Quality by Design in Clinical Trials: A Critical-to-Quality (CtQ) Identification Workflow, Not a Philosophy Lecture
Most "Quality by Design" explainers stop at the slogan and then list the ICH E8 CtQ categories as if naming them were the work. The work is the opposite: deciding which handful of factors actually matter for your protocol, and then deliberately not engineering controls around the rest. This guide treats QbD as a CtQ-identification workflow you can run in a protocol-design meeting, carries one factor end to end into a monitoring trigger, and names where teams reliably get it wrong.
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
On this page · 12 sections
- 01 At a glance
- 02 QbD in one sentence, and the misreading that wastes the most effort
- 03 Where QbD lives: design-time (E8) vs execution-time (E6 RBQM and QTLs)
- · QbD vs RBQM vs QTL, so you stop conflating them
- 04 The CtQ-identification workflow: from objective to errors that matter to CtQ factors
- · A worked CtQ example: primary-endpoint measurement carried to a monitoring trigger
- 05 Who is in the room: cross-functional CtQ review as a risk exercise
- 06 From E8(R1) to E6(R3): what reviewers now expect documented
- 07 Where teams get it wrong
- 08 QbD without a quality department: a minimum-viable version
- · Protocol-meeting CtQ worksheet
- 09 Sources
At a glance
- Quality by Design (QbD) is not “more quality everywhere.” ICH E8(R1) frames it as proactively designing quality into the protocol and processes, then concentrating effort on a short list of Critical-to-Quality (CtQ) factors whose failure would undermine participant protection or the reliability of the results.
- The single most expensive misreading is treating everything as critical. E8(R1) explicitly says CtQ factors should be prioritised and “should not be cluttered with minor issues,” and that study procedures should be proportionate to the risks.
- QbD is design-time (ICH E8(R1)). RBQM and Quality Tolerance Limits are execution-time (ICH E6(R3) §3.10). They are connected, not synonyms: E6(R3) names QbD as the front end of the sponsor’s quality management system.
- A CtQ factor becomes operational when you attach a risk control to it. Under E6(R3) §3.10.1.3, that control can be a pre-specified acceptable range (a Quality Tolerance Limit) whose breach triggers an evaluation for a systemic issue.
- ISO 31000:2018 supplies the underlying risk vocabulary (risk = effect of uncertainty on objectives; assessment = identification, analysis, evaluation) that makes “proportionate” a defensible judgment rather than a slogan.
- Small and academic sponsors are in scope. Neither E8(R1) nor E6(R3) requires a quality department; they require that CtQ factors be identified prospectively and that controls be proportionate.
Most “Quality by Design” explainers stop at the slogan and then list the ICH E8 CtQ categories as if naming them were the work. The work is the opposite: deciding which handful of factors actually matter for your protocol, and then deliberately not engineering controls around the rest. This guide treats QbD as a CtQ-identification workflow you can run in a protocol-design meeting, carries one factor end to end into a monitoring trigger, and names where teams reliably get it wrong.
QbD in one sentence, and the misreading that wastes the most effort
ICH E8(R1) §3.1 states that quality by design in clinical research “sets out to ensure that the quality of a study is driven proactively by designing quality into the study protocol and processes,” using a prospective, multidisciplinary approach proportionate to the risks involved. Quality is treated as fitness for purpose, not perfection.
The misreading is “everything is critical.” It feels safe and it is the most common way teams waste money. ICH E8(R1) §3.2 is blunt about the antidote: a basic set of factors should be identified, “emphasis should be given to those factors that stand out as critical,” and the CtQ factors “should not be cluttered with minor issues.” E8(R1) §3.2 also reminds teams that perfection in every aspect “is rarely achievable or can only be achieved by use of resources that are out of proportion to the benefit obtained,” and that procedures should be proportionate to the risks inherent in the study and the importance of the information collected. A CtQ list of forty items is not thoroughness; it is a failure to prioritise, and it is the anti-pattern E8(R1) is written to prevent.
One disambiguation before going further: this article is about clinical-trial QbD. Pharmaceutical CMC and manufacturing QbD (design space, design of experiments, process characterisation) is a different discipline that happens to share the acronym. Do not import its tooling here.
Where QbD lives: design-time (E8) vs execution-time (E6 RBQM and QTLs)
The two regulations are sequential, not redundant.
