<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20120330//EN" "http://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd">
<!--<?xml-stylesheet type="text/xsl" href="article.xsl"?>-->
<article article-type="research-article" dtd-version="1.2" xml:lang="en" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id journal-id-type="issn">2694-1473</journal-id>
<journal-title-group>
<journal-title>Journal of the Society for Clinical Data Management</journal-title>
</journal-title-group>
<issn pub-type="epub">2694-1473</issn>
<publisher>
<publisher-name>Society for Clinical Data Management</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.47912/jscdm.524</article-id>
<article-categories>
<subj-group>
<subject>GCDMP&#169;</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Risk-based Clinical Data Management</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name>
<surname>Nadolny</surname>
<given-names>Patrick</given-names>
</name>
<email>Patrick.Nadolny@iconplc.com</email>
<xref ref-type="aff" rid="aff-1">*</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Celingant</surname>
<given-names>Catherine</given-names>
</name>
<xref ref-type="aff" rid="aff-2">&#8224;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Christianson</surname>
<given-names>Leonie</given-names>
</name>
<xref ref-type="aff" rid="aff-3">&#8225;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Kalra</surname>
<given-names>Pameljit</given-names>
</name>
<xref ref-type="aff" rid="aff-4">&#167;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>King</surname>
<given-names>Stacey</given-names>
</name>
<xref ref-type="aff" rid="aff-5">&#8214;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Pollard</surname>
<given-names>Nicole</given-names>
</name>
<xref ref-type="aff" rid="aff-6">&#182;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Rieske</surname>
<given-names>Jeffrey</given-names>
</name>
<xref ref-type="aff" rid="aff-4">&#167;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Rowe</surname>
<given-names>Jonathan</given-names>
</name>
<xref ref-type="aff" rid="aff-4">&#167;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Okewole</surname>
<given-names>Nicolette</given-names>
</name>
<xref ref-type="aff" rid="aff-7">**</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>You</surname>
<given-names>Demi</given-names>
</name>
<xref ref-type="aff" rid="aff-8">&#8224;&#8224;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Das</surname>
<given-names>Debojyoti</given-names>
</name>
<xref ref-type="aff" rid="aff-8">&#8224;&#8224;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Hayden</surname>
<given-names>Eugene</given-names>
</name>
<xref ref-type="aff" rid="aff-9">&#8225;&#8225;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Klein</surname>
<given-names>Karen</given-names>
</name>
<xref ref-type="aff" rid="aff-10">&#167;&#167;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Cesario</surname>
<given-names>Lynne</given-names>
</name>
<xref ref-type="aff" rid="aff-2">&#8224;</xref>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Vazquez</surname>
<given-names>Manny</given-names>
</name>
<xref ref-type="aff" rid="aff-11">&#8214;&#8214;</xref>
</contrib>
</contrib-group>
<aff id="aff-1"><label>*</label>ICON, US</aff>
<aff id="aff-2"><label>&#8224;</label>Pfizer, US</aff>
<aff id="aff-3"><label>&#8225;</label>Syneos Health Consulting, US</aff>
<aff id="aff-4"><label>&#167;</label>ZS, US</aff>
<aff id="aff-5"><label>&#8214;</label>AperioClinical, US</aff>
<aff id="aff-6"><label>&#182;</label>eClinical Solutions, US</aff>
<aff id="aff-7"><label>**</label>J&amp;J, US</aff>
<aff id="aff-8"><label>&#8224;&#8224;</label>Sanofi, US</aff>
<aff id="aff-9"><label>&#8225;&#8225;</label>Exelixis, US</aff>
<aff id="aff-10"><label>&#167;&#167;</label>Veeva, US</aff>
<aff id="aff-11"><label>&#8214;&#8214;</label>Merck, US</aff>
<pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-10-06">
<day>06</day>
<month>10</month>
<year>2026</year>
</pub-date>
<pub-date pub-type="collection">
<year>2026</year>
</pub-date>
<volume>6</volume>
<issue>1</issue>
<elocation-id>6</elocation-id>
<history>
<date date-type="received" iso-8601-date="2026-08-21">
<day>21</day>
<month>08</month>
<year>2026</year>
</date>
<date date-type="accepted" iso-8601-date="2026-08-21">
<day>21</day>
<month>08</month>
<year>2026</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright: &#x00A9; 2026 The Author(s)</copyright-statement>
<copyright-year>2026</copyright-year>
<license license-type="open-access" xlink:href="http://creativecommons.org/licenses/by/4.0/">
<license-p>SCDM publishes JSCDM content in an open access manner under a Attribution-Non-Commercial-ShareAlike (CC BY-NC-SA) license. This license lets others remix, adapt, and build upon the work non-commercially, as long as they credit SCDM and the author and license their new creations under the identical terms. See <uri xlink:href="https://creativecommons.org/licenses/by-nc-sa/4.0/">https://creativecommons.org/licenses/by-nc-sa/4.0/</uri>.</license-p>
</license>
</permissions>
<self-uri xlink:href="https://www.jscdm.org/articles/10.47912/jscdm.524/"/>
<abstract>
<p>This chapter aims to define principles and best practices for applying risk-based approaches within Clinical Data Management (CDM). These principles are grounded in evolving regulatory expectations.</p>
<p>Starting over a decade ago, regulators have issued guidance documents advocating for the adoption of risk-based and fit for purpose approaches. The good clinical practice (GCP) guideline from the International Council for Harmonisation (ICH), commonly referred to as ICH E6,<sup><xref ref-type="bibr" rid="B1">1</xref></sup> was updated in 2016 and 2025 to reinforce this direction.</p>
<p>Additionally, the ICH guideline on General Considerations for Clinical Studies (ICH E8)<sup><xref ref-type="bibr" rid="B2">2</xref></sup> emphasized quality by design (QbD), which is grounded in two foundational risk-based principles: Prospectively identifying factors critical to quality and applying risk-based approaches to study design, conduct, monitoring, and reporting. This includes the use of risk-based approaches to quality management throughout the clinical study lifecycle to support the reliability of study results and the protection of participants.</p>
<p>Having already implemented risk-based approaches in the site monitoring and system validation spaces for many years, our traditionally risk-averse industry has become more familiar with strategies that align efforts with the risks to study participants&#8217; rights, safety, and well-being, and to data quality. As of 2021, 88% of clinical studies had implemented at least one component of risk-based quality management (RBQM) compared to 53% in 2019.<sup><xref ref-type="bibr" rid="B3">3</xref></sup></p>
<p>Considering the regulatory evolution and the need to accelerate the development of medicines, it is imperative for organizations managing clinical data and related systems to adopt QbD, RBQM, and fit for purpose principles, focusing on what matters most to participants&#8217; protection and to the reliability of study results.</p>
</abstract>
<kwd-group>
<kwd>Risk-Based Clinical Data Management</kwd>
<kwd>Clinical Data Science</kwd>
<kwd>Critical to Quality Factors</kwd>
<kwd>Quality by Design</kwd>
<kwd>Risk-Based Quality Management</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec>
<title>1) Learning Objectives</title>
<p>After reading this chapter, the reader will be able to:</p>
<list list-type="bullet">
<list-item><p>Explain the benefits of applying risk-based approaches to CDM activities</p></list-item>
<list-item><p>Differentiate between data integrity and data quality</p></list-item>
<list-item><p>Describe the key frameworks underpinning risk-based approaches (i.e., QbD, RBQM, and fit for purpose clinical study quality)</p></list-item>
<list-item><p>Interpret relevant regulatory expectations in the context of CDM practices</p></list-item>
<list-item><p>Apply risk-based principles to identify and prioritize actions that drive data quality in an efficient and effective manner</p></list-item>
</list>
</sec>
<sec>
<title>2) Introduction</title>
<p>This chapter covers how Clinical Data Management (CDM) can evolve from traditional, reactive quality control (QC)-based strategies to proactive, end-to-end Quality Management within a risk-based quality management (RBQM) framework. This risk-based CDM (rb-CDM) evolution should begin with the adoption of foundational principles of quality by design (QbD), and progressively expand to apply RBQM cross-functionally, meaning:</p>
<list list-type="bullet">
<list-item><p>Actively participating in study team discussions and decisions on Critical to Quality (CtQ) factors (e.g., critical design elements, data, processes, and systems), QbD decisions, definitions for Quality Tolerance Limits (QTLs) and Key Risk Indicators (KRIs).</p></list-item>
<list-item><p>Performing a risk assessment during the planning phase of the study and throughout its entire life cycle with clear accountability for areas where CDM contributes expertise, particularly across end-to-end data flows, and where it can proactively minimize or mitigate identified risks.</p></list-item>
<list-item><p>De-risking the protocol prior to study start to prevent avoidable risks, and applying mitigation strategies for risks that cannot be avoided, alongside a quality management approach focused on the CtQ factors and their associated risks. Protocol de-risking is discussed in detail in Sections 5.4 and 6.1.</p></list-item>
</list>
<p>This risk-based framework, including the activities outlined above, enables CDM to effectively implement risk-based study execution strategies and continuous process improvement to support the delivery of quality data sufficient for reliable and timely decision-making.</p>
<p>This means moving from reactively catching mistakes to proactively identifying problems that may jeopardize the outcome of a study. Overall, the end-to-end management of the operational and scientific risks should be embedded throughout the entire CDM Framework, with strong collaboration with other functions and disciplines involved in the process when necessary.</p>
<p>Organizational structures and functional responsibilities for risk-based activities may vary across companies. This chapter does not prescribe specific ownership of these activities. In practice, responsibilities such as risk identification, de-risking, and ongoing oversight may be performed by or shared with other functions (e.g., central monitoring, clinical operations), depending on the organization&#8217;s operating model.</p>
<p>Accordingly, this chapter emphasizes the principles and activities associated with risk-based approaches rather than their allocation to specific roles, allowing for flexibility in implementation across different organizational contexts.</p>
<p>In the absence of a robust body of knowledge and a comprehensive literature base regarding rb-CDM in clinical trial study execution, this content was gathered from regulations considered as minimum standards as well as feedback and insights from early adopters, regulators, and industry leaders to recommend best practices through a consensus-based methodology. As rb-CDM matures, new/revised regulations and guidances emerge, and technology evolves, we anticipate that the body of knowledge on this topic will blossom and lead to further evolution of this Good Clinical Data Management Practice (GCDMP) chapter and the overall SCDM Competency framework.<sup><xref ref-type="bibr" rid="B4">4</xref></sup></p>
<p>This GCDMP chapter applies to all types of studies, whether interventional or non-interventional, and to all categories of medicinal products, including drugs, devices, and biological products.</p>
<p>The authors have made efforts to standardize terminology throughout the document while preserving the original language of cited regulations. When directly quoting regulatory documents, the original regulation&#8217;s terminology has been retained to ensure accurate attribution and to preserve the integrity of this chapter.</p>
<p>Below are some terminology-related conventions used in this paper:</p>
<list list-type="bullet">
<list-item><p>In general, the terms &#8220;study&#8221; and &#8220;trial&#8221; are used interchangeably, with no intent to distinguish between them. However, preference has been given to the term &#8220;study,&#8221; as it broadly encompasses all types of research, whereas &#8220;trial&#8221; is more commonly associated with interventional studies.</p></list-item>
<list-item><p>For similar reasons, the term &#8220;participant&#8221; has been favored over &#8220;patient.&#8221;</p></list-item>
<list-item><p>To avoid repetition, the term participant &#8220;protection&#8221; has been used to encompass participant &#8220;rights, safety, and well-being.&#8221;</p></list-item>
<list-item><p>To align with International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use (ICH) E6 (R3),<sup><xref ref-type="bibr" rid="B1">1</xref></sup> the term &#8220;Service Provider&#8221; has been favored over &#8220;Vendor.&#8221;</p></list-item>
<list-item><p>A summary of abbreviations used throughout the document is provided in Section 10 to support consistent interpretation.</p></list-item>
</list>
</sec>
<sec>
<title>3) Scope</title>
<sec>
<title>3.1) In Scope</title>
<p>This GCDMP chapter provides guidance on the principles, standards, and practical applications of rb-CDM across the lifecycle of clinical studies. It is intended for sponsors, Clinical Research Organizations (CROs), service providers, regulators, and other stakeholders involved in the design, conduct, oversight, and reporting of clinical research. The chapter applies to all types of clinical studies, including interventional and non-interventional research as well as all categories of medicinal products such as drugs, devices, and biological products. The scope encompasses both organizational and study-level practices, emphasizing the integration of QbD, RBQM, and fit for purpose strategies to safeguard participant protection and ensure reliable, high-quality data.</p>
<p>This guidance defines the minimum expectations for applying risk-based principles to CDM, while recognizing that implementation should be flexible, context-dependent, and proportionate to study-specific risks. It is not intended to prescribe rigid operational procedures but rather encourages adoption of a pragmatic, critical-thinking mindset that prioritizes what matters most to participant rights, safety, and well-being, and to the credibility of study results. As such, this document provides a framework that organizations can adapt and evolve as regulations mature, technology advances, and industry experience with rb-CDM expands.</p>
</sec>
<sec>
<title>3.2) Out of Scope</title>
<p>Detailed risk identification methodologies (statistical or non-statistical, technology-based or manual), as well as system-specific lifecycle activities (e.g., selection, validation, and use), are out of scope for this chapter.</p>
<p>Additionally, this chapter does not address broader operational and organizational frameworks, including standard operating procedure (SOP) lifecycle management, change management, and service provider management. These topics may be covered in dedicated SCDM publications (e.g., GCDMP chapters, topic briefs) and should be consulted as appropriate. This chapter should therefore be read in conjunction with other GCDMP chapters, particularly those related to data quality, to ensure a comprehensive understanding of integrated quality management.</p>
