GCP · Blog
Back to journal

The Quality-by-Design Clinical Trial Protocol: Engineering Out Deviations with Critical-to-Quality Factors and a Defensible Schedule of Activities

A protocol is the document that describes how a clinical trial will be conducted, and under ICH E6(R3) it is the instrument that operationalizes Good Clinical Practice for one specific study. The guideline states plainly that clinical trials should be described in a clear, concise, scientifically sound and operationally feasible protocol, and that a well-designed trial protocol is fundamental to the protection of participants and the generation of reliable results (ICH E6(R3) Principle 8). The protocol is not paperwork that precedes the real work; it is the design itself.

GCP 14 min read
A

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.

On this page · 10 sections
  1. 01 At a glance
  2. 02 What a clinical trial protocol is, and the job it actually has to do
  3. 03 The E6(R3) required elements, mapped
  4. 04 Quality by Design first: identifying your critical-to-quality factors before you write a word
  5. 05 The Schedule of Activities: the load-bearing table
  6. 06 Where protocol design silently creates protocol deviations
  7. 07 SPIRIT, NIH-FDA templates and E6(R3): what the templates give you and what they don’t
  8. 08 What a real protocol review interrogates
  9. 09 Endpoints, estimands and the statistics the protocol must lock
  10. 10 Sources

At a glance

  • A clinical trial protocol is the governing document for a study, not a template to fill in. ICH E6(R3) treats a clear, concise and operationally feasible protocol as fundamental to participant protection and reliable results.
  • Quality by Design means identifying the factors critical to quality (CtQ) before you write a section, then designing each protocol decision and Schedule of Activities (SoA) row to protect those factors. ICH E8(R1) is explicit that retrospective review and monitoring are not sufficient to ensure quality.
  • The SoA is the load-bearing table. Over-specified visit windows, assessments your population cannot meet, and unanchored “must” language are design choices that manufacture protocol deviations downstream.
  • Endpoints, estimands and the statistical analysis must be locked in the protocol so that design and analysis agree. ICH E9(R1) requires the estimand to be specified at the initial stages of planning and the design to be aligned to it.
  • Completeness is not soundness. A protocol can contain every E6(R3) Appendix B element and still be deviation-prone. Review the design, not just the section list.
  • The sponsor stays responsible. Quality by Design and a good protocol enable compliance; they do not certify it, and oversight cannot be delegated away.

What a clinical trial protocol is, and the job it actually has to do

A protocol is the document that describes how a clinical trial will be conducted, and under ICH E6(R3) it is the instrument that operationalizes Good Clinical Practice for one specific study. The guideline states plainly that clinical trials should be described in a clear, concise, scientifically sound and operationally feasible protocol, and that a well-designed trial protocol is fundamental to the protection of participants and the generation of reliable results (ICH E6(R3) Principle 8). The protocol is not paperwork that precedes the real work; it is the design itself.

Two operational consequences follow immediately. First, a trial should be conducted in compliance with the protocol that received prior IRB/IEC approval, and the investigator should comply with the protocol, GCP and applicable regulatory requirements (ICH E6(R3) §2.5.2). Every clause you write becomes a binding instruction that sites must follow or formally deviate from. Second, the protocol does not stand alone: ICH E6(R3) §8.3 expects the protocol and the plans for its execution, such as the statistical analysis plan, data management plan and monitoring plan, to be clear, concise and operationally feasible together. A protocol that cannot be executed as written is not a compliant protocol; it is a deviation generator.

This is the gap most “definitive guide” pages miss: they define each section in isolation and conflate “has all the sections” with “is well-designed.” This guide takes the opposite stance, designing the protocol around its critical-to-quality factors and a defensible Schedule of Activities so quality is engineered in at authoring time rather than patched later through deviations.

The E6(R3) required elements, mapped

ICH E6(R3) Appendix B sets out the topics a trial protocol should generally include, noting they may vary with the trial design. Use this as a deliverable checklist, not a tick-box exercise. The contents below trace to Appendix B sections B.1 through B.16.

