Skip to content
§
§ · build vs buy

Build vs Buy: IRB and Human Subjects Compliance Software

Under about 200 protocols a year, almost all minimal risk, buy IRBNet and spend nothing further. This is also one of the rare categories where building can be cheaper than buying, because the packaged products are largely configuration shells.

Internal Tools Development product interface illustration for IRB AND Research Compliance Software Build vs Buy Guide.
The short answer

Under about 200 protocols a year, almost all minimal risk, buy IRBNet and spend nothing further. This is also one of the rare categories where building can be cheaper than buying, because the packaged products are largely configuration shells. If a consultant quotes configuration above roughly $250,000, get a build quote before you sign anything.

The programs that should buy IRBNet and stop

A college reviewing sixty minimal risk social and behavioural protocols a year has no build case. IRBNet is inexpensive, adequate for that shape of work, and the effort of anything more ambitious would exceed the risk it removes. The same applies to a program with no FDA regulated studies, no reliance relationships and a single review board that meets monthly. Buy, configure lightly, and put your attention into training investigators.

Buying is also right when your policies are close to the federal floor. If your institution has not layered much local policy on top of the regulations, the branching logic inside a packaged submission form will fit you well, and the value of expressing that logic yourself is small. Advarra is strong on the clinical and commercial side and is often the right purchase for an institution whose portfolio leans that way. Huron IRB is the most capable option in an academic medical centre context, and Cayuse IRB fits programs already running that vendor's grants stack.

And buy when the human research protection program office is short handed. A build needs your most experienced analyst and probably your board chair for weeks, because their judgement about determinations and local exceptions is the specification. Taking those people out of the review queue has its own compliance consequence, and a lapsed approval costs more than a licence.

One more honest case: if your last audit finding was about investigator behaviour rather than about records, software will not fix it. Education and monitoring will.

Why configuration sometimes costs more than construction

Here is the thing that makes this category unusual. The product you are buying is largely a configuration shell. The submission form is not a form, it is a decision tree encoding your institution's policy: which questions appear when the study involves children, prisoners, pregnant women or participants with impaired consent capacity; when an authorisation or a waiver is required; when the study is FDA regulated and therefore carries a different obligation set; when a device is significant risk; what your local policy adds on top of the federal floor. Change one answer and half the remaining questions change.

Someone has to express all of that, and it is usually a consultant, at consultant rates, over months. When the configuration is the project, you are already paying for a build. You are simply paying for one you will not own and cannot change afterwards without a change request. That is the calculation most human research protection program directors have never run, and it is why our advice here diverges from what we say about almost every other compliance category.

The functional triggers stack on top. Dual framework portfolios, where a study can be exempt under the Common Rule while remaining FDA regulated, and packaged systems push you toward one answer. Reliance volume, since single review for multi site research means external institutions need scoped accounts that see exactly one study and their own site documents rather than emailing your coordinator. Local academic and clinical structures that force staff to maintain a parallel spreadsheet of exceptions. And the failure mode everyone recognises: a person is the clock on continuing review, and when that person takes leave, approvals lapse.

Both numbers, without the flattery

Packaged pricing scales with institution size and module count, with a first year implementation fee that is frequently larger than the subscription. Ask for the configuration estimate separately and in writing, with a named number of workflow variants included and a rate for anything beyond it. Then ask what a policy change costs after go live, because that is the number that reveals the real relationship.

A build, in our delivery bands, runs $80,000 to $160,000 for a first release shipping in 12 to 18 weeks: a versioned smart form with pre submission validation, pathway determination with recorded reasoning, convened meeting management with live quorum computation, and the expiration and modification engine. A full platform adding reliance agreements with scoped external access, reportable new information workflows, conflict of interest integration and links to grants, the animal care committee and clinical trial systems runs $200,000 to $500,000 phased across 8 to 14 months.