</sec>
</sec>
<sec>
<title>4) Minimum Standards</title>
<p>In GCDMP chapters, regulations are considered minimum standards to be met and followed. For this chapter on rb-CDM, important applicable passages have been drawn from the following six regulatory guidances, listed chronologically:</p>
<list list-type="bullet">
<list-item><p>August 2013, US Food and Drug Administration (FDA) guidance on &#8220;A Risk-Based Approach to Monitoring&#8221;<sup><xref ref-type="bibr" rid="B5">5</xref></sup></p></list-item>
<list-item><p>March 2018, UK Medicines and Healthcare products Regulatory Agency (MHRA) &#8220;GXP&#8221; Data Integrity Guidance and Definitions<sup><xref ref-type="bibr" rid="B6">6</xref></sup></p></list-item>
<list-item><p>October 2021, ICH E8 (R1), General Considerations for Clinical Trials<sup><xref ref-type="bibr" rid="B2">2</xref></sup></p></list-item>
<list-item><p>January 2022, MHRA Oversight and monitoring activities<sup><xref ref-type="bibr" rid="B7">7</xref></sup></p></list-item>
<list-item><p>April 2023, FDA, A Risk-Based Approach to Monitoring of Clinical Investigations Questions and Answers<sup><xref ref-type="bibr" rid="B8">8</xref></sup></p></list-item>
<list-item><p>January 2025, ICH E6 (R3), Guideline for Good Clinical Practice<sup><xref ref-type="bibr" rid="B1">1</xref></sup></p></list-item>
</list>
<p>To ease the reading of this GCDMP chapter, those passages have been included in Appendix A and organized around six core concepts introduced in this section.</p>
<sec>
<title>4.1) Risk-based approaches</title>
<p>Risk-based approaches are practices that proportionally align focus and efforts on what matters most to prevent and manage risks to 1) participant&#8217;s rights, safety, and well-being; 2) critical data, processes, and systems; and 3) the reliability of study results considering the likelihood of risk occurrence, their severity and potential detectability.</p>
<p>In CDM, a risk-based approach may focus monitoring and validation on data and processes that directly affect reliability of study results (e.g., primary efficacy and safety endpoints and other critical efficacy variables) or participant&#8217;s protection (e.g., eligibility criteria confirmation data, investigational product (IP) dosing data as recorded in the electronic data capture (EDC) system), while applying a risk-adapted oversight to data not associated with CtQ Factors.</p>
</sec>
<sec>
<title>4.2) Fit for purpose considerations</title>
<p>Fit for purpose clinical study quality means that the study should be of sufficient quality to meet its objectives, provide confidence in the study&#8217;s results, and support sound decision-making, all while adequately protecting the participants involved. As such, regulations, and especially ICH E6 (R3),<sup><xref ref-type="bibr" rid="B1">1</xref></sup> emphasize risk-proportionate strategies that support quality throughout the study.</p>
</sec>
<sec>
<title>4.3) Data Integrity and Quality</title>
<p>The authors acknowledge that there is no industry-wide or regulatory-aligned definition that clearly distinguishes data quality from data integrity, and that these concepts are inherently overlapping. Consistent with prior SCDM publications, this section does not aim to establish prescriptive or universally accepted definitions. Instead, it provides an operational perspective to support the evolving role of CDM toward clinical data science (CDS), where emphasis is placed on risk-based approaches and in ensuring the reliability of trial results, rather than solely focusing on managing data appropriately.</p>
<p>As stated in SCDM&#8217;s 2022 &#8220;The evolution of Clinical Data Management into Clinical Data Science&#8221;, &#8220;<italic>Clinical data management is primarily focused on data flows and data integrity (i.e., data is managed the right way). Clinical Data Science broadens this focus by adding the data risk, data meaning and value dimensions for achieving data quality (i.e., data is credible and reliable)</italic>.&#8221;<sup><xref ref-type="bibr" rid="B9">9</xref></sup></p>
<p>Understanding the difference between data integrity and data quality is critical for CDM professionals, as it is at the core of the evolution of CDM into CDS.</p>
<p>The introduction to MHRA&#8217;s guidance on GxP Data Integrity<sup><xref ref-type="bibr" rid="B6">6</xref></sup> states that data integrity is not data quality since &#8220;<italic>the controls required for integrity do not necessarily guarantee the quality of the data generated</italic>.&#8221;<sup><xref ref-type="bibr" rid="B6">6</xref></sup></p>
<p>First, &#8220;<italic>Data integrity is the degree to which data are complete, consistent, accurate, trustworthy, reliable and that these characteristics of the data are maintained throughout the data life cycle. The data should be collected and maintained in a secure manner, so that they are attributable, legible, contemporaneously recorded, original (or a true copy) and accurate</italic>.&#8221;<sup><xref ref-type="bibr" rid="B6">6</xref></sup> This MHRA definition is consistent with the ALCOA (<bold>A</bold>ttributable, <bold>L</bold>egible, <bold>C</bold>ontemporaneous, <bold>O</bold>riginal and <bold>A</bold>ccurate) principles.</p>
<p>Note the term &#8220;certified copy&#8221; in ICH E6 (R3)<sup><xref ref-type="bibr" rid="B1">1</xref></sup> aligns with the MHRA&#8217;s use of &#8220;true copy,&#8221; since both are defined as an accurate, verified reproduction of the original record.</p>
<p>Data quality is &#8220;<italic>the assurance that data produced is exactly what was intended to be produced and fit for its intended purpose. This incorporates ALCOA</italic>.&#8221;<sup><xref ref-type="bibr" rid="B6">6</xref></sup></p>
<p>Data quality is a broader and more comprehensive goal&#8212;it is &#8220;fit for purpose.&#8221; In the context of clinical studies, data should be fit for purpose and adhere to the definition in Section 4.2.</p>
<p>At its core, &#8220;fit for purpose&#8221; data quality recognizes that no study is conducted perfectly. Striving for perfection may not be realistic or necessary; what truly matters is avoiding errors that could meaningfully affect participant protection or compromise the reliability of study results. Achieving fit for purpose quality therefore requires a pragmatic, risk-proportionate approach, ensuring that efforts are focused on study attributes that are critical to the protection of participants and the reliability of study results.</p>
<p>It is helpful to consider that the quality of clinical data during study execution is dependent on two distinct steps:</p>
<list list-type="bullet">
<list-item><p>The first step is the actual generation of the clinical data, which depends on all of the people, processes, materials and/or equipment involved in conducting the relevant patient assessments or measurements.</p></list-item>
<list-item><p>The second stage involves the reliable management of the data after its generation, including its proper recording (using ALCOA principles), transcription, transmission, storage, review and reporting.</p></list-item>
</list>
<p>Data integrity&#8212;which has traditionally been the primary focus of data management activities&#8212;covers this second stage but generally not the first. Monitoring the reliability of the first stage was traditionally considered outside of the scope of CDM.</p>
<p>In conclusion, we could conceptually differentiate data quality vs. data integrity as follows:</p>
<p>Data integrity means that the data are managed the right way.</p>
<p>Data quality means that the data are reliable and fit for purpose for decision making.</p>
</sec>
<sec>
<title>4.4) Quality by Design (QbD)</title>
<p>ICH E8 (R1)<sup><xref ref-type="bibr" rid="B2">2</xref></sup> states that &#8220;<italic>QbD in clinical research sets out to ensure that the quality of a study is driven proactively by designing quality into the</italic> <bold><italic>study protocol and processes</italic></bold>.&#8221;<sup><xref ref-type="bibr" rid="B2">2</xref></sup> This involves the use of a prospective, cross-functional (e.g., clinical operations, quality, data management, biostatistics) and multidisciplinary (i.e., across different areas of expertise such as sponsors, CROs, technology providers, clinical investigators, patients, patient advocates, and healthcare providers) approach to promote the quality of protocol and process design (at study, program and overall organizational level) in a manner proportionate to the risks involved, with clear documentation and communication on how this will be achieved.</p>
</sec>
<sec>
<title>4.5) Critical to Quality Factors (incl. Critical Data and Processes)</title>
<p>The ICH E8 guidance states that &#8220;<italic>The quality by design approach to clinical research involves focusing on CtQ factors</italic>&#8221;<sup><xref ref-type="bibr" rid="B2">2</xref></sup> and defines them as &#8220;<italic>attributes of a study whose integrity is fundamental to the protection of study participants, the reliability and interpretability of the study results, and the decisions made based on the study results</italic>.&#8221;<sup><xref ref-type="bibr" rid="B2">2</xref></sup> In addition, <italic>CtQ factors</italic> should be considered holistically, so that dependencies among them can be identified and managed appropriately. Understanding these interdependencies is essential for designing a robust, efficient quality management approach aligned with QbD principles. Furthermore, the quality management approach should be proactively integrated into the operational plans ensuring that quality is not only conceptualized but also embedded in the design, conduct, oversight and monitoring of the clinical study.</p>
<p>Refer to <xref ref-type="table" rid="T1">Table 1</xref> for an example of CtQ factors representing critical data and processes to consider (see section 4.6).</p>
<table-wrap id="T1">
<caption>
<p><bold>Table 1</bold>: CTTI Critical to Quality Categories and Factors.<sup><xref ref-type="bibr" rid="B1">1</xref></sup></p>
</caption>
<table>
<tbody>
<tr>
<td align="left" valign="top"><bold>CtQ Categories</bold></td>
<td align="left" valign="top"><bold>CtQ factors</bold></td>
</tr>
<tr>
<td align="left" valign="top"><bold>Protocol Design</bold></td>
<td align="left" valign="top">Eligibility Criteria<break/>Randomization<break/>Masking<break/>Types of Controls<break/>Data Quantity<break/>Endpoints<break/>Procedures Supporting Study Endpoints and Data Integrity<break/>Investigational Product (IP) Handling and Administration</td>
</tr>
<tr>
<td align="left" valign="top"><bold>Feasibility</bold></td>
<td align="left" valign="top">Study and Site Feasibility<break/>Accrual (i.e., Enrollment Strategy)</td>
</tr>
<tr>
<td align="left" valign="top"><bold>Patient Safety</bold></td>
<td align="left" valign="top">Informed Consent<break/>Withdrawal Criteria and Trial Participant Retention<break/>Signal Detection<break/>Safety Reporting<break/>Data Monitoring Committee (DMC)/Stopping Rules (if applicable)</td>
</tr>
<tr>
<td align="left" valign="top"><bold>Study Conduct</bold></td>
<td align="left" valign="top">Training<break/>Data Recording and Reporting<break/>Data Monitoring and Management<break/>Statistical Analysis</td>
</tr>
<tr>
<td align="left" valign="top"><bold>Study Reporting</bold></td>
<td align="left" valign="top">Dissemination of Study Results</td>
</tr>
<tr>
<td align="left" valign="top"><bold>Third-party Engagement</bold></td>
<td align="left" valign="top">Delegation of Sponsor Responsibilities and Collaborations</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p><bold>Note</bold>: The CTTI introduced the CtQ factors in 2015 and organized them around the six major categories below. Those can be used as a guide to define the study specific CtQ Factors.<sup><xref ref-type="bibr" rid="B10">10</xref></sup></p></fn>
</table-wrap-foot>
</table-wrap>
</sec>
<sec>
<title>4.6) Risk Management</title>
<p>Risk management is a systematic approach to managing risks. It includes the identification, assessment, monitoring, mitigations, controls, communications, and evaluation of risks throughout the lifecycle of a clinical study (Refer to Section 5.3 for detailed considerations regarding Risk management).</p>
</sec>
</sec>
<sec>
<title>5) Best Practices</title>
<p>With these guidances in mind, we recommend the following best practices for applying a risk-based approach within CDM.</p>
<list list-type="order">
<list-item><p>Manage risk through a multidisciplinary approach supported by management. [VI]</p></list-item>
<list-item><p>Embed quality at the design stage through critical thinking. [VI]</p></list-item>
<list-item><p>Engage all external parties in risk identification and mitigation. [VI]</p></list-item>
<list-item><p>Keep risk control proportionate, with risk-surveillance strategies defined prospectively, including relevant KRI triggers and pre-specified acceptable ranges such as QTLs. [VI]</p></list-item>
<list-item><p>Focus data integrity assessments on CtQ factors, critical risks, and critical processes. [VI]</p></list-item>
<list-item><p>Review and adapt risk assessments dynamically throughout study conduct. [VI]</p></list-item>
<list-item><p>Communicate and report risks, quality issues, and remedial actions to stakeholders. [VI]</p></list-item>
<list-item><p>Conduct a final risk assessment at close-out and feed lessons learned into corrective actions and preventive actions (CAPAs) and future studies. [VI]</p></list-item>
</list>
<sec>
<title>5.1) Summary of Best Practices</title>
<p>The best practices detailed throughout this section can be summarized as follows. They follow the rb-CDM life cycle, from organizational foundations through study design, conduct, and close-out. Each practice is elaborated in the subsections indicated in <xref ref-type="table" rid="T2">Table 2</xref>.</p>
<table-wrap id="T2">
<caption>
<p><bold>Table 2</bold>: Good Clinical Data Management Practices (GCDMP) Evidence Grading Criteria.</p>
</caption>
<table>
<tbody>
<tr>
<td align="left" valign="top"><bold>Evidence Level</bold></td>
<td align="left" valign="top"><bold>Evidence Grading Criteria </bold></td>
</tr>
<tr>
<td align="left" valign="top">I</td>
<td align="left" valign="top">Large, controlled experiments; meta, or pooled analysis of controlled experiments; regulations or regulatory guidance</td>
</tr>
<tr>
<td align="left" valign="top">II</td>
<td align="left" valign="top">Small controlled experiments with unclear results</td>
</tr>
<tr>
<td align="left" valign="top">III</td>
<td align="left" valign="top">Reviews or syntheses of the empirical literature</td>
</tr>
<tr>
<td align="left" valign="top">IV</td>
<td align="left" valign="top">Observational studies with a comparison group</td>
</tr>
<tr>
<td align="left" valign="top">V</td>
<td align="left" valign="top">Observational studies, including demonstration projects and case studies with no control</td>
</tr>
<tr>
<td align="left" valign="top">VI</td>
<td align="left" valign="top">Consensus of the writing group, including GCDMP Editorial Board and public comment process</td>
</tr>
<tr>
<td align="left" valign="top">VII</td>
<td align="left" valign="top">Opinion papers</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p><italic>Each best practice above is followed by an evidence level grade. Evidence supporting assertions or otherwise informing practice recommendations in GCDMP chapters is graded according to the strength of the evidence. The GCDMP has adopted the grading criteria in the Evidence Classification Table. The strength, also referred to as level of evidence, is based on the amount of evidence &#8211; such as the number of studies supporting a result, as well as the extent to which the study designs support causal inference</italic></p></fn>
