Examples
Worked examples
- Is an instance
A Phase III multi-site trial's monitoring plan assigns a centralized monitor to review accumulating data weekly against pre-defined key risk indicators (KRIs) -- e.g., site-level protocol-deviation rate, screen-failure rate, and serious-adverse-event reporting timeliness -- and triggers a targeted on-site visit, with SDV focused on the flagged data points, only when a KRI crosses its threshold, rather than visiting every site on a fixed monthly schedule with full SDV.
- Is an instance
A sponsor defines quality tolerance limits (QTLs) under ICH E6(R2) Section 5.0.4 for a small number of trial-critical parameters (for example, the rate of missing primary-endpoint data) during trial planning; a QTL breach during conduct triggers a documented root-cause investigation and corrective action, independent of the routine site-visit schedule.
Counter-examples
Looks similar, but isn't
- Not an instance
Simply reducing on-site visit frequency or SDV sampling to cut cost, without a documented risk assessment identifying which data and processes are actually critical to safety or data reliability, is not risk-based monitoring -- it is reduced monitoring using RBM's vocabulary. ICH E6(R2) Section 5.0 requires the risk assessment and quality-management system underpinning a reduced-touch approach, not just the reduction itself.
- Not an instance
Using an electronic CTMS purely to schedule and log 100%-SDV on-site visits, with no centralized or statistical review of accumulating data and no risk-driven prioritization of which sites or data points get attention, is on-site monitoring conducted with digital tools -- not RBM. Buying monitoring software does not, by itself, make a monitoring approach risk-based; the methodology and the tooling are separate questions.
Editorial commentary
Risk-based monitoring (RBM) is a clinical trial monitoring approach that concentrates sponsor oversight resources on the risks most likely to affect participant safety and the reliability (quality) of trial data, rather than applying uniform, fixed-frequency on-site visits with 100% source data verification (SDV) at every site regardless of actual risk. It is a genuine methodological shift from traditional monitoring, not a relabeling of it: a sponsor using RBM builds a documented risk assessment into the monitoring plan itself, then mixes centralized/remote review, statistical risk indicators, and targeted on-site visits in proportion to that assessment.
RBM is formally recognized in the ICH E6 Good Clinical Practice guideline (Section 5.0 and 5.18 of the ICH E6(R2) addendum, carried forward with more explicit emphasis in E6(R3)) and was independently addressed by FDA in a 2013 guidance for industry. The clinical-research field increasingly refers to the broader discipline as risk-based quality management (RBQM), of which monitoring is one part; this entry focuses specifically on the monitoring function.
What makes something risk-based monitoring (operational definition)
A monitoring approach counts as risk-based, as opposed to traditional or merely digitized on-site monitoring, when it has all of the following:
- A documented risk assessment performed before the trial starts (and revisited during conduct) that identifies the trial-critical data and processes — the ones most likely to affect participant safety or the reliability of the trial’s results — as distinct from routine data that carries lower risk if imperfect.
- A monitoring plan tied to that assessment that sets out, and documents the rationale for, the specific mix of on-site, centralized, and combined monitoring the sponsor will use (ICH E6(R2) Section 5.18.3), rather than a single fixed cadence applied uniformly across all sites and data.
- Ongoing, data-driven adjustment — the monitoring intensity for a given site or data point changes as accumulating data reveals new risk signals, rather than staying fixed for the life of the trial.
A monitoring plan that simply reduces visit frequency or SDV sampling to save cost, without the risk assessment and rationale behind it, does not meet this bar — see the counter-examples below.
Key components of an RBM approach
Most RBM implementations combine four elements, though the specific mix is trial-specific and should be documented in the monitoring plan:
- Risk assessment and categorization. Before the trial starts, the sponsor identifies which data points and trial processes are “critical” — most likely to affect participant safety or the reliability of results — versus lower-risk data that does not warrant the same scrutiny. This assessment drives everything else in the plan.
- Centralized (remote) monitoring. Defined in ICH E6(R2) Section 5.18.3 as a remote evaluation of accumulating data, performed in a timely manner by appropriately qualified staff (data managers, biostatisticians, medical monitors). It allows near-real-time review across all sites at once — identifying missing or inconsistent data, unusual trends, outlier sites or investigators, and data patterns that would be difficult or impossible for any single on-site visit to surface.