ICH E8(R1) is the design-time front end. E8(R1) §3.2 places CtQ identification with the sponsor: “the sponsor and other parties designing quality into a clinical study should identify the critical to quality factors,” and having identified them, the team determines the risks that threaten their integrity and decides whether to accept or mitigate them based on probability, detectability and impact.
ICH E6(R3) is the execution-time machinery. E6(R3) §3.10 requires the sponsor to implement a proportionate, risk-based quality management system, and it explicitly names QbD as part of that system: incorporating quality into the design of the trial “(i.e., quality by design)” and identifying “critical to quality factors as described in ICH E8(R1).” So E6(R3) does not re-invent QbD; it imports it by reference and then adds the risk-management loop that runs while the trial is live.
That loop, in E6(R3) §3.10.1, is risk identification, evaluation, control, communication, review and reporting. The connective tissue you care about sits in §3.10.1.3 Risk Control: control should be proportionate to the importance of the risk, and “where relevant, the sponsor should set pre-specified acceptable ranges (e.g., quality tolerance limits at the trial level) to support the control of risks to critical to quality factors.” That one sentence is where a design-time CtQ factor turns into an execution-time Quality Tolerance Limit.
QbD vs RBQM vs QTL, so you stop conflating them
- QbD (ICH E8(R1), design-time): the prospective practice of building quality into the protocol and identifying CtQ factors before the trial starts. It answers “what matters?”
- RBQM / risk-based quality management (ICH E6(R3) §3.10, execution-time): the sponsor’s system for identifying, evaluating, controlling, reviewing and reporting risks to those CtQ factors throughout conduct. It answers “how do we protect what matters, proportionately?”
- QTL / Quality Tolerance Limit (ICH E6(R3) §3.10.1.3, a control, not a category): a specific pre-specified acceptable range at the trial level for a CtQ-linked parameter; a breach should trigger an evaluation of whether there is a systemic issue. It is one risk-control mechanism, not a synonym for monitoring and not required for every factor.
A QTL is not the same as a site-level alert or an individual data query. E6(R3) §3.10.1.3 frames QTLs as trial-level ranges whose breach signals a possible systemic problem worth investigating, which is why you want a few well-chosen ones rather than dozens.
The CtQ-identification workflow: from objective to errors that matter to CtQ factors
Run this as a sequence, ideally in a cross-functional protocol-design meeting rather than alone at a desk.
- State the trial objective in one sentence. ICH E8(R1) §2.2 anchors the whole approach in clear, explicitly stated primary objectives that reflect the research question. If you cannot write the objective plainly, you cannot identify what is critical to it.
- Ask what errors would actually matter. E8(R1) §3.2 defines CtQ factors as attributes “whose integrity is fundamental to the protection of study participants, the reliability and interpretability of the study results, and the decisions made based on the study results,” and they are critical precisely because if their integrity “were to be undermined by errors of design or conduct, the reliability or ethics of decision-making” would be undermined too. The test is therefore not “could this go wrong?” but “would this going wrong invalidate the result or harm a participant?”
- Name the candidate factors and prioritise ruthlessly. E8(R1) §3.3.2 tells teams to focus on activities essential to the reliability and meaningfulness of outcomes and the safe, ethical conduct of the trial, and to deploy resources “to identify and prevent or control errors that matter.” Consider the factors holistically so dependencies surface, as E8(R1) §3.2 advises.
- Decide accept vs mitigate per factor. For each CtQ factor, E8(R1) §3.2 asks you to weigh probability, detectability and impact, then either accept the risk or put a control in place. This is the same triad E6(R3) §3.10.1.2 uses for risk evaluation (likelihood of harm, detectability, impact on participant protection and reliability), which is why the design-time and execution-time views line up cleanly.
- Attach a control and, where relevant, a QTL. Per E6(R3) §3.10.1.3, controls are proportionate, and a CtQ-linked parameter may get a pre-specified acceptable range whose breach triggers an evaluation.
ISO 31000:2018 is the vocabulary underneath steps 2 to 5. Its §3.1 defines risk as the “effect of uncertainty on objectives,” which is exactly why CtQ work starts from the objective. Its §6.4 defines risk assessment as the combination of risk identification, risk analysis and risk evaluation, and §6.4.3 says risk analysis considers the likelihood of events and the nature and magnitude of consequences. When E8(R1) and E6(R3) say “proportionate,” ISO 31000 §6.4.4 is the discipline that makes proportionality auditable: you compare the analysed risk against pre-set criteria and decide whether further action is required.
