Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthWholesale & Retail Medical SupplyMedical supplies, delivered.79,000+ SKUs. Ships in 48h from 8 U.S. hubs. Net-30 for verified accounts.Shop lac.us lac.us

Clinical Trial Auditing: Types, Process, and How It Differs From Monitoring

How clinical trial audits differ from routine monitoring and regulatory inspection, who conducts them, the main audit types, and how sponsor auditing relates to FDA’s BIMO program.

A clinical trial audit is a systematic, independent examination of trial-related activities and documents to determine whether the trial was conducted, and the data recorded, analyzed, and reported, in compliance with the protocol, the sponsor’s standard operating procedures (SOPs), Good Clinical Practice (GCP), and the applicable regulatory requirements. Audits are a required element of a sponsor’s quality assurance (QA) system under ICH E6(R2) Section 5.19, and they are distinct from routine clinical trial monitoring and from a regulatory authority’s own inspection — three related but separate quality-oversight functions that are frequently confused with one another.

This guide covers what a clinical trial audit is, how it differs from monitoring and inspection, who conducts audits and how independence is maintained, the main audit types, what an audit covers and how findings are handled, and how sponsor auditing relates to FDA’s Bioresearch Monitoring (BIMO) program.

Audit vs. Monitoring vs. Inspection

These three terms describe different oversight functions performed by different parties, at different points, for different purposes. Conflating them is a common source of confusion in trial quality documentation.

  • Monitoring is the sponsor’s own ongoing, routine oversight of trial conduct at a site, typically performed at intervals throughout the trial by a Clinical Research Associate (CRA) — the role ICH E6(R2) Section 1.38 defines functionally as the "monitor." Its purpose is to verify that the rights and well-being of subjects are protected, reported data are accurate and verifiable against source documents, and the trial is conducted per protocol, SOPs, GCP, and applicable regulations. Monitoring is continuous and operational, not periodic and independent — see the Clinical Trial Monitoring guide for visit types, source data verification, and risk-based monitoring in depth.
  • Auditing is a periodic, systematic, and independent evaluation of trial conduct and the trial’s quality systems, typically performed by a sponsor’s quality assurance function (or a contracted independent auditor) who is not otherwise involved in the routine conduct or monitoring of the trial. An audit looks at whether the systems and processes that produced the data are sound, not just whether an individual data point matches source documentation.
  • Inspection is a regulatory authority’s official, external review of trial-related documents, facilities, records, and other resources — conducted at the investigator site, sponsor, CRO, or IRB/IEC location, at any point during or after the trial. In the United States this function sits within FDA’s Bioresearch Monitoring (BIMO) program, discussed below.

All three functions draw on the same underlying record: the Trial Master File and site regulatory binder (the Trial Master File), built from what ICH E6(R2) Section 8 calls essential documents — those documents which individually and collectively permit evaluation of trial conduct and data quality. A well-run audit function is, in practice, the sponsor’s own rehearsal for a regulatory inspection: the same files, the same traceability expectations, and often the same kinds of findings.

Who Conducts Clinical Trial Audits

ICH E6(R2) Section 5.19.1 requires the sponsor to designate individuals independent of the clinical trial/systems involved to conduct audits, as part of implementing quality assurance. Independence is the defining structural requirement: an auditor should not be someone who monitored the trial, managed the site relationship, or otherwise had operational responsibility for the activity being audited, so that the audit function is a genuine check on the quality system rather than a self-review by the people who built it.

In practice, audits are conducted by:

  • Sponsor internal QA/audit departments — most large pharmaceutical and biotech sponsors maintain a dedicated GCP quality assurance function structurally separate from clinical operations, reporting through a different line of authority.
  • Independent contracted auditors or specialist audit firms — used by sponsors without in-house audit capacity, or to supplement internal QA for specialized areas (e.g., computer systems validation, pharmacovigilance, biostatistics).
  • A Contract Research Organization (CRO)‘s own QA function, when a sponsor has transferred trial conduct duties to a CRO — but ultimate responsibility for trial data quality and integrity always remains with the sponsor regardless of what has been delegated, so many sponsors also retain the right to audit the CRO itself, and often exercise it.

Types of Clinical Trial Audits

Audits are commonly categorized by trigger and scope rather than by a single regulatory taxonomy — ICH E6(R2) does not itself name discrete audit "types," but the following categories are standard industry practice for how a sponsor’s audit plan is organized:

  • Routine (scheduled/risk-based) audits — planned as part of the sponsor’s audit plan, typically selected using risk-based criteria. ICH E6(R2) Section 5.19.3(b) specifies that the sponsor’s audit plan and procedures should be guided by the importance of the trial to submissions to regulatory authorities, the number of subjects, the type and complexity of the trial, the level of risk to trial subjects, and any identified problem(s) — not a fixed schedule applied uniformly across every trial or site.
  • For-cause audits — triggered by a specific concern: a data-integrity red flag, a safety signal, a whistleblower complaint, repeated protocol deviations at a site, or findings from monitoring that suggest a systemic rather than isolated problem. These are typically unscheduled and scoped tightly to the concern that triggered them.
  • Pre-approval/pre-submission audits — conducted before a marketing application (e.g., an NDA/BLA submission to FDA) to confirm the pivotal trial’s data and documentation will withstand regulatory scrutiny, functioning as a deliberate readiness check ahead of the regulatory authority’s own pre-approval inspection.
  • System/vendor audits — scoped to a specific system or service provider rather than a trial or site as a whole: a CRO, a central laboratory, an electronic data capture (EDC) platform, an IRT/RTSM vendor, or a computerized system’s validation documentation.
  • IRB/IEC and site audits — less common than sponsor-initiated site audits, but sponsors and regulators alike may audit or inspect an Institutional Review Board / Independent Ethics Committee’s own records and procedures.

