Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
SOP Plug-and-play starting point Clinical & GCP

SOP: GCP Audit Program (Sponsor, Site, and Vendor Audits)

A plug-and-play SOP for a risk-based GCP audit program: the audit universe, risk scoring and frequency, routine versus for-cause audits, auditor qualification and independence, reporting and CAPA, and program metrics, with a filled specimen.

Document type: SOP

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use SOP for running a GCP audit program across sponsor systems, investigator sites, and vendors. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through document control. A worked filled specimen follows. Verify each cited regulation against the current source, and confirm the ICH E6 location, because R3 reorganizes the R2 section numbers cited here around its Principles and Annexes.

Document control header

FieldEntry
Document titleGCP Audit Program (Sponsor, Site, and Vendor Audits)
Document number<<FILL: SOP-ID, e.g. SOP-CQA-001>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Supersedes<<FILL: prior version or "New">>
Document owner<<FILL: role, e.g. Head of Clinical Quality Assurance>>
Applies to<<FILL: sponsor entity / regions / programs in scope>>

1. Purpose

This procedure defines how <<FILL: COMPANY NAME>> plans, conducts, reports, and closes GCP audits so that trials are run in compliance with Good Clinical Practice and applicable regulations, subject rights and safety are protected, and trial data are reliable. The program steers finite audit effort by risk, and it feeds a CAPA loop so findings become fixed systems rather than repeated observations.

2. Scope

This procedure applies to all GCP audits <<FILL: COMPANY NAME>> commissions: investigator site audits, vendor and CRO audits, internal and sponsor system or process audits, and database and trial master file audits, whether routine or for-cause. It covers audits performed by internal auditors and by qualified independent contractors acting on the sponsor’s behalf. It does not cover regulatory inspections, which are governed by <<FILL: SOP-ID for inspection management>>, though the audit program is the primary means of staying inspection-ready.

3. Responsibilities

RoleResponsibility
Clinical Quality Assurance (QA)Owns and approves the audit program; assigns and confirms auditor independence; approves reports and closes CAPAs.
Audit program manager / lead GCP auditorBuilds and maintains the risk-based program and schedule; leads or assigns audits.
AuditorPlans and conducts assigned audits, documents findings against evidence, and verifies CAPA.
Clinical operations, data management, pharmacovigilanceProvide risk inputs; own CAPAs for internal findings in their areas.
Senior managementEndorses the program through quality management review and resources it.
Audited party (site, vendor, internal function)Performs root cause analysis and implements CAPA.

4. Definitions

  • Audit: the sponsor’s systematic, independent examination of trial-related activities and documents to determine whether they were conducted, recorded, and reported per the protocol, SOPs, GCP, and applicable requirements. Defined in ICH E6 (R2 definition 1.6; carried forward in R3).
  • Inspection: an official review by a regulatory authority. Defined in ICH E6 (R2 definition 1.29). Not an audit.
  • Routine audit: a planned, periodic, broad audit that samples to confirm an entity is in control.
  • For-cause audit: a directed audit launched by a specific trigger; narrow, deep, and fast.
  • Audit universe: the full list of auditable entities (trials, sites, vendors, systems, processes).

5. Procedure

5.1 Build the audit universe

List every auditable entity: each active and recently completed trial, each investigator site or a documented sample frame of sites, each vendor performing a delegated GCP activity, each computerized system holding subject or trial data, and each core process (informed consent, IP accountability, safety reporting, monitoring, data management, TMF).

5.2 Score risk per entity

Score each entity on a consistent rubric. Typical factors and weights are documented in the risk-scoring worksheet:

FactorConsideration
Subject vulnerability and phaseVulnerable populations, first-in-human, complex safety profile raise risk
Enrollment and site countHigher volume and more sites raise exposure
ComplexityAdaptive design, complex IP, decentralized elements, real-world data
NoveltyNew vendor, new system, new therapeutic area
Prior historyPast audit and inspection findings, open CAPAs
Monitoring signalsOpen queries, protocol deviations, enrollment or data anomalies
Submission proximityTrials feeding a near-term marketing application

Weight and sum to a score, and record the basis.

5.3 Set frequency by risk band

Tie audit type and frequency to score bands (adapt the bands to your rubric):

Risk bandTypical treatment
HighQualification audit before go-live where applicable, then every 1-2 years, plus for-cause
MediumAudit every 2-3 years, or remote/questionnaire with periodic on-site
LowQuestionnaire or remote review; audit on cause

New critical vendors get a qualification audit before contract or go-live regardless of score.

5.4 Reserve for-cause capacity

Do not schedule auditors to full utilization. Hold roughly <<FILL: 20-30>> percent of audit days unscheduled for directed audits triggered during the year. For-cause work is unplannable and high value, so it must have room.

5.5 Approve and baseline the program

QA approves the annual program before the period starts. It becomes the controlled baseline against which execution is measured. Reassess mid-year on triggers: a serious deviation, a safety signal, a failed vendor deliverable, or a regulator action on a peer.