A worked CtQ example: primary-endpoint measurement carried to a monitoring trigger
Take a trial whose objective is to show a difference in a primary efficacy endpoint measured by a specific instrument at week 12.
- Candidate factor: accuracy and completeness of the primary-endpoint measurement at the primary timepoint.
- Does failure invalidate the result or harm subjects? Yes. If the primary-endpoint data are unreliable or substantially missing, the trial cannot answer its question, and per E8(R1) §3.2 the reliability and interpretability of the result is undermined. So this is a CtQ factor, not a minor issue.
- Risk evaluation (E6(R3) §3.10.1.2; ISO 31000 §6.4.3): likelihood of mis-measurement or missingness, detectability through central data review, impact on the primary analysis.
- Control (E6(R3) §3.10.1.3): a trial-level Quality Tolerance Limit on the proportion of primary-endpoint assessments missing or out of window at week 12.
- Monitoring trigger: if the QTL is breached, E6(R3) §3.10.1.3 requires an evaluation to determine whether there is a possible systemic issue and whether action is needed, and §3.10.1.6 requires that such breaches and the remedial actions be summarised and reported in the clinical trial report.
Note what did not get a QTL: a non-critical secondary quality-of-life sub-scale collected for exploratory interest. E8(R1) §3.2 specifically warns against cluttering the CtQ list with extensive secondary objectives not linked to participant protection or the primary objective. Leaving it off the CtQ list is the proportionate decision, not negligence.
Who is in the room: cross-functional CtQ review as a risk exercise
CtQ identification is a judgment call made by people, not a checklist run by one function. ICH E8(R1) §3.3.1 encourages “a culture that values and rewards critical thinking and open, proactive dialogue about what is critical to quality,” explicitly “going beyond sole reliance on tools and checklists,” and discourages inflexible, one-size-fits-all approaches. E8(R1) §3.3.3 adds that study design should be open to challenge by subject-matter experts inside and outside the sponsor, including clinical investigators, study coordinators and patients.
In practice that means clin-ops, data management, medical, biostatistics and QA negotiating the list together, because a factor that looks trivial to one function (an eligibility criterion, an informed-consent step, an endpoint window) is often load-bearing for another. ISO 31000 §6.4.1 reinforces this: risk assessment “should be conducted systematically, iteratively and collaboratively, drawing on the knowledge and views of stakeholders.” The cross-functional meeting is not bureaucratic theatre; it is the mechanism the guidelines assume.
From E8(R1) to E6(R3): what reviewers now expect documented
The two-document chain is the reason QbD is no longer optional framing. E6(R3) §3.10 requires the sponsor to describe the quality management approach implemented in the trial in the clinical trial report, and E8(R1) §6.3 says the report should describe the CtQ factors in the study. So the audit-time expectation is a documented trail: CtQ factors identified prospectively, the risks to them evaluated, the controls (including any QTLs) chosen proportionately, and any QTL breaches and remedial actions reported per E6(R3) §3.10.1.6.
There is no genuine conflict between these regulations on this point; they align by design, with E6(R3) §3.10 importing E8(R1)‘s CtQ concept by name. The only tension worth flagging is one of emphasis and timing: E8(R1) speaks in the language of study design and planning, while E6(R3) speaks in the language of an ongoing quality management system with periodic risk review (E6(R3) §3.10.1.5). A team that does brilliant design-time CtQ work and then never revisits it during conduct satisfies the letter of E8(R1) but not the review-and-adjust loop E6(R3) §3.10.1.5 expects. Treat the two as one continuous workflow, not two filings.
Where teams get it wrong
- The “CtQ list of 40.” Over-inclusive lists are the dominant failure mode, and they are the exact behaviour E8(R1) §3.2 warns against when it says CtQ factors should not be cluttered with minor issues. A long list dilutes attention and converts a risk-based system back into “check everything.”
- Over-monitoring as a proxy for quality. E8(R1) §3.1 notes that retrospective document review and monitoring, even combined with audits, “are not sufficient to ensure quality of a clinical study.” Bolting on more source-data verification does not substitute for designing quality in; it is the costly habit QbD exists to replace.
- Conflating a QTL with every alert. E6(R3) §3.10.1.3 frames QTLs as trial-level pre-specified ranges signalling possible systemic issues, not as a per-site or per-data-point threshold. Setting dozens of “QTLs” recreates the over-monitoring trap under a new name.
