REQ-21CFR11-001 |
Reproducibility |
21 CFR Part 11 – All electronic records must embed the application semantic version |
tests_e2e/audit-trail.spec.ts |
176 |
R script contains application semantic version |
21 CFR Part 11 – Audit Trail: generated code artifact provenance |
⬜ UNKNOWN |
REQ-21CFR11-001 |
Reproducibility |
21 CFR Part 11 – All electronic records must embed the application semantic version |
tests_e2e/audit-trail.spec.ts |
205 |
Python script contains application semantic version |
|
⬜ UNKNOWN |
REQ-21CFR11-001 |
Reproducibility |
21 CFR Part 11 – All electronic records must embed the application semantic version |
tests_e2e/audit-trail.spec.ts |
234 |
SAS script contains application semantic version |
|
⬜ UNKNOWN |
REQ-21CFR11-001 |
Reproducibility |
21 CFR Part 11 – All electronic records must embed the application semantic version |
tests_e2e/audit-trail.spec.ts |
263 |
Stata script contains application semantic version |
|
⬜ UNKNOWN |
REQ-21CFR11-002 |
Reproducibility |
21 CFR Part 11 – Electronic records must carry an ISO 8601 generation timestamp |
tests_e2e/audit-trail.spec.ts |
182 |
R script contains a valid ISO 8601 generated-at timestamp |
|
⬜ UNKNOWN |
REQ-21CFR11-002 |
Reproducibility |
21 CFR Part 11 – Electronic records must carry an ISO 8601 generation timestamp |
tests_e2e/audit-trail.spec.ts |
211 |
Python script contains a valid ISO 8601 generated-at timestamp |
|
⬜ UNKNOWN |
REQ-21CFR11-002 |
Reproducibility |
21 CFR Part 11 – Electronic records must carry an ISO 8601 generation timestamp |
tests_e2e/audit-trail.spec.ts |
240 |
SAS script contains a valid ISO 8601 generated-at timestamp |
|
⬜ UNKNOWN |
REQ-21CFR11-002 |
Reproducibility |
21 CFR Part 11 – Electronic records must carry an ISO 8601 generation timestamp |
tests_e2e/audit-trail.spec.ts |
269 |
Stata script contains a valid ISO 8601 generated-at timestamp |
|
⬜ UNKNOWN |
REQ-21CFR11-003 |
Reproducibility |
21 CFR Part 11 – The unique protocol identifier must appear in every generated artifact |
tests_e2e/audit-trail.spec.ts |
188 |
R script contains the trial protocol identifier |
|
⬜ UNKNOWN |
REQ-21CFR11-003 |
Reproducibility |
21 CFR Part 11 – The unique protocol identifier must appear in every generated artifact |
tests_e2e/audit-trail.spec.ts |
217 |
Python script contains the trial protocol identifier |
|
⬜ UNKNOWN |
REQ-21CFR11-003 |
Reproducibility |
21 CFR Part 11 – The unique protocol identifier must appear in every generated artifact |
tests_e2e/audit-trail.spec.ts |
246 |
SAS script contains the trial protocol identifier |
|
⬜ UNKNOWN |
REQ-21CFR11-003 |
Reproducibility |
21 CFR Part 11 – The unique protocol identifier must appear in every generated artifact |
tests_e2e/audit-trail.spec.ts |
275 |
Stata script contains the trial protocol identifier |
|
⬜ UNKNOWN |
REQ-21CFR11-003 |
Reproducibility |
21 CFR Part 11 – The unique protocol identifier must appear in every generated artifact |
tests_e2e/audit-trail.spec.ts |
452 |
results header displays the protocol identifier |
|
⬜ UNKNOWN |
REQ-21CFR11-004 |
Reproducibility |
21 CFR Part 11 – Audit trail must record the exact PRNG seed used for schema generation |
tests_e2e/audit-trail.spec.ts |
199 |
R script contains the PRNG seed initialisation statement |
|
⬜ UNKNOWN |
REQ-21CFR11-004 |
Reproducibility |
21 CFR Part 11 – Audit trail must record the exact PRNG seed used for schema generation |
tests_e2e/audit-trail.spec.ts |
228 |