Protocol areaE6(R3) Appendix B anchorWhat it must establish
General informationB.1Protocol title, unique identifying number and date; sponsor name and address; person authorised to sign
BackgroundB.2Investigational product description; relevant nonclinical and clinical findings; known and potential risks/benefits; a statement that the trial will be conducted in compliance with the protocol, GCP and applicable regulatory requirements (B.2.5)
Objectives and purposeB.3A clear description of scientific objectives and purpose; information on estimands, when defined
Trial designB.4Statement of primary and secondary endpoints; type and design of trial with a schematic; measures to minimise bias (randomisation, blinding); the schedule of events (B.4.6); duration of involvement; stopping/discontinuation rules
Selection of participantsB.5Inclusion criteria; exclusion criteria; pre-screening and screening mechanism
Discontinuation and withdrawalB.6When and how to discontinue; data handling for withdrawn participants; replacement; follow-up
Treatment and interventionsB.7Treatments, doses, dosing schedule, dose-adjustment criteria; permitted and prohibited concomitant/rescue medication; adherence-monitoring strategy
Assessment of efficacyB.8Efficacy parameters; methods and timing for assessing, recording and analysing them
Assessment of safetyB.9Safety parameters; methods, extent and timing of recording; adverse-event reporting; post-event follow-up
Statistical considerationsB.10Statistical methods and interim-analysis plan; sample size and its justification; significance level; analysis-set selection and handling of intercurrent events, aligned with target estimands
Direct accessB.11Specification that investigators permit monitoring, audit and inspection with direct access to source records
QC/QA, ethics, data handling, financing, publicationB.12-B.16Quality control and assurance; ethics; data handling and record keeping; financing and insurance; publication policy

The checklist tells you what topics must be present, not whether your protocol is sound. That is the work of the next three sections.

Quality by Design first: identifying your critical-to-quality factors before you write a word

ICH E8(R1) §3.1 makes the central claim that drives this whole approach: the likelihood that a study will answer its research questions while preventing important errors can be dramatically improved through prospective attention to the design of all components of the study protocol, procedures and operational plans. Crucially, it states that document and data review and monitoring conducted retrospectively, even combined with audits, are not sufficient to ensure quality of a clinical study. You cannot inspect quality into a protocol after the fact. You design it in.

The mechanism is the critical-to-quality factor. ICH E8(R1) §3.2 defines critical-to-quality factors as attributes of a study whose integrity is fundamental to the protection of study participants, the reliability and interpretability of the results, and the decisions made based on those results. The sponsor and other parties designing quality into a study should identify these factors, then determine the risks that threaten their integrity and decide, based on probability, detectability and impact, whether each risk is accepted or mitigated. ICH E6(R3) §3.10 carries the same concept into GCP, requiring the sponsor to incorporate quality into the design of the trial (quality by design) and to identify the factors likely to have a meaningful impact on participants’ rights, safety and well-being and the reliability of results, explicitly cross-referencing the CtQ factors described in ICH E8(R1).

E8(R1) §3.3.2 sharpens this into a design discipline: focus effort on activities essential to the reliability and meaningfulness of outcomes and the safe, ethical conduct of the study, and give consideration to eliminating nonessential activities and data collection to increase quality by simplifying conduct. Every assessment you add is a liability unless it protects a CtQ factor, the opposite of the template instinct, which adds sections and assessments because the template has a slot for them.

Use a CtQ worksheet to force each factor down to a concrete, auditable design decision and the SoA row that proves it.

Critical-to-quality factorWhy it is critical (E8 §3.2 lens)Design decision in the protocolSoA row that proves it
Eligibility integrityWrong population undermines interpretability and ethicsInclusion/exclusion criteria operationalized to objective, source-verifiable measuresScreening labs and confirmatory diagnostic at Visit 1, before randomisation
Primary endpoint captureEndpoint loss undermines reliability of resultsPrimary endpoint assessment timed to a window sites can realistically meetPrimary endpoint assessment row with a defensible visit window
Safety signal detectionLate detection threatens participant safetySafety parameters and timing proportionate to known IP riskVital signs / labs / AE review at risk-aligned, not reflexive, intervals
Treatment adherenceNon-adherence as an intercurrent event distorts the estimandAdherence-monitoring strategy specified per B.7.3Drug accountability and adherence check at each dosing visit
Data reliability for analysisMissing/inconsistent data weakens decision-makingOnly data required by the protocol are collected (avoid non-essential capture)SoA contains no orphan assessments that feed no endpoint or safety need

ICH E8(R1) §3.3.5 reinforces that the foundation of a successful study is a protocol that is both scientifically sound and operationally feasible, and that feasibility considerations include whether investigators can enrol the targeted population and whether scheduled visits and procedures may be overly burdensome and lead to early dropouts. Feasibility is not a separate workstream run after drafting; it is a CtQ factor you design against.

The Schedule of Activities: the load-bearing table

ICH E6(R3) §B.4.6 requires the trial design to include the schedule of events, namely trial visits, interventions and assessments. The SoA is where Quality by Design either holds or collapses, because it is the one artifact that translates every abstract design choice into an instruction a site executes on a specific day. A protocol can have a flawless objectives section and a fatal SoA.

