Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Quality Improvement vs. Human Subjects Research: How to Determine If You Need IRB Review

Quality improvement and quality assurance projects are not automatically exempt from IRB review, or automatically research. This guide walks through the 45 CFR 46 two-part test, the factors real institutional determination frameworks use (purpose, design, scope — not intent to publish), who should make the call, and how to document it.

TL;DR: Quality improvement (QI), quality assurance (QA), and program-evaluation activities are not automatically exempt from IRB review, and they are not automatically research either. The determining question under the Common Rule is whether the activity meets the two-part test at 45 CFR 46.102: is it research (a systematic investigation designed to develop or contribute to generalizable knowledge, 46.102(l)), and does it involve a human subject (46.102(e))? Most QI/QA work is designed to improve a process or outcome in one local setting, not to produce findings meant to apply beyond it — which is usually, though not always, why it falls outside “research” on the generalizable-knowledge element specifically. Because that line depends on intent and design rather than on how systematic or rigorous the project is, institutions require a documented determination from an authorized reviewer (the IRB or a delegated HRPP official), not self-certification by the project team.

Why this determination matters

Getting this classification wrong runs in both directions, and both are costly. Submitting every QI initiative to full IRB review overloads the committee with work the regulation never intended it to review, slows down legitimate operational improvement, and trains staff to see the IRB as an obstacle rather than a protection. Failing to submit a project that actually is human subjects research — because a team assumed “it’s just QI” — creates a real regulatory exposure: an unapproved study involving human subjects can trigger a finding of noncompliance, jeopardize the institution’s Federalwide Assurance (FWA), and, if the project is later written up for publication, block that publication at the journal stage, since most journals require documented IRB approval or exemption before they will consider a manuscript involving human data.

This is also a genuinely common gray zone, not an edge case. Clinical, quality-improvement, and patient-safety offices at any hospital or academic medical center run a constant stream of chart audits, care-pathway pilots, dashboard-driven process changes, and accreditation self-studies — and a meaningful share of them sit close enough to the regulatory line that a documented screening step, rather than an assumption, is the only defensible way to handle them.

The regulatory test: two questions, not one

The Common Rule does not define “quality improvement” at all — there is no QI carve-out in the regulation. Instead, an activity is subject to IRB review only if it independently satisfies both prongs of the definition covered in detail in CASRAI’s guide to the two-part human subjects research test:

  • Is it “research”? Per 45 CFR 46.102(l), research is “a systematic investigation, including research development, testing, and evaluation, designed to develop or contribute to generalizable knowledge.” Activities meeting this definition are research “whether or not they are conducted or supported under a program that is considered research for other purposes” — meaning a project’s departmental label (“QI initiative,” “clinical audit,” “pilot program”) does not decide the question either way.
  • Does it involve a “human subject”? Per 45 CFR 46.102(e), a living individual about whom an investigator obtains information or biospecimens through intervention or interaction, or obtains identifiable private information or biospecimens.

Both conditions have to be met for Common Rule/IRB jurisdiction to attach. A QI project that involves patients but is not designed to produce generalizable findings fails the first prong and is outside the Common Rule’s scope entirely — not because it is exempt (exemption categories under 45 CFR 46.104 only apply to activities that have already been determined to be research), but because it never became “research” in the regulatory sense in the first place. That distinction matters procedurally: an exemption determination is still documented by the IRB and still assumes the activity is research; a QI/QA determination is a threshold finding that the Common Rule never applied.

What actually distinguishes QI from research in practice

Because “generalizable knowledge” is the operative term and the regulation doesn’t further define it, institutions rely on published decision frameworks and locally adopted checklists to apply it consistently. The most commonly cited factors, drawn from HHS Office for Human Research Protections (OHRP) guidance and the QI/QA determination tools that most academic medical center IRB and HRPP offices publish, include:

  • Primary purpose. Is the activity designed, from the outset, to improve a process, protocol, or outcome within a specific local setting (this hospital’s fall-prevention rate, this clinic’s adherence to a screening guideline) — or is it designed to test a hypothesis and produce findings intended to apply more broadly, beyond the setting where the data were collected?
  • Design. Does the activity apply a practice that is already generally accepted (a guideline, a protocol, a standard of care) and simply measure how well it’s implemented — or does it involve systematic experimental manipulation of an intervention whose effectiveness is not yet established, often with a comparison/control condition?
  • Departure from usual practice. Does participation involve any procedures, data collection, or risk beyond what patients would already experience as part of routine care at that site?
  • Scope. Is the activity confined to one unit, service line, or institution, or does it involve multiple sites collecting data under a common protocol with the intent to pool and generalize results?

One factor that recurs across essentially every published framework, and is worth stating explicitly because it’s the most common misconception: intent to publish, by itself, is not the deciding factor. A QI project that a team later writes up as a case study or a “lessons learned” piece for a quality journal does not retroactively become human subjects research merely because it results in a publication describing what was done locally. What matters is whether the underlying project was designed, from the outset, to produce generalizable findings — publication of a local improvement story is different from a study designed to test whether an intervention works in a way meant to generalize to other settings. That said, intent can genuinely shift mid-project: a QI initiative that a team decides, partway through, to redesign as a multi-site comparative study with the explicit aim of proving an intervention should be adopted elsewhere has crossed into research and needs a fresh determination at that point, not after data collection is complete.

