GCP · Blog
Back to journal

Risk-Based Monitoring in Clinical Trials: The Quality-by-Design Chain That Decides Where a Monitor Goes

Most "what is risk-based monitoring" pages get to the same tired sentence: RBM means doing less 100% source data verification (SDV) to save money. That framing is not just shallow, it is backwards. It treats RBM as a cost lever you pull on the monitoring budget, when RBM is actually the last link in a quality-by-design chain that begins long before anyone opens a monitoring tool. This guide is for the clinical-ops lead, lead CRA, or QA reviewer who is standing up or auditing an RBM program and needs it to be defensible, not just cheaper.

GCP 11 min read
A

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.

On this page · 9 sections
  1. 01 At a glance
  2. 02 RBM in one sentence, and the three things people get wrong
  3. 03 The chain RBM hangs off: critical-to-quality factors, risk assessment, acceptable ranges
  4. 04 QTL vs KRI vs central-monitoring signal: a decision table
  5. 05 The monitoring mix: centralized, targeted on-site, and when on-site is non-negotiable
  6. 06 What ICH E6(R3) and FDA RBM guidance actually require of the sponsor
  7. 07 Building the risk-based monitoring plan: the audited artifact
  8. 08 Where RBM programs fail, and how to avoid it
  9. 09 Sources

At a glance

  • Risk-based monitoring (RBM) is not “less source data verification.” It is the monitoring output of a quality-by-design chain: identify critical-to-quality factors, assess the risks to them, set acceptable ranges, then point monitoring effort where the risk actually is.
  • The chain starts upstream of any tool. ICH E8(R1) tells you to design quality in by identifying critical-to-quality factors; ICH E6(R3) tells you the sponsor must manage the risks to those factors and may set quality tolerance limits; FDA’s 2013 RBM guidance tells you to identify the critical data and build a tailored monitoring plan.
  • A quality tolerance limit (QTL) is a trial-level acceptable range whose breach signals a possible systemic problem. It is not a site-level key risk indicator (KRI) and not a raw central-monitoring signal. Conflating the three is the most common RBM design error.
  • On-site monitoring does not disappear under RBM. It gets targeted, early, complex, and high-risk work, and both ICH and FDA treat fully eliminating on-site monitoring as exceptional, not routine.
  • The audited artifact is the sponsor’s documented monitoring plan. If your QTLs, KRIs, and rationale are not written down and followed, the program is paper-only and will not survive inspection.
  • Buy the tool last. A dashboard cannot tell you which data are critical; that judgment is yours, and the regulations put it on the sponsor.

Most “what is risk-based monitoring” pages get to the same tired sentence: RBM means doing less 100% source data verification (SDV) to save money. That framing is not just shallow, it is backwards. It treats RBM as a cost lever you pull on the monitoring budget, when RBM is actually the last link in a quality-by-design chain that begins long before anyone opens a monitoring tool. This guide is for the clinical-ops lead, lead CRA, or QA reviewer who is standing up or auditing an RBM program and needs it to be defensible, not just cheaper.

RBM in one sentence, and the three things people get wrong

In one sentence: risk-based monitoring is the practice of directing monitoring effort (the mix of centralized analytics and targeted on-site visits) toward the data and processes that matter most to participant safety and result reliability, as identified by a prospective risk assessment.

Three things people get wrong:

  1. They treat RBM as a verb applied to SDV. RBM is not “reduce SDV.” Reduced SDV may be a consequence, but the input is a risk assessment, not a budget target.
  2. They start with the tool. The tool watches risks. If you have not defined the risks, the tool watches noise.
  3. They think centralized monitoring replaces on-site monitoring. It complements it and helps target it. ICH E6(R3) section 3.11.4.2 describes centralized monitoring as providing “additional monitoring capabilities that can complement and reduce the extent and/or frequency of site monitoring or be used on its own,” and notes it “may support the selection of sites and/or processes for targeted site monitoring.” Complement and target, not replace.

