Skip to main content
v2026.11,610 entries · CC-BY 4.0

ICH E6(R3) Definitions: Audit, Inspection, Monitoring and Quality Assurance

What ICH E6(R3) actually says an audit, an inspection, monitoring and quality assurance are — each definition quoted verbatim from the Step 4 Glossary — then the distinction that matters in practice: who performs it, on whose authority, and what the output obliges. Includes a word-level cross-walk to the E6(R2) text still quoted across much of the web, and a map from R2 section numbers to their E6(R3) Annex 1 replacements.

Ask about ICH E6(R3) Definitions: Audit, Inspection, Monitoring and Quality Assurance

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

Version and date this page describes: every definition quoted below is from the ICH E6(R3) Guideline for Good Clinical Practice, the Step 4 final text adopted 6 January 2025 (Principles and Objectives plus Annex 1). Where the wording differs from ICH E6(R2) (the 2016 integrated addendum), both versions are shown side by side. Which one is legally operative depends on your region — see Which version actually applies to you. Last verified against the primary text on 26 August 2026.

According to ICH E6(R3), an audit is defined as

"A systematic and independent examination of trial-related activities and records performed by the sponsor, service provider (including contract research organisation (CRO)) or institution to determine whether the evaluated trial-related activities were conducted and the data were recorded, analysed and accurately reported according to the protocol, applicable standard operating procedures (SOPs), Good Clinical Practice (GCP) and the applicable regulatory requirement(s)."

— ICH E6(R3) Guideline, Glossary, entry "Audit" (Step 4 text, 6 January 2025)

Three things in that sentence do the work, and each of them is load-bearing when you are deciding whether an activity in front of you is actually an audit:

  • "Systematic and independent" — independence is structural, not attitudinal. Annex 1 §3.11.2.1(a) requires the sponsor to appoint individuals "who are independent of the clinical trial/processes being audited." Someone who monitored the site, managed the vendor relationship or wrote the SOP being examined cannot audit it, however rigorous they are.
  • "Performed by the sponsor, service provider (including CRO) or institution" — this clause is new in R3. E6(R2) named no performer at all, which left academic and investigator-initiated settings arguing about whether an institution-run examination counted. R3 settles it: an institution’s own quality unit auditing its trial-related activities is an audit under the guideline.
  • "Trial-related activities and records" — R2 said "activities and documents." The change to "records" is the same technology-neutral move E6(R3) makes throughout (its "essential records" reframing in Appendix C is the other example). An audit scope that is written around a document list rather than around records is scoped to the superseded wording.

What the definition does not say matters too. Nothing in E6(R3) makes a sponsor audit mandatory. Annex 1 §3.11.2 opens "When performed, audits should be conducted in a manner that is proportionate to the risks associated with the conduct of the trial" — a conditional, exactly as E6(R2) §5.19 was conditional ("If or when sponsors perform audits, as part of implementing quality assurance, they should consider"). What is mandatory under §3.11 is the quality assurance and quality control system itself; the audit is one instrument inside it, deployed where risk warrants.

Audit, inspection, monitoring and quality assurance — the four E6(R3) definitions side by side

All four sit in the Glossary at the end of the E6(R3) Guideline, which serves the Principles document and Annex 1 together.

Term ICH E6(R3) Glossary definition (verbatim)
Audit "A systematic and independent examination of trial-related activities and records performed by the sponsor, service provider (including contract research organisation (CRO)) or institution to determine whether the evaluated trial-related activities were conducted and the data were recorded, analysed and accurately reported according to the protocol, applicable standard operating procedures (SOPs), Good Clinical Practice (GCP) and the applicable regulatory requirement(s)."
Inspection "The act by a regulatory authority(ies) of conducting an official review of documents, facilities, records and any other resources that are deemed by the authority(ies) to be related to the clinical trial and that may be accessed at the investigator site, at the sponsor’s and/or service provider’s (including CRO’s) facilities, or at other establishments deemed appropriate by the regulatory authority(ies). Some aspects of the inspection may be conducted remotely."
Monitoring "The act of overseeing the progress of a clinical trial and of ensuring that the clinical trial is conducted, recorded and reported in accordance with the protocol, SOPs, GCP and the applicable regulatory requirement(s)."
Quality Assurance (QA) "All those planned and systematic actions that are established to ensure that the trial is performed and the data are generated, documented (recorded) and reported in compliance with GCP and the applicable regulatory requirement(s)."
Quality Control (QC) "The operational techniques and activities undertaken to verify that the requirements for quality of the trial-related activities have been fulfilled."

