1) Learning Objectives
After reading this chapter, the reader will be able to:
Explain the benefits of applying risk-based approaches to CDM activities
Differentiate between data integrity and data quality
Describe the key frameworks underpinning risk-based approaches (i.e., QbD, RBQM, and fit for purpose clinical study quality)
Interpret relevant regulatory expectations in the context of CDM practices
Apply risk-based principles to identify and prioritize actions that drive data quality in an efficient and effective manner
2) Introduction
This chapter covers how Clinical Data Management (CDM) can evolve from traditional, reactive quality control (QC)-based strategies to proactive, end-to-end Quality Management within a risk-based quality management (RBQM) framework. This risk-based CDM (rb-CDM) evolution should begin with the adoption of foundational principles of quality by design (QbD), and progressively expand to apply RBQM cross-functionally, meaning:
Actively participating in study team discussions and decisions on Critical to Quality (CtQ) factors (e.g., critical design elements, data, processes, and systems), QbD decisions, definitions for Quality Tolerance Limits (QTLs) and Key Risk Indicators (KRIs).
Performing a risk assessment during the planning phase of the study and throughout its entire life cycle with clear accountability for areas where CDM contributes expertise, particularly across end-to-end data flows, and where it can proactively minimize or mitigate identified risks.
De-risking the protocol prior to study start to prevent avoidable risks, and applying mitigation strategies for risks that cannot be avoided, alongside a quality management approach focused on the CtQ factors and their associated risks. Protocol de-risking is discussed in detail in Sections 5.4 and 6.1.
This risk-based framework, including the activities outlined above, enables CDM to effectively implement risk-based study execution strategies and continuous process improvement to support the delivery of quality data sufficient for reliable and timely decision-making.
This means moving from reactively catching mistakes to proactively identifying problems that may jeopardize the outcome of a study. Overall, the end-to-end management of the operational and scientific risks should be embedded throughout the entire CDM Framework, with strong collaboration with other functions and disciplines involved in the process when necessary.
Organizational structures and functional responsibilities for risk-based activities may vary across companies. This chapter does not prescribe specific ownership of these activities. In practice, responsibilities such as risk identification, de-risking, and ongoing oversight may be performed by or shared with other functions (e.g., central monitoring, clinical operations), depending on the organization’s operating model.
Accordingly, this chapter emphasizes the principles and activities associated with risk-based approaches rather than their allocation to specific roles, allowing for flexibility in implementation across different organizational contexts.
In the absence of a robust body of knowledge and a comprehensive literature base regarding rb-CDM in clinical trial study execution, this content was gathered from regulations considered as minimum standards as well as feedback and insights from early adopters, regulators, and industry leaders to recommend best practices through a consensus-based methodology. As rb-CDM matures, new/revised regulations and guidances emerge, and technology evolves, we anticipate that the body of knowledge on this topic will blossom and lead to further evolution of this Good Clinical Data Management Practice (GCDMP) chapter and the overall SCDM Competency framework.4
This GCDMP chapter applies to all types of studies, whether interventional or non-interventional, and to all categories of medicinal products, including drugs, devices, and biological products.
The authors have made efforts to standardize terminology throughout the document while preserving the original language of cited regulations. When directly quoting regulatory documents, the original regulation’s terminology has been retained to ensure accurate attribution and to preserve the integrity of this chapter.
Below are some terminology-related conventions used in this paper:
In general, the terms “study” and “trial” are used interchangeably, with no intent to distinguish between them. However, preference has been given to the term “study,” as it broadly encompasses all types of research, whereas “trial” is more commonly associated with interventional studies.
For similar reasons, the term “participant” has been favored over “patient.”
To avoid repetition, the term participant “protection” has been used to encompass participant “rights, safety, and well-being.”
To align with International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use (ICH) E6 (R3),1 the term “Service Provider” has been favored over “Vendor.”
A summary of abbreviations used throughout the document is provided in Section 10 to support consistent interpretation.
3) Scope
3.1) In Scope
This GCDMP chapter provides guidance on the principles, standards, and practical applications of rb-CDM across the lifecycle of clinical studies. It is intended for sponsors, Clinical Research Organizations (CROs), service providers, regulators, and other stakeholders involved in the design, conduct, oversight, and reporting of clinical research. The chapter applies to all types of clinical studies, including interventional and non-interventional research as well as all categories of medicinal products such as drugs, devices, and biological products. The scope encompasses both organizational and study-level practices, emphasizing the integration of QbD, RBQM, and fit for purpose strategies to safeguard participant protection and ensure reliable, high-quality data.
This guidance defines the minimum expectations for applying risk-based principles to CDM, while recognizing that implementation should be flexible, context-dependent, and proportionate to study-specific risks. It is not intended to prescribe rigid operational procedures but rather encourages adoption of a pragmatic, critical-thinking mindset that prioritizes what matters most to participant rights, safety, and well-being, and to the credibility of study results. As such, this document provides a framework that organizations can adapt and evolve as regulations mature, technology advances, and industry experience with rb-CDM expands.
3.2) Out of Scope
Detailed risk identification methodologies (statistical or non-statistical, technology-based or manual), as well as system-specific lifecycle activities (e.g., selection, validation, and use), are out of scope for this chapter.
Additionally, this chapter does not address broader operational and organizational frameworks, including standard operating procedure (SOP) lifecycle management, change management, and service provider management. These topics may be covered in dedicated SCDM publications (e.g., GCDMP chapters, topic briefs) and should be consulted as appropriate. This chapter should therefore be read in conjunction with other GCDMP chapters, particularly those related to data quality, to ensure a comprehensive understanding of integrated quality management.
4) Minimum Standards
In GCDMP chapters, regulations are considered minimum standards to be met and followed. For this chapter on rb-CDM, important applicable passages have been drawn from the following six regulatory guidances, listed chronologically:
August 2013, US Food and Drug Administration (FDA) guidance on “A Risk-Based Approach to Monitoring”5
March 2018, UK Medicines and Healthcare products Regulatory Agency (MHRA) “GXP” Data Integrity Guidance and Definitions6
October 2021, ICH E8 (R1), General Considerations for Clinical Trials2
January 2022, MHRA Oversight and monitoring activities7
April 2023, FDA, A Risk-Based Approach to Monitoring of Clinical Investigations Questions and Answers8
January 2025, ICH E6 (R3), Guideline for Good Clinical Practice1
To ease the reading of this GCDMP chapter, those passages have been included in Appendix A and organized around six core concepts introduced in this section.
4.1) Risk-based approaches
Risk-based approaches are practices that proportionally align focus and efforts on what matters most to prevent and manage risks to 1) participant’s rights, safety, and well-being; 2) critical data, processes, and systems; and 3) the reliability of study results considering the likelihood of risk occurrence, their severity and potential detectability.
In CDM, a risk-based approach may focus monitoring and validation on data and processes that directly affect reliability of study results (e.g., primary efficacy and safety endpoints and other critical efficacy variables) or participant’s protection (e.g., eligibility criteria confirmation data, investigational product (IP) dosing data as recorded in the electronic data capture (EDC) system), while applying a risk-adapted oversight to data not associated with CtQ Factors.
4.2) Fit for purpose considerations
Fit for purpose clinical study quality means that the study should be of sufficient quality to meet its objectives, provide confidence in the study’s results, and support sound decision-making, all while adequately protecting the participants involved. As such, regulations, and especially ICH E6 (R3),1 emphasize risk-proportionate strategies that support quality throughout the study.
4.3) Data Integrity and Quality
The authors acknowledge that there is no industry-wide or regulatory-aligned definition that clearly distinguishes data quality from data integrity, and that these concepts are inherently overlapping. Consistent with prior SCDM publications, this section does not aim to establish prescriptive or universally accepted definitions. Instead, it provides an operational perspective to support the evolving role of CDM toward clinical data science (CDS), where emphasis is placed on risk-based approaches and in ensuring the reliability of trial results, rather than solely focusing on managing data appropriately.
As stated in SCDM’s 2022 “The evolution of Clinical Data Management into Clinical Data Science”, “Clinical data management is primarily focused on data flows and data integrity (i.e., data is managed the right way). Clinical Data Science broadens this focus by adding the data risk, data meaning and value dimensions for achieving data quality (i.e., data is credible and reliable).”9
Understanding the difference between data integrity and data quality is critical for CDM professionals, as it is at the core of the evolution of CDM into CDS.
