Skip to content
§
§ · build vs buy

Build vs Buy IRB and Ethics Review Management Software

Most research offices should buy. Below roughly eight hundred submissions a year, IRBNet, Cayuse or Huron will cost less than any build and will absorb regulatory change on someone else payroll.

Project Management Software workflow illustration for IRB Ethics Review Management Software Build vs Buy Guide.
The short answer

Most research offices should buy. Below roughly eight hundred submissions a year, IRBNet, Cayuse or Huron will cost less than any build and will absorb regulatory change on someone else payroll. Build only when institution-specific determination rules change more than once a year, when you act as reviewing IRB for external sites, or when several committees need one front door.

Where a packaged system is plainly the better buy

Start with the shape of your office rather than the shape of the software. A human research protection program with three staff, two convened board meetings a month and roughly two hundred submissions a year is doing work that IRBNet, Cayuse IRB or iMedRIS already model well. Your determination pathways sit close to the federal floor, the local policy above that floor fits on two pages, and the volume does not justify anyone owning a codebase.

Buying is also the honest answer when you have already ceded most multi-site work to an external board. If WCG or Advarra reviews the studies that generate your protocol volume, and your own committee handles a residual of investigator-initiated chart reviews and student projects, the reviewing workload you would be automating is small. Advarra CIRBI is shaped around Advarra acting as your reviewing board, and it is genuinely good in that role.

The third case is integration gravity. If your institution already runs Huron for grants and awards, and your research administration team is fluent in it, adding the review module keeps the protocol to award link inside one product. That link is where institutional reporting lives, and giving it up to gain form flexibility is a poor trade for most offices.

A packaged system also absorbs regulatory interpretation for you. When guidance shifts, someone else reads it, decides what it means for the product and ships the change. For an office of three, that is worth more than the configuration freedom you give up, and any consultant telling a small board to build custom is selling hours rather than solving a problem.

The conditions that make building defensible

Building becomes rational when your workload stops resembling the generic model the products encode. The clearest single threshold is volume. Past roughly eight hundred submissions a year, counting initial applications, amendments, continuing reviews and reportable new information together, the cost of staff working around a form starts to exceed the cost of owning one.

Volume alone is not enough. Look for a second signal. Institution-specific determination logic that you change more than once a year is the most common: extra questions for research involving prisoners, a local requirement above the Common Rule for identifiable biospecimens, an exempt category guidance document your own committee wrote. If every one of those changes is a ticket to a vendor, your institutional policy now has an external release schedule.

Acting as the reviewing board for external sites is the second signal. Under the NIH single IRB expectation, the institution serving as sIRB carries reliance agreements, local context reviews, ancillary approvals and reporting duties for sites it does not employ. Packaged review workflows model deliberation, not that administration, so the work reliably ends up in a spreadsheet one analyst maintains and nobody else can read.

Committee breadth is the third. If you also run an IACUC, an institutional biosafety committee, a radiation safety committee or a stem cell research oversight committee, investigators currently face several portals with different logins and different vocabularies. One submission front door with separate versioned rule sets behind it is a build argument that survives scrutiny, because the shared parts, intake, routing, rosters, meeting management and the expiration clock, really are shared.

What each path actually costs

On the buy side, packaged review systems price by institution tier or by active protocol count. For a mid-sized academic medical centre a subscription of roughly $30,000 to $90,000 a year is common, with a first year implementation and configuration engagement of $40,000 to $150,000 on top. Read the configuration clause carefully. Several vendors in this category bill smart form and workflow changes as professional services days rather than as support. If your policy moves twice a year and each move consumes a week of vendor time, that is a recurring purchase order nobody put in the business case.

Building instead prices differently. A first release with branching submission smart forms, determination pathways, reviewer assignment, expedited and convened paths, the expiration clock queue and agenda and minutes generation runs $80,000 to $160,000 and ships in 12 to 18 weeks. A full platform adding reliance and ceded review, conflict screening against disclosures, reportable new information workflows, investigator dashboards, industry study fee billing and accreditation reporting runs $200,000 to $500,000 phased over 7 to 14 months. Budget ongoing support and hosting at roughly a fifth of build cost each year, plus a small standing allowance for regulatory maintenance.

The comparison most committees skip is analyst time. Price one full-time analyst against the difference between the two paths. If three staff each spend six hours a week chasing incomplete submissions and reconciling expiration dates by hand, that is most of a salary, and it is the number the build has to beat rather than the licence fee.

The costs that surface after go-live

Three integrations reliably cost more than the estimate. The first is the training completion feed. Almost every institution checks CITI Program records before a study team member can be listed on a protocol, and the join is by person, not by protocol. Researchers routinely hold two CITI accounts, one from a previous institution and one created with a personal address, and names change. That identity match drifts every single year, and if the system treats a missing record as a hard block, your analysts will spend more time fixing accounts than reviewing science.

