RBQM in Clinical Trials: From Risk Evaluation to Risk Control That Actually Protects Your Study

In our previous issue, we looked at risk evaluation: how identified risks can be assessed more meaningfully by considering likelihood, impact, detectability, and the controls already in place.
That step helps teams understand which risks are more significant in the context of the trial.
But once that evaluation has been done, the next question is a very practical one:
What are we going to do about the risks that matter most?
This is where risk control comes in.

What risk control really means
Some organizations talk about risk controls, while others use the term risk mitigations. These are often used synonymously to refer to actions taken to address prioritized risks. Those actions may aim to:
- Reduce the likelihood that the risk event happens (PREVENTIVE ACTIONS).
- Improve the ability to detect it early enough to act (DETECTIVE ACTIONS).
- Reduce the impact if the event does occur (CONTINGENCY ACTIONS).
This distinction is important because a good control strategy is not just about putting something in place. It is about being clear on what the action is expected to change. If we are not clear about that, we can easily end up with controls that generate effort, but do not really reduce risk in any meaningful way.

The control should match the risk
What matters is not just having a control but making sure that the control is appropriately matched to the nature of the risk. Teams sometimes jump into actions that sound useful but are not well matched to the actual problem. For instamce, adding training when the real issue is poor process design; adding review meetings when the real weakness is lack of timely data visibility; creating a metric without defining what action should follow if the signal appears.
This is why a good control discussion should always return to the original logic of the risk:
- What is the risk event?
- What are the causes?
- What is the harm we are trying to avoid?
- Are we trying to reduce likelihood, improve detectability, or reduce impact?
If a control does not clearly connect back to one of those dimensions, it may not be a very strong control at all.
Proportionality still matters
This also links closely to proportionality. Not every risk needs a new or complex control. Many common risks in trials are already partly addressed through existing procedures, training, checks, and routine oversight activities.
The purpose of this step is not to add more activity everywhere. It is to decide where additional action is really needed and what kind of action is most likely to strengthen protection of participants and reliability of results.
The better question is not “What control can we add?” but “Is additional action really needed here, and if so, what type of action is most likely to make a meaningful difference?”
Because the goal is not to control everything more. It is to control the right things, in the right way, and to the right extent.
Risk control is not the same as delegation
This is another point worth stating clearly. Activities may be delegated but accountability does not disappear.
Sometimes a control is implemented through a CRO, another service provider, central function, or technology platform. That may be appropriate. But delegation is not a control strategy in itself. If a risk is being handled by a third party, the sponsor still needs to be clear on what is expected, who is responsible, how the control will be evidenced, and how its effectiveness will be overseen. Otherwise, the risk may be operationally delegated without being meaningfully controlled. And that is not the same thing.
Where risk control often becomes weak in practice
Most of us are used to seeing RACTs or extracts from risk management systems where a risk has been identified, evaluated, and linked to one or more control actions. That is, of course, an important part of the process. But in many cases, the real challenge starts after that point. The action may be listed in the register, but it is not always fully clear who is responsible for implementing it, by when it should be completed, how progress will be followed, or how the team will later know whether it was actually effective. So while the control appears to exist, the operational follow-through can remain weaker than it should be.
Sometimes too many controls are added without enough thought, creating burden but not always meaningful protection. In other cases, controls are described too vaguely, so the intent sounds reasonable but no one is really clear on what will happen, when, or by whom. Teams may also rely too heavily on detective controls, when what is really needed is stronger prevention earlier in the process. And contingencies are not always thought through, with the assumption that the issue will be prevented, but no clear plan in place if it still occurs.
Another common weakness is that the control does not clearly address the actual risk. It may look active in the register, but it is not always well targeted to the underlying issue or to the harm the team is trying to avoid.
This is why traceability is key. A control is much stronger when it is clear who owns it, what completion looks like, how it will be tracked, and how its implementation and effectiveness will be followed over time. Without that, a control may appear in the register, but it is much harder to show that it has truly become part of the way the study is being managed.
And that matters not only for internal quality management, but also for sponsor oversight. It should be possible to show that prioritized risks were translated into proportionate actions and that those actions did not remain static entries in a tool, but were actually followed through during the life of the trial.
These are exactly the kinds of weaknesses that tend to become visible later, when issues emerge and the response feels more improvised than planned.
Final thoughts
Risk control is really the point where a significant risk stops being something described in an assessment and starts being managed in practice.
Not by adding controls for the sake of it, but by being clear about what the action is meant to achieve, how it will work in practice, and how the team will know whether it is doing its job.
Reflect on this
When your team defines controls for prioritized risks, is it clear what each action is expected to change, who is responsible for it, and how follow-up will be performed?. If not, the control may be documented, but not yet fully operational.
With this issue, we conclude the initial phase of Risk- Based Quality Management (RBQM): the upfront identification, evaluation, and control planning of key trial risks. In the next edition, we will move into what happens once the study is underway: how risks are monitored in practice, how signals are detected, and how RBQM continues during study conduct.
—–
WiseCLIN is our purpose-built RBQM software designed to help sponsors implement risk based quality management in a structured, traceable, and inspection-ready way. Aligned with the principles of ICH E6(R3), WiseCLIN supports proactive RBQM by connecting risk identification, evaluation, mitigation, review, and oversight in one practical workflow.
Contact us here to learn more or request a demo.
Thank You,
Dr. Leire Zuñiga – PharmD PhD
Co-Founder and CQO, Qlarix | Founder and Managing Director, Pharmity | Risk-Based Quality Management (RBQM) Expert.
20+ years experience in Pharma, Biotech, CROs. Skilled in Quality Management, Good Clinical Practice and Computerised System Validation.



