Clinical Quality Assurance Under ICH E6(R3): Build Quality In, Don't Audit It At Lock
Most explainers stop at a dictionary entry: quality assurance is proactive and process-focused, quality control is reactive and inspection-focused. That is correct as far as it goes, and ICH E6(R3) §Glossary supplies the precise wording: quality assurance is "all those planned and systematic actions that are established to ensure that the trial is performed and the data are generated, documented (recorded) and reported in compliance with GCP and the applicable regulatory requirement(s)."
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
On this page · 11 sections
- 01 At a glance
- 02 Clinical QA in one sentence, and why the glossary definition is where teams get stuck
- 03 The four roles people blur: QA vs QC vs monitoring vs audit
- 04 What ICH E6(R3) actually changed: QA as a quality management system, not an audit checkpoint
- 05 Build quality in, don’t inspect it in: critical-to-quality factors and Quality Tolerance Limits
- 06 Risk-based quality management: the continuous QA loop
- 07 When something breaks: the CAPA and root-cause workflow QA owns
- 08 The QA SOP and documentation backbone
- 09 Where teams get it wrong
- 10 What good looks like: a clinical QA maturity checklist
- 11 Sources
At a glance
- Clinical quality assurance is not the team that grades the trial after database lock. ICH E6(R3) defines QA as “all those planned and systematic actions” established to ensure the trial is conducted and data are generated and reported in compliance with GCP, and it puts QA at the front of the trial, not the end.
- E6(R3) reframes quality as a designed-in quality management system: incorporate quality into the protocol by identifying critical-to-quality (CtQ) factors and managing risks to them, then run a continuous risk loop rather than inspecting errors after the fact.
- QA, QC, monitoring, and audit are four distinct roles. E6(R3) is explicit that audit is independent of and separate from routine monitoring and QC functions, and exists to evaluate whether your processes work, not to catch individual data errors.
- Quality Tolerance Limits (pre-specified acceptable ranges) are the trigger mechanism: when a parameter drifts beyond the range, you evaluate for a systemic issue and act, instead of waiting for a finding.
- When something breaks at the level of participant safety or data reliability, E6(R3) requires root-cause analysis, corrective and preventive action (CAPA), and confirmation of adequacy. This is the CAPA loop QA owns.
- The cost of a QA function stuck in reactive audit mode is concrete: repeated findings, inspection observations, and data a regulator may not trust.
Clinical QA in one sentence, and why the glossary definition is where teams get stuck
Most explainers stop at a dictionary entry: quality assurance is proactive and process-focused, quality control is reactive and inspection-focused. That is correct as far as it goes, and ICH E6(R3) §Glossary supplies the precise wording: quality assurance is “all those planned and systematic actions that are established to ensure that the trial is performed and the data are generated, documented (recorded) and reported in compliance with GCP and the applicable regulatory requirement(s).”
The word that teams skip is planned. Planned and systematic actions are things you design before the trial opens, not activities you perform after lock. A QA function whose only deliverable is an audit at the end of the study has read the noun and ignored the verb. The rest of this guide is about what those planned actions actually are under E6(R3).
The four roles people blur: QA vs QC vs monitoring vs audit
These four functions get collapsed into “quality stuff,” which is exactly how a finding slips through every net. E6(R3) gives each a distinct purpose. The clearest line in the guideline is that a sponsor’s audit “is independent of and separate from routine monitoring or quality control functions,” and its purpose is “to evaluate whether the processes put in place to manage and conduct the trial are appropriate.” Audit checks the system; QC checks the output; monitoring checks the sites and data; QA designs and owns the whole quality approach.
| Function | Purpose | Timing | Who | Output |
|---|---|---|---|---|
| QA | Establish planned, systematic actions and risk-based strategies to identify potential or actual causes of serious noncompliance so they can be corrected and prevented | Designed before start, applied throughout | Independent quality function | QMS, SOPs, CtQ/risk plan, CAPA oversight |
| QC | Verify that specific outputs (data, documents) meet defined requirements | Operational, ongoing, at point of work | Operational/data teams | Checks, reconciliations, query resolution |
| Monitoring | Oversee trial conduct at sites; verify higher-criticality data against source; detect deviations, outliers, and integrity problems | Continuous during conduct, extent set by risk | Sponsor monitors (on-site and/or centralised) | Monitoring visit reports, central analytics signals |
| Audit | Independently evaluate whether processes are appropriate to ensure compliance with protocol, GCP, and regulatory requirements | Periodic, proportionate to risk, when performed | Auditors independent of the process audited | Audit findings, audit report |
E6(R3) §3.4.1 frames QA as risk-based strategies to find causes of serious noncompliance and enable their corrective and preventive actions. E6(R3) §3.4.2 establishes the independence of audit. Monitoring’s job, per E6(R3) §3.3, is to verify protocol-required and higher-criticality data against source and to identify missing data, outliers, and protocol deviations. Read together, these mean audit is for assurance, not error detection. If your auditors are finding individual transcription errors, your QC and monitoring nets failed upstream.
What ICH E6(R3) actually changed: QA as a quality management system, not an audit checkpoint
Under the superseded E6(R2) model, quality assurance was widely operationalized as an end-of-study, audit-centric activity layered on top of conduct. E6(R3) changes the mandate. The guideline’s principles direct sponsors to foster a quality culture and to proactively design quality into trials, identifying factors critical to trial quality and using a proportionate, risk-based approach (E6(R3) §2). It then makes the sponsor responsible: “Sponsors should incorporate quality into the design of the clinical trial by identifying factors that are critical to the quality of the trial and by managing risks to those factors” (E6(R3) §3.1).
Quality management, in E6(R3) §3.2, is the design and implementation of efficient protocols and procedures to protect participants and ensure reliable results, and the sponsor “should adopt a proportionate and risk-based approach to quality management.” That is a quality management system (QMS), not a checkpoint. QA owns it. The practical shift for a QA lead: your first deliverable is no longer an audit schedule, it is a contribution to protocol design and a risk plan.
Build quality in, don’t inspect it in: critical-to-quality factors and Quality Tolerance Limits
The “build it in” half comes from ICH E8(R1), which E6(R3) cross-references for critical-to-quality factors. E8(R1) §3 states that quality by design “sets out to ensure that the quality of a study is driven proactively by designing quality into the study protocol and processes,” and that this means “focusing on critical to quality factors.” E8(R1) §3.2 defines CtQ factors as “attributes of a study whose integrity is fundamental to the protection of study participants, the reliability and interpretability of the study results, and the decisions made based on the study results,” and instructs that the sponsor and other parties “should identify the critical to quality factors.” E8(R1) also warns that CtQ factors “should be clear and should not be cluttered with minor issues,” and that they require periodic review because new issues arise once the study begins (E8(R1) §3.3).
The “don’t inspect it in” half is the Quality Tolerance Limit. E6(R3) §3.2 directs that, where relevant, the sponsor “should set pre-specified acceptable ranges” (quality tolerance limits at the trial level) to support the control of risks to CtQ factors, and that “where deviation beyond these ranges is detected, an evaluation should be performed to determine if there is a possible systemic issue and if action is needed.”
A worked example for one trial makes this concrete. Take a randomized cardiovascular outcomes study where the primary endpoint depends on complete follow-up.
- CtQ factor: retention and complete follow-up of enrolled participants (E8(R1) §7 names retention and follow-up as key CtQ factors).
- Risk to it: participants lost to follow-up bias the endpoint and reduce reliability.
- QTL (pre-specified acceptable range): trial-level lost-to-follow-up rate stays at or below, say, 8%.
- Signal: the rate crosses 8%.
- Response under E6(R3) §3.2: evaluate whether a systemic issue exists (one site’s process? a visit-window design flaw?) and decide if action is needed. The QTL breach is not itself a failure; it is the trigger to look.
A QTL is not the same as a routine monitoring threshold or an individual data query. It is a trial-level early-warning band tied to a CtQ factor.
Risk-based quality management: the continuous QA loop
E6(R3) §3.2 lays out the quality management activities as a continuous, named sequence, and it maps cleanly onto the ISO 31000:2018 risk management process, which E6(R3)‘s approach mirrors. ISO 31000:2018 §6.1 describes the risk management process as “the systematic application of policies, procedures and practices to the activities of communicating and consulting, establishing the context and assessing, treating, monitoring, reviewing, recording and reporting risk,” and §6.5 stresses that “although the risk management process is often presented as sequential, in practice it is iterative.” ISO 31000:2018 §6.6 states the purpose of monitoring and review is “to assure and improve the quality and effectiveness of process design, implementation and outcomes.”
The E6(R3) §3.2 loop the QA function runs:
- Risk Identification — identify risks that may have a meaningful impact on CtQ factors prior to trial initiation and throughout conduct.
- Risk Evaluation — evaluate identified risks and existing controls by likelihood, detectability, and impact on participant protection and result reliability.
- Risk Control — apply control proportionate to the importance of the risk; this is where QTLs are set.
- Risk Communication — share so that risk review and continual improvement can happen during conduct.
- Risk Review — periodically review control measures to confirm they remain effective and relevant, adding controls as needed.
- Risk Reporting — summarise and report important quality issues, including instances where acceptable ranges (QTLs) are exceeded.
The ISO backbone underlines the point E6(R3) is making: this is iterative and continual, not a single pre-trial assessment. ISO 31000:2018 §4 lists continual improvement as a principle, and its risk treatment step (§6.5.2) is itself “an iterative process” that includes “assessing the effectiveness of that treatment” and deciding whether remaining risk is acceptable. A QA program that performs risk assessment once at startup and files it has implemented neither the E6(R3) loop nor the ISO process it rests on.
When something breaks: the CAPA and root-cause workflow QA owns
QTLs and monitoring will surface problems. E6(R3) is specific about what happens next. E6(R3) §3.4.1 frames QA itself as “implementing risk-based strategies to identify potential or actual causes of serious noncompliance … to enable their corrective and preventive actions.” When the problem is serious, E6(R3) §3.5 is directive: if noncompliance that significantly affects or could significantly affect participants’ rights, safety, or well-being, or the reliability of results, is discovered, “the sponsor should perform a root cause analysis, implement appropriate corrective and preventive actions and confirm their adequacy unless otherwise justified.”
A minimal CAPA workflow consistent with E6(R3) §3.5:
- Detect and classify — a QTL breach, monitoring signal, or central analytics flag. E6(R3) §2.5 requires strategies to detect and prevent recurrence of serious noncompliance.
- Root-cause analysis — required by E6(R3) §3.5 for significant noncompliance. Treat the QTL breach as a symptom; find the systemic cause.
- Corrective action — fix the instance.
- Preventive action — change the process so it cannot recur. For protocol deviations, E6(R3) §2.5 expects measures to prevent recurrence.
- Confirm adequacy — E6(R3) §3.5 requires confirming the CAPA worked, not just that it was issued.
- Escalate when required — for serious noncompliance, notify the regulatory authority and/or IRB/IEC as applicable (E6(R3) §3.5).
The failure mode here is the “close the CAPA” reflex: an action is written, the record is closed, and nobody confirms it held. E6(R3) §3.5 does not let you stop at issuance.
The QA SOP and documentation backbone
A QA function is only as real as its written, followed procedures. E6(R3)‘s glossary defines audit partly as examination against “applicable standard operating procedures (SOPs),” so SOPs are the baseline an audit measures conduct against. A minimum SOP set for a clinical QA function maps to the E6(R3) duties cited above:
- Quality management / RBQM SOP — the risk loop (E6(R3) §3.2): identification, evaluation, control, review, reporting, plus how QTLs are set.
- CtQ factor identification SOP — aligned to E8(R1) §3.2.
- Deviation management SOP — E6(R3) §2.5 and §3.1 require classifying deviations as important and addressing recurrence.
- CAPA / root-cause SOP — E6(R3) §3.5 (RCA, CAPA, confirm adequacy, escalation).