E6(R3) is unusually direct about how to build adaptability in. Appendix B states that building adaptability into the protocol, for example by including acceptable ranges for specific protocol provisions, can reduce the number of deviations or, in some instances, the requirement for a protocol amendment, and that such adaptability should not adversely affect participant safety or the scientific validity of the trial. That single sentence is the difference between a deviation-prone SoA and a defensible one. Visit windows are the canonical “acceptable range.”

Here is an annotated comparison of the same two SoA rows, written once as a deviation generator and once as a defensible, QbD-native row.

SoA elementDeviation-prone versionDefensible (QbD) versionWhy the difference matters
Follow-up visit timing”Visit 4 occurs on Day 28.""Visit 4 occurs on Day 28 (window Day 25-31).”A fixed day with no window converts every real-world scheduling slip into a protocol deviation. E6(R3) Appendix B endorses acceptable ranges to reduce deviations.
Fasting biomarker”Fasting glucose drawn at every visit.""Fasting glucose drawn at Visits 1 and 4 (endpoint-linked); not required at interim safety visits.”E8(R1) §3.3.2 says eliminate non-essential data collection; an assessment that feeds no endpoint or safety need is burden, not quality.
Imaging assessment”MRI performed at each site at every visit.""MRI at screening and at the primary-endpoint visit; performed only where the modality is available per feasibility assessment.”E8(R1) §3.3.5 ties feasibility (equipment and site capability) to design; specifying an assessment sites cannot deliver guarantees deviations.
Mandatory language”Participants must complete the diary daily.""Participants are asked to complete the diary daily; missing entries are recorded but do not constitute a deviation.”Unanchored “must” creates a binding obligation under §2.5.2; absent a CtQ rationale, it manufactures deviations from ordinary human behavior.

The governing test for every SoA row: does this assessment, at this timing and window, protect a named critical-to-quality factor? If not, E8(R1) §3.3.2 tells you to consider removing it. If yes, calibrate the window and the “must” so a good-faith site can actually hit them.

Where protocol design silently creates protocol deviations

ICH E6(R3) §2.5.3 requires the investigator to document all protocol deviations, and §3.9.3 requires the sponsor to define trial-specific criteria for classifying deviations as important, where important protocol deviations are the subset that may significantly impact the completeness, accuracy or reliability of the trial data, or significantly affect a participant’s rights, safety or well-being. A protocol that generates many avoidable deviations buries the important ones in noise and burns out sites and monitors chasing them.

Most avoidable deviations are authored, not committed. Three patterns dominate:

  • Over-specified visit windows. A precise day with no acceptable range, as discussed above, turns normal scheduling variance into recorded deviations. E6(R3) Appendix B explicitly offers acceptable ranges as the remedy.
  • Ineligible or undeliverable assessments. Requiring a procedure the target population or the site cannot reliably perform contradicts the feasibility discipline of E8(R1) §3.3.5 and produces systematic deviations from day one.
  • Unanchored “must” language. Mandatory phrasing that is not tied to a CtQ factor under E8(R1) §3.2 elevates trivial variation to the status of a binding breach. Reserve “must” for what genuinely protects participants or result reliability.

There is a sponsor-side control that connects design to conduct. ICH E6(R3) §3.10.1.3 provides that, where relevant, the sponsor should set pre-specified acceptable ranges, for example quality tolerance limits at the trial level, that reflect limits which, when exceeded, have the potential to impact participant safety or the reliability of trial results; where a deviation beyond these ranges is detected, an evaluation should determine whether there is a systemic issue and whether action is needed. Quality tolerance limits are not visit windows. A QTL is a trial-level threshold (for example, a maximum acceptable rate of a given deviation) that signals when accumulating deviations point to a design problem rather than isolated noise. Designing QTLs at authoring time closes the loop between a sloppy SoA and the systemic signal it produces.

SPIRIT, NIH-FDA templates and E6(R3): what the templates give you and what they don’t

Practitioners reach for the SPIRIT 2013 reporting guidance and the NIH-FDA protocol template, and they should: the templates give you a defensible section skeleton and consistent structure. But note the boundary clearly. SPIRIT is a reporting guideline, not a regulation, and it is not part of the in-scope corpus for compliance claims here. Anchor every compliance obligation to ICH E6(R3), E8(R1) and E9(R1), and treat SPIRIT and the NIH-FDA template as external structural scaffolding.

What templates give you is completeness: every section present, in a recognised order. What they do not give you is design soundness. A template has no opinion on whether your visit windows are operable, whether an assessment maps to a CtQ factor, or whether your endpoints and estimands agree. It can produce a protocol that satisfies the E6(R3) Appendix B contents list and still generates deviations, because that list (per Appendix B, “may vary depending on the trial design”) is necessary, not sufficient. Use the template to avoid omissions; use Quality by Design to avoid failures.

