4. Why This Matters Now
ICH E6(R3) reinforces a proportionate, risk-based approach to quality management and asks sponsors to identify factors that could meaningfully affect participant rights, safety, well-being, or the reliability of results. (ICH Database)
That matters because modern clinical trials may involve:
- decentralized activities,
- remote visits,
- local healthcare providers,
- digital health technologies,
- external data sources,
- specialized vendors,
- remote consent,
- participant-facing applications. FDA's decentralized-trial guidance explicitly addresses trial activities occurring outside traditional trial sites, including telehealth, in-home visits, and local healthcare providers. (U.S. Food and Drug Administration)
The more distributed the trial becomes, the more important the transitions become.
5. The Core Principle
A controlled system does not automatically create a controlled participant journey.
You may have:
a validated eConsent system,
a validated EDC,
a governed CTMS,
a compliant payment platform,
and defined SOPs.
Yet still have ambiguity around:
- whether a participant's consent is current,
- whether data access is still permitted,
- who owns a remote activity,
- whether a milestone occurred,
- what downstream system should react,
- how withdrawal changes future activity.
The unit of oversight should therefore include the participant event, not only the application.
6. The Participant-Control Chain
For every critical participant event, quality teams should be able to answer six questions: 1. EVENT
What happened?
2. OWNER
Who was responsible?
3. AUTHORITY
What consent, delegation, or permission allowed it?
4. EVIDENCE
What record proves the event occurred?
5. EFFECT
What downstream process changed because of it?
6. EXCEPTION
What happens if the event is late, missing, revoked, or disputed?
That six-part structure becomes the backbone of the controls map.
7. Control Point 1 — Candidate Identification
Event
Potential participant identified.
Control questions
What source produced the candidate?
Was the source permitted for the intended use? Was the candidate identified from:
- site records,
- EHR,
- registry,
- provider network,
- recruitment campaign,
- external data source?
Who is allowed to act on the result?
Evidence to retain
Source category
Timestamp
Matching logic/version where applicable
Owner/recipient
Next-action status
Risk
A candidate is surfaced, but provenance and permitted downstream use are unclear.
8. Control Point 2 — Recontact / Outreach
Event
Participant is contacted or invited.
Control questions
Who performed outreach?
Under what workflow?
Was provider-mediated outreach required?
Was prior permission required? Was the outreach attempt documented?
Was the person contacted through an approved channel?
Evidence
Outreach owner
Timestamp
Channel
Outcome
Recontact basis/workflow
Risk
The organization can identify patients but has inconsistent rules for activating them.
9. Control Point 3 — Pre-Screen
Event
Initial eligibility is assessed.
Control questions
What criteria were evaluated?
What data supported the assessment?
Which criteria were unknown?
Was the decision automated, manual, or mixed?
Can the team reconstruct why the candidate advanced?
Evidence
Criteria version
Inputs used
Missing evidence Decision/result
Reviewer where applicable
Risk
A patient progresses with no transparent rationale for why they were considered likely eligible.
10. Control Point 4 — Informed Consent
Event
Participant provides informed consent.
ICH E6(R3) maintains informed consent as a core participant-protection requirement, while the broader modernized GCP framework emphasizes participant rights, safety, and well-being. (ICH Database)
Control questions
Which consent version?
When was it signed?
By whom?
Was the participant given adequate information?
Was re-consent required later?
Which permissions extend beyond trial participation?
Evidence
Consent version
Timestamp
Participant signature/evidence
Investigator/site evidence as applicable
Re-consent history Risk
A consent artifact exists, but downstream teams cannot determine its current operational meaning.
11. Control Point 5 — Data Access
Event
Participant clinical data is accessed or shared.
Control questions
What data?
Who accessed it?
For what purpose?
What authorization existed?
Was access within the permitted scope?
Did permission expire or change?
Evidence
User/organization
Data category
Timestamp
Purpose/workflow
Permission reference
Risk
The data system logs access technically, but the organization cannot easily relate that access to current participant permission.
12. Control Point 6 — Eligibility Decision
Event
Participant is formally determined eligible or ineligible.
Control questions
Which protocol version applied?
What evidence supported the decision?
Were unresolved criteria present?
Who made the decision?
What changed if the decision was revised?
Evidence
Protocol version
Relevant source evidence
Decision owner
Timestamp
Reason for exclusion if applicable
Risk
Eligibility status changes without a clear evidence trail.
13. Control Point 7 — Remote / Decentralized Activity
Event
A participant completes a study activity outside the traditional site. Examples include telehealth, in-home activities, or visits involving local healthcare providers, all of which are addressed in FDA's decentralized-trial guidance. (U.S. Food and Drug Administration)
Control questions
Who performed or oversaw the activity?
What role had been delegated?
How was completion verified?
Which source data was generated?
Which system received the status?
Was escalation required?
Evidence
Activity type
Responsible role
Timestamp
Completion state
Associated data
Exception state
Risk
The activity occurs successfully, but responsibility or downstream status remains fragmented.
14. Control Point 8 — Digital Health / Participant-Generated Data
Event
Data is generated remotely through a device or participant-facing tool. Control questions
Which device/app generated it?
Which participant does the data belong to?
Was data complete?
Was the device functioning?
Who reviews missing or anomalous data?
Does the event create an operational action?
Evidence
Device/source identifier
Participant link
Timestamp
Data completeness
Exception/escalation state
Risk
Data exists but responsibility for monitoring or action is unclear.
15. Control Point 9 — Study Milestone Completion
Event
A participant completes a qualifying study milestone.
Examples:
- visit,
- assessment,
- telehealth session,
- questionnaire,
- procedure,
- required data contribution.
Control questions
What proves completion?
Which system is authoritative?
Can completion trigger downstream activity?
Is another manual confirmation required?
Evidence
Milestone type
Timestamp
Source system
Verification status
Approver if needed
Risk
The same milestone has different states across EDC, CTMS, patient systems, and finance.
16. Control Point 10 — Participant Payment / Reimbursement
Event
Participant becomes eligible for payment or reimbursement.
Control questions
Which milestone created eligibility?
Was it verified?
What amount/rule applied?
Was an exception processed? When was payment actually made?
Evidence
Milestone reference
Payment eligibility
Amount/category
Approval
Payment timestamp
Exception history
Risk
Finance can prove money moved, but not always which verified participant event authorized the payment.
17. Control Point 11 — Change in Consent / Re-Consent
Event
Participant permission changes.
Control questions
What changed?
When?
Which downstream activities are affected?
Who must be notified?
Does the system prevent future activity inconsistent with the new status?
Evidence
New consent version/status Timestamp
Affected permissions
Downstream acknowledgement
Risk
Consent status changes in one platform but downstream processes continue under outdated assumptions.
18. Control Point 12 — Withdrawal
Event
Participant withdraws from some or all trial activities.
Control questions
What exactly was withdrawn?
Does withdrawal apply to:
- future study participation,
- future contact,
- future data collection,
- optional research activities?
Which existing data remain usable under applicable rules/protocol?
Who must react?
Evidence
Withdrawal scope
Timestamp
Owner
Affected downstream processes
Risk
The word “withdrawn” exists, but operational implications differ between teams and systems. 19. The Participant Journey Controls Table
For every event, complete:
Event Owne Authority/Permissi Eviden System Downstrea Exceptio r on ce of m Effect n Path Record
Candidate identified
Outreach
Pre-screen
Consent
Data access
Eligibility
Remote activity
Milestone
Payment
Re-consen t
Withdrawal
20. The Four Control Failure Patterns
Pattern 1 — Event Exists, Owner Unclear
Example:
A remote visit is completed, but no one clearly owns the downstream exception. Pattern 2 — Owner Exists, Evidence Fragmented
Example:
Coordinator knows the participant completed the activity, but proof lives across email and two applications.
Pattern 3 — Evidence Exists, Permission Unclear
Example:
Clinical data is available, but whether it can be used for the next workflow still requires manual interpretation.
Pattern 4 — Event Is Controlled Locally, but Downstream State Is Wrong
Example:
Consent is updated correctly, but another system continues operating on the previous status.
These are exactly the types of handoffs a cross-system control map should surface.
21. Risk-Based Prioritization
Do not apply equal control intensity to every workflow.
A risk-based model should focus attention where failures could materially affect:
- participant rights,
- participant safety,
- participant well-being,
- reliability of trial results,
- critical trial decisions.
