At a glance
- A monitoring plan is the document that turns your risk assessment into concrete monitoring activity: who watches what, how often, by which method, and what happens when something is found.
- It is not the protocol and not a monitoring SOP. The SOP says how your organization monitors in general; the plan says how this trial is monitored.
- The clinical (site) monitoring plan and the medical monitoring plan are two different documents, with different authors and different jobs. Do not merge them.
- Every monitoring plan should produce a monitoring visit report. The plan defines what gets reviewed; the report records what was found and what action follows.
- Under risk-based monitoring, the plan is a living document. Risk re-assessment changes visit cadence, and the plan is versioned and amended accordingly.
Most monitoring-plan templates you can download are bare fill-in-the-blank forms: section headings with no explanation of why each exists, no link to the report the plan generates, and no separation of the site monitoring plan from the medical monitoring plan. They also tend to predate risk-based monitoring and assume one-size-fits-all 100% source data verification. This guide gives you a section-by-section blueprint with the reasoning behind each part, two copy-ready scaffolds (the monitoring plan and the visit report), and a clear split between the site and medical monitoring tracks. For the broader “what is monitoring and how do the modes relate” overview, see the monitoring discipline guide; this piece is about the document.
What a clinical trial monitoring plan is (and what it is not)
ICH E6(R3) requires the sponsor to develop a monitoring plan tailored to the identified potential safety risks, the risks to data quality, and other risks to the reliability of results, and to give particular attention to procedures relevant to participant safety and to trial endpoints (ICH E6(R3) §3.11.4.3). FDA puts the operational frame on it: for each clinical trial, the sponsor should develop a monitoring plan that describes the monitoring methods, responsibilities, and requirements for the trial, giving those who monitor enough information to carry out their duties (FDA RBM, §IV.D).
Monitoring plan vs monitoring SOP vs the protocol
These three are often confused:
- The protocol defines the trial: objectives, design, endpoints, procedures.
- The monitoring SOP is your organization’s standing procedure for how you monitor across trials.
- The monitoring plan is trial-specific: it applies your SOP and the trial’s risk assessment to this study. ICH E6(R3) notes the monitoring plan should reference the sponsor’s applicable policies and procedures (ICH E6(R3) §3.11.4.3), and FDA agrees a plan may reference existing SOPs rather than repeat them (FDA RBM, §IV.D.4).
Who authors and approves it, and when
The plan is owned by the sponsor (or the CRO acting for the sponsor) and should be reviewed by all sponsor and CRO personnel involved in monitoring, including those who decide on actions arising from monitoring findings (FDA RBM, §IV.D). Finalize it before the trial starts monitoring, because its whole purpose is to direct activity from the first site visit onward. FDA notes the value of an early monitoring visit soon after the first participants enroll, which only works if the plan already exists.
The monitoring plan, section by section
The structure below combines what ICH E6(R3) and FDA’s RBM guidance expect a plan to contain. For each section, the job it does is named.
- Study overview, scope, and monitoring objectives. A brief description of the study, its objectives, and the critical data and procedures, with attention to anything unusual that needs on-site training (FDA RBM, §IV.D.4). Job: orient every monitor to what matters.
- Roles and responsibilities. Sponsor, CRA/monitor, and site responsibilities, including who reviews findings and decides actions (FDA RBM, §IV.D). Job: no finding falls through the cracks.
- Monitoring strategy and risk-based triggers. A description of each monitoring method (on-site, remote, centralized) and how each addresses important risks, plus criteria for the timing, frequency, and intensity of activities and the events that trigger a change in monitoring for a given site (FDA RBM, §IV.D.1). ICH E6(R3) requires the plan to describe the monitoring strategy, the activities of all parties, the methods and tools, and the rationale for their use (ICH E6(R3) §3.11.4.3). Job: make the plan risk-driven rather than calendar-driven.
- Visit types and schedule. Site initiation, routine/interim monitoring, and close-out, with cadence set by risk. A tapered approach, more intensive early and lighter once procedures settle, is often appropriate (FDA RBM, §IV.C). Job: put eyes where and when the trial needs them.
- What gets reviewed. The critical data and processes from the risk assessment: endpoint data, safety and serious adverse events, informed consent, investigational product accountability, and blinding (FDA RBM, §IV.B). Job: focus effort on the data that can actually change the result.
- Escalation, deviations, and follow-up. The process for addressing unresolved or significant noncompliance, including root-cause analysis and corrective and preventive actions (FDA RBM, §IV.D.3), and how monitoring results are communicated to management and stakeholders (FDA RBM, §IV.D.2). Job: turn findings into fixes.
- Training and plan governance. Required training for monitors, and the process for amending the plan when risks change (FDA RBM, §IV.D.4–5).