- Audit program SOP — E6(R3) §3.4.2 (auditor independence and qualification, audit planning).
- Monitoring oversight SOP — E6(R3) §3.3 (extent and nature of monitoring driven by risk).
- TMF / essential records SOP — E6(R3) §3 expects essential records available to monitors, auditors, and regulators to enable evaluation of trial conduct.
For documentation and TMF QA specifically, E6(R3) §3 requires that essential records be available to regulatory authorities, monitors, and auditors to enable evaluation of trial conduct and confidence in results, and treats data integrity (attributable, legible, contemporaneous, original, accurate, complete) as part of being fit for purpose. TMF QA is checking that the record will support that evaluation, not box-ticking completeness. The sibling topics here are risk-based monitoring, quality tolerance limits, protocol deviations, CAPA / root-cause analysis, and TMF / essential documents; build the SOP set so those interlock rather than overlap.
Where teams get it wrong
The recurring failure is a QA team that only audits at lock. The symptoms are predictable: the same findings recur study after study because audit detects but never feeds prevention; inspection observations land on processes QA never designed; and data integrity questions surface too late to fix cleanly. Under E6(R3) this is not just inefficient, it is a misread of the mandate. QA’s job per §3.4.1 is to identify causes of serious noncompliance so they can be prevented, and audit per §3.4.2 is assurance that the system works, deliberately separate from routine error-catching.
Two more traps. First, treating QTL breaches as failures to be explained away rather than triggers to investigate; E6(R3) §3.2 frames a breach as the start of an evaluation. Second, closing CAPAs without confirming adequacy, which §3.5 explicitly requires.
What good looks like: a clinical QA maturity checklist
- QA contributes to protocol design and CtQ identification before first-patient-in, not after lock.
- A documented RBQM risk loop (identify, evaluate, control, review, report) runs continuously, with named owners.
- Trial-level QTLs are pre-specified for the CtQ factors that matter, with a defined evaluation path when a range is exceeded.
- QA, QC, monitoring, and audit have written, distinct charters; audit is staffed by people independent of the processes they audit.
- Every significant noncompliance triggers RCA plus CAPA, with adequacy confirmed and a record of recurrence prevented, not just an issued action.
- The SOP set above exists, is current, and conduct can be measured against it.
- TMF and essential records are maintained so a regulator, monitor, or auditor could evaluate conduct from the record alone.
None of this certifies compliance. Software and process can enable an E6(R3)-aligned QMS, but the sponsor remains responsible for the trial’s quality. The shift this guide argues for is one of timing and ownership: stop selling QA as the grader at the finish line, and build it as the system that designs quality in and keeps it there.
Sources
- ICH E6(R3) Good Clinical Practice, version r3 (current) — https://www.ich.org/page/efficacy-guidelines
- ICH E8(R1) General Considerations for Clinical Studies, version r1 (current)
- ISO 31000:2018 Risk management — Guidelines, version 2018 (current) — https://www.iso.org/standard/65694.html
Written by
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
Continue reading
Root Cause Analysis in Clinical Trials: How to Reach a Systemic Cause Your CAPA Can Actually Prevent
If you have an open protocol deviation or a repeat finding and you are quietly wondering whether your RCA will survive an inspection, this is for you. The honest answer in most cases is: not yet, because the RCA stopped one level too early.
ReadCritical-to-Quality Factors: A Living QbD Spine, Not a Protocol Appendix
The thing most teams get wrong about critical-to-quality factors is treating them as a deliverable. You hold a brainstorm, you copy the catalogue out of the ICH E8(R1) Annex into a protocol appendix, you get the protocol approved, and the list is never touched again. That is not Quality by Design. I...
ReadHow Long to Keep Clinical Trial Records: Retention Periods and Archiving Obligations
There is no single GCP retention period. ICH E6(R3) deliberately sets none and defers to local law, so the number comes from your jurisdiction: two years under 21 CFR Part 312, at least 25 years after the trial ends under EU Regulation 536/2014. Where they overlap, the rule is whichever is longest.
Read