
The “low-risk” vendor that carries your highest exposure
We call it low risk. The data still drives decisions.
There’s a category of vendor that rarely gets much attention. They’re not running the clinical trial, not generating primary endpoints, and not usually front of mind during inspections. So they get labelled, often informally, as “low risk.” And that’s where the problem starts.
In clinical research, this often shows up with laboratories, PK providers, or niche analytical services. In early research, it appears in in vitro discovery work or exploratory studies that sit outside formal GLP frameworks. In both cases, the same logic tends to apply: the work is not pivotal to patient safety, regulators are unlikely to inspect it directly, and the data is considered “supportive” rather than critical.
All of that may be true. But it often leads to a conclusion that doesn’t follow: that these activities require little or no oversight.
The gap between regulatory attention and sponsor responsibility
There’s an assumption that if something is unlikely to be inspected, it carries limited risk. That’s not how the regulations are written, and it’s not how responsibility works in practice.
Under ICH GCP, sponsors remain responsible for the quality and integrity of all data generated within a clinical trial, including exploratory endpoints defined in the protocol. Regulators, including the MHRA, have been clear on this point in guidance and inspection feedback. The absence of inspection focus does not reduce accountability, it simply means the responsibility sits more squarely with the sponsor.
What I see in practice
In some of these environments, the gap is not subtle. Organisations may have limited awareness of GCP expectations, may never have been inspected and never expect to be, and may operate with processes that were never designed for regulated research. Yet they still state, often confidently, that they are working “in line with GCP.”
Without some level of sponsor oversight, that claim is rarely tested in any meaningful way.
The real risk is not what most people think
When I ask QA professionals about the risk of poor-quality early or “non-core” data, the most common answer is that we might continue developing a compound based on unreliable data. That’s a valid concern and it has clear financial and resource implications.
But there is another side to this that receives far less attention.
What if the data leads you to stop?
If unreliable data suggests a compound has little or no potential, it may be shelved early. The programme ends, the organisation moves on, and that decision is rarely revisited. The immediate risk appears to have been avoided, but the longer-term impact may be far greater.
A compound with real potential may never reach patients, not because it failed, but because the data used to judge it could not be trusted.
That risk is harder to see, but arguably far more significant.
The second layer of exposure: how this data travels
Early-stage and exploratory data rarely stays contained. It informs internal decisions, supports progression into regulated studies, and may ultimately be included in documents such as the investigator brochure.
At that point, expectations change. Even if the data was generated outside a formal regulatory framework, there is still an assumption that the sponsor has applied an appropriate level of oversight and understands its limitations.
Where traceability is weak or context is unclear, this creates real challenges. There have been cases where inconsistencies across early research, preclinical, and clinical data have raised questions about transparency and completeness. From a regulator’s perspective, the concern is not just compliance, but whether investigators have been given the information they need to make safe and informed decisions for participants.
This is not an argument for over-engineering
A full qualification programme for every exploratory activity would be disproportionate. But the current alternative in many organisations is not a thoughtful, risk-based model. It is often no deliberate oversight at all.
That’s not a balanced position. It’s simply the absence of a decision.
What would a more deliberate approach look like?
The shift starts with a simple change in thinking. Instead of asking whether the work is regulated, ask how the data will be used and what decisions it will inform. Once you frame it that way, it becomes much easier to design an appropriate level of oversight.
Start by mapping how this data flows through your programme. Where does it influence progression decisions? Where does it feed into regulated studies or formal documentation? If the data informs decisions, then it carries risk, and that risk should be visible.
Next, define what “good enough” looks like at each stage. Not all data needs GLP or GCP-level control, but it does need basic traceability, clarity on methods and limitations, and confidence that results are reproducible at the level required. This is about fitness for purpose, not perfection.
Finally, introduce light-touch, early oversight. This might include a targeted vendor assessment before work begins, a focused review of early data and records, or simply setting clear expectations up front. The aim is not to audit everything, but to avoid discovering fundamental issues when your options are already limited.
A final thought
The vendors that feel “low risk” are often the ones we understand the least. Not because they are inherently problematic, but because we have chosen not to look too closely.
If this month’s theme is about decision-making, then this is one of the clearest examples. Where are you accepting risk without really seeing it?
