Risk-Based Monitoring (RBM) in Clinical Trials: Complete Guide

5 steps of a risk-based monitoring strategy in clinical trials.

Introduction

Clinical trial sponsors are responsible for overseeing trial conduct to protect participants’ rights, safety and well-being and to ensure the reliability of trial results. 

Meeting this responsibility requires more than routine site visits and extensive source data verification. Sponsors need a structured quality-management system that identifies critical data and processes, evaluates potential risks, selects proportionate controls and adapts as new information becomes available. 

Risk-based monitoring, or RBM, supports this approach by directing monitoring resources toward the issues most likely to affect participant protection or the credibility of study results. It may combine centralized, remote and targeted on-site monitoring rather than applying the same level of review to every site and data point. 

The broader concept of risk-based quality management (RBQM) applies risk-based thinking throughout the clinical trial lifecycle, from protocol design and vendor selection to trial conduct, data management, monitoring and final reporting. 

Related Service

Looking for Clinical Regulatory Services?

Accelerate your clinical development with DDReg Pharma's end-to-end Clinical Regulatory Services. Our experts support Clinical Trial Applications (CTA), IND submissions, protocol and Investigator's Brochure review, ethics committee submissions, regulatory strategy, health authority interactions, and global clinical trial compliance to streamline approvals across international markets.

Explore Clinical Regulatory Services →

What Is Risk-Based Monitoring?

Risk-based monitoring is a targeted, data-informed approach to clinical trial oversight. It helps sponsors and study teams identify errors, detect emerging risks and implement appropriate mitigation measures before those issues compromise participant safety or trial reliability. 

Rather than checking every data point equally, RBM focuses on critical data and processes, such as: 

  • Informed consent 
  • Participant eligibility 
  • Primary and important secondary endpoints 
  • Safety reporting 
  • Investigational-product administration 
  • Randomization and blinding 
  • Protocol compliance 
  • Data needed to evaluate the trial’s conclusions 

RBM does not mean less oversight. It means selecting monitoring activities according to the importance and likelihood of the identified risks. 

Regulatory authorities encourage sponsors to use proportionate, risk-based monitoring methods that may combine centralized review, remote monitoring and targeted on-site activities. The goal is to focus sponsor oversight on the aspects of study conduct and reporting that matter most to participant protection and data quality.

Why Clinical Trials Are Moving Beyond Routine 100% SDV

Traditional monitoring models often rely heavily on on-site review and source data verification, or SDV. Under this approach, information recorded in the case report form is compared with the participant’s original medical or source records. 

SDV can identify transcription errors and inconsistencies, but extensive verification is time-consuming, costly and not equally valuable for every variable. 

Checking every low-impact data point may consume resources that could be better spent investigating: 

  • Delayed adverse-event reporting 
  • Repeated protocol deviations 
  • Unusual endpoint patterns 
  • Eligibility violations 
  • Inadequate informed-consent practices 
  • Investigational-product accountability issues 
  • Sites with abnormal withdrawal or enrolment rates 

Risk-based monitoring allows sponsors to concentrate SDV and other monitoring activities on data and processes that could materially affect participant safety or the reliability of the trial’s conclusions. 

FDA Perspective on Risk-Based Monitoring

The US Food and Drug Administration requires sponsors to monitor the progress and conduct of clinical investigations. 

In August 2013, the FDA issued guidance encouraging sponsors to develop monitoring strategies based on the risks of the individual clinical investigation. The agency explained that monitoring should focus on the most important aspects of study conduct and reporting rather than relying automatically on routine practices such as frequent site visits and complete SDV. 

In April 2023, the FDA issued final questions-and-answers guidance that expanded on the 2013 recommendations. It provides practical guidance on: 

  • Planning a risk-based monitoring approach 
  • Identifying critical data and processes 
  • Conducting risk assessments 
  • Developing study-level monitoring plans 
  • Selecting centralized, remote and on-site monitoring methods 
  • Addressing significant monitoring findings 
  • Documenting and communicating monitoring results 

The FDA recommends that the monitoring plan reflect the design, complexity, risks and operational characteristics of the specific clinical investigation.

Centralized Monitoring in Risk-Based Monitoring (RBM)

Centralized monitoring in RBM involves evaluating clinical and operational data from multiple study sites at a central location. 

Instead of reviewing each site in isolation, centralized monitoring allows sponsors to compare patterns across the entire study and detect sites, data points or processes that may require additional attention. 

Depending on the study design, risk assessment, and monitoring plan, centralized monitoring may include reviewing the following clinical, operational, and quality indicators:

  • Comparing enrolment and screen-failure rates 
  • Reviewing participant withdrawal patterns 
  • Tracking protocol deviations 
  • Monitoring adverse-event reporting timelines 
  • Identifying missing or inconsistent data 
  • Evaluating data-entry delays 
  • Reviewing query volumes and resolution times 
  • Checking randomization and treatment patterns 
  • Detecting unusual endpoint distributions 
  • Identifying duplicate or potentially fabricated data 
  • Monitoring key risk indicators 
  • Reviewing quality tolerance limits or other acceptable ranges.

Statistical and analytical methods can help reveal anomalies that may not be obvious during routine site-level review. They can also identify sites that require additional training, focused remote review, corrective action or an on-site visit. 

Traditional Site MonitoringCentralized Monitoring
Reviews one site at a timeReviews data across all study sites
Relies mainly on on-site visitsUses centralized data analytics and remote review
Detects site-specific issuesIdentifies study-wide trends and anomalies
Limited cross-site comparisonCompares performance across investigators and countries
Reactive monitoringProactive, risk-based oversight

What Centralized Monitoring Can Detect ?

Centralized review can help identify: 

  • A site reporting unusually few adverse events 
  • A high rate of protocol deviations at one location 
  • Identical data patterns across multiple participants 
  • Delayed entry of critical endpoint data 
  • Unexpected differences in treatment discontinuation 
  • Missing laboratory or imaging assessments 
  • Unusual visit timing 
  • Inconsistent eligibility decisions 
  • Abnormal variation between investigators or countries 

A single unusual result does not automatically indicate misconduct or poor trial conduct. It acts as a signal requiring evaluation. 

Does Centralized Monitoring Replace On-Site Monitoring?

No. Centralized monitoring should not be treated as a universal replacement for on-site review. 

Some risks may still require direct site evaluation, including: 

  • Informed-consent practices 
  • Investigational-product storage and accountability 
  • Source-record availability 
  • Serious protocol non-compliance 
  • Repeated data-integrity concerns 
  • Investigator oversight 
  • Facility or staffing limitations 

The monitoring strategy should use the right combination of centralized, remote and on-site methods for the trial’s actual risks.

3 Core Steps of Risk Based Monitoring of Clinical Trials

Monitoring Approach

Step 1: Identify Critical Risks – Focus on the data and processes that are most critical to: 

  • Participant safety and rights  
  • Data integrity and study endpoints  
  • Informed consent, eligibility, randomization, and IP administration  

Conduct an initial risk assessment, then continuously evaluate new risks from monitoring findings, protocol deviations, safety data, audits, vendors, and system issues. Protect study blinding through defined access controls and documented procedures. 

Step 2: Develop a Risk-Based Monitoring Plan  – Build a study-specific monitoring plan based on the risk assessment. Define: 

  • Critical data and identified risks  
  • Centralized, remote, and on-site monitoring approaches  
  • Monitoring frequency and targeted SDV/SDR  
  • Escalation criteria, roles, and follow-up actions. 

Adjust monitoring intensity according to study complexity and site performance. 

Step 3: Detect, Act, and Improve  –When significant issues are identified: 

  • Assess impact on participant safety and data quality  
  • Perform root cause analysis  
  • Implement CAPA (Corrective and Preventive Actions)  
  • Update the risk assessment and monitoring plan  
  • Communicate findings to investigators, sponsors, vendors, DMCs, and regulators, as appropriate  

RBM is a continuous, adaptive process that improves trial quality by focusing oversight where risk is greatest. 

Documentation of Monitoring Activities in RBM

Monitoring activities should be documented clearly enough to demonstrate that the approved plan was followed and that identified issues were addressed. 

Records should include: 

  • Date of the activity 
  • Type of monitoring performed 
  • People involved 
  • Data and processes reviewed 
  • Findings identified 
  • Risk assessment 
  • Decisions made 
  • Corrective actions 
  • Follow-up responsibilities 
  • Completion status 

Monitoring records should cover centralized, remote and on-site activities. 

The investigator should be informed of significant findings affecting the site. Sponsor management should also receive appropriate information about major quality, safety or compliance issues.

Risk-Based Monitoring vs Risk-Based Quality Management

RBM and RBQM are closely related, but they are not interchangeable. 

Area 

Risk-Based Monitoring 

Risk-Based Quality Management 

Primary focus 

Monitoring trial conduct and data 

Managing quality across the full trial lifecycle 

Timing 

Mainly during trial conduct 

Begins during trial design and continues through reporting 

Activities 

Centralized, remote and on-site monitoring 

Protocol design, risk assessment, monitoring, data governance, vendor oversight and reporting 

Main objective 

Detect and address important trial risks 

Prevent, control, detect and communicate important quality risks 

Scope 

One component of trial oversight 

Broader quality-management framework 

Risk-based quality management (RBQM) builds quality into the study from the beginning. Risk-based management (RBM) is one of the tools used within that wider system. 

ICH E6(R3) emphasizes quality by design, proportionality, critical-to-quality factors and risk-based decision-making throughout the trial lifecycle. 

Practical Steps to Implement RBM and RBQM

Risk Base Mointorinig Approch

ICH E6(R3) Annex 2 and Innovative Trial Designs in RBM

ICH adopted the final Step 4 version of E6(R3) Annex 2 on June 3, 2026. Step 4 means that the final guideline is recommended for adoption by regulatory authorities in ICH regions. Jurisdiction-specific implementation may follow separate timelines. 

Annex 2 provides additional GCP considerations for trials that incorporate features such as: 

  • Decentralized elements 
  • Real-world data 
  • Pragmatic designs 
  • External control data 
  • Innovative data sources 
  • Complex operational models 

These trial designs do not reduce the sponsor’s responsibility for oversight. They make proportionate RBQM, data governance, technology validation, vendor control and centralized monitoring even more important.

How an Oncology Trial Reduced SDV And Improve Data Quality While Preserving The Primary Result

A published cancer clinical-trial analysis provides a useful example of why 100% SDV may not always be the most efficient quality-control strategy. 

Researchers compared results generated from: 

  • Fully source-verified trial data 
  • The original data before SDV corrections 
  • Centrally monitored survival data from an independent source 

The trial’s primary endpoint was overall survival. 

Although SDV identified discrepancies, the study found no systematic pattern in the errors. Their effect on the primary overall-survival analysis was negligible. 

The estimated treatment effect was almost identical: 

  • Hazard ratio of 1.18 with 100% SDV 
  • Hazard ratio of 1.18 without SDV 
  • Hazard ratio of 1.18 using centrally monitored data 

The confidence intervals and p-values differed slightly, but the overall clinical conclusion did not change. 

What the Oncology Study Actually Demonstrated 

The study did not prove that reducing SDV automatically improves data quality. 

It demonstrated that: 

  • 100% SDV was resource-intensive 
  • Many identified discrepancies were random 
  • Correcting those discrepancies had little effect on the primary outcome 
  • Central monitoring was efficient for the objective overall-survival endpoint 
  • Monitoring controls should reflect the nature and importance of the data 

The study also found that more subjective outcomes, such asradiological tumor response, required different controls. For subjective endpoints, better strategies may include: 

  • Independent blinded review 
  • Endpoint-adjudication committees 
  • Tracking missing scans 
  • Standardized assessment criteria 
  • Central image review 
  • Focused monitoring of assessment timing 

Quality does not come from checking everything equally. It comes from applying the most effective control to the most important risk.

Benefits of Risk-Based Monitoring in Clinical Trails

When properly designed and implemented, RBM may offer: 

  • Earlier detection of systemic issues 
  • More focused monitoring resources 
  • Improved cross-site comparison 
  • Better identification of unusual data patterns 
  • Faster escalation of significant risks 
  • Reduced unnecessary SDV 
  • More targeted on-site visits 
  • Stronger sponsor oversight 
  • Better integration between clinical operations, data management and statistics 
  • Greater attention to participant safety and critical endpoints 

FDA describes quality by design and RBM as approaches that can modernize clinical trials and improve efficiency without compromising participant protection or data integrity. 

Common RBM and RBQM Implementation Challenges

Sponsors may encounter problems when: 

  • Risk assessments are generic 
  • Too many low-value KRIs are tracked 
  • Thresholds lack clear actions 
  • Data are not available quickly enough 
  • Sites do not understand central-monitoring findings 
  • Responsibilities between teams are unclear 
  • Vendor data are not integrated 
  • Monitoring plans are not updated 
  • Reduced SDV is treated mainly as a cost-cutting exercise 
  • Findings are generated but not escalated 

A dashboard filled with red indicators is not a quality system if nobody knows who must act.

Conclusion

Risk-based monitoring gives clinical trial sponsors a more focused way to oversee participant protection, trial conduct and data reliability. 

The approach begins by: 

  • Identifying critical data and processes 
  • Assessing study-level and site-level risks 
  • Developing a proportionate monitoring plan 
  • Combining centralized, remote and on-site activities 
  • Reviewing findings and emerging risks continuously 
  • Implementing and documenting appropriate corrective actions 

RBQM extends these principles across the full trial lifecycle. It helps sponsors build quality into protocol design, data collection, vendor oversight, monitoring and reporting rather than trying to inspect quality into the trial at the end. 

Centralized monitoring and targeted SDV are not shortcuts. Used correctly, they allow sponsors to focus attention where errors would matter most. 

With ICH E6(R3), its 2026 Annex 2 and FDA’s risk-based monitoring guidance, the direction is clear: clinical trial quality should be proactive, proportionate, data-informed and centered on participant protection and reliable results.

References and Further Reading

  • US Food and Drug Administration. Oversight of Clinical Investigations: A Risk-Based Approach to Monitoring. August 2013. 
  • US Food and Drug Administration. A Risk-Based Approach to Monitoring of Clinical Investigations: Questions and Answers. April 2023. 
  • International Council for Harmonisation. ICH E6(R3): Guideline for Good Clinical Practice, Principles and Annex 1. January 2025. 
  • International Council for Harmonisation. ICH E6(R3) Annex 2. June 3, 2026. 
  • Tudur Smith C, Stocken DD, Dunn J, et al. The Value of Source Data Verification in a Cancer Clinical Trial. PLOS ONE. 2012;7(12). 
  • Barnes B, Stansbury N, Brown D, et al. Risk-Based Monitoring in Clinical Trials: Past, Present, and Future. Therapeutic Innovation & Regulatory Science. 2021;55(4):899–906. 

Frequently Asked Questions

The main goal of RBM is to protect participants and improve the reliability of clinical trial results by focusing monitoring activities on the most significant risks to critical data and processes. 

Centralized monitoring in RBM involves reviewing clinical and operational data from multiple sites at a central location. It helps identify unusual trends, compare site performance and determine where remote follow-up, training, corrective action or an on-site visit may be needed. 

Traditional monitoring often relies heavily on routine site visits and extensive SDV. RBM uses a combination of centralized, remote and targeted on-site activities based on the trial’s identified risks.