Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Risk Assessment Plug-and-play starting point Clinical & GCP

Risk Assessment: Clinical Trial Risk Assessment and Categorization (RACT)

A plug-and-play clinical trial risk assessment: critical data and process identification, likelihood/impact/detectability scoring, the risk register table, controls, and the monitoring response that feeds the monitoring plan, with a filled specimen.

Document type: Risk Assessment

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use clinical trial risk assessment in the style of a Risk Assessment and Categorization Tool (RACT). It identifies the trial’s critical data and processes, scores what could go wrong, sets controls, and defines the monitoring response that becomes the input to the monitoring plan. Replace every <<FILL: ...>> placeholder and route it through your normal review before first-subject-first-visit. A filled specimen follows. This is general guidance to adapt and verify, not legal or regulatory advice.

Document control header

FieldEntry
TitleClinical Trial Risk Assessment (RACT)
Protocol number / title<<FILL>>
Version<<FILL>>
Effective date<<FILL>>
Author / owner<<FILL: role>>
Linked monitoring plan<<FILL: CMP ID>>

1. Purpose and method

This assessment identifies the critical-to-safety and critical-to-reliability data and processes for protocol <<FILL>>, scores the risks to each, and defines controls and monitoring. It uses a failure-mode style scoring across three dimensions. The output is a ranked risk register that drives the monitoring plan; a risk with no corresponding control or monitoring activity is a gap.

2. Scoring scales

Define the scales before scoring so ratings are consistent.

Dimension1 (low)23 (high)
Likelihood (how probable the failure)RareOccasionalFrequent
Impact (on subject safety or data reliability)MinorModerateCritical
Detectability (chance of catching it before harm)Easily detectedSometimes detectedRarely detected

Risk priority: Likelihood x Impact x Detectability (or use a likelihood x impact matrix). Set a threshold above which a risk is “high” and requires a documented control and monitoring response, for example <<FILL: e.g. score >= 12 or any Impact = 3>>.

3. Critical data and processes

Critical to safetyCritical to reliability
<<FILL: informed consent>><<FILL: primary endpoint>>
<<FILL: eligibility>><<FILL: randomization / blinding>>
<<FILL: SAE reporting>><<FILL: IP accountability / dosing>>
<<FILL: stopping rules>><<FILL: key inclusion criteria defining the analysis population>>

4. Risk register

Risk IDCritical process / dataWhat could go wrongLIDScoreRisk classControl / mitigationMonitoring responseOwner
<<FILL: R-01>><<FILL: informed consent>><<FILL: consent on a superseded version>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL: EDC version control + 100% SDV of consent>><<FILL: on-site>><<FILL>>
<<FILL: R-02>><<FILL: eligibility>><<FILL: enrollment of ineligible subjects>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL: eligibility checklist + 100% SDV>><<FILL: KRI screen-fail + central>><<FILL>>
<<FILL: R-03>><<FILL: SAE reporting>><<FILL: late or missed SAE reports>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL: SAE timeliness KRI>><<FILL: central + medical>><<FILL>>
<<FILL: R-04>><<FILL: primary endpoint>><<FILL: endpoint mis-measurement or missing data>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL: 100% SDV vs adjudication source>><<FILL: remote/on-site>><<FILL>>
<<FILL: R-05>><<FILL: IP accountability>><<FILL: dosing errors / IP diversion>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL: IP reconciliation>><<FILL: on-site every visit>><<FILL>>

5. Residual risk and monitoring linkage

For each high risk, state the residual risk after controls and confirm a monitoring activity watches it. The monitoring plan (section references) is the documented answer to this register. Any risk rated high with no monitoring activity must be either re-controlled or explicitly accepted with justification.

6. QTL candidates

The small set of trial-level parameters derived from the highest risks that become quality tolerance limits:

  • <<FILL: e.g. overall rate of important eligibility violations>>
  • <<FILL: e.g. rate of incomplete primary endpoint data>>
  • <<FILL>>

7. Acceptance criteria

  • Critical-to-safety and critical-to-reliability data and processes are identified for this specific trial.
  • Every risk is scored on all three dimensions against defined scales.
  • Every high risk has a documented control and a monitoring response.
  • The register feeds the monitoring plan and the QTL set with clear traceability.
  • The assessment is approved before first-subject-first-visit and re-reviewed when risk changes.

8. References

ICH E6(R2) Good Clinical Practice, section 5.0 (quality management); ICH E6(R3) Annex 1. ICH E8(R1), general considerations for clinical studies (critical-to-quality factors). ICH Q9, Quality Risk Management (methodology). FDA guidance, A Risk-Based Approach to Monitoring of Clinical Investigations (2019) and Q&A (2023).

Confirm the current status of each reference before use.

9. Approvals

RoleNameSignatureDate
Author<<FILL>>
Biostatistics<<FILL>>
Medical monitor<<FILL>>
Quality Assurance<<FILL>>

Filled specimen (excerpt)

The following shows two register rows for an example cardiovascular outcomes trial. Illustrative scores only.

Risk IDCritical processWhat could go wrongLIDScoreClassControlMonitoring response
R-02EligibilityEnrollment of subjects who do not meet key inclusion labs23212HighHard-stop eligibility checklist in EDC; PI sign-off100% SDV of eligibility labs; screen-failure KRI vs peers; triggered visit on outlier
R-03SAE reportingLate or missed SAE reporting to sponsor23318HighSite training; 24-hour reporting workflowSAE timeliness KRI (any late report flags); medical monitor review; central corroboration

R-03 scores highest because a missed SAE is critical to safety (Impact 3) and hard to detect from central data alone if the event never enters the system (Detectability 3). That drives both a strong process control (a 24-hour workflow) and a monitoring response combining a timeliness KRI with medical review, because neither alone fully covers the low detectability.

Common inspection findings this assessment prevents

  • A risk register that exists but never connects to the monitoring plan.
  • A high risk with no control or no monitoring activity watching the residual.
  • Scoring with no defined scales, so ratings are inconsistent and indefensible.
  • QTLs invented independently of the risk assessment.
  • An assessment done once and never revisited when a safety signal or amendment changed the risk picture.

How to adapt this assessment

  1. Build the critical-data lists in section 3 from your protocol, not a template.
  2. Set the scoring scales and the high-risk threshold your organization uses.
  3. Ensure every high risk maps to a row in your monitoring plan and, where trial-level, to a QTL.
  4. Re-review after each amendment or new safety signal and version the update.
  5. Confirm the regulatory status of each reference before use.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.