AI-Driven RBQM
in Clinical Trials
How Risk-Based Quality Management is moving from quarterly PDF reports to live, agent-assisted oversight, and what that means for sponsors and CROs working under ICH E6 (R2/R3).
BY CAROLINA BOSCH · DIRECTOR, R&D CLINICAL DATA
What RBQM Actually Is
Risk-Based Quality Management is the operating model ICH E6 asks sponsors to run: identify the handful of things that would truly harm participants or the integrity of the trial, and put your monitoring, data review, and quality controls there, not spread evenly across every CRF field and every site visit.
In practice that means four moving parts: critical-to-quality (CtQ) factors, key risk indicators (KRIs), quality tolerance limits (QTLs), and a central monitoring function that watches them across sites in near real time. RBM, targeted, risk-based site monitoring, is a component of that system, not the whole thing.
From RBM to RBQM
Most sponsors started this journey with risk-based monitoring: score sites, prioritize on-site visits, reduce blanket 100% SDV. That was progress, but it was still a monitoring workflow, largely retrospective and largely manual.
RBQM widens the frame. The same risk lens now drives data management, medical review, safety, statistics, and vendor oversight, and the KRIs and QTLs are computed continuously, not compiled monthly. The technology bar goes up: you need trial-level dashboards, cross-source data pipelines, and clear escalation paths from a signal to an action.
That is exactly where AI stops being decorative and starts paying for itself.
Where AI Fits in RBQM
Live KRI computation
Enrollment lag, screen-fail rate, query aging, AE reporting delay, protocol-deviation density, recomputed continuously across every site, not quarterly.
Anomaly detection
Unsupervised models flag sites whose data patterns diverge from the trial average in ways fixed KRI thresholds miss, digit preference, visit-time clustering, implausible lab variance.
Site risk clustering
Sites are grouped by risk fingerprint so central monitors can act on patterns (a country, a vendor, a protocol version) instead of one row at a time.
Data-quality checks
LLMs cross-read narratives, ConMeds, and AE terms for internal consistency, catching contradictions no edit check was written for.
QTL breach prediction
Time-series models forecast quality tolerance limit breaches weeks before they happen, so the intervention is preventive, not forensic.
Signal-to-action drafting
For every flagged signal an agent drafts the follow-up: investigator query, CAPA candidate, monitor task, or escalation memo, for a human to approve.
Agentic RBQM in Practice
A useful mental model: the RBQM platform stops being a dashboard and becomes a queue of proposed actions. Signals flow in from EDC, eCOA, labs, IRT, safety, and vendor systems. Agents cluster them, rank them by risk, and attach a proposed action with rationale and citations. A human central monitor triages the queue, approves, edits, or rejects.
What that changes operationally: fewer weekly review meetings, faster time from signal to intervention, and, crucially, an audit trail that shows why a decision was made, not just that it was made.
"The model proposes. The central monitor disposes. Every RBQM action still needs a human, a signature, and a trail."
ICH E6 (R2/R3) Expectations
ICH E6 (R2) formalized the shift to a risk-based, proportionate approach to quality management. ICH E6 (R3) goes further: quality is designed into the trial, monitored continuously, and documented in a way that a regulator can reconstruct.
For AI-assisted RBQM that means three non-negotiables: models are validated for their intended use, every automated signal or drafted action is reviewable and reversible by a human, and the whole system emits an audit trail compatible with 21 CFR Part 11 and Annex 11. Skip any of those and you have a demo, not a platform.
Getting Started
- 1
Define CtQ factors first
Before any tooling, agree on the handful of things that would materially compromise participant safety or trial integrity. Everything downstream, KRIs, QTLs, models, hangs off this list.
- 2
Pick a small, honest KRI set
Six to twelve KRIs that you actually intend to act on beat forty vanity metrics. Add anomaly detection on top; do not replace KRIs with it.
- 3
Wire the sources once
Central monitoring only works if EDC, eCOA, labs, IRT, and safety data land in one place on a predictable cadence. Solve this before adding AI.
- 4
Introduce AI as a co-pilot
Start with drafted queries, ranked signals, and site-risk clustering, always with a human approver. Measure how often the human agrees; iterate the model where they do not.
- 5
Instrument the audit trail
Every model version, every proposed action, every human decision. If a regulator asked tomorrow, could you reconstruct the story of a single site's monitoring?
Rolling out RBQM at your org?
I am open to senior leadership roles in AI, Healthcare & Life Sciences, and Developer Ecosystems, plus select consulting engagements on RBQM design, central monitoring, and AI governance in clinical trials.