Skip to content
§
§ · hiring guide

How to Hire an IRB and Research Compliance Software Development Company

Get a configuration quote from a packaged vendor first, then a build quote, and compare them honestly.

Internal Tools Development product interface illustration for IRB AND Research Compliance Software.
The short answer

Get a configuration quote from a packaged vendor first, then a build quote, and compare them honestly. In this category the product is largely a configuration shell, so when the configuration estimate passes roughly $250,000 you are already paying for a build you will not own. A first release runs $80,000 to $160,000 over 12 to 18 weeks.

Hiring for an IRB system is closer to commissioning a court reporter than commissioning software. What you are actually buying is the record, and the record is only read closely on the day something has already gone wrong: a participant enrolled on a Tuesday against an approval that expired the previous Friday, a determination questioned two years later, an inspection that asks how you followed up with the investigators who never responded. Nothing about that day is visible while the system is being demonstrated to you.

The category is also unusual in a way that changes the buying decision. Huron, Cayuse, IRBNet and Advarra are all configurable and all get configured, at length, by consultants. Human research protection programme directors rarely complain that the products are bad. They complain that making a packaged system reflect local policy took longer and cost more than building the thing outright, and ended with a system nobody at the institution can change without raising a change request. Before you compare development firms, get the configuration number, because it is the honest benchmark.

What an IRB software development company actually does

The visible artefact is a submission form. That form is your policy, which is why configuration keeps failing. It is a decision tree encoding which questions appear when a study involves children, prisoners, pregnant women or people with impaired consent capacity, when an authorisation or a waiver is required, when the study is regulated by the Food and Drug Administration and therefore carries obligations the Common Rule does not impose, and what your institution adds above the federal floor.

Building it properly means the form is a versioned decision graph with branching held as data and the version stamped onto every submission, so a study submitted three years ago still renders under the form it was actually submitted against. It means completeness validation before submission rather than after, which is the single change that most reduces coordinator workload, because the administrative pre review becomes something the form already did. It means pathway determination that proposes a category with the specific criteria that matched and records the analyst's confirmation or override. It means a review regime derived per study rather than one global expiration rule, with escalation that ends in an automatic administrative hold instead of a reminder nobody reads. And it means dual framework tracking, because a study can be exempt under one set of rules while remaining regulated under another, and that overlap is where determinations go wrong.

What it really costs in 2026

Digital Heroes delivery bands for human research protection work, assuming an institution with an active portfolio rather than a small teaching college.

ScopeCostTimeline
Versioned smart form with branching logic and pre-submission completeness validation$35,000 to $70,0005 to 8 weeks
First release: pathway determination, convened meeting with live quorum, expiration and modification engine$80,000 to $160,00012 to 18 weeks
Full platform: reliance with scoped external access, reportable new information, conflict of interest, grants and clinical integrations$200,000 to $500,0008 to 14 months
Policy documentation workstream run alongside the build$15,000 to $35,0003 to 6 weeks

Two line items are missing from most quotes and both are yours. The first is writing down the policies that currently exist as practice. Every programme has determination criteria that live in an experienced analyst's judgement rather than in a manual, and those cannot be encoded until somebody writes them. Institutions with a current written policy manual move noticeably faster than those relying on institutional memory, and that difference shows up in the schedule rather than the invoice.

The second is electronic signature scope. If your portfolio includes records regulated by the Food and Drug Administration, whether signatures need to meet Part 11 expectations is a design decision made at the start of the project. It is not a feature added in month nine, and a firm that has not raised it before quoting has not built for a regulated portfolio.

Signals of a strong partner

  • They explain the dual framework without being prompted. A study can be exempt under the Common Rule and still regulated as a drug or device study, and a firm that does not know this will encode one answer where two are needed.
  • Form versioning is their first architectural point. Old submissions must render under the form version they were submitted against, or your historical record becomes unreadable at the first policy change.
  • They refuse to fully automate determinations. The system proposes with matched criteria and a human confirms or overrides with a recorded reason. Anyone offering automatic determinations has misread where the liability sits.
  • Quorum is computed live, not checked afterwards. Including the requirement for a member whose primary concerns are nonscientific, with the chair warned the moment a recusal or a departure breaks it.
  • They ask what your review regimes actually are. Institutions now run several at once, and a single global expiration rule either creates work that is not required or misses a deadline that is.
  • They plan the policy documentation workstream explicitly. With named hours from your programme staff, because that is where the schedule genuinely goes.
  • They ask about Part 11 before quoting. Signature architecture is a start of project decision, and raising it early is a reliable marker of regulated experience.

Red flags

  • The form is a template that gets edited in place. The first policy change silently rewrites how every historical submission renders, which is disqualifying for a compliance system.
  • Determination is offered as an automated feature. That moves regulatory judgement into software and leaves your analysts unable to explain a decision an inspector questions.
  • Escalation stops at an email reminder. Lapses happen during leave and turnover, and only an automatic administrative hold reliably prevents an enrolment against an expired approval.
  • Reliance is described as document sharing. External sites need scoped accounts seeing exactly one study and their own site documents, with local context and training verification held as site records.
  • No question about whether your policies are written down. A firm that assumes your criteria are documented has not worked with a human research protection programme before.

Questions to ask on the first call

  1. Explain the difference between exempt with limited review and expedited review, and how a study can be exempt while remaining subject to drug or device regulation.
  2. How is the submission form versioned, and can a submission from three years ago be rendered under its original form version?
  3. How does the system propose a review pathway, and what does it record about the analyst who confirmed or overrode it?
  4. How is quorum computed during a convened meeting, including the nonscientific member requirement?
  5. How are declared conflicts enforced so a member is excluded from a vote before the meeting rather than during minutes review?
  6. How does each study get its own review regime, and what triggers an administrative hold?
  7. How would an external relying site access one study without seeing anything else?
  8. What is your position on electronic signatures for regulated records, and when is that decided?
  9. What do we own on the last day, and how do we export the complete record set on our own authority?

A simple way to decide

Run the comparison properly. Get the packaged vendor's full configuration quote including consultant days, then buy a paid discovery phase from your two strongest build candidates, capped at four weeks and a fixed fee. What the discovery buys you is a written specification you own: the smart form expressed as a versioned decision graph, your determination criteria written down for the first time, the review regimes mapped per study type, the reliance model, the signature architecture decision argued explicitly, and acceptance criteria any competent firm could build against.

Even if you then configure a packaged product, that specification makes the configuration project shorter and the vendor's estimate defensible. If you build, it is the contract. Digital Heroes works PRD first for exactly this reason, and contracts through India LLP, US LLC and UK LTD entities so intellectual property assigns under law your own counsel already reads. Your IRB records are the evidence in any federal inspection and should never sit somewhere you cannot access or change on your own authority.

Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Per the Standish Group CHAOS 2020 report (reviewed at this URL), across tens of thousands of software projects roughly 31% end successfully, about 50% are 'challenged', and roughly 19% fail outright; small projects succeed far more often than large ones, and Agile approaches succeed at markedly higher rates than Waterfall. Source: The Standish Group (2020) →
  2. McKinsey found that tech debt can amount to 20-40% of the value of a company's entire technology estate before depreciation, and CIOs report that 10-20% of the budget for new products is diverted to resolving tech-debt issues. Source: McKinsey & Company (2020) →
  3. The right combination of digital transformation actions can unlock as much as US$1.25 trillion in additional market capitalization across Fortune 500 companies, while the wrong combinations put more than US$1.5 trillion at risk; companies with all three core factors (strategy, aligned technology, and change capability) saw a 5% market-value lift relative to peers. Source: Deloitte (2023) →
  4. The performance gap between digital and AI leaders and laggards is widening: McKinsey reports leaders pull ahead on shareholder returns, and the average maturity spread between top and bottom performers jumped ~60% (from 10 points in 2016-19 to 16 points in 2020-22), reinforcing that the returns to transformation concentrate among top performers. Source: McKinsey & Company (2023) →
FAQ

Frequently asked questions

How much does it cost to hire a company to build IRB software?

