VendorVigilance - Clinical Trial Vendor Management
All posts

Vendor Oversight

CRO Oversight in Clinical Trials: The Delegated Vendor

Dejan Murko

At a glance

  • A CRO is not just another vendor. Under US regulation it is the one party a sponsor can formally transfer regulatory obligations to, which changes what oversight means.
  • The transfer of obligations must be in writing. Any obligation not described in that writing stays with the sponsor, whatever both sides assumed.
  • A CRO that assumes an obligation becomes directly accountable to the regulator for it, but the sponsor’s ultimate responsibility for the trial never moves.
  • Overseeing a CRO is about governance over a partner that may run much of the trial, not item-by-item supervision: defined responsibilities, retained access, and escalation.
  • The deepest oversight risk with a CRO is the gap between what you think you delegated and what the contract actually says.

This article is the CRO-specific layer of vendor management in clinical trials and applies the system described in vendor oversight to your most consequential vendor.

CRO versus vendor: a real distinction

In casual use, “CRO” and “vendor” are interchangeable, and most vendor management principles apply to both. But there is a precise legal difference worth keeping straight, because it changes how accountability flows.

Under US regulation, 21 CFR §312.52 lets a sponsor transfer responsibility for any or all of its regulatory obligations to a contract research organization. That mechanism is specific to a CRO. You contract a central lab or a courier to perform work, but you formally transfer regulatory obligations to a CRO. The consequence is real: §312.52 provides that a CRO which assumes any obligation of a sponsor must comply with the regulations applicable to that obligation and is subject to the same regulatory action as a sponsor for failing to meet it. A CRO that takes on your monitoring obligation can be held to account by FDA for that monitoring in a way an ordinary vendor cannot.

ICH E6(R3) frames the same relationship in GCP terms: a sponsor may transfer any or all of its trial-related activities to a service provider, and a CRO is a service provider that typically takes on a broad span of them. EU CTR 536/2014 mirrors it for European trials, allowing a sponsor to delegate any or all of its tasks by written contract. Across all three, the CRO is the vendor you hand the most to, which is exactly why getting its oversight right matters most.

In practice CROs come in a spectrum, from full-service providers that run essentially the whole trial to functional service providers, or FSPs, that take a single function such as data management or monitoring. The contracting model differs, but the §312.52 logic is identical: whatever obligations you transfer, transfer them explicitly, and whatever you do not, expect to keep. An FSP arrangement can actually sharpen this, because the narrow scope makes it obvious which obligations moved and which the sponsor still runs. A full-service contract is the riskier one for clarity, because its breadth can lull a sponsor into assuming the CRO “has everything” when the written description says otherwise.

Transfer of obligations: in writing, or it stays with you

The single most important sentence in CRO management is in §312.52: any obligation not covered by the written description is deemed not to have been transferred. That is not a paperwork formality; it is the line between your liability and the CRO’s. If your contract says the CRO handles “monitoring” without specifying which monitoring obligations, or is silent on safety reporting because everyone assumed the CRO had it, those obligations remain the sponsor’s by default.

So the foundational act of CRO oversight happens at contracting, before any oversight activity begins. §312.52 requires the transfer to be described in writing, and where not all obligations move, the writing must describe each obligation the CRO is assuming. The discipline that follows is to maintain an explicit, current map of which obligations sit with the CRO and which the sponsor retained, and to make sure no obligation has quietly fallen into the gap between them. ICH E6(R3) reinforces the same logic from the GCP side: any sponsor activity not specifically transferred to and assumed by the service provider is retained by the sponsor. Two regulators, the same warning: vagueness defaults the obligation back to you.

And even a perfectly drafted transfer does not move the thing that matters most. ICH E6(R3) is explicit that although a sponsor may transfer any or all activities to a service provider, the ultimate responsibility for those activities, including the protection of participants and the reliability of the data, resides with the sponsor. EU CTR Article 71 says the same: delegation is without prejudice to the responsibility of the sponsor, in particular for subject safety and data reliability. You can transfer the obligation and the work. You cannot transfer the accountability.

How to oversee a CRO

Because a CRO often runs a large part of the trial, its oversight is governance, not line-by-line supervision. The components are familiar from oversight generally, applied at partner scale:

  • A clear responsibility map. The documented split of obligations from the transfer agreement, kept current as scope changes, so everyone knows who owns what.
  • Governance cadence. Regular joint review of progress, risks, and performance against agreed metrics, with decisions recorded.
  • Retained access. ICH E6(R3) expects the sponsor to retain access to relevant information and to source records. A CRO arrangement that limits the sponsor’s visibility undermines the oversight the sponsor still owes.
  • Oversight of the CRO’s own subcontractors. ICH E6(R3) extends the sponsor’s oversight to activities the service provider further subcontracts, so a CRO that subcontracts the central lab does not put that lab outside your scope.
  • A working escalation path. Including the regulator-facing end: if significant noncompliance by the CRO persists despite remediation, ICH E6(R3) expects the sponsor to consider terminating the CRO’s participation and to notify the authorities.

Good CRO governance is established at the start, not improvised once problems appear. A governance plan that names the joint oversight committee, its cadence, the metrics it reviews, the decision rights of each side, and the escalation route gives both organisations a shared operating model. Without it, oversight degenerates into status calls where bad news travels slowly, which is the opposite of what a partner relationship at this scale needs. The sponsor’s job in that model is not to do the CRO’s work; it is to keep a confident, evidenced answer to one question: is the CRO delivering the transferred obligations to standard, and how do we know?

The thing to avoid is the two opposite failures: abdication, where the sponsor treats the CRO as a black box and assumes delegation ended its job, and micromanagement, where the sponsor recreates the CRO’s work and gains nothing. Governance is the middle path: hold the CRO to defined outcomes, keep the access and the metrics that let you verify them, and intervene on signal.

This has a blunt inspection consequence. When a regulator finds a problem in work a sponsor delegated to a CRO, the finding lands on the sponsor, because the sponsor owns the trial. A sponsor that can show a clear obligation map, a governance record, and evidence that it acted on signals is in a defensible position even when a CRO underperformed. A sponsor that points at the CRO and says “that was their responsibility” has misunderstood the regulation it is being inspected against.

Where CRO oversight goes wrong

  • The contract gap. An obligation nobody wrote down as the CRO’s, which §312.52 therefore leaves with the sponsor, discovered at inspection.
  • Delegation as abdication. Treating “we have a CRO” as the end of oversight rather than its beginning.
  • Lost visibility. Accepting a CRO arrangement that does not give the sponsor access to the data and records it needs to oversee.
  • Subcontractors out of scope. Forgetting that the CRO’s subcontractors are still within the sponsor’s oversight.

Where VendorVigilance fits. A CRO relationship is exactly where the gap between delegated and retained obligations becomes dangerous, and where governance has to be visible. VendorVigilance holds the CRO in the same central registry as every other vendor, tracks contracts, deliverables, and obligations in its Governance module, and treats transfer-of-obligation risk as one of the six clinical risk types in RIM, so the question “what did we actually delegate, and what did we keep?” has a documented answer rather than a hopeful one. All of it sits on a 21 CFR Part 11-compliant audit trail with a global study filter. Explore the product.

The bottom line

Treat the CRO as the vendor that carries the most, because legally and practically it does. Get the transfer of obligations explicit and in writing so nothing defaults back to you by accident, remember that accountability never transfers however clean the contract, and oversee through governance rather than supervision or abdication. The CRO relationship rewards precision at contracting and steadiness in oversight, and it punishes the gap between what you meant to delegate and what you actually did.

Sources

Dejan Murko

Dejan Murko

Dejan is the co-founder of Mayet, building software for biotech and pharma teams.