This is consistent with E6(R3)'s quality-by-design and critical-to-quality orientation. (ICH Database) Score each handoff
Participant impact: 1–5
Data/reliability impact: 1–5
Frequency: 1–5
Detectability: 1–5
Manual dependency: 1–5
Use the result to identify which participant events deserve tighter controls first.22. Quality Modernization Workshop
A useful 90-minute internal session:
0–15 minutes
Choose one participant journey.
Example:
candidate → consent → source data → screening → remote visit → payment.
15–35 minutes
Identify all critical events.
35–55 minutes
For each event:
owner, authority, evidence, system, downstream effect.
55–70 minutes Identify:
- missing ownership,
- manual verification,
- stale permission,
- disconnected state,
- exception gaps.
70–80 minutes
Score risks.
80–90 minutes
Select one high-risk handoff for remediation.
23. The Key Output
Do not finish with:
“We need better compliance.”
Finish with:
“This participant event has unclear authority, fragmented evidence, and a manual downstream handoff. We will redesign that control.”
That is specific enough to act on.
Make Cross-System Participant Controls Visible. Download the editable Participant Journey Controls Pack and use it with Quality, Clinical Operations, Technology, and DCT Governance teams.
Download includes
- 12 participant-critical control points
- Event/Owner/Authority/Evidence matrix
- consent-to-data worksheet
- decentralized activity control sheet
- milestone-to-payment traceability map
- withdrawal/re-consent map
- risk-scoring framework
- 90-minute workshop agenda
CTA Button
Download the Controls Pack
Fields
First name Work email Company
No phone number required. No product demo required.
COVER
ICH E6(R3) PARTICIPANT JOURNEY CONTROLS MAP
A practical cross-system controls framework for modern CRO workflows. PAGE 2 — 12 Control Points
- Candidate identification
- Outreach / recontact
- Pre-screening
- Informed consent
- Data access
- Eligibility decision
- Decentralized activity
- Participant-generated / DHT data
- Study milestone
- Participant payment
- Re-consent / permission change
- Withdrawal
PAGE 3 — Control Matrix
Event Owner Permission / Evidenc Syste Downstream Event Authority e m
PAGE 4 — Consent & Permission Worksheet Consent version
Current status
Data categories permitted
Purpose(s)
Expiry / review condition
Revocation path
Downstream systems relying on status
Main control risk
PAGE 5 — Decentralized Activity Worksheet
Activity
Location
Home / Local HCP / Site / Remote
Responsible role
Delegation documented?
Yes / Partly / No Completion evidence
Source data location
Exception owner
PAGE 6 — Milestone-to-Payment Traceability
| Participant Event | Completion Evidence | Verification Owner | Payment Rule | Payment Status |
|---|---|---|---|---|
| — | — | — | — | — |
| — | — | — | — | — |
| — | — | — | — | — |
| — | — | — | — | — |
Can the payment event be traced back to a verified participant milestone?
Yes / Partly / No
PAGE 7 — Re-Consent & Withdrawal
Event type
- Re-consent
- Permission change
- Partial withdrawal
- Full withdrawal
Timestamp
Systems affected
Future actions blocked/changed
Responsible owner
Evidence of downstream update
PAGE 8 — Risk Score
Score 1–5:
| Control Point | Participant Impact | Data Impact | Frequency | Low Detectability | Manual Dependency | Total |
|---|---|---|---|---|---|---|
| — | — | — | — | — | — | — |
| — | — | — | — | — | — | — |
| — | — | — | — | — | — | — |
| — | — | — | — | — | — | — |
Highest-priority control gap:
PAGE 9 — Remediation Plan
Control gap
Current workflow
Required future state
Owner Evidence required
Metric
Review date
Some Control Gaps Are Also Operating-Cost Leaks.
Once you've identified the highest-risk manual handoffs, quantify the impact of:
- coordinator effort,
- enrollment delay,
- manual reconciliation,
- participant payment friction,
- and cross-system latency.
Explore the related MinervaLedger workflow →
Take this framework into your next study discussion.
The complete resource is free to read. Get the editable version for your team.
Now calculate what the constraint costs.
Use your own study inputs to quantify the operational impact.
Run the Leakage Calculator