A versioned smart form with branching logic and pre-submission validation runs $35,000 to $70,000 over five to eight weeks. A first release adding pathway determination, convened meeting management with live quorum and the expiration engine runs $80,000 to $160,000 over 12 to 18 weeks. A full platform with reliance, reportable new information, conflict of interest and grants or clinical integrations reaches $200,000 to $500,000 across 8 to 14 months.

Is building genuinely cheaper than configuring Huron or Cayuse?

Sometimes, and this is one of the few categories where that is honestly true. The packaged products are largely configuration shells, so a configuration project for a complex programme can exceed the cost and timeline of a purpose built system while leaving you unable to change anything without a change request. A workable rule of thumb: if the configuration estimate exceeds roughly $250,000, get a build quote before signing. Below that, configure.

What is the most important architectural question to ask?

Whether the submission form is versioned, and whether a submission from three years ago still renders under the form version it was actually submitted against. Systems that edit the current form in place make the historical record unreadable after the first policy change, which for a compliance system is disqualifying. Ask for a demonstration rather than an assurance, because the answer is easy to give and harder to show.

What usually makes an IRB build run late?

Not engineering. It is the number of local policies that exist as practice rather than as written policy, since determination criteria living in an experienced analyst's judgement have to be documented before they can be encoded. Programmes with a current written policy manual move noticeably faster. The other schedule risk is electronic signature scope for regulated records, which has to be decided at the start rather than added later.

Who owns the code and the IRB records if an agency builds the system?

You should own the repository, the cloud infrastructure accounts and the unrestricted right to hire another firm, written into the contract before kickoff. Digital Heroes assigns code from the first commit and contracts through India LLP, US LLC and UK LTD entities so assignment sits under your own law. IRB records are the evidence in any federal inspection and must never live inside a system you cannot access or modify on your own authority.

How do I know when spreadsheets are no longer enough to run my operations?

Replace the spreadsheet once more than three people edit it, versions travel by email, or a single broken formula could cost real money. Other reliable signals: staff keep personal shadow copies, month-end reporting takes days of manual assembly, and nobody can say who changed a number or why. In Digital Heroes discovery calls the tipping point is almost always a specific expensive error, a mispriced quote, a missed order, or payroll built on a tab someone sorted wrong.

When does a company outgrow Airtable?

The usual breaking points are record limits, permissions, and automation complexity. Airtable's Team plan caps each base at 50,000 records and Business at 125,000, so operations logging thousands of rows a month hit the ceiling within a year or two. The other trigger Digital Heroes sees constantly is permissions: restricting who can view specific fields or records is clumsy below Airtable's Enterprise tier, which becomes a genuine problem once salaries, pricing, or client contracts live in the base.

How long does it take to build an internal tool from scratch?

A working first version typically ships in 4 to 8 weeks, and larger multi-module tools run 10 to 16 weeks. Across Digital Heroes internal tool projects the schedule splits into roughly one week of process mapping, 3 to 6 weeks of build, and 1 to 2 weeks of testing with your actual staff. The most common delay is not development but waiting on the client for sample data and workflow decisions, so name one internal owner before kickoff.

What happens to my software if the agency shuts down or we stop working together?

Nothing dramatic, if the engagement was set up correctly: the code sits in your repository, hosting runs on your cloud account, and a handover document explains how to deploy and operate the system. Any competent replacement team can then take over in days rather than months. If the agency controls the repo, the servers, or the domain, fix that now, because renegotiating access during a dispute is the most expensive place to discover the problem.

Can I build my product on a no-code tool like Bubble instead of hiring developers?

For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.

Will a custom internal tool scale as our company grows?

