Compliance
Dejan MurkoClinical Trial Oversight: A Governance Duty, Mapped to KPIs
At a glance
- Oversight is not “watching the trial.” It is the sponsor’s governance duty to ensure the trial’s conduct, processes, and data are good enough for reliable results and participant safety, and to be able to prove it.
- Under GCP, the sponsor keeps that duty even when work is delegated to a CRO or vendor. You can transfer the task; you cannot transfer the responsibility.
- The way to make oversight provable is to attach each oversight duty to a metric. This guide maps GCP sponsor-oversight duties to a small, runnable set of KPIs with sensible starting thresholds.
- A KPI tells you whether the trial is on track. A KRI (key risk indicator) is a metric tied to a risk threshold that signals trouble. A quality tolerance limit (QTL) is a study-level version of that threshold defined in GCP.
- A small team does not need an enterprise PMO. It needs a handful of the right metrics, a review cadence, and a clear escalation path.
Most pages treat “oversight” and “KPIs” as two separate topics: one explains sponsor responsibilities in the abstract, the other dumps a long list of metrics with no tie to why you track each. That leaves a small team with duties it cannot demonstrate and metrics it cannot justify. This guide fuses the two. It explains what oversight actually means under GCP, what stays your responsibility when you delegate, and then hands you a starter oversight KPI set, each metric tied to the duty it covers, with a threshold and a review owner. It deliberately does not cover how to build a monitoring tracker, write a risk management plan, or run day-to-day trial conduct; those are separate guides.
What clinical trial oversight actually means
Oversight is a governance function, not a conduct function. ICH E6(R3) defines the sponsor’s oversight duty in concrete terms: the sponsor should ensure that the trial design and conduct, the processes undertaken, and the data generated are of sufficient quality to ensure reliable results, participant safety, and appropriate decision making (ICH E6(R3) §3.9.1), and that trial processes comply with the protocol, applicable requirements, and ethical standards (ICH E6(R3) §3.9.2). FDA states the underlying obligation: sponsors are required to provide oversight to ensure adequate protection of the rights, welfare, and safety of human subjects and the quality and integrity of the resulting data (FDA RBM, §II).
Oversight vs running the trial
Running the trial is conduct: enrolling participants, dosing, collecting data. Oversight sits above that, asking whether conduct is producing safe, reliable results, and stepping in when it is not. FDA makes the boundary clear in a memorable line: quality is a systems property that must be built into an enterprise and cannot be achieved by oversight or monitoring alone (FDA RBM, §II). In other words, oversight does not create quality; it verifies and steers it. ICH E6(R3) adds that the range and extent of oversight measures should be fit for purpose and tailored to the complexity of and risks associated with the trial (ICH E6(R3) §3.9.5).
The sponsor stays accountable even when work is delegated
This is the rule small teams most often get wrong. Under GCP principle 10, a sponsor may transfer activities to a service provider, but responsibility for the conduct of the trial, including the quality and integrity of the data, still resides with the sponsor (ICH E6(R3) §II, principle 10). FDA says the same for CROs: although sponsors can transfer monitoring responsibilities to a CRO, they retain responsibility for oversight of the work the CRO performs (FDA RBM, §VI.B). Delegation changes who does the work, never who answers for it.
Sponsor oversight duties under GCP
ICH E6(R3) §3.9 enumerates the sponsor’s oversight duties. The ones that matter most for a small team:
- Ensure the conduct, processes, and data are of sufficient quality for reliable results and safety (ICH E6(R3) §3.9.1).
- Determine trial-specific criteria for classifying protocol deviations as important, where important deviations are those that may significantly affect data reliability or participant rights, safety, or well-being (ICH E6(R3) §3.9.3).
- Tailor oversight to trial complexity and risk; the selection and oversight of investigators and service providers are fundamental features of the process (ICH E6(R3) §3.9.5).
- Ensure appropriate and timely escalation and follow-up of issues (ICH E6(R3) §3.9.6).
- Consider an independent data monitoring committee to assess progress and safety and recommend whether to continue, modify, or stop the trial (ICH E6(R3) §3.9.7).
Oversight of delegated activities and CRO/vendor oversight
When work is delegated, oversight does not shrink; it changes shape. You now oversee the vendor’s performance. FDA’s guidance treats the selection and oversight of investigators and service providers as central, and centralized oversight metrics, such as delays in reporting data or high frequency of eligibility violations, are exactly the kind of signals that reveal whether a delegated party is performing (FDA RBM, §IV.A.2). The duty to oversee delegated activities is explicit in GCP (ICH E6(R3) §3.9.5).
