← Back to blog

90 Day RBM Setup for Clinical Ops: Checklist & FDA ICH

October 5, 2026
90 Day RBM Setup for Clinical Ops: Checklist & FDA ICH

A risk-based monitoring setup focuses monitoring effort on a trial's critical-to-quality data and processes, and the first move is running a formal risk assessment to identify those factors. From there, the work expands into writing a monitoring plan, setting quality tolerance limits, choosing centralized or on-site methods, and building the operational habits that keep the whole system running.


TL;DR:

  • Rigorous data infrastructure and timely electronic data flow are essential before reducing on-site visits and fully implementing centralized monitoring strategies.
  • A focused risk assessment must prioritize critical-to-quality factors, with clear scoring and documented thresholds, to guide effective monitoring actions.
  • Keeping monitoring thresholds and review procedures current and well-documented is vital for compliance and efficient handling of potential issues.
  • Training staff to interpret centralized dashboards and establish clear escalation pathways enhances the effectiveness of risk-based monitoring.
  • An operational partner can help align trial goals with workflow design, especially when integrating AI tools and navigating complex protocol or data challenges.

Haiphai
Align Clinical Operations With Your Goals
HaiPhai helps life sciences teams identify operational bottlenecks and tailor AI-enabled workflows for regulatory and clinical processes.
Explore HaiPhai

Table of Contents

Monitoring plan components: what to include and why

A monitoring plan is the document that turns a risk assessment into daily practice. Regulators expect it to connect directly back to the trial's critical-to-quality, or CtQ, factors rather than reading as a generic template copied from a previous study. The FDA's guidance on risk-based monitoring lays out what belongs in that plan: a study description tied to CtQ factors and objectives, the monitoring methods selected and why, timing and frequency criteria, and the documentation rules that keep the whole exercise auditable.

Start with the study description. This section should restate the trial's objectives in terms of the data and processes that matter most: informed consent integrity, eligibility confirmation, investigational product accountability, and primary safety or efficacy endpoints. Anyone reading the plan should understand within a paragraph why those elements were chosen over others.

Next comes the choice of monitoring methods. A plan might rely on centralized monitoring for data that flows in electronically and in near real time, targeted on-site visits for processes that cannot be verified remotely, such as physical drug accountability, and a hybrid approach for most trials in between. The rationale for each choice belongs in the plan itself, not just in a planning meeting's notes.

Timing and frequency criteria need specificity. Rather than "monitor quarterly," a usable plan states what triggers a visit: a site's first patient enrolled, a protocol deviation rate exceeding a set threshold, or a safety signal flagged through centralized review. The FDA's Q&A on risk-based monitoring gives examples of these triggers and how sponsors have documented them in practice.

A complete monitoring plan generally includes a study description tied to critical-to-quality factors, defined monitoring methods with their rationale, timing and frequency criteria detailing triggers for visits, clear roles and responsibilities including delegation, documentation requirements specifying recording details, and amendment procedures outlining how the plan is updated.

Responsibilities and delegation deserve their own section rather than a footnote. Clinical research associates, data managers, and medical monitors each touch different parts of the monitoring workflow, and a plan that leaves this implicit invites confusion during an audit. Delegation logs, sign-off authority for closing an action item, and escalation paths should all be named.

Finally, build in the expectation that the plan will change. Trials evolve: enrollment patterns shift, new sites open, safety signals emerge. A monitoring plan that cannot be amended without a lengthy approval cycle becomes a liability rather than a tool. Document the amendment process up front, including who approves a change and how it gets communicated to the monitoring team, and schedule periodic reviews of the plan itself as a planned activity rather than a reaction to a problem.

Identifying critical data and processes through formal risk assessment

Before a monitoring plan can be written, someone has to decide what actually matters in a given trial. That is the job of identifying critical-to-quality factors: the data points and processes whose errors would meaningfully affect participant safety or the reliability of trial results. Informed consent documentation, eligibility criteria verification, investigational product accountability, and primary safety endpoints are the factors that show up in nearly every trial's CtQ list, though the specific weighting depends on the protocol.