An FDA regulated portfolio raises the number, because dual framework tracking and device risk determinations add genuine logic. Reliance volume raises it, since external access and site level records form a substantial subsystem. Integration with an electronic health record or a clinical trial management system is usually the largest single line at an academic medical centre. Electronic signature requirements for regulated records are a design decision taken at the start, not retrofitted. And the count of local policies that exist as practice rather than as written policy is where the schedule actually goes.

What the configuration quote omits

The first omission is policy archaeology, and it applies to both routes equally. Your program runs on decisions that have never been written down: how a particular category is applied, when a specific determination is escalated, what your board treats as more than minimal risk in practice. Someone has to extract and document all of it before any form logic can be built or configured. Programs with a current written policy manual move noticeably faster than those relying on institutional memory, and the difference is measured in weeks.

The second is form versioning, and it is the question to ask before anything else. Can a study submitted three years ago still be rendered under the form version it was actually submitted against? Systems that mutate the current form in place make your historical record unreadable after the first policy change. For a compliance system whose records are the evidence in a federal inspection, that is disqualifying, and it is rarely covered in a demonstration.

The third is the parallel period. You cannot switch an active protocol portfolio overnight. Expect a phase where new submissions enter the new system while existing studies continue in the old one until their next continuing review or modification, which means your coordinators work two systems for a stretch. Plan the staffing for it explicitly.

The fourth is board member adoption. Members are volunteers with day jobs. If packets, agendas and voting do not work on the device they actually use, they will revert to paper, and your minutes will be reconstructed from handwritten notes exactly as before.

The lapsed approval walkthrough

Do this with your human research protection program director and one coordinator, using a real study rather than a demonstration.

  • Pick a study whose approval expires in the next sixty days and show who has been notified, when, and what happens if nobody responds.
  • Show which review regime applies to that study and where that determination is recorded.
  • Produce the currently approved consent document, and prove it is the version in use at every site.
  • Render a submission from three years ago under the form as it existed then.
  • For a convened meeting last quarter, show the quorum composition at the moment of each vote and every recusal.

If your current system answers all five, keep it and fix your process. If it answers four, buy the missing module. If the third and fifth questions require someone to open a shared drive, and the fourth is simply impossible, you are running compliance on institutional memory and the system is decoration.

Put the same five questions to every vendor, and insist they answer against a configuration that reflects your structure rather than a generic demonstration tenant. Ask specifically what each answer would cost to configure. The gap between the demonstration and the quote is the number that decides build versus buy in this category, and it is usually larger than anyone expects.

How to run the decision alongside your board calendar

Do the policy work first, whichever route you choose. Write down determination criteria, escalation rules, local additions to the federal floor and the review regime logic per study type. That document is the configuration specification and the build specification at the same time, so it is never wasted effort, and producing it frequently improves the program on its own by surfacing inconsistencies.

Then get both numbers before committing to either. A configuration estimate with a named variant count, and a build quote against the same written specification. Comparing them is a twenty minute conversation once the specification exists, and it is impossible before.

Sequence go live around your board calendar and your busiest submission season. New submissions move first, existing studies migrate at their next continuing review or modification, and nothing cuts over during the weeks before an accreditation visit or a scheduled inspection.

Where a build is the answer, Digital Heroes starts with a written product requirements document, which for a human research protection program means the form decision graph, the determination criteria and the review regime logic are agreed on paper before engineering begins. We are a 50 plus person team with more than 2,000 projects delivered and Fiverr Vetted Pro status, and we contract as a US LLC, UK LTD or India LLP so the repository and its intellectual property assign to the institution under its own law. Our engineering work is published to 2.5 million subscribers on YouTube. Ask us how we would version your smart form before anything else is discussed, and hold every vendor to the same question.