5.6 Qualify and assign auditors

  1. Confirm each auditor is qualified: education and trial experience, recorded GCP and audit-technique training, and supervised co-auditing before leading alone. Maintain an auditor qualification record.
  2. Confirm independence at assignment: the auditor must not audit an activity, system, or relationship they helped run.

5.7 Conduct, report, and close each audit

Each audit runs the standard loop: plan and notify, conduct (opening meeting, document and facility review, trace real transactions, interviews), debrief and close-out, report within the SOP timeline, obtain and verify CAPA, and close on effectiveness. Classify findings as critical, major, or minor per <<FILL: SOP-ID for finding classification>>. Use the per-audit plan and report templates.

5.8 Handle for-cause audits

Launch a for-cause audit on any trigger (serious or repeated non-compliance, safety-reporting failure, data anomaly suggesting fabrication, whistleblower, failed vendor deliverable, regulator action on a peer, or a data-integrity signal). Scope tightly to the trigger but follow the data. Preserve original records and audit trails where misconduct is possible. Escalate immediately on subject-safety or data-reliability findings. Where a for-cause audit confirms a serious breach likely to affect subject safety or data reliability, notify the relevant authority within the required timeline (under the EU CTR, without undue delay and not later than seven days of awareness).

5.9 Report program metrics

Report program KPIs to management on a defined cadence: audits planned versus completed, findings per audit by classification, CAPA on-time closure, repeat findings, and for-cause volume.

6. Acceptance criteria

The audit program is acceptable when it is:

  • Risk-traceable: every scheduled audit maps to a risk score or a written trigger.
  • Resourced: auditor days reconcile to the schedule with a for-cause reserve.
  • Independent: no auditor is scheduled to audit their own work, and auditors are qualified.
  • Measurable: it carries KPIs and reports them up.
  • Approved before the period starts, and reassessed on triggers.

If a manager cannot state in one sentence why a given audit is on the schedule and another is not, the program is not risk-based.

7. References

ICH E6 Good Clinical Practice (audit under R2 section 5.19; risk-based quality management under 5.0; sponsor responsibility for delegated duties under 5.2). Confirm the R3 location. 21 CFR Part 312 (312.50, 312.53, 312.56, 312.58), Part 50, Part 54, Part 56; Part 812 for device trials. FDA BIMO Compliance Program Guidance Manuals: 7348.811 (clinical investigators), 7348.810 (sponsors/monitors/CROs), 7348.809 (IRBs). Regulation (EU) No 536/2014 (Clinical Trials Regulation). ICH Q9 (Quality Risk Management); ICH Q10 (management responsibility).

Confirm the current version and clause numbers of each reference before issue.

8. Records generated

Audit program and master schedule; risk-scoring worksheet; auditor qualification records; per-audit plans and reports; CAPA records; program KPI reports; quality management review minutes.

9. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

10. Approvals

RoleNameSignatureDate
Author<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Head of Clinical QA)<<FILL>>

Filled specimen

The following shows a short extract of a completed annual program for an illustrative sponsor running two programs. The company, entities, and numbers are illustrative; replace them with your own.

Program year: 2026. Auditor days available: 180. For-cause reserve: 25 percent (45 days held).

EntityTypeRisk scoreBandAudit type and timingLead auditorIndependence confirmed
Trial ONC-301 (Phase 3, registration)Trial / sites84High4 site audits + pre-lock database audit, Q2-Q3A. LundYes
Central bioanalytical lab (PK)Vendor78HighPeriodic (last 2023); re-audit Q2M. DiazYes
EDC / eTMF providerVendor72HighPeriodic re-audit Q4A. LundYes
ICF translation vendorVendor22LowQuestionnaire onlyn/an/a
Internal PV / SAE reportingProcess60MediumInternal system audit Q3J. OkoroYes (not in PV line)

The extract shows the program is risk-traceable (each row carries a score and a band), resourced (a for-cause reserve is stated), and independent (the internal PV audit is assigned to an auditor outside the PV line). Those three properties are the first thing an inspector tests.

Common inspection findings this SOP prevents

  • An audit program that is not risk-based: auditing easy targets, skipping high-risk ones, or auditing everyone at one flat frequency.
  • No for-cause capacity, so the highest-value audits never happen.
  • Auditors auditing their own work, or auditors with no documented qualification.
  • Findings that do not close, shown by repeat findings at the next audit.
  • No program metrics, so management cannot see whether the loop is closing.
  • Serious breaches found in a for-cause audit but not reported to the authority within the required timeline.

How to adapt this SOP

  1. Set your document number, owner, and effective date in the header.
  2. Replace the risk factors and bands in sections 5.2 and 5.3 with your rubric, and set your for-cause reserve in 5.4.
  3. Point the cross-references to your real finding-classification, inspection-management, and CAPA procedures.
  4. Confirm the ICH E6 version in force in each region and update the R3 citation locations before issue.
  5. Confirm every regulation in section 7 against the current published version.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.