GCP · Blog
Back to journal

Clinical Trial Design and Management as One Quality-by-Design Chain: From Critical-to-Quality Factors to Risk-Based Oversight

This is the pillar for clinical-operations leads, study managers, and CRAs who are scoping a new trial or onboarding to one. It is deliberately deep on the connective logic and the tables, and it names sibling playbooks (quality by design, CtQ factors, quality tolerance limits, monitoring plans, decentralized models) rather than re-explaining each in full.

GCP 12 min read
A

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.

On this page · 12 sections
  1. 01 At a glance
  2. 02 Design and management are one chain, not two jobs
  3. 03 Step 1: Fix the critical-to-quality factors at design (ICH E8)
  4. 04 Step 2: Turn each CtQ factor into a quality tolerance limit and a risk (the design-to-RBM handoff)
  5. · CtQ-to-control decision table
  6. 05 Step 3: Choose the operating model the design implies
  7. · Site-model decision table
  8. 06 Step 4: Build the management layer the model requires
  9. 07 Who owns what across the chain
  10. · Responsibility checklist across the design-to-conduct handoff
  11. 08 Where teams get it wrong: designing for the protocol but managing for the SOP
  12. 09 Sources

At a glance

  • Design and management are not two jobs joined by a glossary. They are one continuous chain: every design choice sets a critical-to-quality (CtQ) factor, and the management layer exists to defend those factors.
  • ICH E8(R1) frames quality by design as building quality into the protocol up front; ICH E6(R3) and FDA’s risk-based monitoring guidance then operationalize it through quality tolerance limits and risk-proportionate monitoring.
  • A CtQ factor is not abstract. It becomes a documented risk, a pre-specified acceptable range (a quality tolerance limit), and a monitoring signal that tells a team when the trial is drifting.
  • The operating model (site-based, decentralized, hybrid) is implied by the design, not chosen for fashion. Endpoint type, population, and data-capture risk should drive it.
  • The sponsor retains overall responsibility for quality and the reliability of trial results, even when activities are delegated. Oversight does not transfer.
  • Most deviations are not random. They are the predictable result of designing for the protocol while managing for the SOP, so the seam between the two teams is where teams get it wrong.

This is the pillar for clinical-operations leads, study managers, and CRAs who are scoping a new trial or onboarding to one. It is deliberately deep on the connective logic and the tables, and it names sibling playbooks (quality by design, CtQ factors, quality tolerance limits, monitoring plans, decentralized models) rather than re-explaining each in full.

Design and management are one chain, not two jobs

The conventional split treats design as the statistician-and-medical-writer phase that ends when the protocol is signed, and management as the clinical-operations phase that begins when sites open. That handoff is exactly where trials leak. A protocol can be elegant on paper and un-runnable at the site, and the CtQ factors that actually matter are too often discovered only after the first wave of deviations.

The regulatory frameworks do not endorse the split. ICH E8(R1) sets out that quality by design in clinical research aims to ensure study quality is driven proactively by designing quality into the study protocol and processes, rather than relying on retrospective correction. ICH E6(R3) carries the same logic forward: the sponsor should adopt a proportionate and risk-based approach to quality management, which involves incorporating quality into the design of the clinical trial and identifying the factors likely to have a meaningful impact on participants’ rights, safety and well-being and the reliability of results. The two guidelines describe one chain, not a baton pass. Design names what matters; management defends it.

Step 1: Fix the critical-to-quality factors at design (ICH E8)

The first move is to name a small set of factors whose integrity is fundamental to the trial. ICH E8(R1) states that a basic set of factors relevant to ensuring study quality should be identified for each study, and that these critical-to-quality factors are attributes whose integrity is fundamental to protecting participants and to the reliability and interpretability of results. The guideline is explicit that the sponsor and other parties designing quality into a study should identify the CtQ factors, and that they should be considered holistically so dependencies among them can be seen.

A common failure mode is over-listing. ICH E8(R1) warns that CtQ factors should be clear and should not be cluttered with minor issues. If the list reads like a 200-row risk register, it is not a CtQ list; it is noise. The factors typically cluster around a few design decisions the brief’s reader will recognize: the study population and eligibility, the endpoints and how they are measured, the key procedures, and the data flow. ICH E8(R1) reinforces that good planning derives from attention to design elements such as clear pre-defined objectives, selection of appropriate participants, methods to minimise bias, and endpoints that are well-defined, measurable, clinically meaningful, and relevant to patients.

Crucially, ICH E8(R1) makes operational feasibility a first-class design concern, not an afterthought: it states that the foundation of a successful study is a protocol that is both scientifically sound and operationally feasible. This is the sentence that collapses the design/management wall. If the protocol cannot be run at the site, the CtQ factors cannot be protected, regardless of how clean the statistics are.

For the deeper mechanics of identifying factors, open the critical to quality factors and quality by design clinical trials siblings, and the ICH E8 clinical study considerations overview.

Step 2: Turn each CtQ factor into a quality tolerance limit and a risk (the design-to-RBM handoff)

A CtQ factor that stays a noun is useless. It has to become a measurable boundary and a monitored signal. This is where ICH E6(R3) does the heavy lifting. It describes a structured risk management cycle: the sponsor should identify risks that may have a meaningful impact on CtQ factors prior to trial initiation and throughout conduct, evaluate them by likelihood, detectability, and impact, and then control them proportionately.

The control step is the pivot point. ICH E6(R3) states that, where relevant, the sponsor should set pre-specified acceptable ranges (for example, quality tolerance limits at the trial level) to support the control of risks to CtQ factors, and that these ranges reflect limits which, when exceeded, have the potential to impact participant safety or the reliability of results. It adds that where a deviation beyond these ranges is detected, an evaluation should be performed to determine if there is a possible systemic issue and whether action is needed. A quality tolerance limit, in other words, is the trial-level alarm wired directly to a design decision. (For the detail of setting and defending limits, see the quality tolerance limits clinical trials sibling.)

FDA’s risk-based monitoring guidance supplies the matching idea on the data side: it recommends that a study protocol clearly identify the procedures and data that are critical to the reliability of the study findings, and that these generally include the data supporting primary and secondary endpoints, data critical to subject safety such as serious adverse events, and the processes that underpin data integrity such as blinding and adjudication. The same guidance is blunt that not all errors are equal: it notes that a low rate of errors in baseline characteristics will not generally affect study results, whereas a small number of errors related to study endpoints can profoundly affect them. That is the entire justification for stopping 100% source data verification and monitoring by criticality instead.

The table below shows the chain end to end. It is illustrative of the logic, not a template to copy without your own risk assessment.

CtQ-to-control decision table

Design decisionCtQ factor it setsQuality tolerance limit (illustrative)RBM signal / monitoring response
Narrow eligibility for a vulnerable populationEnrolling only eligible participantsEligibility-violation rate across sites stays within a pre-specified rangeCentralized review of screen-fail and eligibility data; targeted on-site visit to outlier sites
Subjective primary endpoint (e.g., clinician-rated scale)Consistent, protocol-defined endpoint captureInter-site variance / missing-endpoint rate within rangeOn-site review of endpoint application with the investigator; FDA RBM notes interpretive endpoints may need on-site assessment
Open-label or complex-titration designMaintenance of the blind / dosing integrityUnblinding events or dosing errors at or near zeroIntensified, higher-frequency monitoring of blinding and IP accountability
High SAE-likelihood populationTimely, complete safety reportingSAE reporting latency within rangeReal-time centralized data review for missing or late safety data

The point of the table is the arrows, not the rows: a quality tolerance limit that is not traceable back to a design decision is decoration, and a monitoring activity that is not traceable to a CtQ factor is busywork.

Step 3: Choose the operating model the design implies

Decentralized versus traditional is not a brand decision; it is a consequence of the design. FDA’s RBM guidance lists the factors that should drive monitoring type, frequency, and intensity, and they are all design attributes: complexity of the study design (more intensive monitoring as complexity increases, with adaptive or stratified designs and complex titrations called out), the type of study endpoints (interpretive or subjective endpoints may need on-site assessment, while objective endpoints like laboratory values are more amenable to remote verification), the clinical complexity of the population, and geography.

ICH E6(R3) confirms the model is part of the strategy: it states the monitoring approach should consider the activities and services involved, including decentralised settings, and be included in the monitoring plan. It also expands the monitoring toolkit beyond the on-site visit, describing centralised monitoring as an evaluation of accumulated data performed in a timely manner by the sponsor’s qualified persons, which can complement and reduce the extent or frequency of site monitoring, or be used on its own. FDA’s guidance pushes in the same direction, encouraging greater reliance on centralized monitoring than was historically the case, while cautioning that it would be appropriate only in exceptional circumstances to rely entirely on centralized monitoring.

That is a genuine tension worth stating plainly rather than smoothing over. ICH E6(R3) permits centralised monitoring to be used on its own; FDA’s RBM guidance permits heavy reliance on centralized monitoring but adds that it may still be advisable to conduct at least one on-site visit per site, preferably early, particularly for trials intended to support marketing applications. The two are not contradictory, but they are not identical in emphasis, and a US-facing sponsor should plan to the more conservative on-site expectation rather than assume the broader ICH latitude.

Site-model decision table

Trial attributeLeans traditional / site-basedLeans decentralizedLeans hybrid
Visit and procedure complexityHigh (infusions, imaging, in-clinic assessments)Low (self-report, wearables, remote labs)Mixed: in-clinic for key procedures, remote for follow-up
Population reach and burdenConcentrated near sitesGeographically dispersed, mobility-limitedBroad reach with periodic central visits
Data-capture riskSource mostly paper/local, harder to access remotelyStrong EDC and remote source accessPartial remote access
Endpoint typeSubjective/interpretive, benefits from on-site reviewObjective, remotely verifiableMixed endpoints
Regulatory destinationUS marketing application (expect early on-site visit)Lower-risk or exploratoryEither, planned to the stricter expectation

For the deeper operational playbooks, route to the decentralized clinical trials and risk based monitoring / remote monitoring siblings.

