Two protocol deviations happen in the same week, at two different sites. One is a delegation log that's missing an initial. The other is an eligibility criterion that was misapplied, and a subject who shouldn't have been enrolled was. Under a monitoring plan that treats every deviation the same way logged, reviewed, closed both get roughly equal attention. Under ICH E6(R3), that's exactly the problem the guideline was rewritten to fix. Only one of those two deviations actually threatens participant safety or the reliability of the trial's results, and a monitoring plan that can't tell the difference isn't managing risk it's just recording it.
This isn't a small technical footnote in the R3 revision. It's one of the guideline's central shifts, and it has a name: Critical-to-Quality factors.
A Critical-to-Quality factor is an attribute of trial design or conduct that, if it fails, would meaningfully compromise participant protection or the reliability of the trial's results. ICH E6(R3) asks sponsors to identify these factors during protocol design as part of a quality-by-design approach rather than discovering them reactively once something has already gone wrong.
Typical examples include:
The point of naming these explicitly is proportionality: R3 expects sponsors to concentrate monitoring effort, source data verification, and oversight resources on the factors that actually matter, instead of spreading equal scrutiny across every field on every form.
Under the previous approach, many monitoring plans defaulted to broad, largely uniform checks high rates of source data verification applied evenly across most data points, regardless of whether a field had any real bearing on subject safety or result validity. That approach can produce a monitoring plan that looks thorough on paper while still missing what actually matters, because effort isn't weighted toward the few things that matter most.
R3 asks for something different and more specific: sponsors need to be able to show that they identified their CtQ factors deliberately, that monitoring intensity is proportionate to those factors, and that oversight is continuous not a snapshot pulled together before an inspection. An auditor working from R3's framework isn't going to ask only "was this deviation logged?" They're going to ask "how did you decide this was worth monitoring closely, and how do you know, right now, whether it's trending toward a problem?"
| Uniform / Broad Monitoring | CtQ-Focused Monitoring (ICH E6(R3)) | |
|---|---|---|
| What gets closely reviewed | Most data points, roughly equally | The specific factors identified as critical to safety or result validity |
| How monitoring effort is allocated | Spread evenly, often driven by habit or template | Concentrated on CtQ factors, lighter elsewhere |
| Evidence of oversight | A completed monitoring visit log | Ongoing tracking against defined thresholds for each CtQ factor |
| Response to a trending risk | Usually noticed at the next scheduled visit | Flagged as it happens, before it becomes a deviation |
| What an inspector can verify | That checks happened | That the sponsor identified the right things to check, and was watching them continuously |
If more than one of these is a "not really," the CtQ factors most likely exist in a document, not in the monitoring process itself.
Cloudbyz CTMS's capability lets sponsors identify the specific data and processes that matter most for a given study safety data, enrollment criteria, primary or secondary objectives and set those up as Key Risk Indicators with defined thresholds, rather than relying on a blanket monitoring approach. Source data verification rules can be targeted to those specific items instead of applied uniformly, so review effort follows the same proportionality R3 asks for. Because CTMS shares a common data model with Cloudbyz eTMF and EDC, KRI dashboards update in real time as data comes in from sites, giving sponsors continuous visibility into CtQ factors rather than a picture reconstructed before an inspection.
For teams running the Protocol Intelligence Agent alongside CTMS, this goes a step further: the agent monitors for deviation patterns across sites and visit types, flags issues tied to safety-relevant findings first, and builds pre-visit risk briefings that prioritize the same CtQ factors the monitoring plan was built around turning "we defined these factors" into "we're actively watching them" without adding manual reporting work.
Book a demo with Cloudbyz team to know more on capabilities.