This is a ready-to-use SOP for running a GCP audit program across sponsor systems, investigator sites, and vendors. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through document control. A worked filled specimen follows. Verify each cited regulation against the current source, and confirm the ICH E6 location, because R3 reorganizes the R2 section numbers cited here around its Principles and Annexes.
Document control header
| Field | Entry |
|---|---|
| Document title | GCP Audit Program (Sponsor, Site, and Vendor Audits) |
| Document number | <<FILL: SOP-ID, e.g. SOP-CQA-001>> |
| Version | <<FILL: version, e.g. 1.0>> |
| Effective date | <<FILL: effective date>> |
| Supersedes | <<FILL: prior version or "New">> |
| Document owner | <<FILL: role, e.g. Head of Clinical Quality Assurance>> |
| Applies to | <<FILL: sponsor entity / regions / programs in scope>> |
1. Purpose
This procedure defines how <<FILL: COMPANY NAME>> plans, conducts, reports, and closes GCP audits so that trials are run in compliance with Good Clinical Practice and applicable regulations, subject rights and safety are protected, and trial data are reliable. The program steers finite audit effort by risk, and it feeds a CAPA loop so findings become fixed systems rather than repeated observations.
2. Scope
This procedure applies to all GCP audits <<FILL: COMPANY NAME>> commissions: investigator site audits, vendor and CRO audits, internal and sponsor system or process audits, and database and trial master file audits, whether routine or for-cause. It covers audits performed by internal auditors and by qualified independent contractors acting on the sponsor’s behalf. It does not cover regulatory inspections, which are governed by <<FILL: SOP-ID for inspection management>>, though the audit program is the primary means of staying inspection-ready.
3. Responsibilities
| Role | Responsibility |
|---|---|
| Clinical Quality Assurance (QA) | Owns and approves the audit program; assigns and confirms auditor independence; approves reports and closes CAPAs. |
| Audit program manager / lead GCP auditor | Builds and maintains the risk-based program and schedule; leads or assigns audits. |
| Auditor | Plans and conducts assigned audits, documents findings against evidence, and verifies CAPA. |
| Clinical operations, data management, pharmacovigilance | Provide risk inputs; own CAPAs for internal findings in their areas. |
| Senior management | Endorses the program through quality management review and resources it. |
| Audited party (site, vendor, internal function) | Performs root cause analysis and implements CAPA. |
4. Definitions
- Audit: the sponsor’s systematic, independent examination of trial-related activities and documents to determine whether they were conducted, recorded, and reported per the protocol, SOPs, GCP, and applicable requirements. Defined in ICH E6 (R2 definition 1.6; carried forward in R3).
- Inspection: an official review by a regulatory authority. Defined in ICH E6 (R2 definition 1.29). Not an audit.
- Routine audit: a planned, periodic, broad audit that samples to confirm an entity is in control.
- For-cause audit: a directed audit launched by a specific trigger; narrow, deep, and fast.
- Audit universe: the full list of auditable entities (trials, sites, vendors, systems, processes).
5. Procedure
5.1 Build the audit universe
List every auditable entity: each active and recently completed trial, each investigator site or a documented sample frame of sites, each vendor performing a delegated GCP activity, each computerized system holding subject or trial data, and each core process (informed consent, IP accountability, safety reporting, monitoring, data management, TMF).
5.2 Score risk per entity
Score each entity on a consistent rubric. Typical factors and weights are documented in the risk-scoring worksheet:
| Factor | Consideration |
|---|---|
| Subject vulnerability and phase | Vulnerable populations, first-in-human, complex safety profile raise risk |
| Enrollment and site count | Higher volume and more sites raise exposure |
| Complexity | Adaptive design, complex IP, decentralized elements, real-world data |
| Novelty | New vendor, new system, new therapeutic area |
| Prior history | Past audit and inspection findings, open CAPAs |
| Monitoring signals | Open queries, protocol deviations, enrollment or data anomalies |
| Submission proximity | Trials feeding a near-term marketing application |
Weight and sum to a score, and record the basis.
5.3 Set frequency by risk band
Tie audit type and frequency to score bands (adapt the bands to your rubric):
| Risk band | Typical treatment |
|---|---|
| High | Qualification audit before go-live where applicable, then every 1-2 years, plus for-cause |
| Medium | Audit every 2-3 years, or remote/questionnaire with periodic on-site |
| Low | Questionnaire or remote review; audit on cause |
New critical vendors get a qualification audit before contract or go-live regardless of score.
5.4 Reserve for-cause capacity
Do not schedule auditors to full utilization. Hold roughly <<FILL: 20-30>> percent of audit days unscheduled for directed audits triggered during the year. For-cause work is unplannable and high value, so it must have room.
5.5 Approve and baseline the program
QA approves the annual program before the period starts. It becomes the controlled baseline against which execution is measured. Reassess mid-year on triggers: a serious deviation, a safety signal, a failed vendor deliverable, or a regulator action on a peer.
5.6 Qualify and assign auditors
- Confirm each auditor is qualified: education and trial experience, recorded GCP and audit-technique training, and supervised co-auditing before leading alone. Maintain an auditor qualification record.
- Confirm independence at assignment: the auditor must not audit an activity, system, or relationship they helped run.
5.7 Conduct, report, and close each audit
Each audit runs the standard loop: plan and notify, conduct (opening meeting, document and facility review, trace real transactions, interviews), debrief and close-out, report within the SOP timeline, obtain and verify CAPA, and close on effectiveness. Classify findings as critical, major, or minor per <<FILL: SOP-ID for finding classification>>. Use the per-audit plan and report templates.
5.8 Handle for-cause audits
Launch a for-cause audit on any trigger (serious or repeated non-compliance, safety-reporting failure, data anomaly suggesting fabrication, whistleblower, failed vendor deliverable, regulator action on a peer, or a data-integrity signal). Scope tightly to the trigger but follow the data. Preserve original records and audit trails where misconduct is possible. Escalate immediately on subject-safety or data-reliability findings. Where a for-cause audit confirms a serious breach likely to affect subject safety or data reliability, notify the relevant authority within the required timeline (under the EU CTR, without undue delay and not later than seven days of awareness).
5.9 Report program metrics
Report program KPIs to management on a defined cadence: audits planned versus completed, findings per audit by classification, CAPA on-time closure, repeat findings, and for-cause volume.
6. Acceptance criteria
The audit program is acceptable when it is:
- Risk-traceable: every scheduled audit maps to a risk score or a written trigger.
- Resourced: auditor days reconcile to the schedule with a for-cause reserve.
- Independent: no auditor is scheduled to audit their own work, and auditors are qualified.
- Measurable: it carries KPIs and reports them up.
- Approved before the period starts, and reassessed on triggers.
If a manager cannot state in one sentence why a given audit is on the schedule and another is not, the program is not risk-based.
7. References
ICH E6 Good Clinical Practice (audit under R2 section 5.19; risk-based quality management under 5.0; sponsor responsibility for delegated duties under 5.2). Confirm the R3 location. 21 CFR Part 312 (312.50, 312.53, 312.56, 312.58), Part 50, Part 54, Part 56; Part 812 for device trials. FDA BIMO Compliance Program Guidance Manuals: 7348.811 (clinical investigators), 7348.810 (sponsors/monitors/CROs), 7348.809 (IRBs). Regulation (EU) No 536/2014 (Clinical Trials Regulation). ICH Q9 (Quality Risk Management); ICH Q10 (management responsibility).
Confirm the current version and clause numbers of each reference before issue.
8. Records generated
Audit program and master schedule; risk-scoring worksheet; auditor qualification records; per-audit plans and reports; CAPA records; program KPI reports; quality management review minutes.
9. Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
10. Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Author | <<FILL>> | ||
| Reviewer (QA) | <<FILL>> | ||
| Approver (Head of Clinical QA) | <<FILL>> |
Filled specimen
The following shows a short extract of a completed annual program for an illustrative sponsor running two programs. The company, entities, and numbers are illustrative; replace them with your own.
Program year: 2026. Auditor days available: 180. For-cause reserve: 25 percent (45 days held).
| Entity | Type | Risk score | Band | Audit type and timing | Lead auditor | Independence confirmed |
|---|---|---|---|---|---|---|
| Trial ONC-301 (Phase 3, registration) | Trial / sites | 84 | High | 4 site audits + pre-lock database audit, Q2-Q3 | A. Lund | Yes |
| Central bioanalytical lab (PK) | Vendor | 78 | High | Periodic (last 2023); re-audit Q2 | M. Diaz | Yes |
| EDC / eTMF provider | Vendor | 72 | High | Periodic re-audit Q4 | A. Lund | Yes |
| ICF translation vendor | Vendor | 22 | Low | Questionnaire only | n/a | n/a |
| Internal PV / SAE reporting | Process | 60 | Medium | Internal system audit Q3 | J. Okoro | Yes (not in PV line) |
The extract shows the program is risk-traceable (each row carries a score and a band), resourced (a for-cause reserve is stated), and independent (the internal PV audit is assigned to an auditor outside the PV line). Those three properties are the first thing an inspector tests.
Common inspection findings this SOP prevents
- An audit program that is not risk-based: auditing easy targets, skipping high-risk ones, or auditing everyone at one flat frequency.
- No for-cause capacity, so the highest-value audits never happen.
- Auditors auditing their own work, or auditors with no documented qualification.
- Findings that do not close, shown by repeat findings at the next audit.
- No program metrics, so management cannot see whether the loop is closing.
- Serious breaches found in a for-cause audit but not reported to the authority within the required timeline.
How to adapt this SOP
- Set your document number, owner, and effective date in the header.
- Replace the risk factors and bands in sections 5.2 and 5.3 with your rubric, and set your for-cause reserve in 5.4.
- Point the cross-references to your real finding-classification, inspection-management, and CAPA procedures.
- Confirm the ICH E6 version in force in each region and update the R3 citation locations before issue.
- Confirm every regulation in section 7 against the current published version.