Written and maintained by CASRAI Editorial Board
Last updated
What a Protocol Deviation Log Is
A protocol deviation log is the running, auditable record a clinical trial site keeps of every point at which trial conduct departed from the IRB/IEC-approved protocol, from a single missed visit window to a dosing error. It is distinct from the deviation itself: the protocol deviation is the event; the log is the documentation system that captures it, tracks its resolution, and — critically — lets a site, sponsor, or monitor look across dozens of entries at once instead of one incident at a time. ICH E6(R2)/(R3) Good Clinical Practice does not prescribe a specific log template or field set, but it does require investigators to document and explain any deviation from the approved protocol and, per Section 4.5, to report significant deviations to the sponsor and to the IRB/IEC. A log is the practical mechanism sites use to meet that documentation obligation and to demonstrate it during a monitoring visit or inspection.
Core Fields a Protocol Deviation Log Should Capture
Templates vary by sponsor and CTMS, but a defensible log — one that would hold up under monitor or FDA/MHRA inspection review — captures the same functional information regardless of format:
- Deviation ID and study/site identifiers. A unique, sequential reference number so the entry can be cited in a monitoring report, a note to file, or a regulatory submission without ambiguity.
- Date the deviation occurred and date it was identified. These are frequently different dates, and the gap between them is itself a data point — a deviation identified weeks after it occurred, through source document review rather than real-time recognition, signals a different kind of site problem than one caught and logged the same day.
- Description of the deviation. A specific, factual account of what happened relative to what the protocol specified — not a conclusion about severity, which belongs in its own field.
- Classification. Whether the entry meets the site’s or sponsor’s definition of an important (sometimes called “major”) deviation, versus a minor one — see the next section.
- Root cause. Why it happened: a training gap, an ambiguous protocol instruction, a scheduling conflict, a systems/EHR interface issue, subject-driven (e.g., a missed visit), or investigator/staff error. A log that records only what happened, never why, cannot support trending.
- Corrective and preventive action (CAPA). What was done to address this instance (corrective) and to reduce recurrence (preventive) — retraining, an SOP revision, a protocol clarification request to the sponsor.
- Sponsor and IRB/IEC notification. Whether notification was required, the date it was sent, and the date of any acknowledgment or required response.
- Resolution date and reviewer sign-off. Who at the site (typically the PI) reviewed and closed the entry, and when.
Some sites add a field distinguishing planned/prospective deviations (an anticipated, documented departure requested in advance) from unplanned/retrospective ones — the FDA’s December 2024 draft guidance on protocol deviation reporting treats these as needing different reporting pathways, which is a reasonable structural choice to carry into a log even before that guidance is finalized.
Minor vs. Important Deviation: Where the Line Actually Falls
Neither ICH E6(R2) nor E6(R3) supplies a numbered checklist that sorts deviations into “minor” and “major.” What GCP actually gives is a functional test, and FDA’s draft guidance, Protocol Deviations for Clinical Investigations of Drugs, Biological Products, and Devices (released December 2024, comment period closed February 2025, not yet finalized as of this writing), states it in almost exactly ICH’s own language: an important protocol deviation is one that “might significantly affect the completeness, accuracy, and/or reliability of the study data or that might significantly affect a subject’s rights, safety, or well-being.”
In practice, that test resolves most classification calls without needing a rigid rule:
- Minor — a visit conducted two days outside its allowed window with no clinical consequence; a lab sample drawn but not centrifuged within the specified time, with no effect on the assay result; a missing initial on a source document that is otherwise complete. These get logged, explained, and closed — they rarely trigger expedited reporting on their own, though a pattern of them can (see trending, below).
- Important/major — enrollment of a subject who did not meet a key eligibility criterion; administration of the wrong dose or wrong investigational product; a missed safety assessment that could mask an adverse event; failure to obtain informed consent, or consent obtained from the wrong version of the form. These affect either data integrity or subject welfare directly, which is exactly the two-pronged test above.
The comparison between these two categories, including how “deviation” itself differs from the more serious “violation,” is covered in more depth in Protocol Deviation vs. Violation. Classification is a judgment call made against the protocol’s own risk profile and the site’s or sponsor’s documented deviation-management SOP — the log should record not just the classification itself but which criterion it was made against, so a monitor or auditor can follow the reasoning later rather than take the label on faith.
When a Deviation Requires Expedited IRB and Sponsor Notification
21 CFR 312.66 requires an investigator to promptly report to the IRB any change in research activity and any unanticipated problem involving risk to subjects, and prohibits implementing a change without prior IRB approval except where necessary to eliminate an apparent immediate hazard. ICH E6 Section 4.5 tracks the same structure: deviations should not be implemented without prior sponsor and IRB/IEC approval unless it is to eliminate an immediate hazard to subjects, and any deviation that does occur must be documented and explained, with significant ones reported promptly.
FDA’s draft guidance translates that principle into concrete timelines that many sites now build directly into their log workflow even ahead of finalization: for a planned deviation, sponsor and IRB approval is obtained before implementation, except in urgent situations where the deviation is implemented immediately and then promptly reported; for an unplanned deviation, the report goes to the sponsor and IRB within the timelines set by the trial’s own procedures; for device studies specifically, an emergency deviation implemented before approval should be reported within five business days. The full reporting sequence — what to do first, in what order, and how the IRB submission itself should read — is walked through step by step in Major Protocol Deviation: What to Do and How to Report It to the IRB; this page focuses on the log as the ongoing record, not the one-time response.
The log is where the notification obligation actually gets tracked to closure. An important deviation entry that shows a classification but no corresponding notification date is an open compliance gap, not a completed record — this is one of the first things a monitor checks during a monitoring visit, and it is a frequent finding in common GCP violations reviews.
Root Cause and CAPA: The Fields That Make the Log Useful, Not Just Compliant
A log that records only “what happened” satisfies the letter of the documentation requirement but does none of the useful work. Root cause analysis — asking why the deviation occurred, not just what occurred — is what separates a deviation log from a simple incident list, and it is the same discipline used across regulated-research quality systems generally, whether or not GCP calls it by that name. (ICH E6 itself does not use the term “CAPA” verbatim; it expects sponsors and investigators to identify and correct noncompliance, and CAPA is the operational process organizations use, borrowed from the GMP/ISO quality lineage, to meet that expectation in practice.) A short methodology overview of how to actually run that analysis, rather than write a root cause field that just restates the description, is in Root Cause Analysis and CAPA.
Two disciplines matter here specifically for deviation logging: keep “root cause” and “description” genuinely distinct fields (a common failure mode is writing the same sentence in both), and record the corrective action taken for this instance separately from the preventive action intended to reduce recurrence — they are frequently the same action, but treating them as one field makes it impossible to later ask “did the preventive action actually work,” which is the question trending is supposed to answer.
Trending: Reading the Log as a Site-Level Signal, Not a Pile of Incidents
The single biggest missed value in deviation logging is treating every entry as a closed, isolated event. Reviewed one at a time, a run of five minor visit-window deviations at one site over three months looks like five unrelated minor findings. Reviewed as a trend — by deviation type, by root cause category, by site, by investigator, or by study coordinator — the same five entries can reveal a scheduling-system problem, a training gap on a specific procedure, or a protocol design element that is systematically difficult to follow across sites, any of which is a real quality signal a case-by-case review will not surface.
This is consistent with where ICH E6(R3) has moved the center of gravity for oversight generally: Section 3.11 frames monitoring and data management as the trial’s principal quality control activities, sitting under a quality assurance/quality control structure the sponsor is required to maintain (even though neither E6(R2) nor E6(R3) makes an audit itself mandatory — see Section 3.11.2, “when performed”). A sponsor or CRO practicing risk-based monitoring uses exactly this kind of aggregated deviation data — alongside source data verification findings and central statistical monitoring signals — to decide where to direct on-site monitoring effort, rather than monitoring every site at the same fixed intensity regardless of its actual deviation pattern.
Practically, trending a deviation log means periodically (monthly or quarterly, depending on enrollment pace and study risk) pulling the log and asking:
- Is one deviation type recurring across multiple subjects at the same site — a sign the root cause is systemic (a form, a piece of equipment, an SOP) rather than a one-off human error?
- Is one site, relative to others in the study, generating a disproportionate share of important deviations — a signal that should feed into monitoring frequency and possibly a for-cause visit, independent of whether any single entry alone crossed the important-deviation threshold?
- Is the same root cause category (training, staffing, protocol ambiguity) recurring across otherwise-unrelated deviation types — the strongest evidence that a CAPA from three months ago did not actually work?
None of this requires sophisticated statistics for most single-site or small-study programs — a simple pivot by type, site, and root cause over time in the log itself is usually enough to see the pattern. What it does require is a log built with structured, consistent fields (a controlled classification list and a controlled root-cause category list, not free text every time) rather than a narrative log that has to be re-read line by line to find the pattern.
Building or Choosing a Deviation Log Template
Whether the log lives in a study’s CTMS, a sponsor-provided eTMF module, or a site-maintained spreadsheet for a smaller trial, the same design principles apply: use controlled fields (dropdown classification, dropdown root-cause category) everywhere trending depends on consistent values; keep description, root cause, and corrective/preventive action in separate fields even though they are related; record both the date identified and the date occurred; and make the notification-date field impossible to leave blank on an entry classified as important. A log format that satisfies GCP’s documentation requirement but cannot be pivoted by type, site, or root cause has met the compliance bar and missed the actual point of keeping one.
Frequently Asked Questions
Does ICH E6 require a specific protocol deviation log format?
No. ICH E6(R2)/(R3) requires that deviations be documented, explained, and — where significant — reported to the sponsor and IRB/IEC, but it does not mandate a particular log template or field set. The fields in this guide reflect what sites and sponsors commonly use to meet that requirement in a way that also survives monitor and inspector review.
Who decides whether a deviation is minor or important?
Typically the principal investigator makes the initial classification call, against the site’s or sponsor’s documented deviation-management procedure and the two-part test (effect on data reliability, or effect on subject rights/safety/well-being) that both ICH E6 and FDA’s draft guidance apply. The sponsor and IRB can and do reclassify on review.
How often should a site review its deviation log for trends?
There is no regulatory-mandated cadence. Monthly or quarterly review, timed to the study’s enrollment pace and risk level, is common practice and aligns with how risk-based monitoring plans typically schedule their own periodic data review.
Is a protocol deviation log the same thing as a note to file?
No, though the two are often used together. A note to file documents the explanation and resolution of one specific event in narrative form, sometimes as backup to a log entry; the log is the structured, running record across every deviation in the study, which is what makes cross-entry trending possible in the first place.
Does a pattern of minor deviations ever require IRB notification on its own?
It can. Even when no single instance meets the important-deviation threshold, a recurring pattern can itself constitute the kind of continuing or systemic issue that a site’s or IRB’s own noncompliance-reporting policy expects to be raised — which is exactly why trending the log, not just classifying each entry in isolation, matters for compliance and not only for quality improvement.