Yes, provided it sits on a standard stack with a real database: PostgreSQL comfortably handles millions of records, and adding users costs hosting pennies rather than per-seat fees. The real scaling risks are organizational, not technical: new departments want features, processes change, and the tool needs a budget line to evolve. Set aside a small quarterly improvement budget instead of treating launch as the finish line, and the tool stays useful for a decade rather than getting rebuilt every two years.

How many people should be working on my software project?

Three to five for a typical focused build: a project lead, one or two engineers, a designer, and part-time QA, which is the standard shape across 2,000+ Digital Heroes projects. Larger platforms justify 6 to 10, but a ten-person team on a small first version usually signals bill padding rather than horsepower. What predicts success is whether a senior engineer is writing your code daily, not the headcount on the proposal.

Who owns the code when an agency builds our internal tool?

You should, outright, with full IP transfer in the contract and the code delivered to a repository you control, such as your own GitHub organization. Digital Heroes transfers complete ownership on final payment as standard practice, and any agency that keeps the code or licenses it back to you is building a dependency you will pay for later. Confirm you also own the hosting, domain, and database accounts, since many of the vendor disputes Digital Heroes gets called into involve infrastructure registered under the agency's name.

Who owns the code when an agency builds my software?

You should, completely, through a written intellectual property assignment that transfers everything on final payment; without that clause, copyright stays with whoever wrote the code by default. Insist that the repository lives in your own GitHub organization from day one and that hosting, domains, and third-party accounts are registered to you. Also check for licenses to the agency's proprietary frameworks buried in the contract, because those can make switching vendors practically impossible even when you own your own code.

We run everything on spreadsheets and Airtable. How do we know it's time for custom software?

The reliable signals are re-typing the same data into multiple tools, one employee acting as human middleware between systems, and errors appearing in handoffs between teams. Hard limits force the issue too: Airtable's Team plan caps at 50,000 records per base, and Business costs $45 per seat per month, so a 20-person team pays about $10,800 a year for a tool it has already outgrown. When workarounds consume more hours than the tools save, the spreadsheet era is over.

Should we build the whole internal tool at once or start with an MVP?

Start with a version that fully replaces one workflow, ship it in 4 to 6 weeks, and let real usage set the roadmap. Internal tools have a captive audience, so you learn within days which features matter, and across Digital Heroes projects roughly a third of initially requested features never get built once staff work with version one. Phasing also spreads the spend: a $40,000 vision becomes a $15,000 phase one that starts paying for itself while phase two is scoped.

How many SaaS seats do we need before building custom becomes cheaper?

The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.

What does it cost to keep an internal tool running after launch, and do we need to hire a developer?

Budget 15 to 20 percent of the build cost per year, so a $25,000 tool runs roughly $300 to $400 a month covering hosting, security patches, dependency updates, and small tweaks, figures drawn from Digital Heroes maintenance contracts. You do not need an in-house developer; a monthly retainer with the agency that built it covers the typical internal tool comfortably. Hosting itself is cheap for internal audiences, often $20 to $100 a month, because you serve dozens of users rather than the open internet.

Is a custom internal tool secure enough for HR records and financial data?

A properly built custom tool is generally safer for sensitive data than the shared spreadsheet it replaces, because you get role-based access, audit logs, encrypted storage, and the ability to cut one person's access instantly. Ask the agency specifically for encryption in transit and at rest, permissions down to the field level, and an audit trail showing who viewed or changed each record. If HIPAA, GDPR, or SOC 2 expectations from enterprise clients apply to you, raise it before the quote, because compliance features add real scope.

What questions should I ask a development agency on the first call?

Ask who exactly will build it, what happens when scope changes mid-project, what their maintenance terms are after launch, and what they will need from you every week. Then ask them to describe a project that went wrong and what they changed afterward; teams that have shipped at real volume have war stories, and teams claiming a perfect record are hiding something. The scope-change answer matters most: a disciplined shop describes a written change-order process, not a vague promise to be flexible.

Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply