GCP · Blog
Back to journal

GCP Audit Checklist: Two Lists, Not One — Site (BIMO) vs. Vendor/CRO, Graded by Subject Protection and Data Integrity

A working GCP audit checklist has to survive contact with an actual inspection. Most don't, because they hand you one undifferentiated bullet list and quietly conflate a site audit with a vendor audit. Those are different jobs. This guide splits the checklist by audit type, anchors every line to a current clause, and gives you a defensible way to grade what you find. Software, templates, and quality systems can help you run this well, but they do not make a sponsor compliant: under 21 CFR §312.50 the sponsor stays responsible for proper monitoring of its investigations, and that responsibility does not transfer.

GCP 9 min read
A

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.

On this page · 11 sections
  1. 01 At a glance
  2. 02 GCP audit vs. FDA inspection vs. self-assessment
  3. 03 Pick the right checklist: investigator-site/BIMO vs. vendor/CRO
  4. 04 The two questions every line must serve
  5. 05 Investigator-site GCP audit checklist
  6. 06 Vendor / CRO audit checklist
  7. 07 Grading findings: critical, major, minor
  8. 08 Risk-ranking audit frequency
  9. 09 From checklist to CAPA: closing the loop
  10. 10 Where teams get it wrong
  11. 11 Sources

At a glance

  • A GCP audit checklist is not one flat list. A site audit and a vendor/CRO audit have different auditors, different scope, different evidence, and different governing clauses. Run them as two checklists.
  • Organize every line around the two questions FDA’s Bioresearch Monitoring (BIMO) program exists to answer: are participants protected, and are the data accurate and reliable. If a line does not serve one of those, it is noise.
  • An audit is not an inspection. Under ICH E6(R3) §3.11.2 a sponsor audit is independent of routine monitoring; an FDA BIMO inspection is the regulator verifying compliance after the fact.
  • Grade findings as critical, major, or minor by impact on subject safety or data reliability, not by how many boxes are unticked. ICH E6(R3) §3.9.3 frames the “important” cut line you should borrow.
  • Delegation and oversight are where audits are won or lost: a missing delegation record and “a contract but no oversight evidence” are recurring findings, and both trace to named clauses.
  • A finding that does not flow into root cause and CAPA is an observation, not a closed loop. ICH E6(R3) §3.12.2 requires that flow for noncompliance that affects safety or data reliability.

A working GCP audit checklist has to survive contact with an actual inspection. Most don’t, because they hand you one undifferentiated bullet list and quietly conflate a site audit with a vendor audit. Those are different jobs. This guide splits the checklist by audit type, anchors every line to a current clause, and gives you a defensible way to grade what you find. Software, templates, and quality systems can help you run this well, but they do not make a sponsor compliant: under 21 CFR §312.50 the sponsor stays responsible for proper monitoring of its investigations, and that responsibility does not transfer.

GCP audit vs. FDA inspection vs. self-assessment

These three get blurred, and the blur is itself an audit risk. A self-assessment is your team checking its own work, useful but not independent. A sponsor audit is a formal, independent evaluation: ICH E6(R3) §3.11.2 states that a sponsor’s audit is independent of and separate from routine monitoring or quality control, and its purpose is to evaluate whether the processes put in place to manage and conduct the trial are appropriate to ensure compliance with the protocol, GCP, and applicable regulatory requirements. An FDA inspection is the regulator doing its own verification. The FDA BIMO compliance program 7348.811 (Part I) describes the program’s purpose as protecting the rights, safety, and welfare of human subjects and verifying the accuracy and reliability of clinical study data submitted to FDA. Your audit checklist should anticipate the inspection, not duplicate the self-assessment.

The practical takeaway: an audit is your last chance to find what an inspector would find, while you can still fix it. That only works if your checklist is scoped and graded the way an inspector reasons.

Pick the right checklist: investigator-site/BIMO vs. vendor/CRO

The single most common structural mistake is one checklist for two audits. They diverge on every axis.

DimensionInvestigator-site auditVendor / CRO audit
Who runs itSponsor QA or delegate, independent of monitoring (ICH E6(R3) §3.11.2)Sponsor QA / vendor qualification, independent of the audited process (ICH E6(R3) §3.11.2)
Primary subjectThe clinical investigator and site staffThe service provider’s quality system and delegated activities
ScopeConsent, eligibility, IP accountability, source/SDV, safety reporting, TMF, delegationQMS, scope-of-work vs. delegated duties, oversight evidence, computerized systems, subcontractor flow-down
Evidence requiredSource records, consent forms, delegation log, IP logs, IRB correspondenceSOPs, training records, oversight metrics, agreements, subcontract flow-down records
Governing reg21 CFR Part 312 (subpart D), ICH E6(R3) §2, BIMO 7348.811ICH E6(R3) §3.6, §3.9, §10; 21 CFR §312.50

The deeper reason they cannot share a list: ICH E6(R3) §10.2 provides that where activities are transferred or delegated to service providers, the responsibility for the conduct of the trial, including the quality and integrity of the trial data, resides with the sponsor or investigator respectively. So a vendor audit is not asking “did the vendor do the work” but “can the sponsor demonstrate oversight of work it remains responsible for.”

The two questions every line must serve

Borrow the FDA’s own frame. BIMO 7348.811 (Part I) ties every inspectional activity to two ends: subject protection and the accuracy and reliability of data. Make each checklist line declare which question it serves. A consent line serves subject protection. A source-data-verification line serves data integrity. A delegation line serves both, because an unqualified person obtaining consent threatens protection, and an undocumented data-entry delegation threatens reliability. Lines that serve neither are tick-box theater and should be cut.

Investigator-site GCP audit checklist

ItemWhat “good” looks likeGoverning clause
Informed consent obtained before any procedureConsent form signed and dated by the participant (or LAR) before participation; the case history documents that consent was obtained prior to participationICH E6(R3) §2.8.7; 21 CFR §312.62(b)
Consent delegated only to qualified staffThe person who obtained consent was delegated that task by the investigator and is qualified; delegation is recordedICH E6(R3) §2.3.2–§2.3.3; BIMO 7348.811 (Part III)
IRB review and approval before study proceduresInvestigator assured an IRB responsible for initial and continuing review; protocol and consent approved before initiation21 CFR §312.66; BIMO 7348.811 (Part III)
Case histories adequate and accurateCase histories record all observations on each subject; source records are attributable, legible, contemporaneous, original, accurate, complete21 CFR §312.62(b); ICH E6(R3) §2.12.2
Source/SDV traceableChanges to source records do not obscure the original entry and carry an audit trailICH E6(R3) §2.12.2
Safety reporting timelySAEs reported immediately to the sponsor with a causality assessmentICH E6(R3) §2.7.2(b)
Delegation log completeA record is maintained of persons/parties to whom the investigator delegated trial-related activities, proportionate to their significanceICH E6(R3) §2.3.3
IP accountabilityInvestigational product supplied only to authorized persons; receipt, use, and disposition documented21 CFR §312.62(b); ICH E6(R3) §2.10.2
Protocol deviations reportedDeviations reported to the IRB and sponsor; site addressed them to prevent recurrenceBIMO 7348.811 (Part III)

Note on consent specifics: 21 CFR Part 50 (informed consent) and Part 54 (financial disclosure) are not yet in this corpus, so the lines above anchor to the nearest in-corpus authority, the consent provisions of 21 CFR §312.62(b) and ICH E6(R3) §2.8, rather than citing Part 50 clauses we cannot verify here.

Vendor / CRO audit checklist

ItemWhat “good” looks likeGoverning clause
QMS fit for purposeThe service provider implements appropriate quality management; existing processes may satisfy GCP if fit for purpose in the trial contextICH E6(R3) §3.6.6; §3.6.10
Scope of work vs. delegated dutiesAgreements document the roles, activities, and responsibilities transferred; what the vendor actually does matches what was delegatedICH E6(R3) §3.6.2; §10.2
Oversight evidence, not just a contractThe sponsor maintains appropriate oversight of transferred activities; selection and oversight of service providers are treated as fundamental oversight featuresICH E6(R3) §3.9.5; §3.6.9
Sponsor retains responsibilityThe audit confirms the sponsor, not the vendor, owns trial conduct and data integrity for the delegated workICH E6(R3) §10.2; 21 CFR §312.50
Computerized systems fit for purposeSystems are fit for purpose with risk-based validation; data-integrity-critical factors addressed in designICH E6(R3) §9.3
Subcontractor flow-downOversight extends to activities the service provider further subcontractsICH E6(R3) §3.6.9
Issue escalationThe arrangement provides for timely escalation and follow-up of issuesICH E6(R3) §3.9.6

The line auditors actually fail teams on is “oversight evidence, not just a contract.” A signed agreement proves intent; ICH E6(R3) §3.9.5 makes oversight of service providers an active, ongoing feature of the sponsor’s process. When FDA asks a sponsor about a vendor, it asks for the oversight, not the contract.

Grading findings: critical, major, minor

A checklist that only marks pass/fail cannot survive an inspection, because inspectors reason about impact. Grade by effect on the two questions. ICH E6(R3) §3.9.3 gives you the cut line to borrow: important protocol deviations are the subset that may significantly impact the completeness, accuracy, or reliability of the data, or significantly affect a participant’s rights, safety, or well-being.

GradeDefinitionWorked example
CriticalSignificant, demonstrated impact on subject safety or data reliability, or systemic failureConsent obtained after a study procedure, or no consent on file, threatening subject protection and the validity of that subject’s data
MajorA clause requirement not met, with potential (not yet demonstrated) impact, or a recurring minorA delegation log missing the staff member who entered primary-endpoint data: the data’s reliability is now unverifiable until reconstructed
MinorIsolated documentation gap with no plausible impact on safety or reliabilityA monitoring visit report filed late but complete, with no downstream effect on subject protection or data

Why a vague consent gap can be critical or minor depending on facts: if the consent was obtained but the version control note is missing, that is likely minor; if the timeline shows a screening procedure before the signature, ICH E6(R3) §2.8.7 and 21 CFR §312.62(b) are both implicated and it is critical. The grade follows the impact on the two questions, not the document count.

Risk-ranking audit frequency

Do not audit every vendor on the same calendar. ICH E6(R3) §3.11.2.2 states that the audit plan, program, and procedures should be guided by factors such as the importance of the trial to regulatory submissions, the number of participants, the type and complexity of the trial, the level of risk to participants, and any identified problems. Translate that into a criticality tier: a vendor handling primary-endpoint data or drug supply for a pivotal trial earns more frequent, deeper audits than a vendor providing a low-risk ancillary service. Frequency is an output of risk, not a fixed annual ritual.

From checklist to CAPA: closing the loop

A finding is not closed when it is written down. For noncompliance that significantly affects, or could affect, participant safety or data reliability, ICH E6(R3) §3.12.2 requires the sponsor to perform a root cause analysis, implement appropriate corrective and preventive actions, and confirm their adequacy; and where the noncompliance is serious, to notify the regulatory authority and/or IRB/IEC as applicable. So your checklist’s last column should not be pass/fail but “finding → grade → root cause → CAPA → verification.” That is the difference between an audit that documents problems and one that resolves them before an inspector arrives.

Where teams get it wrong

  • One list for two audits. Site and vendor audits share neither scope nor evidence nor governing clause. Splitting them is the first fix.
  • Grading by box count. Three minor documentation gaps are not one major finding. Grade by impact on subject protection and data reliability, the frame ICH E6(R3) §3.9.3 sets for “important.”
  • A contract treated as oversight. ICH E6(R3) §3.9.5 makes oversight an active feature; the contract is the floor, not the evidence.
  • Findings with no CAPA. ICH E6(R3) §3.12.2 ties safety- or reliability-relevant noncompliance to root cause and CAPA. Stopping at the observation leaves the loop open.
  • Citing clauses you cannot verify. If a line cannot be anchored to a current provision, soften it or cut it. An invented section number is itself an inspection finding waiting to happen.

Sources

A

Written by

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.