01 · Monitoring vs. Audit
The Site That Looked Fine
The monitoring report said everything was fine. Enrollment was on track. Queries were being resolved. The site had a “green” status on the tracker for three consecutive visits.
Then an unannounced audit found: a critical inclusion criterion had been misapplied for six subjects. Source documents didn’t match the EDC on adverse event onset dates. The PI hadn’t reviewed and signed delegation logs in four months.
None of this showed up in the CRA’s visit reports. Not because anyone was hiding anything — but because the person writing the reports was also the person responsible for making the site look good to the sponsor.
This is the quiet risk in a lot of trial oversight: the same team that manages a site is often the one grading its own performance. It’s not an integrity problem. It’s a structural one.
The sites that surprise sponsors the most are rarely the ones flagged as “at risk.” They’re the ones that looked fine on paper — until someone without a stake in the outcome took a second look.
Illustrative scenario — not a specific ClariTria client engagement.
02 · Delegation vs. Decisions
Who’s Actually Making the Call
On paper, the Principal Investigator was overseeing everything. The delegation log listed their name against every critical task. Their signature was on the informed consent forms. Their credentials were exactly what the protocol required.
What the log didn’t show: the PI hadn’t personally seen a study patient in five months. Dose modification decisions, AE causality assessments, and eligibility calls were being made by a sub-investigator who was never formally delegated that authority. The PI reviewed and signed off on things after the fact — sometimes days later, sometimes in batches, sometimes without reading them closely at all.
Nothing about this looked wrong from the outside. The paperwork was complete. The signatures were there. It took someone actually asking, “Who made this call, and when?” — not just “Is this documented?” — to see the gap.
Delegation logs tell you who’s accountable on paper. They don’t tell you who’s actually making the decisions. That distinction is exactly where a lot of oversight stops looking — and exactly where it shouldn’t.
Illustrative scenario — not a specific ClariTria client engagement.
03 · IP & Temperature Reconciliation
When the Numbers Add Up But Aren’t True
The temperature log looked perfect. Every entry, every day, within range. Then someone pulled the freezer’s calibration certificate and noticed it had expired eight months earlier. The device had been quietly drifting the entire time — not enough to trigger an obvious excursion, just enough that no one questioned it. Every dose administered in that window was now a question mark: was the investigational product still within spec when it was given to patients?
Investigational product accountability is one of those areas everyone assumes is fine because the paperwork says so. Receipt logs match shipments. Dispensing logs match receipt logs. Temperature logs are filled in on schedule. It all reconciles — right up until someone checks whether the equipment generating those numbers was actually working.
Reconciliation tells you the numbers add up. It doesn’t tell you the numbers were ever true. That gap is easy to miss when the same site staff who dispense the product are also the ones documenting that everything went fine.
Illustrative scenario — not a specific ClariTria client engagement.
04 · SAE Reporting Timelines
Twelve Days on a 24-Hour Clock
The SAE was reported. Just not on time — and not to everyone who needed it. A patient was hospitalized on a Friday. The site coordinator documented it in the source notes over the weekend. It made it into the EDC the following Wednesday. By the time it reached the sponsor’s safety desk, twelve days had passed — well outside the 24-hour reporting window the protocol required.
No one had ignored the event. The coordinator was juggling three studies. The PI was traveling. The person who usually handled expedited reporting was on leave, and no one had been formally designated to cover it. Each individual delay looked minor. Stacked together, they turned a same-day reportable event into a two-week-late one — the kind of finding that draws real regulatory attention.
SAE timelines don’t fail because people don’t understand the rule. They fail because the rule assumes a chain of people who are all paying attention, all the time, with no single point of failure. Checking whether that chain actually holds — not just whether the SLA is written down — is a different kind of oversight than most sites get.
Illustrative scenario — not a specific ClariTria client engagement.
05 · Data Entry Timing
Clean by the Time the Monitor Arrived
One site was always “caught up” by the time the monitor visited. Every visit, the metrics looked fine: queries resolved, data entered, nothing overdue. What the visit-to-visit snapshot didn’t show was the pattern in between — data wasn’t being entered as visits happened. It was being entered in batches, right before each monitoring visit, sometimes three or four weeks after the actual patient encounter.
No data was wrong, exactly. But entries made three weeks after the fact rely on memory and reconstructed notes, not real-time documentation. Vital signs, concomitant medications, AE onset dates — all recorded with a lag that made “contemporaneous” a technicality rather than a fact. And because the backlog was always cleared before the CRA arrived, it never showed up as a finding.
Standard site metrics measure whether data eventually gets in. They don’t measure the lag between when something happened and when it was recorded — which is often the more important number. A site that’s “green” on entry completeness can still be running a documentation practice that wouldn’t hold up under real scrutiny. You only catch it by looking at timing patterns across visits, not the state of the data on any single day.
Illustrative scenario — not a specific ClariTria client engagement.
06 · Amendments & Re-Consent
Signed, But Not on the Current Form
The consent forms were all signed. That was never the question. The protocol had been amended twice in eight months — a dosing change, then a new risk added to the safety profile. Both amendments came with updated consent forms, approved by the ethics committee on time. What slipped through was re-consenting the patients already enrolled. Fourteen subjects continued in the study on a version of the consent form that no longer reflected what they were actually being exposed to.