The chain RBM hangs off: critical-to-quality factors, risk assessment, acceptable ranges

RBM is the visible output of an upstream chain. Skip a link and the whole thing rests on nothing.

Link 1: Critical-to-quality (CtQ) factors (ICH E8(R1)). ICH E8(R1) Section 3 establishes that a quality-by-design approach focuses on critical-to-quality factors, which it defines as “attributes of a study whose integrity is fundamental to the protection of study participants, the reliability and interpretability of the study results, and the decisions made based on the study results.” E8(R1) also warns that these factors “should be clear and should not be cluttered with minor issues.” That last point is the discipline most programs lack: a CtQ list that includes everything identifies nothing.

Link 2: Risk management on those factors (ICH E6(R3)). ICH E6(R3) section 3.10 requires the sponsor to “adopt a proportionate and risk-based approach to quality management,” incorporating quality by design and identifying critical-to-quality factors “as described in ICH E8(R1).” This is where the two ICH guidelines explicitly hand off to each other. E6(R3) section 3.10.1.1 then requires the sponsor to “identify risks that may have a meaningful impact on critical to quality factors prior to trial initiation and throughout trial conduct,” and section 3.10.1.2 requires evaluating each risk by the likelihood of harm, its detectability, and its impact on participant protection and result reliability.

Link 3: Acceptable ranges and risk control (ICH E6(R3)). E6(R3) section 3.10.1.3 says risk control should be proportionate, and that “where relevant, the sponsor should set pre-specified acceptable ranges (e.g., quality tolerance limits at the trial level) to support the control of risks to critical to quality factors.” Crucially, it ties consequences to a breach: where a deviation beyond these ranges is detected, “an evaluation should be performed to determine if there is a possible systemic issue and if action is needed.”

Link 4: Identify the critical data (FDA RBM, 2013). FDA’s RBM guidance section IV.A tells sponsors to “perform a risk assessment that generally considers the types of data to be collected,” and to focus the plan on data “critical to the reliability of the study findings, specifically those data that support primary and secondary endpoints,” data critical to subject safety such as serious adverse events, and the processes underpinning both. Note FDA’s status: its guidance documents “do not establish legally enforceable responsibilities.” The binding requirement is the regulation itself; FDA’s section II points to 21 CFR 312.50, which requires a sponsor to ensure “proper monitoring of the investigation(s).” RBM is FDA’s recommended way to meet a duty that already exists.

Only after all four links is “what does the monitor do” a question with a real answer.

QTL vs KRI vs central-monitoring signal: a decision table

These three are routinely treated as synonyms. They operate at different levels and trigger different actions. Getting this wrong produces either alarm fatigue or a QTL that never moves.

Quality tolerance limit (QTL)Key risk indicator (KRI)Central-monitoring signal
LevelTrial-wideUsually site or regionAny (often record or visit)
What it isA pre-specified acceptable range on a parameter tied to a critical-to-quality factorA metric tracked against a threshold to flag risk at a unitAn anomaly surfaced by analytics on accumulated data
Source in corpusICH E6(R3) 3.10.1.3 “pre-specified acceptable ranges (e.g., quality tolerance limits at the trial level)“Practitioner construct, not a defined ICH/FDA termICH E6(R3) 3.11.4.2 “evaluation of accumulated data”
Breach meansPossible systemic issue; trigger a documented evaluation (E6(R3) 3.10.1.3)This site warrants attention or a targeted visitInvestigate the anomaly; may feed a KRI or QTL
Reported whereClinical trial report; E6(R3) 3.10.1.6 requires reporting instances where acceptable ranges are exceededInternal dashboards / monitoring reportsCentral monitoring report

The practical rule: a KRI tells you which site to look at; a QTL tells you whether the trial as a whole has a systemic problem worth reporting. Note that “KRI” is a practitioner term, not a defined term in the in-scope regulations; do not present it as a regulatory requirement. The regulatory anchor is the QTL concept in E6(R3) section 3.10.1.3 and its reporting obligation in section 3.10.1.6, which requires the sponsor to summarize and report important quality issues including instances in which acceptable ranges are exceeded.

