Risk-based quality management (RBQM) is the practical application, at trial level, of a principle International Council for Harmonisation (ICH) guidance has pushed to the center of Good Clinical Practice since 2016: quality should be built into a clinical trial from the start, not inspected into it afterward. Rather than relying primarily on exhaustive downstream activity — 100% source data verification, blanket on-site monitoring, after-the-fact audits — to catch problems, RBQM directs a sponsor’s limited quality resources toward the specific processes and data most likely to affect participant safety and the reliability of trial results, and does so proactively, starting at protocol design.
This guide covers where RBQM comes from in ICH E6(R2), the quality-by-design principle underneath it, how critical-to-quality (CtQ) factors are identified, and the risk management cycle — identification, evaluation, control, communication, and review — that Section 5.0 sets out as the operational mechanism.
Quality-by-design: the principle behind RBQM
Quality-by-design, as applied to clinical trials, means designing quality into the protocol, procedures, and systems before a trial starts enrolling, rather than treating quality as something monitoring and audit are supposed to verify after conduct is already underway. The idea did not originate in clinical research — it is adapted from manufacturing and pharmaceutical quality frameworks (the same lineage behind ICH’s Q8-Q10 pharmaceutical-quality guideline series) — but ICH formalized it for trial conduct specifically in two steps:
- ICH E6(R2), the 2016 addendum to the original E6(R1) Good Clinical Practice guideline, added a new Section 5.0, Quality Management, which requires sponsors to implement a system to manage quality throughout all stages of the trial process and to take a risk-based, proportionate approach to doing so.
- ICH E6(R3), the current core GCP guideline (reached ICH Step 4 on 6 January 2025; EMA set 23 July 2025 as the effective date for its Principles and Annex 1, and FDA issued its own final E6(R3) guidance on 8 September 2025), restructures GCP around principles and annexes and sharpens the risk-based, quality-by-design emphasis further, extending it explicitly to decentralized and pragmatic trial designs and electronic data sources that E6(R2) did not contemplate.
Because implementation timelines differ by jurisdiction during the R2-to-R3 transition, a sponsor running a multi-region trial needs to know which revision applies where rather than assuming a single global cutover date. See the CASRAI guide to Good Clinical Practice (GCP) for the fuller regulatory history of both revisions.
In practice, quality-by-design for a trial means asking, at the protocol-design stage: which processes and data points, if they went wrong, would actually threaten participant safety or the reliability of the trial’s conclusions — and then designing the protocol, case report forms, monitoring plan, and systems to prevent or catch problems in exactly those areas, rather than applying uniform, maximal scrutiny everywhere. A protocol with unnecessary complexity, ambiguous procedures, or excessive data collection creates more opportunities for error and makes it harder to tell which deviations actually matter — quality-by-design pushes sponsors to simplify and clarify the protocol itself as a quality measure, not only to monitor harder once it is running.
Critical-to-quality (CtQ) factors
Critical-to-quality factors — sometimes called critical-to-quality data and processes — are the specific trial attributes that quality-by-design and RBQM are built around identifying. ICH E6(R2) Section 5.0.1 frames this as a sponsor responsibility: identifying, during protocol development, the critical processes and data necessary to achieve the trial’s objectives. Not every process or data point in a trial carries equal weight — CtQ factors are the ones where an error or deviation would meaningfully affect either:
- Participant safety — for example, eligibility-criteria verification, dosing accuracy, or timely reporting of serious adverse events.
- The reliability of the trial’s results — for example, primary endpoint assessment, randomization integrity, or blinding.
Identifying CtQ factors is a protocol-specific exercise, not a generic checklist — a hematology-oncology trial’s CtQ factors around dosing and toxicity grading look different from a decentralized cardiovascular trial’s CtQ factors around remote device data and eConsent. This is also why CtQ identification happens early: it directly shapes what the monitoring plan, data management plan, and statistical analysis plan each need to prioritize once the trial is running, and it is the reference point the entire downstream risk management cycle is built against.
RBQM as the operational mechanism: the ICH E6(R2) Section 5.0 risk cycle
Quality-by-design describes the principle; RBQM is how ICH E6(R2) Section 5.0 operationalizes it as a repeatable, documented cycle rather than a one-time exercise. Industry and regulatory-training summaries of Section 5.0 consistently describe it as a sequence of related steps:
- Identify critical processes and data (5.0.1). As described above — determine, during protocol development, which processes and data are essential to participant protection and result reliability.
- Identify risks to those critical processes and data (5.0.2). For each CtQ factor, identify what could go wrong — at the trial level (design, procedures, protocol complexity, data collection tools) and at the process level (site, sponsor, vendor, and other trial-conduct activities).
- Evaluate identified risks (5.0.3). Assess each risk against the likelihood of error occurring, the extent to which it would be detected, and the impact it would have on participant safety or data reliability — prioritizing quality resources toward the risks that score highest on this combination rather than distributing effort evenly.
- Control risks (5.0.4). Decide and implement risk-control activities proportionate to the significance of the risk. This is the step most associated with risk-based monitoring (RBM) and quality tolerance limits (QTLs) — predefined thresholds set for a small number of trial-critical parameters, such that breaching a QTL triggers a documented evaluation to determine whether a systemic quality issue is developing. Controls are not limited to monitoring: they can include protocol simplification, targeted training, system edit-checks, or centralized monitoring of accumulating data as a substitute for, or complement to, on-site visits.
- Communicate about risk and quality management (5.0.5). Risk decisions, the rationale behind the chosen monitoring approach, and quality issues that arise need to be documented and communicated to the people responsible for acting on them — across the sponsor, any delegated CRO, and site staff.
- Review risk-control measures (5.0.6). Periodically review whether the implemented controls are working and whether the risk assessment itself still holds as the trial accumulates data and experience — risk is not assessed once and left static.
- Report on quality management (5.0.7). Describe the quality management approach taken and the significant deviations from the pre-specified quality tolerance limits in the clinical study report, so reviewers can see how quality was actually managed rather than only its end results.
This sequence is why RBQM is best understood as the specific mechanism through which trial-level quality-by-design gets executed, rather than a separate or competing concept — quality-by-design sets the intent (build quality in from the start), and the Section 5.0 risk cycle is the documented, auditable process a sponsor follows to do it.
RBQM vs. risk-based monitoring (RBM): related but not identical
These terms are frequently used interchangeably, but they describe different scopes. Risk-based monitoring is specifically about how monitoring activity is planned and executed — for example, choosing on-site, centralized, or a combination of both based on risk, and reducing reliance on 100% source data verification (SDV) in favor of targeted, risk-driven checks. See the CASRAI guide on clinical trial monitoring for how monitoring visit types and SDV fit together in practice. RBQM is broader: it is the trial-wide quality management system Section 5.0 describes, of which risk-based monitoring is one major output, alongside protocol design decisions, data management controls, training, and vendor oversight. In short, RBM answers the narrower question of how to monitor a given trial, while RBQM answers the broader question of how to manage quality across the trial as a whole — monitoring strategy is downstream of, and shaped by, the broader RBQM risk assessment.
Why this shift matters in practice
The regulatory shift toward risk-based, proportionate quality management was, in part, a response to the recognition that the historical industry default of near-universal 100% SDV and maximal on-site monitoring was resource-intensive without strong evidence that it produced better data quality than a targeted, risk-driven approach. Neither ICH E6 nor FDA guidance has ever mandated 100% SDV — it became a de facto industry practice beyond what regulation actually required, and RBQM formalizes a documented, defensible alternative to that default rather than simply relaxing oversight. For a sponsor or CRO, this means the quality management plan and monitoring plan need to show their work: which CtQ factors were identified, how risks against them were evaluated, what controls were chosen and why, and how those decisions are being reviewed as the trial progresses — not just that monitoring happened.
Frequently asked questions
Is RBQM the same as risk-based monitoring (RBM)?
No. RBM is one component of RBQM, specifically covering how monitoring visits and source data verification are planned around risk. RBQM is the broader trial-level quality management system described in ICH E6(R2) Section 5.0, of which monitoring strategy is one output among several.
What are quality tolerance limits (QTLs)?
QTLs are predefined thresholds set for a small number of trial-critical parameters identified as CtQ factors. Breaching a QTL triggers a documented investigation into whether a systemic issue — rather than an isolated, expected deviation — is developing, and any significant QTL breaches must be described in the clinical study report per Section 5.0.7.
Who is responsible for RBQM under ICH E6(R2)?
The sponsor. Section 5.0 places quality management responsibility with the sponsor, though in practice much of the operational execution — risk assessment workshops, KRI/QTL tracking, centralized monitoring review — is frequently delegated to a CRO under the sponsor’s oversight, consistent with Section 5.2’s delegation-of-duties framework.
Does RBQM apply only to large, industry-sponsored trials?
No. ICH E6(R2) Section 5.0 applies to trial sponsors generally, and the proportionality built into the framework is specifically meant to scale down as well as up — a smaller, lower-risk investigator-initiated trial should apply a simpler, right-sized risk assessment rather than the same apparatus a large multi-region pivotal trial would use, while still documenting that the exercise was done.