What an Audit Covers

Scope varies by audit type and trigger, but a trial-level audit commonly examines: informed consent documentation and process (see the CASRAI Informed Consent Form worked example for what these records look like in practice); protocol adherence and documented deviations; source data and Case Report Form (CRF) accuracy and traceability; investigational product accountability (receipt, storage, dispensing, return/destruction records); adverse event identification, assessment, and reporting timeliness; IRB/IEC approval and continuing-review documentation; and the completeness of essential documents in the Trial Master File against ICH E6(R2) Section 8’s requirements. A quality-systems-level audit (as opposed to a trial-level audit) looks further upstream: whether SOPs exist, are current, and are actually being followed; whether staff training records are complete; and whether corrective actions from prior audits were actually implemented.

Audit Findings and Follow-Up

Audit findings are typically documented in a formal audit report, classified by severity (commonly critical, major, and minor, though exact category labels vary by sponsor SOP), and routed into a Corrective and Preventive Action (CAPA) process. Unlike a regulatory inspection, an internal sponsor audit report and its underlying findings are generally treated as confidential quality-assurance work product rather than a document routinely shared with the investigator site or submitted to a regulatory authority — though the sponsor may still be required to produce audit certificates (confirming that an audit took place) if a regulatory authority requests them, and ICH E6(R2) draws an explicit distinction between the audit process itself and the routine trial-related documents that ARE reviewable by regulators.

Sponsor Audits and FDA’s BIMO Program

FDA’s Bioresearch Monitoring (BIMO) Program is the regulatory-inspection counterpart to sponsor auditing: a comprehensive program of on-site inspections and data audits covering clinical investigators (GCP), sponsors/CROs/monitors, IRBs, nonclinical testing laboratories (GLP), bioequivalence facilities, and postmarketing safety reporting. Its purpose is to assure the quality and integrity of data submitted to FDA in support of marketing applications and to confirm protection of human subjects’ rights and welfare.

FDA clinical-investigator-site inspections under BIMO are generally either routine (the most common type, often triggered by a marketing-application submission or high enrollment in a pivotal trial, typically announced with the agency contacting the investigator to schedule) or for-cause (triggered by a specific complaint, safety signal, or data-integrity concern, and may involve minimal or no advance notice). Inspection outcomes are classified into one of three tiers under FDA’s standard inspection-classification system, which applies across BIMO the same way it applies to other FDA inspection programs: No Action Indicated (NAI) (no objectionable conditions found), Voluntary Action Indicated (VAI) (objectionable conditions found, but not warranting regulatory/administrative action — typically accompanied by an FDA Form 483 listing observations), and Official Action Indicated (OAI) (a compliance state serious enough to warrant regulatory or administrative action, which for a clinical investigator can escalate toward disqualification proceedings). See the CASRAI Inspection Readiness entry for more on how essential-document completeness and inspection classification interact.

A sponsor’s own audit program is, functionally, both a compliance obligation in its own right and a form of inspection preparedness: an organization whose internal QA audits routinely find and correct the same categories of problem an FDA BIMO inspector would look for is far less likely to receive an OAI classification when the real inspection happens.

Frequently Asked Questions

What is the difference between clinical trial monitoring and a clinical trial audit?

Monitoring is the sponsor’s own continuous, operational oversight of trial conduct, typically performed by a CRA throughout the trial. Auditing is a periodic, independent, systematic evaluation — usually performed by a sponsor’s quality assurance function, structurally separate from the people who monitor or manage the trial — that assesses whether the trial’s quality systems and documented conduct actually meet GCP, protocol, and regulatory requirements.

Who is required to conduct clinical trial audits?

ICH E6(R2) requires the sponsor to implement a quality assurance system that includes audits, conducted by individuals independent of the trial’s clinical conduct and monitoring. This can be an internal sponsor QA department, an independent contracted auditor, or a CRO’s own QA function when trial duties have been delegated — but responsibility for the trial’s overall data quality and integrity always remains with the sponsor.

Is an FDA inspection the same thing as an audit?

No. An audit is conducted by or on behalf of the sponsor, as part of the sponsor’s own quality system, and its findings are generally treated as internal. An inspection is conducted by a regulatory authority (in the US, under FDA’s BIMO program) and can result in official inspection classifications (NAI/VAI/OAI) and public enforcement documents such as an FDA Form 483.

What triggers a for-cause audit?

A for-cause audit is typically triggered by a specific concern rather than run on a routine schedule — examples include a data-integrity red flag, a safety signal, a complaint (including from staff), or a pattern of protocol deviations or monitoring findings serious enough to suggest a systemic problem rather than an isolated one.

What happens after an audit finds a problem?

Findings are typically documented in a formal audit report, classified by severity, and addressed through a Corrective and Preventive Action (CAPA) process. Sponsors generally treat audit reports themselves as confidential quality-assurance records rather than documents routinely shared with the site or filed with regulators, though audit certificates confirming an audit occurred may be requested by a regulatory authority.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →