MHRA GCP Inspection Findings as a Risk Map: Map the Recurring Themes to ICH E6(R3) and Self-Inspect Before They Cite You
The MHRA GCP Inspections Metrics report gets read the wrong way. Teams treat it as annual news: skim the headline counts ("four critical for commercial sponsors this cycle"), note the critical-versus-major definitions, and move on. That misses the point. The findings barely move year over year. The same handful of root causes generate critical and major gradings every cycle, which means the report is less a news bulletin than a standing risk map. If you read it that way, you can pre-empt the findings most likely to land on you, instead of reacting to last year's numbers.
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
On this page · 10 sections
- 01 At a glance
- 02 What the MHRA GCP Inspections Metrics report actually is
- 03 How findings are graded: critical, major, and other
- 04 Who gets cited, and for what
- 05 The themes that never go away
- 06 Each recurring theme mapped to the duty it breaches
- 07 Where teams get it wrong
- 08 Turn the metrics into a self-inspection plan
- 09 What “oversight of delegated functions” looks like done right
- 10 Sources
At a glance
- The MHRA GCP Inspections Metrics report is published by the MHRA’s GCP inspectorate and lags real inspections by roughly three years, so its value is not the headline counts but the pattern underneath them.
- The same root causes drive critical and major findings cycle after cycle: sponsor oversight of delegated and subcontracted functions, pharmacovigilance and safety reporting, trial master file (TMF) completeness, and data integrity.
- Read as a recurring risk map, those four themes map cleanly onto specific duties in ICH E6(R3), the EMA TMF guideline, and FDA’s risk-based monitoring guidance, which is what lets you remediate before an inspection rather than after one.
- Oversight of delegated functions is the single biggest repeat offender, and ICH E6(R3) is explicit that delegation never transfers the underlying responsibility.
- The practical output of this article is four tools: a grading table, a findings-by-organisation-type table, a recurring-theme to ICH E6(R3) duty mapping, and a prioritised self-inspection checklist you can run before your next inspection.
The MHRA GCP Inspections Metrics report gets read the wrong way. Teams treat it as annual news: skim the headline counts (“four critical for commercial sponsors this cycle”), note the critical-versus-major definitions, and move on. That misses the point. The findings barely move year over year. The same handful of root causes generate critical and major gradings every cycle, which means the report is less a news bulletin than a standing risk map. If you read it that way, you can pre-empt the findings most likely to land on you, instead of reacting to last year’s numbers.
This piece does three things. It explains what the report is and how MHRA grades findings, separates the findings by organisation type so you can self-locate, then maps each recurring theme to the specific regulatory duty it breaches and turns that into a self-inspection plan. Throughout, report-specific figures and definitions are attributed to the MHRA report itself; the duties each finding breaches are anchored to the in-scope regulations.
What the MHRA GCP Inspections Metrics report actually is
The report is published by the MHRA’s GCP inspectorate and summarises, in aggregate, the findings raised across the GCP inspections it conducted in a given reporting period. It covers GCP only: not GMP, GDP, or pharmacovigilance-system (GPvP) inspection metrics, which are reported separately. Two structural features matter for how you use it.
First, cadence and lag. The report is periodic and, by design, trails the inspections it describes by roughly three years, because findings are only aggregated and published after inspections close and gradings are finalised. That lag is exactly why the headline counts are a poor planning input: by the time you read “this many criticals,” the cycle is old. The themes, however, are stable, and stable themes are forecastable.
Second, it is aggregated by organisation type and by finding category, not by company. You cannot see who was cited, but you can see which kind of organisation (commercial sponsor, contract research organisation, non-commercial sponsor, investigator site) attracts which kind of finding. That is the part worth mining.
How findings are graded: critical, major, and other
MHRA grades each inspection finding into a tier, and the tier reflects the seriousness of the risk the deficiency poses, not how many times it occurred. Per the MHRA report’s own definitions, the tiers run as follows.
| Grade | What it means (per the MHRA report) | The bar / trigger |
|---|---|---|
| Critical | Conditions, practices, or processes that adversely affect the rights, safety, or well-being of participants and/or the quality and integrity of data. | A deficiency serious enough to harm participant safety/rights or to undermine data reliability; may also be a pattern of major findings that together rise to critical. |
| Major | Conditions, practices, or processes that could adversely affect those same interests, but to a lesser degree. | A serious deficiency that could (not yet has) compromise safety/rights or data reliability, or a major departure from GCP. |
| Other | Conditions, practices, or processes that would not be expected to adversely affect those interests. | A deficiency not expected to materially affect safety, rights, or data, but still a departure from GCP. |
The throughline of the grading model is the same standard the in-scope regulations hold you to. ICH E6(R3) frames the entire enterprise around protecting “the rights, safety and well-being of trial participants” and ensuring “the clinical trial results are reliable” (Principles, §2.5). A critical finding is, in effect, the inspectorate concluding that one of those two pillars was actually compromised; a major is the conclusion that it could have been. FDA’s risk-based monitoring guidance describes the same dual objective, stating that sponsors must provide oversight to ensure “adequate protection of the rights, welfare, and safety of human subjects and the quality and integrity of the data” (FDA RBM §II, Background). When two regulators on two continents anchor the bar to the same two interests, you have your prioritisation rule for free: anything touching participant safety or data reliability is where criticals come from.
Who gets cited, and for what
The report separates findings by organisation type, which is the most actionable cut in it. Treat the table below as a self-location tool: find your row, and you have the theme most likely to generate your next major or critical. The dominant-theme column reflects the persistent pattern across cycles, not a single year.
| Organisation type | Dominant recurring theme | Why it lands here |
|---|---|---|
| Commercial sponsor | Oversight of delegated/subcontracted functions; pharmacovigilance | Sponsors delegate heavily to CROs and vendors but retain the duty; thin oversight documentation is the classic gap. |
| CRO | Quality systems, computerised systems, and execution of the activities delegated to them | The CRO performs the work but must do it to GCP; defects surface as system and process findings. |
| Non-commercial sponsor (academia/NHS) | Sponsor oversight capacity, TMF, pharmacovigilance | Limited infrastructure and part-time roles make systematic oversight and complete TMFs hard to sustain. |
| Investigator site | Source data, informed consent, investigational product, and delegation logs | Site-level execution: what was actually done to the participant and whether it is documented and attributable. |
Two notes for readers benchmarking themselves. Commercial and non-commercial sponsors share the oversight theme but for different reasons: commercial sponsors over-delegate, non-commercial sponsors under-resource. And a CRO’s findings are not the sponsor’s escape hatch. As covered below, the sponsor still owns the outcome.
The themes that never go away
Strip the cycles back and four themes recur: sponsor oversight of delegated functions, pharmacovigilance and safety reporting, TMF completeness, and data integrity. They recur because they are systemic, not clerical. You cannot fix them with a one-off cleanup; they need a standing process. Here is what each one is, in inspector terms.
Sponsor oversight of delegated functions. The sponsor hands work to a CRO or vendor and then cannot evidence that it knew what the vendor was doing or whether it was done to GCP. The finding is rarely “the CRO did it wrong”; it is “the sponsor had no documented oversight of the CRO doing it.”
Pharmacovigilance and safety reporting. Late or missing expedited reports, weak SUSAR handling, or no documented process for getting safety information from site to sponsor to regulator on time.
TMF completeness. Missing essential documents, documents filed late, or a TMF that could not be used to reconstruct what happened in the trial. This is a perennial because the TMF is a living artefact, not an end-of-trial assembly job.
Data integrity. Source data that is not attributable, contemporaneous, or complete; audit trails that are missing or off; changes that obscure the original entry. The inspectorate’s question is always “can I trust this number?”
Each recurring theme mapped to the duty it breaches
This is the mapping the top-ranking pages never provide, and it is what converts the report from trivia into a CAPA plan. For each theme, the specific in-scope duty an inspector measures you against:
| Recurring finding | The duty it breaches | Source |
|---|---|---|
| Thin/absent oversight of delegated work | The sponsor retains ultimate responsibility for delegated activities and must ensure appropriate oversight of important activities transferred to service providers, including activities further subcontracted. | ICH E6(R3) §3.9 (Sponsor Oversight) |
| Delegation treated as transfer of responsibility | Where activities are transferred or delegated to service providers, responsibility for trial conduct, including data quality and integrity, resides with the sponsor or investigator. | ICH E6(R3) §2.5 (Principles) |
| Weak vendor selection / no documented agreement | Sponsor activities transferred to a service provider must be documented in an agreement; the sponsor is responsible for assessing suitability and selecting the provider. | ICH E6(R3) §3.6 / §3.9 |
| Late or missing expedited safety reports | The sponsor must expedite reporting of SUSARs to regulatory authorities in accordance with applicable requirements and ICH E2A. | ICH E6(R3) §3.13.2 (Safety Reporting) |
| Site-to-sponsor SAE handoff gaps | All SAEs must be reported immediately to the sponsor; the investigator may delegate safety-reporting activities but retains overall responsibility for compliance. | ICH E6(R3) §2.7.2 (Safety Reporting) |
| Incomplete/late TMF; cannot reconstruct the trial | The TMF must be complete, legible, and accurate, and sufficient to reconstruct the activities undertaken in conducting the trial. | EMA TMF guideline §3.1 |
| No ongoing TMF QC | Risk-based QC or review processes must keep the TMF up to date with all essential documents appropriately filed. | EMA TMF guideline §4.1 |
| Source data not attributable/contemporaneous | Source records must be attributable, legible, contemporaneous, original, accurate, and complete. | ICH E6(R3) §2.12 / §4.2 |
| Quality bolted on, not designed in | The sponsor must implement a quality management system using a proportionate, risk-based approach that builds quality into the trial design. | ICH E6(R3) §3.10 (Quality Management) |
| Monitoring not targeted to risk | Sponsors must determine the extent and nature of monitoring based on identified risks; centralized monitoring should be used where appropriate. | FDA RBM §IV; ICH E6(R3) §3.11.4 |
One alignment worth stating plainly, because the brief’s archetype is a compliance explainer and not a regulatory smoother: ICH E6(R3) and FDA’s RBM guidance agree on the direction of monitoring. ICH E6(R3) §3.11.4 directs sponsors to set the extent and nature of monitoring from identified risks and allows centralized monitoring; FDA’s 2013 guidance independently encourages “greater use of centralized monitoring methods where appropriate” and a focus on the most critical data elements (FDA RBM §I). These do not conflict; they reinforce each other, and an inspector who finds undifferentiated 100% source data verification with no risk rationale can cite you under either framework. Where the two differ is jurisdictional scope and citation, not substance, so you map your monitoring plan to both rather than choosing between them.
Where teams get it wrong
The recurring failures are predictable, which is the good news.
They read the report as a scoreboard. Counting last cycle’s criticals tells you nothing about your exposure. The themes are the signal.
They equate delegation with offloading. This is the costliest error. ICH E6(R3) is unambiguous: a sponsor “may transfer any or all” of its trial-related activities to a service provider, “however, the ultimate responsibility for the sponsor’s trial-related activities, including protection of participants’ rights, safety and well-being and reliability of the trial data, resides with the sponsor” (§3.9). Software, a CRO, or a vendor process can enable your compliance; none of them makes you compliant or moves the responsibility off your books.
They keep the TMF as an end-of-trial project. The EMA guideline expects ongoing, risk-based QC so the TMF stays up to date and reconstructable throughout (§4.1), not a frantic reconciliation before archiving.
They document oversight thinly. “We have a contract with the CRO” is not oversight. The agreement is necessary (ICH E6(R3) §3.6) but the inspectorate looks for evidence you exercised oversight: reviewed vendor performance, acted on issues, and recorded it.
Turn the metrics into a self-inspection plan
A self-inspection mapped to the four recurring themes is how you metabolise the report. Run it before you are scheduled, and prioritise in the order below, because the order tracks where criticals come from.
- Oversight of delegated functions (highest priority). For every delegated or subcontracted function, can you produce a signed agreement defining the transfer (ICH E6(R3) §3.6) and dated evidence that you exercised oversight (performance review, issue escalation, follow-up)? ICH E6(R3) §3.9 requires oversight to extend to activities the service provider further subcontracts, so trace the chain to the end.
- Pharmacovigilance and safety reporting. Is there a documented, time-bound path from site SAE awareness to sponsor to regulator? Can you evidence that SAEs reached the sponsor immediately (ICH E6(R3) §2.7.2) and that SUSARs were expedited to authorities (§3.13.2)? Pull a sample and check the clock on each.
- TMF completeness. Run a risk-based QC pass now, not at archiving (EMA TMF §4.1). For a sampled set of essential documents, is each present, in date, and filed so the trial could be reconstructed from the TMF alone (EMA TMF §3.1)?
- Data integrity. Sample source records against the attributable-legible-contemporaneous-original-accurate-complete standard (ICH E6(R3) §2.12). Check that audit trails exist and that changes do not obscure the original entry.
- Quality and monitoring rationale. Can you show your monitoring plan was set from identified risks rather than habit (ICH E6(R3) §3.11.4; FDA RBM §IV), and that your quality approach was designed in, not bolted on (ICH E6(R3) §3.10)?
What “oversight of delegated functions” looks like done right
Because it is the biggest repeat offender, it deserves a closing standard. Done right, oversight is a documented loop, not a contract on a shelf. You select the vendor against defined criteria and record why (ICH E6(R3) §3.9). You capture the transfer of activities in an agreement (§3.6). You then monitor the vendor’s performance against agreed metrics, act on what you find, and keep the records, including for work the vendor subcontracts onward, because §3.9 explicitly extends your duty to further-subcontracted activities. For the EU TMF dimension, your oversight includes ensuring the TMF the CRO maintains on your behalf stays complete and inspection-ready, since the EMA guideline keeps ultimate responsibility for the TMF’s quality, integrity, and retrieval with the sponsor even when a CRO archives it.
The phrasing matters here, and it is the discipline this whole article is built on. None of these regulations let a sponsor certify itself compliant by buying a tool or signing a CRO. They define duties that remain yours. The MHRA report simply records, every cycle, what happens when teams forget that. Read it as the risk map it is, map each theme to the duty above, and self-inspect against the checklist, and you change the only number that matters: the findings that land on you next time.
For deeper treatment of the individual themes, see the sibling articles on TMF management and completeness, sponsor oversight of CROs and vendors, pharmacovigilance and SAE reporting, and data integrity under ALCOA+, and the broader GCP inspection-readiness pillar they sit under.
Sources
- ICH E6(R3) Good Clinical Practice, version r3 (ICH, adopted 06 January 2025) — https://www.ich.org/page/efficacy-guidelines
- EMA Guideline on the content, management and archiving of the clinical trial master file (paper and/or electronic), version 2018 (EMA/INS/GCP/856758/2018, GCP Inspectors Working Group)
- FDA Guidance for Industry: Oversight of Clinical Investigations — A Risk-Based Approach to Monitoring, version 2013 (FDA)
- MHRA GCP Inspections Metrics report (MHRA GCP inspectorate) — primary source for the report’s grading definitions, organisation-type breakdown, and finding categories; not yet in the corpus, attributed to the published MHRA report itself.
Written by
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
Continue reading
GCP Audit Checklist: Two Lists, Not One — Site (BIMO) vs. Vendor/CRO, Graded by Subject Protection and Data Integrity
A working GCP audit checklist has to survive contact with an actual inspection. Most don't, because they hand you one undifferentiated bullet list and quietly conflate a site audit with a vendor audit. Those are different jobs. This guide splits the checklist by audit type, anchors every line to a c...
ReadThe Visit-Type-Aware Clinical Trial Monitoring Visit Checklist: SQV, SIV, IMV, COV, and Inspection Prep, Mapped to GCP
Most monitoring checklists circulating as ACRP PDFs and site SOPs share three defects: they blur the visit types into one generic "monitoring visit," they never tell you why GCP requires a given check, and they stop at the visit and ignore the follow-up letter as a timed deliverable. This reference ...
ReadClinical Trial Audits: The Independent, Risk-Triggered QA Instrument (Not Monitoring, Not an Inspection)
Audit, monitoring, and inspection get used interchangeably on clinical teams, and that sloppiness is expensive. They are three different instruments with three different owners and three different purposes. This guide pins the distinctions to what the regulations actually require, then walks through...
Read