Ninety Percent of Trials Use RBQM. Most Still Run Full SDV.
ACRO's seventh landscape survey reports risk-based components on 90% of 4,296 outsourced studies and 100% source data review and verification on most of them. Both numbers come from the same report.
The Association of Clinical Research Organizations ran its seventh consecutive risk-based quality management landscape survey in 2026, covering 4,296 outsourced studies at eight member CROs for the 2025 data year. Two findings sit in it. First, 90% of those trials included at least one RBM or RBQM component, and studies run on traditional monitoring fell to 10%, down from roughly half in 2019. Second, in ACRO's own words, "industry adoption of RBQM components has steadily grown from 2019 to 2025, and we're still seeing 100% SDR/SDV on most studies."
Both sentences appear on the same page of ACRO's RBQM survey summary report. Read together, they say the industry adopted the vocabulary and kept the cost.
That matters to anyone building a business case for AI in clinical monitoring, because every such case rests on the same saving: fewer source-data-verification hours per patient. Regulators have permitted sampling instead of exhaustive verification since 2013. Nine years after ICH E6(R2) reached Step 4 in November 2016, the median outsourced study still verifies everything. A model that finds the risky records faster does not, by itself, change what is written in the monitoring plan or priced in the work order.
- ACRO's 2025 survey covers 4,296 outsourced studies at eight member CROs: 90% carried at least one RBQM component, and 100% SDR/SDV persisted on most of them.
- "At least one component" is a weak measure. On the stricter one, roughly half of new study starts used risk assessments, KRIs, centralised monitoring or remote monitoring.
- ICH E6(R3) (Step 4, 6 January 2025; EU effective 23 July 2025) mentions source data verification exactly once, in a list of options, and explicitly permits sampling supported by data analytics.
- ADAMON randomised 213 sites and found risk-adapted monitoring non-inferior to extensive on-site monitoring, at 2.1 times fewer visits. TEMPER found triggered visits no more productive than untriggered ones.
- ACRO attributes persistent 100% SDR/SDV to multi-vendor FSP contracting, not to a lack of tooling. That is a contract problem, and no model solves it.
What the 4,296-study survey actually counted
The headline is softer than it reads. "At least one RBM or RBQM component" is satisfied by a documented initial risk assessment on a study that then verifies every field of every case report form. It is a floor, not a behaviour.
ACRO reports the stricter measure separately: on new study starts, "roughly half of new studies outsourced to CROs utilize risk assessments, KRIs, centralized monitoring, and remote monitoring." Within 2025, use of key risk indicators rose 7% against 2024 and centralised monitoring rose 11%, both after a dip in 2024. That is real movement. It is also movement around the 50% mark, not the 90% mark.
Three limits on the dataset deserve stating, because they cut in different directions. Half the studies are small, under 100 participants, where the economics of building a centralised-monitoring capability are worst. Functional service providers and specialty CROs are excluded from the survey entirely, so the sample is the outsourced-to-a-full-service-CRO segment and nothing else. And ACRO is the CROs' trade association reporting on its own members' modernity, which makes the SDV admission more credible, not less: it is the finding the publisher had least incentive to print.
The distribution is the interesting part. ACRO reports that mid-size sponsors, defined as $1bn to $10bn in annual revenue, were more likely to reduce SDR/SDV than either small or large sponsors, and that Phase 4 studies were the phase most likely to reduce it. Phase 3 studies were more likely to use quality tolerance limits, KRIs and centralised monitoring. So the sophisticated risk machinery is being installed in the large late-phase trials, and the actual cost reduction is being taken somewhere else.
The regulators stopped asking for full SDV in 2013
The most common defence of 100% SDV is that the sponsor's QA function will not accept anything else because the regulator expects it. On 30 August 2026, no instrument in the table below sets a verification percentage.
| Instrument | Date | Status on 30 Aug 2026 | On SDV |
|---|---|---|---|
| FDA, Oversight of Clinical Investigations — A Risk-Based Approach to Monitoring | August 2013 | Final guidance, non-binding recommendations | Centralised monitoring "could have identified more than 90% of the findings identified during on-site monitoring visits" |
| EMA reflection paper on risk based quality management in clinical trials (EMA/269011/2013) | 18 November 2013 | Reflection paper, non-binding | Targeted SDV on important variables "with no or reduced SDV on others" |
| Regulation (EU) No 536/2014, Article 48 | Applicable 31 January 2022 | Binding EU law | "When establishing the extent of monitoring, the characteristics of the clinical trial shall be taken into account". No percentage |
| ICH E6(R2), section 5.18.3 | Step 4, 9 November 2016 | Superseded in the EU | "In general there is a need for on-site monitoring… however in exceptional circumstances" centralised monitoring may suffice |
| FDA, A Risk-Based Approach to Monitoring — Questions and Answers | Final 12 April 2023 | Final guidance, non-binding | Finalises the 15 March 2019 draft; sampling approaches expected to be justified |
| ICH E6(R3) Principles and Annex 1 | Step 4, 6 January 2025 | EU effective 23 July 2025 | Verification "can be done on the basis of using samples and supported by data analytics" |
| ICH E6(R3) Annex 2 | Step 4, 3 June 2026 | CHMP adopted 25 June 2026, EU effective 15 January 2027, so not yet in effect | Decentralised, pragmatic and real-world-data elements; no verification percentage |
I searched the full text of both ICH PDFs on 30 August 2026. In the E6(R3) Step 4 final guideline adopted 6 January 2025, the phrase "source data verification" appears once, inside a list of monitoring approaches that also includes source data review, data analytics and site visits. In the E6(R2) Step 4 addendum dated 9 November 2016, the phrase does not appear at all.