- One-and-done CtQ work. E6(R3) §3.10.1.5 requires periodic review of risk controls as knowledge and experience accumulate, and E8(R1) §3.3.4 says periodic review of CtQ factors should drive adjustments when new or unanticipated issues arise. A CtQ list frozen at protocol approval misses this.
QbD without a quality department: a minimum-viable version
Small and academic sponsors are not exempt, and they are not required to build infrastructure they do not have. E6(R3) §3.10 asks for a quality management approach that is proportionate, and E8(R1) §3.2 places CtQ identification on the sponsor without prescribing a department. The minimum-viable version is a short, defensible workflow:
- Write the trial objective in one sentence (E8(R1) §2.2).
- In one cross-functional meeting, list candidate factors and apply the single test from E8(R1) §3.2: would failure invalidate the result or harm participants? Keep only those.
- For each surviving CtQ factor, record likelihood, detectability and impact (E6(R3) §3.10.1.2), and decide accept vs mitigate (E8(R1) §3.2).
- For the few factors that warrant it, set a trial-level acceptable range and define what a breach triggers (E6(R3) §3.10.1.3).
- Schedule one review point (E6(R3) §3.10.1.5) and capture all of it in the protocol and clinical trial report (E8(R1) §6.3, E6(R3) §3.10).
That is a complete, proportionate QbD program. It is small because proportionality is the point, not a concession.
Protocol-meeting CtQ worksheet
Run one row per candidate factor:
| Trial objective | Candidate factor | Does failure invalidate the result or harm subjects? | CtQ? | Linked control / QTL | Monitoring trigger |
|---|---|---|---|---|---|
| (one sentence) | e.g. primary-endpoint measurement at wk 12 | Yes, unreliable endpoint invalidates the primary analysis | Yes | Trial-level QTL on missing/out-of-window primary assessments | Breach prompts systemic-issue evaluation (E6(R3) §3.10.1.3) |
| (same) | e.g. exploratory secondary sub-scale | No, exploratory only | No | None; routine handling | None |
If most rows answer “no,” you are doing it right. A worksheet where every row says “yes” is the signal to stop and re-read E8(R1) §3.2.
Related explainers on this site go deeper on the execution-time machinery this article only frames: the Quality Tolerance Limits explainer, the protocol-deviation classification guide, the risk-based monitoring (RBQM) pillar, and the QMS-under-E6(R3) overview. None of these regulations certifies a trial “compliant” by virtue of having a CtQ list; they require that the sponsor identify what is critical, control it proportionately, and stay responsible for the judgment throughout.
Sources
- ICH E8(R1) General Considerations for Clinical Studies, version r1 (ICH, 2021) — quality by design principles and Critical-to-Quality factor identification (Sections 2.2, 3.1, 3.2, 3.3, 6.3).
- ICH E6(R3) Good Clinical Practice, version r3 (ICH, 2025) — risk-based quality management system, risk management loop, and Quality Tolerance Limits (Sections 3.10, 3.10.1.1–3.10.1.6, 3.11). https://www.ich.org/page/efficacy-guidelines
- ISO 31000:2018 Risk management — Guidelines, version 2018 (ISO) — risk definition and the risk-assessment vocabulary (identification, analysis, evaluation) applied to CtQ proportionality (Sections 3.1, 6.4, 6.4.3, 6.4.4). https://www.iso.org/standard/65694.html
Written by
Aileen
Aileen writes practical guidance for clinical trial teams at GCP Blog.
Continue reading
The Living Data Management Plan: A Risk-Based DMP Template That Survives Database Lock and Inspection
A Data Management Plan that passes internal review but falls apart at database lock is the most common failure mode in clinical data management (CDM). It usually happens because the team treated the DMP as a document to produce, not a control system to operate. This guide hands you an annotated temp...
ReadQuery Management in Clinical Data Management: A Closure-Clock Playbook for One-Round Resolution
Most query guides hand you two definitions (manual versus system-generated) and a four-box lifecycle, then stop. That is the part of query management that does not actually cost you anything. What costs you is the re-query loop: a vague query goes to the site, the coordinator answers the wrong thing...
ReadThe Investigator Site File as an Inspection-Ready Evidence System: Reconciling the ISF to the TMF, and the Four Failure Modes Inspectors Cite
This guide is written for the people who actually host the visit: CRCs, PIs, and site QA/regulatory coordinators preparing for, or recovering from, a monitoring visit or a BIMO/MHRA/EMA inspection. The pain it addresses is specific: "my binder looks complete, but I don't know what an inspector will ...
Read