The introduction to MHRA’s guidance on GxP Data Integrity6 states that data integrity is not data quality since “the controls required for integrity do not necessarily guarantee the quality of the data generated.”6
First, “Data integrity is the degree to which data are complete, consistent, accurate, trustworthy, reliable and that these characteristics of the data are maintained throughout the data life cycle. The data should be collected and maintained in a secure manner, so that they are attributable, legible, contemporaneously recorded, original (or a true copy) and accurate.”6 This MHRA definition is consistent with the ALCOA (Attributable, Legible, Contemporaneous, Original and Accurate) principles.
Note the term “certified copy” in ICH E6 (R3)1 aligns with the MHRA’s use of “true copy,” since both are defined as an accurate, verified reproduction of the original record.
Data quality is “the assurance that data produced is exactly what was intended to be produced and fit for its intended purpose. This incorporates ALCOA.”6
Data quality is a broader and more comprehensive goal—it is “fit for purpose.” In the context of clinical studies, data should be fit for purpose and adhere to the definition in Section 4.2.
At its core, “fit for purpose” data quality recognizes that no study is conducted perfectly. Striving for perfection may not be realistic or necessary; what truly matters is avoiding errors that could meaningfully affect participant protection or compromise the reliability of study results. Achieving fit for purpose quality therefore requires a pragmatic, risk-proportionate approach, ensuring that efforts are focused on study attributes that are critical to the protection of participants and the reliability of study results.
It is helpful to consider that the quality of clinical data during study execution is dependent on two distinct steps:
The first step is the actual generation of the clinical data, which depends on all of the people, processes, materials and/or equipment involved in conducting the relevant patient assessments or measurements.
The second stage involves the reliable management of the data after its generation, including its proper recording (using ALCOA principles), transcription, transmission, storage, review and reporting.
Data integrity—which has traditionally been the primary focus of data management activities—covers this second stage but generally not the first. Monitoring the reliability of the first stage was traditionally considered outside of the scope of CDM.
In conclusion, we could conceptually differentiate data quality vs. data integrity as follows:
Data integrity means that the data are managed the right way.
Data quality means that the data are reliable and fit for purpose for decision making.
4.4) Quality by Design (QbD)
ICH E8 (R1)2 states that “QbD in clinical research sets out to ensure that the quality of a study is driven proactively by designing quality into the study protocol and processes.”2 This involves the use of a prospective, cross-functional (e.g., clinical operations, quality, data management, biostatistics) and multidisciplinary (i.e., across different areas of expertise such as sponsors, CROs, technology providers, clinical investigators, patients, patient advocates, and healthcare providers) approach to promote the quality of protocol and process design (at study, program and overall organizational level) in a manner proportionate to the risks involved, with clear documentation and communication on how this will be achieved.
4.5) Critical to Quality Factors (incl. Critical Data and Processes)
The ICH E8 guidance states that “The quality by design approach to clinical research involves focusing on CtQ factors”2 and defines them as “attributes of a study whose integrity is fundamental to the protection of study participants, the reliability and interpretability of the study results, and the decisions made based on the study results.”2 In addition, CtQ factors should be considered holistically, so that dependencies among them can be identified and managed appropriately. Understanding these interdependencies is essential for designing a robust, efficient quality management approach aligned with QbD principles. Furthermore, the quality management approach should be proactively integrated into the operational plans ensuring that quality is not only conceptualized but also embedded in the design, conduct, oversight and monitoring of the clinical study.
Refer to Table 1 for an example of CtQ factors representing critical data and processes to consider (see section 4.6).
Table 1: CTTI Critical to Quality Categories and Factors.1
| CtQ Categories | CtQ factors |
| Protocol Design | Eligibility Criteria Randomization Masking Types of Controls Data Quantity Endpoints Procedures Supporting Study Endpoints and Data Integrity Investigational Product (IP) Handling and Administration |
| Feasibility | Study and Site Feasibility Accrual (i.e., Enrollment Strategy) |
| Patient Safety | Informed Consent Withdrawal Criteria and Trial Participant Retention Signal Detection Safety Reporting Data Monitoring Committee (DMC)/Stopping Rules (if applicable) |
| Study Conduct | Training Data Recording and Reporting Data Monitoring and Management Statistical Analysis |
| Study Reporting | Dissemination of Study Results |
| Third-party Engagement | Delegation of Sponsor Responsibilities and Collaborations |
Note: The CTTI introduced the CtQ factors in 2015 and organized them around the six major categories below. Those can be used as a guide to define the study specific CtQ Factors.10
4.6) Risk Management
Risk management is a systematic approach to managing risks. It includes the identification, assessment, monitoring, mitigations, controls, communications, and evaluation of risks throughout the lifecycle of a clinical study (Refer to Section 5.3 for detailed considerations regarding Risk management).
5) Best Practices
With these guidances in mind, we recommend the following best practices for applying a risk-based approach within CDM.
Manage risk through a multidisciplinary approach supported by management. [VI]
Embed quality at the design stage through critical thinking. [VI]
Engage all external parties in risk identification and mitigation. [VI]
Keep risk control proportionate, with risk-surveillance strategies defined prospectively, including relevant KRI triggers and pre-specified acceptable ranges such as QTLs. [VI]
Focus data integrity assessments on CtQ factors, critical risks, and critical processes. [VI]
Review and adapt risk assessments dynamically throughout study conduct. [VI]
Communicate and report risks, quality issues, and remedial actions to stakeholders. [VI]
Conduct a final risk assessment at close-out and feed lessons learned into corrective actions and preventive actions (CAPAs) and future studies. [VI]
5.1) Summary of Best Practices
The best practices detailed throughout this section can be summarized as follows. They follow the rb-CDM life cycle, from organizational foundations through study design, conduct, and close-out. Each practice is elaborated in the subsections indicated in Table 2.
Table 2: Good Clinical Data Management Practices (GCDMP) Evidence Grading Criteria.
| Evidence Level | Evidence Grading Criteria |
| I | Large, controlled experiments; meta, or pooled analysis of controlled experiments; regulations or regulatory guidance |
| II | Small controlled experiments with unclear results |
| III | Reviews or syntheses of the empirical literature |
| IV | Observational studies with a comparison group |
| V | Observational studies, including demonstration projects and case studies with no control |
| VI | Consensus of the writing group, including GCDMP Editorial Board and public comment process |
| VII | Opinion papers |
Each best practice above is followed by an evidence level grade. Evidence supporting assertions or otherwise informing practice recommendations in GCDMP chapters is graded according to the strength of the evidence. The GCDMP has adopted the grading criteria in the Evidence Classification Table. The strength, also referred to as level of evidence, is based on the amount of evidence – such as the number of studies supporting a result, as well as the extent to which the study designs support causal inference
5.2) Overall rb-CDM Framework considerations
It is essential to recognize that quality in clinical studies is multi-dimensional, bringing together QbD and RBQM, which complement each other to ensure fit for purpose study quality. Within this broader, cross-functional and multidisciplinary quality framework, rb-CDM serves as a key component that contributes to both QbD and RBQM.
A critical concept underpinning this quality framework is fit for purpose clinical study quality, as defined in Sections 4.2 and 4.3: rather than striving for perfection in every aspect of a study, efforts should be focused on the study attributes that are critical to the protection of participants and the reliability of study results.
In essence, QbD establishes the foundation for clinical study quality by proactively identifying and embedding quality into the study from the outset, during the study design and planning stage, using sound scientific understanding and proactive risk management. This approach enables sponsors to “de-risk” the protocol upfront by identifying CtQ factors and potential risks to those factors, ensuring that the study design is optimized to prevent foreseeable issues.
RBQM builds on this foundation by applying risk assessments and mitigation strategies throughout study conduct, ensuring that risks are continuously evaluated and that risk controls remain appropriate and are adapted dynamically as the study progresses.
Quality should be embedded from the study design stage through critical thinking. This requires anticipating issues before they occur by evaluating trial activities from multiple perspectives—scientific, operational, and regulatory.
Critical thinking enables proactive, risk-based quality management by:
Identifying vulnerabilities — determining which data or processes are most susceptible to errors or deviations and understanding the potential consequences.
Anticipating proactively — evaluating study activities holistically to foresee and address risks early in the trial lifecycle.
Prioritizing risks — assessing which risks could most significantly impact trial outcomes or participant safety.
Targeting mitigation — deciding where enhanced procedures, monitoring, or validation are needed to prevent or control high-priority risks.
Adapting in real time — continuously monitoring trial data, systems, and processes, and being flexible when new risks emerge.
To support this mindset, flexible and targeted quality oversight approaches should be implemented through predefined, risk-based strategies and continuously refined throughout the study.
This quality framework operates at both an organizational and a study level. At an organization level, “the sponsor should implement an appropriate system to manage quality throughout all stages of the trial process.”1 At a clinical study level, it includes “the design and implementation of efficient clinical trial protocols, including tools and procedures for trial conduct (including for data collection and management), in order to ensure the protection of participants’ rights, safety and well-being and the reliability of trial results.”1 As illustrated in rb-CDM Framework in figure 1 below, these four dimensions—Quality by Design and RBQM, applied across both the organization and study levels—must be considered together to establish a robust rb-CDM framework that aligns with risk-based quality management practices.
This risk-based quality framework moves beyond tools and checklists to foster prospective planning, critical thinking, and flexible, proactive, study-specific strategies in study design and conduct. It explicitly discourages one-size-fits-all approaches, advocating instead for tailored, risk-proportionate strategies that support quality throughout the study.2
The QbD process should be led by a cross-functional, multidisciplinary team—for example, representatives from clinical operations, data management, biostatistics, medical, regulatory affairs, pharmacovigilance, digital data technology (or equivalent), drug supplies, and quality assurance—with each discipline bringing a unique perspective to identify CtQ factors and potential risks. These teams collaboratively define quality objectives, risk mitigation strategies, QTLs, and KRIs. Engaging external stakeholders (e.g., patients, patient advocacy groups, healthcare providers, and clinical investigators) is equally vital to ensuring that clinical studies are scientifically valid, operationally feasible, ethically sound, and patient-centered. Organizational adoption of this collaborative model is detailed in Section 5.3.
In summary, the overall quality framework applies to all drug development stakeholders involved and aims to ensure participant protection and the reliability of study results throughout the clinical study lifecycle (i.e., starting from protocol design and extending through study conduct, evaluation, and reporting phases). Important risks that cannot be eliminated through study design may be mitigated and managed through the study’s operational plans, processes, and procedures. These plans, processes, and procedures should be implemented in a way that is proportionate to the risks to study participants and the importance of the data collected.
5.3) Organizational considerations
As discussed, Risk Management (including QbD and RBQM) and its rb-CDM component should ideally be recognized as a multidisciplinary and cross-functional responsibility supported by a leadership-driven culture in which critical thinking and open, proactive dialogue about what is critical to quality are valued and rewarded2 (see also Section 6.3). It is therefore recommended to follow a systematic, cross-functional approach to define and embed the right culture, policies, processes and training in order to adopt new ways of working, build new skills, prevent siloed RBQM delivery, and build trust in new tools and techniques.
Below are some of the elements that could be considered when creating an RBQM framework, with a particular emphasis on rb-CDM:
Aligning on core principles – Leadership and stakeholders should align on definitions of core principles such as “risk proportionate ways of working,” “errors that matter,” and the definition of “clean data.” Aligning on these principles ensures organizations are thinking about this in the same way, growing their capabilities in a complementary way, and then supporting implementation.
Building a preventative rather than corrective mindset – instilling a “get it right first time” data quality mindset and a focus on improving critical processes at the site, at all service providers (incl. central laboratories, central imaging, eCOA Providers, CROs, etc.) and within the study team. This could include a systematic and regular review of EDC forms and electronic Patient Reported Outcome (ePRO) instruments with sites and study participants to improve data collection and data flow, or it could include a retrospective analysis of recent studies to understand the root causes of historical protocol deviations that could be avoided through protocol design or more tailored protocol training at the site. Moving QbD and development of the risk assessment upstream into protocol development can also foster a more proactive and preventative mindset.
Developing skillsets, training, and change management – new skills may be required across all the functional groups to reinforce the RBQM framework. This should be a combination of analytical skills, such as critical thinking and root cause analysis techniques; and technical knowledge, such as regulatory guidances (i.e., minimum requirements); and the development of comprehensive corrective and preventative action plans. Formal training should be supplemented by a comprehensive mentoring program so that key concepts and rb-CDM principles can be applied in a consistent yet flexible way, and reinforced through a variety of communication and shared-learning techniques including lessons learned and the sharing of successes. Change management should emphasize the risks of one-size-fits-all approaches and over-reliance on tools and checklists.2 Continuous training, competency assessments, and change management programs help sustain rb-CDM maturity over time by reinforcing critical-thinking and risk-management skills across all rb-CDM stakeholders.
-
Embedding processes, SOPs, and roles – processes should be re-assessed to ensure teams are applying QbD from the earliest stage of protocol development onwards and that appropriate focus is placed on RBQM and rb-CDM activities during the study. Process flows, SOPs, job descriptions and training curriculums should all align to the new ways of working and explicitly state expectations for RBQM and rb-CDM, as guided by the core principles above, to ensure RBQM does not become a tick box exercise adding unnecessary burden to study teams. Considerations include but are not limited to:
- Institutionalizing a continuous improvement cycle that incorporates lessons learned and CAPA insights into standard libraries, SOPs, and training materials, thereby progressively enhancing rb-CDM maturity.
- Ensuring consistent execution and oversight: organizations should establish formal governance structures with clear accountability for RBQM and rb-CDM activities, including defined roles for decision-making, escalation, and continuous improvement.
- Supporting reliable data collection, traceability, and regulatory compliance: The rb-CDM framework may leverage appropriate standardized data formats and interoperable systems (e.g., CDISC, HL7, FHIR), enabling consistent data exchange and integration across platforms and stakeholders.
- Establishing standard and compound-specific libraries (e.g., of CtQ factors, KRIs, QTLs, and risk assessments) that can be reused across similar studies with buy-in from stakeholders.
- Organizations should also consider a technology enablement strategy to support RBQM and rb-CDM, including the identification of solutions (internally or through third party services) for activities such as centralized monitoring, data reviews, and real-time risk detection.
Note: Consider leveraging established industry references such as:
5.4) Study Level considerations
Figure 2 highlights the core elements, organized across eight steps, to implement a study level rb-CDM life cycle framework.
It illustrates the iterative process flow of the rb-CDM life cycle, beginning with Quality by Design (QbD) and progressing through risk management steps mentioned in ICH E6 (R3).1 Each element in the figure corresponds to process steps described in Section 6.1 below, providing a visual anchor for understanding the integration of risk-based approaches at the study level.
First and foremost, even though this GCDMP chapter focuses on rb-CDM, it is essential that all risk management related activities incorporate input from the cross-functional and multidisciplinary team described in Section 5.2, representing all critical disciplines and functions involved in the study.
This collaborative approach should be applied regardless of the operational model—whether in-house or outsourced—ensuring comprehensive expertise and alignment throughout the rb-CDM process.
It is essential to consider all external parties (e.g., CROs, technology and service providers) as risk identification should “be considered across … service provider activities)”1 and risk mitigation “activities may be incorporated, for example, in … agreements between parties defining roles and responsibilities.”1
When engaging with external parties in risk management activities, the following elements should be considered:
Establishing clear roles and responsibilities (e.g., documented using a Responsible, Accountable, Consulted and Informed (RACI) matrix)
Aligning SOPs and work instructions
Leveraging technology to reduce burden; ensure prompt oversight and limit risk of transcription error. Service providers may as an example supply tools for centralized monitoring, data visualizations, system to system integration.
Ensuring the integrity of the data chain of custody
Defining a governance and communication framework to track service provider performance based on KPIs and key metrics
Training and continuous improvement on rb-CDM principles and tools
At study level, performing a cross-functional risk assessment and sharing lessons learned
The rb-CDM Life Cycle focuses on core data-related components within the QbD and RBQM framework. Aligned with the ICH E6 (R3),1 it begins with QbD by identifying CtQ factors and associated risks, followed by the six risk management steps described in its section 3.10.1, “Risk Management.”
It is important to note that while the rb-CDM life cycle follows a structured framework, its implementation must be customized to the specific needs of each study. Factors such as therapeutic area, study design complexity, data sources, and participant population should inform the prioritization and execution of risk management activities.
This approach ensures that data quality is proactively designed and continuously monitored throughout the clinical study lifecycle, supporting regulatory compliance and improving patient protection and data reliability.
Table 3 relates the eight lifecycle steps shown in Figure 2 to the six risk-management steps of ICH E6(R3) section 3.10.1 and to the Section 6 stage at which each is implemented. It provides a single reference point that links the QbD/RBQM lifecycle, the regulatory risk-management process, and this document’s stage-based guidance.
Table 3: Best practices and corresponding chapter sections.
| # | Best Practice | Life Cycle Phase | Elaborated In | Regulatory Basis (App. A) |
| 1 | Multidisciplinary risk management supported by management | Foundational | 5.2, 5.3 | A.6 |
| 2 | Quality embedded at the design stage through critical thinking | Set-up | 5.2 (QbD), 6.1 | A.1, A.4 |
| 3 | External parties engaged in risk identification and mitigation | Foundational/Set-up | 5.2, 5.4, 6.1 | A.6 |
| 4 | Proportionate risk control with prospectively defined surveillance strategies and applicable thresholds | Set-up | 5.4 (risk control), 6.1 | A.5, A.6 |
| 5 | Data integrity assessments of CtQ factors, critical risks, and critical processes | Execution | 4.3, 5.4, 6.1 | A.3, A.5 |
| 6 | Dynamic review and adaptation of risk assessments during study conduct | Execution | 5.4 (risk review), 6.1 | A.6 |
| 7 | Risk communication and reporting to stakeholders and in the clinical study report | Execution/Close-out | 5.4 (risk communication and reporting) | A.6 |
| 8 | Final risk assessment at close-out, with lessons learned feeding CAPAs and future studies | Close-out | 6.1, 6.3 | A.6 |
This crosswalk represents an illustrative mapping of the rb-CDM lifecycle to the ICH E6(R3) risk-management framework and should not be interpreted as a regulatory classification of the individual lifecycle steps.
The considerations below combine regulatory requirements with recommended rb-CDM best practices. Unless explicitly attributed to a regulatory source, additional operational practices should be interpreted as recommendations rather than direct regulatory requirements.
Each of these steps is described in detail below:
1. Risk Identification: Identify risks that may have a meaningful impact on CtQ factors prior to study initiation and throughout study conduct. “Risks should be considered across the critical processes and systems,” that matter most to the overall reliability of trial results and participant safety, “including computerized systems used in the clinical trial (e.g., trial design, participant selection, informed consent process, randomization, blinding, investigational product administration, data handling and service provider activities).”1
Identifying CtQ factors (i.e., critical data, processes, and systems) considering the study design and objectives
Identifying potential risks to the integrity and quality of the critical data
Identifying risks to the data that could jeopardize the evaluation and management of participant’s rights, safety and well-being
Identifying risks to the data that could jeopardize the reliability of the study results
-
TransCelerate suggests considering the following elements when assessing risks13
- Trial-level risk management plan (including controls)
- Number of participants
- Number of sites
- Trial Duration—adequate duration of the trial is a consideration to implementing the QTL process and implementing any remedial actions as a part of the QTL process
- Recruitment rate
- Trial Design (e.g., dose escalating cohorts because of the small number of participants in each cohort)
- Trial population
Although this list may not represent a complete set of considerations, it provides a strong starting point. Organizations should also evaluate additional factors that are specific to the study protocol or informed by prior experience. These may include:
Study phase
Safety information from the Investigator Brochure
Study type (e.g., interventional or real-world)
Risk of unintentional unblinding
Data source heterogeneity, such as EHRs, registries, or decentralized trial components
Extent and experience of service providers
Study specific privacy and cybersecurity risks
2. Risk Evaluation: Assess the identified risks—and existing controls in place—to mitigate the risk considering its likelihood of occurrence, its detectability and its impact.
Evaluate risks to critical data, processes, and systems that are the most vulnerable to errors or deviations to understand the potential consequences of those risks.
Evaluate which risks could most significantly impact the study outcomes and participant’s protection.
Document the risk evaluation in the risk assessment plan and proactive mitigations in relevant functional plans including role-based review and monitoring strategies.
The risk evaluation should consider:
The likelihood of harm/hazard occurring
The extent to which such harm/hazard would be detectable
The impact of such harm/hazard on study participant protections and the reliability of study results.
3. Risk Control: Establish robust risk-proportionate approaches to monitoring, validation, and management of risks to the CtQ factors (i.e., critical data, processes, and systems) while remaining flexible and adaptive to emerging risks. Those risk-proportionate controls should be fit for purpose—reflecting the importance of the data—in ensuring participant’s protection and the reliability of study results.
The distinction between critical and non-critical data is not strictly binary. Organizations may implement a tiered classification framework, assigning varying levels of criticality based on the importance of the data within the trial; that is the extent to which errors could impact on participant’s protection, the reliability of study results, and decision-making. The rb-CDM process shall be adjusted accordingly considering risk proportionality to each defined tier.
The most efficient risk control is to prevent it, if possible, by proactively de-risking the study, with QbD in mind, during protocol development.
This entails incorporating feedback from study personnel, healthcare providers, participants, and participant advocates in the study design to reduce unnecessary protocol complexity, for example by eliminating the collection of non-essential data, by simplifying and/or reducing visit schedules and study procedures, and by leveraging technology for data collection.
Build pro-active measures to mitigate remaining risks that could not have been fully de-risked (i.e., risks that could not be fully prevented). This includes the ability to monitor risks and prevent and/or limit their occurrences such as ensuring appropriate validation, access controls, audit trails and trainings for critical systems.
It also means building risk-based mitigation strategies into study related plans. While study plans span multiple functions, Clinical Data Managers/Scientists may specifically contribute to the data management plan (DMP), the centralized monitoring plan (CMP) and/or the integrated quality risk management plan (IQRMP) as appropriate in their organization. This may include:
Incorporating automated validations into the data collection systems such as edit checks in EDC and patient alerts for missing data in electronic Clinical Outcome Assessment (eCOA)
Defining KRIs at site and country level as well as “pre-specified acceptable ranges (e.g., QTL at the trial level).”1
Set up systems to perform signal detection and analysis
Implement cross-functional mitigation strategies to manage risks. This includes leveraging clinical data and metadata to identify emerging risks during study conduct through the use of KRIs, QTLs, and other data-driven approaches, such as data analytics and automated data validations, to flag inconsistencies and missing data patterns.
4. Risk Communication: Communicate risk-related information among all parties involved in the study so that the risks that matter and the controls in place are commonly understood and acted upon.
The anticipated CtQ risks identified, the outcome of their assessment as well as mitigating strategies resulting from the prior three steps (identification, evaluation, and control), should be communicated to and agreed with all impacted stakeholders, ideally prior to initiating participant enrollment.
When monitoring risks, any identified occurrences should be documented and communicated to the appropriate stakeholders (e.g., site staff, site monitor, medical monitor). Relevant context should be provided to guide corrective and preventive actions, such as whether the risks are emerging or anticipated, isolated or widespread, any known or potential root causes, and areas that may require further investigation.
Treat communication as a two-way exchange rather than one-directional reporting. Actively seek input from sites, service providers, and other stakeholders so that concerns and emerging risk signals surface early.
Agree the communication channels and forums up front (e.g., cross-functional risk reviews and escalation paths) so that risk information flows consistently among internal and external stakeholders throughout the study.
Maintain a traceable record of risk-communication activities and decisions to support transparency and accountability; these records also feed the risk reporting described in Step 6.
5. Risk Review: Risk review is the ongoing, cross-functional re-evaluation of the CDM/CDS-identified risks and their CtQ factors—confirming that existing controls remain effective and detecting new or evolving risks as data accumulate over the course of the study.
It should be also noted that risk assessment and management is a continuous and iterative process. While risk identification and mitigation are initiated at the time of protocol development, the steps above should also be repeated at regular intervals, ideally pre-defined within the process and any time a protocol is amended, or systemic issues are identified.
The study team should learn by “periodically reviewing risk control measures to ascertain whether the implemented quality management activities remain effective and relevant, taking into account emerging knowledge and experience. Additional risk control measures may be implemented as needed.”1
Hold regular cross-functional risk reviews in which data management, data science, clinical operations, biostatistics, and relevant service providers reassess the identified risks and the effectiveness of their controls.
Analyze accumulating data trends and KRI/QTL signals to detect emerging or previously unrecognized CtQ risks before they escalate.
Feed findings from centralized and statistical monitoring, data quality checks, audits, and inspections back into the risk assessment so that controls are refined throughout the study.
-
Adapt to prevent further re-occurrence i.e.,
- Updating the study plans to include measures preventing systematic emerging risks to re-occur
- Adapt systems and processes accordingly
6. Risk Reporting: Risk reporting documents and communicates the rb-CDM risk-management approach and its outcomes—including important quality issues and any QTL breaches—to the study team, functional and sponsor governance, and, through the clinical study report (CSR), health authorities.
Important quality issues impacting participant protection and/or the reliability of study results should be summarized and reported “(including instances in which pre-defined acceptable ranges are exceeded)”1 with the corresponding remedial actions taken. Those should be documented in the clinical study report.1
Report the status and effectiveness of the data-related risk controls and mitigations, including relevant KRIs and QTLs and the supporting data-quality metrics, so recipients can judge whether risks to the CtQ data stayed adequately controlled.
Summarize audit and inspection findings relevant to data integrity and rb-CDM risk management, together with how they were addressed.