</table-wrap-foot>
</table-wrap>
</sec>
<sec>
<title>5.2) Overall rb-CDM Framework considerations</title>
<p>It is essential to recognize that quality in clinical studies is multi-dimensional, bringing together QbD and RBQM, which complement each other to ensure fit for purpose study quality. Within this broader, cross-functional and multidisciplinary quality framework, rb-CDM serves as a key component that contributes to both QbD and RBQM.</p>
<p>A critical concept underpinning this quality framework is fit for purpose clinical study quality, as defined in Sections 4.2 and 4.3: rather than striving for perfection in every aspect of a study, efforts should be focused on the study attributes that are critical to the protection of participants and the reliability of study results.</p>
<p>In essence, QbD establishes the foundation for clinical study quality by proactively identifying and embedding quality into the study from the outset, during the study design and planning stage, using sound scientific understanding and proactive risk management. This approach enables sponsors to &#8220;de-risk&#8221; the protocol upfront by identifying CtQ factors and potential risks to those factors, ensuring that the study design is optimized to prevent foreseeable issues.</p>
<p>RBQM builds on this foundation by applying risk assessments and mitigation strategies throughout study conduct, ensuring that risks are continuously evaluated and that risk controls remain appropriate and are adapted dynamically as the study progresses.</p>
<p>Quality should be embedded from the study design stage through <italic>critical thinking</italic>. This requires anticipating issues <italic>before they occur</italic> by evaluating trial activities from multiple perspectives&#8212;scientific, operational, and regulatory.</p>
<p>Critical thinking enables proactive, risk-based quality management by:</p>
<list list-type="bullet">
<list-item><p>Identifying vulnerabilities &#8212; determining which data or processes are most susceptible to errors or deviations and understanding the potential consequences.</p></list-item>
<list-item><p>Anticipating proactively &#8212; evaluating study activities holistically to foresee and address risks early in the trial lifecycle.</p></list-item>
<list-item><p>Prioritizing risks &#8212; assessing which risks could most significantly impact trial outcomes or participant safety.</p></list-item>
<list-item><p>Targeting mitigation &#8212; deciding where enhanced procedures, monitoring, or validation are needed to prevent or control high-priority risks.</p></list-item>
<list-item><p>Adapting in real time &#8212; continuously monitoring trial data, systems, and processes, and being flexible when new risks emerge.</p></list-item>
</list>
<p>To support this mindset, flexible and targeted quality oversight approaches should be implemented through predefined, risk-based strategies and continuously refined throughout the study.</p>
<p>This quality framework operates at both an organizational and a study level. At an organization level, &#8220;<italic>the sponsor should implement an appropriate system to manage quality throughout all stages of the trial process</italic>.&#8221;<sup><xref ref-type="bibr" rid="B1">1</xref></sup> At a clinical study level, it includes <italic>&#8220;the design and implementation of efficient clinical trial protocols, including tools and procedures for trial conduct (including for data collection and management), in order to ensure the protection of participants&#8217; rights, safety and well-being and the reliability of trial results</italic>.&#8221;<sup><xref ref-type="bibr" rid="B1">1</xref></sup> As illustrated in rb-CDM Framework in <xref ref-type="fig" rid="F1">figure 1</xref> below, these four dimensions&#8212;Quality by Design and RBQM, applied across both the organization and study levels&#8212;must be considered together to establish a robust rb-CDM framework that aligns with risk-based quality management practices.</p>
<fig id="F1">
<caption>
<p><bold>Figure 1</bold>: rb-CDM Framework.</p>
</caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g1.png"/>
</fig>
<p>This risk-based quality framework moves beyond tools and checklists to foster prospective planning, critical thinking, and flexible, proactive, study-specific strategies in study design and conduct. It explicitly discourages one-size-fits-all approaches, advocating instead for tailored, risk-proportionate strategies that support quality throughout the study.<sup><xref ref-type="bibr" rid="B2">2</xref></sup></p>
<p>The QbD process should be led by a cross-functional, multidisciplinary team&#8212;for example, representatives from clinical operations, data management, biostatistics, medical, regulatory affairs, pharmacovigilance, digital data technology (or equivalent), drug supplies, and quality assurance&#8212;with each discipline bringing a unique perspective to identify CtQ factors and potential risks. These teams collaboratively define quality objectives, risk mitigation strategies, QTLs, and KRIs. Engaging external stakeholders (e.g., patients, patient advocacy groups, healthcare providers, and clinical investigators) is equally vital to ensuring that clinical studies are scientifically valid, operationally feasible, ethically sound, and patient-centered. Organizational adoption of this collaborative model is detailed in Section 5.3.</p>
<p>In summary, the overall quality framework applies to all drug development stakeholders involved and aims to ensure participant protection and the reliability of study results throughout the clinical study lifecycle (i.e., starting from protocol design and extending through study conduct, evaluation, and reporting phases). Important risks that cannot be eliminated through study design may be mitigated and managed through the study&#8217;s operational plans, processes, and procedures. These plans, processes, and procedures should be implemented in a way that is proportionate to the risks to study participants and the importance of the data collected.</p>
</sec>
<sec>
<title>5.3) Organizational considerations</title>
<p>As discussed, Risk Management (including QbD and RBQM) and its rb-CDM component should ideally be recognized as a multidisciplinary and cross-functional responsibility supported by a leadership-driven culture in which critical thinking and open, proactive dialogue about what is critical to quality are valued and rewarded<sup><xref ref-type="bibr" rid="B2">2</xref></sup> (see also Section 6.3). It is therefore recommended to follow a systematic, cross-functional approach to define and embed the right culture, policies, processes and training in order to adopt new ways of working, build new skills, prevent siloed RBQM delivery, and build trust in new tools and techniques.</p>
<p>Below are some of the elements that could be considered when creating an RBQM framework, with a particular emphasis on rb-CDM:</p>
<list list-type="bullet">
<list-item><p><bold>Aligning on core principles</bold> &#8211; Leadership and stakeholders should align on definitions of core principles such as &#8220;risk proportionate ways of working,&#8221; &#8220;errors that matter,&#8221; and the definition of &#8220;clean data.&#8221; Aligning on these principles ensures organizations are thinking about this in the same way, growing their capabilities in a complementary way, and then supporting implementation.</p></list-item>
<list-item><p><bold>Building a preventative rather than corrective mindset</bold> &#8211; instilling a &#8220;get it right first time&#8221; data quality mindset and a focus on improving critical processes at the site, at all service providers (incl. central laboratories, central imaging, eCOA Providers, CROs, etc.) and within the study team. This could include a systematic and regular review of EDC forms and electronic Patient Reported Outcome (ePRO) instruments with sites and study participants to improve data collection and data flow, or it could include a retrospective analysis of recent studies to understand the root causes of historical protocol deviations that could be avoided through protocol design or more tailored protocol training at the site. Moving QbD and development of the risk assessment upstream into protocol development can also foster a more proactive and preventative mindset.</p></list-item>
<list-item><p><bold>Developing skillsets, training, and change management</bold> &#8211; new skills may be required across all the functional groups to reinforce the RBQM framework. This should be a combination of analytical skills, such as critical thinking and root cause analysis techniques; and technical knowledge, such as regulatory guidances (i.e., minimum requirements); and the development of comprehensive corrective and preventative action plans. Formal training should be supplemented by a comprehensive mentoring program so that key concepts and rb-CDM principles can be applied in a consistent yet flexible way, and reinforced through a variety of communication and shared-learning techniques including lessons learned and the sharing of successes. Change management should emphasize the risks of one-size-fits-all approaches and over-reliance on tools and checklists.<sup><xref ref-type="bibr" rid="B2">2</xref></sup> Continuous training, competency assessments, and change management programs help sustain rb-CDM maturity over time by reinforcing critical-thinking and risk-management skills across all rb-CDM stakeholders.</p></list-item>
<list-item><p><bold>Embedding processes, SOPs, and roles</bold> &#8211; processes should be re-assessed to ensure teams are applying QbD from the earliest stage of protocol development onwards and that appropriate focus is placed on RBQM and rb-CDM activities during the study. Process flows, SOPs, job descriptions and training curriculums should all align to the new ways of working and explicitly state expectations for RBQM and rb-CDM, as guided by the core principles above, to ensure RBQM does not become a tick box exercise adding unnecessary burden to study teams. Considerations include but are not limited to:</p>
<list list-type="simple">
<list-item><p>- Institutionalizing a continuous improvement cycle that incorporates lessons learned and CAPA insights into standard libraries, SOPs, and training materials, thereby progressively enhancing rb-CDM maturity.</p></list-item>
<list-item><p>- Ensuring consistent execution and oversight: organizations should establish formal governance structures with clear accountability for RBQM and rb-CDM activities, including defined roles for decision-making, escalation, and continuous improvement.</p></list-item>
<list-item><p>- Supporting reliable data collection, traceability, and regulatory compliance: The rb-CDM framework may leverage appropriate standardized data formats and interoperable systems (e.g., CDISC, HL7, FHIR), enabling consistent data exchange and integration across platforms and stakeholders.</p></list-item>
<list-item><p>- Establishing standard and compound-specific libraries (e.g., of CtQ factors, KRIs, QTLs, and risk assessments) that can be reused across similar studies with buy-in from stakeholders.</p></list-item>
<list-item><p>- Organizations should also consider a technology enablement strategy to support RBQM and rb-CDM, including the identification of solutions (internally or through third party services) for activities such as centralized monitoring, data reviews, and real-time risk detection.</p></list-item></list></list-item></list>
<p><bold>Note</bold>: Consider leveraging established industry references such as:</p>
<list list-type="bullet">
<list-item><p>The CtQ categories and factors from the Clinical Trial Transformation Initiative (CTTI).<sup><xref ref-type="bibr" rid="B10">10</xref></sup></p></list-item>
<list-item><p>The TransCelerate Risk Assessment Categorization Tool (RACT),<sup><xref ref-type="bibr" rid="B11">11</xref></sup> risk indicator library<sup><xref ref-type="bibr" rid="B12">12</xref></sup> and the Framework for successful QTL implementation<sup><xref ref-type="bibr" rid="B13">13</xref></sup> and other TransCelerate RBQM related recommendations.</p></list-item>
</list>
</sec>
<sec>
<title>5.4) Study Level considerations</title>
<p><xref ref-type="fig" rid="F2">Figure 2</xref> highlights the core elements, organized across eight steps, to implement a study level rb-CDM life cycle framework.</p>
<p>It illustrates the iterative process flow of the rb-CDM life cycle, beginning with Quality by Design (QbD) and progressing through risk management steps mentioned in ICH E6 (R3).<sup><xref ref-type="bibr" rid="B1">1</xref></sup> Each element in the figure corresponds to process steps described in Section 6.1 below, providing a visual anchor for understanding the integration of risk-based approaches at the study level.</p>
<fig id="F2">
<caption>
<p><bold>Figure 2</bold>: rb-CDM Study Life Cycle.</p>
</caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g2.png"/>
</fig>
<p>First and foremost, even though this GCDMP chapter focuses on rb-CDM, it is essential that all risk management related activities incorporate input from the cross-functional and multidisciplinary team described in Section 5.2, representing all critical disciplines and functions involved in the study.</p>
<p>This collaborative approach should be applied regardless of the operational model&#8212;whether in-house or outsourced&#8212;ensuring comprehensive expertise and alignment throughout the rb-CDM process.</p>
<p>It is essential to consider all external parties (e.g., CROs, technology and service providers) as risk identification should &#8220;<italic>be considered across &#8230; service provider activities)</italic>&#8221;<sup><xref ref-type="bibr" rid="B1">1</xref></sup> and risk mitigation &#8220;<italic>activities may be incorporated, for example, in &#8230; agreements between parties defining roles and responsibilities</italic>.&#8221;<sup><xref ref-type="bibr" rid="B1">1</xref></sup></p>
<p>When engaging with external parties in risk management activities, the following elements should be considered:</p>
<list list-type="bullet">
<list-item><p>Establishing clear roles and responsibilities (e.g., documented using a Responsible, Accountable, Consulted and Informed (RACI) matrix)</p></list-item>
<list-item><p>Aligning SOPs and work instructions</p></list-item>
<list-item><p>Leveraging technology to reduce burden; ensure prompt oversight and limit risk of transcription error. Service providers may as an example supply tools for centralized monitoring, data visualizations, system to system integration.</p></list-item>
<list-item><p>Ensuring the integrity of the data chain of custody</p></list-item>
<list-item><p>Defining a governance and communication framework to track service provider performance based on KPIs and key metrics</p></list-item>
<list-item><p>Training and continuous improvement on rb-CDM principles and tools</p></list-item>
<list-item><p>At study level, performing a cross-functional risk assessment and sharing lessons learned</p></list-item>
</list>
<p>The rb-CDM Life Cycle focuses on core data-related components within the QbD and RBQM framework. Aligned with the ICH E6 (R3),<sup><xref ref-type="bibr" rid="B1">1</xref></sup> it begins with QbD by identifying CtQ factors and associated risks, followed by the six risk management steps described in its section 3.10.1, &#8220;Risk Management.&#8221;</p>
