Problems & solutions · Project Management

IRB and Ethics Review Management Software Problems: The 7 That Stop Research, and How to Avoid Them

IRB Ethics Review Management Software workflow illustration showing common problems and fixes.
The short answer

The most expensive failure is a system that models submissions as a queue with a status field rather than as clocks with owners. Approvals then lapse mid enrolment, because the submission sat in pre review waiting for a document, or with a reviewer on leave, and no state in the system belonged to a named person. Enrolment stops, subjects already enrolled need a decision, somebody has to determine whether it is reportable, and the institutional cost is measured in halted studies rather than in software.

Why does the every committee, every submission type first release fail?

The pitch is compelling. Investigators want one front door instead of three portals, so the project scopes the institutional review board, the institutional animal care and use committee, biosafety and radiation safety together, with every submission type and a full migration of legacy protocols. Nine months later nothing is live, because each committee's determination logic turned out to be a different rule set and the migration inventory alone consumed a quarter.

What makes this specific to research administration is that the shared parts are genuinely shared and the different parts are genuinely different. Submission intake, routing, rosters, meeting management and the clock engine are common. Determination logic, required content and reporting obligations are not, and forcing them into one form produces a system that serves no committee well. Institutions that discover this in month seven usually end up with a compromise everyone works around.

Sequence it as one committee, new submissions only, with the clock queue in release one. That means branching smart forms, determination pathways, reviewer assignment, expedited and convened review, the expiration queue and agenda and minutes generation for the institutional review board. Additional committees come as separate versioned rule sets on the shared spine. Legacy protocols stay where they are and close out naturally, which removes the single largest schedule risk from the first release.

What goes wrong when you migrate legacy protocols?

The instinct is to bring everything across so there is one system. In practice, a study approved four years ago exists as a package of documents, a determination made under a policy that has since changed, an expiration date that may have been amended twice, and a set of study team members whose training status is stale. Re keying that produces a record that looks structured and is not, because the fields were invented during migration rather than captured during review.

The specific failure arrives during an audit or an accreditation visit. Someone asks how a determination made in a prior year was reached, and the migrated record shows the current form structure with values mapped into it, which cannot demonstrate what the rules were at the time. That is a worse position than pointing at the original file, because it implies a precision the record does not have.

Migrate selectively. Studies still active and likely to be audited are worth the effort, and even then the inventory and mapping pass should be its own workstream with its own owner rather than a data load bolted onto the build. Everything else stays in the old system as a read only archive with a clear pointer from the new one. The related discipline is policy versioning: from go live, every determination records the version of the rules that governed it, so the question an auditor asks becomes answerable going forward even though it is not answerable backwards.

Why do the research administration integrations break after launch?

Three connections matter and all three fail on identifiers rather than on technology. Grants and research administration is the first. Institutions want to report protocols against funding, and the identifiers rarely match, because a protocol number and an award number were never designed to relate to each other and the mapping is maintained by a person. When that person changes role, new links stop being made and nobody notices until a report comes back short.

Conflict of interest disclosure is the second, and it fails on timing. An annual import of disclosures means the screening at a convened meeting in October runs against data captured in March. A member who took a consulting role in June is screened as clean, participates in a vote, and the problem surfaces during minutes review or, worse, later.

Human subjects training records are the third. Certificates expire, a study team member is added mid study, and the completeness check passes because the roster in the protocol was never updated.

The fixes are mundane. Reconcile identifier mappings on a schedule and raise a named exception for any protocol with funding recorded upstream and no link downstream. Screen conflicts against live disclosure data rather than an annual snapshot, or if that is genuinely impossible, show the disclosure date on screen at agenda build so staff can see how old it is. And check training status at the point of submission and again at approval, not once.

What happens when quorum, conflicts and reliance are not properly covered?