If you want a second opinion before signing anything, Digital Heroes contracts through India LLP, US LLC and UK LTD entities, so the agreement and the intellectual property assignment sit under law your own advisers already read. Nothing about that commits you to the build.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Almost half of all the activities people are paid almost $16 trillion in wages to do in the global economy have the potential to be automated by adapting currently demonstrated technologies. Source: McKinsey Global Institute (2017) →
  2. SaaS spend averaged $4,830 per employee (up 21.9% year over year), with large enterprises (10,000+ employees) spending roughly $284M annually and running about 660 apps, while organizations wasted an average of $21M annually on unused licenses. Source: Zylo (2025) →
  3. The average number of formal learning hours used per employee fell to 13.7 in 2024, down from 17.4 in 2023, a decline the report attributes partly to a shift toward informal and on-the-job learning not captured in the formal-hours metric. Source: Association for Talent Development (ATD) (2025) →
  4. Across more than 5,400 IT projects studied by McKinsey and the University of Oxford BT Centre, large IT projects ran on average 45% over budget and 7% over schedule while delivering 56% less value than predicted. Source: McKinsey & Company / University of Oxford (BT Centre for Major Programme Management) (2012) →
FAQ

Frequently asked questions

How much does it cost to build custom IRB software for a research university?

A first release with a versioned smart form, pathway determination, convened meeting management and the expiration engine runs $80,000 to $160,000 in Digital Heroes delivery experience. A full platform adding reliance agreements with external access, reportable new information workflows and integrations with grants and clinical systems runs $200,000 to $500,000. An FDA regulated portfolio and high reliance volume are the two largest cost drivers.

How long does it take, and when should a new system go live?

Twelve to eighteen weeks for a first release. Sequence go live so new submissions enter the new system first while existing studies migrate at their next continuing review or modification, which means coordinators work two systems for a period. Avoid any cutover in the weeks before an accreditation visit or a scheduled inspection, and avoid your busiest submission season entirely.

What happens to years of approved protocols and historic submissions?

Active studies migrate with their currently approved document set. Closed studies usually stay in a read only archive, because reconstructing years of submissions into a new model rarely repays the effort. The critical requirement is that a historic submission can still be rendered under the form version it was actually submitted against, since those records are the evidence in any federal inspection.

Can it integrate with our grants system, electronic health record or trial management system?

Yes, and at an academic medical centre the clinical integration is usually the single largest line in the budget. Grants system links are more straightforward and are worth doing early, because funding and approval status questions arrive constantly. Ask any vendor or developer which named systems they have connected in production rather than which they support on paper.

Who from our office has to be involved, and for how long?

Your human research protection program director and at least one senior analyst, for several weeks. Their judgement about determination criteria, escalation rules and local practice is the specification, and it cannot be delegated to a supplier. Programs with a current written policy manual move noticeably faster than those relying on institutional memory, so writing the policy down first shortens the engagement whichever route you take.

Who actually builds IRB and human subjects compliance software?

Small programs should buy IRBNet. When a build is warranted, Digital Heroes takes this work on: 50 plus people, more than 2,000 projects delivered, Fiverr Vetted Pro status, and a written product requirements document before any code. Institutions pick us partly for jurisdiction, since we contract as a US LLC, UK LTD or India LLP so the repository and intellectual property assign to the university under its own law.

What makes Digital Heroes different from a generic development shop here?

We build the submission form as a versioned decision graph with the version stamped onto every submission, so a study from three years ago still renders under the form it was submitted against. We also carry both the Common Rule and FDA frameworks in parallel rather than forcing one answer, which is where determination mistakes concentrate. Generic shops build a long form and mutate it in place when policy changes.

How do we verify a development partner is legitimate before signing?

Check the D-U-N-S registration and confirm the entity matches your contract signatory, since university procurement will ask anyway. Read the public Clutch and Trustpilot profiles for how delays and disputes were handled. Require repository, cloud account and record ownership in writing before kickoff, because IRB records are the evidence in any federal inspection and must never sit somewhere you cannot access on your own authority.

What questions should I ask a development agency on the first call?

Ask who exactly will build it, what happens when scope changes mid-project, what their maintenance terms are after launch, and what they will need from you every week. Then ask them to describe a project that went wrong and what they changed afterward; teams that have shipped at real volume have war stories, and teams claiming a perfect record are hiding something. The scope-change answer matters most: a disciplined shop describes a written change-order process, not a vague promise to be flexible.