The second is the grants and clinical trial management link. Protocol numbers and award numbers are assigned by different offices under different conventions and rarely match. Any reporting that crosses the two, which is most of what leadership asks for, depends on a mapping table somebody has to own.

The third is policy versioning. An auditor asks about a study approved three years ago, and the correct answer is the rule that governed it then, not the rule in force today. A system that only holds current rules cannot answer, and retrofitting effective dating after launch means rewriting the determination engine.

One deadline usually sets the schedule rather than the budget. Institutions accredited by AAHRPP are reviewed on a multi-year cycle, and the site visit asks for evidence spanning that whole period. If your reaccreditation falls in eighteen months, you either finish and have a year of clean data, or you present two systems and reconcile them by hand in front of a site visitor.

A decision test you can run in a week

Pull twenty approved submissions at random from the last eighteen months. Give them to an experienced analyst and ask four questions per submission, with email closed: which policy version governed the determination, on what date the approval expires and how that date was derived, which reviewer was assigned and whether their conflicts were screened before the vote, and where the reliance documentation sits if review was ceded. Time each one.

If the median answer takes more than a few minutes, or if any question requires opening a spreadsheet outside the system, your record is not a record. That is the finding, and it is independent of vendor marketing.

Run a second count alongside it. List every form or workflow change you asked your current vendor for in the last two years, what each cost, and how long it took to reach production. Multiply by the next two years. Buyers who do this arithmetic honestly usually discover the decision was already made for them, in one direction or the other. Neither exercise requires a vendor demonstration, and both are considerably harder to argue with than a feature comparison grid.

What to do next

Write the policy down before you write software or a request for proposal. Determination pathways, expiration derivation, quorum rules and reliance responsibilities should exist as a document your own staff agree on. Every failed project in this category started with a system built to encode rules nobody had settled.

If you buy, negotiate two things: an unrestricted data export including determination history and rule versions, and configuration changes treated as support rather than as billable days. If you build, insist on a written product requirements document before any code, because the requirement here is regulatory rather than aesthetic and it needs to be reviewed by your compliance office, not interpreted from a wireframe.

Digital Heroes insists on that document precisely because the content here is a regulatory interpretation rather than a design brief. Fifty plus staff sit behind the work, more than two thousand projects have been delivered, and three signing entities exist across India, the United States and the United Kingdom, so a university procurement office can execute the agreement and take assignment of intellectual property at home rather than abroad. If you would rather watch the team explain something technical than read a capability deck, the Digital Heroes YouTube channel carries 2.5 million subscribers.

Whichever way you go, get repository, infrastructure and data export ownership agreed in writing before kickoff. An office whose entire function is independent oversight should not depend on a vendor to answer questions about its own record.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Median SaaS spend reached $9,455 per employee, and organizations leave an average of 36% of their SaaS licenses unused. Source: Zylo (2026) →
  2. Across more than 5,400 IT projects studied by McKinsey and the University of Oxford BT Centre, large IT projects ran on average 45% over budget and 7% over schedule while delivering 56% less value than predicted. Source: McKinsey & Company / University of Oxford (BT Centre for Major Programme Management) (2012) →
  3. The share of tasks performed mainly by humans is projected to fall from 47% to 33% by 2030 as human-machine collaboration expands, with 170 million jobs created and 92 million displaced (a net gain of 78 million). Source: World Economic Forum (2025) →
  4. SaaS spend averaged $4,830 per employee (up 21.9% year over year), with large enterprises (10,000+ employees) spending roughly $284M annually and running about 660 apps, while organizations wasted an average of $21M annually on unused licenses. Source: Zylo (2025) →
FAQ

Frequently asked questions

How much does IRB review management software cost to build or buy?

Packaged systems for a mid-sized academic medical centre typically run $30,000 to $90,000 a year plus $40,000 to $150,000 of first year implementation. A custom first release covering smart forms, determination pathways, review paths and the expiration clock runs $80,000 to $160,000, with a full platform at $200,000 to $500,000. Compare both against the analyst hours currently spent chasing incomplete submissions.

How long does an IRB system implementation take?

A packaged implementation usually runs three to six months, most of which is configuring smart forms and mapping your local policy onto the product model. A custom first release ships in 12 to 18 weeks and a full platform is phased across 7 to 14 months. If AAHRPP reaccreditation is on your calendar, work backwards from the site visit rather than forwards from kickoff.

Should we migrate historical protocols into the new system?

Usually only the ones still active or likely to be audited. The pattern that works is launching with new submissions and letting legacy studies close out in the old system, which avoids re-keying protocols that will expire anyway. Keep the old system readable for the full retention period. Treat any historical migration as its own workstream with an inventory and mapping pass, not as a data load at the end.

Which integrations matter most for an IRB platform?

Three: the CITI Program training feed, your grants or clinical trial management system, and your identity provider. The training feed is the one that breaks repeatedly, because researchers hold duplicate accounts and names change, so the person level match drifts. Grants integration matters because protocol numbers and award numbers follow different conventions and need a mapping table someone owns permanently.