Python script contains the PRNG seed initialisation statement |
|
⬜ UNKNOWN |
REQ-21CFR11-004 |
Reproducibility |
21 CFR Part 11 – Audit trail must record the exact PRNG seed used for schema generation |
tests_e2e/audit-trail.spec.ts |
257 |
SAS script contains the PRNG seed initialisation statement |
|
⬜ UNKNOWN |
REQ-21CFR11-004 |
Reproducibility |
21 CFR Part 11 – Audit trail must record the exact PRNG seed used for schema generation |
tests_e2e/audit-trail.spec.ts |
286 |
Stata script contains the PRNG seed initialisation statement |
|
⬜ UNKNOWN |
REQ-21CFR11-004 |
Reproducibility |
21 CFR Part 11 – Audit trail must record the exact PRNG seed used for schema generation |
tests_e2e/audit-trail.spec.ts |
444 |
results header displays the randomization seed used for the schema |
21 CFR Part 11 – Audit Trail: results grid metadata stamping |
⬜ UNKNOWN |
REQ-21CFR11-005 |
Reproducibility |
21 CFR Part 11 – PDF/XLSX exports must embed a SHA-256 audit hash for integrity verification |
scripts/verify_audit_hash.py |
2 |
Execute scripts/verify_audit_hash.py |
Standalone Script |
⬜ UNKNOWN |
REQ-21CFR11-005 |
Reproducibility |
21 CFR Part 11 – PDF/XLSX exports must embed a SHA-256 audit hash for integrity verification |
src/app/domain/randomization-engine/core/crypto-hash-parity.spec.ts |
27 |
should generate the exact same SHA-256 hash as the Python verification utility for the reference mock payload |
|
⬜ UNKNOWN |
REQ-21CFR11-005 |
Reproducibility |
21 CFR Part 11 – PDF/XLSX exports must embed a SHA-256 audit hash for integrity verification |
src/app/domain/randomization-engine/core/crypto-hash-parity.spec.ts |
66 |
should successfully verify the audit hash for |
|
⬜ UNKNOWN |
REQ-21CFR11-006 |
Reproducibility |
21 CFR Part 11 – PDF audit artifact must embed version, timestamp, protocol ID and PRNG seed |
tests_e2e/audit-trail.spec.ts |
409 |
PDF export contains the application semantic version |
21 CFR Part 11 – Audit Trail: PDF export provenance |
⬜ UNKNOWN |
REQ-21CFR11-006 |
Reproducibility |
21 CFR Part 11 – PDF audit artifact must embed version, timestamp, protocol ID and PRNG seed |
tests_e2e/audit-trail.spec.ts |
415 |
PDF export contains a valid ISO 8601 generated-at timestamp |
|
⬜ UNKNOWN |
REQ-21CFR11-006 |
Reproducibility |
21 CFR Part 11 – PDF audit artifact must embed version, timestamp, protocol ID and PRNG seed |
tests_e2e/audit-trail.spec.ts |
421 |
PDF export contains the trial protocol identifier |
|
⬜ UNKNOWN |
REQ-21CFR11-006 |
Reproducibility |
21 CFR Part 11 – PDF audit artifact must embed version, timestamp, protocol ID and PRNG seed |
tests_e2e/audit-trail.spec.ts |
427 |
PDF export contains the PRNG seed value |
|
⬜ UNKNOWN |
REQ-EXPORT-001 |
Reproducibility |
CSV/XLSX export filename must contain an 8-digit date component for per-generation traceability |
tests_e2e/audit-trail.spec.ts |
460 |
CSV download filename contains a date component for traceability |
|
⬜ UNKNOWN |
REQ-EXPORT-002 |
Reproducibility |
PDF export must trigger a file download containing a properly named randomization artifact |
tests_e2e/audit-trail.spec.ts |
436 |
PDF export filename matches the expected pattern |
|
⬜ UNKNOWN |
REQ-EXPORT-002 |
Reproducibility |
PDF export must trigger a file download containing a properly named randomization artifact |
tests_e2e/results-operations.spec.ts |
126 |
should trigger a PDF download when the PDF button is clicked |
|
⬜ UNKNOWN |
REQ-EXPORT-003 |
Reproducibility |
Excel export must produce a two-sheet workbook (Schema + Audit & Configuration) |
— |
— |
(no tests tagged) |
— |
⚠️ NO COVERAGE |
REQ-ICH-E6-001 |
Scientific Validity |
GCP – Subject IDs must be unique and fully traceable to site and block (ICH E6 §4.9) |
src/app/domain/randomization-engine/core/randomization-algorithm.spec.ts |
657 |
{RND:n} produces no duplicate subject IDs across the schema |
|
⬜ UNKNOWN |
REQ-ICH-E6-002 |
Scientific Validity |
Site information must be captured and present in all exported records (ICH E6 §4.1) |
— |
— |
(no tests tagged) |
— |
⚠️ NO COVERAGE |
REQ-ICH-E9-001 |
Scientific Validity |
Randomization algorithm must be deterministic and reproducible from a fixed PRNG seed (ICH E9 §2.3) |
scripts/cross-env/verify_python_schema.py |
2 |
Execute scripts/cross-env/verify_python_schema.py |
Standalone Script |
⬜ UNKNOWN |
REQ-ICH-E9-001 |
Scientific Validity |
Randomization algorithm must be deterministic and reproducible from a fixed PRNG seed (ICH E9 §2.3) |
src/app/domain/randomization-engine/core/statistical-validation.spec.ts |
145 |
1:1 ratio converges to 50 % per arm across 200 Monte Carlo trials |
ICH E9 – Law of Large Numbers: allocation ratio convergence |
⬜ UNKNOWN |
REQ-ICH-E9-001 |
Scientific Validity |
Randomization algorithm must be deterministic and reproducible from a fixed PRNG seed (ICH E9 §2.3) |
tests_e2e/schema-generation.spec.ts |
11 |
should generate a schema and display results grid |
|
⬜ UNKNOWN |
REQ-ICH-E9-002 |
Scientific Validity |
Stratification factors must be applied correctly to the randomization schedule (ICH E9 §2.3.3) |
src/app/domain/randomization-engine/core/statistical-validation.spec.ts |
278 |
per-stratum caps are never exceeded across 100 random seeds |
ICH E9 – Stratum Cap Enforcement: dynamic caps are never exceeded |
⬜ UNKNOWN |
REQ-ICH-E9-003 |
Scientific Validity |
Block randomization must respect declared block sizes and produce balanced allocations (ICH E9 §2.3.4) |
scripts/cross-env/verify_python_schema.py |
3 |
Execute scripts/cross-env/verify_python_schema.py |
Standalone Script |
⬜ UNKNOWN |
REQ-ICH-E9-003 |
Scientific Validity |
Block randomization must respect declared block sizes and produce balanced allocations (ICH E9 §2.3.4) |
src/app/domain/randomization-engine/core/statistical-validation.spec.ts |
185 |
every block has exactly the correct count of each arm for a 1:1 ratio with block size 4 |
ICH E9 – Block Balance: strict intra-block arm balance |
⬜ UNKNOWN |
REQ-SBOM-001 |
Reproducibility |
A Software Bill of Materials (SBOM) must be generated for every production build |
.github/workflows/ci.yml |
782 |
Job: sbom |
CI Workflow |
⬜ UNKNOWN |
REQ-ZERO-TRUST-001 |
Zero-Trust |
No subject or schema data may be transmitted to external servers (zero-trust architecture) |
tests_e2e/zero-trust.spec.ts |
53 |
schema generation produces zero outbound XHR/Fetch requests to external servers |
Zero-Trust Architecture: no outbound network requests |
⬜ UNKNOWN |
REQ-ZERO-TRUST-001 |
Zero-Trust |
No subject or schema data may be transmitted to external servers (zero-trust architecture) |
tests_e2e/zero-trust.spec.ts |
71 |
CSV export produces zero outbound requests to external servers |
|
⬜ UNKNOWN |
REQ-ZERO-TRUST-001 |
Zero-Trust |
No subject or schema data may be transmitted to external servers (zero-trust architecture) |
tests_e2e/zero-trust.spec.ts |
92 |
PDF export produces zero outbound requests to external servers |
|
⬜ UNKNOWN |