What RBQM means for clinical data management
Risk-Based Quality Management (RBQM) is a systematic approach to identifying, assessing, and controlling risks to data quality and subject safety in clinical trials. Under ICH E6(R3) Step 4 (January 2025), it is no longer optional guidance — it is a specific requirement of §3.10, which mandates that sponsors implement a quality management system that includes a prospective approach to quality risk management.
For CDM teams, RBQM means three things in practice: identifying which data elements are most critical to the trial outcome, defining measurable indicators that signal when those elements are at risk, and having a documented process for responding when those indicators breach defined thresholds. The paperwork is what most teams are missing.
Critical-to-Quality (CtQ) factors
A CtQ factor is a data element, process, or outcome that is essential to the reliability of the trial's primary conclusions. ICH E6(R3) §3.10.1 requires sponsors to identify CtQ factors prospectively — before the study begins — and to document them.
In CDM practice, CtQ factors typically fall into three categories:
- Efficacy endpoints: the primary and secondary endpoint data that drive the study conclusion. For an oncology trial, this might be progression-free survival data; for a cardiovascular study, MACE event adjudication data.
- Safety data: adverse event completeness, SAE timeliness, and the accuracy of causality and severity assessments.
- Eligibility and protocol compliance: inclusion/exclusion criteria, key protocol-required procedures, and visit windows for time-sensitive assessments.
The Medical Monitor or clinical team lead should sign off on the CtQ factor list. This sign-off should be documented — it is one of the first things an inspector will ask to see when reviewing RBQM implementation.
Key Risk Indicators (KRIs) and Quality Tolerance Limits (QTLs)
Once CtQ factors are identified, CDM teams define Key Risk Indicators (KRIs) — measurable signals that indicate when a CtQ factor is at risk. Each KRI needs three defined parameters: how it is calculated, what the alert threshold is (the value that triggers review), and what the action threshold is (the value that triggers escalation).
Common CDM KRIs include:
- Query rate per 1,000 data points — as a proxy for data quality at site level
- Missing primary endpoint data rate — percentage of expected endpoint CRF pages not yet completed
- SAE-to-database entry lag — days from SAE onset to EDC entry, against the study-defined SLA
- Protocol deviation rate — particularly for eligibility-related deviations
Quality Tolerance Limits (QTLs) operate at the portfolio or study-population level. Where a KRI monitors site-level signals, a QTL defines the overall study-level threshold beyond which the trial data integrity or subject safety is considered to be at unacceptable risk. QTL breaches require formal escalation and documented investigation — not just a note in the monitoring report.
The RBQM Risk Register
The Risk Register is the living document that ties CtQ factors, KRIs, and QTLs together. It records the current status of every KRI — the most recent value, whether it is within threshold, whether any breach has occurred, and what action was taken. It is reviewed and updated at defined intervals (typically monthly for active studies and quarterly for low-enrolment studies).
The Risk Register is not a static document produced at study start and filed in the eTMF. Inspectors expect to see a current Risk Register with a documented review history — evidence that the RBQM process was active throughout the study, not assembled retrospectively before a database lock.
What your RBQM SOP must document
Many CDM teams have some form of risk tracking in practice. What ICH E6(R3) now requires is that the process is formally documented in a SOP that specifies:
- How CtQ factors are identified and who approves them
- How KRIs are defined, calculated, and at what frequency they are reviewed
- What constitutes an alert threshold vs an action threshold, and what the escalation path is for each
- What the Risk Register contains, who maintains it, and how often it is reviewed
- How QTL breaches are investigated, documented, and reported
- How the RBQM outputs feed into the Data Review Plan and the overall study monitoring strategy
An RBQM process without a documented SOP is not defensible at inspection. An RBQM SOP without an active Risk Register to show for it is equally problematic. Both are required.
"The most common RBQM finding is not the absence of KRIs — it is a Risk Register that was created at study start and never updated. RBQM is an ongoing process, not a start-up deliverable."— Sarah Huntley, 25+ years CDM experience
ICH E6(R3) §3.10 — the specific requirements
ICH E6(R3) §3.10.1 states that the sponsor's quality management system should include a prospective, risk-based approach that identifies CtQ factors, assesses risks to those factors, implements appropriate risk controls, and reviews the effectiveness of those controls throughout the trial. §3.10.2 addresses QTLs specifically, requiring that sponsors define acceptable ranges for key parameters and document what happens when those ranges are exceeded.
These are not vague aspirational requirements. Inspectors from the FDA and EMA are now asking CDM and clinical operations teams to produce specific documentation: the signed CtQ factor list, the current Risk Register with its review history, and records of any KRI or QTL breach investigations.
CDM Library
CDM-SOP-005: Risk-Based Quality Management (RBQM)
A complete RBQM SOP for CDM teams — CtQ factor identification process, 4-level risk assessment matrix, standard KRI reference table, Risk Register field specification, escalation procedure, and review schedule. Built from ICH E6(R3) §3.10 and GCDMP: Assuring Data Quality.
Related articles: ICH E6(R3) vs E6(R2): What Changed for CDM · Audit Trail Requirements in Clinical Trials