Illustrative example (composite, not a specific institution)

The following is an illustrative composite built to show how the factors above interact — it does not describe any real project, institution, or individual.

A hospital unit notices its hand-hygiene compliance rate is below its own internal target. The infection-prevention team redesigns the workflow (moves dispenser locations, adds a huddle prompt) and tracks the unit’s compliance rate before and after the change, using data the unit already collects as part of routine infection-control monitoring. The intervention is only ever intended to run on that unit, using an already-recommended practice, to move that unit’s own metric. Under the framework above, this is QI: local scope, an already-accepted practice being implemented rather than tested, and no design intent to produce generalizable findings.

Contrast that with a version of the same idea redesigned as a study: the team develops a new hand-hygiene prompting protocol that has not been validated elsewhere, plans to roll it out at several unaffiliated hospitals using a common data-collection instrument, and states the project’s purpose as determining whether the new protocol reduces hospital-acquired infection rates in a way other institutions should adopt. Same clinical topic, but the design (an untested intervention, multi-site, explicit generalization intent) now meets the 46.102(l) research definition and needs an IRB determination before it starts.

Who makes the determination, and how it should be documented

Because the line depends on design intent rather than on a bright-line rule, institutions do not let investigators or project leads self-certify a project as “not research.” The standard practice, reflected in OHRP guidance and in the determination tools published by IRB/HRPP offices across academic medical centers, is:

  • The project team completes a short screening questionnaire (commonly built around the factors above) and submits it to the IRB office, the HRPP, or a delegated QI/QA review function before the project begins.
  • An authorized reviewer — not the project team — issues a written determination: “not human subjects research,” “exempt human subjects research,” or “requires IRB review,” and the determination is kept on file. Some institutions route this through a “not human subjects research” (NHSR) determination letter, which functions similarly to an exemption determination but reflects that the Common Rule never attached at all.
  • That documentation exists precisely because journals, IRBs at collaborating institutions, and, in an audit, OHRP itself may all ask for evidence that the classification was made deliberately rather than assumed.

For the parallel process once a project is determined to be human subjects research — the three review pathways (exempt, expedited, full board) and what triggers each — see CASRAI’s guide to the IRB/REC approval process. Institutions preparing for or maintaining AAHRPP accreditation of their Human Research Protection Program (HRPP) are generally expected to show a documented, consistently applied QI/QA-versus-research screening process as part of that program — see CASRAI’s HRPP self-assessment guide for how that self-assessment is structured.

Related activities that raise the same question

QI/QA is the most common version of this determination question, but the same two-part test governs several adjacent activity types that institutions routinely need to screen the same way:

  • Program evaluation (assessing whether an existing program met its own local objectives) is generally treated the same way as QI when it is not designed to produce generalizable findings.
  • Accreditation self-studies and internal operations audits are typically excluded from “research” on the same generalizable-knowledge element, even when they are highly systematic.
  • Public health surveillance conducted or authorized by a public health authority is deemed, by regulation, not to be research at all under 45 CFR 46.102(l)(2) — a separate, explicit exclusion rather than a generalizable-knowledge judgment call.
  • Case reports describing a single patient’s clinical course are generally treated as outside the “research” definition for the same reason — see CASRAI’s dictionary entry on the case report IRB exemption for how that specific, narrower determination works.

Frequently asked questions

Does a QI project need IRB approval if it uses patient data?

Using patient data by itself does not trigger IRB review — that only satisfies the “human subject” prong of the two-part test. The project also has to meet the “research” prong (designed to produce generalizable knowledge) for Common Rule jurisdiction to attach. Most QI work that uses patient data to track a local process improvement fails that second prong and does not require IRB review, but the determination still has to be documented by an authorized reviewer, not assumed by the project team.

If we plan to publish our QI results, does that automatically make it research?

No. Per OHRP guidance, intent to publish is, by itself, an insufficient criterion for determining whether a project is research. What matters is whether the project was designed from the outset to produce generalizable findings. A published account of a local improvement effort is different from a study designed to generalize beyond its own setting.

Can our department decide on its own that a project is “just QI” and skip the IRB?

This is the most common source of institutional risk in this area. Because the QI-versus-research line depends on judgment calls about design intent rather than a bright-line regulatory rule, institutions require a documented determination from the IRB, HRPP office, or a delegated review function — not self-certification by the project team. If a determination is later challenged (by a journal, a collaborating institution’s IRB, or in an OHRP compliance review), the institution needs to be able to show who made the call and on what basis.

What happens if a QI project’s scope changes partway through?

The determination should be revisited, not left in place from the project’s original scope. If a project that started as a local process-improvement effort is redesigned mid-course to add a control group, expand to multiple sites, or explicitly aim to generalize findings for adoption elsewhere, it can cross into the 46.102(l) research definition at that point and needs a fresh determination before the expanded activity proceeds.

Is a “not human subjects research” determination the same as an exemption?

No, and the distinction is more than semantic. An exemption determination (under 45 CFR 46.104) is made by the IRB after concluding that an activity is research but qualifies for one of the regulation’s exempt categories. A “not human subjects research” (NHSR) determination reflects a conclusion that the Common Rule never applied in the first place, because the activity failed the research and/or human-subject prong of the 46.102 definition. Both are documented determinations made by an authorized reviewer rather than by the project team, but they rest on different regulatory findings.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →