← Insights

Beyond the MTA: Coordinating Multi-Centre Research Without the Legal Bottleneck

Multi-centre studies lose 6-12 months to CTA, MTA and data-sharing negotiations. Standardised, code-enforced agreements change the shape of that problem without replacing legal review.

24 August 2026 9 min read DimenChain
Figure 1One coordinating site, four participating sites, milestones recorded along a shared timeline.
6–12 Months lost to contracts
CTA · MTA · DSA Agreements per site
Arbiscan Where logs are hashed

Ask any principal investigator what actually killed the timeline on their last multi-centre study, and you will rarely hear about the science. You will hear about the contracts. A protocol that four sites agreed on in a single afternoon takes the better part of a year to become an operational study, because four institutional legal departments must first agree on indemnity wording, publication embargoes, background intellectual property, data controllership and the precise definition of a deliverable.

This is the coordination layer of modern research, and it is where a great deal of public funding quietly disappears. Multi-centre scale-up traditionally requires months of negotiating Clinical Trial Agreements, Material Transfer Agreements and separate data-sharing contracts. By the time every institution’s legal office has signed, projects are routinely delayed by six to twelve months and the grant has been drained by administrative overhead before a single patient is enrolled or a single sample is shipped.

The instinctive response is to blame the lawyers. That is the wrong diagnosis. Institutional legal review exists for good reasons: liability is real, patient data is genuinely sensitive, and universities have obligations to their funders and their populations. The problem is not that review happens. The problem is the shape of the negotiation — bilateral, bespoke, and repeated once per pair of institutions, with no shared operational substrate underneath it.

The bilateral web is the bottleneck

Consider a clinical group that has tested a device successfully in one hospital and now needs to expand to three other EU hospitals to satisfy regulatory requirements. On paper this is one study. In administrative reality it is a web of separate instruments: a CTA with each site, an MTA wherever physical material moves, a data-processing arrangement wherever personal data is involved, and a separate understanding — often informal, often unwritten — about who gets authorship, who owns any resulting IP, and what happens if one site under-recruits.

Each of those instruments is negotiated from a different starting template, by a different office, with a different risk appetite. The negotiations cannot fully parallelise, because a concession made to site two changes what site three will accept. Meanwhile the sponsor’s operational reality — recruitment rates, protocol deviations, data completeness — is tracked in whatever spreadsheets and email threads each site happens to use, reconciled retrospectively during monitoring visits.

Two distinct failures are compounded here. The first is legal-administrative: the same terms are renegotiated from scratch, repeatedly. The second is operational: even after signature, there is no shared, tamper-evident record of what each site actually did and when. Most platforms address one or the other. The interesting question is what changes when the agreement and the operational record are the same object.

One workspace, standardised terms, enforced execution

DimenChain approaches multi-centre coordination through a master workspace rather than a set of bilateral relationships. A sponsor or coordinating investigator establishes a single multi-centre workspace and defines standardised, localised on-chain milestones for each participating site. Sites join through cryptographic workspace invitations, which means participation is provable and access is bound to a verified identity rather than to a mailing list.

Within that workspace, the terms that usually live in a hundred pages of prose are expressed as a smart-contract agreement covering four concrete things: research credit, data delivery expectations, milestone definitions, and milestone payouts. These are the clauses that most often turn into disputes, and they are also the ones most amenable to standardisation. What percentage of contribution does site three hold. What constitutes a delivered dataset. What triggers a payment. When those are encoded once and reused across every site in the study, the negotiation stops being four bespoke documents and becomes a review of one standard instrument with site-specific parameters.

The operational half runs alongside it. Participating sites upload hashes of their daily clinical logs to Arbitrum, verifiable on Arbiscan. The raw clinical data never leaves the site’s own systems — only the cryptographic fingerprint is published. What this produces is a continuous, independently verifiable record of data integrity across all sites in real time, rather than a reconstruction assembled during a monitoring visit eight months later. If a log is altered after the fact, the hash no longer matches, and the discrepancy is evident to everyone with access to the workspace, including the sponsor and, where appropriate, an auditor.

Credit accrues automatically as milestones complete. Contributions are recognised with Soulbound Tokens — non-transferable records bound to the contributor — so that a site’s or an individual’s demonstrable role in a study travels with them independently of whether they are named on the eventual paper. Governance decisions within the workspace use weighted voting tied to equity stake, so the party carrying most of the risk carries proportionate influence over changes.

A smart contract is an execution layer, not a legal jurisdiction. It does not replace the agreement — it makes the agreement’s operational half self-executing and auditable.

StepTodayWith on-chain agreements
Site agreement termsNegotiated per institutionStandardised template, signed cryptographically
Milestone creditingManual, reconciled laterAutomatic on completion
Data integrity across sitesTrust and periodic auditDaily log hashes, independently checkable
Ethics approvalRequiredUnchanged — still required
Regulatory obligationsRequiredUnchanged — still required
Institutional legal reviewRequiredUnchanged — still required
Table 1 — What standardised, code-enforced agreements change — and what they leave exactly as it was.