Three supporting Glossary entries are frequently needed alongside these and are quoted here so the set is complete:

  • Audit Certificate — "A declaration of confirmation by the auditor that an audit has taken place."
  • Audit Report — "A record describing the conduct and outcome of the audit."
  • Monitoring Report — "A documented report following site and/or centralised monitoring activities."

The distinction that actually matters: who performs it, on whose authority, what the output obliges

Audit and inspection are routinely used interchangeably in trial documentation, and the substitution is never harmless: the two run on different authority and produce outputs with entirely different legal weight. Monitoring is a third thing again, and E6(R3) is more explicit than R2 about where it sits.

Dimension Monitoring Audit Inspection
Who performs it The sponsor’s monitor (commonly a CRA), or a delegated CRO. E6(R3) §3.11.4 adds that centralised monitoring activities may be performed "by different methods and persons with different roles (e.g., data scientist)" The sponsor, a service provider (including a CRO) or the institution — per the R3 definition. Must be someone independent of the trial or processes being audited (§3.11.2.1(a)) A regulatory authority — and only a regulatory authority. No private party can conduct an inspection in the E6 sense
On whose authority The sponsor’s own quality system and monitoring plan. Contractual, not statutory The sponsor’s (or institution’s) own quality assurance system, documented in its own procedures (§3.11.2.2(a)) Statutory inspection powers of the authority, exercised under national law. The investigator/institution must permit it (§2.3.5)
Where it sits in the quality system Quality control. E6(R3) §3.11.4 states plainly: "Monitoring is one of the principal quality control activities" Quality assurance. §3.11.2 places audit under QA and requires it to be "independent of and separate from routine monitoring or quality control functions" Outside the sponsor’s quality system entirely — it is an external check on that system
What it examines Trial progress and conduct as it happens — site communication, staff qualifications, site resources, source data review and verification, data analytics, site visits (§3.11.4) "Whether the processes put in place to manage and conduct the trial are appropriate" (§3.11.2). Systems, not individual data points "Documents, facilities, records and any other resources" the authority deems related to the trial — at the site, the sponsor, a service provider, or elsewhere
Output A monitoring report; issues resolved operationally at the site, usually in near-real time An audit report ("a record describing the conduct and outcome of the audit"), plus an audit certificate where regulation requires one (§3.11.2.2(e)) The authority’s own findings, in whatever instrument its law provides (in the US, e.g., an FDA Form 483 and any subsequent letter)
What the output obliges Correction of the specific finding; escalation if it suggests a systemic problem Evaluation at systems level, typically feeding CAPA. Critically, the report stays inside the sponsor: §3.11.2.2(d) says regulatory authorities "should not routinely request the audit reports" A regulated response on the authority’s timetable, with enforcement consequences available to the authority if it is inadequate
Can it be remote? Yes — "site monitoring (performed on-site and/or remotely) and centralised monitoring" (§3.11.4) Yes — §3.11.2.2(a) now requires procedures covering "how to audit (i.e., on-site and/or remote)" Yes — the R3 definition adds "Some aspects of the inspection may be conducted remotely." R2’s definition did not

The audit-report shield, and its limit

The single most consequential practical difference between audit and inspection is what happens to the paperwork. E6(R3) §3.11.2.2(d) reads:

"To preserve the independence and value of the audit function, the regulatory authority(ies) should not routinely request the audit reports. Regulatory authority(ies) may seek access to an audit report on a case-by-case basis (i.e., when evidence or suspicion of serious GCP noncompliance exists or in the course of legal proceedings)."

The emphasis is ours, and it is the change: E6(R2) §5.19.3(d) said "when evidence of serious GCP non-compliance exists." R3 adds suspicion. The threshold at which an authority may reach for your audit reports is now lower and more subjective than it was under R2, and any internal policy that quotes the R2 threshold back to an inspector is quoting a superseded text. Note also that the guideline never protects the audit certificate: §3.11.2.2(e) requires the sponsor to provide one where applicable regulatory requirements demand it.

The access clause that separates all three

E6(R3) Annex 1 §2.3.5 states the whole hierarchy in one line: the investigator/institution "should permit monitoring and auditing by the sponsor, inspection by the appropriate regulatory authority(ies) and, in accordance with applicable regulatory requirements, review by IRB/IEC(s)." Four oversight functions, three different sources of authority. If you need one sentence for an SOP or a site training deck, that is the one.

What changed from E6(R2): a word-level cross-walk

Much published material still reproduces the E6(R2) wording and section numbers — often without saying which version it is quoting. The differences are small in word count and real in effect. The R2 column below is quoted from the E6(R2) integrated addendum (Step 4, 9 November 2016).

Term E6(R2) E6(R3) What actually changed
Audit §1.6 — "…examination of trial related activities and documents… according to the protocol, sponsor’s standard operating procedures (SOPs)…" Glossary — "…examination of trial-related activities and records performed by the sponsor, service provider (including CRO) or institution… according to the protocol, applicable standard operating procedures (SOPs)…" Performer named explicitly for the first time; "documents" becomes "records"; the SOPs measured against are no longer only the sponsor’s
Inspection §1.29 — "…may be located at the site of the trial, at the sponsor’s and/or contract research organization’s (CRO’s) facilities…" Glossary — "…may be accessed at the investigator site, at the sponsor’s and/or service provider’s (including CRO’s) facilities… Some aspects of the inspection may be conducted remotely." Remote inspection is contemplated for the first time; scope widens from CROs to any service provider
Monitoring §1.38 Glossary Substantively unchanged — punctuation and "it" to "the clinical trial" only. The classification changed, not the definition (see below)
Quality Assurance §1.46 Glossary Unchanged
Quality Control §1.47 — "operational techniques and activities undertaken within the quality assurance system to verify…" Glossary — "operational techniques and activities undertaken to verify…" QC is no longer defined as nested inside QA; the two are set out as parallel processes under §3.11
Audit Report §1.8 — "A written evaluation by the sponsor’s auditor of the results of the audit." Glossary — "A record describing the conduct and outcome of the audit." No longer necessarily written, no longer necessarily the sponsor’s — consistent with the widened set of performers
Audit Trail §1.9 — "Documentation that allows reconstruction of the course of events." Glossary — "Metadata records that allow the appropriate evaluation of the course of events by capturing details on actions (manual or automated)… should show activities, initial entry and changes to data fields or records, by whom, when and, where applicable, why. In computerised systems, the audit trail should be secure, computer-generated and time stamped." The largest single expansion of the four-word R2 entry — an audit trail is now defined as metadata with named attributes, which is what makes it testable
Monitoring Report §1.39 — "A written report from the monitor to the sponsor after each site visit…" Glossary — "A documented report following site and/or centralised monitoring activities." Centralised monitoring becomes a first-class reportable activity rather than an exception to a visit-based model

The classification change that R2 readers miss

The monitoring definition barely moved, but where monitoring sits did. E6(R2) §5.1.3 said only that "quality control should be applied to each stage of data handling." E6(R3) §3.11.3 says: "Within clinical trials, monitoring and data management processes are the main quality control activities." That is an explicit statement, absent from R2, that monitoring is QC — which is precisely why §3.11.2 can then require the audit to be "independent of and separate from routine monitoring or quality control functions." Under R3 the QA/QC line is drawn through the org chart, not through the thoroughness of the review.

