At a glance
- Clinical trial monitoring exists to do two things: protect participants and keep the data reliable. Everything else is method.
- There are not four “types” of monitoring to memorize. There are three delivery modes, on-site, remote, and central, and one strategy, risk-based monitoring (RBM), that decides the mix.
- Source data verification (SDV) is one monitoring task, not the whole job. Under a risk-based approach, how much SDV you do is set by risk, focused on the most critical data.
- On-site, remote, and central monitoring each catch different things. A good plan combines them deliberately, based on where the trial actually needs eyes.
- The guidelines, ICH E6(R3) and FDA’s risk-based monitoring guidance, require sponsors to monitor but are deliberately not prescriptive about how. The “how” is yours to design around risk.
If you read the top search results on clinical trial monitoring, you will come away thinking there are four monitoring “types” to learn, with risk-based monitoring sitting alongside on-site, remote, and central as a fourth peer. That framing is wrong, and it leads small teams to plan badly. This guide reframes monitoring around the question that actually matters, where does this trial need eyes, and shows how the three delivery modes are dials you set per risk under one governing strategy. It stays at the conceptual level: how to write the monitoring plan, which monitoring software to buy, and how to build a monitoring tracker each have their own dedicated guides.
What is clinical trial monitoring?
Monitoring is the activity by which a sponsor checks that a trial is being run correctly and that its data can be trusted. ICH E6(R3) states the aim plainly: the aim of monitoring is to ensure participants’ rights, safety, and well-being and the reliability of trial results as the trial progresses, and monitoring is one of the principal quality control activities (ICH E6(R3) §3.11.4). FDA frames it the same way: monitoring is a quality control tool for determining whether investigation activities are being carried out as planned (FDA RBM Q&A, Introduction). So monitoring is not paperwork for its own sake. It is the feedback loop that catches safety problems and data problems while there is still time to fix them.
Importantly, the rules require monitoring but not a particular method. FDA’s regulations require sponsors to monitor the conduct and progress of their investigations but are not specific about how (FDA RBM Q&A, Background). That deliberate openness is what makes a risk-based approach possible.
The monitor’s role: who is a CRA and what they actually do
The person doing site monitoring is usually a clinical research associate (CRA), acting as the sponsor’s representative. ICH E6(R3) requires that monitoring be performed by persons not involved in the clinical conduct of the trial at the site being monitored (ICH E6(R3) §3.11.4). Their work spans communicating with sites, verifying staff qualifications and resources, reviewing trial documents, and checking that essential records, consent, adverse-event reporting, and recruitment are in order (ICH E6(R3) §3.11.4). On-site monitoring, in FDA’s words, is an in-person evaluation carried out by sponsor personnel or representatives at the site (FDA RBM, §IV.A.1).
Source data verification is one task, not the whole job
The single most common misconception is that monitoring equals SDV, the line-by-line checking of case report form entries against source records. It does not. SDV is one activity among many, and under a risk-based approach its extent is bounded by risk. FDA is explicit: while SDV may be part of a risk-based monitoring approach, the extent to which SDV is used should be guided by the sponsor’s risk assessment and focused on critical study data and processes, which lets sponsors achieve a quality investigation without frequent routine visits to all sites and extensive SDV (FDA RBM Q&A, Q3). Treating SDV as the whole job is how teams burn their entire monitoring budget verifying low-risk fields while real signals go unwatched.
The three delivery modes: on-site, remote, and central
ICH E6(R3) groups monitoring into site monitoring, performed on-site and/or remotely, and centralised monitoring (ICH E6(R3) §3.11.4). These are the delivery modes.
On-site monitoring
An in-person visit to the site. It is good at things you can only judge in person: the quality of source documentation, staff familiarity with the protocol, investigational product accountability, and the overall conduct of the site (FDA RBM, §IV.A.1). FDA notes on-site monitoring is particularly critical early in a study, especially for complex or novel protocols (FDA RBM, §IV.A.1).
Remote monitoring
Site monitoring performed remotely, which ICH E6(R3) explicitly allows, including secure, direct read-only access to source records and data acquisition tools (ICH E6(R3) §3.11.4.1). Remote monitoring can accomplish much of what on-site visits do for data review, when records can be accessed securely.
Central (centralized) monitoring
A remote, analytical evaluation of accumulated data across sites. ICH E6(R3) defines it as a timely evaluation of accumulated data by qualified persons (for example a data scientist, statistician, or medical monitor) that can complement and reduce the extent or frequency of site monitoring, or be used on its own, to identify systemic or site-specific issues including protocol noncompliance and potentially unreliable data (ICH E6(R3) §3.11.4.2). FDA describes its uses concretely: review study-wide data for inconsistencies, check completeness and consistency, verify source data where feasible, and determine which sites need an on-site visit (FDA RBM Q&A, Q4). Central monitoring is especially good at what on-site visits miss: cross-site statistical outliers and anomalous data distributions that can indicate error or even fraud (FDA RBM, §IV.A.2).
On-site vs remote vs central: a decision matrix
| Mode | Best at catching | Blind spots | Use when |
|---|---|---|---|
| On-site | Source-document quality, IP accountability, site conduct, staff competence | Cross-site patterns; expensive and infrequent | Early in a study, complex/novel protocols, high-risk or inexperienced sites |
| Remote | Document and data review with secure source access | Physical site conditions, in-person rapport | Source records are accessible electronically; routine data review between visits |
| Central | Cross-site outliers, missing/inconsistent data, anomalies, fraud signals | Anything requiring physical presence | Continuously, to target and reduce on-site visits |
The point of the matrix is that no single mode is sufficient. FDA recommends a plan that ordinarily includes a mix of centralized and on-site monitoring tailored to the trial’s risks (FDA RBM, §IV).
Risk-based monitoring (RBM): the strategy that sets the mix
Here is the reframe. RBM is not a fourth delivery mode. It is the governing strategy that decides how much on-site, remote, and central monitoring a trial gets, and where. FDA recommends that sponsors use a risk-based approach to develop and revise their monitoring plans, identifying at the protocol-design stage the critical data and processes necessary for human-subject protection and data integrity, then performing a risk assessment to drive the plan (FDA RBM Q&A, Background). Those critical items typically include the data supporting primary and secondary endpoints, serious adverse events, informed consent, investigational product accountability, and blinding (FDA RBM, §IV.B).
From 100% SDV to risk-proportionate monitoring
The shift RBM represents is away from the old assumption that frequent on-site visits with 100% data verification are what FDA expects. FDA wrote the 2013 guidance precisely to correct that, encouraging greater reliance on centralized monitoring and a focus on the most critical data elements as more likely to ensure subject protection and study quality than routine visits to all sites with 100% verification (FDA RBM, §II.C). ICH E6(R3) aligns: the sponsor should determine the appropriate extent and nature of monitoring based on identified risks, considering the trial’s objective, design, complexity, blinding, number of participants, and endpoints (ICH E6(R3) §3.11.4). The risk assessment itself should weigh the likelihood, detectability, and severity of each risk (FDA RBM Q&A, Q1).
The monitoring process end-to-end
Across a trial’s life, monitoring runs from pre-study and site initiation through routine monitoring to close-out, with intensity that flexes by risk. FDA notes a tapered approach is often appropriate: more intensive, on-site monitoring early, then lighter monitoring once site procedures are established (FDA RBM, §IV.C). Throughout, the sponsor should monitor not only the risks identified up front but also new risks that emerge during conduct, revising the plan as needed (FDA RBM Q&A, Q2). When monitoring surfaces a significant issue, the response is a prompt root-cause analysis and corrective and preventive action, with the risk assessment and plan revised to prevent recurrence (FDA RBM Q&A, Q7).
What the guidelines require
To summarize the regulatory floor: sponsors must monitor, but they choose the method. ICH E6(R3) requires the sponsor to develop a monitoring plan tailored to the identified safety and data-reliability risks, focused on what is critical to quality (ICH E6(R3) §3.11.4.3). FDA’s guidance, both the 2013 RBM guidance and its 2023 Q&A, recommends a documented, risk-based approach and is explicit that its guidances are recommendations, not legally binding requirements, unless they cite a specific regulation (FDA RBM Q&A, Introduction). The binding obligation is to provide oversight and proper monitoring; the risk-based method is the recommended way to meet it.
A note on tooling and scope: this is a guide to what monitoring is and how the modes relate, not a how-to for the monitoring plan, a monitoring tracker, or monitoring software. TrialTrack handles clinical project management, tracking visits, timelines, and tasks, and sits around the monitoring workflow rather than performing the monitoring fieldwork or SDV itself.
The bottom line
Stop memorizing four monitoring “types.” Ask instead where your trial needs eyes, then set the dials: on-site for what you must see in person, remote for accessible data review, central for cross-site signals. Risk-based monitoring is the strategy that makes those choices, and it replaces reflexive 100% SDV with effort aimed at the data that actually matters. That is what both ICH E6(R3) and FDA’s guidance ask for, and it is what a lean team can actually execute.
Sources
Dejan Murko
Dejan is the co-founder of Mayet, building software for biotech and pharma teams.
