ICH E8(R1) in Practice: Turning Critical-to-Quality Factors into Risk-Proportionate Controls and an E6(R3) RBQM Hand-off
ICH E8(R1) is most useful when you stop reading it as a guideline summary and start running it as an operating system for Quality by Design. The 2021 revision reframed the document around a single operational question: for this specific study, what are the few things that genuinely determine whether the result will be trustworthy and the participants protected, and how do we proportion our effort to those things? This article is a practitioner playbook for answering that question, identifying CtQ factors, proportioning mitigations, and handing the output to E6(R3) execution, rather than a paraphrase of the PDF.
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
On this page · 10 sections
- 01 At a glance
- 02 What ICH E8(R1) actually is, and why the 2021 revision matters
- 03 Quality by Design in one paragraph: build it in, do not inspect it in
- 04 Critical-to-Quality factors: the critical few, not the comprehensive many
- 05 A CtQ identification workflow you can run on Monday
- 06 Worked example: CtQ factors mapped to risk-proportionate mitigations
- 07 From E8(R1) to E6(R3): how CtQ factors become QTLs, RBQM, and the monitoring plan
- 08 Where ICH E9(R1) decides what is reliability-critical
- 09 Where teams get it wrong
- 10 Sources
At a glance
- ICH E8(R1) is not a catalogue of study types; it is a quality-planning framework that asks you to design quality into the protocol up front rather than inspect it in later.
- The core discipline is naming a study’s Critical-to-Quality (CtQ) factors: the handful of attributes whose integrity protects participant safety and rights, the reliability of results, and the interpretability of decisions made on those results.
- The CtQ list is a critical few, not a comprehensive many. E8(R1) explicitly warns against cluttering it with minor issues, and prioritisation happens at the time of study design.
- Risk controls must be proportionate to the risk. Over-controlling a non-critical factor wastes resources without improving quality.
- E8(R1) tells you what to protect and when; ICH E6(R3) tells you how to operate it through risk evaluation, risk control, quality tolerance limits, and a tailored monitoring plan.
- ICH E9(R1) decides which factors are reliability-critical, because the estimand and its intercurrent events determine which data, if missing or mishandled, actually threaten the result.
ICH E8(R1) is most useful when you stop reading it as a guideline summary and start running it as an operating system for Quality by Design. The 2021 revision reframed the document around a single operational question: for this specific study, what are the few things that genuinely determine whether the result will be trustworthy and the participants protected, and how do we proportion our effort to those things? This article is a practitioner playbook for answering that question, identifying CtQ factors, proportioning mitigations, and handing the output to E6(R3) execution, rather than a paraphrase of the PDF.
What ICH E8(R1) actually is, and why the 2021 revision matters
The original 1997 E8 was largely a taxonomy: it organised clinical studies by objective and development phase. The R1 revision keeps that scaffolding but moves the centre of gravity to quality. Quality by design now sits at the front of the guideline as a primary planning activity. ICH E8(R1) §3.1 states that quality is a primary consideration in the design, planning, conduct, analysis, and reporting of clinical studies and a necessary component of clinical development programmes. The shift is from describing kinds of studies to prescribing how quality should be built into any study.
Concretely, ICH E8(R1) §3 establishes that quality by design in clinical research sets out to ensure that the quality of a study is driven proactively by designing quality into the study protocol and processes, using a prospective, multidisciplinary approach proportionate to the risks involved. That is the whole thesis in one sentence: proactive, multidisciplinary, proportionate. Everything operational in E8(R1) flows from it.
Quality by Design in one paragraph: build it in, do not inspect it in
Quality by Design is the opposite of catching defects at the end. ICH E8(R1) §3 frames the approach as focusing on critical to quality factors to ensure protection of the rights, safety, and wellbeing of study participants, the generation of reliable and meaningful results, and the management of risks to those factors using a risk-proportionate approach. The practical consequence: if a quality problem can be designed out at protocol-writing time (an unrealistic eligibility window, a burdensome assessment schedule that drives dropout), you fix the design, you do not staff up monitoring to chase the symptom later. E8(R1) §6.1 reinforces this, noting that successful application of quality by design may minimise the need for protocol modifications and make adherence more likely.
Critical-to-Quality factors: the critical few, not the comprehensive many
A CtQ factor is an attribute of the study whose integrity is fundamental to quality. ICH E8(R1) §3.2 defines critical to quality factors as attributes of a study whose integrity is fundamental to the protection of study participants, the reliability and interpretability of the study results, and the decisions made based on those results. Note the three things they protect: participant safety and rights, data reliability, and interpretability of results. Every candidate factor should be testable against those three objectives; if it does not clearly serve one of them, it is probably not critical.
The discipline is restraint. ICH E8(R1) §3.2 requires a basic set of factors and says the critical to quality factors should be clear and should not be cluttered with minor issues. E8(R1) §3.2 is explicit on timing and prioritisation too: the quality factors should be prioritised to identify those that are critical to the study at the time of the study design, and study procedures should be proportionate to the risks inherent in the study. A CtQ list that names twenty factors has usually failed, because it has not separated the critical few from the trivial many.