The monitoring mix: centralized, targeted on-site, and when on-site is non-negotiable

ICH E6(R3) section 3.11.4 frames monitoring as “one of the principal quality control activities” and says “the sponsor should determine the appropriate extent and nature of monitoring based on identified risks,” considering the objective, design, complexity, blinding, number of participants, and endpoints of the trial. That sentence is the whole philosophy: extent follows risk.

Centralized monitoring is, per E6(R3) section 3.11.4.2, “an evaluation of accumulated data, performed in a timely manner, by the sponsor’s qualified and trained persons.” FDA’s guidance is, if anything, more emphatic: it “specifically encourages greater use of centralized monitoring methods where appropriate,” and observes that some problems such as non-random data distributions “may be more readily detected by centralized monitoring techniques than by on-site monitoring.”

On-site monitoring is not a relic. FDA’s RBM guidance section IV.B states that on-site monitoring “ordinarily should be devoted to assessing the critical study data and processes and evaluating significant risks and potential site non-compliance identified through other sponsor oversight activities,” and stresses it is “particularly critical early in a study, especially if the protocol is complex, and includes novel procedures with which investigators may be unfamiliar.”

Where the two regimes are in tension, say so plainly. FDA’s 2013 guidance places greater weight on centralized monitoring than ICH E6 originally did. FDA acknowledges this directly: it “recognizes that this draft guidance places greater emphasis on centralized monitoring than was envisioned at the time ICH E6 was finalized,” and expects industry “will, for the foreseeable future, continue to use some amount of on-site monitoring,” concluding that “the complete absence of on-site monitoring will likely continue to be unusual.” ICH E6(R3) does not mandate a minimum on-site quota, but it does require that the extent and nature of monitoring follow identified risks (section 3.11.4) and that the rationale live in the monitoring plan (section 3.11.4.3). The two are not contradictory, but they emphasize different defaults: do not read FDA’s enthusiasm for centralized methods as license to drop on-site monitoring entirely, and document the rationale either way.

A practical on-site-still-required trigger list, grounded in the above:

  • Early in a complex study, before site procedures are established (FDA section IV.B).
  • Novel procedures investigators may be unfamiliar with (FDA section IV.B).
  • Seriously ill or vulnerable populations, where FDA notes more intensive on-site monitoring may be required to confirm protection.
  • Sites flagged by central analytics or KRIs for targeted follow-up (E6(R3) section 3.11.4.2(c), targeted site monitoring).
  • Critical data and processes that cannot be adequately verified remotely.

What ICH E6(R3) and FDA RBM guidance actually require of the sponsor

Strip away the vendor gloss and the obligations are concrete.

  • The sponsor owns quality management. E6(R3) section 3.10 requires the sponsor to “implement an appropriate system to manage quality throughout all stages of the trial process,” using a proportionate, risk-based approach.
  • Risk identification is prospective and continuous. E6(R3) section 3.10.1.1 requires identifying risks “prior to trial initiation and throughout trial conduct” across processes and systems including computerised systems.
  • There must be a monitoring plan tailored to risk. E6(R3) section 3.11.4.3 requires a monitoring plan “tailored to the identified potential safety risks, the risks to data quality and/or other risks to the reliability of the trial results,” describing “the monitoring strategy, the monitoring activities of all the parties involved, the various monitoring methods and tools to be used, and the rationale for their use.” FDA section IV is aligned: each sponsor should “design a monitoring plan that is tailored to the specific human subject protection and data integrity risks of the trial,” ordinarily mixing centralized and on-site practices.
  • Breaches of acceptable ranges get evaluated and reported. E6(R3) section 3.10.1.3 requires an evaluation when a QTL is exceeded, and section 3.10.1.6 requires reporting such instances and the remedial actions in the clinical trial report.
  • Monitoring is independent. E6(R3) section 3.11.4 requires that “monitoring should be performed by persons not involved in the clinical conduct of the trial at the site being monitored.”