<p>It is important to note that while the rb-CDM life cycle follows a structured framework, its implementation must be customized to the specific needs of each study. Factors such as therapeutic area, study design complexity, data sources, and participant population should inform the prioritization and execution of risk management activities.</p>
<p>This approach ensures that data quality is proactively designed and continuously monitored throughout the clinical study lifecycle, supporting regulatory compliance and improving patient protection and data reliability.</p>
<p><xref ref-type="table" rid="T3">Table 3</xref> relates the eight lifecycle steps shown in <xref ref-type="fig" rid="F2">Figure 2</xref> to the six risk-management steps of ICH E6(R3) section 3.10.1 and to the Section 6 stage at which each is implemented. It provides a single reference point that links the QbD/RBQM lifecycle, the regulatory risk-management process, and this document&#8217;s stage-based guidance.</p>
<table-wrap id="T3">
<caption>
<p><bold>Table 3</bold>: Best practices and corresponding chapter sections.</p>
</caption>
<table>
<tbody>
<tr>
<td align="left" valign="top"><bold>#</bold></td>
<td align="left" valign="top"><bold>Best Practice</bold></td>
<td align="left" valign="top"><bold>Life Cycle Phase</bold></td>
<td align="left" valign="top"><bold>Elaborated In</bold></td>
<td align="left" valign="top"><bold>Regulatory Basis (App. A)</bold></td>
</tr>
<tr>
<td align="left" valign="top"><bold>1</bold></td>
<td align="left" valign="top">Multidisciplinary risk management supported by management</td>
<td align="left" valign="top">Foundational</td>
<td align="left" valign="top">5.2, 5.3</td>
<td align="left" valign="top">A.6</td>
</tr>
<tr>
<td align="left" valign="top"><bold>2</bold></td>
<td align="left" valign="top">Quality embedded at the design stage through critical thinking</td>
<td align="left" valign="top">Set-up</td>
<td align="left" valign="top">5.2 (QbD), 6.1</td>
<td align="left" valign="top">A.1, A.4</td>
</tr>
<tr>
<td align="left" valign="top"><bold>3</bold></td>
<td align="left" valign="top">External parties engaged in risk identification and mitigation</td>
<td align="left" valign="top">Foundational/Set-up</td>
<td align="left" valign="top">5.2, 5.4, 6.1</td>
<td align="left" valign="top">A.6</td>
</tr>
<tr>
<td align="left" valign="top"><bold>4</bold></td>
<td align="left" valign="top">Proportionate risk control with prospectively defined surveillance strategies and applicable thresholds</td>
<td align="left" valign="top">Set-up</td>
<td align="left" valign="top">5.4 (risk control), 6.1</td>
<td align="left" valign="top">A.5, A.6</td>
</tr>
<tr>
<td align="left" valign="top"><bold>5</bold></td>
<td align="left" valign="top">Data integrity assessments of CtQ factors, critical risks, and critical processes</td>
<td align="left" valign="top">Execution</td>
<td align="left" valign="top">4.3, 5.4, 6.1</td>
<td align="left" valign="top">A.3, A.5</td>
</tr>
<tr>
<td align="left" valign="top"><bold>6</bold></td>
<td align="left" valign="top">Dynamic review and adaptation of risk assessments during study conduct</td>
<td align="left" valign="top">Execution</td>
<td align="left" valign="top">5.4 (risk review), 6.1</td>
<td align="left" valign="top">A.6</td>
</tr>
<tr>
<td align="left" valign="top"><bold>7</bold></td>
<td align="left" valign="top">Risk communication and reporting to stakeholders and in the clinical study report</td>
<td align="left" valign="top">Execution/Close-out</td>
<td align="left" valign="top">5.4 (risk communication and reporting)</td>
<td align="left" valign="top">A.6</td>
</tr>
<tr>
<td align="left" valign="top"><bold>8</bold></td>
<td align="left" valign="top">Final risk assessment at close-out, with lessons learned feeding CAPAs and future studies</td>
<td align="left" valign="top">Close-out</td>
<td align="left" valign="top">6.1, 6.3</td>
<td align="left" valign="top">A.6</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>This crosswalk represents an illustrative mapping of the rb-CDM lifecycle to the ICH E6(R3) risk-management framework and should not be interpreted as a regulatory classification of the individual lifecycle steps.</p>
<p>The considerations below combine regulatory requirements with recommended rb-CDM best practices. Unless explicitly attributed to a regulatory source, additional operational practices should be interpreted as recommendations rather than direct regulatory requirements.</p>
<p>Each of these steps is described in detail below:</p>
<p><bold><underline>1. Risk Identification:</underline></bold> Identify risks that may have a meaningful impact on CtQ factors prior to study initiation and throughout study conduct. <italic>&#8220;Risks should be considered across the critical processes and systems</italic>,&#8221; that matter most to the overall reliability of trial results and participant safety, <italic>&#8220;including computerized systems used in the clinical trial (e.g., trial design, participant selection, informed consent process, randomization, blinding, investigational product administration, data handling and service provider activities)</italic>.&#8221;<sup><xref ref-type="bibr" rid="B1">1</xref></sup></p>
<list list-type="bullet">
<list-item><p>Identifying CtQ factors (i.e., critical data, processes, and systems) considering the study design and objectives</p></list-item>
<list-item><p>Identifying potential risks to the integrity and quality of the critical data</p></list-item>
<list-item><p>Identifying risks to the data that could jeopardize the evaluation and management of participant&#8217;s rights, safety and well-being</p></list-item>
<list-item><p>Identifying risks to the data that could jeopardize the reliability of the study results</p></list-item>
<list-item><p>TransCelerate suggests considering the following elements when assessing risks<sup><xref ref-type="bibr" rid="B13">13</xref></sup></p>
<list list-type="simple">
<list-item><p>- Trial-level risk management plan (including controls)</p></list-item>
<list-item><p>- Number of participants</p></list-item>
<list-item><p>- Number of sites</p></list-item>
<list-item><p>- Trial Duration&#8212;adequate duration of the trial is a consideration to implementing the QTL process and implementing any remedial actions as a part of the QTL process</p></list-item>
<list-item><p>- Recruitment rate</p></list-item>
<list-item><p>- Trial Design (e.g., dose escalating cohorts because of the small number of participants in each cohort)</p></list-item>
<list-item><p>- Trial population</p></list-item></list></list-item>
</list>
<p>Although this list may not represent a complete set of considerations, it provides a strong starting point. Organizations should also evaluate additional factors that are specific to the study protocol or informed by prior experience. These may include:</p>
<list list-type="bullet">
<list-item><p>Study phase</p></list-item>
<list-item><p>Safety information from the Investigator Brochure</p></list-item>
<list-item><p>Study type (e.g., interventional or real-world)</p></list-item>
<list-item><p>Risk of unintentional unblinding</p></list-item>
<list-item><p>Data source heterogeneity, such as EHRs, registries, or decentralized trial components</p></list-item>
<list-item><p>Extent and experience of service providers</p></list-item>
<list-item><p>Study specific privacy and cybersecurity risks</p></list-item>
</list>
<p><bold><underline>2. Risk Evaluation:</underline></bold> Assess the identified risks&#8212;and existing controls in place&#8212;to mitigate the risk considering its likelihood of occurrence, its detectability and its impact.</p>
<list list-type="bullet">
<list-item><p>Evaluate risks to critical data, processes, and systems that are the most vulnerable to errors or deviations to understand the potential consequences of those risks.</p></list-item>
<list-item><p>Evaluate which risks could most significantly impact the study outcomes and participant&#8217;s protection.</p></list-item>
<list-item><p>Document the risk evaluation in the risk assessment plan and proactive mitigations in relevant functional plans including role-based review and monitoring strategies.</p></list-item>
<list-item><p>The risk evaluation should consider:</p></list-item>
<list-item><p>The likelihood of harm/hazard occurring</p></list-item>
<list-item><p>The extent to which such harm/hazard would be detectable</p></list-item>
<list-item><p>The impact of such harm/hazard on study participant protections and the reliability of study results.</p></list-item>
</list>
<p><bold><underline>3. Risk Control:</underline></bold> Establish robust risk-proportionate approaches to monitoring, validation, and management of risks to the CtQ factors (i.e., critical data, processes, and systems) while remaining flexible and adaptive to emerging risks. Those risk-proportionate controls should be fit for purpose&#8212;reflecting the importance of the data&#8212;in ensuring participant&#8217;s protection and the reliability of study results.</p>
<p>The distinction between critical and non-critical data is not strictly binary. Organizations may implement a tiered classification framework, assigning varying levels of criticality based on the importance of the data within the trial; that is the extent to which errors could impact on participant&#8217;s protection, the reliability of study results, and decision-making. The rb-CDM process shall be adjusted accordingly considering risk proportionality to each defined tier.</p>
<list list-type="bullet">
<list-item><p>The most efficient risk control is to prevent it, if possible, by proactively de-risking the study, with QbD in mind, during protocol development.</p></list-item>
</list>
<p>This entails incorporating feedback from study personnel, healthcare providers, participants, and participant advocates in the study design to reduce unnecessary protocol complexity, for example by eliminating the collection of non-essential data, by simplifying and/or reducing visit schedules and study procedures, and by leveraging technology for data collection.</p>
<list list-type="bullet">
<list-item><p>Build pro-active measures to mitigate remaining risks that could not have been fully de-risked (i.e., risks that could not be fully prevented). This includes the ability to monitor risks and prevent and/or limit their occurrences such as ensuring appropriate validation, access controls, audit trails and trainings for critical systems.</p></list-item>
<list-item><p>It also means building risk-based mitigation strategies into study related plans. While study plans span multiple functions, Clinical Data Managers/Scientists may specifically contribute to the data management plan (DMP), the centralized monitoring plan (CMP) and/or the integrated quality risk management plan (IQRMP) as appropriate in their organization. This may include:</p></list-item>
<list-item><p>Incorporating automated validations into the data collection systems such as edit checks in EDC and patient alerts for missing data in electronic Clinical Outcome Assessment (eCOA)</p></list-item>
<list-item><p>Defining KRIs at site and country level as well as &#8220;<italic>pre-specified acceptable ranges (e.g., QTL at the trial level)</italic>.&#8221;<sup><xref ref-type="bibr" rid="B1">1</xref></sup></p></list-item>
<list-item><p>Set up systems to perform signal detection and analysis</p></list-item>
</list>
<p>Implement cross-functional mitigation strategies to manage risks. This includes leveraging clinical data and metadata to identify emerging risks during study conduct through the use of KRIs, QTLs, and other data-driven approaches, such as data analytics and automated data validations, to flag inconsistencies and missing data patterns.</p>
<p><bold><underline>4. Risk Communication:</underline></bold> Communicate risk-related information among all parties involved in the study so that the risks that matter and the controls in place are commonly understood and acted upon.</p>
<list list-type="bullet">
<list-item><p>The anticipated CtQ risks identified, the outcome of their assessment as well as mitigating strategies resulting from the prior three steps (identification, evaluation, and control), should be communicated to and agreed with all impacted stakeholders, ideally prior to initiating participant enrollment.</p></list-item>
<list-item><p>When monitoring risks, any identified occurrences should be documented and communicated to the appropriate stakeholders (e.g., site staff, site monitor, medical monitor). Relevant context should be provided to guide corrective and preventive actions, such as whether the risks are emerging or anticipated, isolated or widespread, any known or potential root causes, and areas that may require further investigation.</p></list-item>
<list-item><p>Treat communication as a two-way exchange rather than one-directional reporting. Actively seek input from sites, service providers, and other stakeholders so that concerns and emerging risk signals surface early.</p></list-item>
<list-item><p>Agree the communication channels and forums up front (e.g., cross-functional risk reviews and escalation paths) so that risk information flows consistently among internal and external stakeholders throughout the study.</p></list-item>
<list-item><p>Maintain a traceable record of risk-communication activities and decisions to support transparency and accountability; these records also feed the risk reporting described in Step 6.</p></list-item>
</list>
<p><bold><underline>5. Risk Review:</underline></bold> Risk review is the ongoing, cross-functional re-evaluation of the CDM/CDS-identified risks and their CtQ factors&#8212;confirming that existing controls remain effective and detecting new or evolving risks as data accumulate over the course of the study.</p>
<list list-type="bullet">
<list-item><p>It should be also noted that risk assessment and management is a continuous and iterative process. While risk identification and mitigation are initiated at the time of protocol development, the steps above should also be repeated at regular intervals, ideally pre-defined within the process and any time a protocol is amended, or systemic issues are identified.</p></list-item>
<list-item><p>The study team should learn by &#8220;<italic>periodically reviewing risk control measures to ascertain whether the implemented quality management activities remain effective and relevant, taking into account emerging knowledge and experience. Additional risk control measures may be implemented as needed</italic>.&#8221;<sup><xref ref-type="bibr" rid="B1">1</xref></sup></p></list-item>
<list-item><p>Hold regular cross-functional risk reviews in which data management, data science, clinical operations, biostatistics, and relevant service providers reassess the identified risks and the effectiveness of their controls.</p></list-item>
<list-item><p>Analyze accumulating data trends and KRI/QTL signals to detect emerging or previously unrecognized CtQ risks before they escalate.</p></list-item>
<list-item><p>Feed findings from centralized and statistical monitoring, data quality checks, audits, and inspections back into the risk assessment so that controls are refined throughout the study.</p></list-item>
<list-item><p>Adapt to prevent further re-occurrence i.e.,</p>
<list list-type="simple">
<list-item><p>- Updating the study plans to include measures preventing systematic emerging risks to re-occur</p></list-item>
<list-item><p>- Adapt systems and processes accordingly</p></list-item></list></list-item>
</list>
<p><bold><underline>6. Risk Reporting:</underline></bold> Risk reporting documents and communicates the rb-CDM risk-management approach and its outcomes&#8212;including important quality issues and any QTL breaches&#8212;to the study team, functional and sponsor governance, and, through the clinical study report (CSR), health authorities.</p>
<list list-type="bullet">
<list-item><p>Important quality issues impacting participant protection and/or the reliability of study results should be summarized and reported <italic>&#8220;(including instances in which pre-defined acceptable ranges are exceeded)&#8221;</italic><sup><xref ref-type="bibr" rid="B1">1</xref></sup> with the corresponding remedial actions taken. Those should be documented in the clinical study report.<sup><xref ref-type="bibr" rid="B1">1</xref></sup></p></list-item>
<list-item><p>Report the status and effectiveness of the data-related risk controls and mitigations, including relevant KRIs and QTLs and the supporting data-quality metrics, so recipients can judge whether risks to the CtQ data stayed adequately controlled.</p></list-item>
<list-item><p>Summarize audit and inspection findings relevant to data integrity and rb-CDM risk management, together with how they were addressed.</p></list-item>
<list-item><p>Report the status and outcomes of data-related corrective and preventive actions (CAPAs), confirming that they were completed and that preventive measures are in place to avoid recurrence.</p></list-item>
</list>
</sec>
</sec>
<sec>
<title>6) rb-CDM Process Implementation Considerations During Different Stages of Protocol Development</title>
<p>The adoption of rb-CDM approaches has a deep impact on our traditional CDM ways of working, as shown in the process flows in this section. Throughout this section, examples of process flows have been provided in which risk-based process steps (in green) have been added to the traditional CDM steps (in blue) to illustrate the end-to-end nature of risk-based approaches.</p>
<sec>
<title>6.1) Risk Based Considerations During Study Design and Study Planning</title>
<fig id="F3">
<caption>
<p><bold>Figure 3</bold>: Example of rb-CDM Set-Up Process.</p>
</caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g3.png"/>
</fig>
<p>The Study Design and Planning steps shown in <xref ref-type="fig" rid="F3">Figure 3</xref> have also been summarized as a checklist in Appendix B.</p>
<p><bold>Risk Identification, Operational Feasibility and Risk Assessment</bold></p>
<p>Risk management is a core component of QbD and RBQM, encompassing the proactive identification, assessment, and control of risks throughout the clinical study lifecycle. It begins with risk prevention, by identifying threats prior to the first patient being enrolled into the study, which have the potential of leading to errors that could negatively impact patient protection, the credibility and reliability of the study results. As such, a sound scientific protocol, operationally feasible and without unnecessary burden to sites and patients, is the foundation of study execution.</p>
<p>First and foremost, it is critical to engage the appropriate cross-functional, multi-disciplinary, internal and external experts to manage all risks through their entire life cycle.</p>
<p><bold>Engage Stakeholders and Align on Protocol Design</bold></p>
<list list-type="bullet">
<list-item><p>Actively <bold>identify and engage with internal and external, multidisciplinary, cross-functional stakeholders</bold> (e.g., Clinical, Biostatistics, Safety) during protocol development to ensure alignment on protocol design.</p></list-item>
<list-item><p>Evaluate <bold>data and data management risks</bold> related to the entire data flow and processing of <bold>primary/secondary endpoints and safety data</bold>.</p></list-item>
<list-item><p>Ensure the <bold>protocol is operationally feasible</bold> and especially that the <bold>data flow does not introduce risks to data</bold> (e.g., leading to data capture, interpretation, and/or transformation errors).</p></list-item>
</list>
<p><bold>Identify and Document Critical to Quality (CtQ) Factors</bold></p>
<list list-type="bullet">
<list-item><p>Identify and document <bold>Critical to Quality (CtQ) factors</bold> prior to protocol finalization (i.e., critical data<bold>, systems and processes</bold>, including data review strategies).</p></list-item>
</list>
<table-wrap id="T4">
<caption>
<p><bold>Table 4</bold>: rb-CDM Lifecycle Crosswalk.</p>
</caption>
<table>
<tbody>
<tr>
<td align="left" valign="top"><bold>Lifecycle step (<xref ref-type="fig" rid="F2">Figure 2</xref>)</bold></td>
<td align="left" valign="top"><bold>Main Objective</bold></td>
<td align="left" valign="top"><bold>ICH E6(R3)</bold></td>
<td align="left" valign="top"><bold>Implemented in</bold></td>
</tr>
<tr>
<td align="left" valign="top">1. Identify CtQ Factors</td>
<td align="left" valign="top">QbD</td>
<td align="left" valign="top">Risk Identification</td>
<td align="left" valign="top">6.1</td>
</tr>
<tr>
<td align="left" valign="top">2. De-risk Study</td>
<td align="left" valign="top">QbD</td>
<td align="left" valign="top">Risk Identification + Risk Control (by design)</td>
<td align="left" valign="top">6.1</td>
</tr>
<tr>
<td align="left" valign="top">3. Define Mitigation &amp; Monitoring Strategies (QTLs, KRIs)</td>
<td align="left" valign="top">RBQM</td>
<td align="left" valign="top">Risk Evaluation + Risk Control</td>
<td align="left" valign="top">6.1&#8211;6.2</td>
</tr>
<tr>
<td align="left" valign="top">4. Implement Mitigation &amp; Monitoring Strategies</td>
<td align="left" valign="top">RBQM</td>
<td align="left" valign="top">Risk Control</td>
<td align="left" valign="top">6.2</td>
</tr>
<tr>
<td align="left" valign="top">5. Monitor Risks</td>
<td align="left" valign="top">RBQM</td>
<td align="left" valign="top">Risk Review + Risk Communication</td>
<td align="left" valign="top">6.2</td>
</tr>
<tr>
<td align="left" valign="top">6. Correct</td>
<td align="left" valign="top">Improvement loop</td>
<td align="left" valign="top">Risk Control (corrective)</td>
<td align="left" valign="top">6.2&#8211;6.3</td>
</tr>
<tr>
<td align="left" valign="top">7. Learn</td>
<td align="left" valign="top">Improvement loop</td>
<td align="left" valign="top">Risk Review</td>
<td align="left" valign="top">6.3</td>
</tr>
<tr>
<td align="left" valign="top">8. Adapt</td>
<td align="left" valign="top">Improvement loop</td>
<td align="left" valign="top">Risk Review</td>
<td align="left" valign="top">6.3</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p><bold>Note</bold>: Risk Communication and Risk Reporting are cross-cutting. Communication runs throughout the lifecycle (the center of <xref ref-type="fig" rid="F2">Figure 2</xref>), while Reporting concentrates at close-out (Section 6.3 and the clinical study report).</p></fn>
</table-wrap-foot>
</table-wrap>
<p><bold>Conduct Study Risk Assessment</bold></p>
<p>While many risks would be evaluated and accounted for by the multidisciplinary and cross-functional study team, some risks related to areas such as the 5Vs of the clinical data<sup><xref ref-type="bibr" rid="B13">13</xref></sup> (i.e., Volume, Variety, Velocity, Veracity, and Value), the data flow&#8217;s complexity, the extent of service providers involved, and planned technologies used through the data life cycle would be the primary focus of CDM.</p>
<list list-type="bullet">
<list-item><p>Perform a study <bold>risk assessment</bold> of the identified CtQs. There are many risk areas associated with the CtQ factors, including but not limited to the:</p>
<list list-type="simple">
<list-item><p>- complexity of protocol designs such as umbrella, basket, platform, master and adaptive;</p></list-item>
<list-item><p>- vulnerability of the patient population (e.g., elderly, pediatric);</p></list-item>
<list-item><p>- complexity of enrollment procedures (e.g., consent, eligibility, stratification and randomization);</p></list-item>
<list-item><p>- deviations from standard of care;</p></list-item>
<list-item><p>- characteristics of the participating countries (e.g., standard of care, customs, dialects);</p></list-item>
<list-item><p>- planned rate and distribution of enrollment;</p></list-item>
<list-item><p>- number, profile and experience of the study sites personnel (Incl. Principal Investigator) and countries;</p></list-item>
<list-item><p>- nature of the protocol-required procedures, with specific emphasis on the burden they may place on patients and sites (e.g., hourly blood draws, long clinic visits);</p></list-item>
<list-item><p>- organization of the study (e.g., site-centric vs. decentralized) with telemedicine and home nursing;</p></list-item>
<list-item><p>- planned technologies used to collect data, including when patients bring their own device;</p></list-item>
<list-item><p>- complexity of the data flow, including variety of the data sources;</p></list-item>
<list-item><p>- oversight of the capture and modification of the eSource data owned by the sites;</p></list-item>
<list-item><p>- number and experience of the data and operational Service Providers;</p></list-item>
<list-item><p>- and any other study execution activities that may lead to data errors that could negatively impact the credibility and reliability of the study results (e.g., central readers, decentralized study procedures).</p></list-item></list></list-item>
</list>
<p><bold>Protocol De-Risking</bold></p>
<list list-type="bullet">
<list-item><p>Based on the risk assessment, CDM should collaborate with the cross-functional and multidisciplinary study team to assess whether or not the protocol design introduces unnecessary risks due to its complexities and recommend simplification opportunities to reduce those risks (i.e., &#8220;de-risk&#8221; the protocol).</p></list-item>
</list>
<p><bold>Define Mitigations and Surveillance Plans for Remaining Risks: Design Data Review and Validation Strategy</bold></p>
<p>Develop a cross-functional, multidisciplinary and CDM-specific data review and validation strategy proportionate to risks.</p>
<list list-type="bullet">
<list-item><p>Define approaches for managing critical vs. non-critical data.</p></list-item>
<list-item><p>Identify data and associated strategies that will require site monitoring including Source Data Verification (SDV) and Source Data Review (SDR).</p></list-item>
</list>
<p><bold>Note</bold>: While this GCDMP chapter focuses on rb-CDM, the parallels between SDV and data review are important to highlight. Increasingly, CDM organizations are configuring EDC systems to dynamically adjust SDV requirements based on strategies outlined in the study monitoring plan. As a result, CDM subject matter experts (SMEs) should have a clear understanding of the SDV process and its implications for overall data quality.</p>
<p><underline>Important considerations</underline></p>
<p>Some publications, such as the 2014 TransCelerate publication on &#8220;<italic>Evaluating Source Data Verification as a Quality Control Measure in Clinical Trials</italic>&#8221;<sup><xref ref-type="bibr" rid="B15">15</xref></sup> and the 2021 SCDM publication on &#8220;<italic>Risk-based Quality Management in CDM</italic>&#8221;<sup><xref ref-type="bibr" rid="B16">16</xref></sup> have highlighted that Queries and SDV seem to have a low impact on study data corrections and study results, when evaluated as an <underline>overall study</underline> measure (e.g., as study level QTL).</p>
<p>Those publications showed that at study level, the industry median of eCRF data correction due to SDV was only 1.1%<sup><xref ref-type="bibr" rid="B14">14</xref></sup> and those from auto-queries varied from 0.9%<sup><xref ref-type="bibr" rid="B15">15</xref></sup> to 1.4%.<sup><xref ref-type="bibr" rid="B14">14</xref></sup></p>
<p>This does not suggest that SDV and query management lack value or should be eliminated from our traditional processes. With 100% SDV, all mistakes can theoretically be corrected. However, when assessing data corrections following SDV, at eCRF forms, sites, countries and Therapeutic Areas (TAs) level, it could highlight variability in the rate of data corrections across those dimensions. As an example, the median of eCRF data change rate due to SDV in Oncology was 2.7%<sup><xref ref-type="bibr" rid="B14">14</xref></sup> and only 0.5% for Pharmacokinetic studies.<sup><xref ref-type="bibr" rid="B14">14</xref></sup></p>
<p>So, while a study may show an overall low data change rate resulting from SDV, some sites may exhibit significantly higher rates&#8212;indicating potential issues with source data control. It means that correcting all transcription errors through SDV is not addressing the root cause, but only correcting errors retrospectively.</p>
<p>An efficient risk-adapted SDV approach should prioritize evaluating whether data quality meets predefined targets, rather than simply correcting individual transcription errors. It relies on a meaningful, data-driven sampling strategy to assess quality at both the study and site levels. When deficiencies are identified, proportionate corrective actions should follow to safeguard overall data integrity. Risk-adapted SDV is not designed as a mechanism for fixing isolated transcription errors; rather, it serves to detect and address underlying, systematic issues that require resolution.</p>
<p>Risk-based SDV and query strategies should therefore ensure focus on activities where they are most needed, proportionally to risks, without compromising data quality or patient protection.</p>
<p>As such, a sound approach should therefore apply proportionate SDV based on objective (i.e., data and fact driven) information such as (but not limited to):</p>
<list list-type="bullet">
<list-item><p>Pre-defined study and site-specific sampling strategies considering, as examples:</p>
<list list-type="simple">
<list-item><p>- historical performance of the site</p></list-item>
<list-item><p>- site experience in clinical research</p></list-item>
<list-item><p>- complexity of the data collected</p></list-item>
<list-item><p>- whether study procedures comply with country specific standard of care</p></list-item></list></list-item>
<list-item><p>During the study, study and site level SDV may be adjusted considering, as examples:</p>
<list list-type="simple">
<list-item><p>- Staff turnover</p></list-item>
<list-item><p>- SDV findings from initial sampling</p></list-item>
<list-item><p>- Protocol amendment</p></list-item></list></list-item>
</list>
<p><bold>Note</bold>: Site monitoring frequency should not be dictated by SDV efforts. A risk-based SDV approach does not necessarily mean fewer site monitoring visits, either on-site or remote, but rather a shift in focus to critical risk areas (e.g., SDR, protocol compliance, adherence to procedures). Frequency of monitoring visits may align with the minimum frequency necessary for broader oversight, with triggered monitoring visits based on findings and/or workload (e.g., SDR, drug reconciliation, etc.), beyond SDV alone.</p>
<list list-type="bullet">
<list-item><p>Similarly, data reviews need a well-defined and risk-proportionate strategy that ensures patient protection and the reliability of study results. It should rely on objective and holistic measures, not just on Queries.</p></list-item>
<list-item><p>As an example, while data review plans should primarily focus on edit checks and the validation of critical data points, it is equally important to have a clearly defined risk-proportionate strategy in place to monitor the quality of non-critical data. This would foster organization alignment and avoid ambiguity within the study team on the expectation for reviewing data (based on its criticality). This can be achieved through methods such as targeted sampling, trend analyses, and statistical techniques to detect atypical patterns or outliers.</p></list-item>
<list-item><p>Although considered non-critical, recurring or emerging data trends at the form, site, or even country level may indicate underlying issues that could compromise the reliability or credibility of study outcomes. Such signals may warrant further investigation or corrective actions to safeguard the overall integrity of the study.</p></list-item>
<list-item><p>Consider risks to data and data related activities performed by external service and technology providers.</p>
<list list-type="simple">
<list-item><p>- Evaluate the risk of eliminating non-critical data validation if other safety nets exist (e.g., aggregated data trending or statistical monitoring of non-critical data).</p></list-item></list></list-item>
</list>
<p><bold>Define Quality Control and Risk Mitigation Plan</bold></p>
<list list-type="bullet">
<list-item><p>Establish a quality control and risk mitigation plan, including the definition of targeted data acceptability targets to demonstrate reliability of study results (e.g., rate of missing data for primary end point).</p>
<list list-type="simple">
<list-item><p>- &#8220;<italic>Pre-specified acceptable ranges (e.g., Quality Tolerance Limits (QTLs) at study level)</italic>&#8221;<sup><xref ref-type="bibr" rid="B1">1</xref></sup> to monitor CtQ factors.</p></list-item>
<list-item><p>- KRIs for ongoing risk management.</p></list-item>
<list-item><p>- Risk based review of metadata including Audit Trail is expected according to ICH E6 (R3), which states the &#8220;<italic>Procedures for review of trial-specific data, audit trails and other relevant metadata should be in place</italic>.&#8221;<sup><xref ref-type="bibr" rid="B1">1</xref></sup> Identify issues that are not otherwise easily detectable as &#8220;<italic>beyond the reconstruction of the data events, audit trails can also provide critical insights on how the data is being collected</italic>&#8221;.<sup><xref ref-type="bibr" rid="B17">17</xref></sup></p></list-item></list></list-item>
</list>
<p>Potential objectives of a risk-based audit trail review include:</p>
<list list-type="bullet">
<list-item><p>investigation of data integrity issue</p></list-item>
<list-item><p>identification of suspicious justification and/or fraudulent data</p></list-item>
<list-item><p>identification of alternative source data implemented by sites</p></list-item>
<list-item><p>unauthorized accesses and data events</p></list-item>
<list-item><p>oversight on changes to critical data</p></list-item>
<list-item><p>process improvements based on trends</p></list-item>
<list-item><p>performance of users.</p></list-item>
</list>
<p>Example use cases and risk scenarios include:</p>
<list list-type="bullet">
<list-item><p>unauthorized access or lack of access control management</p></list-item>
<list-item><p>limited system access for specific roles, potentially indicating lack of oversight (e.g., by clinical investigator)</p></list-item>
<list-item><p>high proportion of data changes, potentially indicating high proportion of transcription errors</p></list-item>
<list-item><p>high proportion of changes specific to inclusion/exclusion (I/E) criteria data, primary efficacy, key secondary, having the potential to affect the reliability of study results</p></list-item>
<list-item><p>data not collected per protocol timing or collected at &#8220;unanticipated/suspicious&#8221; time.</p></list-item>
</list>
<p>For a more comprehensive list of scenarios, please refer to appendix 3 of the SCDM and eClinical Forum Position paper on Audit Trail Review.<sup><xref ref-type="bibr" rid="B17">17</xref></sup></p>
<p><bold>Specify Reporting and Analytics Requirements</bold></p>
<list list-type="bullet">
<list-item><p>Define specifications for reports, analytics, monitoring metrics, and risk indicators and dashboards to monitor critical data and processes.</p></list-item>
<list-item><p>Define how and to what extent non-critical data and process will be monitored.</p></list-item>
</list>
<p><bold>Implement Risk Control Strategies</bold></p>
<list list-type="bullet">
<list-item><p>Ensure all mitigations above are developed and implemented, ideally prior to the first participants entering the study.</p></list-item>
</list>
<p><bold>Additional Considerations</bold></p>
<list list-type="bullet">
<list-item><p>Define milestones-based deliverables and compliance monitoring.</p>
<list list-type="simple">
<list-item><p>- Specify the extent of data review needed for specific study milestones (i.e., Interim Data Deliverables) such as <bold>Interim Analyses (IAs), Data Safety Monitoring Board (DSMB) reports</bold>, and <bold>Development Safety Update Reports (DSURs)</bold>.</p></list-item>
<list-item><p>- Define and implement <bold>ongoing data compliance reports</bold> to monitor data quality and completeness.</p></list-item></list></list-item>
<list-item><p>Considerations when outsourcing CDM activities:</p>
<list list-type="simple">
<list-item><p>- Conduct Knowledge Transfer (KT) and secure the service provider collaboration (if applicable).</p></list-item>
<list-item><p>- Ensure KT to newly onboarded CDM Study Experts (included in the context of outsourced studies). This includes but is not limited to:</p>
<list list-type="bullet">
<list-item><p>the QbD principles applied to the study design and conduct;</p></list-item>
<list-item><p>the list of prioritized data to review and the purpose of the review;</p></list-item>
<list-item><p>the expected risks to watch that have been identified at study start or emerged during study conduct.</p></list-item></list></list-item></list></list-item>
<list-item><p>Require the service provider SMEs to perform an independent risk assessment based on the KT and encourage the service provider SMEs to raise questions or share additional insights.</p></list-item>
</list>
<p><bold>Key Takeaway</bold>: These start-up activities position CDM experts as <bold>proactive risk managers and data quality stewards</bold> from the earliest study stages, aligning with risk-based and quality-focused study execution.</p>
</sec>
<sec>
<title>6.2) Risk-Based Study Execution Considerations</title>
<fig id="F4">
<caption>
<p><bold>Figure 4</bold>: Example of rb-CDM Study Execution Process.</p>
</caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g4.png"/>
</fig>
<p>During the study execution phase, CDM experts should focus on the following key activities to ensure data quality and manage risks effectively. The Study Execution steps shown in <xref ref-type="fig" rid="F4">Figure 4</xref> have also been summarized as a checklist in Appendix C.</p>
<p><bold>Monitor, Document and Address Observed Risks</bold></p>
<p><bold>Conduct tailored data review proportional to risk</bold></p>
<list list-type="bullet">
<list-item><p>Perform data reviews commensurate with the level of risk being identified during the study start-up according to the corresponding strategy pre-defined upfront. As an example, non-critical data may be only reviewed through trending analysis or other means.</p></list-item>
<list-item><p>Prioritize the review of critical data, ensuring it is reviewed promptly and with heightened scrutiny as soon as possible upon data collection.</p></list-item>
<list-item><p><bold>Monitor KRIs and QTLs</bold>. &#8220;<italic>These pre-specified ranges reflect limits that when exceeded have the potential to impact participant safety or the reliability of trial results. Where deviation beyond these ranges is detected, an evaluation should be performed to determine if there is a possible systemic issue and if action is needed</italic>.&#8221;<sup><xref ref-type="bibr" rid="B1">1</xref></sup></p></list-item>
<list-item><p><bold>Identify systematic or process driven data issues</bold> including those stemming from study design and study conduct factors such as rate of enrollment, technologies used, etc. The key will be to efficiently and reliably monitor such risks through the holistic review of <bold><underline>all</underline></bold> clinical and operational data (i.e., finding data patterns and anomalies across studies, countries, sites, patients and eCRF forms).</p></list-item>
</list>
<p><bold>Monitor trends in non-critical data as identified through the risk assessment (i.e., data not associated with CtQ, data related to tertiary efficacy)</bold></p>
<list list-type="bullet">
<list-item><p>Conduct <bold>periodic trend reviews of non-critical data</bold> to detect emerging risks or issues.</p></list-item>
<list-item><p>Document, with appropriate justification, issues that do not present risks to participants&#8217; rights, safety, or well-being, nor to the reliability of study results.</p></list-item>
<list-item><p>Increase monitoring level of <bold>non-critical data similar to critical data</bold> when trend analysis or risk indicators suggest increased risk requiring heightened focus.</p></list-item>
</list>
<p><bold>Review critical data and associated metadata</bold></p>
<list list-type="bullet">
<list-item><p>Ensure the review of <bold>critical data includes associated metadata</bold>&#8212;for example, reviewing <bold>audit trail</bold> to confirm appropriate and justified data modifications.</p></list-item>
</list>
<p><bold>Monitor for the possible emergence of any new risks</bold></p>
<p>This includes, but is not limited to:</p>
<list list-type="bullet">
<list-item><p>Disasters and public health emergencies (PHEs) such as &#8220;<italic>hurricanes, earthquakes, military conflicts, infectious disease outbreaks, or bioterrorist attacks</italic>.&#8221;<sup><xref ref-type="bibr" rid="B18">18</xref></sup></p></list-item>
<list-item><p>Database availability delays that could delay study start.</p></list-item>
<list-item><p>Study timelines and data flow delays, which could negatively impact the availability of study data and/or results for safety reviews, the potential submission, and product approval.</p></list-item>
<list-item><p>Protocol amendments.</p></list-item>
<list-item><p>Protocol deviations.</p></list-item>
<list-item><p>Investigative site attrition.</p></list-item>
</list>
<p><bold>Monitor critical processes during study execution</bold></p>
<list list-type="bullet">
<list-item><p>Perform ongoing oversight of <bold>critical processes</bold>, including processes tied to <bold>endpoint data collection, protocol amendments, and Independent Review Committee (IRC) activities</bold>.</p></list-item>
</list>
<p><bold>Ensure synergetic oversight across stakeholders</bold></p>
<list list-type="bullet">
<list-item><p>Ensure alignment of <bold>sponsor and Service Provider oversight strategies and reporting</bold> to support <bold>timely assessment of data quality and study progress</bold>.</p></list-item>
<list-item><p>Conduct data integrity assessments.</p></list-item>
<list-item><p>Perform the data-integrity assessments defined in Section 5.4, at a cadence proportionate to the study&#8217;s CtQ factors and critical processes.</p>
<list list-type="simple">
<list-item><p>- Adjust the frequency of these assessments based on the outcome of the monitoring of <bold>risk assessment, QTL, and KRIs</bold>.</p></list-item></list></list-item>
</list>
<p><bold>Signal Review</bold></p>
<list list-type="bullet">
<list-item><p>Once a signal is determined to have moved from a risk to an issue, the underlying process or data issue needs to be addressed. Lastly, to close the loop, teams should follow up to make sure the issue has been fully resolved.</p></list-item>
</list>
<p>Below are some examples of signals that can be found with the potential responses made by teams.</p>
<list list-type="bullet">
<list-item><p>At a site in Puerto Rico, all enrolled patients are Hispanic. While this may appear statistically atypical when compared to other sites outside South America, it is not unexpected given the site&#8217;s geographic and demographic context. No immediate action is required; however, the study team should continue monitoring enrollment at the site to assess whether this pattern persists through the end of recruitment.</p></list-item>
<list-item><p>Many patients at a site have the same respiratory rate: Rather than questioning if the value was correctly entered into the source document, teams should think about how this lack of variability occurred. It is possible, but highly unlikely, that many patients at a site have the same respiratory rate. It is more likely that something was wrong with how the measurements were taken and/or recorded. Thus, the process for collecting and recording the rate should be reviewed. The importance of site compliance and of accurate data collection and recording should be reiterated to the site personnel. Since the existing data is not going to change, any issue with the process in taking measurements should be addressed, fixed, and monitored moving forward.</p></list-item>
<list-item><p>Patients on an oncology study have either no or a very low number of adverse events (AEs): This is statistically unlikely. The study team should ensure the site personnel understand how to collect AEs, and increase the SDR to check for unreported AEs. The site personnel may need retraining, and the study team should follow up to make sure the situation is resolved. Current data might not change, but the process should be fixed and then tracked for ongoing correctness.</p></list-item>
</list>
<p>To address the examples above, the CDM SMEs and the study team should dig deep into the data to understand the root cause of the issues. They need to perform detailed root cause analysis (RCA) and data review findings to resolve them. Occasionally, the team will need to go through multiple iterations of RCA and follow-up to fully understand the root cause. This requires a focus on details and strong communication skills as most findings will not result in queries, but rather in addressing systematic process issues and site behaviors.</p>
<p><bold>Adapt by Maintaining Dynamic Risk Management</bold></p>
<list list-type="bullet">
<list-item><p>Proactively solicit feedback from newly onboarded team members to benefit from fresh perspectives or therapeutic area insights.</p></list-item>
<list-item><p>During execution, apply the Risk Review step from Section 5.4 on an ongoing basis: reassess risks and the effectiveness of controls at defined intervals and whenever signals, audit or inspection findings, or amendments arise, updating the study risk assessment and standard libraries accordingly.</p></list-item>
</list>
<p><bold>Protocol Amendments or Major Study Updates (e.g., Urgent Safety Measures): Continuous Review and Protocol Amendments</bold></p>
<list list-type="bullet">
<list-item><p>Ensure all above activities are reviewed and updated in case of <bold>protocol amendments</bold>.</p></list-item>
<list-item><p>Evaluate all protocol or major study updates (e.g., within Investigator Brochure) for their impact on the risk assessment and mitigations required.</p></list-item>
</list>
<p><bold>Key Takeaway</bold>: These activities empower CDM experts to maintain proactive oversight of data quality, ensuring that critical data and processes are continuously monitored and managed in alignment with study risks.</p>
</sec>
<sec>
<title>6.3) Risk-Based Study Close-Out Considerations</title>
<fig id="F5">
<caption>
<p><bold>Figure 5</bold>: Example of rb-CDM Study Closure.</p>
</caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g5.png"/>
</fig>
<p>At the <bold>close-out phase</bold> of a clinical study, CDM experts should ensure the following activities are completed to confirm data integrity, regulatory compliance, and risk mitigation. The Study Closure steps shown in <xref ref-type="fig" rid="F5">Figure 5</xref> have also been summarized as a checklist in Appendix D.</p>
