Contents
Introduction
Most clinical trial management frameworks are built around a workflow metaphor: a series of steps that proceed from left to right, each one beginning after the previous one ends. Protocol finalized. IRB submitted. Site activated. Patients enrolled. Data locked. Report submitted. The Gantt chart stretches across the screen and the assumption embedded in it is that completion of one task creates the conditions for the next.
That assumption is wrong, and it explains a remarkable fraction of the delays, audit findings, and amendment cascades that plague clinical development. Clinical trials are not pipelines. They are dependency graphs, and the organizations that understand the difference are meaningfully better at predicting where their programs will break.
Why the Workflow Metaphor Fails
A workflow has a topology. It moves forward. In a true workflow, a downstream task does not reach backward and change the meaning of an upstream one. Update step seven and steps one through six remain intact.
Clinical trials do not work this way. Every major document and operational decision in a trial sits in bidirectional relationship with several others. The protocol is the anchor node, but changes to safety data in the Investigator's Brochure (IB) can require protocol amendments; those amendments invalidate the informed consent form (ICF), trigger IRB resubmission, force updates to the statistical analysis plan (SAP), require reprogramming of the electronic data capture (EDC) system, cascade into site retraining timelines, and ultimately touch the clinical study report (CSR) that will not be written for another three years. No step in that sequence is optional. Each one is a dependency.
The Tufts Center for the Study of Drug Development (Tufts CSDD) has been tracking the consequences of mismanaging this structure for years. A 2022 study analyzing 950 protocols and 2,188 amendments found that protocol amendment prevalence across Phase I through Phase IV trials has risen from 57% to 76% since 2015, and the mean number of amendments per protocol has increased 60%, from 2.1 to 3.3 [1]. These are not primarily the result of poor science. A much higher percentage of amendments, 77% in the more recent cohort, were deemed unavoidable, with regulatory agency requests and changes in study strategy cited as the top reasons [1].
- → IB → DSUR
- → IB → ICF
- → SAP → CSR
- → EDC / CRF → SAP
- → EDC / CRF → CSR
- → Protocol Amendment → ICF, IRB/EC, EDC, SAP, site training, contracts
A protocol amendment is not a task update. It is a graph traversal event.
An earlier Tufts CSDD analysis found that 45% of substantial amendments were deemed avoidable [2]. That the share of unavoidable amendments has since grown from 55% to 77% reflects increasing external pressure on trial designs. The operational finding, however, remains constant: when any amendment arrives, whether from inside or outside the sponsor organization, teams must accurately trace which documents, systems, and site processes carry content that the change will affect. That tracing problem does not disappear because an amendment was required by a regulator.
Mapping the Graph: What Depends on What
To reason about a clinical trial as a dependency graph, it helps to identify its principal nodes and the directed edges between them.
The protocol is the graph's root. Every other major document either derives content from it or must maintain consistency with it. The ICF, for instance, is not a downstream translation of the protocol, it is a structurally dependent document: changes affecting participant-facing information, eligibility criteria, procedures, visit burden, risk disclosures, or consent content require a corresponding update to the ICF and, frequently, resubmission to the IRB [3]. That resubmission has its own timeline. Sites that are already active cannot implement the changed protocol until IRB approval is secured (except where a change is made to eliminate immediate hazard to participants, which may be implemented before formal approval with subsequent notification), meaning that some sites may operate under one protocol version while others operate under a prior version during the gap period [3],[4].
The IB sits in a different part of the graph but is no less consequential. Under ICH E2F, the Development Safety Update Report (DSUR) uses the IB as its reference safety document, and Section 7.1 of the DSUR must specify the IB version and date used to determine the expectedness of adverse events [5]. If the IB is updated during the reporting period because new safety signals have emerged, ICH E2F requires that any changes to the reference safety information be addressed in the DSUR, including attaching the revised IB and discussing what changed. As an operational matter, this means the report should address how any mid-period IB changes bear on the expectedness characterizations documented for that reporting period [5]. This is not an administrative nuance; it is a pharmacovigilance accuracy requirement with direct inspection exposure if mishandled.
The SAP derives its primary structure from the protocol's endpoint definitions, estimand framework, and statistical methodology. Under ICH E9(R1), the protocol and analysis plan should pre-specify the estimand, primary analysis method, and sensitivity analyses [6]. Major protocol changes affecting study design or statistical methodology require corresponding SAP revisions, ideally formalized before database lock to preserve the integrity of pre-specified analyses; ICH E3 similarly requires the CSR to describe any deviations from planned analyses and the conditions actually used versus those originally specified [6],[13]. If an eligibility amendment changes the composition of the intended treatment population, the SAP's analysis populations may require revision. If a primary endpoint changes, the SAP's entire analysis hierarchy may be affected. TransCelerate's Clinical Content and Reuse (CC&R) Initiative formally acknowledged this interdependence by developing a Clinical Template Suite in which the common protocol template (CPT), SAP template, and CSR template are designed to share structured content and maintain consistency through automation, with the SAP explicitly described as integrating with the CPT [7].
The CSR, in turn, depends on the final protocol, the final SAP, and the accumulated data from the trial. An amendment that altered the primary endpoint mid-study does not simply appear as a footnote in the report; it requires explanation of the pre-amendment and post-amendment analysis populations, any changes in statistical power assumptions, and the regulatory rationale for the change. The CSR is at risk of inconsistency if the protocol, SAP, and EDC are not all synchronized with each other.
Clinical Trial Document Dependency Map
The table below summarizes the primary directed dependencies between the core trial documents. A change to any document in the left column propagates review or update requirements to the documents listed in the right column.
| Source Document | Directly Dependent Documents / Systems |
|---|---|
| Protocol | ICFSAPCRF/EDCIB (safety sections)DSURCSRsite training materialsregulatory submissions |
| Investigator's Brochure (IB) | DSUR (reference safety information, Section 7.1)protocol (safety context)ICF (risk disclosures) |
| SAP | CSR (analysis populations, primary endpoint tables, TLFs)EDC (analysis flags, database lock criteria) |
| ICF | IRB/EC submissionssite initiation recordsconsent tracking logs |
| EDC / CRF | SAP (analysis variable definitions)CSR (data section)monitoring plan |
| Protocol Amendment | ICF (re-consent)IRB/EC (resubmission)EDC (reprogramming)SAP (if endpoints or populations change)site trainingcontracts |
This is not a complete map, but it captures the highest-consequence dependency edges. A protocol amendment that touches eligibility criteria, endpoints, or safety procedures will typically affect multiple columns in this table simultaneously, and the appropriate scope of downstream review should be assessed for each amendment.
The Cascade Problem in Practice
What happens when a team manages a trial as a workflow rather than a dependency graph is predictable: they optimize each node in isolation without tracing the directed edges downstream.
A sponsor amends the eligibility criteria for a Phase III oncology trial to improve recruitment. The protocol is updated and submitted to the regulatory authority. The IRB receives the amendment, but the site-level consent templates have not yet been revised. The EDC still reflects the old inclusion and exclusion logic. The pharmacist is dispensing under the prior version. Site staff received informal verbal notification but no updated training records exist.
These are not hypothetical scenarios. Advarra's clinical experts have described the cascade explicitly: "amendments can disrupt patient visits, consent status, and continuity of care almost immediately. There's a cascade effect that slows implementation, and sites become understandably hesitant to move forward without full approval because even minor changes can create significant additional work" [8]. Implementation of amendments now averages 260 days, with sites sometimes operating under different protocol versions simultaneously during that window [1]. Tufts CSDD data shows that protocols with amendments are associated with longer timelines for study initiation, execution, and close-out, and result in fewer screened and enrolled patients relative to baseline plan [2].
The cost is substantial. Tufts CSDD's 2016 analysis of Phase III amendments reported a median direct implementation cost of $535,000 per amendment [2]. At a mean of 3.3 amendments per protocol, those costs and the associated timeline consequences become structural program risk, not incidental overhead.
What Dependency Graph Thinking Requires
In software engineering, a directed acyclic graph (DAG) is the formal data structure used to represent dependencies. Build systems like Bazel and workflow orchestration platforms like Apache Airflow use DAGs precisely because they allow a system to understand which components must be updated when an upstream node changes [9]. When a software module changes, the build system does not ask whether downstream modules need updating; it knows, because the dependency graph encodes that information.
Clinical research does not yet have a canonical equivalent of this structure, but the industry's most sophisticated reform initiatives are moving toward it.
TransCelerate's CC&R Initiative explicitly aims to enable "digitization, traceability, and the opportunity to reuse content for downstream processes, documents, and registries" through its technology-enabled templates [7]. The technology-enabled version of the CPT exports up to 47 variables in XML format, enabling downstream automated reuse in SAP authoring and CSR generation [10]. This is, functionally, a partial implementation of a dependency graph: a structured representation of which content values originated where, and which downstream documents must be updated if that value changes.
ICH E6(R3), adopted as a Step 4/Final Guideline in January 2025 [11], introduced what it explicitly calls an "interdependent" principles framework, stating that its principles "should be considered in their totality to assure ethical trial conduct and reliable results" [12]. The guidance further formalized the role of structured documentation across document types, including appendices dedicated to the IB, protocol, and essential records. These appendices do not exist independently; they reflect the regulatory acknowledgment that these documents must be consistent with each other, not merely individually correct.
ICH E3, which governs the structure of clinical study reports, specifies that the CSR must reflect an accurate account of the protocol as it was actually conducted, including all amendments, deviations, and the rationale for any changes to planned analyses [13]. A CSR written against a protocol that has undergone three amendments is, in effect, writing a history of how the dependency graph evolved over time.
Where the Graph Breaks: Three High-Risk Dependency Failures
Several failure patterns are well-documented and recur across therapeutic areas and development phases.
Protocol-to-ICF version drift. When protocol amendments are processed faster than site-level consent revisions, patients may be consented under an outdated form. This creates a GCP compliance gap with direct patient safety implications and generates audit exposure that regulatory inspectors will examine closely. IRB inconsistency across sites compounds the problem further, because different IRBs may approve the amended consent at different times, creating a period during which some sites are operating under the new protocol but the old consent and others under the new consent but awaiting site initiation approval [3].
IB-to-DSUR version misalignment. The DSUR's expectedness determination depends on the IB version current at the start of the reporting period. If an IB is updated during a reporting year and the DSUR fails to correctly specify which IB version served as reference safety information, or fails to address how mid-period IB changes bear on expectedness assessments, the adverse event characterizations in the report may be inaccurate. This is not a formatting issue; it is a pharmacovigilance accuracy failure with regulatory consequences [5].
Protocol-to-SAP endpoint inconsistency. A protocol amendment changing the primary endpoint from overall survival to progression-free survival, for example, requires a corresponding SAP amendment. If the SAP is not updated before database lock, the primary analysis cannot be conducted against the amended endpoint without post-hoc deviation from the pre-specified plan, which regulators will scrutinize carefully. Tufts CSDD's analysis has documented that amendments affecting endpoints or assessments have downstream impacts on EDC programming, statistical programming, Tables Listings and Figures, and final deliverable timelines [1].
Regulatory and Documentation Considerations
Regulatory agencies do not use the language of dependency graphs, but their documentation requirements embed the concept. FDA's guidance on electronic records under 21 CFR Part 11 requires secure, computer-generated, time-stamped audit trails for the creation, modification, or deletion of electronic records, essentially a version-controlled history of the state of each node in the trial document graph [14]. ICH E6(R3)'s emphasis on a risk-based quality management framework asks sponsors to proactively identify and monitor critical data and processes, which requires knowing which upstream changes create which downstream risks [11].
