Skip to main content
v2026.11,610 entries · CC-BY 4.0

CQAP (CASRAI)

Clinical Research Quality Assurance & Audit Certification — Professional

LevelProfessionalCQACQAP (CASRAI)
115 h
Nominal
Self-paced study
12
Lessons
12 modules
8
Domains
Exam blueprint
72
Exam items
Per attempt
70%
Pass mark
Fixed, uncurved
90
Retake wait
Days

What you earn

The credential itself

Pass the examination and CASRAI issues this certificate and the post-nominal CQAP (CASRAI), signed by the Programme Director and verifiable by anyone, permanently, from the code on its face.

Specimen. Issued as a signed PDF and as a machine-readable Open Badge; the holder and code shown are illustrative.
How it appears on your CV

Certifications

CQAP (CASRAI)Clinical Research Quality Assurance & Audit, Professional

CASRAI·Issued Mar 2026·Credential ID CASRAI-CQA-2026-RBVKKH

casrai.org/verify/CASRAI-CQA-2026-RBVKKH

Every certificate is issued under the signature of Dr. Diana Nieves Castro, MD, Programme Director of CASRAI Certification, who sets the syllabus, blueprint and pass mark for this credential.

It certifies that its holder passed the CASRAI examination for this course on the date shown, scored against the blueprint and pass mark published on this page — and anyone can confirm it from the verification code, without an account and without contacting us.

About this credential

What it covers

Body of knowledge

Exam blueprint

The exam is assembled to these weights on every attempt. They are published before purchase because a blueprint you cannot see is not a blueprint.

Domains and weights8 domains · 72 scored items
DomainWeight
Quality management, quality by design, and the QA / QC / monitoring / audit boundaryP1
12%9 items
SOP architecture, document control and the training systemP2
10%7 items
Risk-based audit planning and the audit programmeP3
12%9 items
Conducting audits: site, service provider, system, process and documentP4
16%12 items
Audit reporting, grading, follow-up and audit recordsP5
10%7 items
Deviation, noncompliance, serious breach and CAPAP6
14%10 items
Computerised systems, validation and data integrity in an audit contextP7
14%10 items
Regulatory inspections and inspection readinessP8
12%9 items
Total100%

Item counts are approximate. Each attempt draws a fresh form to the weights above, so the exact number of items per domain varies between attempts.

Syllabus

12 modules, 12 lessons

Every lesson and every learning outcome is listed. The lesson bodies open on enrolment; nothing else about the course is withheld.

12 modules · 12 lessons · 115 h

Lesson material opens once you are enrolled. The full syllabus and every learning outcome are shown here so you can judge the coverage before you pay.

  1. Module 1

    P-M1

    1 lesson · 9 h

    1. Locked.Quality management and the QA / QC / audit boundary9 h · Locked

      On completion you will be able to

      • By the end of this module the learner can:
      • Classify a described activity as quality assurance, quality control, monitoring, audit or inspection, and justify the classification from the E6(R3) Glossary.
      • Explain why monitoring is a quality control activity and state what follows from that for who may perform it.
      • State the independence requirement at §3.11.2 and apply it to a proposed audit assignment.
      • Work the §3.10.1 risk cycle for a supplied protocol and derive two quality tolerance limits with defined breach actions.
      • Describe the R2→R3 changes that alter an audit programme's scope.
  2. Module 2

    P-M2

    1 lesson · 9 h

    1. Locked.SOP architecture and document control9 h · Locked

      On completion you will be able to

      • Justify, citing Appendix C.2.12, why an organisation's SOPs and validation records are essential records.
      • Design an SOP hierarchy proportionate to a described organisation and defend the scope decisions against Principle 7.
      • Audit a document-control system using a tracer approach.
      • Assess whether a training system evidences competence or attendance.
      • Apply §3.6.10 correctly to a service provider whose quality system was not designed to be GCP-compliant.
  3. Module 3

    P-M3

    1 lesson · 10 h

    1. Locked.Risk-based audit planning and the audit programme10 h · Locked

      On completion you will be able to

      • Derive an audit programme from identified risks and document the rationale.
      • Prioritise audits against defined inputs and defend the priority order.
      • Scope an individual audit and state what is out of scope and why.
      • Produce a coverage statement that would survive a regulator's challenge.
      • Determine which audit type is the right instrument for a described concern.
  4. Module 4

    P-M4

    1 lesson · 6 h

    1. Locked.Vendor qualification and service provider oversight6 h · Locked

      On completion you will be able to

      • Distinguish vendor qualification from vendor audit and state when each is required.
      • Apply the §3.6.4 default rule to a transfer-of-responsibility matrix and identify which activities the sponsor has retained.
      • Extend an oversight assessment to subcontracted activity under §3.6.9.
      • Assess a shared or consortium audit report for sufficiency.
  5. Module 5

    P-M5

    1 lesson · 12 h

    1. Locked.Conducting a site audit12 h · Locked

      On completion you will be able to

      • Prepare, open, conduct and close a site audit against a defined scope.
      • Gather evidence sufficient to support a finding after the auditor has left the room.
      • Interview without leading, and handle the anxious, hostile and over-helpful interviewee.
      • Identify consent, eligibility, source, IP and delegation defects from a document set.
      • Apply the preserve/document/escalate discipline on encountering suspected data manipulation, and state what the auditor must not do.
  6. Module 6