Nobody skipped a step on purpose. The amendment tracker showed both versions as “implemented.” The site’s regulatory binder had the current form on file. What it didn’t show was whether that form had actually been walked through with each existing patient — versus just filed for new enrollments going forward.
Amendment tracking usually answers “do we have the right version?” It rarely answers “does every patient currently on study know what’s now on that version?” Those are two different facts, and the gap between them is where consent stops being valid even though every signature in the file is real.
Illustrative scenario — not a specific ClariTria client engagement.
07 · Finding Closure
Closed on a Promise
The finding was open for three visits in a row. Then, suddenly, it wasn’t. Site logs — the ones documenting drug accountability, temperature checks, equipment maintenance — had been incomplete since early in the study. The CRA raised it at visit one. Raised it again at visit two. By visit three, the study team was asking why this site’s metrics kept dragging down the program’s overall compliance numbers, and whether it was really worth escalating over paperwork.
The CRA closed the finding based on a verbal assurance from the PI that it would be brought current. No corrective action plan. No re-check built into the next visit. It went into the file as “resolved” and stayed that way — not because it actually was, but because closing it made the tracker look better and the pressure stopped.
Months later, when the logs were finally reviewed in full, the gaps were still there. Some were now unrecoverable — no one could reconstruct what had actually happened on days no one had documented in real time.
A finding closed on a promise isn’t a resolved finding. It’s an open one wearing a different status. The pressure to keep metrics clean is real, and it’s exactly the pressure an independent set of eyes isn’t subject to.
Illustrative scenario — not a specific ClariTria client engagement.
08 · Risk-Based Monitoring
The Sample That Missed It
The risk-based monitoring plan said 20% source data verification was enough for this site. On paper, it was. The site had a clean history, low protocol deviation rate, experienced staff. Every risk indicator pointed toward reduced oversight being the right call. So the CRA sampled one in five records each visit, exactly as the plan specified, and every sampled record checked out.
What the 20% never touched: a primary efficacy endpoint that was being measured with a device the site had recalibrated incorrectly after a firmware update. It affected every patient at that site, but by chance, none of the specific visits pulled for verification happened to fall in the window where the error was most visible. The sampling wasn’t wrong. It was just sampling — and the one systematic error at that site was exactly the kind a partial sample is statistically likely to miss.
Risk-based monitoring is built on a reasonable premise: you don’t need to check everything if the risk is genuinely low. But the plan is calibrated against historical risk, not against what’s happening at the site right now. A site can look low-risk on every indicator the plan tracks and still be sitting on a systematic issue that indicator was never designed to catch. That’s not a flaw in reducing SDV — it’s a reason someone still has to periodically ask whether the plan’s assumptions still hold.
Illustrative scenario — not a specific ClariTria client engagement.
09 · Deviation Logging
The Log That Was Too Clean
The deviation log for the site had four entries in eighteen months. Impressively clean — until someone compared it against the source notes.
The source notes told a different story: visit windows missed and quietly reopened without a note. Lab samples drawn outside the protocol-specified fasting period, documented as “fasting: yes” anyway. A dosing hold that should have triggered a formal deviation but was instead handled as an informal “clinical judgment call” between the PI and coordinator, never logged at all.
None of it was hidden exactly. It just never crossed the threshold of getting written down as a deviation, because the people deciding whether something counted as a deviation were the same people who’d have to report it if it did. Each individual call seemed defensible in isolation. Across eighteen months, the site had developed an informal, undocumented standard for what counted as “close enough” — one that never appeared anywhere a sponsor could see it.
A low deviation count can mean a well-run site. It can also mean the definition of “deviation” quietly shifted at the site level, one judgment call at a time. The only way to tell the difference is to look at what happened against what got logged — not just at how clean the log looks.
Illustrative scenario — not a specific ClariTria client engagement.
10 · Deviation Classification
Minor, Except for What It Measured
It was classified as a minor deviation. The classification was the actual problem. A patient had received a prohibited concomitant medication for three weeks before anyone flagged it — an interaction the protocol specifically excluded because of its effect on the primary safety endpoint. The site logged it, reported it, and categorized it as minor: the patient hadn’t experienced an adverse event, so on the surface, nothing had gone wrong.
A remote review of the deviation log against the exclusion criteria told a different story. The medication wasn’t excluded because it was inherently dangerous — it was excluded because it could mask or distort the very outcome the trial was measuring. Whether the patient felt fine was beside the point. The classification required someone to cross-reference the deviation against the protocol’s rationale, not just its symptom criteria, and that connection isn’t something a site — focused on patient welfare, correctly — is naturally positioned to catch.
This is a case where nothing needed to be seen on-site. The deviation report, the concomitant medication log, and the protocol’s exclusion rationale were all it took — reviewed together, remotely, by someone whose only job was to ask whether “minor” actually meant minor. Reclassified in time, it’s a data integrity conversation with the sponsor. Reclassified after database lock, it’s a conversation with the endpoint’s validity.
Illustrative scenario — not a specific ClariTria client engagement.