TrialTrack - Clinical Trial Project Management
All posts

Compliance

Protocol Deviation Log Template: Fields, Rubric, CAPA

Dejan Murko

At a glance

  • A protocol deviation is any departure from the approved protocol. The modern term for the serious ones is “important protocol deviation,” which is replacing the older “violation” language.
  • This page ships a fillable deviation log template plus the decision logic behind each column, so the log is a tracked workflow, not a dead spreadsheet.
  • Classification turns on impact: a deviation is important when it may significantly affect participant rights, safety, or well-being, or the completeness, accuracy, or reliability of the data.
  • The investigator documents all deviations; the sponsor sets the criteria for what counts as important. Reporting timelines are sponsor- and IRB/EC-defined, with GCP setting the documentation expectation.
  • An important deviation should trigger evaluation and, where appropriate, corrective and preventive action (CAPA). The log is where that bridge begins.

Most “protocol deviation log” pages give you a definition pair (deviation vs. violation) and a blank form with no instructions. They do not tell you how to classify severity, when a deviation becomes reportable, or how the log connects to CAPA and the audit trail, and many still use outdated terminology. This page is the working artifact plus the logic around it: a fillable template, a classification rubric, the reporting picture, and the deviation-to-CAPA bridge.

It is scoped to the deviation log. It does not teach how to author the protocol (see the protocol structure guide), the full monitoring and oversight workflow (see the oversight guides), or general CAPA/eQMS design beyond the trigger. For how log entries are preserved, see the audit-trail guide.

Protocol deviation vs. violation: the terminology, settled

A protocol deviation is any departure from the approved protocol, from a visit a few days out of window to a missed safety assessment. Historically, the more serious ones were called “violations,” but that word carries a punitive tone and an unclear threshold.

Why “important protocol deviation” is replacing “violation”

Modern GCP frames the serious subset as important protocol deviations, defined by impact rather than blame. ICH E6(R3) puts it precisely: the sponsor should determine trial-specific criteria for classifying protocol deviations as important, and important protocol deviations are a subset that may significantly impact the completeness, accuracy, or reliability of the trial data, or may significantly affect a participant’s rights, safety, or well-being (§ 3.9.3). That is the term to use. It is clearer than “violation” because it names the test (significant impact) instead of implying wrongdoing.

What a protocol deviation log actually needs (field-by-field)

A useful log captures enough to classify, escalate, and resolve each deviation. The fields:

Column What goes in it
Deviation ID Unique identifier for the entry
Date occurred When the deviation happened
Date identified When it was discovered
Site / subject Which site and (if applicable) which participant
Description What happened, factually
Protocol section affected The requirement that was departed from
Category E.g. eligibility, visit window, procedure, consent, IP, safety
Planned or unplanned Was it a pre-approved waiver/planned deviation or unplanned?
Classification Minor or important (per the rubric below)
Impact assessment Effect on safety, rights, and/or data integrity
Reported to (and date) Sponsor, IRB/EC, as applicable, with dates
CAPA required? Yes/No, with link to the CAPA record
Status Open / under review / closed
Owner Who is accountable for resolution

The download: a fillable protocol deviation log template

Copy the column headers above into a spreadsheet, one row per deviation. Here is a worked example row, filled end to end:

  • Deviation ID: PD-0042
  • Date occurred: 2026-02-10
  • Date identified: 2026-02-12
  • Site / subject: Site 03 / Subject 03-008
  • Description: Subject’s Week 4 visit conducted on day 35, outside the protocol-defined day 28 ±5 window.
  • Protocol section affected: Section 7.2, visit schedule
  • Category: Visit window
  • Planned or unplanned: Unplanned
  • Classification: Minor
  • Impact assessment: No impact on safety or eligibility; single out-of-window PK sample noted; data reliability not significantly affected.
  • Reported to: Sponsor 2026-02-12; not separately reportable to IRB per sponsor criteria
  • CAPA required?: No (isolated scheduling conflict; site re-briefed on windows)
  • Status: Closed
  • Owner: Site 03 CRC

How to classify severity: minor vs. major / important

A simple decision rubric

Ask three questions of every deviation:

  1. Did it affect participant rights, safety, or well-being?
  2. Did it affect the completeness, accuracy, or reliability of the data?
  3. Is it part of a pattern (recurring deviations can be important even when each instance looks minor)?

If the answer to (1) or (2) is “significantly,” classify it important. If the answers are “no” or “negligibly,” classify it minor. This mirrors the ICH E6(R3) test: important protocol deviations are those that may significantly impact data completeness, accuracy, or reliability, or significantly affect a participant’s rights, safety, or well-being (§ 3.9.3). The word doing the work is “significantly,” classification is a judgment about impact, made against the sponsor’s trial-specific criteria, not a mechanical label.