Where these obligations live in E6(R3), and the R2 references they replace

E6(R3) is a different document, not a re-edit: an Introduction, eleven numbered Principles, then Annex 1 containing section 1 (IRB/IEC), 2 (Investigator), 3 (Sponsor) and 4 (Data governance), followed by Appendices A–C and the Glossary. Any SOP cross-reference written against an R2 section number now points at nothing. The mapping for this subject area:

Subject E6(R2) E6(R3)
Definitions of audit, inspection, monitoring, QA, QC §1.6, 1.29, 1.38, 1.46, 1.47 (numbered glossary at the front) Glossary, unnumbered and alphabetical, at the end of the guideline
Sponsor duty to run QA and QC §5.1.1 Annex 1 §3.11
Quality assurance as a risk-based activity — (no direct equivalent) Annex 1 §3.11.1
Audit — purpose and independence §5.19, §5.19.1 Annex 1 §3.11.2
Selection and qualification of auditors §5.19.2 Annex 1 §3.11.2.1
Auditing procedures, report access, audit certificate §5.19.3 Annex 1 §3.11.2.2
Quality control §5.1.3 Annex 1 §3.11.3
Monitoring §5.18 Annex 1 §3.11.4
Permitting monitoring, audit, inspection and IRB/IEC review §4.1.4 / §5.1.2 (direct access) Annex 1 §2.3.5; direct access to source records at Appendix B.11
Audit trail expectations in computerised systems §5.5.3 (addendum) Annex 1 §4.2.2 ("Relevant Metadata, Including Audit Trails")

Two smaller drafting changes are worth carrying into an SOP rewrite. R3 §3.11.2.1 drops R2’s separate sentence "An auditor’s qualifications should be documented" while keeping the qualification requirement itself; and R3 §3.11.2.2(b) speaks of the sponsor’s "audit plan, program and procedures" and prefixes its risk factors with "for example," where R2 §5.19.3(b) presented the same list without that qualifier.

Which version actually applies to you right now

ICH Step 4 adoption is not an effective date anywhere. Each ICH regulatory member adopts a guideline on its own timetable, so "is E6(R3) in force?" has a different answer per region, and a different answer again for Annex 2:

Region / body Status of E6(R3) Date
ICH (global) Principles and Objectives plus Annex 1 reached Step 4 6 January 2025
ICH (global) Annex 2 (pragmatic, decentralised and real-world-data trials) reached Step 4 3 June 2026
European Union (EMA/CHMP) Principles and Annex 1 in effect as the operative GCP guideline 23 July 2025
European Union (EMA/CHMP) Annex 2 adopted by CHMP; comes into effect later Adopted 25 June 2026; effective 15 January 2027
United States (FDA) Final guidance for industry issued. FDA guidance states current recommendations and is non-binding by design; no fixed US compliance date was set analogous to the EU effective date Guidance posted 8 September 2025
Canada (Health Canada) Adopted with a transition period Effective 1 April 2026; transition to 30 September 2026; full compliance from 1 October 2026

The EU dates above were re-verified directly against EMA’s ICH E6 scientific-guideline page on 26 August 2026. The ICH, FDA and Health Canada rows are carried from CASRAI’s regional adoption table for E6(R3), last verified 16 August 2026. Adoption in several regions is still moving; confirm against ich.org or the relevant regulator before relying on any date for a specific submission. For regions not listed — including the UK, Japan, Switzerland and the many national authorities that reference ICH GCP without being ICH members — check the national regulator directly rather than assuming the EU date carries.

The practical consequence for definitions specifically: on a trial running in the EU, quoting E6(R2) §1.6 for what an audit is means quoting a text that has not been the operative EU guideline since July 2025. On an FDA-regulated trial the same quotation is not wrong — FDA’s E6(R3) guidance is non-binding and R2 was never itself binding either — but it is out of step with the agency’s stated current expectation.

Frequently asked questions

According to ICH E6(R3), what is an audit?

"A systematic and independent examination of trial-related activities and records performed by the sponsor, service provider (including contract research organisation (CRO)) or institution to determine whether the evaluated trial-related activities were conducted and the data were recorded, analysed and accurately reported according to the protocol, applicable standard operating procedures (SOPs), Good Clinical Practice (GCP) and the applicable regulatory requirement(s)." The definition sits in the Glossary of the E6(R3) Guideline; the sponsor’s obligations around auditing are in Annex 1 §3.11.2.

What is the difference between an audit and an inspection in GCP?