What a real protocol review interrogates

Completeness review asks “is every section here?” Design review asks “will this protocol survive audit and the site?” The two are different activities, and conflating them is the core mistake the gap-to-beat pages make. Run this reviewer’s decision checklist, which interrogates design soundness against the in-scope guidelines:

  • Objectives and estimands. Are scientific objectives clearly and explicitly stated (E6(R3) Principle 8.2), and where defined, are estimands present in B.3? ICH E9(R1) §A.3.4 requires the clinical questions of interest and associated estimands to be specified at the initial stages of planning. If the objective cannot be mapped to an estimand, the design is not locked.
  • CtQ traceability. Can each major design choice and assessment be traced to a critical-to-quality factor (E8(R1) §3.2)? Are non-essential assessments removed (E8(R1) §3.3.2)? Orphan assessments are a finding, not a courtesy.
  • SoA operability. Does every timed event carry a defensible window, and can a good-faith site hit it (E6(R3) Appendix B acceptable ranges; E8(R1) §3.3.5 feasibility)?
  • Deviation surface. Does the “must” language map to genuine CtQ obligations, or does it manufacture deviations (E6(R3) §2.5.3, §3.9.3)? Are important-deviation criteria defined (§3.9.3)?
  • Design/analysis agreement. Do the endpoints (B.4.1), the statistical considerations (B.10), the handling of intercurrent events and the analysis sets align with the target estimands (B.10.4; E9(R1) §A.4)?
  • Risk and tolerance. Are risks to CtQ factors identified prospectively (E6(R3) §3.10.1.1) and, where relevant, quality tolerance limits set (§3.10.1.3)?

A protocol that passes this checklist is design-sound. One that merely passes a contents check is template-complete, which is not the same thing.

Endpoints, estimands and the statistics the protocol must lock

This is where design and analysis must be made to agree at authoring time, because E6(R3) pushes the statistical lock into the protocol. Appendix B.10.1 requires a description of the statistical methods, including the timing and purpose of any interim analyses and the criteria for stopping the trial; B.10.2 requires the planned sample size and the reason for it, including power calculations and clinical justification; and B.10.4 requires that the selection of participants for the planned analyses, the statistical methods, and the procedures for handling intercurrent events and missing data be aligned with the target estimands, when defined (cross-referencing E9(R1)).

ICH E9(R1) supplies the discipline behind that alignment. §A.3.3 sets out the estimand attributes used to construct the treatment effect of interest: the treatment condition (and any comparator), the population, the variable (endpoint) to be obtained for each patient, the handling of intercurrent events, and a population-level summary measure for comparison between treatment conditions. §A.3.4 requires these clinical questions and estimands to be specified at the initial stages of planning, and §A.4 states that the design of a trial needs to be aligned to the estimands that reflect the trial objectives, informing the inclusion and exclusion criteria, the permitted and prohibited medications, and other aspects of patient management and data collection. The estimand is therefore not a statistician’s afterthought bolted on at analysis; it shapes B.5 eligibility, B.7 concomitant medication rules, and the SoA’s data-collection timing.

Two guideline demands sit close enough to feel like one rule, and a careful drafter keeps them distinct. E9(R1) §A.4 requires the trial design to be aligned to the estimand. E6(R3) §3.16.2(d) requires the sponsor to pre-define, in the protocol or the statistical analysis plan, the criteria for inclusion or exclusion of participants from any analysis set, and §3.16.2(e) requires that deviations from the planned statistical analysis occur only in exceptional circumstances and be documented and justified. The two are aligned in intent (lock the analysis to the design before data are seen) but place the obligation at different artifacts: E9(R1) on the estimand and trial design, E6(R3) on the protocol or SAP. A protocol that names a primary endpoint but defers the estimand, analysis-set definitions and intercurrent-event handling to a later document satisfies neither. Lock the estimand, the endpoints, the analysis sets and the intercurrent-event strategy in the protocol, and design and analysis will agree by construction rather than by amendment.

Sources

  • ICH E6(R3) Good Clinical Practice (version r3) — https://www.ich.org/page/efficacy-guidelines
  • ICH E8(R1) General Considerations for Clinical Studies (version r1) — ICH
  • ICH E9(R1) Statistical Principles for Clinical Trials, Addendum on Estimands and Sensitivity Analysis (version r1) — ICH
  • SPIRIT 2013 Statement and the NIH-FDA Clinical Trial Protocol Template are referenced as external best-practice context only and are not regulatory sources.
A

Written by

Aileen

Aileen writes practical guidance for clinical trial teams at GCP Blog.