Why risk-based oversight replaced “check everything”
The modern expectation is to focus oversight where risk concentrates. FDA’s whole risk-based monitoring guidance exists to move sponsors away from the assumption that checking everything equals good oversight, toward focusing on the most critical data and processes (FDA RBM, §II.C). ICH E6(R3) builds the same logic into quality management: identify the factors critical to quality and the risks to them, and control those risks proportionately (ICH E6(R3) §3.10).
The starter oversight KPI set (the deliverable)
Here is a small set you can run from week one. Each KPI is tied to the oversight duty it evidences. Thresholds are illustrative starting points, not regulatory requirements; calibrate them to your trial and document your rationale. Nothing here makes a sponsor compliant; these are tools for demonstrating that oversight is happening and working.
| KPI | Oversight duty it covers | Starter threshold (illustrative) | Reviewed by / cadence |
|---|---|---|---|
| Sites activated vs plan | Quality of trial conduct; feasibility (§3.9.1) | < 80% of planned at milestone → investigate | Study lead, monthly |
| Screen-failure rate | Eligibility integrity; protocol fit (§3.9.1) | Site > 1.5x study mean → review eligibility process | Study lead, monthly |
| Open query rate / query age | Data reliability (§3.9.1) | > 10% open beyond 30 days → escalate | Data manager, biweekly |
| Important protocol deviation rate | Deviation classification and control (§3.9.3) | Any upward trend or site outlier → review | QA owner, monthly |
| SAE reporting timeliness | Participant safety; escalation (§3.9.6) | Any late report → immediate escalation | Medical/safety, continuous |
| Vendor/CRO deliverable on-time rate | Oversight of delegated activities (§3.9.5) | < 90% on time → vendor review | Study lead, monthly |
| Essential-records (TMF) timeliness | Conduct quality; inspection readiness (§3.9.1) | Filing lag > 30 days → corrective action | QA owner, monthly |
The table is the centerpiece. Each row answers “which duty does this prove?” so an inspector or sponsor can see oversight is structured, not improvised.
KPIs vs KRIs, and how often to review
The three terms get blurred, so separate them:
- A KPI (key performance indicator) tells you whether the trial is on track: sites activated, query age, on-time deliverables.
- A KRI (key risk indicator) is a metric tied to a risk threshold that signals a developing problem, for example a screen-failure rate or deviation rate crossing a pre-set line. KRIs operationalize the risks you identified in your risk assessment.
- A quality tolerance limit (QTL) is the GCP-defined, study-level version of that threshold. ICH E6(R3) says that where relevant the sponsor should set pre-specified acceptable ranges, such as quality tolerance limits at the trial level, whose breach has the potential to impact participant safety or the reliability of results, and that breaches should be investigated for systemic issues (ICH E6(R3) §3.10.1.3).
So the relationship is: KPIs track performance, KRIs and QTLs track risk against thresholds, and a QTL breach is a study-level event you must investigate. For a small team, a handful of each is plenty. Over-instrumenting is its own failure mode: FDA warns that oversight cannot substitute for quality built in, and a wall of metrics nobody reviews is not oversight.
Putting oversight on a cadence
Metrics only become oversight when someone reviews them on a schedule and acts. Set a recurring governance review (monthly works for most small trials), bring the KPI set, and run it against thresholds. When a threshold or QTL is breached, escalate promptly, ICH E6(R3) requires appropriate and timely escalation and follow-up of issues (ICH E6(R3) §3.9.6), do a root-cause analysis, and act. Document the review and the decisions, because the documentation is what turns “we watched the trial” into “we governed it, and here is the evidence.”
A note on tooling: purpose-built clinical project management software can centralize these oversight KPIs for a small team, so the governance review reads from one place instead of a stack of spreadsheets. TrialTrack is one such tool. It helps organize oversight; it does not perform monitoring, EDC, or eTMF functions, and no tool makes a sponsor compliant. The responsibility stays with you.
The bottom line
Oversight is a governance duty GCP places squarely on the sponsor, and it survives delegation intact. Make it provable by attaching each oversight duty to a metric: a small KPI set with thresholds and review owners, KRIs and QTLs for the risks that matter, and a monthly cadence with real escalation. That is how a lean team demonstrates a trial is under control without an enterprise oversight apparatus.
Sources
Dejan Murko
Dejan is the co-founder of Mayet, building software for biotech and pharma teams.