How do I vet a software development agency before signing a contract?

Ask to speak with two past clients whose projects resemble yours in size and industry, and ask exactly who will write your code, since some agencies sell senior faces and deliver junior or subcontracted hands. Demand a written specification with acceptance criteria before any fixed price, and check that their portfolio links to products that are actually live. An instant quote given without questions about your workflows is the clearest warning sign there is.

What tech stack should an internal tool be built with?

Boring and popular: a React or Next.js frontend, a Node.js or Python backend, and PostgreSQL covers the vast majority of internal tools and keeps future hiring easy. The stack matters far less than whether a different developer can pick the code up in two years, so require documentation as a deliverable and avoid anything exotic. Treat it as a red flag if an agency pushes a proprietary platform only they maintain, because that quietly converts your tool into a subscription to that agency.

How do I vet a development agency for an internal tools project?

Ask to see two or three internal tools they have shipped and whether those clients still use them daily, because internal tools fail on adoption, not code quality. Good signs: they ask to see your current spreadsheet or process before quoting, they propose a phased build instead of one big launch, and they spell out who handles training and post-launch changes. Walk away from anyone who gives a fixed price before seeing your actual workflow, since internal tools live or die on process details.

Will a custom internal tool scale as our company grows?

Yes, provided it sits on a standard stack with a real database: PostgreSQL comfortably handles millions of records, and adding users costs hosting pennies rather than per-seat fees. The real scaling risks are organizational, not technical: new departments want features, processes change, and the tool needs a budget line to evolve. Set aside a small quarterly improvement budget instead of treating launch as the finish line, and the tool stays useful for a decade rather than getting rebuilt every two years.

How do we migrate years of spreadsheet or Airtable data into a new internal tool?

Migration is a standard part of the build, not a separate project: the agency writes import scripts that clean, deduplicate, and map your existing rows into the new database. On typical spreadsheet and Airtable histories, Digital Heroes budgets 3 to 10 extra days, most of it spent resolving inconsistencies like the same customer spelled four different ways. The safe sequence is a trial migration first, a review of flagged conflicts with your team, then final cutover over a weekend so nobody loses a working day.

What does an internal tool cost for a small business with 20 to 50 employees?

Plan on $5,000 to $15,000 for a focused tool that replaces one painful spreadsheet workflow, such as job scheduling, quoting, or PTO tracking. In Digital Heroes projects at this size, the sweet spot is one core workflow, two or three user roles, and a single integration, usually QuickBooks or Google Workspace. Quotes far below $5,000 usually mean a template with your logo on it rather than software built around your process.

What are the most common mistakes companies make when building internal tools?

The three failures Digital Heroes sees most: building for every department at once instead of nailing one workflow, designing without the end users so staff quietly go back to their spreadsheets, and leaving no named owner after launch so small bugs pile up until the tool dies. A subtler fourth is faithfully recreating the old spreadsheet, including its workarounds, instead of fixing the process first. Start with one team's most painful workflow and put the actual users in the room from week one.

How do I calculate whether custom software will pay for itself?

Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.

What does it cost to keep an internal tool running after launch, and do we need to hire a developer?

Budget 15 to 20 percent of the build cost per year, so a $25,000 tool runs roughly $300 to $400 a month covering hosting, security patches, dependency updates, and small tweaks, figures drawn from Digital Heroes maintenance contracts. You do not need an in-house developer; a monthly retainer with the agency that built it covers the typical internal tool comfortably. Hosting itself is cheap for internal audiences, often $20 to $100 a month, because you serve dozens of users rather than the open internet.

How many people should be working on my software project?

Three to five for a typical focused build: a project lead, one or two engineers, a designer, and part-time QA, which is the standard shape across 2,000+ Digital Heroes projects. Larger platforms justify 6 to 10, but a ten-person team on a small first version usually signals bill padding rather than horsepower. What predicts success is whether a senior engineer is writing your code daily, not the headcount on the proposal.

Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply