[ ENTERPRISE PILLAR 04 ]

Clinical Development & Operations

Protect participants while producing reliable clinical evidence through controlled study design, execution, oversight, data, and reporting.

What this pillar does not claim

This pillar owns trial strategy and execution; safety case management after and across trials connects to the safety-surveillance pillar.

The capability framing below, its failure modes and the boundary with neighbouring pillars are SPEQ’s practitioner reading — not a regulatory requirement, and not an assessment of any organization.

THE CAPABILITY

What this capability is

This is the only capability in the enterprise whose raw material is other people's willingness to take part, and whose output has to be reconstructable years later by a stranger, from records made largely by people the organization does not employ. It behaves like a distributed manufacturing operation whose product is evidence and whose plants are hospitals. The scientific half and the operational half are one capability rather than two because they fail into each other: a study that cannot be run as written yields a dataset that does not answer the question it was designed to ask, and no amount of operational excellence rescues a design that asked for something impossible in a clinic. Everything else here — sites, providers, the data, the essential records — exists to keep one chain intact, running from the intent behind an endpoint to the number that eventually appears in a report somebody else will read.

Why it is hard

Almost none of the work is done by the organization answerable for it. A sponsor is accountable for conduct performed by investigators it does not manage, inside institutions with their own priorities and their own queues, through providers it selected but does not run, involving people who may stop at any moment and owe nobody an explanation. Authority and accountability are separated by contract, so every control has to be exercised as persuasion, documentation or detection rather than instruction, and the strength of any control is bounded by how fast the sponsor can see what has already happened. The evidence is perishable in a way nothing else here is. A measurement not taken at a visit is gone: no retained sample, no repeat run, no second pass at that hour in somebody's life. Error is spent forward, and a quality problem found late can be described accurately but never repaired. Then there is the record. It has to let somebody who was not present reconstruct events several years afterwards, and it is written at the point of maximum operational pressure by clinical staff for whom the study is one demand among many and rarely the most urgent one. Each of those constraints is structural, and none of them yields to running the constituent activities well.

How it fails

Each of these happens with the individual branches below being run competently. That is what makes them capability failures rather than performance problems.

The protocol is designed for the answer, not the visit

The schedule is scientifically defensible and unaffordable inside a real clinic day. Sites absorb the difference with sequencing workarounds, and the departures that follow are read as site quality rather than as a design signal being returned by the network. The diagnostic is simple and rarely applied: if the same departure appears at most sites, it is a property of the protocol, not of the sites.

Monitoring verifies transcription and misses the study

Visits check what is checkable — fields against source, consent dates, product accountability — and often check it well. Meanwhile the thing that will undermine an analysis is a pattern across sites: an entry criterion consistently read one way at the highest-enrolling centres, an assessor whose scoring drifts across a year. No single visit can see a pattern that exists only in aggregate, and the visit report has nowhere to put one.

The essential file is assembled rather than kept

Documents are collected ahead of an inspection instead of being filed as events happen. What emerges is a plausible history rather than a contemporaneous one, and the gaps land exactly where events were unusual, because unusual events were handled by people who were busy. Timing cannot be added afterwards: a file that became complete last month says something quite different from one that was complete throughout.

Reading the provider report is mistaken for oversight

Governance meetings run on measures the provider produced about its own performance, so escalation depends on the provider deciding an issue is worth escalating, and the categories depend on how the provider defines its own terms. The sponsor learns about the problems the provider is comfortable reporting, on the provider cadence, and attendance at the meeting gets mistaken for the oversight it was meant to constitute.

WHERE THIS STOPS

Ours or theirs

This pillar owns the trial. It does not own the safety picture across and beyond it, and that is the seam that causes the most argument at the worst possible moment. An event reported at a site is at once a study event and a safety case, and the two obligations begin on different documents, in different systems, on clocks that start at different instants — so the dispute is rarely about what happened and almost always about when somebody first knew. The second seam is investigational supply: this capability owns whether the right participant received the right kit at the right time, the manufacturing and supply capabilities own whether it was made, labelled and shipped under control, and an excursion in transit is the point at which each assumes the other is judging fitness for use. The third is data, where clinical data management owns the study database and the meaning of what sits in it while the platforms, access model and retention belong to the digital pillar. The fourth is upstream: development characterizes the thing being tested, and this pillar produces the evidence of what it does in people.

Questions practitioners ask

What does sponsor oversight require beyond a well written contract?

Independent sight of the underlying work, at a frequency proportionate to what could go wrong: access to the data rather than a summary of it, sight of the provider quality events rather than a count of them, and at least one route by which a problem can reach the sponsor without passing through the party it concerns. A contract allocates responsibility; it does not create visibility.

Is risk-based quality management a monitoring strategy?

It is broader than monitoring, and calling it a monitoring model tends to shrink it to the part that is easiest to buy. It starts at design, by deciding which few factors genuinely determine whether the study can answer its question, and then shapes the protocol, the provider scope, the data flow and the oversight around those factors. Monitoring is one instrument it selects, not the thing itself.

Why is the trial master file treated as a live system rather than an archive?

Because its evidential value comes from when documents arrived, not only from whether they are present. A file that was complete and contemporaneous shows an operation that was under control while it ran; a file completed retrospectively shows an operation that could be described afterwards. Only the first supports the reconstruction a later reader needs, and the difference between them is not recoverable.

When does a protocol departure become a data problem?

As soon as it touches something the analysis depends on: eligibility, the timing of a primary assessment, the integrity of blinding, or the conditions under which a measurement was made. The routine that works is to ask, at the point of recording, which analysis population or endpoint the departure could move, and to route it on that basis rather than filing every departure into one undifferentiated queue.

CAPABILITY BRANCH MAP

What this pillar contains

01

Clinical development strategy

The plan for what evidence the programme must generate: endpoints, populations, phases, regions, comparators and the decision criteria that determine whether to continue after each stage.

A trial that runs perfectly against the wrong question wastes years and exposes participants for nothing. Strategy is where the evidence a regulator and a payer will each require is reconciled, before either can be asked.

HOW IT FAILS

  • Endpoints are chosen for statistical tractability rather than for what regulators and clinicians accept as meaningful.
  • Regional requirements are addressed sequentially, so a second market demands a study that could have been built into the first.
  • Go/no-go criteria are set after the data arrive, which makes continuation a negotiation rather than a decision.

WHAT CONTAINS IT

  • A development plan stating the evidence required per market and per audience, agreed cross-functionally.
  • Early regulatory advice on endpoints and design in the markets that matter most.
  • Decision criteria fixed before the data unblind, with the decision recorded against them.

EVIDENCE IT OPERATES

  • Clinical development plan with endpoint and population rationale.
  • Scientific advice and authority feedback on the design.
  • Stage-gate decisions recorded against pre-set criteria.
02

Protocol, statistics & study design

Turning the strategy into an executable study: objectives and estimands, endpoints, sample size, eligibility, assessment schedule, and the identification of what is genuinely critical to quality.

The protocol is the single document that governs everything sites do. Complexity added here multiplies across every participant at every visit, and the burden falls on people who had no part in writing it.

HOW IT FAILS

  • Assessments accumulate because each function adds what it would like, and feasibility is judged only after sites decline.
  • Eligibility criteria are written so tightly that recruitment fails, then amended repeatedly mid-study.
  • Critical-to-quality factors are not distinguished, so trivial and vital deviations receive the same response.

WHAT CONTAINS IT

  • Operational feasibility assessed with sites before finalisation, not after activation stalls.
  • A documented critical-to-quality analysis that names what actually matters and what does not.
  • Amendment discipline that treats each change as a cost to sites and participants, not only to timelines.