    P-M6

    1 lesson · 9 h

    1. Locked.Service provider, system and process audits9 h · Locked

      On completion you will be able to

      • Scope a service provider audit from the agreement's transferred activities.
      • Design a process audit that examines a process across studies rather than a study.
      • Explain why process audits detect systemic issues that site audits cannot.
      • Identify decentralised elements in a described trial and state the additional audit questions they raise.
  7. Module 7

    P-M7

    1 lesson · 7 h

    1. Locked.Document and TMF completeness audits7 h · Locked

      On completion you will be able to

      • Apply the Appendix C.3.1(a)–(n) essentiality test to records that appear on no list.
      • Conduct a TMF completeness audit against the essentiality test and the protocol, not against a reference model's zone list.
      • Test timeliness under C.2.5 and identify a retrospectively assembled file.
      • Request and assess the C.2.4 location record.
      • State the EU obligations on the clinical trial master file and its archiving.
  8. Module 8

    P-M8

    1 lesson · 9 h

    1. Locked.Audit reporting, grading and follow-up9 h · Locked

      On completion you will be able to

      • Write a finding in requirement / evidence / gap / risk form that survives challenge.
      • Apply a grading scheme consistently and identify grade inflation and deflation in a supplied report.
      • Distinguish the audit report from the audit certificate and state the circumstances in which a regulatory authority may seek the report.
      • Evaluate an auditee response and determine whether it closes the finding.
      • Select metrics that measure the audit function rather than count its output.
  9. Module 9

    P-M9

    1 lesson · 9 h

    1. Locked.Deviations, noncompliance and serious breach9 h · Locked

      On completion you will be able to

      • Classify an event across protocol deviation, important protocol deviation, noncompliance and serious noncompliance, citing the clause for each.
      • State who determines the criteria that make a deviation important.
      • Route a serious breach in the EU and the UK with the correct deadline and recipient, and explain why the two definitions differ.
      • Distinguish an EU Article 52 serious breach from an Article 53 unexpected event and an Article 54 urgent safety measure.
      • Identify sponsor-caused noncompliance under §3.12.1.
  10. Module 10

    P-M10

    1 lesson · 10 h

    1. Locked.Root-cause analysis and CAPA10 h · Locked

      On completion you will be able to

      • Conduct a root-cause analysis using a named method and state its limits.
      • Distinguish a cause from a contributing factor from a symptom.
      • Distinguish correction, corrective action and preventive action, and classify "retrained the coordinator" correctly.
      • Design an effectiveness check that measures effectiveness rather than completion, with a pre-specified success criterion.
      • Diagnose a CAPA system from its ageing and backlog data.
  11. Module 11

    P-M11

    1 lesson · 13 h

    1. Locked.Computerised systems, validation and data integrity13 h · Locked

      On completion you will be able to

      • Determine which instrument governs a described system — E6(R3) Annex 1 §4.3, 21 CFR part 11, or EudraLex Annex 11 — and justify it.
      • Assess a validation package for sufficiency against risk-based validation under Principle 9.3.
      • Review an audit trail as an audit technique and identify the four classic signals.
      • State E6(R3)'s data-integrity attributes correctly and distinguish them from ALCOA+.
      • Audit user provisioning, de-provisioning and segregation of duties.
  12. Module 12

    P-M12

    1 lesson · 12 h

    1. Locked.Regulatory inspections and inspection readiness12 h · Locked

      On completion you will be able to

      • Describe the inspection framework a trial is exposed to in the US, the EU and the UK, and identify what differs.
      • Assess an organisation's inspection readiness as a state and produce a gap list.
      • Plan the hosting of an inspection, including roles, request logging and internal debrief.
      • Draft a post-inspection response that commits to a root cause, an action, an effectiveness check and a date.
      • State what FDA's December 2025 BIMO guidance replaced.

Assessment

How the exam works

The exam is closed-book and multiple choice. Each attempt draws a fresh form to the domain weights above, so no two attempts are the same paper and no answer key circulates. The pass mark is 70% and is fixed — there is no curve, no quota and no adjustment by cohort.

Scoring is immediate. You are shown your overall result and, for every item, the option you chose, the correct option and the reasoning behind it — whether you passed or not. A failed attempt may be retaken after 90 days. The wait exists so a retake is a second attempt at the material rather than a second attempt at remembering the paper.

Forms are assembled to the blueprint above or not at all: where a domain cannot yet be sampled to that standard, the exam declines to start rather than issue an unbalanced paper. Your material and progress are never affected, and there is no time limit on when you sit.

Passing candidates are issued a certificate with a verification code. Anyone can check that code on our public verification page without an account and without contacting us.

Certifying authority

Signed by Dr. Diana Nieves Castro, MD

CASRAI’s certification programme is academically and medically directed by Dr. Diana Nieves Castro, MD, Programme Director, who sets the syllabus and blueprint for this credential and signs every certificate issued under it.

CASRAI has maintained the terminology and reporting standards of research administration for over a decade. It assumed leadership of the CRediT contributor-roles taxonomy in 2014 and carried it through to adoption as ANSI/NISO Z39.104-2022, now in use by publishers, funders and institutions worldwide. This examination is drawn from that body of work.

What the credential certifies: that its holder passed the CASRAI examination for this course on the date shown, scored against the blueprint and pass mark published above — verifiable by anyone, permanently, from the code on its face.

The ladder

Other levels of Clinical Research Quality Assurance & Audit

Levels are independent purchases. There is no prerequisite chain — sit whichever level matches the work you already do.

All CASRAI credentials

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →