Clinical trial audits are independent quality assurance evaluations of trial activities, records, systems, facilities, and organizations. The main types include:
- Investigator site
- Sponsor
- Contract research organization (CRO) and vendor
- Trial-specific
- System or process
- Computerized system
- Specialized good practice (GxP)
The appropriate audit depends on what’s being evaluated, when it occurs, why it was initiated, and which regulatory framework applies. The sections that follow compare these audit types and explain when each is used. They also cover what organizations can do before an audit and after findings are issued.
What are clinical trial audits?
A clinical trial audit is a systematic, independent examination of trial activities and documentation to determine whether they comply with the protocol, a, Good Clinical Practice (GCP), and applicable regulations. It evaluates how the trial was conducted and whether the records accurately document that conduct.
The purpose of a clinical trial audit is to help protect participants, support reliable data, verify compliance, and identify quality risks affecting an individual study or a broader system.
Auditing differs from routine monitoring, which provides ongoing oversight of trial conduct. It also differs from a regulatory inspection, which is conducted by a regulatory authority to assess compliance.
Audit classifications can overlap. Subject and scope describe what an audit examines, while timing and trigger describe when and why it occurs. The applicable GxP framework adds another distinction. Clinical trial audits should be performed by qualified personnel who are independent of the activities being evaluated.
What are the main clinical trial audit types?
The most common types of clinical trial audits differ according to the organization, study, process, system, or records being evaluated.
Investigator site audits
A research site may be selected through a routine risk-based audit program or because of performance or compliance concerns. An investigator site audit then independently evaluates trial conduct and documentation at the site. It may examine informed consent, participant eligibility, protocol adherence, safety reporting, investigational product accountability, source data, and essential documents. The resulting audit report typically documents findings, required corrective actions, and follow-up activities.
Sponsor audits
Sponsor oversight and quality management responsibilities are the focus of a sponsor audit. The scope may include trial and risk management, safety processes, monitoring oversight, quality systems, vendor governance, and regulatory compliance.
The audit may focus on one study or examine sponsor-level systems and processes. Findings commonly address weaknesses in sponsor controls, oversight gaps, and corrective and preventive action (CAPA) requirements.
CRO and vendor audits
Sponsors and institutions may delegate trial-related responsibilities to CROs and other vendors, including laboratories, imaging providers, data-management partners, technology vendors, and specialized service providers. CRO and vendor audits examine how these third parties perform that work.
Audits may occur during vendor qualification, as part of routine oversight, or in response to performance concerns. Their outputs may include a qualification decision, risk classification, documented findings, and required remediation.
Trial-specific audits
At important study milestones – or when a study is selected through a risk-based program – organizations may conduct a trial-specific audit. This end-to-end evaluation examines the conduct and documentation of one clinical study, focusing on participant protection, protocol compliance, safety reporting, critical-to-quality factors, data integrity, and essential records.
Findings and recommendations address quality issues within the study and actions needed to correct them or prevent recurrence.
System or process audits
Unlike a trial-specific audit, a system or process audit examines procedures used across multiple clinical trials. These audits may cover SOP governance, training, safety reporting, monitoring, vendor oversight, trial master file management, data management, or CAPA processes.
System or process audits can reveal weaknesses that recur across studies, sites, or business units. Organizations can use process-level findings to investigate root causes and improve quality assurance.
Computerized system audits
Computerized system audits assess technology used to create, process, maintain, transfer, or report clinical trial information. Review areas generally fall into two groups: whether the system is fit for its intended use, including validation and change control, and whether electronic records remain secure and reliable, including access controls, security, audit trails, backup and recovery, vendor controls, and data integrity.
The audit should apply relevant electronic record requirements, including 21 Code of Federal Regulations (CFR) 11 when applicable, without assuming every requirement applies identically to every system. Outputs may include validation or control findings, identified data-integrity risks, remediation requirements, and follow-up testing.
Specialized GxP audits
The applicable GxP framework depends on the activity, product, facility, system, process, and data being evaluated. Specialized GxP audits apply that framework to regulated activities supporting a clinical trial.
GCP, Good Laboratory Practice (GLP), and Good Manufacturing Practice (GMP) audits differ primarily in what they assess:
- A GCP audit focuses on clinical trial conduct.
- A GLP audit addresses nonclinical laboratory activities.
- A GMP audit examines investigational product manufacturing and testing.
The most common audits focus on investigator sites, sponsors, vendors, individual trials, processes, computerized systems, or specialized GxP activities. An investigator site audit examines trial conduct at one research site, while a system audit evaluates a process used across multiple trials.
How do clinical trial audit types differ by timing and trigger?
Clinical trial audits may also be classified according to when they occur and what prompted them.
Planned or routine audits
Planned audits are scheduled through a risk-based audit program. Studies, sites, vendors, processes, and systems may be prioritized according to participant risk, data criticality, operational complexity, and regulatory exposure.
Qualification or pre-award audits
Qualification audits occur before an organization selects a site, vendor, laboratory, or other service provider. They assess whether the prospective partner has the personnel, experience, infrastructure, procedures, and controls required for the proposed work.
Findings may shape selection decisions, contract requirements, risk classifications, and oversight plans.
For-cause audits
For-cause audits are targeted assessments prompted by a specific quality, safety, compliance, or data-integrity concern. Triggers may include recurring protocol deviations, unusual data patterns, safety-reporting gaps, suspected misconduct, inadequate oversight, or unresolved monitoring findings.
A sponsor should consider a for-cause audit when available evidence indicates a significant or potentially systemic issue that routine monitoring cannot adequately evaluate.
Pre-inspection or mock inspection audits
Pre-inspection audits test inspection readiness by identifying weaknesses in documentation, processes, systems, and staff preparation. They may assess document retrieval, interview readiness, inspection logistics, known compliance gaps, and the organization’s ability to explain how the trial was conducted.
Before an audit, organizations should make sure relevant records can be retrieved and that staff are ready to explain how the trial was conducted.
Follow-up audits
After findings are issued, the responsible team should evaluate their significance and document how each will be corrected. Follow-up audits then determine whether CAPAs were implemented as planned and addressed the underlying issue.
Clinical trial audit types at a glance
| Category | Audit type | What it evaluates | Common use or trigger | Typical output |
| Audit type | Investigator site audit | Trial conduct and documentation at a research site | Routine risk-based selection or site-level compliance concern | Findings, corrective actions, and follow-up requirements |
| Audit type | Sponsor audit | Sponsor oversight, trial management, and quality systems | Study milestone, routine quality program, or oversight concern | Control findings, CAPA requirements, and quality improvements |
| Audit type | CRO or vendor audit | Third parties performing trial-related responsibilities | Qualification, routine oversight, or performance concern | Qualification decision, risk classification, and remediation plan |
| Audit type | Trial-specific audit | Conduct and documentation of one clinical study | Study milestone, risk signal, or inspection preparation | Study-level findings and corrective actions |
| Audit type | System or process audit | Processes used across multiple trials | Systemic risk, recurring findings, or routine quality review | Process findings, root-cause analysis, and system improvements |
| Audit type | Computerized system audit | Regulated technology and electronic records | Implementation, upgrade, vendor qualification, or data-integrity concern | Validation findings, remediation, and follow-up testing |
| Audit type | Specialized GxP audit | Clinical, laboratory, manufacturing, or related regulated activities | Applicable GCP, GLP, GMP, or other GxP responsibility | Compliance assessment, findings, CAPAs, and follow-up |
| Audit timing and triggers | Planned or routine audit | A prioritized study, site, vendor, process, or system | Risk-based audit schedule | Audit report, findings, and ongoing oversight actions |
| Audit timing and triggers | Qualification or pre-award audit | A prospective site, vendor, laboratory, or service provider | Before selection or contracting | Qualification decision, conditions, and oversight plan |
| Audit timing and triggers | For-cause audit | A specific quality, safety, compliance, or data concern | Significant deviation, unusual data, suspected misconduct, or unresolved issue | Targeted findings, root-cause assessment, and CAPA requirements |
| Audit timing and triggers | Pre-inspection or mock inspection audit | Inspection readiness across records, systems, processes, and personnel | Anticipated regulatory inspection | Readiness assessment, gap analysis, and preparation plan |
| Audit timing and triggers | Follow-up audit | Previously identified findings and corrective actions | CAPA completion or remediation milestone | Effectiveness assessment, closure decision, or additional actions |
Build an audit program around trial risks and responsibilities
Clinical trial audits may focus on investigator sites, sponsors, vendors, individual studies, quality systems, computerized systems, or specialized GxP activities. They may also be routine, qualification, for-cause, pre-inspection, or follow-up audits.
The right type and scope depend on the organization’s quality objectives, the trial stage, identified risks, and regulatory responsibilities. A coordinated, risk-based program can identify gaps early, strengthen oversight, protect participants, preserve data integrity, and support inspection readiness.