EVIDENCE IT OPERATES

  • Protocol with estimands, endpoints and sample-size justification.
  • Feasibility assessments and site input before finalisation.
  • Critical-to-quality factor analysis and the monitoring approach derived from it.
03

Feasibility, startup & site management

Selecting countries and sites, activating them, agreeing contracts and budgets, confirming they are genuinely ready, and supporting them for the duration of the study.

Sites are where the protocol meets reality, and they are independent organisations with their own pressures. A site activated before it is ready produces the deviations that consume the rest of the study.

HOW IT FAILS

  • Sites are selected on past enrolment volume rather than fit for this protocol and population.
  • Activation is treated as a document milestone, so a site is opened before staff are trained or supplies have arrived.
  • Support ends after activation, so a site with rising queries is not identified until data cleaning.

WHAT CONTAINS IT

  • Selection criteria that include population access, staffing and infrastructure for this specific protocol.
  • Readiness confirmed as a condition of activation, covering training, supplies and systems access.
  • Ongoing site performance review with intervention triggers rather than end-of-study discovery.

EVIDENCE IT OPERATES

  • Site feasibility, selection rationale and activation records.
  • Training and delegation logs current for the duration.
  • Site performance metrics and the support actions taken in response.
04

Participant protection, consent & engagement

The protections owed to the people in the study: ethics review, informed consent as an ongoing process, recruitment and retention practices, privacy, and communication with participants including about results.

This is the ethical foundation the entire discipline rests on, and the one failure that cannot be remediated after the fact. Consent obtained without genuine understanding is not consent, however complete the signature page.

HOW IT FAILS

  • Consent is treated as a form to be signed at enrolment rather than a process revisited as the study changes.
  • Re-consent after a substantial amendment is delayed, so participants continue under terms they never agreed.
  • Recruitment materials or incentives create pressure that undermines the voluntariness of the decision.

WHAT CONTAINS IT

  • Consent documents written for the participant and reviewed for comprehensibility, not only for completeness.
  • A defined re-consent trigger tied to amendments and new safety information, with tracking to completion.
  • Ethics review of recruitment materials, incentives and vulnerable-population safeguards.

EVIDENCE IT OPERATES

  • Ethics approvals for the protocol, amendments and participant-facing materials.
  • Consent records including version control and re-consent completion.
  • Privacy and data-protection assessments for participant data.
05

Trial execution & monitoring

Running the study: conduct against the protocol, monitoring, deviation handling, investigational product accountability, vendor coordination and escalation when something goes wrong.

Execution is where a good protocol either produces reliable evidence or does not. Deviations are the visible signal, and the way they are handled determines whether an issue is contained at one site or discovered across all of them at the end.

HOW IT FAILS

  • Deviations are logged and categorised but not aggregated, so a systemic protocol problem reads as many isolated site problems.
  • Investigational product accountability is reconciled at closeout, when discrepancies can no longer be explained.
  • Escalation depends on a monitor’s judgement with no defined threshold, so similar issues are treated differently.

WHAT CONTAINS IT

  • Deviation trending across sites with defined thresholds for protocol or process intervention.
  • Ongoing product accountability reconciliation rather than a single closeout exercise.
  • Documented escalation criteria and paths, including to the sponsor’s quality function.

EVIDENCE IT OPERATES

  • Monitoring reports and follow-up to closure.
  • Deviation records with categorisation, trending and resulting actions.
  • Investigational product accountability and temperature-excursion records.
06

Risk-based quality management

Directing oversight at what matters: identifying critical-to-quality factors, setting indicators and tolerance limits, monitoring centrally, and managing the issues that surface — rather than checking everything everywhere equally.

Effort spent verifying non-critical data is effort not spent on the factors that determine whether the trial can be relied on. Risk-based quality management is now the expectation rather than an alternative to full source verification.

HOW IT FAILS

  • Indicators are defined and then watched without pre-agreed tolerance limits, so nothing ever formally triggers.
  • Central monitoring identifies signals that no one owns, and they accumulate without disposition.
  • The risk assessment is completed at startup and never revisited as the study reveals where the real risk sits.

WHAT CONTAINS IT

  • Quality tolerance limits agreed in advance with a defined response when one is breached.
  • Named ownership for signal review and disposition, with timeframes.
  • Periodic re-assessment of risk during conduct, not only at design.

EVIDENCE IT OPERATES

  • Risk assessment and quality tolerance limits with rationale.
  • Central monitoring outputs with signal disposition records.
  • Records of tolerance-limit breaches and the actions taken.
07

Clinical data management & biostatistics

Everything that happens to trial data between collection and analysis: capture, coding, query management, reconciliation across sources, database lock, statistical analysis and the traceability that connects result to source.

The analysis is only as trustworthy as the path back to the source record. Where that path is broken, the result cannot be defended — and an inspector who cannot reconstruct a data point will not accept the conclusion built on it.

HOW IT FAILS

  • External data from laboratories, devices or vendors are reconciled late, and discrepancies surface near lock.
  • Query resolution changes data without the audit trail explaining who decided and on what basis.
  • Analysis populations and derivations are finalised after seeing the data, which invites unblinded choices.

WHAT CONTAINS IT

  • Ongoing reconciliation of every external data source against the primary database.
  • Audit-trailed query and correction handling with attributable decisions.
  • A statistical analysis plan finalised before unblinding, with deviations from it documented.

EVIDENCE IT OPERATES

  • Data management plan, reconciliation records and lock documentation.
  • Audit trails for data changes and query resolutions.
  • Statistical analysis plan with version history predating unblinding.
08

Trial master file & essential records

The essential records that allow the trial to be reconstructed: what exists, whether it is complete and contemporaneous, who can access it, and how it is archived for the retention period.

The trial master file is the trial as far as an inspector is concerned. A study conducted correctly but documented late is indistinguishable, from the outside, from one conducted badly.

HOW IT FAILS

  • Documents are filed in bulk before an inspection, so timestamps show curation rather than contemporaneous conduct.
  • Completeness is measured against a generic index rather than against what this study actually generated.
  • Records held by vendors and sites are assumed to be filed and are never confirmed to exist.

WHAT CONTAINS IT

  • Contemporaneous filing with completeness reviewed during conduct, not at closeout.
  • A study-specific expected-document list rather than a generic template.
  • Defined ownership and periodic confirmation for records held by sites and vendors.

EVIDENCE IT OPERATES

  • Trial master file completeness and quality-review records during conduct.
  • Filing timeliness metrics against document creation dates.
  • Archival records with retention period and retrieval demonstrated.
09

Clinical vendors, laboratories & systems

The external organisations and technologies the trial depends on — contract research organisations, central laboratories, imaging providers, eClinical platforms — and the sponsor oversight that remains regardless of delegation.

Activities can be delegated; accountability cannot. Sponsors are held to what their vendors did, and the oversight failure is usually not that a vendor performed badly but that nobody was checking in a way that would have noticed.

HOW IT FAILS

  • Oversight consists of receiving vendor status reports rather than reviewing the underlying quality data.
  • Responsibilities are allocated in a contract but never reconciled against what each party actually does.
  • System interfaces between vendor platforms are validated individually, and the data flow between them is not.

WHAT CONTAINS IT

  • A documented responsibility allocation reconciled against observed practice, not only signed.
  • Sponsor oversight based on quality indicators and audit, not status reporting alone.
  • End-to-end validation of data flows across system boundaries, including transfer specifications.

EVIDENCE IT OPERATES

  • Vendor qualification, contracts and responsibility matrices.
  • Sponsor oversight records including audits and issue escalation.
  • System validation and data-transfer verification across interfaces.
10

Closeout, disclosure & study reporting

Ending the study properly: site closeout and reconciliation, the clinical study report, registry disclosure and results posting, retention of records, and communication back to participants.

Disclosure obligations are legal duties with deadlines, and they are enforced independently of how the trial went. Closeout is also the last point at which a missing record can still be recovered from a site that still exists.

HOW IT FAILS

  • Registry results posting is missed or late because ownership transfers when the study team disbands.
  • Site closeout completes without confirming that records the sponsor will need remain retrievable.
  • The study report presents outcomes without accounting for deviations that bear on interpretation.

WHAT CONTAINS IT

  • Named ownership for disclosure obligations that survives study-team dissolution, with tracked deadlines.
  • Closeout checklists covering record retention and retrievability at the site, not only document return.
  • Study reports that address deviations, missing data and their effect on the conclusions.

EVIDENCE IT OPERATES

  • Site closeout records and retention agreements.
  • Registry registration and results-posting confirmations with dates.
  • Clinical study report with deviation and data-handling disclosures.

Why it matters in regulated work

  • Combines scientific quality with participant rights, safety, and well-being.
  • Coordinates sponsors, sites, investigators, laboratories, and service providers.
  • Maintains traceability from protocol intent through data and report.

Principal failure modes

  • Critical-to-quality factors are not controlled
  • Participant protection or safety escalation fails
  • Trial data or essential records are incomplete or unreliable

Control objectives

  • Design quality into the protocol and operating model
  • Control sites, vendors, safety, data, and essential records
  • Preserve traceability through closeout and reporting

Evidence families

  • Protocol, statistical, monitoring, and risk-management records
  • Consent, safety, site, and vendor-oversight records
  • Clinical data, trial master file, and study report

CONNECTED OPERATING MODEL

Where this capability connects

Lifecycle reach

  • Clinical Development
  • Regulatory Submission & Approval
  • Pharmacovigilance
  • Post-Market Surveillance
  • Discontinuation & Record Retention

Quality capabilities

  • Supplier Quality
  • Quality Risk Management
  • Audit & Inspection Management
  • Data Governance
  • Document & Record Control
  • Training & Qualification

System classes

  • CTMS
  • eTMF
  • EDC
  • eCOA / ePRO
  • IRT / RTSM
  • Safety / PV Database

Roles to start with

  • Clinical Data Coordinator
  • Pharmacovigilance Associate
  • Quality Assurance Associate

MATURITY ORIENTATION · SPEQ SYNTHESIS

What stronger operation looks like

  1. 01ReactiveOwnership and evidence are reconstructed after events; controls depend on individuals.
  2. 02DefinedScope, roles, methods, records, and escalation are documented for routine use.
  3. 03ControlledCritical controls are risk-based, verified, monitored, and governed through change.
  4. 04PredictiveLeading signals connect performance, drift, capacity, risk, and intervention.
  5. 05AdaptiveLearning improves the operating model without weakening accountability or evidence.

HIGH-VALUE INTERSECTIONS

SOURCE BASIS

REGULATORY BASIS

What governs this capability

The 12 standards SPEQ maps to this pillar, and the 6 regulatory bodies behind them. Which standards belong to a pillar is a SPEQ judgement; the bodies, disciplines and industries below are read from the standards themselves.

DISCIPLINES

BODIES

EC · EMA · FDA · ICH · ISO · VICH

Also reached through the systems this pillar runs on

These 8 standards govern the system classes this pillar depends on rather than the pillar itself. The distinction matters: a standard that governs a system is not thereby a standard of every capability that uses it.

21 CFR Part 11ISPE GAMP 5 (2022)MHRA GxP DI (2018)EU GVP ModulesICH E2AICH E2B(R3)ICH E2C(R2)21 CFR 314.80

PROFESSIONAL · READINESS ORIENTATION

Turn the pillar into a bounded operating conversation.

Rate observable operation from 0 (not established) to 4 (adaptive). The protected output prioritizes operating dimensions and evidence—not a compliance score.