An audit is conducted by the sponsor, a service provider or the institution, under its own quality assurance system, and produces an audit report that regulators "should not routinely request." An inspection is conducted by a regulatory authority under statutory powers, over any documents, facilities, records or resources it deems related to the trial, and produces findings the sponsor or site must answer on the authority’s terms. The difference is not thoroughness — it is who holds the authority and what the output obliges.

Is an audit required under ICH E6(R3)?

No. Annex 1 §3.11.2 is conditional: "When performed, audits should be conducted in a manner that is proportionate to the risks associated with the conduct of the trial." E6(R2) §5.19 was equally conditional. What is required is the sponsor’s quality assurance and quality control system under §3.11; the audit is one risk-proportionate instrument within it, not a standing obligation on every trial.

Is monitoring quality assurance or quality control?

Quality control. E6(R3) §3.11.4 states that "monitoring is one of the principal quality control activities," and §3.11.3 adds that "monitoring and data management processes are the main quality control activities" within clinical trials. Audit belongs to quality assurance and must be independent of and separate from routine monitoring and QC.

Can a GCP inspection be conducted remotely?

Under E6(R3), yes in part. The R3 Glossary definition of inspection ends "Some aspects of the inspection may be conducted remotely" — a sentence that does not appear in E6(R2) §1.29. Whether and how a given authority exercises that is a matter of its own inspection procedures, not of E6.

Can a regulator demand our internal audit reports?

Not routinely. E6(R3) §3.11.2.2(d) asks authorities not to request audit reports as a matter of course, allowing case-by-case access "when evidence or suspicion of serious GCP noncompliance exists or in the course of legal proceedings." Note that R3 added "or suspicion" to R2’s §5.19.3(d) wording, lowering the threshold. An audit certificate has no such protection and must be provided where regulation requires it (§3.11.2.2(e)).

Did the definition of quality assurance change in E6(R3)?

No. The QA definition is carried over from E6(R2) §1.46 unchanged. Quality control did change: R2 defined QC as activities undertaken "within the quality assurance system," and R3 drops that phrase, presenting QA and QC as parallel processes under Annex 1 §3.11 rather than one nested in the other.

Which E6(R3) section replaced E6(R2) section 5.19 on auditing?

Annex 1 §3.11.2, with §3.11.2.1 covering auditor selection and qualification (replacing §5.19.2) and §3.11.2.2 covering auditing procedures, audit-report access and the audit certificate (replacing §5.19.3).

Primary sources

  • ICH E6(R3) Guideline for Good Clinical Practice, Step 4 final text, 6 January 2025 — Glossary and Annex 1 §§2.3.5, 3.11. ICH database (PDF).
  • ICH E6(R2) Integrated Addendum to ICH E6(R1): Guideline for Good Clinical Practice, Step 4, 9 November 2016 — §§1.6, 1.8, 1.9, 1.29, 1.38, 1.39, 1.46, 1.47, 5.1, 5.19. ICH database (PDF).
  • European Medicines Agency, ICH E6 Good clinical practice — scientific guideline (EU effective dates). ema.europa.eu.

For the structural and philosophical changes behind these definitions — the Principles-plus-Annexes architecture, quality by design and the full regional adoption picture — see ICH E6(R3): What Changed in Good Clinical Practice. The controlled-vocabulary entries for both revisions are ICH E6(R3) and ICH E6(R2), alongside the broader ICH GCP entry and the foundational What Is Good Clinical Practice? overview.

On the operational side, clinical trial auditing covers audit types and how findings are handled, monitor versus auditor works through reporting lines and independence, and for-cause audit and second-party audit define two of the specific forms an audit takes. Preparing for the regulatory side is covered in GCP inspections at FDA and EMA, MHRA GCP inspection, inspection readiness and the trial master file, which is the record all three functions ultimately read.

The risk-proportionate framing that §3.11 rests on is set out in risk-based quality management, and sponsor oversight of delegated CRO functions under E6(R3) takes the service-provider angle further. Readers coming from a wider regulated-laboratory context will find the equivalent QA/QC and audit vocabulary across the other GxP disciplines in GxP compliance and the validation master plan, both part of the lab compliance cluster.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.