Courtesy Pexels
Intro
Life Sciences is a trillion dollar industry that is exceptionally good at proving that it followed a process.
Yet only about 5–6% of oncology therapies entering Phase I ultimately receive FDA approval. And Phase I is after discovery and target selection — exactly where enormous amounts of AI investment are going today.
Can we become equally good at proving that we understood the risk instead of accepting it as the cost of doing business?
Are patient risk, data quality and protocol compliance audit issues?
The 3 pillars of GCP are:
patient safety
clinical data quality
clinical protocol compliance
I was reading ICH E6(R3) Good Clinical Practice guideline from 2025.
The word “audit” and its derivatives appear 54 times. The phrase “safety risk” appears once. The phrases “clinical data quality” and “clinical protocol compliance” are not mentioned explicitly.
That surprised me because this is a standard for GCP .
The ICH standard says that trial processes should be proportionate to risks to participants, and:
“The focus should be on the risks associated with trial participation.”
Those risks explicitly include the rights, safety and well-being of trial participants as well as the reliability of trial results.
So far, so good.
But then something interesting happens.
Patient risk becomes risk-based quality management
When ICH gets to implementation, risk gets translated into a risk-based quality-management framework.
Sponsors identify risks to critical-to-quality factors.
They evaluate likelihood, detectability and impact.
Then come risk controls, monitoring plans, agreements, training, quality tolerance limits, risk communication, review and reporting.
Then comes Quality Assurance and Quality Control.
Then audit.
And the stated purpose of the sponsor’s audit is to determine whether the processes used to manage the trial ensure compliance with the protocol, GCP and regulatory requirements.
All of these things are useful.
But I think there is a fundamental difference between asking:
Are we managing a process correctly?
and asking:
What prevents us from protecting patient safety, acquiring high-quality clinical data and assuring protocol compliance?
The first question produces a quality system that sustains a process (something that life sciences industry does very well).
The second produces a threat model.
What if we started with the threats?
Suppose we took a different approach to GCP risk?
Before evaluating the CRO.
Before evaluating the protocol and EDC, ePRO, eCOA implementations.
Before evaluating the central lab, imaging provider, ePRO platform, AI endpoint provider or other service providers.
Build an independent model of how the trial can fail.
And ask 8 questions:
What can harm a participant?
What can compromise informed consent?
What can cause the wrong patient to be enrolled?
What can cause the wrong treatment to be administered?
What can break blinding?
What can cause a safety signal to be missed?
What can make an endpoint unreliable?
What can destroy the evidence you’re spending millions of dollars to produce?
Then map those threats to the systems, processes and vendors that can cause or control them.
Interestingly, ICH itself gets surprisingly close to asking for this.
The sponsor is supposed to identify risks across trial processes and systems, explicitly including participant selection, informed consent, randomisation, blinding, investigational-product administration, data handling and service-provider activities.
But it stops short of providing an objective, vendor-neutral model for identifying those threats and evaluating the controls.
Risk manage the quality system or risk manage the clinical trial?
CROs, software companies, labs and other service providers all have their own quality systems.
They should.
But a life science company needs something else as well. I believe that any biotech or device company needs an objective, vendor-neutral view of the risks of its clinical trial. This view start with the patient and the evidence, models what can go wrong, maps threats to controls and then map the vendors to the threats and controls for which they are responsible.
Now you can ask a much more interesting question than:
Does my CRO have the right SOPs?
You can ask:
Where can this trial fail, hurt patients or destroy the evidence — and which of my vendors controls each failure mode?
That’s risk analysis.
Audit against the risk
I’ve spent the past few months developing risk models for 1,501 FDA-cleared AI-enabled medical devices using OpenCRO - the AI risk officer.
Assets.
Threats.
Countermeasures.
Residual exposure.
I’m starting to wonder whether the same approach belongs upstream, in clinical trials.
OpenCRO is not another GCP compliance system, its not another dashboard of quality indicators, its not another pile of audit evidence.
The beauty of OpenCRO is speed and independence - being able to produce a risk model and evaluate SLE (single loss events) in dollars in 60s based on public records.
Because maybe we have the order backwards - before enforcing the process:
First understand the risk.
Then decide what needs to be controlled.
Then decide what needs to be monitored.
Then audit whether it happened.
Risk manage the clinical trial.
Not risk manage your CRO’s quality system.


