Bridging the Gap: Ensuring Risk-Based Monitoring in Clinical Trials

Smit Shah
CTBM

Request a demo specialized to your need.

Most studies have a risk assessment on file. Far fewer can show, with confidence, that the risk-based decisions in that document actually shaped how monitoring happened over the life of the trial. ICH E6(R3) is explicit that quality management is meant to be a continuous process — identify, evaluate, control, communicate, review not a document produced once at study start and left largely untouched. The gap between those two things is exactly where "compliance on paper" and "compliance in practice" diverge, and it's rarely obvious until someone specifically checks for it.

Here are six signs that gap has opened up in a given study.

1. The risk assessment hasn't been revisited since it was first approved

A risk assessment is meant to reflect current understanding of the study's critical-to-quality factors but that understanding evolves as real data comes in. If the document on file is identical to the version approved before first patient in, despite months of accumulated monitoring and data experience, it's serving as a compliance artifact rather than an active management tool.

2. Monitoring triggers are defined but not systematically checked against live data

A risk-based monitoring plan typically defines specific triggers meant to prompt targeted action — a data quality threshold, an enrollment deviation pattern, a safety signal frequency. If nobody is systematically checking current study data against those defined triggers, the triggers exist on paper without functioning as an actual monitoring mechanism.

3. Centralized monitoring findings don't feed back into the risk plan

Central statistical monitoring often surfaces patterns a site with unusual data trends, a recurring protocol deviation type — that should logically inform an update to the risk assessment. When these findings stay siloed in a separate analytics report instead of updating the documented risk picture, the risk assessment drifts further from what's actually happening in the study.

4. There's no clear record connecting a risk-based decision to a specific action

If a site is flagged as higher risk, that designation should be traceable to specific monitoring decisions — more frequent visits, additional SDV, targeted follow-up. Without a clear record linking the risk designation to the resulting action, an inspector reviewing the study has no way to confirm the risk-based approach was actually operationalized rather than just documented.

5. The eTMF treats the risk plan as a filed document, not a connected record

When the risk assessment sits in the eTMF as a static filed document with no connection to actual monitoring visit records, CRA assignments, or centralized data review activity, there's no structural way to demonstrate that the plan informed real decisions. The document and the operational reality live in separate places.

6. Monitoring intensity doesn't actually vary by the documented risk tiers

A risk-based monitoring approach should mean genuinely different attention for higher-risk versus lower-risk sites different visit frequency, different SDV percentage, different review depth. If every site receives essentially the same monitoring regardless of its documented risk tier, the risk stratification exists in the document but isn't shaping actual practice.

What separates documented risk from demonstrated action

Sign Documented Only Demonstrated in Practice
Risk assessment currency Unchanged since study start Updated as new data and patterns emerge
Monitoring triggers Defined but not actively checked Systematically monitored against live data
Central monitoring findings Siloed in a separate report Feed back into the risk assessment
Risk-to-action traceability No clear link between designation and response Clearly recorded connection
eTMF relationship Static filed document Connected to actual monitoring activity
Monitoring intensity Uniform regardless of risk tier Genuinely varies by documented risk level

Why this matters under ICH E6(R3)

ICH E6(R3) frames the risk-based quality management approach as a continuous cycle, not a one-time deliverable — identifying critical-to-quality factors, evaluating risk, implementing proportionate controls, and reviewing whether those controls are actually working, on an ongoing basis throughout the trial. An inspector examining this area isn't just checking whether a risk assessment document exists; they're checking whether the study's actual conduct reflects the risk-based decisions that document claims to represent. A well-written risk assessment that was never operationalized doesn't satisfy that expectation, even though the document itself might look complete.

How Cloudbyz approaches this

Cloudbyz's risk-based monitoring capability, connected to CTMS and the AI eTMF Agent on the same platform, is designed to keep the risk assessment linked to actual monitoring activity rather than existing as an isolated filed document. Monitoring visit assignments, SDV levels, and CRA attention can be configured to reflect documented risk tiers directly, and the connected platform is intended to make it easier to trace a specific monitoring decision back to the risk designation that prompted it. Because the eTMF Agent and CTMS share the same underlying data, updates to site-level risk understanding are positioned to be reflected across both the documentation and the operational monitoring plan, rather than requiring a separate manual update process each time.

What this means by role

  • Clinical Operations Directors and Quality leaders get a clearer, demonstrable link between documented risk and actual monitoring practice, supporting inspection readiness on this specific area.
  • CRAs get monitoring assignments and intensity that genuinely reflect current site risk, rather than a uniform approach applied regardless of the risk assessment.
  • QA and Compliance Directors get an audit trail connecting risk-based decisions to specific actions, addressing exactly the kind of gap inspectors are trained to look for.

A risk assessment that's well-written but never revisited isn't risk-based quality management it's a document that was true once. Demonstrating that the risk-based approach is actually alive throughout a study is what separates documented compliance from the real thing ICH E6(R3) is asking for.

Book a demo with Cloudbyz.