CCDM Risk-Based Monitoring 2 — Questions and Answers
Question 1: What does 'targeted source data verification' (targeted SDV) mean in a risk-based monitoring plan?
- Verifying only data from the top-enrolling clinical sites
- Reviewing 100% of data fields for a randomly selected subset of subjects
- Selecting specific critical data fields or subject records for SDV based on risk assessment rather than checking all data (Correct answer)
- Limiting SDV to safety data only and skipping efficacy data
Correct answer: Selecting specific critical data fields or subject records for SDV based on risk assessment rather than checking all data
Targeted SDV focuses verification efforts on data fields defined as critical or high-risk (e.g., primary endpoints, eligibility criteria, serious adverse events) rather than performing 100% SDV across all data.
Question 2: According to ICH E6(R2), which entity is primarily responsible for implementing a quality management system for a clinical trial?
- The Institutional Review Board (IRB)
- The contract research organization (CRO) if one is used
- The sponsor (Correct answer)
- The principal investigator at each site
Correct answer: The sponsor
ICH E6(R2) Section 5.0 places the responsibility for implementing a quality management system — including risk identification and risk-based monitoring — squarely on the sponsor.
Question 3: In risk-based monitoring, what is the purpose of establishing a risk threshold for a KRI?
- To set the maximum number of protocol deviations allowed before a site is closed
- To define the point at which a KRI value triggers a predefined escalation or investigation action (Correct answer)
- To determine the minimum number of on-site visits required per year
- To calculate the overall budget for monitoring activities
Correct answer: To define the point at which a KRI value triggers a predefined escalation or investigation action
Risk thresholds define actionable cut-points; when a KRI value crosses the threshold, it generates a signal that prompts investigation, contact with the site, or an unplanned visit.
Question 4: Which statistical technique is commonly used in centralized monitoring to identify sites that are statistical outliers compared to the overall study population?
- Kaplan-Meier survival analysis
- Z-score and interquartile range (IQR) analysis (Correct answer)
- ANCOVA for treatment effect estimation
- Chi-square test for primary endpoint analysis
Correct answer: Z-score and interquartile range (IQR) analysis
Z-scores and IQR-based outlier detection are standard centralized monitoring tools that flag sites where data distributions (e.g., adverse event rates, missing data rates) deviate significantly from the study-wide norm.
Question 5: What action should a clinical data manager take when a KRI exceeds its predefined threshold during centralized monitoring review?
- Immediately lock the database for that site
- Escalate findings per the monitoring plan, which may include contacting the site and documenting the signal (Correct answer)
- Remove the site's data from the final analysis
- Wait until the next scheduled monitoring visit to investigate
Correct answer: Escalate findings per the monitoring plan, which may include contacting the site and documenting the signal
Exceeding a KRI threshold triggers the escalation process defined in the monitoring plan, which typically includes documenting the signal, contacting the site monitor or investigator, and determining whether additional oversight is needed.
Question 6: Which component must be included in a risk-based monitoring plan to satisfy ICH E6(R2) requirements?
- A complete list of all FDA-approved software platforms used at each site
- Documentation of the risk assessment that informed the monitoring strategy, including identified risks and mitigations (Correct answer)
- Signatures from all site investigators confirming they understand the monitoring approach
- A guarantee that no protocol deviations will occur during the study
Correct answer: Documentation of the risk assessment that informed the monitoring strategy, including identified risks and mitigations
ICH E6(R2) requires that the monitoring plan document the rationale for the chosen approach, including the risks identified, the KRIs selected, thresholds, and the mitigation strategies for each risk.
Question 7: Which of the following best describes a 'critical data' element in the context of risk-based monitoring?
- Any data field that is collected more than once per visit
- Data that directly affects subject safety determinations or the primary efficacy analysis (Correct answer)
- Data collected from the highest-enrolling sites only
- Electronic data capture fields that require double-data entry
Correct answer: Data that directly affects subject safety determinations or the primary efficacy analysis
Critical data are those whose accuracy directly impacts patient safety (e.g., serious adverse events, eligibility criteria) or the primary endpoint analysis, making them high-priority targets for SDV in an RBM framework.
What does 'targeted source data verification' (targeted SDV) mean in a risk-based monitoring plan?