- Statistical monitoring: key risk indicators (KRIs) and quality tolerance limits (QTLs). Centralized monitoring is typically operationalized through KRIs — metrics such as enrollment rate, protocol-deviation rate, query rate, or adverse-event reporting timeliness, tracked per site and compared against expected ranges or peer sites — and QTLs, pre-defined thresholds for a small number of trial-critical parameters (ICH E6(R2) Section 5.0.4) whose breach triggers a formal, documented investigation and corrective action. TransCelerate BioPharma’s 2013 RBM methodology position paper was an influential early industry framework for operationalizing KRIs and centralized/off-site monitoring at scale, and much of that vocabulary persists in current sponsor SOPs and RBM software.
- Targeted, adaptive on-site visits. Rather than a fixed schedule of full-SDV visits to every site, on-site monitoring is triggered or prioritized by what centralized/statistical monitoring flags, and SDV during a visit is focused on the specific data points or processes the risk assessment and accumulating data indicate are worth verifying in person — not exhaustive review of every source document.
Why RBM emerged: cost, efficiency, and the evidence on 100% SDV
Traditional monitoring — a fixed schedule of on-site visits performing 100% SDV against every case report form entry — became one of the largest cost drivers in clinical trial conduct as trial size and complexity grew, without a correspondingly strong evidence base that it actually delivered better data quality. Neither ICH E6 nor FDA’s own GCP-related guidance has ever mandated 100% SDV; industry practice adopted it as a de facto default well beyond what regulation required.
FDA’s 2013 guidance, Oversight of Clinical Investigations — A Risk-Based Approach to Monitoring (issued August 2013), made the regulatory rationale explicit: it encourages sponsors to focus monitoring resources and methods on preventing or mitigating important and likely risks to data quality and to human subject protection, and states that monitoring approaches beyond on-site visits can lead to increased quality of clinical trial oversight. A subsequent FDA Q&A guidance on the same topic (finalized April 2023) reinforced and expanded that position. Independent literature has since examined the evidence base directly: a 2024 scoping review of SDV quality research found no absolute measures establishing that 100% SDV reliably produces error-free data, noted that manual SDV is itself prone to human error in the same way as the record abstraction it checks, and concluded that reference data on SDV’s actual accuracy is still needed to confidently calibrate reduced-SDV, risk-based processes — meaning the regulatory shift toward RBM proceeded on cost and efficiency grounds and a reasoned risk-management rationale, more than on a settled evidence base proving reduced SDV preserves data quality outright.
RBM in regulation: FDA guidance and ICH E6
- 2013 — TransCelerate BioPharma publishes its RBM methodology position paper (June 2013), an influential industry framework for centralized/off-site monitoring and KRIs, independent of any single regulator.
- 2013 — FDA issues its final guidance, Oversight of Clinical Investigations — A Risk-Based Approach to Monitoring: Guidance for Industry (August 2013), the primary US regulatory articulation of RBM for FDA-regulated drug, biologic, and device trials.
- 2016 — The ICH E6(R2) addendum to Good Clinical Practice formally incorporates risk-based monitoring and a broader risk-based quality management framework (new Section 5.0, revised Section 5.18), making it part of the internationally harmonized GCP standard rather than a US-specific position.
- 2023 — FDA finalizes a Q&A guidance elaborating on planning, monitoring-plan content, and communicating results under the 2013 guidance.
- 2025 — ICH E6(R3) is finalized (ICH Step 4, January 2025), restructuring GCP around principles and annexes and placing more explicit emphasis on risk-based quality management and appropriate use of technology than the R2 addendum.
RBM platforms and software: what the category generally does
“Risk-based monitoring software” is a real, searched category, but it describes a set of capabilities layered on top of an RBM methodology, not a single defined product type — and buying the software does not by itself make a monitoring approach risk-based (see the counter-examples above). At a category level, RBM platforms and RBQM modules (offered standalone, bundled into a clinical trial management system (CTMS), or as an add-on to an EDC/CDMS) generally provide some combination of:
- KRI dashboards that aggregate and visualize site- and trial-level risk indicators (enrollment, deviations, queries, safety-reporting timeliness) pulled from EDC, CTMS, safety, and other trial data sources, typically refreshed on a recurring (often near-real-time) cycle.
- Statistical/analytics-driven signal detection — automated flagging of outlier sites, data anomalies, or trends outside expected ranges, sometimes using more advanced statistical or machine-learning techniques to surface issues a manual review would miss.
- QTL tracking and threshold alerting against the trial’s pre-defined quality tolerance limits, with workflow support for the root-cause-investigation and corrective-action documentation ICH E6(R2) expects when a QTL is breached.
- Risk assessment and monitoring-plan documentation tools that help build and maintain the risk assessment and the resulting monitoring plan as living, auditable documents rather than a static PDF written once at trial start.
- Visit and SDV-sample management that connects the flagged risk signals to which sites need a targeted on-site visit next, and which specific data points a monitor should prioritize for SDV during that visit, rather than an undifferentiated full-record review.
CASRAI does not evaluate or rank specific commercial products; the capabilities above describe what the category is generally built to do, not any particular vendor’s implementation.
Related CASRAI resources
- ICH GCP (Good Clinical Practice) — the standard formally incorporating risk-based monitoring into GCP via the E6(R2) addendum and E6(R3).
- Clinical Research Associate (CRA) — the role that performs the monitor function RBM reallocates across centralized and on-site activities.
- Clinical Trial Management System (CTMS) — the operational system that commonly hosts or integrates RBM/RBQM dashboards and visit tracking.
- Clinical Data Management: Processes, Systems, and Standards — the broader data-management discipline that centralized/statistical monitoring draws its accumulating-data review from.
- Pharmacovigilance in Clinical Research — adverse-event and SAE reporting timeliness is a common key risk indicator in RBM monitoring plans.
- Clinical Trial Supply Management — investigational-product accountability, a critical data area under most trials’ risk assessments.
- Clinical Research Administration — cluster hub for CASRAI’s clinical-research content.
Frequently asked questions
Is risk-based monitoring the same as remote or centralized monitoring?
No — centralized/remote monitoring is one component of RBM, not a synonym for it. RBM is the overall risk-driven methodology; a sponsor can use centralized monitoring alongside on-site visits, or in some justified cases rely on centralized monitoring only, but the defining feature of RBM is that the mix is chosen based on a documented risk assessment, not that any particular activity happens off-site.
Does RBM mean sponsors do less monitoring overall?
Not necessarily less monitoring — differently allocated monitoring. Lower-risk sites and data points may see reduced on-site frequency and SDV sampling, but higher-risk signals identified through centralized/statistical monitoring can trigger more frequent or intensive on-site attention than a fixed traditional schedule would have provided. The goal, per FDA’s 2013 guidance, is focusing resources on the risks most likely to affect data quality and human subject protection, not a blanket reduction.
Does ICH E6 or FDA require 100% source data verification?
No. Neither ICH E6 nor FDA’s GCP-related guidance has ever mandated 100% SDV; it became a de facto industry default beyond what regulation required. ICH E6(R2) and FDA’s 2013 and 2023 guidances both explicitly support risk-based, less-than-100% SDV approaches when justified by the trial’s risk assessment.
Is RBM only relevant to large pharmaceutical sponsors?
No. ICH E6(R2)/(R3) and FDA’s guidance apply to any sponsor of an ICH-region or FDA-regulated clinical investigation, including academic and investigator-initiated trials, though the scale of centralized-monitoring infrastructure a sponsor builds or buys typically does scale with trial size, complexity, and available resources.
What is the difference between RBM and risk-based quality management (RBQM)?
RBQM is the broader discipline — applying risk-based thinking to the trial’s overall quality management system, including protocol design, data management, and site oversight. RBM specifically refers to the monitoring function within that broader system: how monitoring resources (centralized, remote, and on-site) are allocated based on risk.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Risk-Based Monitoring (RBM)"
vocab-term-identifier="https://casrai.org/dictionary/term/risk-based-monitoring-rbm" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/risk-based-monitoring-rbm",
"name": "Risk-Based Monitoring (RBM)",
"identifier": "https://casrai.org/dictionary/term/risk-based-monitoring-rbm",
"description": "Risk-based monitoring (RBM) is a clinical trial monitoring methodology, formally incorporated into ICH E6(R2)/(R3) Good Clinical Practice and described in FDA's 2013 guidance for industry, in which a sponsor allocates monitoring resources -- the mix of centralized, remote, and on-site activities, and the extent of source data verification (SDV) -- according to a documented, protocol-specific risk assessment of what is most likely to affect participant safety and the reliability of trial results. It replaces the older default of fixed-frequency on-site visits with 100% SDV at every site, regardless of actual risk, with a monitoring plan that is proportionate to identified risk and revisited as the trial progresses.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/risk-based-monitoring-rbm",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-17T06:45:56",
"inLanguage": "en"
}