The substantive change between the two versions is one clause. E6(R2) kept the legacy sentence that centralised monitoring alone was for "exceptional circumstances". E6(R3) section 3.11.4.2(b) replaces it: centralised monitoring processes "can complement and reduce the extent and/or frequency of site monitoring or be used on its own". That removes the last written hook a conservative QA reviewer could hang a full-SDV position on. It became effective in the EU on 23 July 2025, thirteen months ago.
What the trials that tested this found
Three pieces of evidence get cited in RBQM business cases. They do not all say what the deck says they say.
Sheetz and colleagues, in Therapeutic Innovation & Regulatory Science in 2014, analysed 1,168 Phase 1 to Phase 4 studies across 53 sponsors. A median of 1.1% of the total eCRF dataset was corrected by SDV, against 3.7% corrected by any data-cleaning method. That is the number the industry has repeated for a decade, usually stripped of its second half: the same analysis found that between 7.5% and 11.8% of reported adverse events were entered into the database less than seven days after an SDV visit. The visit was not verifying data so much as prompting a site to report events it had not reported. Any monitoring redesign that removes the visit has to replace that prompt with something, and a KRI dashboard does not obviously do it. This is the part of the case that survives contact with a medical monitor, and it is why the reduction stalls.
ADAMON, a cluster-randomised non-inferiority study published in Clinical Trials in 2017, randomised 213 sites across 11 trials to extensive on-site monitoring or risk-adapted monitoring and audited 1,618 patients at the end. Major or critical GCP findings were present for 64.2% of audited patients in the extensive arm and 59.2% in the risk-adapted arm, with a monitoring effect of −0.04 on the logit scale (95% CI −0.40 to 0.33) against a pre-specified non-inferiority margin of 0.60. The extensive arm used 2.1 times the visits per patient and 2.7 times the cumulative on-site hours to get there.
TEMPER, published in Clinical Trials in 2018, is the awkward one. It matched 42 pairs of triggered and untriggered site visits across three Phase 3 oncology trials. New major or critical findings were present at 88.1% of triggered visits and 81.0% of untriggered visits, an absolute difference of 7.1% (95% CI −8.3 to +22.5, p = 0.365). The triggers, as implemented, did not discriminate. The honest reading is that risk-adapted monitoring is safe to do, and that the specific triggering logic used in those trials was not doing the work it was credited with. That is the exact claim an AI monitoring vendor now makes about its own triggers, and it is the claim TEMPER shows must be measured rather than assumed.
Where the monitoring money actually sits
Business cases routinely open with SDV consuming 25 to 30% of a trial budget. That figure has two incompatible sources and the difference is worth 15 points of a P&L.
The most granular public cost model remains the ASPE and Eastern Research Group study of clinical trial costs, dated 24 July 2014 and authored by Sertkaya, Birkenbach, Berlind and Eyraud. Its Table 2 puts site monitoring at 9.33% of per-study cost in Phase 1, 14.25% in Phase 2, 14.28% in Phase 3 and 13.60% in Phase 4. Site monitoring, not SDV — SDV is a component of it. On that model, eliminating SDV entirely could not reach 15% of trial cost.
The 25% figure traces to a different lineage. A 2023 review in the British Journal of Clinical Pharmacology, Andersen et al. on the impact of monitoring approaches on data quality, reports that SDV has been reported to account for up to 25% of a trial budget. That is a characterisation of prior literature rather than a fresh cost model, and it is an upper bound rather than a median.
Both can be true if the underlying trials differ enough. What is not defensible is quoting the 25 to 30% figure to a finance director without saying which of these you mean, because the ASPE breakdown is public and someone will find it. A defensible case states the realistic range, 5 to 12% of trial cost from full SDV in a mid-size Phase 3, and wins on the range rather than on the ceiling.
Why the saving does not arrive
ACRO gives the answer in a footnote, and it is not a technology answer. Where a sponsor runs a functional service provider strategy and contracts several vendors or CROs on one study, coordination risk rises, and so, in ACRO's words, sponsors "may be more inclined to include 100% SDR/SDV as a back-up when outsourcing in this model."
Full SDV, in other words, is being bought as insurance against a sourcing model, not as a data-quality control. That is a rational purchase. It is also completely immune to better analytics, because the thing being insured is the seam between vendors, not the data.
The second mechanism appears in a 2025 Therapeutic Innovation & Regulatory Science analysis of the ACRO series, which reports that between 8% and 18% of new study starts reduced SDR and/or SDV without implementing centralised monitoring, while 65% of new study starts that did adopt centralised monitoring reduced both. So the coupling works in one direction and leaks in the other: centralised monitoring reliably unlocks the reduction, and a meaningful minority take the reduction without installing the compensating control. Those studies are the ones that produce an inspection finding, and every one of them makes the next sponsor's QA director more conservative.
What an AI monitoring business case has to prove in 2026
Start from what the regulator has and has not said about the tool. I searched both ICH texts on 30 August 2026: the E6(R3) Step 4 guideline of 6 January 2025 and the Annex 2 Step 4 guideline of 3 June 2026 each contain zero occurrences of "artificial intelligence" or "machine learning". There is no GCP-specific AI clause to comply with. Governance falls back to general instruments: the EMA guideline on computerised systems and electronic data in clinical trials, effective 10 September 2023, and the non-binding EMA reflection paper on the use of AI in the medicinal product lifecycle adopted 9 September 2024.
Two adjacent instruments do not apply and should not appear in your slides. The draft Annex 11 revision and the new draft Annex 22 on artificial intelligence were published for consultation on 7 July 2025, consultation closed 7 October 2025, and neither is law; the binding EU computerised-systems text remains the 2011 Annex 11. Both are EudraLex Volume 4, meaning GMP scope, not GCP. A centralised-monitoring platform in a clinical trial is outside them on two counts.
On the EU AI Act, prohibited practices and the Article 4 AI literacy obligation have applied since 2 February 2025 and the general-purpose AI obligations since 2 August 2025. The Annex III high-risk deadline was deferred from 2 August 2026 to 2 December 2027, and Annex I to 2 August 2028, by the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. Clinical-trial monitoring analytics does not appear in the Annex III list in any case, so the deferral is not the reason to proceed.
Which leaves the business case with nothing to hide behind. If the tool is not blocked by regulation and the guideline explicitly permits sampling supported by data analytics, then the only remaining explanation for nine years of flat SDV is commercial, and the case has to name it.
What this means in practice
The artefact you are changing is the monitoring plan and the CRO work order. ICH E6(R3) section 3.11.4.3 requires the monitoring plan to describe the monitoring methods and tools and "the rationale for their use". That sentence is where the SDV percentage actually lives. If your programme does not produce a redrafted monitoring plan and a repriced work order, it has not produced a saving, whatever the dashboard says.
Baseline before you buy. Pull the specified SDV percentage from the monitoring plan of your last twenty protocol starts, and separately pull the achieved SDV rate from the CTMS. Count how many specify below 100%, and of those, how many document a centralised-monitoring plan. If the first number exceeds the second you are already carrying the 8 to 18% failure mode ACRO's analysts found, and the priority is the control, not the tool.
Check how monitoring is priced. If the CRO contract charges CRA time per FTE or per visit, cutting SDV cuts the CRA's workload and leaves your invoice where it was. The reduction has to be converted into fewer budgeted visits or a lower unit price in a change order, signed by procurement, before any of it reaches the P&L. This is the single step most RBQM programmes skip.
Sign-off is joint. The monitoring plan is a sponsor document, so clinical operations drafts it, but the medical monitor owns the safety-signal argument and QA owns the inspection-readiness argument. Neither will sign a reduction that has no replacement for the adverse-event prompting effect Sheetz measured. Give them one: a defined cadence of site contact and a documented AE-reporting-latency KRI, rather than a claim that the model will notice.
Commit to the metric that ACRO will publish next year. Report SDV percentage on new protocol starts quarterly, next to centralised-monitoring coverage on the same protocols. If coverage rises and SDV does not, the programme is producing a label, which is precisely what the last nine years produced.
Questions people ask about this
- What percentage of clinical trials use RBQM in 2026?
- ACRO's seventh landscape survey, covering 4,296 outsourced studies at eight member CROs for the 2025 data year, found that 90% included at least one risk-based monitoring or RBQM component, with traditional monitoring down to 10% from roughly half in 2019. The stricter measure is lower: roughly half of new study starts used risk assessments, key risk indicators, centralised monitoring or remote monitoring.
- Does ICH E6(R3) require 100% source data verification?
- No. ICH E6(R3), adopted at Step 4 on 6 January 2025 and effective in the EU from 23 July 2025, mentions source data verification once, in a list of possible monitoring approaches. Section 3.11.4.5 states that checking reported data against source records "can be done on the basis of using samples and supported by data analytics". No ICH text sets an SDV percentage.
- How much of a clinical trial budget does source data verification consume?
- The figure is contested. The most detailed public breakdown, the 2014 ASPE and Eastern Research Group report, puts all site monitoring at 9.33% of Phase 1 per-study cost and 14.28% of Phase 3. A 2023 British Journal of Clinical Pharmacology review reports SDV accounting for up to 25% of a trial budget. Anyone quoting 25 to 30% should say which source they mean.
- Why do sponsors still run full SDV under a risk-based monitoring model?
- ACRO's own explanation is contractual. Where a sponsor splits a study across several functional service providers and CROs, coordination risk rises, and sponsors "may be more inclined to include 100% SDR/SDV as a back-up". The reduction is a work-order and monitoring-plan decision, not a technology decision, which is why better analytics on their own have not moved it.