Step 4: Build the management layer the model requires

Once the model is set, the management layer is largely determined. ICH E6(R3) requires the sponsor to develop a monitoring plan tailored to the identified potential safety risks, the risks to data quality, and other risks to the reliability of results, with particular attention to procedures relevant to participant safety and to trial endpoints, and the plan should focus on aspects that are critical to quality. FDA’s RBM guidance echoes this, recommending that each sponsor design a monitoring plan tailored to the specific human-subject-protection and data-integrity risks of the trial, identifying the methods to be used and the rationale for their use. (See the clinical trial monitoring plan sibling for the full document anatomy.)

Two adjacent management artifacts hang off the same CtQ list. Medical and data-safety monitoring follow from the safety-related CtQ factors, and the data-management layer follows from the data-flow factors: ICH E6(R3) describes quality control applied using a risk-based approach to each stage of data handling to ensure data are reliable and processed correctly, and centralised monitoring that uses data analytics to identify missing data, outliers, and protocol deviations. These are covered in depth by the medical and data-safety monitoring plans and clinical trial data management plan siblings. Registry and disclosure obligations sit alongside the database but are routed to their own sibling; this pillar does not cover registration mechanics.

The discipline here is that the management layer should be the mirror image of the CtQ list. If a monitoring plan monitors things no CtQ factor named, or fails to monitor a factor the design set, the seam has already leaked.

Who owns what across the chain

Responsibility is where the design-to-conduct handoff most often fails on paper. The non-negotiable principle in ICH E6(R3) is that the sponsor may transfer, and the investigator may delegate, tasks, but they retain overall responsibility for their respective activities. The guideline states that where activities are transferred or delegated to service providers, the responsibility for the conduct of the trial, including the quality and integrity of the trial data, resides with the sponsor or investigator respectively, and that they should maintain appropriate oversight. On the site side, ICH E6(R3) is equally clear that the investigator retains ultimate responsibility and should maintain appropriate oversight of any delegated activities, proportionate to the importance of the data and the risks to participants. Monitoring itself, per ICH E6(R3), should be performed by persons not involved in the clinical conduct of the trial at the site being monitored.

The following RACI-style checklist maps the design-to-conduct handoff. Use it as a starting structure; the actual allocation depends on your delegation agreements.

Responsibility checklist across the design-to-conduct handoff

ActivitySponsorInvestigator / siteMonitor
Identify CtQ factors at designAccountableConsulted (feasibility input)Informed
Define risks and set quality tolerance limitsAccountableInformedConsulted
Write the monitoring planAccountableInformedConsulted
Conduct the trial per protocol at the siteOversightAccountableVerifies
Delegate site tasks and document delegationInformedAccountableVerifies
Execute on-site and centralized monitoringAccountable (oversight)Provides accessResponsible
Review breached tolerance limits for systemic issuesAccountableConsultedResponsible (signal)
Retain overall responsibility for data integrityAccountable (never transfers)Accountable for site dataInformed

The single most important cell is the last row. Under ICH E6(R3), delegation moves the task, never the accountability. Software and service providers can enable compliant conduct, but the sponsor and investigator remain responsible; no tool or CRO “makes a trial compliant.”

Where teams get it wrong: designing for the protocol but managing for the SOP

The recurring failure is a mismatch of reference documents. The design team optimizes against the protocol and the scientific question. The operations team executes against standard operating procedures that were written for the last trial, not this one. When the protocol’s CtQ factors and the SOP’s monitoring routines do not line up, deviations are not bad luck; they are structural.

ICH E8(R1) anticipates this. It states that adherence to the study protocol is essential and that many aspects of adherence should themselves be considered among the study’s CtQ factors, and that successful application of quality-by-design principles may minimise the need for protocol modifications and make adherence more likely. ICH E8(R1) also treats retention and follow-up of participants as key CtQ factors and links feasibility considerations back into design. In practice this means three habits:

  • Build the monitoring plan from the CtQ list, not from a template. FDA’s RBM guidance frames the monitoring plan as focusing on the critical data and processes identified by the risk assessment, which only works if the risk assessment is anchored in the design.
  • Treat operational feasibility as a design output, not an operations problem. ICH E8(R1) names the operationally feasible protocol as the foundation of a successful study.
  • Review CtQ factors as the trial runs. ICH E8(R1) calls for periodic review of CtQ factors to determine whether adjustments to risk control mechanisms are needed, because new or unanticipated issues may arise once the study has begun, and ICH E6(R3) requires the sponsor to periodically review risk control measures and add controls as needed.

Read this way, design and management stop being two teams arguing across a handoff. They become one quality-by-design chain that a CRA, a study manager, and an inspector can all trace from a single design decision to the signal that proves it held. From here, open the deep sibling for whichever link you are about to build next.

Sources

  • ICH E8(R1) General Considerations for Clinical Studies — ICH, version r1 (2021)
  • ICH E6(R3) Good Clinical Practice — ICH, version r3 (2025) — https://www.ich.org/page/efficacy-guidelines
  • FDA Guidance: Oversight of Clinical Investigations — A Risk-Based Approach to Monitoring — FDA, version 2013
A

Written by

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.