This is a ready-to-use risk-based Clinical Monitoring Plan (CMP), the controlling document that translates a trial’s risk assessment into a monitoring strategy. Some sponsors split an Integrated Quality and Risk Management Plan from the CMP; the content here works either way. Replace every <<FILL: ...>> placeholder and route it through your normal review and approval before first-subject-first-visit. A filled specimen follows. This is general guidance to adapt and verify, not legal or regulatory advice.
Document control header
| Field | Entry |
|---|---|
| Plan title | Risk-Based Clinical Monitoring Plan |
| Protocol number / title | <<FILL>> |
| Plan version | <<FILL>> |
| Effective date | <<FILL>> |
| Sponsor | <<FILL>> |
| Author / owner | <<FILL: role, e.g. Clinical Trial Lead>> |
| Linked risk assessment reference | <<FILL: RACT / risk register ID>> |
1. Purpose and scope
This plan defines how the risks to the critical data and processes of protocol <<FILL>> are monitored across central, remote, and on-site modes. It applies to all sites and covers the period from site activation through database lock. It is the documented monitoring response to the trial’s risk assessment; every monitoring activity here traces to a risk in the register.
2. Critical data and critical processes
Identified for this trial from the protocol and risk assessment. Anything not listed receives light-touch treatment (system edit checks only).
| Critical to safety | Critical to reliability |
|---|---|
<<FILL: informed consent (presence, version, dating)>> | <<FILL: primary efficacy endpoint>> |
<<FILL: eligibility / inclusion-exclusion>> | <<FILL: randomization and blinding integrity>> |
<<FILL: SAE identification and reporting>> | <<FILL: IP accountability and dosing>> |
<<FILL: dose modifications / stopping rules>> | <<FILL: endpoint adjudication source>> |
3. Monitoring strategy: the central, remote, and on-site mix
| Activity | Mode | Trigger / frequency |
|---|---|---|
| KRI and data-quality dashboard review | Central | Continuous; formally reviewed every <<FILL: e.g. 2>> weeks |
| Targeted SDV of primary endpoint, consent, eligibility | Remote or on-site | 100% of these fields, all subjects |
| Targeted SDV of other critical data | Remote or on-site | Risk-based sample, <<FILL: e.g. 25%>> |
| Non-critical data | EDC edit checks only | System checks only |
| Routine interim on-site visit | On-site | Every <<FILL: e.g. 12-16>> weeks, risk-adjusted |
| Triggered on-site visit | On-site | Within <<FILL: e.g. 10>> business days of a red signal |
| IP accountability and storage check | On-site | Every visit |
Rationale for the mix: <<FILL: brief justification tied to the trial's risk profile>>.
4. Source data verification strategy
- High-criticality fields (
<<FILL: consent, eligibility, primary endpoint, SAEs>>): 100% SDV, all subjects, plus source data review of conduct and safety. - Medium-criticality fields: defined sample of
<<FILL: e.g. 30%>>of subjects per site. - Low-criticality fields: EDC edit checks and central monitoring only, no manual SDV.
- Escalation rule: if a sampled site shows an error rate above
<<FILL: e.g. 5%>>, raise that site to 100% SDV on the affected fields, run a query sweep, and investigate the data flow.
Source data verification (transcription accuracy) is reduced and targeted; source data review (conduct, safety, consent, plausibility) is not reduced.
5. Key risk indicators
Each KRI has a threshold and a defined action. A KRI without an action is not included.
| KRI | Threshold logic | Action when breached |
|---|---|---|
<<FILL: screen failure rate>> | <<FILL: flag if far from study mean>> | <<FILL: central review; corroborate>> |
<<FILL: enrollment rate vs plan>> | <<FILL: flag outliers vs peers>> | <<FILL: assess for eligibility signal>> |
<<FILL: query rate / aging>> | <<FILL: aged > X days>> | <<FILL: site follow-up>> |
<<FILL: data entry lag>> | <<FILL: median > X days>> | <<FILL: remote check>> |
<<FILL: AE/SAE rate vs expected>> | <<FILL: far from pooled rate>> | <<FILL: safety review; triggered visit>> |
Full KRI definitions, data sources, review cadence, and the signal disposition log are maintained in Log: KRI/QTL Register and Signal Disposition Log.
6. Quality tolerance limits
QTLs are few and trial-level. A breach is assessed for root cause and impact and may be reported in the clinical study report.
| QTL parameter | Limit | Escalation on breach |
|---|---|---|
<<FILL: rate of a specific important protocol deviation>> | <<FILL>> | <<FILL: assess root cause and impact; document>> |
<<FILL: rate of important eligibility violations>> | <<FILL>> | <<FILL>> |
<<FILL: rate of incomplete primary endpoint data>> | <<FILL>> | <<FILL>> |
7. Central monitoring activities
- Dashboards and KRI computation:
<<FILL: tool / system>>. - Statistical checks: distributional and variance checks, digit-preference/Benford-type checks, duplicate detection, impossible-value logic, timing checks.
- Review cadence and forum:
<<FILL: e.g. biweekly central monitoring meeting>>, attended by<<FILL: central monitor, clinical lead, data management, biostatistics>>. - Every signal and its disposition (including “reviewed, no action”) is recorded.
8. On-site visit plan
| Visit type | Purpose | Frequency basis |
|---|---|---|
| Site initiation | Activate and train the site | Before enrollment |
| Interim (routine) | Ongoing oversight | Risk-adjusted interval |
| Triggered | Respond to a signal | Within defined days of a red flag |
| Close-out | Reconcile and archive | At site completion |
9. Escalation and communication
Define the path a signal follows from central monitor to CRA to clinical lead to medical monitor to QA, with timelines. <<FILL: describe the escalation path and who is notified for each severity>>.
10. Roles and responsibilities
| Role | Responsibility |
|---|---|
| Sponsor / clinical trial lead | Owns the trial QMS, approves the plan, accountable for risk and QTL decisions |
| Central monitor | Runs analytics, raises and dispositions signals, recommends triggered visits |
| CRA / clinical monitor | On-site and remote monitoring, SDV/SDR, visit reports, site follow-up |
| Data management | EDC edit checks, KRI data, query management |
| Biostatistics | Defines QTLs and statistical methods, interprets anomalies |
| Medical monitor | Reviews safety, SAEs, eligibility and dosing concerns |
| Quality assurance | Independent oversight and audit; does not perform the monitoring |
The sponsor remains accountable for oversight even when a CRO performs the monitoring (ICH E6(R2) 5.2).
11. Review and revision
This plan is living. It is re-reviewed at <<FILL: defined points, e.g. protocol amendment, new safety signal, region added>> and updated under version control, with the reason for each revision recorded.
12. Acceptance criteria for this plan
- Every prioritized risk in the register maps to at least one monitoring activity here.
- Every KRI has a threshold and a named action.
- QTLs are few and tied to trial-level quality.
- The SDV strategy is justified, with an escalation rule.
- Roles are unambiguous.
- The plan is approved before first-subject-first-visit and re-reviewed at defined points.
13. References
ICH E6(R2) Good Clinical Practice, sections 5.0 (quality management), 5.18.3 (monitoring), 5.20 (noncompliance); ICH E6(R3) Principles and Annex 1. FDA guidance, A Risk-Based Approach to Monitoring of Clinical Investigations (2019) and its Questions and Answers (2023). EMA Reflection paper on risk based quality management in clinical trials (EMA/INS/GCP/394194/2011, 2013). ICH E8(R1) (general considerations for clinical studies) for critical-to-quality factors.
Confirm the current status of each reference for every region the study touches before you rely on it.
14. Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Author (Clinical Trial Lead) | <<FILL>> | ||
| Biostatistics | <<FILL>> | ||
| Quality Assurance | <<FILL>> | ||
| Sponsor approver | <<FILL>> |
Filled specimen (excerpt)
The following shows the monitoring-mix and KRI sections completed for an example 30-site oncology study. Illustrative only.
Monitoring mix: KRI dashboard reviewed centrally every 2 weeks; 100% SDV of consent, eligibility, and adjudicated primary endpoint for all subjects; 25% risk-based sample of other critical data; routine interim visits every 12 weeks, risk-adjusted; triggered visits within 10 business days of a red signal.
| KRI | Threshold logic | Action when breached |
|---|---|---|
| Screen failure rate | Flag if > 2 SD from study mean of 34% | Central review, corroborate with AE and enrollment KRIs |
| Enrollment rate vs peers | Flag site > 3x median | Assess for eligibility/integrity signal |
| AE rate per subject | Flag if < half pooled rate of 1.9 | Safety review; consider triggered visit |
Worked signal: Site 014 showed enrollment 9 subjects in 6 weeks (median 2), screen failure 11% (mean 34%), AE rate 0.4 (pooled 1.9). Individually benign; together a classic eligibility-and-underreporting pattern. The plan’s defined action triggered a focused on-site visit within 10 business days with targeted SDV of consent, eligibility, and AE source for all enrolled subjects plus a coordinator interview. The central monitor documented the signal, the trigger, and the disposition.
Common inspection findings this plan prevents
- A generic plan that is a template with the protocol number changed, whose KRIs do not match the trial’s risks.
- No traceability from a risk in the register to a monitoring activity.
- KRIs reviewed but never acted on, with red flags sitting for weeks.
- QTLs absent or confused with site-level KRIs.
- Reduced SDV with no risk basis or escalation rule.
- A plan frozen while the trial’s risk picture changed.
How to adapt this plan
- Populate sections 2, 5, and 6 directly from your risk assessment and critical-to-quality factor register.
- Set the SDV percentages, KRI thresholds, and visit intervals from this trial’s risk profile, not a default.
- Keep QTLs to a handful; anything more is a mislabeled KRI.
- Point the escalation path in section 9 to your actual roles and timelines.
- Confirm the regulatory status of each reference for every region before first-subject-first-visit.