A formal, documented risk assessment is how that list gets built, and the FDA's risk-based monitoring guidance expects sponsors to perform one prospectively rather than relying on institutional habit. The process follows a repeatable sequence:

  1. Define the risk question. Frame what you are assessing, such as "what could compromise the reliability of the primary efficacy endpoint at this site type."
  2. Collect inputs. Pull from protocol design, prior trial experience, site history, and known risks for the therapeutic area or technology involved.
  3. Score likelihood, detectability, and impact. Rate how probable each risk is, how easily it would be caught, and how severe the consequence would be if missed.
  4. Rank the results. Sort risks by combined score to produce a prioritized list rather than an undifferentiated catalog.
  5. Translate rankings into monitoring actions. Decide which risks warrant a KRI, a QTL, a targeted visit trigger, or simply ongoing centralized review.

Several established tools can structure this work. Failure Mode and Effects Analysis, or FMEA, is well suited to breaking a process into steps and scoring each for likelihood and severity of failure. Fault Tree Analysis works backward from a specific adverse outcome to map the contributing causes, which helps when a single failure mode, like a missed safety signal, could stem from several different root causes. Hazard Analysis and Critical Control Points, borrowed from food and manufacturing safety, suits trials with complex physical handling steps, such as cell and gene therapy logistics. Preliminary Hazard Analysis works well early in protocol design, before detailed process maps exist, to flag broad categories of risk for deeper review later.

Pro Tip: Run the risk workshop with a standardized scoring rubric and predefined questions rather than open discussion alone, since open-ended brainstorming tends to overweight whoever speaks first.

Subjectivity is the main threat to a useful risk assessment. ICH Q9(R1) specifically warns against letting risk scoring drift into guesswork, recommending clear risk questions and established scoring scales to keep results comparable across sites and studies. A workshop that starts with a written rubric, defined in advance of the meeting, produces more consistent rankings than one where participants assign scores from memory. Where historical data exists, calibrating the rubric against past deviation rates or past audit findings reduces the guesswork further.

The deliverable from this process is a prioritized risk register: a living document listing each identified risk, its score, the rationale behind that score, and the monitoring action assigned to it. From the register, a short list of key risk indicators emerges, along with recommendations for which risks need a quality tolerance limit and which can be handled through routine centralized review. Our guide to building an inspection-ready risk register walks through the structure of that document and how to link it directly to KRI dashboards.

Quality tolerance limits and key risk indicators serve distinct purposes: KRIs provide continuous early warnings of potential issues, while QTLs set boundaries for a limited number of parameters critical to trial validity, with breaches prompting documented evaluations of possible systemic problems. The CASRAI guide to risk-based quality management frames QTLs as deliberately few in number, because a long list of "critical" thresholds defeats the purpose of flagging what truly matters.

Selecting QTLs begins with the prioritized risks from the assessment phase, focusing on those with high likelihood and impact on trial validity, and proposing thresholds based on historical data or statistical rationale that represent acceptable variation within normal trial conduct rather than management targets.

A few example QTL and KRI pairings illustrate the relationship:

  • QTL: Overall major protocol deviation rate across the trial. Linked KRI: site-level deviation rate trending upward over consecutive months.
  • QTL: Rate of unevaluable primary endpoint data. Linked KRI: missing or delayed case report form entries for the primary endpoint.
  • QTL: Serious adverse event reporting timeliness across all sites. Linked KRI: individual site average days-to-report trending beyond the historical norm.

Guidance from the CASRAI RBQM resource holds that a QTL breach should trigger a documented evaluation to determine whether the issue reflects an isolated event or a systemic quality problem, with that evaluation and its outcome recorded in the trial master file.

Documentation matters as much as the thresholds themselves. QTLs belong in the monitoring plan alongside the rationale for each limit, and any breach needs a dated record of the investigation, its findings, and any resulting plan amendment. This record becomes part of the evidence base for the clinical study report, where sponsors are expected to describe how quality was managed throughout the trial rather than only reporting results. Keeping that documentation current as the trial progresses, rather than reconstructing it near database lock, saves considerable effort when the study report is drafted.

Choosing monitoring modalities: centralized, on-site, and hybrid strategies

Most trials now run on a mix of centralized monitoring and targeted on-site visits, and the right balance depends on what data is available electronically, how quickly it arrives, and what still requires a human on the ground. The FDA's guidance notes that centralized monitoring can replicate many of the functions of on-site monitoring and, where source data access and timeliness are established, can complement or even replace some on-site visits.

