GCP · Blog
Back to journal

Critical-to-Quality Factors: A Living QbD Spine, Not a Protocol Appendix

The thing most teams get wrong about critical-to-quality factors is treating them as a deliverable. You hold a brainstorm, you copy the catalogue out of the ICH E8(R1) Annex into a protocol appendix, you get the protocol approved, and the list is never touched again. That is not Quality by Design. It is a compliance artifact pretending to be one. Done properly, your CtQ set is the live spine of the whole risk-based quality management (RBQM) system: a short, prospectively identified, risk-scored set that drives your quality tolerance limits, your monitoring plan, and the scope of source data verification, and that gets reviewed and adjusted as the trial teaches you things. This guide shows how to build that spine and keep it alive. It assumes GCP fluency and sits alongside our pillar on quality by design in clinical trials and our companion pieces on quality tolerance limits, risk-based quality management, risk-based monitoring, and the clinical trial monitoring plan.

GCP 11 min read
A

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.

On this page · 10 sections
  1. 01 At a glance
  2. 02 What “critical to quality” actually means in ICH E8(R1)
  3. 03 E8 CtQ factors vs E6(R3) “critical data and processes”: the design-to-conduct handoff
  4. 04 The identify-assess-control-review loop, with ISO 31000 vocabulary
  5. 05 Narrowing the E8 Annex catalogue into a short, study-specific set
  6. 06 A worked CtQ identification and scoring table
  7. 07 Wiring each CtQ factor downstream: QTLs, monitoring, and SDV scope
  8. 08 Keeping it live: review cadence, triggers, and documenting changes
  9. 09 Where teams get it wrong
  10. 10 Sources

At a glance

  • Critical-to-quality (CtQ) factors are the attributes of a study whose integrity is fundamental to participant protection and to the reliability and interpretability of results. ICH E8(R1) §3.2 defines them, and they should be identified prospectively, at design time.
  • A 40-item CtQ list is a failure mode. ICH E8(R1) §3.2 is explicit that the factors should be prioritised to the few that are genuinely critical and not cluttered with minor issues.
  • E8(R1) frames CtQ broadly at the design stage; ICH E6(R3) operationalises the same idea at conduct stage as the data and processes critical to trial quality that drive risk identification, the monitoring plan, and quality tolerance limits (QTLs).
  • ISO 31000:2018 supplies the risk vocabulary underneath the scoring: likelihood (chance of something happening) combined with consequence (the outcome affecting objectives), then evaluation against pre-set criteria.
  • A CtQ factor that does not change what gets monitored is dead weight. ICH E6(R3) §3.11.4.3 requires the monitoring plan to focus on aspects critical to quality.
  • CtQ factors are not static. Both E8(R1) §3.3.4 and E6(R3) require proactive review and adjustment when new or unanticipated issues arise during the trial.

The thing most teams get wrong about critical-to-quality factors is treating them as a deliverable. You hold a brainstorm, you copy the catalogue out of the ICH E8(R1) Annex into a protocol appendix, you get the protocol approved, and the list is never touched again. That is not Quality by Design. It is a compliance artifact pretending to be one. Done properly, your CtQ set is the live spine of the whole risk-based quality management (RBQM) system: a short, prospectively identified, risk-scored set that drives your quality tolerance limits, your monitoring plan, and the scope of source data verification, and that gets reviewed and adjusted as the trial teaches you things. This guide shows how to build that spine and keep it alive. It assumes GCP fluency and sits alongside our pillar on quality by design in clinical trials and our companion pieces on quality tolerance limits, risk-based quality management, risk-based monitoring, and the clinical trial monitoring plan.

What “critical to quality” actually means in ICH E8(R1)

Start with the definition, because the ranking pages skip past it. ICH E8(R1) §3.2 describes critical to quality factors as attributes of a study whose integrity is fundamental to the protection of study participants, to the reliability and interpretability of the study results, and to the decisions made based on those results. The “critical” label is earned, not assigned: a factor is critical because if its integrity were undermined by an error of design or conduct, the reliability or ethics of the decisions made from the trial would also be undermined.

Two consequences follow. First, CtQ identification is a design-stage activity. ICH E8(R1) §3.1 makes the point bluntly: retrospective document review, monitoring, and audits are part of quality assurance, but even combined they are not sufficient to ensure the quality of a study. Quality has to be designed in prospectively. Second, the set should be short. ICH E8(R1) §3.2 says the quality factors should be prioritised to those that are critical, and explicitly warns against cluttering the list with minor issues such as extensive secondary objectives or data collection not linked to participant protection or the primary objectives. If your CtQ list reads like a table of contents for the protocol, you have not done the prioritisation the guideline asks for.

E8 CtQ factors vs E6(R3) “critical data and processes”: the design-to-conduct handoff

The most common conceptual blur is between the E8 and E6 framings. They are not two competing concepts; they are the same idea at two stages of the lifecycle.

ICH E8(R1) critical to quality factorsICH E6(R3) critical data and processes
StageDesign and planning (broad, programme-level)Trial conduct (operational, trial-level)
FramingAttributes fundamental to participant protection and result reliability (§3.2)The data and processes critical to trial quality, identified via QbD (Principle 6.2 / §3.10)
Primary useShape the protocol, design, and feasibilityDrive risk identification, QTLs, and the monitoring plan
ReviewPeriodic review of factors (§3.3.4)Risks managed proactively and adjusted during conduct (Principle 7.3)

ICH E6(R3) Principle 6.2 requires that the factors critical to the quality of the trial be identified prospectively, and defines them in language that deliberately mirrors E8: attributes fundamental to the protection of participants and to the reliability and interpretability of results. E6(R3) §3.10 then ties the loop explicitly back to E8, instructing the sponsor to identify the factors likely to have a meaningful impact on participants’ rights, safety, and well-being and on result reliability, the critical to quality factors as described in ICH E8(R1). So the handoff is clean by design: E8 tells you to find the critical attributes when you design the study; E6(R3) tells you to translate them into the concrete data and processes you will control, monitor, and bound during conduct. Read the two as one continuous obligation, not as a choice.

The identify-assess-control-review loop, with ISO 31000 vocabulary

Underneath both guidelines sits a generic risk-management loop, and ISO 31000:2018 gives you the words for it. The standard defines risk assessment (ISO 31000:2018 §6.4.1) as the overall process of risk identification, risk analysis, and risk evaluation, conducted systematically and iteratively. Risk analysis (§6.4.3) involves considering the likelihood of events and consequences and the nature and magnitude of those consequences. That is where the familiar “probability times impact” scoring comes from: ISO 31000:2018 §3.7 defines likelihood as the chance of something happening, and §3.6 defines consequence as the outcome of an event affecting objectives.

E8 maps cleanly onto this. ICH E8(R1) §3.2 says that once the factors are identified, you determine the risks that threaten their integrity and decide whether to accept or mitigate them based on their probability, detectability, and impact. Note that E8 adds detectability to ISO’s likelihood-and-consequence pair: a high-impact risk you cannot detect is more dangerous than one you can. E6(R3) §3.10.1.1 then names where these risks live, telling the sponsor to identify risks across the processes and systems of the trial, including trial design, participant selection, the informed consent process, randomisation, blinding, investigational product administration, and data handling. The control step closes it: ISO 31000:2018 §6.5.2 lists treatment options including changing the likelihood, changing the consequences, or removing the risk source, which is exactly the menu a CtQ risk-control column should choose from.

Narrowing the E8 Annex catalogue into a short, study-specific set

ICH E8(R1) Section 7 supplies a long catalogue of considerations for identifying CtQ factors: eligibility criteria reflective of the objectives, adequate measures to protect participant rights and safety, well-defined response variables, systems that ensure the integrity of critical study data, monitoring tailored to the design, and so on. This catalogue is an input, not an output. The guideline itself frames it that way: ICH E8(R1) Section 7 says these considerations are not exhaustive and may not apply to all studies, and that different factors will stand out as critical for different study types.

So the work is subtraction. For each candidate, ask the E8(R1) §3.2 test: if this attribute’s integrity were undermined, would the reliability or ethics of the decisions from this trial be undermined? If the honest answer is no, it is not a CtQ factor for this study, however worthy it is otherwise. ICH E8(R1) §3.3.5 reinforces this by treating feasibility, retention, and follow-up as study-specific judgments rather than universal checkboxes. How few is right? The guideline gives a number to no one, but its instruction in §3.2 to avoid clutter and to focus on what genuinely stands out means a defensible set is usually a handful per domain, not dozens. If you cannot explain on one page why each factor is critical, the list is too long.

A worked CtQ identification and scoring table

Here is the artifact the ranking pages never deliver: a scoring table that wires each factor downstream. Likelihood and impact are scored on a 1 to 5 scale per your pre-set risk criteria; the QTL and monitoring columns are where a CtQ factor either earns its place or exposes itself as decoration.

CtQ factorWhy criticalLikelihood x impactRisk controlDownstream QTL / monitoring actionReview trigger
Eligibility verification at enrolmentWrong population undermines interpretability and can harm participants3 x 5Pre-enrolment eligibility checklist; central review of key criteriaQTL on ineligible-enrolment rate; eligibility named as higher-criticality data in the monitoring planAny confirmed ineligible enrolment; protocol amendment to criteria
Valid informed consent before any procedureEthical and legal foundation of participation2 x 5Consent process SOP; site training; consent in the risk-identification scope100% consent verification on early participants, then sampledConsent-form version change; new site activation
Primary endpoint ascertainmentErrors here directly undermine the result3 x 5Standardised assessment; blinding where feasibleEndpoint data flagged as higher-criticality; targeted SDVOutlier or missing-data trend on the endpoint
Investigational product accountabilityDosing errors threaten safety and exposure validity2 x 4Accountability logs; reconciliationQTL on dosing-deviation rateRepeated accountability discrepancies at a site
Data integrity for critical variablesUnreliable critical data invalidates conclusions3 x 4Edit checks; audit-trail reviewHigher-criticality data verified against source; centralised analyticsAudit-trail anomaly; systemic edit-check failure

The scoring scale is an operational convention, not a regulatory mandate, but the columns trace to the guidelines: the probability-and-impact judgment to ICH E8(R1) §3.2, the QTL column to ICH E6(R3) §3.10.1.3, and the monitoring column to ICH E6(R3) §3.11.4.3.

Wiring each CtQ factor downstream: QTLs, monitoring, and SDV scope

A CtQ factor is worthless unless it changes what the trial does. The wiring runs to three places.

To QTLs. ICH E6(R3) §3.10.1.3 instructs the sponsor, where relevant, to set pre-specified acceptable ranges such as quality tolerance limits at the trial level to support the control of risks to critical to quality factors, and says that when a deviation beyond these ranges is detected, an evaluation should determine whether there is a systemic issue and whether action is needed. A QTL with no parent CtQ factor is a number with no meaning; a CtQ factor with no QTL or other control is an intention with no teeth.

To the monitoring plan and SDV scope. ICH E6(R3) §3.11.4.3 requires the sponsor to develop a monitoring plan tailored to the identified safety and data-quality risks, giving particular attention to participant safety and trial endpoints, and states plainly that the plan should focus on aspects that are critical to quality. The plan, per §3.11.4.3, should describe the monitoring strategy, methods, and tools and the rationale for their use. This is where SDV scope is set: ICH E6(R3) §3.11.4.5.4 directs monitoring to verify that the data identified as of higher criticality in the monitoring plan are consistent with the source. That single clause is the lever that turns CtQ identification into targeted, risk-based monitoring instead of blanket 100% SDV. If a factor is critical, its data are higher-criticality and get verified; if it is not, you have just justified not spending monitoring budget there.

To the protocol and trial documentation. ICH E6(R3) §B.12.1 expects a description of the identified critical to quality factors, their associated risks, and the risk mitigation strategies, documented in the trial. The CtQ set is therefore not an internal worksheet you can lose; it is part of the trial’s quality record.

Keeping it live: review cadence, triggers, and documenting changes

This is the half of the discipline that gets dropped. ICH E8(R1) §3.3.4 requires that accumulated experience and knowledge, together with periodic review of critical to quality factors, be used to determine whether adjustments to risk-control mechanisms are needed, because new or unanticipated issues may arise once the study has begun, and it singles out adaptive designs and interim decision points for specific attention. ICH E6(R3) Principle 7.3 states the same obligation in conduct-stage terms: risks to critical to quality factors should be managed proactively and adjusted when new or unanticipated issues arise once the trial has begun.

ISO 31000:2018 §6.6 supplies the mechanism: monitoring and review should take place at all stages of the process, should be a planned part of it with responsibilities clearly defined, and should record results and provide feedback. In practice that means a standing cadence (for example, at each RBQM or quality-oversight meeting), explicit triggers (a QTL breach, a protocol amendment, a new site, a safety signal, an interim analysis), and a documented change log so that a reviewer can see why the set changed and when. A CtQ register with no revision history is a strong signal that the review obligation in E8(R1) §3.3.4 and E6(R3) Principle 7.3 is being honoured on paper only.

Note one point of alignment worth stating because it is easy to assume a conflict where none exists: E8(R1) §3.3.4 (design-stage guideline) and E6(R3) Principle 7.3 (conduct-stage guideline) impose the same review-and-adjust duty from two directions, and they reinforce rather than contradict each other. The only nuance is scope: E8 frames the review around the broad CtQ factors and risk-control mechanisms, while E6(R3) frames it around the operational risks to those factors during conduct. Treat them as one continuous review obligation spanning design through reporting.

Where teams get it wrong

  • The 40-item list. Copying the ICH E8(R1) Section 7 catalogue wholesale produces a list that flags everything and therefore prioritises nothing, which is precisely what ICH E8(R1) §3.2 warns against when it says not to clutter the factors with minor issues.
  • Design-time only. Identifying CtQ factors at protocol approval and never revisiting them violates the explicit review duties in ICH E8(R1) §3.3.4 and ICH E6(R3) Principle 7.3.
  • No downstream link. A CtQ factor that does not feed a QTL, a monitoring decision, or an SDV-scope choice is decoration. The whole point of ICH E6(R3) §3.11.4.3 is that the monitoring plan focuses on what is critical to quality.
  • Confusing the artifact with the system. A polished CtQ appendix is not RBQM. The factors are inputs to risk identification (E6(R3) §3.10.1.1), control (§3.10.1.3), and monitoring (§3.11.4.3), and they only do their job when the trial acts on them.

A final point on responsibility, because “critical to quality” is sometimes sold as something a tool or a vendor delivers. It is not. ICH E6(R3) §3.10 places the quality-management system, including the identification of critical to quality factors, squarely on the sponsor. Software and analytics platforms can make the identify-assess-control-review loop faster and more visible, and a good RBQM system enables compliance with these expectations, but the sponsor remains accountable for designing the set, scoring the risks, setting the limits, and reviewing them through the trial. The regulations tell you what to do; only your team can decide what is critical about your study.

Sources

A

Written by

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.