<p><bold>Conduct a Final Risk Evaluation</bold></p>
<list list-type="bullet">
<list-item><p>Perform a comprehensive final review of all occurrences of issues related to CtQ factors that have been observed (anticipated or not in the risk assessment) to confirm that all identified issues associated with those risks have been appropriately addressed.</p></list-item>
<list-item><p>Ensure any newly identified risks are mitigated, if necessary, prior to database lock.</p></list-item>
<list-item><p>Conduct a final data quality assessment focused on CtQ factors, QTLs and KRIs, thus evaluating the impact of all observed issues on 1) regulatory and protocol compliance, 2) participant protection, and 3) the reliability of study results.</p></list-item>
</list>
<p><bold>Assess Remaining Outstanding Issues</bold></p>
<p><bold>Review and close outstanding issues</bold></p>
<list list-type="bullet">
<list-item><p>Resolve new and remaining issues impacting participant&#8217;s rights, safety and well-being, the reliability of study results and regulatory and protocol compliance.</p></list-item>
<list-item><p>Formally close <bold>any remaining issues that do not impact patient protection or the reliability of study results</bold> with clear justifications and documentation.</p></list-item>
</list>
<p><bold>Document process completion and compliance</bold></p>
<list list-type="bullet">
<list-item><p>Prepare documentation confirming completion of close-out activities and adherence to the study&#8217;s quality plan.</p></list-item>
<list-item><p>Examples of documentation include:</p>
<list list-type="simple">
<list-item><p>- CtQ assessments</p></list-item>
<list-item><p>- KRI and QTLs assessments</p></list-item>
<list-item><p>- Corrective Action and Preventive Action (CAPA) outcomes</p></list-item>
<list-item><p>- Other relevant compliance records</p></list-item></list></list-item>
</list>
<p><bold>Adapt Processes and Systems Based on Lessons Learned</bold></p>
<list list-type="bullet">
<list-item><p>Perform cross-functional and multidisciplinary lessons learned by assessing the following:</p>
<list list-type="simple">
<list-item><p>- the outcome of the final data quality evaluation,</p></list-item>
<list-item><p>- the risks realized in the studies,</p></list-item>
<list-item><p>- the effectiveness of mitigations,</p></list-item>
<list-item><p>- related audits and inspections.</p></list-item></list></list-item>
<list-item><p>Complete the close-out lessons-learned and CAPA activities described in Section 5.1 (Best Practice 8) and Section 5.3, updating SOPs, processes, and systems to prevent recurrence in future studies; CDM subject-matter experts should drive the resulting CAPAs.</p></list-item>
</list>
<p><bold>Key Takeaway</bold>: These close-out activities ensure a high-quality, compliant database lock and clear documentation of risk management outcomes.</p>
</sec>
<sec>
<title>6.4) Practical rb-CDM Study examples for CDM Experts</title>
<p>The examples below are illustrative and do not represent an exhaustive identification of CtQ factors, risks, or mitigation strategies for the studies described.</p>
<p><bold>Example #1: Age-Specific Protocols</bold></p>
<table-wrap>
<table>
<tbody>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g6.png"/></td>
<td align="left" valign="top"><bold>Risk Identification and Risk Assessment</bold><break/>Selected CtQ factors may include the accuracy and consistency of the primary PRO endpoint (IBS-SSS), including diary compliance and handling of missing data. Assessments are added by age (a PRO at the age of 8, a second PRO at the age of 9, self-administration of IMP at the age of 12, a daily diary at the age of 13), but no new PROs are introduced beyond a participant&#8217;s first visit &#8212; so some participants miss PROs they would otherwise reach, leaving data gaps.</td>
</tr>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g7.png"/></td>
<td align="left" valign="top"><bold>De-risk Study Considerations</bold><break/>Make the design participant-centric and adaptive &#8212; allow a baseline ePRO whenever a participant joins (not only at age 8), add a participant-burden check tied to a drop-out KRI, and review prior protocols for age-related deviations to inform QbD.</td>
</tr>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g8.png"/></td>
<td align="left" valign="top"><bold>Define risk mitigation and Controls</bold><break/>Set age-specific KRIs on ePRO-completion compliance alongside a study-wide ePRO-compliance QTL.</td>
</tr>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g9.png"/></td>
<td align="left" valign="top"><bold>Implement risk mitigation and Controls</bold><break/>Activate the QTL and KRIs; train site staff on the requirement; create age-appropriate data-entry guidance (an 8- and a 13-year-old differ cognitively); and add edit checks for a prior ePRO, ePRO reminders/prompts, and source-data-review checks.</td>
</tr>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g10.png"/></td>
<td align="left" valign="top"><bold>Monitor risks</bold><break/>Watch for links between daily-ePRO inconsistencies and other compliance issues, and review the KRIs and QTL at the defined frequency, tracking trends over time.</td>
</tr>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g11.png"/></td>
<td align="left" valign="top"><bold>Correct, Learn &amp; Adapt</bold><break/>Document corrective actions (e.g., friendly ePRO reminders for 8-to-9-year-olds if compliance dips) and run a Plan-Do-Check-Act cycle to sustain data quality as participants age.</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p><bold>Note</bold>: IBS-SSS: Irritable Bowel Syndrome Severity Scoring System.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>A pediatric inflammatory bowel disease study introduces PRO assessments at different ages, creating a data-collection risk.</p>
<p><bold>Example #2: Endpoint-Specific Protocols</bold></p>
<p>A Phase II study assessing the reduction in the rate of acute chronic obstructive pulmonary disease (COPD) exacerbations, where data quality depends on how exacerbations are reported.</p>
<table-wrap>
<table>
<tbody>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g12.png"/></td>
<td align="left" valign="top"><bold>CtQ Identification and Risk Assessment</bold><break/>Selected CtQ factors may include the accurate, consistent, and timely reporting of acute COPD exacerbations (investigator severity grading; patient symptom reporting via the EXACT eDiary and the CAT) plus upfront investigator training. Key risks: &#8220;acute worsening&#8221; lacks measurable thresholds (diagnostic variability), and the &gt; =14-day rule between events can fragment a single ongoing episode.</td>
</tr>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g13.png"/></td>
<td align="left" valign="top"><bold>De-risk Study Considerations</bold><break/>Simplify endpoint definitions and add technical controls &#8212; define worsening concretely (e.g., a &gt; =2-point CAT increase within 48 hours), require real-time reporting, and count a new event only after symptoms return to baseline and remain stable for &gt; =7 days.</td>
</tr>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g14.png"/></td>
<td align="left" valign="top"><bold>Define risk mitigation and Controls</bold><break/>Design a KRI that calculates the rate of acute COPD exacerbations per participant-visit at each site to detect under- or over-reporting across sites and countries.</td>
</tr>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g15.png"/></td>
<td align="left" valign="top"><bold>Implement risk mitigation and Controls</bold><break/>Program the KRI and data-quality assessment; assign the medical manager as primary reviewer; set triggers (low rates prompt eCRF-completeness checks, high rates prompt safety assessment); and review and refine thresholds throughout the study.</td>
</tr>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g16.png"/></td>
<td align="left" valign="top"><bold>Monitor risks</bold><break/>Site A reported 0 exacerbations versus a study average of 0.64 per patient, across ~10 participants over three years.<break/>A cross-functional review (Clinical Data Management, Medical Monitoring, and Project Management) examined four risk categories and identified two root causes:
<list list-type="bullet">
<list-item><p>Site process (the protocol was misunderstood, with inconsistent, subjective assessment) and</p></list-item>
<list-item><p>Data collection (inefficient workflows caused delayed or missing eCRF entries).</p></list-item>
<list-item><p>Participant-reporting and systemic/system causes were ruled out, because the issue was site-wide while other sites performed normally.</p></list-item>
</list></td>
</tr>
<tr>
<td align="left" valign="top"><inline-graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="jscdm-6-1-524-g17.png"/></td>
<td align="left" valign="top"><bold>Correct, Learn and Adapt</bold><break/>Retrospectively document all missed cases from source data and eDiaries, and retrain the site on precise exacerbation identification, real-time reporting, and workflow optimization; reporting compliance improved and was sustained.<break/>Refresh critical-process training regularly (not only at start-up), identify risks at protocol design to reduce complexity and site/participant burden, and make regular training standard practice as a preventive action.</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn>
<p><bold>Note</bold>: CAT: COPT Assessment Test.</p></fn>
</table-wrap-foot>
</table-wrap>
</sec>
<sec>
<title>6.5) Additional considerations</title>
<p>First and foremost, we need to clearly understand what adopting rb-CDM approaches means.</p>
<p>It evolves around adopting rb-CDM means applying the QbD and RBQM framework of Section 5 &#8212; embedding quality at design, focusing effort proportionately on what is critical, and running the six-step risk-management cycle (Section 5.4) within the cross-functional, critical-thinking culture described in Sections 5.2&#8211;5.3.</p>
<p>It does <bold><underline>not</underline></bold> mean:</p>
<list list-type="bullet">
<list-item><p>Taking risk nor promoting risk.</p></list-item>
<list-item><p>Asking other functions to increase their data oversight to perform activities CDM is no longer planning to perform (or not performing as historically performed).</p></list-item>
</list>
</sec>
</sec>
<sec>
<title>7) SOP Considerations</title>
<p>The relevant SOP may vary from company to company. There might be an overarching SOP and then associated job aids or work instructions, or it may spread across various SOPs. However, the following areas should be covered by process document(s):</p>
<list list-type="simple">
<list-item><p>1. <bold>Risk Assessment, Categorization and Prevention SOP(s)</bold></p></list-item></list>
<p>Purpose: Define a structured approach to identify, assess, and mitigate data-related risks.</p>
<p>Key Elements:</p>
<list list-type="bullet">
<list-item><p>Identification and categorization of data-related risks at the protocol and system level</p></list-item>
<list-item><p>Identification and documentation of CtQ factors</p></list-item>
<list-item><p>Definition of mitigations and risk-surveillance strategies</p></list-item>
</list>
<list list-type="simple">
<list-item><p>2. <bold>Data Management Plan (DMP) Development SOP</bold></p></list-item></list>
<p>Purpose: Ensure the DMP reflects risk-based data strategies.</p>
<p>Key Elements:</p>
<list list-type="bullet">
<list-item><p>Integration of risk-based data strategies into the DMP</p></list-item>
<list-item><p>Mapping critical data flows with associated system and data risks</p></list-item>
<list-item><p>Inclusion of risk-informed roles, responsibilities, and data review strategies</p></list-item>
<list-item><p>References to KRIs, QTLs, and mitigation procedures</p></list-item>
</list>
<list list-type="simple">
<list-item><p>3. <bold>Risk-Based Data Review and Validation SOP(s)</bold></p></list-item></list>
<p>Purpose: Define risk-informed approaches to data validation and review.</p>
<p>Key Elements:</p>
<list list-type="bullet">
<list-item><p>Risk-prioritized review of critical data elements and processes</p></list-item>
<list-item><p>Query strategy aligned with risk levels and CtQ factors</p></list-item>
<list-item><p>Metadata and operational data review processes</p></list-item>
<list-item><p>Use of centralized monitoring techniques and technologies</p></list-item>
<list-item><p>Review of trends, outliers, KRIs, and QTLs</p></list-item>
<list-item><p>Action thresholds and trigger-based follow-up procedures</p></list-item>
</list>
<list list-type="simple">
<list-item><p>4. <bold>Signal Detection and Escalation SOP</bold></p></list-item></list>
<p>Purpose: Standardize how potential data quality issues or anomalies are detected and acted upon.</p>
<p>Key Elements:</p>
<list list-type="bullet">
<list-item><p>Proactive signal detection via statistical and visual analytics</p></list-item>
<list-item><p>Decision-tree for determining whether findings are isolated, systemic, or critical</p></list-item>
<list-item><p>Escalation pathways to clinical, quality, or regulatory teams</p></list-item>
<list-item><p>Time-bound escalation handling and documentation procedures</p></list-item>
</list>
<list list-type="simple">
<list-item><p>5. <bold>Risk Management and CAPA SOP</bold></p></list-item></list>
<p>Purpose: Govern how emerging risks and deviations are investigated and managed.</p>
<p>Key Elements:</p>
<list list-type="bullet">
<list-item><p>Ongoing review and update of the risk assessment, risk monitoring, and mitigation strategies</p></list-item>
<list-item><p>Identification of systematic or process driven data related issues</p></list-item>
<list-item><p>Documentation and resolution of data-related risk signals</p></list-item>
<list-item><p>Root cause analysis and preventive action</p></list-item>
</list>
<list list-type="simple">
<list-item><p>6. <bold>Protocol Deviation and Data Anomaly Handling SOP</bold></p></list-item></list>
<p>Purpose: Clarify classification, triage, and resolution of unexpected data issues.</p>
<p>Key Elements:</p>
<list list-type="bullet">
<list-item><p>Differentiating between protocol deviations, data inconsistencies, and fraud</p></list-item>
<list-item><p>Triage framework based on patient&#8217;s protection and reliability of trial results</p></list-item>
<list-item><p>Documentation and follow-up of confirmed anomalies</p></list-item>
</list>
<list list-type="simple">
<list-item><p>7. <bold>Oversight and Governance of Risk-Based Data Management SOP</bold></p></list-item></list>
<p>Purpose: Establish governance and ownership for ongoing risk-based data oversight.</p>
<p>Key Elements:</p>
<list list-type="bullet">
<list-item><p>Definition of cross-functional roles and responsibilities</p></list-item>
<list-item><p>Documentation of decision-making processes and risk sign-offs</p></list-item>
<list-item><p>Governance model for ongoing review of risk strategy effectiveness</p></list-item>
</list>
<list list-type="simple">
<list-item><p>8. <bold>Database Lock SOP</bold></p></list-item></list>
<p>Purpose: Pre-database lock checks with risk-based quality control emphasis.</p>
<p>Key Elements:</p>
<list list-type="bullet">
<list-item><p>Conduct a final data quality assessment focused on CtQ factors</p></list-item>
<list-item><p>Documentation of any open issues, their justification, or resolution</p></list-item>
<list-item><p>Confirmation of protocol-defined quality acceptance criteria before lock</p></list-item>
</list>
<list list-type="simple">
<list-item><p>9. <bold>Audit Trail and Documentation SOP</bold></p></list-item></list>
