What actually happens when trials switch to risk-based monitoring
Risk-based monitoring has been the recommended approach in guidance documents for long enough that it's easy to assume it's also the common approach in practice. A national survey of clinical trials found otherwise, and the gap between recommendation and adoption turns out to be worth understanding on its own terms.
Guidance says risk-based. Practice mostly still says everything, everywhere
The survey contacted 3,689 studies and received 441 completed responses, a 77.4% completion rate among the 589 who responded at all. What those studies reported doing didn't match what the guidance recommends: 55% of studies applied source data verification broadly, and full, 100% on-site monitoring was the most common approach among studies using anything resembling a traditional model. Only 10 to 11% of studies had actually adopted risk-based targeted or triggered monitoring, the approach that guidance has favoured for years.
Where risk-based, triggered monitoring was used, the study identified what actually prompted a site visit: adverse events triggered visits in 63% of cases, protocol deviations in 44%. That's a useful detail in itself, since it tells you the trigger points that are actually driving monitoring resource in practice, rather than the theoretical risk categories a protocol might list on paper.
The researchers' conclusion was direct: small, single-site studies in particular were persisting with monitoring procedures that are time-consuming and expensive, rather than the more targeted alternative that guidance recommends, and they called for clearer formal guidelines to help close that gap.
Why the gap exists: a second study gets specific
A separate paper, documenting lessons learned from an actual risk-based monitoring rollout in an academic trial setting, offers a plausible explanation for why adoption lags so far behind the guidance. It isn't simply inertia or unfamiliarity. Monitors in that study raised a specific, legitimate concern: a fear of missing systematic errors precisely because visit frequency had gone down. Reduced visit frequency is the entire mechanism by which risk-based monitoring saves time and cost, and it's also the exact thing that makes the people doing the monitoring uneasy about what they might be failing to catch.
The same study found something sharper underneath that general unease. When they examined what on-site visits under the risk-based approach actually turned up, the findings were overwhelmingly administrative (46.2%) and related to patient rights (49.1%), not the kind of systematic data integrity problems that would validate the monitors' concern about missed errors. That's a genuinely important mismatch: the risk factors used to decide which sites got visited, and how often, were not well aligned with what those visits actually ended up finding. The risk model and the real risk had drifted apart.
The fix wasn't more visits. It was a different kind of check entirely
Rather than concluding that risk-based monitoring should be abandoned or scaled back, the study's authors proposed something more specific: complement the risk-based, on-site approach with centralised data checks, and let that combination shift the monitor's role from someone conducting periodic inspections toward something closer to an ongoing partner in trial quality.
That reframing matters more than it might first read. A monitor visiting a site every few months, hoping to catch whatever might have gone wrong since the last visit, is a fundamentally reactive posture. A monitor with continuous visibility into incoming data, able to flag an anomaly the day it appears rather than the day of the next scheduled visit, is doing a different job with the same title. The infrequent physical visit stops being the primary safety net and becomes one input among several, freed up to focus on exactly the kind of in-person verification, patient rights checks, informed consent review, that the data showed those visits were actually good at catching.
What this means for a study deciding how to monitor
Two practical conclusions follow from putting these findings together:
- A risk model is only as good as its inputs, and needs revisiting against what visits actually find. If a study's risk categorisation hasn't been checked against real outcomes in a while, it may be triggering visits for the wrong reasons, or missing the actual predictors of a finding.
- Reduced visit frequency only works safely alongside continuous data visibility, not instead of it. The monitors' concern about missing systematic errors is legitimate under a model with fewer visits and no other safety net. It's substantially less legitimate once centralised, ongoing data checks are actually running alongside the reduced visit schedule.
The wider pattern here isn't really about monitoring specifically. It's that a guidance recommendation adopted without the infrastructure that makes it safe, in this case continuous data visibility, doesn't fail because the underlying idea was wrong. It fails, or simply doesn't get adopted, because the version of it that actually gets implemented is missing the part that made the theory sound in the first place.