What a Deviation Code Leaves Out
Somewhere in a sponsor's clinical trial management system, a column is filling up with a short vocabulary: MISSED VISIT, WINDOW DEVIATION, IMPROPER DOSING, ELIGIBILITY DEVIATION, MISSING ASSESSMENT. Every entry is accurate, captured by software doing exactly the job it was built for. And every entry stops one step short of the question that matters most to the trial.
The code is not the decision. The same nominal deviation can be inconsequential, or it can be important, and importance itself splits two ways: trial-data integrity and participant safety. It can be an isolated event or the visible edge of a systemic pattern at one site. Sometimes the protocol itself is the cause. Add the question of whether it is reportable, CAPA-worthy, or merely something to document, and a single recorded event carries nine possible meanings, each pointing toward a different action.
Two missed visit windows show the spread. In the first, the participant was hospitalized; the deviation is clinically consequential and belongs in front of a reviewer. In the second, a noncritical assessment shifted by an hour for administrative reasons, which under many protocols' own rules lands as non-important. Identical code, opposite handling, and everything that separates the two is context the code never carried.
An invitation written into the guidance
What makes this a live research problem is that the judgment has been formally assigned to sponsors. FDA's protocol-deviation guidance states that FDA regulations do not establish a system for classifying deviation types, while stressing consistent identification, classification, and reporting. ICH E6(R3) goes further: the sponsor should determine trial-specific criteria for classifying deviations as important, tied to participant rights, safety, and well-being, and to the reliability of trial data.
Read together, the two documents describe a gap with a name on it. The classification scheme must exist, it must be consistent, and it must be specific to the trial, yet neither regulator supplies one. Every sponsor therefore already runs deviation-classification logic somewhere; today it tends to live in meetings, spreadsheets, and the memory of whoever reviews the deviation listing this cycle. The invitation, as we read it, is to make that logic explicit, versioned, and auditable, so the same deviation classified in March and in November comes out the same way for the same reasons.
What the logic would hold
The inputs are unglamorous and mostly captured already: protocol and version, the deviation itself, the visit or procedure affected, whether a critical endpoint is involved, whether there is safety impact, the magnitude of the window miss, site history and recurrence, prior deviations in the same category, correctability, and the trial-specific importance rules the sponsor has defined. Because protocol and version sit among the inputs, the rules would amend when the protocol amends, and a classification made under version three would stay explainable after version four ships. The output is a small closed vocabulary of states.
| State | What it asserts |
|---|---|
| NON_IMPORTANT | Falls below the trial's importance criteria |
| IMPORTANT_DATA_INTEGRITY | Threatens the reliability of trial data |
| IMPORTANT_SAFETY | Touches participant rights, safety, or well-being |
| SYSTEMIC_SITE_PATTERN | Recurrence at one site, larger than any single event |
| PROTOCOL_DESIGN_SIGNAL | The protocol itself is generating the deviations |
| INSUFFICIENT_EVIDENCE | The inputs cannot yet support a classification |
Downstream of each state sits a finite action set: document, investigate, escalate, open a CAPA, route to clinical review, trend, report. Every classification carries its rationale with it, and a human approves before anything moves. The sixth state deserves particular respect. A system willing to say the evidence is insufficient has declared the boundary of its own competence, and that declaration is what lets a quality organization extend trust to the other five states.
A layer the CTMS would consume
The systems already in the building do their jobs well. Veeva CTMS and Medidata capture deviations, route them reliably, and push them into risk-based quality management, and any deployment we attempted would go beside them, the same way Interpret and Triage are designed to sit beside retail and manufacturing stacks. The research target is not deviation-management software. It is the sponsor-owned, protocol-specific decision logic that determines what a deviation means, held independently of whichever CTMS records the event, so the same logic could serve a Veeva deployment, a Medidata deployment, or a CRO's in-house system without rewriting.
One caution travels with this. We treat one-week logic integration as a design principle and decline to read it as a go-live schedule; in a GxP environment, validation and change control set the calendar, whatever the build effort was. A serious pilot plan budgets for that from the first conversation.
This is why protocol deviation triage sits first in our research queue. Measured against the opportunity test we apply to every candidate vertical, nearly every condition holds: the deviation is already recorded digitally while its meaning is still worked out by hand, and the handful of actions that follow can be encoded, explained, and shown to an auditor. On top of all that sits the rarest property a candidate problem can have: a regulator that has already asked the sponsor to own the judgment. To be plain about status, this is research territory, nothing described here is available today, and Interpret and Triage remain the only systems open for pilot. When the guidance says the classification criteria are the sponsor's to define, and the incumbent software stops one step short of defining them, the research question nearly asks itself.
The shape this work extends is already open for pilot: Triage is built to run the same kind of judgment on a plant floor.