Two gaps have consequences beyond inconvenience. The first is meeting validity. A convened meeting requires a majority present including at least one member whose primary concerns are in nonscientific areas, and a member with a conflicting interest must not participate in the vote on that study. Minutes must record the vote including those for, against and abstaining, and the basis for required determinations. Get this wrong and the review itself is invalid, which is a far worse problem than a late letter and one that can require re review of everything approved at that meeting.

Systems that fail here do so by enforcing at the wrong moment. Quorum checked at minutes review is quorum checked after the damage. It has to constrain the agenda builder, which means modelling the roster properly: member roles, scientific or nonscientific designation, affiliation status, alternates and who they may substitute for, term dates and expertise tags.

The second gap is reliance. Single institutional review board expectations for multi site work mean your office now spends real effort on studies it does not review, and packaged systems most often push that into a spreadsheet because the obligations of a relying site are administrative rather than deliberative. Treat a reliance agreement as an object with parties, scope and effective dates, and treat each ceded study as a first class record holding the external board, approval documents received, local ancillary reviews still required, local context requirements and the expiration to watch. Nobody outside an institutional review board office appreciates how much time this consumes or how invisible it is in most tools.

Should you build custom or configure what you already own?

Some institutions should not build. If you review a few dozen studies a year, cede most multi site work and have no local requirements above the federal floor, IRBNet or an external board will cost less than any build and free staff for work that actually protects subjects. It is affordable document routing, and at that volume document routing is what you need.

Do not build either if you are already deep in Huron for grants and awards. The integration value of one research administration suite is real, and giving it up to gain faster smart form changes is usually a bad trade. Advarra CIRBI is similarly the right answer if Advarra is your reviewing board, because the system is shaped around that service.

Build when two or more of these hold: you process more than roughly eight hundred submissions a year; your smart forms encode institution specific policy you change more than once a year and cannot change without a vendor; you serve as reviewing board for external sites and your reliance tracking lives in a spreadsheet; you run several committees and want one submission front door; or your last accreditation cycle produced a finding you could not evidence your way out of because the data was spread across systems.

How do hidden costs get into the quote?

Integration with grants and research administration is the most common escalator, because the identifier mapping problem is discovered rather than specified. Ask for it to be scoped explicitly, including who owns the mapping and what happens to unmatched records.

Live conflict of interest screening is the second. Screening against an existing disclosure system in real time is materially more work than an annual import, and the difference is often buried in a single line of a proposal. Third, historical migration, which is why the recommendation above is to avoid it: an inventory of several thousand legacy protocols is weeks of staff time before any engineering happens. Fourth, additional committees, since each brings its own determination rules and required content even on a shared spine. Fifth, accreditation evidence, if you want reporting to be a query rather than a project.

Two questions worth asking before contract. What exactly is included per additional committee. And what happens when the institution updates its exempt category guidance: if the answer is a change request, you have bought the same constraint in a different colour.

What separates a build that works from one that fails here?

Ask a prospective partner to whiteboard the clock model before you sign. A team that has done this draws study, submission, review, determination and expiration as separate objects and asks immediately how an amendment affects the expiration date. A team that draws a request with a status field has built helpdesk software and will build you helpdesk software again.

Then ask how the system reconstructs which policy version governed a submission approved two years ago. Systems that hold only current rules cannot answer the question auditors actually ask, and no amount of reporting compensates for that.

The builds that work also fix the front door, because most pre review delay is incomplete submissions rather than slow reviewers. Validation at submission, contextual help in your institution's language, consent templates carrying required elements, and a completeness check that flags what an analyst would flag: a risk in the protocol missing from the consent form, a team member without current training, a procedure with no corresponding consent item, an advertisement whose claims exceed the protocol. The builds that fail ship an elegant reviewer interface and leave intake untouched, then discover that turnaround did not improve because the delay was never in the review.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. In the Flexera 2025 State of ITAM report, respondents reported roughly 33% of SaaS spend is wasted, underscoring how paying for off-the-shelf seats and tiers that go unused erodes the supposed cost advantage of generic SaaS. Source: Flexera (2025) →
  2. Across more than 5,400 IT projects studied by McKinsey and the University of Oxford BT Centre, large IT projects ran on average 45% over budget and 7% over schedule while delivering 56% less value than predicted. Source: McKinsey & Company / University of Oxford (BT Centre for Major Programme Management) (2012) →
  3. APQC's Open Standards Benchmarking data on the monthly financial close found median performers take about 6.4 calendar days to close the books, while top performers (top 25%) do it in 4.8 days or fewer and bottom performers (bottom 25%) take 10 or more days. Source: APQC (2018) →
  4. The EY survey of 508 payroll professionals at U.S. companies with 250-10,000 employees quantifies the direct and indirect cost of payroll inaccuracy, reinforcing the ROI case for payroll automation; the study is the original source of the frequently cited $291-per-error figure. Source: BusinessWire / EY (Ernst & Young) (2022) →
Rohan K. · Director of Web Platform Engineering · Delhi

Rohan directs web platform engineering at Digital Heroes, the group that builds the custom web applications, portals and internal tools behind client operations. He writes about how those systems are structured, where they usually break under load, and what makes one maintainable years later.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How do we phase an IRB build when several committees want to be included?
Build the spine once and add committees as separate versioned rule sets. Release one covers the institutional review board with branching smart forms, determination pathways, reviewer assignment, expedited and convened review, the expiration queue and agenda and minutes generation. Shared intake, routing, rosters and meeting management then carry the animal care, biosafety and radiation safety committees later without forcing their determination logic into one form.
Should we migrate legacy protocols into the new system?
Only studies still active or likely to be audited, and treat that inventory and mapping as its own workstream with its own owner. Everything else stays in the old system as a read only archive with a pointer from the new one. Re keyed historic records look structured but cannot demonstrate what the rules were at the time, which is a weaker position during an audit than the original file.
How do we stop approvals lapsing while a submission sits in pre review?
Make the clock a work queue rather than a report, with a named owner on every state. The daily list should show what is expiring in sixty days with nothing submitted, what has been stalled in pre review for fourteen days, what is assigned to a reviewer who has not opened it, and what is approved with no letter issued. Lapses come from states nobody owns, not from reviewers being slow.
Why does annual conflict of interest screening fail at a convened meeting?
Because it screens against a snapshot rather than against current disclosures. A member who took a consulting role in June is screened as clean in October, participates in a vote, and the problem surfaces during minutes review or later. Screen against live disclosure data where possible, and where it genuinely is not, display the disclosure date at agenda build so staff can see how stale it is.
How should reliance and ceded review be modelled?
As first class records rather than as a spreadsheet beside the system. A reliance agreement is an object with parties, scope and effective dates. Each ceded study holds the external board, approval documents received, local ancillary reviews still required, local context requirements and the expiration to monitor. The administrative burden of being a relying site is large and almost invisible in tools designed around deliberative review.
What happens if quorum or conflict rules are enforced at minutes review instead of agenda build?
The review can be invalid, which is far more damaging than a late letter and can require re review of everything approved at that meeting. Enforcement has to constrain the agenda builder, which means modelling the roster properly with member roles, scientific or nonscientific designation, affiliation status, alternates, term dates and expertise tags. Minutes should then assemble from structured events rather than being typed.
What should we ask a vendor or developer about changing our exempt category guidance?
Ask what happens when the institution updates it. If the answer is a change request on their schedule, you have bought the same constraint you already have. Determination rules are institutional policy, and policy you cannot change on your own timetable is policy somebody else effectively owns. Ask the same question about adding a required question for research involving children or identifiable biospecimens.
Where does software actually shorten submission turnaround?
At the front door, because most pre review delay is incomplete submissions rather than slow reviewers. Validation at submission, contextual help in your institution's language, consent templates carrying required elements, and a completeness check that flags a risk missing from the consent form, a team member without current training or an advertisement exceeding the protocol. Every round trip removed is an analyst hour returned to actual review.
What should I have ready before I contact a development agency?
Four things: an export from your current tool, a list of the specific workflows it fails at, screenshots of the spreadsheets you use as workarounds, and your integration list with a budget range. Buyers who arrive with those cut discovery from two or three weeks to days, and that time comes straight off the invoice. You do not need a formal spec document; a good agency writes that with you.
What does it cost to keep custom project management software running each year?
Budget 15 to 20 percent of the original build cost annually, so a $100,000 platform costs $15,000 to $20,000 a year to run. That covers hosting, security patches, dependency upgrades, and the item buyers forget: fixing integrations when Slack, Google, or QuickBooks change their APIs, which happens every year. Skipping the maintenance budget is how a two-year-old tool becomes impossible to upgrade.
How much should a small business budget for its first custom app or website?
For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.
Which integrations should a custom project management tool have?
Start with the three that move money and attention: Slack or Teams for notifications, calendar sync for deadlines, and your accounting tool such as QuickBooks or Xero so tracked time flows into invoices without retyping. Development teams usually add GitHub or GitLab so tasks close when code merges. Each solid two-way integration adds roughly 1 to 2 weeks of build time, so rank them by hours saved per week rather than wishlist order.
How do I vet a software agency before hiring them to build a PM tool?
Ask to click through a workflow tool they shipped, live rather than in screenshots, and get a reference from a client whose system has been in production for over a year. Then ask two questions that expose weak vendors: how they migrate data out of your current tool, and what their maintenance retainer covered for that reference client last quarter. An agency that has genuinely shipped project management software answers both in specifics.
Will a custom tool built for 50 people still work when we're 500?
Yes, if it sits on a standard stack; a PostgreSQL-backed application handles 500 concurrent users without exotic engineering, and unlike Monday or Asana, seats 51 through 500 add nothing to your license bill. What does need rework at that scale is organizational rather than technical: permission models, department-level reporting, and admin tooling. Have the agency design the data model for multi-team use on day one, even if version one serves a single team.
Should I hire a freelancer or an agency for my software project?
A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.
What security features does custom project management software need?
The non-negotiables are single sign-on, role-based permissions, encryption in transit and at rest, and an audit log of who changed what. If client work under NDA lives in the tool, custom actually improves your position, because you can run single-tenant on your own cloud account instead of shared SaaS infrastructure. You only need SOC 2 certification if you plan to sell the tool to others; for internal use, an annual penetration test is the sensible spend.
What are the biggest mistakes first-time software buyers make?
Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.
I run a 15-person business. Is there a cheaper option than a full custom project management build?
Yes: a custom layer on top of a tool you already pay for. Digital Heroes ships client dashboards, automated reporting, and workflow glue built on the Asana and ClickUp APIs for $8,000 to $20,000, which fixes the specific gap without replacing the whole tool. A full custom platform rarely makes sense below roughly 50 seats unless the software faces your own customers.
What's the most common mistake companies make when building their own PM tool?
Chasing feature parity with Asana or Jira. Across 2,000+ Digital Heroes projects, the builds that blow their budgets are the ones recreating Gantt charts, portfolio dashboards, and mobile apps nobody asked for, while the builds that succeed go deep on the two or three workflows that made the team leave their old tool. You are not competing with Asana's roadmap; you are replacing the 20 percent of it you actually use.
We run everything on spreadsheets and Airtable. How do we know it's time for custom software?
The reliable signals are re-typing the same data into multiple tools, one employee acting as human middleware between systems, and errors appearing in handoffs between teams. Hard limits force the issue too: Airtable's Team plan caps at 50,000 records per base, and Business costs $45 per seat per month, so a 20-person team pays about $10,800 a year for a tool it has already outgrown. When workarounds consume more hours than the tools save, the spreadsheet era is over.
Who can build a custom project management software system?

Digital Heroes builds custom project management software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other project management software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?