeks, based on Digital Heroes delivery experience. A full platform adding reliance tracking, conflict of interest screening, reportable new information workflows, billing and accreditation reporting runs $200,000 to $500,000 phased over 7 to 14 months. Integration with grants and research administration systems is the most common cost escalator.
Is Huron Research Suite or IRBNet enough for our IRB office?
IRBNet is a reasonable answer at smaller institutions that review a few dozen studies a year and cede most multi-site work, because it is affordable document routing and the workload does not justify more. Huron is built for large academic institutions and is genuinely deep, with the trade-off that smart form and policy changes are specialist configuration work on a long cycle. Building becomes rational when your determination rules change more than once a year and you cannot make those changes on your own schedule.
How do you stop IRB approvals from lapsing and stopping enrollment?
Make the clock a work queue rather than a report. The system should compute per study which regime applies, then surface a daily list: expiring in 60 days with nothing submitted, stalled in pre-review for 14 days, assigned to a reviewer who has not opened it, approved but the letter has not been issued. Lapses almost always come from a submission sitting in a state nobody owns, not from a reviewer taking too long, and a queue that names the owner fixes that.
Does every study still need annual continuing review?
No, and that is exactly why institutions now run several regimes at once. The 2018 revisions to the Common Rule removed the annual continuing review requirement for certain minimal-risk categories, while FDA-regulated research still expects periodic continuing review. Your system therefore has to determine, per study, which regulatory basis applies and what is due when. A single global expiration rule will either create unnecessary work or miss a real deadline, and both are visible to auditors.
How should software handle quorum and conflicts of interest at a convened meeting?
Model the roster with member roles, scientific or nonscientific designation, affiliation status, alternates and expertise, then constrain the agenda builder by quorum rather than letting staff type a list. Conflict screening should run automatically against disclosed interests and the study team roster so a member is removed from a vote before the meeting rather than during minutes review. Minutes should assemble from structured events, including attendance at the time of each vote and the counts for, against and abstaining.
Can software track reliance and ceded review under the single IRB requirement?
It should, and this is where packaged tools most often push institutions back to a spreadsheet. Treat a reliance agreement as an object with parties, scope and effective dates, and treat each ceded study as a first-class record holding the external IRB, approval documents received, local ancillary reviews still required, local context requirements and the expiration to monitor. The administrative burden of being a relying site is large and almost invisible in tools designed around deliberative review.
Where does AI actually help an IRB office?
In pre-submission completeness checking, which is where the delay really lives. A model reads the package and flags what an analyst would flag: a risk in the protocol that is missing from the consent form, a study team member without current training, a procedure with no corresponding consent item, an advertisement whose claims exceed the protocol. It also drafts minutes narrative from recorded structured facts. It never makes determinations, and staff approve everything before it becomes a record.
How long does it take to implement and migrate to a new IRB system?
A first release typically ships in 12 to 18 weeks, and the migration decision drives the rest. The pattern that works is launching with new submissions only and letting legacy studies close out in the old system, which avoids re-keying protocols that will expire anyway. Historical migration is worth doing only for studies still active or likely to be audited, and even then the inventory and mapping pass should be treated as its own workstream rather than a data load.
Can one system serve the IRB, IACUC and biosafety committees?
Yes, and it is one of the better arguments for building, because investigators want one front door rather than three portals with different logins and vocabularies. The shared parts are submission intake, routing, committee rosters, meeting management and the clock engine. The determination logic and required content differ per committee and should be modelled as separate versioned rule sets rather than forced into one form, otherwise you get a shared system that serves nobody well.
How big a team does it take to build a project management platform?
A typical Digital Heroes pod is 4 to 5 people: a product designer, two or three engineers, and a shared project manager and QA. Smaller than that and timelines stretch because one person is context-switching across design, backend, and testing; bigger only helps after the MVP, when work splits into parallel streams. Headcount matters less than whether the same pod stays on your project from discovery to launch.
How much should a small business budget for its first custom app or website?
For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.
What security features does custom project management software need?
The non-negotiables are single sign-on, role-based permissions, encryption in transit and at rest, and an audit log of who changed what. If client work under NDA lives in the tool, custom actually improves your position, because you can run single-tenant on your own cloud account instead of shared SaaS infrastructure. You only need SOC 2 certification if you plan to sell the tool to others; for internal use, an annual penetration test is the sensible spend.
How do I vet a software agency before hiring them to build a PM tool?
Ask to click through a workflow tool they shipped, live rather than in screenshots, and get a reference from a client whose system has been in production for over a year. Then ask two questions that expose weak vendors: how they migrate data out of your current tool, and what their maintenance retainer covered for that reference client last quarter. An agency that has genuinely shipped project management software answers both in specifics.
How much does it cost to build a custom project management tool for my company?
A focused build that replaces one painful workflow runs $60,000 to $90,000, and a full platform with portfolio views, client access, and integrations runs $120,000 to $200,000 or more. Those are Digital Heroes delivery bands across 2,000+ projects, not list prices. Add 15 to 20 percent of the build cost per year for hosting, maintenance, and integration upkeep.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
What are the biggest mistakes first-time software buyers make?
Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.
How small can the first version of my software be and still be worth building?
One workflow, end to end, for one type of user: the single process that currently burns the most hours or loses the most money. In Digital Heroes delivery experience, first versions scoped to 6 to 10 weeks of build time ship, get used, and generate the feedback that makes version two obviously right, while 9-month first versions routinely launch with features nobody touches. Everything you cut from v1 gets cheaper to build later, because real usage reorders the roadmap for you.
How many SaaS seats do we need before building custom becomes cheaper?
The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.
What's the most common mistake companies make when building their own PM tool?
Chasing feature parity with Asana or Jira. Across 2,000+ Digital Heroes projects, the builds that blow their budgets are the ones recreating Gantt charts, portfolio dashboards, and mobile apps nobody asked for, while the builds that succeed go deep on the two or three workflows that made the team leave their old tool. You are not competing with Asana's roadmap; you are replacing the 20 percent of it you actually use.
Does it matter which tech stack the agency wants to use?
Yes, but not in the way most buyers expect: the goal is boring, popular technology such as React, Node.js or Python, and PostgreSQL, because any future team can maintain it and hiring a replacement developer takes days, not months. The red flag is an agency-proprietary framework or an unusual language, which welds you to that one vendor no matter what your contract says about code ownership. A useful test: could you find three freelancers fluent in this stack within a week? If not, push back.
Who can build a custom project management software system?

Digital Heroes builds custom project management software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other project management software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?