Report the status and outcomes of data-related corrective and preventive actions (CAPAs), confirming that they were completed and that preventive measures are in place to avoid recurrence.
6) rb-CDM Process Implementation Considerations During Different Stages of Protocol Development
The adoption of rb-CDM approaches has a deep impact on our traditional CDM ways of working, as shown in the process flows in this section. Throughout this section, examples of process flows have been provided in which risk-based process steps (in green) have been added to the traditional CDM steps (in blue) to illustrate the end-to-end nature of risk-based approaches.
6.1) Risk Based Considerations During Study Design and Study Planning
The Study Design and Planning steps shown in Figure 3 have also been summarized as a checklist in Appendix B.
Risk Identification, Operational Feasibility and Risk Assessment
Risk management is a core component of QbD and RBQM, encompassing the proactive identification, assessment, and control of risks throughout the clinical study lifecycle. It begins with risk prevention, by identifying threats prior to the first patient being enrolled into the study, which have the potential of leading to errors that could negatively impact patient protection, the credibility and reliability of the study results. As such, a sound scientific protocol, operationally feasible and without unnecessary burden to sites and patients, is the foundation of study execution.
First and foremost, it is critical to engage the appropriate cross-functional, multi-disciplinary, internal and external experts to manage all risks through their entire life cycle.
Engage Stakeholders and Align on Protocol Design
Actively identify and engage with internal and external, multidisciplinary, cross-functional stakeholders (e.g., Clinical, Biostatistics, Safety) during protocol development to ensure alignment on protocol design.
Evaluate data and data management risks related to the entire data flow and processing of primary/secondary endpoints and safety data.
Ensure the protocol is operationally feasible and especially that the data flow does not introduce risks to data (e.g., leading to data capture, interpretation, and/or transformation errors).
Identify and Document Critical to Quality (CtQ) Factors
Identify and document Critical to Quality (CtQ) factors prior to protocol finalization (i.e., critical data, systems and processes, including data review strategies).
Table 4: rb-CDM Lifecycle Crosswalk.
| Lifecycle step (Figure 2) | Main Objective | ICH E6(R3) | Implemented in |
| 1. Identify CtQ Factors | QbD | Risk Identification | 6.1 |
| 2. De-risk Study | QbD | Risk Identification + Risk Control (by design) | 6.1 |
| 3. Define Mitigation & Monitoring Strategies (QTLs, KRIs) | RBQM | Risk Evaluation + Risk Control | 6.1–6.2 |
| 4. Implement Mitigation & Monitoring Strategies | RBQM | Risk Control | 6.2 |
| 5. Monitor Risks | RBQM | Risk Review + Risk Communication | 6.2 |
| 6. Correct | Improvement loop | Risk Control (corrective) | 6.2–6.3 |
| 7. Learn | Improvement loop | Risk Review | 6.3 |
| 8. Adapt | Improvement loop | Risk Review | 6.3 |
Note: Risk Communication and Risk Reporting are cross-cutting. Communication runs throughout the lifecycle (the center of Figure 2), while Reporting concentrates at close-out (Section 6.3 and the clinical study report).
Conduct Study Risk Assessment
While many risks would be evaluated and accounted for by the multidisciplinary and cross-functional study team, some risks related to areas such as the 5Vs of the clinical data13 (i.e., Volume, Variety, Velocity, Veracity, and Value), the data flow’s complexity, the extent of service providers involved, and planned technologies used through the data life cycle would be the primary focus of CDM.
-
Perform a study risk assessment of the identified CtQs. There are many risk areas associated with the CtQ factors, including but not limited to the:
- complexity of protocol designs such as umbrella, basket, platform, master and adaptive;
- vulnerability of the patient population (e.g., elderly, pediatric);
- complexity of enrollment procedures (e.g., consent, eligibility, stratification and randomization);
- deviations from standard of care;
- characteristics of the participating countries (e.g., standard of care, customs, dialects);
- planned rate and distribution of enrollment;
- number, profile and experience of the study sites personnel (Incl. Principal Investigator) and countries;
- nature of the protocol-required procedures, with specific emphasis on the burden they may place on patients and sites (e.g., hourly blood draws, long clinic visits);
- organization of the study (e.g., site-centric vs. decentralized) with telemedicine and home nursing;
- planned technologies used to collect data, including when patients bring their own device;
- complexity of the data flow, including variety of the data sources;
- oversight of the capture and modification of the eSource data owned by the sites;
- number and experience of the data and operational Service Providers;
- and any other study execution activities that may lead to data errors that could negatively impact the credibility and reliability of the study results (e.g., central readers, decentralized study procedures).
Protocol De-Risking
Based on the risk assessment, CDM should collaborate with the cross-functional and multidisciplinary study team to assess whether or not the protocol design introduces unnecessary risks due to its complexities and recommend simplification opportunities to reduce those risks (i.e., “de-risk” the protocol).
Define Mitigations and Surveillance Plans for Remaining Risks: Design Data Review and Validation Strategy
Develop a cross-functional, multidisciplinary and CDM-specific data review and validation strategy proportionate to risks.
Define approaches for managing critical vs. non-critical data.
Identify data and associated strategies that will require site monitoring including Source Data Verification (SDV) and Source Data Review (SDR).
Note: While this GCDMP chapter focuses on rb-CDM, the parallels between SDV and data review are important to highlight. Increasingly, CDM organizations are configuring EDC systems to dynamically adjust SDV requirements based on strategies outlined in the study monitoring plan. As a result, CDM subject matter experts (SMEs) should have a clear understanding of the SDV process and its implications for overall data quality.
Important considerations
Some publications, such as the 2014 TransCelerate publication on “Evaluating Source Data Verification as a Quality Control Measure in Clinical Trials”15 and the 2021 SCDM publication on “Risk-based Quality Management in CDM”16 have highlighted that Queries and SDV seem to have a low impact on study data corrections and study results, when evaluated as an overall study measure (e.g., as study level QTL).
Those publications showed that at study level, the industry median of eCRF data correction due to SDV was only 1.1%14 and those from auto-queries varied from 0.9%15 to 1.4%.14
This does not suggest that SDV and query management lack value or should be eliminated from our traditional processes. With 100% SDV, all mistakes can theoretically be corrected. However, when assessing data corrections following SDV, at eCRF forms, sites, countries and Therapeutic Areas (TAs) level, it could highlight variability in the rate of data corrections across those dimensions. As an example, the median of eCRF data change rate due to SDV in Oncology was 2.7%14 and only 0.5% for Pharmacokinetic studies.14
So, while a study may show an overall low data change rate resulting from SDV, some sites may exhibit significantly higher rates—indicating potential issues with source data control. It means that correcting all transcription errors through SDV is not addressing the root cause, but only correcting errors retrospectively.
An efficient risk-adapted SDV approach should prioritize evaluating whether data quality meets predefined targets, rather than simply correcting individual transcription errors. It relies on a meaningful, data-driven sampling strategy to assess quality at both the study and site levels. When deficiencies are identified, proportionate corrective actions should follow to safeguard overall data integrity. Risk-adapted SDV is not designed as a mechanism for fixing isolated transcription errors; rather, it serves to detect and address underlying, systematic issues that require resolution.
Risk-based SDV and query strategies should therefore ensure focus on activities where they are most needed, proportionally to risks, without compromising data quality or patient protection.
As such, a sound approach should therefore apply proportionate SDV based on objective (i.e., data and fact driven) information such as (but not limited to):
-
Pre-defined study and site-specific sampling strategies considering, as examples:
- historical performance of the site
- site experience in clinical research
- complexity of the data collected
- whether study procedures comply with country specific standard of care
-
During the study, study and site level SDV may be adjusted considering, as examples:
- Staff turnover
- SDV findings from initial sampling
- Protocol amendment
Note: Site monitoring frequency should not be dictated by SDV efforts. A risk-based SDV approach does not necessarily mean fewer site monitoring visits, either on-site or remote, but rather a shift in focus to critical risk areas (e.g., SDR, protocol compliance, adherence to procedures). Frequency of monitoring visits may align with the minimum frequency necessary for broader oversight, with triggered monitoring visits based on findings and/or workload (e.g., SDR, drug reconciliation, etc.), beyond SDV alone.
Similarly, data reviews need a well-defined and risk-proportionate strategy that ensures patient protection and the reliability of study results. It should rely on objective and holistic measures, not just on Queries.
As an example, while data review plans should primarily focus on edit checks and the validation of critical data points, it is equally important to have a clearly defined risk-proportionate strategy in place to monitor the quality of non-critical data. This would foster organization alignment and avoid ambiguity within the study team on the expectation for reviewing data (based on its criticality). This can be achieved through methods such as targeted sampling, trend analyses, and statistical techniques to detect atypical patterns or outliers.
Although considered non-critical, recurring or emerging data trends at the form, site, or even country level may indicate underlying issues that could compromise the reliability or credibility of study outcomes. Such signals may warrant further investigation or corrective actions to safeguard the overall integrity of the study.
-
Consider risks to data and data related activities performed by external service and technology providers.
- Evaluate the risk of eliminating non-critical data validation if other safety nets exist (e.g., aggregated data trending or statistical monitoring of non-critical data).
Define Quality Control and Risk Mitigation Plan
-
Establish a quality control and risk mitigation plan, including the definition of targeted data acceptability targets to demonstrate reliability of study results (e.g., rate of missing data for primary end point).
- “Pre-specified acceptable ranges (e.g., Quality Tolerance Limits (QTLs) at study level)”1 to monitor CtQ factors.
- KRIs for ongoing risk management.
- Risk based review of metadata including Audit Trail is expected according to ICH E6 (R3), which states the “Procedures for review of trial-specific data, audit trails and other relevant metadata should be in place.”1 Identify issues that are not otherwise easily detectable as “beyond the reconstruction of the data events, audit trails can also provide critical insights on how the data is being collected”.17
Potential objectives of a risk-based audit trail review include:
investigation of data integrity issue
identification of suspicious justification and/or fraudulent data
identification of alternative source data implemented by sites
unauthorized accesses and data events
oversight on changes to critical data
process improvements based on trends
performance of users.
Example use cases and risk scenarios include:
unauthorized access or lack of access control management
limited system access for specific roles, potentially indicating lack of oversight (e.g., by clinical investigator)
high proportion of data changes, potentially indicating high proportion of transcription errors
high proportion of changes specific to inclusion/exclusion (I/E) criteria data, primary efficacy, key secondary, having the potential to affect the reliability of study results
data not collected per protocol timing or collected at “unanticipated/suspicious” time.
For a more comprehensive list of scenarios, please refer to appendix 3 of the SCDM and eClinical Forum Position paper on Audit Trail Review.17
Specify Reporting and Analytics Requirements
Define specifications for reports, analytics, monitoring metrics, and risk indicators and dashboards to monitor critical data and processes.
Define how and to what extent non-critical data and process will be monitored.
Implement Risk Control Strategies
Ensure all mitigations above are developed and implemented, ideally prior to the first participants entering the study.
Additional Considerations
-
Define milestones-based deliverables and compliance monitoring.
- Specify the extent of data review needed for specific study milestones (i.e., Interim Data Deliverables) such as Interim Analyses (IAs), Data Safety Monitoring Board (DSMB) reports, and Development Safety Update Reports (DSURs).
- Define and implement ongoing data compliance reports to monitor data quality and completeness.
-
Considerations when outsourcing CDM activities:
- Conduct Knowledge Transfer (KT) and secure the service provider collaboration (if applicable).
-
- Ensure KT to newly onboarded CDM Study Experts (included in the context of outsourced studies). This includes but is not limited to:
the QbD principles applied to the study design and conduct;
the list of prioritized data to review and the purpose of the review;
the expected risks to watch that have been identified at study start or emerged during study conduct.
Require the service provider SMEs to perform an independent risk assessment based on the KT and encourage the service provider SMEs to raise questions or share additional insights.
Key Takeaway: These start-up activities position CDM experts as proactive risk managers and data quality stewards from the earliest study stages, aligning with risk-based and quality-focused study execution.
6.2) Risk-Based Study Execution Considerations
During the study execution phase, CDM experts should focus on the following key activities to ensure data quality and manage risks effectively. The Study Execution steps shown in Figure 4 have also been summarized as a checklist in Appendix C.
Monitor, Document and Address Observed Risks
Conduct tailored data review proportional to risk
Perform data reviews commensurate with the level of risk being identified during the study start-up according to the corresponding strategy pre-defined upfront. As an example, non-critical data may be only reviewed through trending analysis or other means.
Prioritize the review of critical data, ensuring it is reviewed promptly and with heightened scrutiny as soon as possible upon data collection.
Monitor KRIs and QTLs. “These pre-specified ranges reflect limits that when exceeded have the potential to impact participant safety or the reliability of trial results. Where deviation beyond these ranges is detected, an evaluation should be performed to determine if there is a possible systemic issue and if action is needed.”1
Identify systematic or process driven data issues including those stemming from study design and study conduct factors such as rate of enrollment, technologies used, etc. The key will be to efficiently and reliably monitor such risks through the holistic review of all clinical and operational data (i.e., finding data patterns and anomalies across studies, countries, sites, patients and eCRF forms).
Monitor trends in non-critical data as identified through the risk assessment (i.e., data not associated with CtQ, data related to tertiary efficacy)
Conduct periodic trend reviews of non-critical data to detect emerging risks or issues.
Document, with appropriate justification, issues that do not present risks to participants’ rights, safety, or well-being, nor to the reliability of study results.
Increase monitoring level of non-critical data similar to critical data when trend analysis or risk indicators suggest increased risk requiring heightened focus.
Review critical data and associated metadata
Ensure the review of critical data includes associated metadata—for example, reviewing audit trail to confirm appropriate and justified data modifications.
Monitor for the possible emergence of any new risks
This includes, but is not limited to:
Disasters and public health emergencies (PHEs) such as “hurricanes, earthquakes, military conflicts, infectious disease outbreaks, or bioterrorist attacks.”18
Database availability delays that could delay study start.
Study timelines and data flow delays, which could negatively impact the availability of study data and/or results for safety reviews, the potential submission, and product approval.
Protocol amendments.
Protocol deviations.
Investigative site attrition.
Monitor critical processes during study execution
Perform ongoing oversight of critical processes, including processes tied to endpoint data collection, protocol amendments, and Independent Review Committee (IRC) activities.
Ensure synergetic oversight across stakeholders
Ensure alignment of sponsor and Service Provider oversight strategies and reporting to support timely assessment of data quality and study progress.
Conduct data integrity assessments.
-
Perform the data-integrity assessments defined in Section 5.4, at a cadence proportionate to the study’s CtQ factors and critical processes.
- Adjust the frequency of these assessments based on the outcome of the monitoring of risk assessment, QTL, and KRIs.
Signal Review
Once a signal is determined to have moved from a risk to an issue, the underlying process or data issue needs to be addressed. Lastly, to close the loop, teams should follow up to make sure the issue has been fully resolved.
Below are some examples of signals that can be found with the potential responses made by teams.
At a site in Puerto Rico, all enrolled patients are Hispanic. While this may appear statistically atypical when compared to other sites outside South America, it is not unexpected given the site’s geographic and demographic context. No immediate action is required; however, the study team should continue monitoring enrollment at the site to assess whether this pattern persists through the end of recruitment.
Many patients at a site have the same respiratory rate: Rather than questioning if the value was correctly entered into the source document, teams should think about how this lack of variability occurred. It is possible, but highly unlikely, that many patients at a site have the same respiratory rate. It is more likely that something was wrong with how the measurements were taken and/or recorded. Thus, the process for collecting and recording the rate should be reviewed. The importance of site compliance and of accurate data collection and recording should be reiterated to the site personnel. Since the existing data is not going to change, any issue with the process in taking measurements should be addressed, fixed, and monitored moving forward.
Patients on an oncology study have either no or a very low number of adverse events (AEs): This is statistically unlikely. The study team should ensure the site personnel understand how to collect AEs, and increase the SDR to check for unreported AEs. The site personnel may need retraining, and the study team should follow up to make sure the situation is resolved. Current data might not change, but the process should be fixed and then tracked for ongoing correctness.
To address the examples above, the CDM SMEs and the study team should dig deep into the data to understand the root cause of the issues. They need to perform detailed root cause analysis (RCA) and data review findings to resolve them. Occasionally, the team will need to go through multiple iterations of RCA and follow-up to fully understand the root cause. This requires a focus on details and strong communication skills as most findings will not result in queries, but rather in addressing systematic process issues and site behaviors.
Adapt by Maintaining Dynamic Risk Management
Proactively solicit feedback from newly onboarded team members to benefit from fresh perspectives or therapeutic area insights.
During execution, apply the Risk Review step from Section 5.4 on an ongoing basis: reassess risks and the effectiveness of controls at defined intervals and whenever signals, audit or inspection findings, or amendments arise, updating the study risk assessment and standard libraries accordingly.
Protocol Amendments or Major Study Updates (e.g., Urgent Safety Measures): Continuous Review and Protocol Amendments
Ensure all above activities are reviewed and updated in case of protocol amendments.
Evaluate all protocol or major study updates (e.g., within Investigator Brochure) for their impact on the risk assessment and mitigations required.
Key Takeaway: These activities empower CDM experts to maintain proactive oversight of data quality, ensuring that critical data and processes are continuously monitored and managed in alignment with study risks.
6.3) Risk-Based Study Close-Out Considerations
At the close-out phase of a clinical study, CDM experts should ensure the following activities are completed to confirm data integrity, regulatory compliance, and risk mitigation. The Study Closure steps shown in Figure 5 have also been summarized as a checklist in Appendix D.
Conduct a Final Risk Evaluation
Perform a comprehensive final review of all occurrences of issues related to CtQ factors that have been observed (anticipated or not in the risk assessment) to confirm that all identified issues associated with those risks have been appropriately addressed.
Ensure any newly identified risks are mitigated, if necessary, prior to database lock.
Conduct a final data quality assessment focused on CtQ factors, QTLs and KRIs, thus evaluating the impact of all observed issues on 1) regulatory and protocol compliance, 2) participant protection, and 3) the reliability of study results.
Assess Remaining Outstanding Issues
Review and close outstanding issues
Resolve new and remaining issues impacting participant’s rights, safety and well-being, the reliability of study results and regulatory and protocol compliance.
Formally close any remaining issues that do not impact patient protection or the reliability of study results with clear justifications and documentation.
Document process completion and compliance
Prepare documentation confirming completion of close-out activities and adherence to the study’s quality plan.
-
Examples of documentation include:
- CtQ assessments
- KRI and QTLs assessments
- Corrective Action and Preventive Action (CAPA) outcomes
- Other relevant compliance records
Adapt Processes and Systems Based on Lessons Learned
-
Perform cross-functional and multidisciplinary lessons learned by assessing the following:
- the outcome of the final data quality evaluation,
- the risks realized in the studies,
- the effectiveness of mitigations,
- related audits and inspections.
Complete the close-out lessons-learned and CAPA activities described in Section 5.1 (Best Practice 8) and Section 5.3, updating SOPs, processes, and systems to prevent recurrence in future studies; CDM subject-matter experts should drive the resulting CAPAs.
Key Takeaway: These close-out activities ensure a high-quality, compliant database lock and clear documentation of risk management outcomes.
6.4) Practical rb-CDM Study examples for CDM Experts
The examples below are illustrative and do not represent an exhaustive identification of CtQ factors, risks, or mitigation strategies for the studies described.
Example #1: Age-Specific Protocols
![]() |
Risk Identification and Risk Assessment Selected CtQ factors may include the accuracy and consistency of the primary PRO endpoint (IBS-SSS), including diary compliance and handling of missing data. Assessments are added by age (a PRO at the age of 8, a second PRO at the age of 9, self-administration of IMP at the age of 12, a daily diary at the age of 13), but no new PROs are introduced beyond a participant’s first visit — so some participants miss PROs they would otherwise reach, leaving data gaps. |
![]() |
De-risk Study Considerations Make the design participant-centric and adaptive — allow a baseline ePRO whenever a participant joins (not only at age 8), add a participant-burden check tied to a drop-out KRI, and review prior protocols for age-related deviations to inform QbD. |
![]() |
Define risk mitigation and Controls Set age-specific KRIs on ePRO-completion compliance alongside a study-wide ePRO-compliance QTL. |
![]() |
Implement risk mitigation and Controls Activate the QTL and KRIs; train site staff on the requirement; create age-appropriate data-entry guidance (an 8- and a 13-year-old differ cognitively); and add edit checks for a prior ePRO, ePRO reminders/prompts, and source-data-review checks. |
![]() |
Monitor risks Watch for links between daily-ePRO inconsistencies and other compliance issues, and review the KRIs and QTL at the defined frequency, tracking trends over time. |
![]() |
Correct, Learn & Adapt Document corrective actions (e.g., friendly ePRO reminders for 8-to-9-year-olds if compliance dips) and run a Plan-Do-Check-Act cycle to sustain data quality as participants age. |
Note: IBS-SSS: Irritable Bowel Syndrome Severity Scoring System.
A pediatric inflammatory bowel disease study introduces PRO assessments at different ages, creating a data-collection risk.
Example #2: Endpoint-Specific Protocols
A Phase II study assessing the reduction in the rate of acute chronic obstructive pulmonary disease (COPD) exacerbations, where data quality depends on how exacerbations are reported.
![]() |
CtQ Identification and Risk Assessment Selected CtQ factors may include the accurate, consistent, and timely reporting of acute COPD exacerbations (investigator severity grading; patient symptom reporting via the EXACT eDiary and the CAT) plus upfront investigator training. Key risks: “acute worsening” lacks measurable thresholds (diagnostic variability), and the > =14-day rule between events can fragment a single ongoing episode. |
![]() |
De-risk Study Considerations Simplify endpoint definitions and add technical controls — define worsening concretely (e.g., a > =2-point CAT increase within 48 hours), require real-time reporting, and count a new event only after symptoms return to baseline and remain stable for > =7 days. |
![]() |
Define risk mitigation and Controls Design a KRI that calculates the rate of acute COPD exacerbations per participant-visit at each site to detect under- or over-reporting across sites and countries. |
![]() |
Implement risk mitigation and Controls Program the KRI and data-quality assessment; assign the medical manager as primary reviewer; set triggers (low rates prompt eCRF-completeness checks, high rates prompt safety assessment); and review and refine thresholds throughout the study. |
![]() |
Monitor risks Site A reported 0 exacerbations versus a study average of 0.64 per patient, across ~10 participants over three years. A cross-functional review (Clinical Data Management, Medical Monitoring, and Project Management) examined four risk categories and identified two root causes:
|
![]() |
Correct, Learn and Adapt Retrospectively document all missed cases from source data and eDiaries, and retrain the site on precise exacerbation identification, real-time reporting, and workflow optimization; reporting compliance improved and was sustained. Refresh critical-process training regularly (not only at start-up), identify risks at protocol design to reduce complexity and site/participant burden, and make regular training standard practice as a preventive action. |
-
Note: CAT: COPT Assessment Test.
6.5) Additional considerations
First and foremost, we need to clearly understand what adopting rb-CDM approaches means.
It evolves around adopting rb-CDM means applying the QbD and RBQM framework of Section 5 — embedding quality at design, focusing effort proportionately on what is critical, and running the six-step risk-management cycle (Section 5.4) within the cross-functional, critical-thinking culture described in Sections 5.2–5.3.
It does not mean:
Taking risk nor promoting risk.
Asking other functions to increase their data oversight to perform activities CDM is no longer planning to perform (or not performing as historically performed).
7) SOP Considerations
The relevant SOP may vary from company to company. There might be an overarching SOP and then associated job aids or work instructions, or it may spread across various SOPs. However, the following areas should be covered by process document(s):
1. Risk Assessment, Categorization and Prevention SOP(s)
Purpose: Define a structured approach to identify, assess, and mitigate data-related risks.
Key Elements:
Identification and categorization of data-related risks at the protocol and system level
Identification and documentation of CtQ factors
Definition of mitigations and risk-surveillance strategies
2. Data Management Plan (DMP) Development SOP
Purpose: Ensure the DMP reflects risk-based data strategies.
Key Elements:
Integration of risk-based data strategies into the DMP
Mapping critical data flows with associated system and data risks
Inclusion of risk-informed roles, responsibilities, and data review strategies
References to KRIs, QTLs, and mitigation procedures
3. Risk-Based Data Review and Validation SOP(s)
Purpose: Define risk-informed approaches to data validation and review.
Key Elements:
Risk-prioritized review of critical data elements and processes
Query strategy aligned with risk levels and CtQ factors
Metadata and operational data review processes
Use of centralized monitoring techniques and technologies
Review of trends, outliers, KRIs, and QTLs
Action thresholds and trigger-based follow-up procedures
4. Signal Detection and Escalation SOP
Purpose: Standardize how potential data quality issues or anomalies are detected and acted upon.
Key Elements:
Proactive signal detection via statistical and visual analytics
Decision-tree for determining whether findings are isolated, systemic, or critical
Escalation pathways to clinical, quality, or regulatory teams
Time-bound escalation handling and documentation procedures
5. Risk Management and CAPA SOP
Purpose: Govern how emerging risks and deviations are investigated and managed.
Key Elements:
Ongoing review and update of the risk assessment, risk monitoring, and mitigation strategies
Identification of systematic or process driven data related issues
Documentation and resolution of data-related risk signals
Root cause analysis and preventive action
6. Protocol Deviation and Data Anomaly Handling SOP
Purpose: Clarify classification, triage, and resolution of unexpected data issues.
Key Elements:
Differentiating between protocol deviations, data inconsistencies, and fraud
Triage framework based on patient’s protection and reliability of trial results
Documentation and follow-up of confirmed anomalies
7. Oversight and Governance of Risk-Based Data Management SOP
Purpose: Establish governance and ownership for ongoing risk-based data oversight.
Key Elements:
Definition of cross-functional roles and responsibilities
Documentation of decision-making processes and risk sign-offs
Governance model for ongoing review of risk strategy effectiveness
8. Database Lock SOP
Purpose: Pre-database lock checks with risk-based quality control emphasis.
Key Elements:
Conduct a final data quality assessment focused on CtQ factors
Documentation of any open issues, their justification, or resolution
Confirmation of protocol-defined quality acceptance criteria before lock
9. Audit Trail and Documentation SOP
Purpose: Ensure audit readiness and traceability of risk-based decisions and activities.
Key Elements:
Risk-prioritized review of audit trail to assess risks to critical data and processes.
Traceability of risk-related decisions and data oversight activities
Acronyms
| Acronym | Description |
| AE | Adverse Event |
| ALCOA | Attributable, Legible, Contemporaneous, Original and Accurate |
| CAPA | Corrective Action and Preventive Action |
| CAT | COPD Assessment Test |
| CDISC | Clinical Data Interchange Standards Consortium |
| CDM | Clinical Data Management |
| CDS | Clinical Data Science |
| CMP | Centralized Monitoring Plan |
| COPD | Chronic Obstructive Pulmonary Disease |
| CRO | Clinical Research Organization |
| CtQ | Critical to Quality |
| CTTI | Clinical Trial Transformation Initiative |
| DMP | Data Management Plan |
| DSMB | Data Safety Monitoring Board |
| DSUR | Development Safety Update Report |
| eCOA | electronic Clinical Outcome Assessment |
| EDC | Electronic Data Capture |
| EMA | European Medicines Agency |
| ePRO | electronic Patient Reported Outcome |
| EXACT | EXAcerbations of Chronic pulmonary disease Tool |
| FDA | Food and Drug Administration |
| FHIR | Fast Healthcare Interoperability Resources |
| GCDMP | Good Clinical Data Management Practice |
| GCP | Good Clinical Practice |
| HL7 | Health Level Seven |
| IA | Interim Analysis |
| ICH | International Council for Harmonisation |
| IQRMP | Integrated Quality Risk Management Plan |
| IRC | Independent Review Committee |
| KRI | Key Risk Indicator |
| KT | Knowledge Transfer |
| PHE | Public Health Emergency |
| QbD | Quality by Design |
| QC | Quality Control |
| QTL | Quality Tolerance Limit |
| RACI | Responsible, Accountable, Consulted & Informed |
| RACT | Risk Assessment Categorization Tool |
| rb-CDM | risk-based Clinical Data Management |
| RBQM | Risk-Based Quality Management |
| RCA | Root Cause Analysis |
| SCDM | Society for Clinical Data Management |
| SDR | Source Data Review |
| SDV | Source Data Verification |
| SME | Subject Matter Expert |
| SOP | Standard Operating Procedure |
| TA | Therapeutic Area |
Additional File
The additional file for this article can be found as follows:
Appendices. Appendix A to D. DOI: https://doi.org/10.47912/jscdm.524.s1
Acknowledgements
We would like to acknowledge the valuable contributions of Cheryl Grandinetti (FDA) and Steve Young (CluePoints), whose input and support greatly assisted the development of this chapter.
Literature Review
Due to the evolving ongoing work on Risk-Based CDM, there was no literature search and review done for this chapter.
Revision History
| Publication Date | Comments |
| September 2025 | Final DRAFT for public review |
| April 2026 | Post Public review Version |
Competing Interests
The authors have no competing interests to declare.
References
International Council for Harmonisation. Integrated Addendum to ICH E6(R2): Guideline for Good Clinical Practice E6 (R3). International Council for Harmonisation; 2025. Accessed August 25, 2026. https://www.ich.org/page/efficacy-guidelines#6-2
International Council for Harmonisation. ICH E8 (R1), General Considerations for Clinical Trials. International Council for Harmonisation; 2021. Accessed August 25, 2026. https://database.ich.org/sites/default/files/E8-R1_Guideline_Step4_2021_1006.pdf
Adams A, Adelfio A, Barnes B, et al. Risk-based monitoring in clinical trials: 2021 update. Ther Innov Regul Sci. 2023; 57:529–537. DOI: http://doi.org/10.1007/s43441-022-00496-9
Society for Clinical Data Management. SCDM competency framework. Society for Clinical Data Management. Accessed August 25, 2026. https://scdm.org/cdm-competency-framework/
US Food and Drug Administration. Guidance for industry, oversight of clinical investigations — a risk-based approach to monitoring. US Department of Health and Human Services; 2013. Accessed August 25, 2026. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/oversight-clinical-investigations-risk-based-approach-monitoring
Medicines and Healthcare Products Regulatory Agency. ‘GXP’ data integrity guidance and definitions. HM Government; 2018. Accessed August 25, 2026. https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/687246/MHRA_GxP_data_integrity_guide_March_edited_Final.pdf
Medicines and Healthcare Products Regulatory Agency. Oversight and monitoring. HM Government; 2022. Accessed August 25, 2026. https://www.gov.uk/government/publications/oversight-and-monitoring-of-investigational-medical-product-trials/oversight-and-monitoring-activities
US Food and Drug Administration. A risk-based approach to monitoring of clinical investigations questions and answers. US Department of Health and Human Services; 2023. Accessed August 25, 2026. https://www.fda.gov/media/121479/download
Society for Clinical Data Management. Position paper on how to create a clinical data science organization. Society for Clinical Data Management; 2022. Accessed August 25, 2026. https://scdm.org/wp-content/uploads/2024/03/SCDM-Position-Paper-Evolution-into-Clinical-to-Data-Science-V9.0.pdf
Clinical Trials Transformation Initiative. Quality by Design (QbD) project, critical to quality factors principles document. Clinical Trials Transformation Initiative; 2015. Accessed August 25, 2026. https://ctti-clinicaltrials.org/wp-content/uploads/2021/07/CTTI_QbD_Workshop_Principles_Document.pdf
TransCelerate Biopharma Inc. The Risk Assessment Categorization Tool (RACT) template. TransCelerate Biopharma Inc; 2013. Accessed August 25, 2026. https://www.transceleratebiopharmainc.com/assets/risk-based-monitoring-solutions/
TransCelerate Biopharma Inc. The Risk Indicator Library. TransCelerate Biopharma Inc; 2019. Accessed August 25, 2026. https://www.transceleratebiopharmainc.com/wp-content/uploads/2019/02/TransCelerate-RBM-Risk-Indicator-Library_Final-21Feb2019.xlsx
TransCelerate Biopharma Inc. Quality Tolerance Limits: Framework for Successful Implementation in Clinical Development. TransCelerate Biopharma Inc; 2020. Accessed August 25, 2026. https://pmc.ncbi.nlm.nih.gov/articles/PMC7864825/
Society for Clinical Data Management. The 5Vs of clinical data. Society for Clinical Data Management; 2022. Accessed August 25, 2026. https://scdm.org/wp-content/uploads/2024/03/SCDM-The-5Vs-of-Clinical-Data-FINAL.pdf
TransCelerate Biopharma Inc. Evaluating source data verification as a quality control measure in clinical trials. TransCelerate Biopharma Inc.; 2014, Accessed August 25, 2026. https://journals.sagepub.com/doi/pdf/10.1177/2168479014554400
Stokman PG, Ensign L, Langeneckhardt D, et al., 2021, Risk-based quality management in CDM An inquiry into the value of generalized query-based data cleaning. J Soc Clin Data Manage. 2021; 1(1). DOI: http://doi.org/10.47912/jscdm.20
Society for Clinical Data Management and eClinical Forum. Audit trail review: A key tool to ensure data integrity. Society for Clinical Data Management and eClinical Forum; 2021, Accessed August 25, 2026. https://scdm.org/wp-content/uploads/2024/07/2021-eCF_SCDM-ATR-Industry-Position-Paper-Version-PR1-2.pdf
US Food and Drug Administration. Considerations for the conduct of clinical trials of medical products during major disruptions due to disasters and public health emergencies. US Department of Health and Human Services; 2023. Accessed August 25, 2026. https://www.fda.gov/media/172258/download
















