Monitoring, in the conventional CRO operating model, is an exercise in data verification. The monitor visits the site, opens the CRF, opens the source document, and checks that the values match. They check that the consent form is signed. They check that the dates are consistent. They check that the eligibility criteria were documented. The visit produces a monitoring report listing what was verified and any queries raised. The work is rigorous in the sense that fields get checked, and limited in the sense that field-level integrity is not the question the validation actually has to answer.

The validation has to answer whether the data supports the assay's intended-use claim. Field-level integrity is necessary for that case but nowhere near sufficient. A subject whose CRF data is perfect, whose consent is properly executed, and whose source documentation is impeccable can still be the wrong subject — enrolled outside the intended-use population, or enrolled at a time when the assay performance the claim depends on cannot be evaluated, or enrolled under conditions that compromise the assay's reference comparator. None of those problems show up in conventional field-by-field monitoring. All of them sink the validation at submission.

The framework below describes monitoring as we have come to understand it: as an investigation, in service of a case. The investigator's job is not just to verify the data. It is to assemble the evidence the regulator will eventually evaluate — and to do so with the regulatory question in mind throughout. Monitoring is what the documentary The Investigation would look like if it were filmed inside a CRO. The principles below describe how we run that investigation.

01

Monitor against the intended-use claim, not against the CRF.

The CRF is the artifact. The intended-use claim is the goal. Every monitoring decision should be made with reference to the claim the validation has to defend.

The first principle is the orientation. Most monitoring activity, in our experience, is oriented toward the CRF — the monitor opens the form, checks the fields, raises queries against discrepancies. This orientation is wrong. The CRF is the artifact, not the goal. The goal is whether each enrolled subject contributes to the case the validation has to make to FDA, and the CRF is one piece of evidence in that case among several.

The corrective is to anchor every monitoring action to the intended-use claim. This subject — does their enrollment, their eligibility, their sample collection, their visit cadence support the claim the assay will eventually be making? If the answer is yes, field-level integrity confirms the case. If the answer is no, field-level integrity is irrelevant — the subject does not belong in the dataset regardless of how clean their CRF is. The monitoring decisions that matter most are the ones at the level of subject fit, not field fit.

Where this principle came from

On rescue engagements we have repeatedly inherited datasets where the prior CRO had completed exhaustive field-level monitoring and produced a clean database — and where, on review against the intended-use claim, a meaningful share of the enrolled subjects were not in the population the claim referenced. The clean database did not save the validation. The validation required restructuring around which subjects were claim-supporting versus which were not, and the field-level cleanliness of the rest of the data was rendered moot by the population mismatch.

In practice

The intended-use claim should be on the wall in the monitoring room. Every subject reviewed should be reviewed first against the claim, then against the CRF. If the order is reversed, the monitoring is solving the wrong problem.

02

Every subject is a piece of evidence.

Monitoring is building a case, subject by subject. Each enrolled subject either supports the claim or does not — and the support is more than data integrity.

The second principle is investigative. A criminal investigator does not check every page of evidence with equal scrutiny. They prioritize the evidence that bears on the question. An IVD monitor should do the same thing. Each enrolled subject is evidence about whether the assay performs in the population the claim addresses, and the monitor's job is to assess each subject's evidentiary value before getting to the field-level details.

Some subjects are stronger evidence than others. A subject whose enrollment was clean, whose sample was collected under specified conditions, whose comparator was the gold-standard test, and whose values fall in the meaningful range of the claim — that subject is high-evidentiary-value evidence. A subject whose enrollment was technically eligible but whose comparator was a non-standard test, whose collection conditions were borderline, and whose values fall in a range the claim does not particularly address — that subject is low-evidentiary-value evidence. The monitor should know which is which on every subject in the database.

The investigative posture also surfaces evidence the conventional posture misses. Patterns across subjects are evidence. A site whose enrolled subjects systematically skew older than the eligibility envelope intends, even though every individual subject is technically eligible, is signaling something the field-level monitoring will not catch. A monitoring program that only checks fields, not patterns, will miss this signal entirely.

In practice

For each enrolled subject, the monitoring file should record an evidentiary assessment: what does this subject contribute to the case, with what strength, and against which part of the claim? Subjects that contribute weakly should be flagged. Subjects that contradict the claim should be reviewed in detail. The pattern across subjects, by site and over time, should be reviewed at every monitoring visit.

03

Check the details that matter, not all details equally.

100% source data verification on irrelevant fields wastes the monitoring budget. Eligibility-to-intended-use fit, source documentation, and deviation patterns are the fields that matter most.

The third principle is operational. The conventional monitoring model — 100% source data verification on every field — is an artifact of the era when monitoring was thought to need to verify everything because nothing else could. It is not the right discipline today. Risk-based monitoring guidance from FDA and ICH has explicitly authorized targeted approaches, and the targeting is not a corner-cutting move; it is a discipline that allocates the limited monitoring budget to the fields most predictive of validation outcomes.

The fields that matter most are not always the obvious ones. Eligibility-to-intended-use fit matters more than demographic fields. Source documentation for the comparator test matters more than for the visit dates. Deviation patterns across subjects at a site matter more than individual deviation counts on any one subject. The monitoring plan should rank fields by claim-relevance, allocate verification effort accordingly, and accept that some fields will be sampled rather than verified at 100%. The accepted samples are the fields whose imperfection does not threaten the claim.

In practice

The monitoring plan should categorize fields by claim-relevance: critical (verified at 100%), important (verified at a defined sampling rate), supportive (verified at a low sampling rate or via algorithmic checks). The categorization is part of the protocol; it should not be invented at the first monitoring visit.

04

Write the monitoring artifact as the case it is.

The monitoring report is part of the evidence the regulator will eventually evaluate. Write it as a case, not a checklist.

The fourth principle is about the artifact the monitoring produces. Conventional monitoring reports are checklists — fields verified, queries raised, deviations noted, signatures confirmed. The checklist format produces a document that is auditable but not persuasive. The validation submission, when it eventually goes to FDA, will not benefit from a stack of checklists. It will benefit from a coherent record of the investigation that produced the dataset — what was looked at, what was found, what was concluded, and on what evidence.

The right monitoring report reads like a case, not a checklist. The site's enrollment pattern over the period is described, not just enumerated. The deviation pattern, where one exists, is characterized with hypotheses about cause. The evidence for or against the validity of each subject is summarized, not assumed. The report tells the story of the investigation in a way the regulator could read and follow. The persuasive monitoring report is the same artifact as the auditable one — it just has narrative scaffolding the checklist version omits.

The deeper move this enables is the organizational discipline of treating monitoring as part of the regulatory submission, not as a separate operational function. The monitor who is writing toward an eventual regulator audience writes more carefully, reaches different conclusions, and surfaces different patterns than the monitor who is writing toward an internal status review. The audience matters. The right audience for the monitoring report is the regulator who will eventually read the validation submission, with the monitoring report sitting in the regulatory binder behind it.

In practice

Every monitoring report should include a narrative section above the checklists: what was investigated this visit, what evidence was assembled, what conclusions can be drawn, what remains open. The narrative should be readable by a regulator unfamiliar with the engagement and should make the case as clearly as the data permits.

What this framework rules out.

The four principles describe monitoring as an investigation in service of a regulatory case. They also rule out a few conventions worth naming.

They rule out data verification as the primary monitoring activity. Verification is a substep. The primary activity is investigation against the intended-use claim, with verification supporting where it matters and standing aside where it does not.

They rule out uniform 100% SDV as the default discipline. It is a discipline imported from an earlier era, and the regulators who would have required it have explicitly authorized targeted approaches. CROs that still default to 100% are paying for diligence that does not, on the margin, improve the validation case.

They rule out checklist-style monitoring reports as the format that serves the regulatory submission. Checklists are auditable but not persuasive. The submission needs both, and the persuasive part requires narrative the checklist format omits.

The framework is not closed. When the study outcome matters, you call RDI. Monitoring is investigation. Treat it that way and the validation it produces is the one the regulator can act on.