Note on planned vs. unplanned: a planned deviation (a documented waiver agreed in advance) is still logged, but the protocol fundamentally should not be deviated from without prior documented IRB/EC approval of an amendment, except when necessary to eliminate immediate hazards to participants (§ 1.4.7). Treat “planned deviation” carefully; recurring planned deviations often signal a protocol that needs amending.

Logging the deviation: who, when, and the reporting timeline

Who. The investigator is responsible for documenting all protocol deviations. ICH E6(R3) states the investigator should document all protocol deviations, review them, and for those deemed important, explain the deviation and implement appropriate measures to prevent recurrence where applicable (§ 2.5.3). In practice the coordinator (CRC) often makes the log entry, under the investigator’s responsibility.

When and to whom. Reporting timelines and thresholds are defined by the sponsor and the IRB/EC, not by a single universal deadline. GCP sets the expectation that deviations are documented and that important ones are acted on; the specific “report within X days” rules come from your sponsor’s procedures and your IRB/EC’s requirements. One firm rule: where a deviation was undertaken to eliminate an immediate hazard to participants, the investigator should inform the sponsor promptly (§ 2.5.4). For everything else, follow your sponsor and IRB/EC timelines rather than assuming a number.

From log entry to CAPA: when a deviation needs corrective action

A deviation log is not just a record; it feeds corrective action. An important deviation, or a pattern of minor ones, should trigger an evaluation of root cause and, where appropriate, corrective and preventive action (CAPA). This is the same instinct GCP brings to quality assurance: quality assurance should use risk-based strategies to identify potential or actual causes of serious noncompliance with the protocol, GCP, or regulatory requirements, to enable their corrective and preventive actions (§ 3.11.1). The bridge in practice: when an entry is classified important (or you notice a recurring minor pattern), set “CAPA required?” to Yes, open a CAPA record, and link it from the log. The deviation log thus becomes the front end of your quality loop, not a graveyard of incidents.

For preservation, log entries and their changes should be captured with an audit trail so the history of each deviation, and how it was classified and resolved, is reconstructable (see the audit-trail guide).

Common mistakes that make a deviation log fail an audit

  • Definition-only, no logic. A form with no classification rubric, so severity is inconsistent across entries.
  • Outdated “violation” framing instead of impact-based “important deviation” classification.
  • No impact assessment, so an inspector cannot see why something was graded minor.
  • No CAPA linkage, so important deviations have no corrective action trail.
  • Late or missing entries, undermining the contemporaneous record.
  • Logging the deviation but not the resolution, leaving entries perpetually open.

A log that classifies by impact, assesses each entry, links to CAPA, and is kept contemporaneously is the one that survives scrutiny.

A practical tooling note: a deviation log can live in a spreadsheet, but it benefits from sitting alongside the rest of the trial’s tracking with a proper audit trail. TrialTrack is clinical project management software that can centralize a deviation log with the trial’s other tracking; it is not an eQMS and does not make anyone GCP-compliant. For a small team, that centralization is the main draw; the classification discipline above is what actually matters.

Frequently asked questions

What is a protocol deviation vs. a violation? A deviation is any departure from the approved protocol. “Violation” was the older term for serious ones; modern GCP uses “important protocol deviation,” defined by significant impact on participant rights/safety or data reliability.

What goes in a protocol deviation log? Identifiers, dates occurred and identified, site/subject, description, protocol section, category, planned/unplanned, classification, impact assessment, reporting, CAPA linkage, status, and owner.

How do you classify a deviation as minor vs. important? By impact: if it may significantly affect participant rights, safety, or well-being, or data completeness, accuracy, or reliability, it is important. Otherwise minor. Patterns can elevate minor deviations.

Who logs deviations and within what timeline? The investigator is responsible for documenting all deviations (often via the CRC). Reporting timelines are set by the sponsor and IRB/EC; deviations to eliminate an immediate hazard must be reported to the sponsor promptly.

When does a deviation trigger a CAPA? When it is classified important, or when a pattern of minor deviations reveals a systemic cause. Open a CAPA record and link it from the log.

The bottom line

A protocol deviation log earns its keep only when it carries the decision logic, not just a definition. Capture the right fields, classify by impact using the “significant effect on rights/safety or data reliability” test, follow your sponsor and IRB/EC reporting timelines (reporting immediate-hazard deviations promptly), and bridge important deviations into CAPA. Build the log that way, keep it contemporaneous with an audit trail, and it becomes a tracked quality workflow that holds up under audit.

Sources

Dejan Murko

Dejan Murko

Dejan is the co-founder of Mayet, building software for biotech and pharma teams.