The contribution problem: finding partners without exposing the idea

Multi-centre coordination is one half of the collaboration problem. The other half is finding the collaborator at all, which today largely means cold-emailing strangers and describing an unprotected idea in enough detail to make it interesting — with no timestamp, no agreed terms, and no recourse if the recipient simply proceeds without you.

Take a computational biology group that designs candidate molecular structures using machine learning but owns no wet lab. Its entire pipeline is blocked on physical validation it cannot perform. Rather than approaching laboratories individually and disclosing the work in advance of any agreement, the group can post an open collaborator role in its workspace with a defined 15 per cent project equity share locked in a smart contract. A wet lab takes the role, runs the physical validation, and if the work is subsequently licensed, royalties are routed automatically on an 85/15 split according to the terms already agreed. Nobody negotiates the split after the money appears, which is precisely the moment at which such negotiations become adversarial.

The same structure scales down to narrow, well-defined problems. A materials-science team blocked on a specific chemical stabilisation issue can post a targeted bounty offering either a 3 per cent royalty or a €5,000 stablecoin payment on verified completion. The problem is stated, the reward is stated, the verification condition is stated, and the payout executes when the condition is met. That is a substantively different proposition from an unanswered email to a department three countries away.

Throughout, the privacy model is deliberately conservative. Raw research data stays off-chain, under the control of the institution that generated it. Only encrypted metadata, hashed proofs and contract events are written to Arbitrum. The chain records that something happened, when, and under what terms — never the substance of what was recorded. This is what makes the model GDPR-aligned rather than GDPR-adjacent, and it is the correct default for any platform handling material adjacent to clinical data.

What this does not do

Any honest account of this technology has to be equally clear about its boundaries, because the failure mode of the sector has been overclaiming. Nothing described above removes any of the following:

  • Institutional legal review. Your legal office still reviews and signs the agreement. What changes is that it reviews one standardised instrument with site-specific parameters rather than four bespoke documents drafted from four different templates. Review remains; redrafting largely does not.
  • Ethics approval. No ethics committee has been replaced by anything, anywhere. Every site still obtains its own approval under its own national process, on its own timeline, and the study does not begin without it.
  • Regulatory obligations. Sponsor duties, clinical trial registration, adverse-event reporting, device and medicinal-product requirements, inspection readiness — all unchanged. An immutable audit trail may help you evidence compliance. It does not constitute compliance.
  • National contract law. The enforceable agreement between institutions is the legal agreement, governed by a chosen jurisdiction and adjudicated by courts. Code executes the terms; it does not confer them.
  • Data-protection accountability. Controller and processor roles, lawful bases, and cross-border transfer assessments remain the institution’s responsibility. Keeping raw data off-chain is a sound architectural choice, not a legal exemption.

What smart contracts genuinely contribute is narrower and more useful than the marketing around the technology usually suggests: standardisation of terms that are needlessly renegotiated, automatic execution of obligations once conditions are met, a tamper-evident audit trail spanning every site, and attribution of credit that does not depend on anyone’s memory or goodwill. Those four things are worth a great deal in a multi-centre study. They are not a substitute for governance, and DimenChain does not present them as one.

Where the boundary actually sits

Legal layer

Jurisdiction, liability, indemnity, warranties, termination, dispute resolution, publication policy, background IP. This remains prose, reviewed by lawyers, signed by authorised signatories, and enforceable in a national court. It is not going anywhere, and it should not.

Execution layer

Milestone definitions and completion, contribution percentages, payout triggers, credit attribution, data-delivery evidence, access control, and the integrity record. This is where deterministic code performs better than an email thread, because it executes identically for every site, leaves a record nobody can quietly amend, and does not depend on a coordinator remembering to act.

Confusing the two layers is how this technology gets discredited. Keeping them distinct is how it becomes useful. The legal instrument says what the parties owe each other; the execution layer makes sure that what was agreed is what actually happens, visibly, across four hospitals in four countries, without a coordinator chasing spreadsheets.

A realistic expectation

The honest claim is not that multi-centre studies become frictionless. It is that a meaningful portion of the six-to-twelve-month delay is spent renegotiating terms that did not need renegotiating, and reconciling operational records that could have been verifiable from the first day. That portion is addressable now, with a standard master agreement, code-enforced milestones and a shared integrity record — while ethics, regulatory and legal review proceed on their own timelines, as they must.

DimenChain operates on Arbitrum, keeps raw research data off-chain by design, is built to align with GDPR, and is protected under WIPO PCT/IB2024/058791. It launches from the Netherlands into a European research environment where cross-border collaboration is the norm and the administrative cost of that collaboration is one of the least examined line items in the sector. Reducing that cost does not require replacing the institutions. It requires giving them a shared substrate to work on.

See this on your own research

A short walkthrough with the team, using your institution’s actual workflow.

Log in →