None of these requirements certify your program as compliant. They define what the sponsor remains responsible for. A tool can enable this work; it cannot assume the responsibility, and no software makes a sponsor compliant.

Building the risk-based monitoring plan: the audited artifact

When an inspector arrives, the monitoring plan is the document that either holds up or exposes a paper-only program. Build it as the written record of the chain above. A defensible plan, drawn from E6(R3) section 3.11.4.3 and FDA section IV.D, includes:

  • Critical-to-quality factors for this trial, clearly stated and not cluttered with minor issues (ICH E8(R1) Section 3).
  • Risk assessment mapping each risk to likelihood, detectability, and impact (E6(R3) section 3.10.1.2).
  • Critical data and processes the plan focuses on, including data supporting primary and secondary endpoints and data critical to safety (FDA section IV.A).
  • The monitoring strategy and method mix, with the rationale for each method’s use (E6(R3) section 3.11.4.3).
  • Quality tolerance limits on the parameters tied to critical-to-quality factors, with the action that a breach triggers (E6(R3) section 3.10.1.3).
  • On-site triggers and frequency, modified as knowledge is gained (E6(R3) section 3.11.4.1).
  • Roles and independence, confirming monitors are not involved in site clinical conduct (E6(R3) section 3.11.4).
  • Off-site critical processes, such as central labs or image reading, addressed explicitly (E6(R3) section 3.11.4, monitoring of important data performed outside the investigator site).
  • Documentation and reporting, including how breaches and findings are escalated and recorded (E6(R3) section 3.10.1.6; FDA section IV.E).

This dovetails with sibling topics you should plan alongside the RBM plan: how protocol deviations are tracked and escalated, how essential documents and the trial master file (TMF) capture the evidence trail, and how central monitoring signals route into action. Those are separate plans, but they share the same risk spine.

Where RBM programs fail, and how to avoid it

Tool before risk. The single most common failure: a sponsor buys an analytics platform, configures its out-of-the-box KRIs, and calls it RBM. But the regulations put the critical-data judgment on the sponsor (FDA section IV.A; E6(R3) section 3.10.1.1), and a generic KRI set is not a risk assessment. Fix: complete the CtQ-to-QTL chain on paper first, then configure the tool to watch it.

Vanity KRIs. A dashboard full of green tiles measuring query rates and enrollment pace, none of which connect to a critical-to-quality factor, is theater. The audit question that exposes it: “Show me which critical-to-quality factor this indicator protects, and what action a breach triggers.” If the answer is silence, the KRI is decoration. Fix: every indicator should trace to a CtQ factor and a defined action, consistent with E6(R3) section 3.10.1.3’s requirement that a breach drives an evaluation.

QTL drift. Teams set quality tolerance limits at study start, then never revisit them, so the limits stop reflecting the trial. E6(R3) section 3.10.1.5 requires the sponsor to “periodically review risk control measures to ascertain whether the implemented quality management activities remain effective and relevant,” and section 3.10.1.6 requires reporting instances where ranges are exceeded. A QTL nobody monitors or reports against is the inspection finding waiting to happen. Fix: schedule the risk review and log it.

Paper-only plans. The plan exists, beautifully written, but the monitoring activity on the ground does not follow it. E6(R3) section 3.11.4.4 is blunt: persons performing monitoring “should follow the sponsor’s monitoring plan and applicable monitoring procedures.” The plan is the audited artifact; divergence between plan and practice is exactly what an inspector looks for. Fix: make the plan operational and check adherence as part of the risk review.

The throughline is the same idea the top-of-funnel content misses: RBM is not a monitoring discount. It is the disciplined act of letting risk decide where effort goes, documented well enough that the discipline survives an inspection.

Sources

  • ICH E6(R3) Good Clinical Practice (ICH, version r3, effective 2025) — https://www.ich.org/page/efficacy-guidelines
  • ICH E8(R1) General Considerations for Clinical Studies (ICH, version r1, 2021)
  • FDA Guidance: Oversight of Clinical Investigations — Risk-Based Monitoring (FDA, 2013)
A

Written by

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.