A CtQ identification workflow you can run on Monday
E8(R1) gives you the principles; here is how to operationalise them as a repeatable cross-functional session, run before the protocol is finalised.
- Convene the right people. ICH E8(R1) §3.2 assigns ownership clearly: the sponsor and other parties designing quality into a clinical study should identify the critical to quality factors. In practice this is a cross-functional table, clinical, medical, statistics, data management, operations, safety, and regulatory, not a single function ticking a box. E8(R1) §3.3.3 adds that study design is best informed by input from a broad range of stakeholders, including patients and healthcare providers, and should be open to challenge by subject matter experts from outside as well as within the sponsor organisation.
- Generate candidate factors against the objective. ICH E8(R1) §3.3 anchors identification in whether the study objectives are clearly articulated and whether the design can meet the research question well and most efficiently. Start from the primary objective and the estimand (see the E9 section below), then ask what could undermine it.
- Apply the “is this critical?” filter. Keep a factor only if degrading it would meaningfully harm participant safety/rights, result reliability, or interpretability. ICH E8(R1) §3.3.2 directs that efforts should be focused on activities that are essential to the reliability and meaningfulness of study outcomes and the safe, ethical conduct of the study.
- Proportion the mitigation. ICH E8(R1) §6.1 requires that risk-proportionate mitigation measures should be employed to ensure the integrity of the critical to quality factors. Heavy control on a critical factor, light touch on the rest.
- Document the rationale, then keep it alive. ICH E8(R1) §3.3.4 instructs that accumulated experience and periodic review of critical to quality factors should be used to determine whether adjustments to risk control mechanisms are needed, because new or unanticipated issues may arise once the study has begun. The CtQ list is a living artifact, not a kickoff deliverable.
Worked example: CtQ factors mapped to risk-proportionate mitigations
A short, illustrative slice for a confirmatory two-arm efficacy trial. The point is the mapping discipline, name the factor, name what it protects, then size the control to the risk.
| CtQ factor | Primarily protects | Risk-proportionate mitigation | Why proportionate |
|---|---|---|---|
| Eligibility criteria correctly applied at enrolment | Participant safety; interpretability | Targeted source verification of key inclusion/exclusion items; site training; eligibility checklist in EDC | High impact on both safety and the analysis population, so verify the few decisive criteria, not every field |
| Primary endpoint measurement collected and recorded reliably | Result reliability | Higher-criticality data flagged in the monitoring plan; central data trend review | Endpoint integrity is decision-critical; concentrate scrutiny here |
| Participant retention and follow-up through the primary timepoint | Reliability; interpretability | Visit-window reminders; realistic visit schedule designed at protocol stage; missing-data tracking | Dropout creates missing data that threatens the estimand; design it down before monitoring it |
| Informed consent properly obtained and documented | Participant rights/safety | Consent process SOP; consent verification on monitoring visits | Ethical non-negotiable; control is mandatory regardless of risk sizing |
| Routine administrative form completeness (non-endpoint) | Minor | Standard data-management edit checks only | Not CtQ; do not escalate monitoring or verification here |
The retention row is not incidental: ICH E8(R1) §3.3.5 names the retention and follow up of study participants as key critical to quality factors. The last row is the discipline in action, a genuinely minor item gets standard handling, not a custom control.
From E8(R1) to E6(R3): how CtQ factors become QTLs, RBQM, and the monitoring plan
This is the hand-off teams most often blur. E8(R1) is the why and when of quality planning; E6(R3) is the how of GCP execution. They are explicitly linked. ICH E6(R3) §3.1 directs that quality by design should be implemented to identify the factors likely to have a meaningful impact on participants’ rights, safety and well-being and the reliability of results, the critical to quality factors as described in ICH E8(R1). E6(R3) then operationalises them through a defined risk-management cycle:
- Risk identification. ICH E6(R3) §3.1 requires the sponsor to identify risks that may have a meaningful impact on critical to quality factors prior to trial initiation and throughout trial conduct.
- Risk evaluation. ICH E6(R3) §3.1 directs the sponsor to evaluate identified risks by considering the likelihood of harm occurring, the extent to which it would be detectable, and its impact on participant protection and the reliability of trial results.
- Risk control and QTLs. ICH E6(R3) §3.1 requires that risk control be proportionate to the importance of the risk, and provides for quality tolerance limits at the trial level to support the control of risks to critical to quality factors. The QTL is the bridge: a CtQ factor becomes a measurable trial-level threshold whose breach signals a systemic problem.
- Monitoring plan. ICH E6(R3) §3.2 requires the sponsor to develop a monitoring plan tailored to the identified potential safety risks, the risks to data quality, and other risks to the reliability of the trial results, and §3.2 directs that monitoring verify data identified as of higher criticality in the monitoring plan against the source. That higher-criticality flagging is where your CtQ list earns its keep in execution.
The division of labor is clean: E8(R1) decides what is critical and when to decide it; E6(R3) decides how to evaluate, tolerance-limit, and monitor it. Note one consistency worth flagging rather than smoothing over: both guidelines speak to proportionality and to managing risks proactively, ICH E8(R1) §3.3.4 and ICH E6(R3) §3.1 each call for ongoing review and adjustment when new issues arise. They align here rather than conflict, and you should let that alignment carry: the same CtQ rationale should read consistently across the E8 quality plan and the E6 risk documentation, not be re-derived from scratch in each.
Where ICH E9(R1) decides what is reliability-critical
Not every data point is equally critical to the result, and statistics, not operations, should decide which are. ICH E9(R1) §A.3 frames the estimand as the precise specification of the treatment effect of interest, and states that the statistical analysis should be aligned to the estimand. Crucially for CtQ work, ICH E9(R1) §A.3 explains that having clarity in the estimand gives a basis for planning which data need to be collected, and hence which data, when not collected, present a missing data problem to be addressed in the analysis. In other words, the estimand tells you which missing or mishandled data actually threatens the result, and those are your reliability-critical CtQ factors.
Intercurrent events are the bridge between E9 and CtQ identification. ICH E9(R1) §A.3 defines intercurrent events as events occurring after treatment initiation that affect either the interpretation or the existence of the measurements associated with the clinical question of interest. E8(R1) §5 makes the connection operational, noting that careful consideration of intercurrent events helps identify critical to quality factors such as reducing study discontinuation and continuing data collection following treatment discontinuation. So the workflow is: define the estimand, enumerate the intercurrent events it must handle, and let those determine which retention, data-collection, and follow-up factors are reliability-critical. ICH E9(R1) §A.5 then closes the loop, stating that once defined, a trial can be designed to enable reliable estimation of the targeted treatment effect.
Where teams get it wrong
- Treating CtQ as a one-time kickoff checkbox. ICH E8(R1) §3.3.4 requires periodic review because new or unanticipated issues may arise once the study has begun. A CtQ list frozen at protocol approval has stopped doing its job.
- Listing everything, so nothing is critical. When the CtQ register has thirty entries, the critical few are buried. E8(R1) §3.2 is explicit that the factors should not be cluttered with minor issues.
- Over-controlling non-critical factors. Proportionality cuts both ways: ICH E6(R3) §3.1 requires control proportionate to the importance of the risk, so escalating monitoring on trivial administrative data dilutes attention from the endpoints that matter.
- No documented rationale. If you cannot show why a factor was judged critical (or not), you cannot defend the monitoring plan or the risk file to an inspector, and you cannot revisit the judgment as ICH E8(R1) §3.3.4 expects.
- Letting operations, not statistics, decide reliability-criticality. Without the estimand lens from ICH E9(R1) §A.3, teams guess at which data are decision-critical instead of deriving it from the clinical question of interest.
A final framing for sponsors: none of this certifies a trial as compliant. E8(R1), E6(R3), and E9(R1) describe what to protect, how to proportion controls, and how to define a reliable result. Running the CtQ-to-RBQM workflow well enables a quality approach; the sponsor remains responsible for the judgment behind every factor named, every control sized, and every rationale documented. Done as a discipline rather than a deliverable, the payoff is a protocol where quality was designed in, and a monitoring plan that watches the few things that actually decide the trial.
For deeper operational siblings, see the related coverage on risk-based monitoring and RBQM, quality tolerance limits, protocol deviations, and the broader ICH E6(R3) Good Clinical Practice overview.
Sources
- ICH E8(R1) General Considerations for Clinical Studies, version r1 (ICH, 2021)
- ICH E6(R3) Good Clinical Practice, version r3 (ICH, 2025) — https://www.ich.org/page/efficacy-guidelines
- ICH E9(R1) Statistical Principles for Clinical Trials (Addendum on Estimands and Sensitivity Analysis), version r1 (ICH, 2019)
Written by
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
Continue reading
MHRA GCP Inspection Findings as a Risk Map: Map the Recurring Themes to ICH E6(R3) and Self-Inspect Before They Cite You
The MHRA GCP Inspections Metrics report gets read the wrong way. Teams treat it as annual news: skim the headline counts ("four critical for commercial sponsors this cycle"), note the critical-versus-major definitions, and move on. That misses the point. The findings barely move year over year. The ...
ReadGCP Audit Checklist: Two Lists, Not One — Site (BIMO) vs. Vendor/CRO, Graded by Subject Protection and Data Integrity
A working GCP audit checklist has to survive contact with an actual inspection. Most don't, because they hand you one undifferentiated bullet list and quietly conflate a site audit with a vendor audit. Those are different jobs. This guide splits the checklist by audit type, anchors every line to a c...
ReadThe Visit-Type-Aware Clinical Trial Monitoring Visit Checklist: SQV, SIV, IMV, COV, and Inspection Prep, Mapped to GCP
Most monitoring checklists circulating as ACRP PDFs and site SOPs share three defects: they blur the visit types into one generic "monitoring visit," they never tell you why GCP requires a given check, and they stop at the visit and ignore the follow-up letter as a timed deliverable. This reference ...
Read