CROs & Contract Research

Contract research organizations — conducting clinical and nonclinical studies, bioanalysis, and pharmacovigilance under sponsor oversight.

What this page does not claim

A sector is an organization’s role in the value chain, not a legal category. SPEQ maps the disciplines and standards that role typically operates under; it does not determine which apply to your organization, and a count of decoded standards measures SPEQ’s coverage.

WHAT THIS SECTOR DOES

Contract research organizations (CROs) run studies on behalf of sponsors — clinical trials, nonclinical/toxicology studies, bioanalysis, and, increasingly, pharmacovigilance case processing. They generate the data that supports a marketing application, so the integrity and traceability of that data is the product. CROs span the full development pipeline from first-in-human through post-marketing safety.

REGULATORY LANDSCAPE

Clinical work follows Good Clinical Practice (ICH E6(R2), moving to E6(R3)), the EU Clinical Trials Regulation (536/2014), and FDA 21 CFR 50/54/56/312. Nonclinical safety studies follow Good Laboratory Practice (FDA 21 CFR Part 58, OECD GLP). Pharmacovigilance work follows EU GVP and ICH E2A/E2D. Computerised systems throughout are governed by 21 CFR Part 11 and EU GMP Annex 11.

THE OVERSIGHT MODEL

The sponsor may delegate trial conduct to a CRO but cannot delegate accountability — under 21 CFR 312.52 any transferred obligation must be described in writing, and the sponsor retains oversight duty. The CRO executes to the protocol and its SOPs; the sponsor performs risk-based oversight, reviews the Trial Master File, and remains answerable to the health authority for the study.

WHAT QUALITY MEANS HERE

01

Data integrity & the audit trail

ALCOA+ clinical and bioanalytical data with intact audit trails across EDC, LIMS, and eTMF — the evidence a regulator relies on to trust the submission.

02

Sponsor oversight & delegation

Clear written transfer of obligations, delegation logs, and the risk-based monitoring that lets the sponsor demonstrate real oversight of delegated work.

03

GLP study conduct

The study director model, protocol adherence, and independent Quality Assurance Unit that define a defensible 21 CFR Part 58 nonclinical study.

04

Pharmacovigilance timeliness

Case intake, assessment, and expedited reporting within GVP timelines — where a missed clock is itself a finding.

55
Standards decoded
5
GxP disciplines

STANDARDS SPEQ DECODES · 55

Open the full library →
21 CFR Part 11FDAHIGH INSPECTION RISK
Electronic Records; Electronic Signatures
EU GMP Annex 11EMAHIGH INSPECTION RISK
Computerised Systems
EU GMP Annex 22EC
Artificial Intelligence
ISPE GAMP 5 (2022)ISPE
Good Practice Guide: Compliant GxP Computerised Systems
ICH E6(R3)ICHHIGH INSPECTION RISK
Good Clinical Practice (GCP)
ICH E8(R1)ICH
General Considerations for Clinical Studies
21 CFR Part 312FDAHIGH INSPECTION RISK
Investigational New Drug Application (IND)
21 CFR Part 50FDAHIGH INSPECTION RISK
Protection of Human Subjects (Informed Consent)
21 CFR Part 56FDA
Institutional Review Boards (IRBs)
Regulation (EU) 536/2014EMAHIGH INSPECTION RISK
Clinical Trials Regulation (CTR)
21 CFR Part 58FDAHIGH INSPECTION RISK
Good Laboratory Practice for Nonclinical Laboratory Studies
OECD GLP PrinciplesOECD
OECD Principles of Good Laboratory Practice
Directive 2004/10/ECEC
Harmonisation of Laws Relating to the Application of GLP
EU GVP ModulesEMAHIGH INSPECTION RISK
EU Good Pharmacovigilance Practices (GVP)
21 CFR 314.80FDAHIGH INSPECTION RISK
Postmarketing Reporting of Adverse Drug Experiences
ICH E2B(R3)ICH
Electronic Transmission of Individual Case Safety Reports (ICSRs)
ICH E2AICH
Clinical Safety Data Management: Definitions and Standards for Expedited Reporting
WHO GCLP (2009)WHO
Good Clinical Laboratory Practice (GCLP)
VICH GL9VICH
Good Clinical Practice (Veterinary)
21 CFR Part 803FDAHIGH INSPECTION RISK
Medical Device Reporting (MDR)
IEC 62304:2006+A1:2015IEC
Medical Device Software — Software Life Cycle Processes
IMDRF/SaMD WG/N10IMDRF
Software as a Medical Device (SaMD): Key Definitions
IMDRF/SaMD WG/N12IMDRF
SaMD: Possible Framework for Risk Categorization and Corresponding Considerations
ISO/IEC 17025:2017ISO
General requirements for the competence of testing and calibration laboratories
ILAC MRAILAC
ILAC Mutual Recognition Arrangement
ICH M10ICHHIGH INSPECTION RISK
Bioanalytical Method Validation and Study Sample Analysis
ISO 20916:2019ISO
In vitro diagnostic medical devices — Clinical performance studies using specimens from human subjects
ICH E9(R1)ICHHIGH INSPECTION RISK
Statistical Principles for Clinical Trials, incl. Addendum on Estimands and Sensitivity Analysis
ICH E3ICHHIGH INSPECTION RISK
Structure and Content of Clinical Study Reports
ICH E2C(R2)ICHHIGH INSPECTION RISK
Periodic Benefit-Risk Evaluation Report (PBRER)
ISO 14155:2026ISOHIGH INSPECTION RISK
Clinical Investigation of Medical Devices for Human Subjects — Good Clinical Practice
ISO 15189:2022ISOHIGH INSPECTION RISK
Medical Laboratories — Requirements for Quality and Competence
FDA CSA Guidance (2026)FDAHIGH INSPECTION RISK
Computer Software Assurance for Production and Quality Management System Software
OECD GLP Advisory No. 22OECD
Advisory Document on GLP Data Integrity
ICH E2D(R1)ICH
Post-Approval Safety Data: Definitions and Standards for Management and Reporting of Individual Case Safety Reports
Reg. (EU) 520/2012ECHIGH INSPECTION RISK
Commission Implementing Regulation on the Performance of Pharmacovigilance Activities
21 CFR 600.80FDAHIGH INSPECTION RISK
Postmarketing Reporting of Adverse Experiences (Biological Products)
VICH GL24VICH
Pharmacovigilance of Veterinary Medicinal Products: Management of Adverse Event Reports (AERs)
ICH E2EICH
Pharmacovigilance Planning
IEC 81001-5-1:2021IEC
Health Software and Health IT Systems Safety, Effectiveness and Security — Part 5-1: Security — Activities in the Product Life Cycle
FDA GPSV (2002)FDAHIGH INSPECTION RISK
General Principles of Software Validation
FDA Premarket Cybersecurity (2026)FDAHIGH INSPECTION RISK
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
FDA PCCP for AI-Enabled DSF (2024)FDA
Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions
IEC 82304-1:2016IEC
Health Software — Part 1: General Requirements for Product Safety
42 CFR Part 493CMSHIGH INSPECTION RISK
Laboratory Requirements (CLIA)
40 CFR Part 160EPA
Good Laboratory Practice Standards (FIFRA)
OECD GLP Advisory No. 17OECD
Application of GLP Principles to Computerised Systems
EMA/INS/GCP/532137/2010EMA
Reflection Paper for Laboratories That Perform the Analysis or Evaluation of Clinical Trial Samples
ISO/IEC 27001:2022ISO
Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements
IEC 62443-2-1:2024IEC
Security for Industrial Automation and Control Systems — Part 2-1: Security Program Requirements for IACS Asset Owners
IEC 62443-3-3:2013IEC
Industrial Communication Networks — Network and System Security — Part 3-3: System Security Requirements and Security Levels
ICH M8 (eCTD v4.0)ICH
Electronic Common Technical Document (eCTD)
Regulation (EU) 2016/679EC
General Data Protection Regulation (GDPR)
ISO 31000:2018ISO
Risk Management — Guidelines
WHO LBM 4th ed. (2020)WHO
Laboratory Biosafety Manual, Fourth Edition

WHERE QUALITY FAILS

  • Data-integrity gaps in clinical, bioanalytical, or safety systems
  • Sponsor oversight that is documented on paper but not exercised in practice
  • Trial Master File that is incomplete or not inspection-ready
  • Expedited safety reports filed outside the required GVP/ICH timelines

KEY REGULATORY BODIES

Derived from the 55 standards SPEQ decodes for this sector.

CROs & Contract Research: frequently asked questions

Reference answers on what a cros & contract research does, what governs it, and who is accountable for quality.

What is a CRO?

A contract research organization runs studies on behalf of sponsors — clinical trials, nonclinical/toxicology studies, bioanalysis, and increasingly pharmacovigilance case processing. It generates the data that supports a marketing application, so the integrity and traceability of that data is the product, spanning the pipeline from first-in-human through post-marketing safety.

Which regulations govern a CRO?

Clinical work follows Good Clinical Practice (ICH E6(R2), moving to E6(R3)), the EU Clinical Trials Regulation 536/2014, and FDA 21 CFR 50/54/56/312. Nonclinical safety studies follow Good Laboratory Practice (FDA 21 CFR Part 58, OECD GLP), pharmacovigilance follows EU GVP and ICH E2A/E2D, and computerised systems fall under 21 CFR Part 11 and EU GMP Annex 11.

Can a sponsor delegate accountability to a CRO?

No. A sponsor may delegate trial conduct but not accountability. Under 21 CFR 312.52 any transferred obligation must be described in writing, and the sponsor retains its oversight duty. The CRO executes to the protocol and its SOPs; the sponsor performs risk-based oversight, reviews the Trial Master File, and remains answerable to the health authority.