Centralized monitoring requires prerequisites such as timely electronic data capture, accessible source documents for remote verification when applicable, and clearly defined clinical operations processes for data review and action before it can effectively replace in-person monitoring. Skipping these prerequisites is a common reason pilots stall: teams reduce on-site visits before the underlying data infrastructure can actually support the shift.

Certain signals should prompt a targeted on-site visit despite strong centralized monitoring, including new or inexperienced sites in early enrollment, KRIs trending outside expected ranges, QTL breaches needing in-person investigation, physical verification tasks like drug accountability or equipment calibration not possible remotely, and participant safety concerns identified through adverse event tracking.

Three clinical monitoring pathways and escalation triggers

The monitoring plan should spell out these triggers explicitly rather than leaving the decision to individual judgment calls mid-trial. Documenting the modality choice and its rationale for each site type, along with the specific conditions that would escalate a site to targeted visits, gives auditors a clear paper trail and gives the monitoring team a consistent standard to apply.

This shift also changes what CRAs spend their time on. Less travel for routine source document verification means more time available for site training, follow-up on open action items, and resolving issues flagged by centralized review, work that often gets shortchanged under a purely on-site model. Staffing plans should reflect this shift rather than simply reducing headcount when visit frequency drops.

Master protocols and trials using digital health technologies add complexity here. Different substudies within a master protocol may carry different risk profiles and therefore different monitoring approaches, and FDA guidance addressing master protocols notes that selective safety data collection across substudies needs explicit treatment in the monitoring plan rather than a one-size-fits-all approach. Trials relying on wearables or other digital health technologies for endpoint data introduce their own data quality and timeliness questions that the centralized monitoring plan needs to address directly.

Implementation checklist and workflows: from risk register to routine monitoring operations

Turning a risk register into daily monitoring operations requires mapping each item to a specific workstream with an owner and a cadence. A KRI tied to enrollment deviations might get a weekly review by the lead CRA, while a QTL tied to overall data quality might warrant a monthly review by the sponsor's clinical quality lead. Writing this mapping down, rather than leaving it to informal habit, is what separates a monitoring plan that works from one that exists only on paper.

A handful of templates make this operational:

  1. Risk register. The master list of identified risks, scores, and assigned monitoring actions, kept current throughout the trial.
  2. KRI dashboard. A living view of current metric values against thresholds, updated on a defined cadence.
  3. Monitoring visit report. A standardized record of findings from each on-site or targeted visit, including follow-up items.
  4. Investigation log. A record of every QTL breach or significant KRI deviation, its root cause analysis, and resolution.

Escalation rules need clear ownership. Decide in advance who signs off when a KRI crosses into warning territory, who is authorized to close an investigation, and who approves a monitoring plan amendment. Leaving these decisions ambiguous during setup means they get decided ad hoc during a crisis, which is the worst time to establish a new process.

Pro Tip: Assign a single named owner to each KRI and QTL in the monitoring plan itself, not just in a separate RACI chart that nobody checks during a live investigation.

Training is often underestimated. CRAs accustomed to a purely on-site model need practice interpreting centralized monitoring dashboards and knowing when a flagged signal warrants escalation rather than a routine note. Site staff need clear expectations about what centralized review means for their day-to-day documentation habits. Change management here benefits from treating the shift as an operational change, not just a documentation update: a short training session paired with a few weeks of parallel monitoring, where both the old and new processes run side by side, smooths the transition considerably.

A practical first-90-days timeline looks like this: weeks one through three for the risk assessment workshop and initial CtQ identification, weeks four through six for drafting the monitoring plan and selecting QTLs and KRIs, weeks seven through ten for a pilot at a handful of sites with parallel monitoring, and the final weeks for refining thresholds based on pilot findings before handing the system to routine operations. Our site readiness checklist covers the prerequisites worth confirming before that pilot phase begins.

Four-stage 90-day RBM implementation timeline

Lessons from the field: what actually slows down RBM adoption

We approach a risk-based monitoring setup the way we approach most operational problems in biotech: starting from the strategic goal and working backward to find where the current process creates friction before selecting tools. Teams that start from a software purchase instead of a diagnosis of their actual bottlenecks tend to end up with a monitoring dashboard nobody trusts.

The pitfall we see most often is centralized monitoring rolled out before the data pipeline can support it: source data arrives too slowly, access agreements with sites are incomplete, and the monitoring team ends up reverting to on-site visits anyway, having spent months building a system nobody uses. The fix is sequencing: confirm data timeliness and access before reducing visit frequency, not after.

For teams weighing whether to build this capability internally or bring in outside support, our decision framework for choosing a fractional AI partner versus an internal team lays out the tradeoffs plainly. Our 90-day partnered pilot case study covers how predictive analytics on KRIs can catch drifting site performance before it becomes a QTL breach.

Why most RBM setups stall before they start

The conventional advice on risk-based monitoring treats it as a documentation exercise: write the plan, list some KRIs, get sign-off. That misses the actual difficulty, which is operational sequencing. The trials that get this right do not start with monitoring methods at all. They start by confirming their data actually arrives on time and in a form someone can review, then build the risk assessment and thresholds around what that infrastructure can support.

What gets overrated is the sophistication of the QTL and KRI list itself. A short list of well-chosen, well-documented thresholds with a clear investigation pathway beats an elaborate dashboard with forty tracked metrics that nobody reviews consistently. What gets underrated is training: a monitoring plan is only as good as the CRA's ability to read a centralized dashboard and know when a flag is noise versus a signal.

If you take one thing from this guide, prioritize the risk assessment workshop and the data infrastructure check before touching software or dashboards. Everything downstream depends on getting those two things right first.

— John

Where an operational partner fits into your RBM rollout

Setting up risk-based monitoring touches protocol design, data systems, site relationships, and quality oversight all at once, which is exactly the kind of cross-functional bottleneck that an operating partnership can address. Rather than selling a monitoring software license and leaving you to configure it, the approach starts from the trial's actual goals and timelines, maps where the current process creates delay or risk, and designs the workflow, including AI-enabled pieces, around what the team specifically needs.

Haiphai

For teams that have read this far and are weighing whether to build RBM capability in-house or bring in support, our AI Operating Maturity Diagnostic gives a concrete readiness picture before you commit resources either way. If a monitoring setup has been stuck in planning for months, that diagnostic is a reasonable place to start the conversation.

FAQ

What is risk-based monitoring?

Risk-based monitoring is an approach to overseeing clinical trial conduct that focuses monitoring resources on the data and processes most critical to participant safety and data reliability, rather than applying the same intensity of review everywhere. It relies on a formal risk assessment to identify those critical-to-quality factors and then tailors monitoring methods, frequency, and triggers accordingly, as described in FDA's risk-based monitoring guidance.

What are the top risk management tools used in clinical trials?

Teams commonly use Failure Mode and Effects Analysis, Fault Tree Analysis, Hazard Analysis and Critical Control Points, and Preliminary Hazard Analysis, each suited to a different stage or type of risk assessment. FMEA works well for breaking down a process step by step, while Fault Tree Analysis is better for tracing a specific adverse outcome back to its contributing causes.

What is the FDA's guidance for risk-based monitoring?

The FDA's guidance, Oversight of Clinical Investigations: A Risk-Based Approach to Monitoring, directs sponsors to prospectively identify critical data and processes, perform a documented risk assessment, and build a monitoring plan that specifies methods, timing, triggers for on-site visits, and documentation rules. A companion Q&A document adds practical examples for implementing these requirements.

How do I set up a risk management plan for a clinical trial?

Start by identifying your trial's critical-to-quality factors through a formal, documented risk assessment that scores each risk for likelihood, detectability, and impact. From that prioritized risk register, select a small number of quality tolerance limits for trial-critical parameters, define key risk indicators for ongoing tracking, and write a monitoring plan that specifies methods, frequency, escalation rules, and documentation requirements, consistent with the structure described in CASRAI's RBQM guide.

Sources

For primary guidance on monitoring plan components and centralized monitoring, see the FDA's risk-based monitoring guidance and its Q&A companion. For QTL and risk assessment methodology, see CASRAI's RBQM guide and ICH Q9(R1). For data integrity prerequisites underlying centralized monitoring, see Qualitum's GxP compliance guide.