The clinical trial monitoring plan template (fillable scaffold)
1. Study overview and monitoring objectives
2. Scope and critical data/processes (from the risk assessment)
3. Roles and responsibilities (sponsor / CRA / site / central reviewers)
4. Monitoring strategy
4.1 On-site monitoring (when, what, intensity)
4.2 Remote monitoring (scope, secure source access)
4.3 Centralized monitoring (analytics, signals, KRIs)
4.4 Risk-based triggers for changing monitoring
5. Visit types and schedule (SIV / routine / close-out)
6. What gets reviewed (consent, eligibility, SDR/SDV scope, AE/SAE, IP accountability, blinding)
7. Escalation, deviations, root cause and CAPA
8. Communication and reporting (formats, recipients, timing)
9. Training requirements for monitors
10. Plan governance: version control and amendment triggers
The medical monitoring plan: a separate track
The medical monitoring plan is a different document with a different author and a different purpose. Where the site monitoring plan governs data and process oversight, the medical monitoring plan governs ongoing safety surveillance by a medical monitor. FDA’s RBM guidance itself notes that “monitoring” can refer to the ongoing evaluation of safety data and the emerging risk-benefit profile of an investigational product by a medical monitor, a distinct sense from site monitoring (FDA RBM, §II). The medical monitor reviews accumulating safety data on a defined cadence and connects to safety reporting and, where one exists, to the independent data monitoring committee that ICH E6(R3) allows a sponsor to establish to assess progress and safety and recommend whether to continue, modify, or stop a trial (ICH E6(R3) §3.9.7). Keep this plan separate: merging it into the site monitoring plan blurs two different review functions and two different escalation paths. (Public templates such as the NIH/NIDCR clinical monitoring plan family are a common starting point for the site plan; treat them as structure, not as risk-based content.)
The monitoring visit report it produces
A plan that generates no record is not auditable. FDA specifies what documentation of monitoring activities should include: the date of the activity and who conducted it; a summary of the data or activities reviewed; a description of any noncompliance, potential noncompliance, data irregularities, or other deficiencies identified; and a description of any actions taken, to be taken, or recommended, with the person responsible and the anticipated completion date (FDA RBM, §V). That list is, in effect, the spec for your visit report.
Monitoring visit report template (fillable scaffold)
- Report metadata: study, site, visit type, date, monitor
- Activities and data reviewed (with sampling scope)
- Findings: noncompliance / data irregularities / deficiencies
- Action items: owner, due date, status
- Open items carried from prior visits
- Escalations raised
- Sign-off
Closing findings creates an audit trail that runs from the report back to the plan: a finding triggers an action, the action is tracked to closure, and recurring findings feed back into a revised risk assessment.
How a risk-based approach changes visit frequency
The biggest practical difference between a modern monitoring plan and the templates that predate risk-based monitoring is how visit frequency is set. The old default was a fixed calendar: visit every site every four to eight weeks, verify everything. A risk-based plan replaces that with a cadence driven by what each site and the study actually need. ICH E6(R3) makes the sponsor responsible for determining the appropriate extent and nature of monitoring based on identified risks, considering the trial’s objective, design, complexity, blinding, number of participants, and endpoints (ICH E6(R3) §3.11.4). So the plan should not state a single frequency; it should state the factors that raise or lower it.
FDA’s guidance turns this into concrete levers. It recommends a tapered approach, more intensive and on-site monitoring early in a trial and during a site’s first visits, then lighter monitoring once procedures are established and the site is performing (FDA RBM, §IV.C). It also lists the factors that justify more intensive monitoring for a given site: study complexity, endpoint type, population vulnerability, investigator experience, and the safety profile of the product (FDA RBM, §IV.C). The result is a plan where a high-risk or inexperienced site is seen more often than a seasoned one running a simple protocol, and where centralized monitoring signals, not the calendar, trigger the next on-site visit. Write the plan so those triggers and the factors behind them are explicit, and the cadence becomes a defensible consequence of risk rather than a number someone picked.
Keeping the plan alive: risk re-assessment and version control
A monitoring plan is not a one-time deliverable. FDA expects sponsors to consider what events require revision of the plan and to establish processes for timely updates, for example after a protocol amendment, a change in the definition of significant protocol deviations, or identification of new risks to study integrity (FDA RBM, §IV.D.5). ICH E6(R3) frames the same expectation through its risk-management cycle, where risk control measures are reviewed periodically and adjusted as new knowledge emerges (ICH E6(R3) §3.10.1). Version the plan, date each revision, and tie changes back to the risk that prompted them.
A note on tooling: TrialTrack is clinical project management software that can track monitoring visits, findings, and action items against the plan. It does not author the plan for you and it is not a standalone monitoring module; it is where the plan’s visits and follow-ups stay organized once the plan exists.
The bottom line
A good monitoring plan is the bridge between your risk assessment and real monitoring activity, written for this trial, kept separate from the medical monitoring plan, and built to produce a visit report that closes the loop. Make it risk-driven, not calendar-driven; version it as risks change; and let every finding flow into an action and, where needed, back into the plan. Do that, and the plan stops being a locked template and becomes the operating document monitoring actually runs on.
Sources
Dejan Murko
Dejan is the co-founder of Mayet, building software for biotech and pharma teams.
