Who actually checks a trial's insurance cover?
Insurance is one of those requirements that gets treated as settled the moment a document exists confirming it. A policy is in the file, a research ethics committee has signed off, and everyone moves on to the parts of study set-up that feel more urgent. An MHRA inspection finding shows what can happen when that assumption goes unexamined for long enough.
During routine good clinical practice inspections, the MHRA found that a number of Clinical Research Organisations and Phase 1 Trial Organisations were not independently reviewing sponsor insurance at all. The reason wasn't negligence in the usual sense. It was a genuine, widely shared misunderstanding: sites assumed the research ethics committee had already reviewed the suitability of the cover, because the REC had confirmed that cover existed. It had. What it hadn't done was assess whether that cover was actually appropriate for the specific trial in question.
Confirming existence is not the same as confirming suitability
This is a distinction that sounds obvious once stated and yet clearly wasn't operating in practice across enough sites for the MHRA to flag it as a pattern. A REC verifying that a policy document exists is a completely different exercise from a site or sponsor checking that the policy actually covers what this trial needs it to cover: the right population, the right intervention, the right level of risk, with no exclusions that would leave a participant unprotected in a scenario the study could plausibly produce.
The gap only shows up when something goes wrong and the policy turns out not to apply, at which point discovering the gap is the worst possible time to discover it. The MHRA's inspections found three specific weaknesses sitting behind that risk:
- No independent suitability check. Non-NHS Phase 1 sites were not conducting their own review of whether a sponsor's insurance suited the specific trial, beyond confirming a policy existed.
- No reassessment at renewal. Insurance was not being reviewed again when policies came up for annual renewal, even though a trial's risk profile, population, or procedures can shift over that time.
- No documented due diligence. Where checks may have happened informally, nothing was filed in the trial master file to demonstrate that due diligence had actually taken place.
Any one of these on its own is a process gap. All three together describe a system where insurance adequacy was effectively nobody's ongoing responsibility, only a one-time box ticked at study start-up and never revisited.
What changes now, and why documentation is the actual fix
The MHRA's expectation, formalised from 28 April 2026, is straightforward to state and more demanding to operationalise: sites must independently verify that sponsor insurance is appropriate to the specific trial, with no inappropriate exclusions, and document that verification with sign-off from someone qualified to assess it. Coverage exclusions need particular attention, since an exclusion that seems reasonable in the abstract can still leave a genuine trial participant without protection in exactly the scenario the study is most likely to produce.
The documentation requirement is doing more work here than it might first appear. A due diligence check that happens but isn't recorded is functionally invisible to an inspector, and just as importantly, it's invisible to the next person at the site who inherits responsibility for that trial. Written sign-off from a qualified reviewer turns a one-off judgement call into an artefact that survives staff turnover, annual renewal cycles, and the inevitable gap between who set a study up and who is still running it two years later.
This is where a study's documentation system matters as much as the insurance decision itself. A trial master file that makes it easy to see who reviewed cover, when, against what criteria, and with what sign-off, is a fundamentally different risk position than one where that information exists only in an email thread or someone's memory of a conversation from initial set-up. Version-controlled, timestamped records of exactly this kind of due diligence are precisely what an eTMF is meant to capture, and precisely the kind of check that's easy to skip when a study's documentation lives across scattered folders and inboxes instead.
The wider pattern behind this specific finding
It's worth noticing what actually broke down here. It wasn't that anyone deliberately skipped a safety check. It was a division of responsibility that looked complete from each individual party's point of view, a REC confirming a document existed, a site assuming that confirmation meant more than it did, and nobody explicitly owning the suitability judgement in between.
That kind of gap is easy to miss precisely because everyone involved is behaving reasonably given their own narrow view of the process. The fix isn't more scrutiny at any single point; it's making the division of responsibility explicit, documented, and reassessed on a schedule, rather than assumed once and left alone. For a requirement as consequential as insurance cover for trial participants, "someone else checked it" is not a control. A dated, sign-off record showing exactly who checked it, and against what, is.