What staffing do we need to run a custom IRB system?

Less than people expect for operations and more than expected for policy. You do not need a developer on staff if support is contracted, but you do need one named owner of determination policy who can approve rule changes, plus an analyst who understands the queue. Institutions that skip the policy owner end up with a system whose rules drift from what the committee actually decided.

Who actually builds IRB and ethics review software?

Specialist product vendors cover the mainstream, and a handful of custom firms take institutions whose rules do not fit one. Digital Heroes works on determination logic versioned by effective date and reliance treated as a first class record, and can contract through its Indian, American or British entity, which university procurement offices tend to raise early. Its Fiverr Vetted Pro listing and record of more than two thousand projects are both checkable.

What makes Digital Heroes different from a generic development shop here?

The written product requirements document before any code. In this domain the requirement is a regulatory interpretation your compliance office has to approve, not a screen a designer can guess at, and a PRD makes the determination rules reviewable before they are expensive to change. The firm also operates ShopScore, HeroCheckout and Section Vault as products of its own, so it lives with software after launch instead of walking away at handover.

How do we verify a development partner is legitimate before paying?

Look the firm up under its D-U-N-S number first and confirm the registered business is the one that will sign. Read Clutch and Trustpilot properly, weighting entries from named institutions above anonymous ones. Establish which country law governs the agreement, since that decides your remedy if the relationship fails. Then put repository and infrastructure ownership in the contract rather than leaving it to handover.

What security features does custom project management software need?

The non-negotiables are single sign-on, role-based permissions, encryption in transit and at rest, and an audit log of who changed what. If client work under NDA lives in the tool, custom actually improves your position, because you can run single-tenant on your own cloud account instead of shared SaaS infrastructure. You only need SOC 2 certification if you plan to sell the tool to others; for internal use, an annual penetration test is the sensible spend.

What tech stack should a custom project management tool be built on?

A deliberately boring one: React on the front end, Node or Python on the API, PostgreSQL for data, and websockets for live updates, which is the stack behind most tools in this category. The test is hiring risk: if your agency proposes something a mid-level developer cannot pick up in a week, you are buying a dependency, not an asset. Save exotic choices for genuine needs like offline-first mobile.

We've outgrown ClickUp. Does that mean we need custom software?

Not automatically. First check whether ClickUp's Business tier at about $12 per user per month plus its API covers the gap, because most complaints about outgrowing ClickUp are really automation limits, not data model limits. The genuine signal for custom is structural: your work does not fit the task-in-a-list model, for example a job that must sit under two clients with separate billing at the same time. If you are paying someone monthly just to maintain workarounds, it is time to price a build.

What happens if the agency that built our project management tool shuts down?

Nothing fatal, if you set things up correctly from day one: code in your own GitHub organization, infrastructure in your own cloud account, and written deployment documentation as a contract deliverable. With those in place, any competent team can take over a standard-stack codebase in one to two weeks. Takeover disasters happen when the vendor hosted everything in accounts they owned, so verify account ownership before the first sprint, not after the relationship sours.

How many people should be working on my software project?

Three to five for a typical focused build: a project lead, one or two engineers, a designer, and part-time QA, which is the standard shape across 2,000+ Digital Heroes projects. Larger platforms justify 6 to 10, but a ten-person team on a small first version usually signals bill padding rather than horsepower. What predicts success is whether a senior engineer is writing your code daily, not the headcount on the proposal.

Who owns the code when an agency builds my project management software?

You should, in full, and the contract must say so: work-for-hire language with all intellectual property assigned to you on final payment. Watch for agencies that license you their platform or framework, because that quietly turns your custom tool back into a subscription you cannot leave. Digital Heroes assigns full ownership and delivers into a GitHub organization the client controls; treat anything less as a red flag.

I run a 15-person business. Is there a cheaper option than a full custom project management build?

Yes: a custom layer on top of a tool you already pay for. Digital Heroes ships client dashboards, automated reporting, and workflow glue built on the Asana and ClickUp APIs for $8,000 to $20,000, which fixes the specific gap without replacing the whole tool. A full custom platform rarely makes sense below roughly 50 seats unless the software faces your own customers.

What does it cost to keep custom project management software running each year?

Budget 15 to 20 percent of the original build cost annually, so a $100,000 platform costs $15,000 to $20,000 a year to run. That covers hosting, security patches, dependency upgrades, and the item buyers forget: fixing integrations when Slack, Google, or QuickBooks change their APIs, which happens every year. Skipping the maintenance budget is how a two-year-old tool becomes impossible to upgrade.

How long does it take to build custom project management software?

Plan on 12 to 16 weeks for a working first version and 6 to 9 months for a mature platform; those are typical Digital Heroes delivery timelines. The schedule killers are undecided permission rules and mid-build scope additions, not the code itself. Locking the workflow map during discovery is what keeps a build inside 16 weeks.

Who can build a custom project management software system?

Digital Heroes builds custom project management software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other project management software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply