For the past three years, I have worked as an independent consultant with emerging CROs, helping them establish quality processes, train teams, conduct internal audits and prepare for sponsor and external audits. This article draws on that experience.


Quality expectations apply to every CRO

Every CRO needs sound quality processes. Clinical trial data informs decisions about the safety and efficacy of medicines, so the expectations for data quality and trial operations remain high regardless of company size.

Core controls include:

  • Data integrity
  • Confidentiality and data protection
  • Controlled SOPs and documents
  • Appropriate training and competency
  • Review and quality control
  • Traceability
  • Issue and deviation management

ICH E6(R3) defines data integrity through the attributes of attributable, legible, contemporaneous, original, accurate, complete, secure and reliable data that is fit for purpose. These attributes provide a useful basis for reviewing processes and records during an internal audit.

Consider a programmer working on an efficacy dataset without the required qualifications or study knowledge. If an incorrect result reaches a regulatory submission, the effect extends beyond the CRO. It can affect a decision about a medicine intended for many patients.

Company size does not reduce that risk. It does affect how the CRO organises its controls, which processes it formalises first and how much infrastructure it needs to support them.


What an internal audit examines

ICH E6(R3) defines an audit as a systematic and independent examination of trial-related activities and records. Its purpose is to determine whether activities were conducted, and data recorded, analysed and reported, according to the protocol, applicable SOPs, GCP and regulatory requirements.

For an internal audit, this translates into five practical questions:

  • Are teams following the defined processes?
  • Are those processes practical and properly documented?
  • Are the controls relevant to data quality and participant protection working?
  • Can the organisation produce evidence that the activities took place?
  • Which gaps require action?

Some controls are essential whether the CRO employs 20 people or 2,000. Others depend on the services it provides, the risks attached to those activities and its stage of development.


Scale changes how controls are organised

A large CRO usually has a dedicated quality assurance team, an established quality management system, standardised technology and years of sponsor-audit experience. An emerging CRO often has a lean team, people carrying several responsibilities and procedures developed alongside active delivery.

ICH E6(R3) reflects this operational reality. Section 3.6 states that a service provider must implement appropriate quality management. It also recognises that existing quality processes can meet GCP requirements when they are fit for purpose in the context of the trial. Section 3.9 requires oversight measures to be tailored to the complexity and risks of the work.

The core obligations still apply. An emerging CRO needs to decide which controls require immediate formalisation and how to build the supporting infrastructure without creating procedures that add work but provide little protection.


Existing practices need documented evidence

Smaller CROs often follow sensible processes without formally defining them or retaining evidence that they took place.

During a recent audit, an auditor asked whether study teams were required to understand the protocol before starting study activities. The CRO already conducted a protocol walkthrough before biostatistics and programming work began on every study. The control existed, but the relevant SOP did not require it, and the organisation had no record of who attended or what the walkthrough covered.

We added the walkthrough to the study initiation section of the SOP and introduced a simple kickoff record containing the study details, date, participants and method used. The update documented an established practice and made its consistent use verifiable.

The same issue appears in training. Sponsors commonly examine how a CRO hires people, assesses skills, authorises staff to join a study and manages study-specific training. Smaller organisations often provide knowledge-sharing sessions, external training and study briefings. Their records may be incomplete or stored inconsistently.

Attendance records, certificates, training logs, competency assessments and study-specific training files allow the CRO to demonstrate who was prepared to perform each activity and when. ICH E6(R3) requires sponsors to use appropriately qualified individuals and gives sponsors access to information such as service-provider SOPs and performance metrics for selection and oversight. A CRO therefore needs records that support its claims about staff readiness.


Audit findings require an applicability and risk assessment

Audit findings differ in severity, relevance and potential effect. Each one needs an assessment against the CRO's services, contractual responsibilities, existing controls and applicable requirements.

In one sponsor audit, the CRO I was supporting received a finding requiring a formal Project Management SOP. The CRO specialised in statistical programming and related biometrics services and had no separate project management function. It still performed study coordination activities, including planning work, assigning responsibilities, managing timelines, assessing study-level risks and communicating issues.

The finding therefore required a closer review of where those responsibilities sat and whether the existing procedures controlled them adequately. The relevant requirements could be incorporated into established study initiation, delivery, risk management and escalation procedures. If the assessment identified gaps, the CRO needed to update those procedures, assign ownership and record the action through its CAPA process. A standalone Project Management SOP would be necessary only if the CRO's operating model or agreed responsibilities required one.

This approach aligns with ICH E6(R3) Section 3.6, which requires transferred trial-related activities to be documented in an agreement. The organisation's procedures should then cover the activities it has accepted and show how it controls them.

Findings involving data integrity, confidentiality, staff qualification, quality control, traceability or regulatory non-compliance need prompt attention. Findings related to process development still need a documented response, with timelines based on risk, sponsor expectations, contractual commitments and the CRO's CAPA governance.


What an emerging CRO needs from an internal audit

Emerging CROs often operate with fewer SOPs, forms and quality staff than large organisations. Their quality systems still need to show:

  • Which controls are essential for its current services
  • How those controls operate in practice
  • What evidence confirms they were followed
  • Which gaps carry the greatest risk
  • Who owns each corrective action and when it is due
  • Which requested processes do not apply, with the rationale recorded

An internal audit tests whether the quality system reflects the work the CRO performs. It also gives the organisation a structured way to identify missing evidence, strengthen weak controls and prioritise improvement before a sponsor or regulator finds the same gaps.

For an emerging CRO, that is the practical value of the exercise: a quality system that sponsors can examine, teams can follow and the organisation can sustain as it grows.


References