Mediconomics – für individuelle CRO-Lösungen.

Glossar

A serious breach is a breach of Regulation (EU) No 536/2014 or of the version of the clinical trial protocol applicable at the time of the breach, which is likely to significantly affect the rights or safety of participants or the reliability and robustness of the data. The term is a reportable legal term. The sponsor shall report a confirmed serious breach via CTIS without undue delay and no later than seven days after becoming aware of it.

Legal Term and Reporting Procedure

The classification requires an objective assessment of severity and potential impact. It is not only about damage that has already occurred: a breach that is likely to cause significant impairment is also covered. According to the European Commission’s guiding questions, the deadline begins when the sponsor becomes aware of a possible breach. Within this period, the initial analysis, confirmation of severity, and submission of the initial report must take place; only confirmed serious breaches are reported.

The report does not replace the immediate safeguarding of participants, the root cause analysis, or communication with the clinical trial site. Its purpose is to enable the affected Member States to assess risks and impacts in a timely manner. Therefore, the facts, their scope, protective measures already taken, and planned follow-up steps must be coherently compiled. Findings regarding other sites, data, or individuals are further pursued in quality and safety management.

Assessment and Follow-up Measures

If the investigation reveals significant non-compliance, ICH E6(R3) expects a root cause analysis and appropriate corrective and preventive actions. The appropriateness of these measures must be confirmed, unless otherwise justified. Recurring or persistent problems may require additional monitoring, retraining, process changes, or, in exceptional cases, the termination of a site’s or service provider’s involvement. Regulatory reporting and internal action management are therefore separate but coordinated work streams.

Distinction from Important Protocol Deviation and Serious Non-Compliance

An important protocol deviation is a subgroup of deviations defined by ICH E6(R3) that may have a significant impact on data or participants. Its classification is based on study-specific quality criteria. A serious breach, on the other hand, is directly linked to Article 52 of the Regulation and, if confirmed, triggers reporting via CTIS. Therefore, not every important protocol deviation is a serious breach.

Serious non-compliance according to ICH E6(R3) describes a significant disregard of the clinical trial protocol, SOPs, GCP, or legal requirements and calls for root cause analysis as well as corrective and preventive actions. It is a GCP and quality management term. Whether this also constitutes a serious breach within the meaning of the Regulation must be decided based on the legal requirements and the individual case.

The clarification of facts must withstand the tight deadline without generating premature reports of unconfirmed individual cases. It is expedient to have predefined escalation levels, contact persons, and documentation of the time the notification was received. This allows the sponsor to check within the allotted timeframe whether the legal threshold has been reached, which persons or data are affected, and which immediate measures were necessary. The justification for the decision, even if the reporting obligation is denied, belongs in the quality documentation. Work does not end after the initial report: new findings may expand the scope, change corrective measures, or require a broader review of other sites. A clear distinction between facts, assessment, and hypotheses protects traceability and facilitates communication with authorities and ethics committees.

For governance, independent quality assurance of the decision is also helpful. It checks whether the assessment is based on complete information, whether the seven-day deadline was correctly applied, and whether the measures initiated correspond to the risk. This review increases the consistency of comparable cases and supports robust communication with the affected parties.

Compared to the related terms protocol deviation and protocol violation, the legal effect must always be examined. The entry on corrective and preventive actions describes the processing of a problem, the GCP inspection its official review; neither replaces the reporting of a confirmed serious breach.

Relevance for clinical trials

In clinical trial practice, a robust escalation chain is crucial: indications must be recorded, professionally assessed, checked against reporting requirements, and effectively processed at the affected sites. Auditors and inspectors pay particular attention to whether the sponsor recognized early signals, documented the decision, and managed the consequences for participant protection and data integrity.

Full-service CROs like Mediconomics support initial assessment, compilation of monitoring, safety, and data information, and root cause analyses. They can operationally prepare CTIS reports, track corrective and preventive actions, and structure evidence for audits and inspections.

Frequently Asked Questions (FAQ)

Does the seven-day period only begin after the investigation is completed?

No. It begins as soon as the sponsor becomes aware of a possible breach; the initial assessment and confirmation must take place within this period.

Who reports the serious breach?

The reporting obligation lies with the sponsor. Therefore, information from clinical trial sites or service providers must immediately enter their assessment processes.

Is a data error always a serious breach?

No. The decisive factor is whether the breach is likely to significantly affect the reliability and robustness of the data or the rights and safety of participants.

Regulatory References

  • ICH E6(R3), Section 3.9.3 — classifies important protocol deviations as a study-specific subgroup to be defined.
  • Regulation (EU) No 536/2014, Article 52 — regulates the reporting of serious breaches.
  • European Commission’s guiding questions on Regulation (EU) No 536/2014, Chapter 11.3 — explain the timing and confirmation of the report.
Scroll to Top