<p>Purpose: Ensure audit readiness and traceability of risk-based decisions and activities.</p>
<p>Key Elements:</p>
<list list-type="bullet">
<list-item><p>Risk-prioritized review of audit trail to assess risks to critical data and processes.</p></list-item>
<list-item><p>Traceability of risk-related decisions and data oversight activities</p></list-item>
</list>
</sec>
<sec>
<title>Acronyms</title>
<table-wrap>
<table>
<tbody>
<tr>
<td align="left" valign="top">Acronym</td>
<td align="left" valign="top">Description</td>
</tr>
<tr>
<td align="left" valign="top">AE</td>
<td align="left" valign="top">Adverse Event</td>
</tr>
<tr>
<td align="left" valign="top">ALCOA</td>
<td align="left" valign="top">Attributable, Legible, Contemporaneous, Original and Accurate</td>
</tr>
<tr>
<td align="left" valign="top">CAPA</td>
<td align="left" valign="top">Corrective Action and Preventive Action</td>
</tr>
<tr>
<td align="left" valign="top">CAT</td>
<td align="left" valign="top">COPD Assessment Test</td>
</tr>
<tr>
<td align="left" valign="top">CDISC</td>
<td align="left" valign="top">Clinical Data Interchange Standards Consortium</td>
</tr>
<tr>
<td align="left" valign="top">CDM</td>
<td align="left" valign="top">Clinical Data Management</td>
</tr>
<tr>
<td align="left" valign="top">CDS</td>
<td align="left" valign="top">Clinical Data Science</td>
</tr>
<tr>
<td align="left" valign="top">CMP</td>
<td align="left" valign="top">Centralized Monitoring Plan</td>
</tr>
<tr>
<td align="left" valign="top">COPD</td>
<td align="left" valign="top">Chronic Obstructive Pulmonary Disease</td>
</tr>
<tr>
<td align="left" valign="top">CRO</td>
<td align="left" valign="top">Clinical Research Organization</td>
</tr>
<tr>
<td align="left" valign="top">CtQ</td>
<td align="left" valign="top">Critical to Quality</td>
</tr>
<tr>
<td align="left" valign="top">CTTI</td>
<td align="left" valign="top">Clinical Trial Transformation Initiative</td>
</tr>
<tr>
<td align="left" valign="top">DMP</td>
<td align="left" valign="top">Data Management Plan</td>
</tr>
<tr>
<td align="left" valign="top">DSMB</td>
<td align="left" valign="top">Data Safety Monitoring Board</td>
</tr>
<tr>
<td align="left" valign="top">DSUR</td>
<td align="left" valign="top">Development Safety Update Report</td>
</tr>
<tr>
<td align="left" valign="top">eCOA</td>
<td align="left" valign="top">electronic Clinical Outcome Assessment</td>
</tr>
<tr>
<td align="left" valign="top">EDC</td>
<td align="left" valign="top">Electronic Data Capture</td>
</tr>
<tr>
<td align="left" valign="top">EMA</td>
<td align="left" valign="top">European Medicines Agency</td>
</tr>
<tr>
<td align="left" valign="top">ePRO</td>
<td align="left" valign="top">electronic Patient Reported Outcome</td>
</tr>
<tr>
<td align="left" valign="top">EXACT</td>
<td align="left" valign="top">EXAcerbations of Chronic pulmonary disease Tool</td>
</tr>
<tr>
<td align="left" valign="top">FDA</td>
<td align="left" valign="top">Food and Drug Administration</td>
</tr>
<tr>
<td align="left" valign="top">FHIR</td>
<td align="left" valign="top">Fast Healthcare Interoperability Resources</td>
</tr>
<tr>
<td align="left" valign="top">GCDMP</td>
<td align="left" valign="top">Good Clinical Data Management Practice</td>
</tr>
<tr>
<td align="left" valign="top">GCP</td>
<td align="left" valign="top">Good Clinical Practice</td>
</tr>
<tr>
<td align="left" valign="top">HL7</td>
<td align="left" valign="top">Health Level Seven</td>
</tr>
<tr>
<td align="left" valign="top">IA</td>
<td align="left" valign="top">Interim Analysis</td>
</tr>
<tr>
<td align="left" valign="top">ICH</td>
<td align="left" valign="top">International Council for Harmonisation</td>
</tr>
<tr>
<td align="left" valign="top">IQRMP</td>
<td align="left" valign="top">Integrated Quality Risk Management Plan</td>
</tr>
<tr>
<td align="left" valign="top">IRC</td>
<td align="left" valign="top">Independent Review Committee</td>
</tr>
<tr>
<td align="left" valign="top">KRI</td>
<td align="left" valign="top">Key Risk Indicator</td>
</tr>
<tr>
<td align="left" valign="top">KT</td>
<td align="left" valign="top">Knowledge Transfer</td>
</tr>
<tr>
<td align="left" valign="top">PHE</td>
<td align="left" valign="top">Public Health Emergency</td>
</tr>
<tr>
<td align="left" valign="top">QbD</td>
<td align="left" valign="top">Quality by Design</td>
</tr>
<tr>
<td align="left" valign="top">QC</td>
<td align="left" valign="top">Quality Control</td>
</tr>
<tr>
<td align="left" valign="top">QTL</td>
<td align="left" valign="top">Quality Tolerance Limit</td>
</tr>
<tr>
<td align="left" valign="top">RACI</td>
<td align="left" valign="top">Responsible, Accountable, Consulted &amp; Informed</td>
</tr>
<tr>
<td align="left" valign="top">RACT</td>
<td align="left" valign="top">Risk Assessment Categorization Tool</td>
</tr>
<tr>
<td align="left" valign="top">rb-CDM</td>
<td align="left" valign="top">risk-based Clinical Data Management</td>
</tr>
<tr>
<td align="left" valign="top">RBQM</td>
<td align="left" valign="top">Risk-Based Quality Management</td>
</tr>
<tr>
<td align="left" valign="top">RCA</td>
<td align="left" valign="top">Root Cause Analysis</td>
</tr>
<tr>
<td align="left" valign="top">SCDM</td>
<td align="left" valign="top">Society for Clinical Data Management</td>
</tr>
<tr>
<td align="left" valign="top">SDR</td>
<td align="left" valign="top">Source Data Review</td>
</tr>
<tr>
<td align="left" valign="top">SDV</td>
<td align="left" valign="top">Source Data Verification</td>
</tr>
<tr>
<td align="left" valign="top">SME</td>
<td align="left" valign="top">Subject Matter Expert</td>
</tr>
<tr>
<td align="left" valign="top">SOP</td>
<td align="left" valign="top">Standard Operating Procedure</td>
</tr>
<tr>
<td align="left" valign="top">TA</td>
<td align="left" valign="top">Therapeutic Area</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec sec-type="supplementary-material">
<title>Additional File</title>
<p>The additional file for this article can be found as follows:</p>
<supplementary-material id="S1" xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://doi.org/10.47912/jscdm.524.s1">
<!--[<inline-supplementary-material xlink:title="local_file" xlink:href="jscdm-6-1-524-s1.docx">jscdm-6-1-524-s1.docx</inline-supplementary-material>]-->
<!--[<inline-supplementary-material xlink:title="local_file" xlink:href="jscdm-6-1-524-s1.pdf">jscdm-6-1-524-s1.pdf</inline-supplementary-material>]-->
<caption>
<p><bold>Appendices.</bold> Appendix A to D. DOI: <uri>https://doi.org/10.47912/jscdm.524.s1</uri></p>
</caption>
</supplementary-material>
</sec>
</body>
<back>
<sec>
<title>Acknowledgements</title>
<p>We would like to acknowledge the valuable contributions of Cheryl Grandinetti (FDA) and Steve Young (CluePoints), whose input and support greatly assisted the development of this chapter.</p>
</sec>
<sec>
<title>Literature Review</title>
<p>Due to the evolving ongoing work on Risk-Based CDM, there was no literature search and review done for this chapter.</p>
</sec>
<sec>
<title>Revision History</title>
<table-wrap>
<table>
<tbody>
<tr>
<td align="left" valign="top"><bold>Publication Date</bold></td>
<td align="left" valign="top"><bold>Comments</bold></td>
</tr>
<tr>
<td align="left" valign="top">September 2025</td>
<td align="left" valign="top">Final DRAFT for public review</td>
</tr>
<tr>
<td align="left" valign="top">April 2026</td>
<td align="left" valign="top">Post Public review Version</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec>
<title>Competing Interests</title>
<p>The authors have no competing interests to declare.</p>
</sec>
<ref-list>
<ref id="B1"><mixed-citation publication-type="webpage"><collab>International Council for Harmonisation</collab>. <source>Integrated Addendum to ICH E6(R2): Guideline for Good Clinical Practice E6 (R3)</source>. <publisher-name>International Council for Harmonisation</publisher-name>; <year>2025</year>. Accessed August 25, 2026. <uri>https://www.ich.org/page/efficacy-guidelines#6-2</uri></mixed-citation></ref>
<ref id="B2"><mixed-citation publication-type="webpage"><collab>International Council for Harmonisation</collab>. <source>ICH E8 (R1), General Considerations for Clinical Trials</source>. <publisher-name>International Council for Harmonisation</publisher-name>; <year>2021</year>. Accessed August 25, 2026. <uri>https://database.ich.org/sites/default/files/E8-R1_Guideline_Step4_2021_1006.pdf</uri></mixed-citation></ref>
<ref id="B3"><mixed-citation publication-type="journal"><string-name><surname>Adams</surname> <given-names>A</given-names></string-name>, <string-name><surname>Adelfio</surname> <given-names>A</given-names></string-name>, <string-name><surname>Barnes</surname> <given-names>B</given-names></string-name>, et al. <article-title>Risk-based monitoring in clinical trials: 2021 update</article-title>. <source>Ther Innov Regul Sci</source>. <year>2023</year>;<volume>57</volume>:<fpage>529</fpage>&#8211;<lpage>537</lpage>. DOI: <pub-id pub-id-type="doi">10.1007/s43441-022-00496-9</pub-id></mixed-citation></ref>
<ref id="B4"><mixed-citation publication-type="webpage"><collab>Society for Clinical Data Management</collab>. <source>SCDM competency framework</source>. <publisher-name>Society for Clinical Data Management</publisher-name>. Accessed August 25, 2026. <uri>https://scdm.org/cdm-competency-framework/</uri></mixed-citation></ref>
<ref id="B5"><mixed-citation publication-type="webpage"><collab>US Food and Drug Administration</collab>. <source>Guidance for industry, oversight of clinical investigations &#8212; a risk-based approach to monitoring</source>. <publisher-name>US Department of Health and Human Services</publisher-name>; <year>2013</year>. Accessed August 25, 2026. <uri>https://www.fda.gov/regulatory-information/search-fda-guidance-documents/oversight-clinical-investigations-risk-based-approach-monitoring</uri></mixed-citation></ref>
<ref id="B6"><mixed-citation publication-type="webpage"><collab>Medicines and Healthcare Products Regulatory Agency</collab>. <source>&#8216;GXP&#8217; data integrity guidance and definitions</source>. <publisher-name>HM Government</publisher-name>; <year>2018</year>. Accessed August 25, 2026. <uri>https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/687246/MHRA_GxP_data_integrity_guide_March_edited_Final.pdf</uri></mixed-citation></ref>
<ref id="B7"><mixed-citation publication-type="webpage"><collab>Medicines and Healthcare Products Regulatory Agency</collab>. <source>Oversight and monitoring</source>. <publisher-name>HM Government</publisher-name>; <year>2022</year>. Accessed August 25, 2026. <uri>https://www.gov.uk/government/publications/oversight-and-monitoring-of-investigational-medical-product-trials/oversight-and-monitoring-activities</uri></mixed-citation></ref>
<ref id="B8"><mixed-citation publication-type="webpage"><collab>US Food and Drug Administration</collab>. <source>A risk-based approach to monitoring of clinical investigations questions and answers</source>. <publisher-name>US Department of Health and Human Services</publisher-name>; <year>2023</year>. Accessed August 25, 2026. <uri>https://www.fda.gov/media/121479/download</uri></mixed-citation></ref>
<ref id="B9"><mixed-citation publication-type="webpage"><collab>Society for Clinical Data Management</collab>. <source>Position paper on how to create a clinical data science organization</source>. <publisher-name>Society for Clinical Data Management</publisher-name>; <year>2022</year>. Accessed August 25, 2026. <uri>https://scdm.org/wp-content/uploads/2024/03/SCDM-Position-Paper-Evolution-into-Clinical-to-Data-Science-V9.0.pdf</uri></mixed-citation></ref>
<ref id="B10"><mixed-citation publication-type="webpage"><collab>Clinical Trials Transformation Initiative</collab>. <source>Quality by Design (QbD) project, critical to quality factors principles document</source>. <publisher-name>Clinical Trials Transformation Initiative</publisher-name>; <year>2015</year>. Accessed August 25, 2026. <uri>https://ctti-clinicaltrials.org/wp-content/uploads/2021/07/CTTI_QbD_Workshop_Principles_Document.pdf</uri></mixed-citation></ref>
<ref id="B11"><mixed-citation publication-type="webpage"><collab>TransCelerate Biopharma Inc</collab>. <source>The Risk Assessment Categorization Tool (RACT) template</source>. <publisher-name>TransCelerate Biopharma Inc</publisher-name>; <year>2013</year>. Accessed August 25, 2026. <uri>https://www.transceleratebiopharmainc.com/assets/risk-based-monitoring-solutions/</uri></mixed-citation></ref>
<ref id="B12"><mixed-citation publication-type="webpage"><collab>TransCelerate Biopharma Inc</collab>. <source>The Risk Indicator Library</source>. <publisher-name>TransCelerate Biopharma Inc</publisher-name>; <year>2019</year>. Accessed August 25, 2026. <uri>https://www.transceleratebiopharmainc.com/wp-content/uploads/2019/02/TransCelerate-RBM-Risk-Indicator-Library_Final-21Feb2019.xlsx</uri></mixed-citation></ref>
<ref id="B13"><mixed-citation publication-type="webpage"><collab>TransCelerate Biopharma Inc</collab>. <source>Quality Tolerance Limits: Framework for Successful Implementation in Clinical Development</source>. <publisher-name>TransCelerate Biopharma Inc</publisher-name>; <year>2020</year>. Accessed August 25, 2026. <uri>https://pmc.ncbi.nlm.nih.gov/articles/PMC7864825/</uri></mixed-citation></ref>
<ref id="B14"><mixed-citation publication-type="webpage"><collab>Society for Clinical Data Management</collab>. <source>The 5Vs of clinical data</source>. <publisher-name>Society for Clinical Data Management</publisher-name>; <year>2022</year>. Accessed August 25, 2026. <uri>https://scdm.org/wp-content/uploads/2024/03/SCDM-The-5Vs-of-Clinical-Data-FINAL.pdf</uri></mixed-citation></ref>
<ref id="B15"><mixed-citation publication-type="webpage"><collab>TransCelerate Biopharma Inc</collab>. <source>Evaluating source data verification as a quality control measure in clinical trials</source>. <publisher-name>TransCelerate Biopharma Inc.</publisher-name>; <year>2014</year>, Accessed August 25, 2026. <uri>https://journals.sagepub.com/doi/pdf/10.1177/2168479014554400</uri></mixed-citation></ref>
<ref id="B16"><mixed-citation publication-type=""><string-name><surname>Stokman</surname> <given-names>PG</given-names></string-name>, <string-name><surname>Ensign</surname> <given-names>L</given-names></string-name>, <string-name><surname>Langeneckhardt</surname> <given-names>D</given-names></string-name>, et al., <article-title>2021, Risk-based quality management in CDM An inquiry into the value of generalized query-based data cleaning</article-title>. <source>J Soc Clin Data Manage</source>. <year>2021</year>;<volume>1</volume>(<issue>1</issue>). DOI: <pub-id pub-id-type="doi">10.47912/jscdm.20</pub-id></mixed-citation></ref>
<ref id="B17"><mixed-citation publication-type="webpage"><collab>Society for Clinical Data Management and eClinical Forum</collab>. <source>Audit trail review: A key tool to ensure data integrity</source>. <publisher-name>Society for Clinical Data Management and eClinical Forum</publisher-name>; <year>2021</year>, Accessed August 25, 2026. <uri>https://scdm.org/wp-content/uploads/2024/07/2021-eCF_SCDM-ATR-Industry-Position-Paper-Version-PR1-2.pdf</uri></mixed-citation></ref>
<ref id="B18"><mixed-citation publication-type="webpage"><collab>US Food and Drug Administration</collab>. <source>Considerations for the conduct of clinical trials of medical products during major disruptions due to disasters and public health emergencies</source>. <publisher-name>US Department of Health and Human Services</publisher-name>; <year>2023</year>. Accessed August 25, 2026. <uri>https://www.fda.gov/media/172258/download</uri></mixed-citation></ref>
</ref-list>
</back>
</article>