The EU Clinical Trials Regulation (CTR) adds a submission-level dependency. The CTR entered into application on January 31, 2022; became mandatory for all new clinical trial applications submitted via the CTIS portal from January 31, 2023; and set a final transition deadline of January 31, 2025 for trials previously authorized under the Clinical Trials Directive [15]. Within this framework, sponsors must decide whether to submit Part I and Part II of the clinical trial application in parallel or sequentially, with the parallel submission offering the fastest timeline but requiring both parts to be internally consistent at submission [15]. A Part I submission that describes a protocol and a Part II submission that describes site-specific requirements must be synchronized; inconsistencies between them can result in questions, delays, or refusal of the application depending on the nature of the issue.
For multi-regional trials, the dependency graph acquires additional regional nodes. Country-specific protocol amendments, local language requirements for consent forms, and jurisdiction-specific IRB review cycles all operate on different timelines and may place individual sites at different protocol versions at any given moment during implementation [3].
When a Protocol Section Changes: A Practical Review Checklist
Sponsors and CROs can reduce cascade failures by using a structured checklist at the point of any protocol amendment. The following areas should be reviewed whenever a protocol section is changed, before the amendment is finalized and submitted.
| Protocol Section Changed | Documents and Systems to Review |
|---|---|
| Eligibility criteria |
|
| Primary or key secondary endpoints |
|
| Dosing, administration, or visit schedule |
|
| Safety reporting requirements |
|
| Statistical methodology |
|
| Participant population or subgroups |
|
Every amendment should trigger dependency review before submission, not after downstream inconsistencies appear during activation, monitoring, or CSR preparation.
This checklist is not exhaustive. The appropriate scope will depend on the nature and breadth of the amendment, and regulatory or clinical operations leadership should make the final determination of which dependent documents require revision before submission. It is also worth noting that some of these dependencies are operationally bidirectional: a safety signal that prompts an IB update may require a protocol amendment, while the protocol amendment may in turn require a new IB edition to maintain coherence across both documents. These bidirectional edges do not carry the same formal regulatory status as the dependencies reflected in ICH guidance, but they represent real operational risk that amendment management processes should account for. See also: How Kitsa approaches cross-document consistency in regulatory document generation.
AI and Automation: What Dependency-Aware Systems Can Do
An AI system that treats clinical trial documents as independent artifacts is solving the wrong problem. An AI system that models the dependency relationships between documents, and tracks the state of each relationship as the trial evolves, is solving the right one.
Current large language model-based document generation tools can produce individual documents with high fluency and reasonable regulatory alignment. The limitation is that generating a protocol amendment without simultaneously identifying the downstream documents that must be updated, and the specific sections within those documents that carry the affected content, produces a first draft and a second problem.
Dependency-aware document systems, by contrast, would maintain a structured representation of which content in the ICF was sourced from which section of the protocol, which SAP parameters were derived from which protocol endpoints, and which IB version was current when each DSUR section was drafted. When a protocol node changes, the system can traverse the outgoing edges and identify which downstream documents contain content that must be reviewed or updated. That capability is qualitatively different from generating documents in sequence; it is about tracking the provenance and currency of every substantive claim across the document set.
The industry is beginning to move in this direction. TransCelerate's eTemplates represent a meaningful step, enabling automated content reuse between the CPT, SAP, and CSR through structured XML export [7],[10]. Agentic AI frameworks in clinical development extend this further by maintaining context across multiple documents and time periods, which is a prerequisite for dependency traversal rather than mere document generation. What these systems can currently do is surface candidate documents for review when a protocol change occurs; what they cannot yet reliably do is make the scientific, regulatory, and safety judgments required at each dependency boundary. Those remain human responsibilities.
What remains essential, regardless of the level of automation, is human review at each dependency boundary. An AI system can surface which documents need updating when a protocol changes; it cannot determine whether the scientific rationale for the change is sound, whether the regulatory strategy is appropriate, or whether the patient safety implications have been fully considered. Those judgments require domain expertise, and the human-in-the-loop requirement at each consequential node is not a limitation of current AI but an appropriate design choice for a high-stakes environment.
How Kitsa Fits Into This Problem
Kitsa positions KScribe, its AI-native regulatory document generation product, as designed to maintain content consistency across the document types that constitute a trial's core dependency graph: Protocol, IB, ICF, DSUR, SAP, and CSR. For sponsors and CROs managing programs where amendment cascades are a recurring source of delay and inspection risk, infrastructure designed to track document relationships rather than treat each artifact in isolation addresses the structural problem the industry has been working around for decades.
Clinical trial documents are not isolated artifacts. Protocols, ICFs, IBs, DSURs, SAPs, CSRs, EDC logic, site training, and regulatory submissions form a dependency graph. KScribe is designed to support regulatory document generation across this connected document layer, helping sponsors manage cross-document consistency, amendment propagation, and audit-ready review workflows.
Explore KScribeKey Takeaways
- Clinical trials are dependency graphs, not linear workflows. Every major document and decision depends on others in ways that are bidirectional and often non-obvious.
- Protocol amendment prevalence has risen to 76% across all trial phases, with a mean of 3.3 amendments per protocol. Each amendment propagates changes across multiple downstream documents simultaneously, at a median direct cost of $535,000 per Phase III amendment [1],[2].
- The protocol-ICF-IB-SAP-DSUR-CSR chain has specific, guidance- and process-defined dependency relationships. Failure to trace these relationships under ICH E2F, E6(R3), E9(R1), and E3 creates both compliance exposure and data integrity risk [5],[11],[6],[13].
- TransCelerate's Clinical Template Suite explicitly acknowledges cross-document dependency by enabling structured content reuse from the CPT into the SAP and CSR, including XML export of up to 47 protocol variables [7],[10].
- The EU CTR's Part I/Part II submission structure formalizes a dependency at the regulatory submission level: both parts must be internally consistent at the time of submission, or queries and delays follow [15].
- Amendment cascade failures are not documentation errors; they are graph traversal failures. Teams that do not map which documents carry content derived from an amended section will produce inconsistent trial records.
- Human review at each dependency boundary remains necessary regardless of automation level. AI can surface which documents need attention when a protocol changes; domain experts determine what those changes mean for the science and for patient safety.
FAQ
What is a dependency graph in the context of clinical trials?
Why do protocol amendments cascade across so many documents?
What does ICH E6(R3) say about cross-document consistency?
How does the DSUR depend on the Investigator's Brochure?
What is TransCelerate's Clinical Content and Reuse Initiative and why does it matter?
Can AI systems currently manage clinical trial document dependencies?
References
- [1]Getz K, Smith Z, Botto E, Murphy E, Dauchy A. "New Benchmarks on Protocol Amendment Practices, Trends and their Impact on Clinical Trial Performance." Therapeutic Innovation and Regulatory Science. 2024;58(3):539-548. doi:10.1007/s43441-024-00622-9. https://pubmed.ncbi.nlm.nih.gov/38438658/
- [2]Getz KA, Stergiopoulos S, Short M, Surgeon L, Krauss R, Pretorius S, Desmond J, Dunn D. "The Impact of Protocol Amendments on Clinical Trial Performance and Cost." Therapeutic Innovation and Regulatory Science. 2016;50(4):436-441. doi:10.1177/2168479016632271. https://link.springer.com/article/10.1177/2168479016632271
- [3]Advarra. "Reducing Startup Delays in Oncology Clinical Trials Through Consistent IRB Processes." Advarra Blog, February 2026. https://www.advarra.com/blog/reducing-startup-delays-in-oncology-clinical-trials/
- [4]Applied Clinical Trials. "Accelerating Clinical Trial Activation." Applied Clinical Trials Online, June 21, 2024. https://www.appliedclinicaltrialsonline.com/view/accelerating-clinical-trial-activation
- [5]U.S. Food and Drug Administration. "Guidance for Industry E2F Development Safety Update Report." FDA, August 2011. https://www.fda.gov/media/71255/download
- [6]ICH. "ICH E9(R1) Addendum on Estimands and Sensitivity Analysis in Clinical Trials to the Guideline on Statistical Principles for Clinical Trials." ICH, November 2019. https://database.ich.org/sites/default/files/E9-R1_Step4_Guideline_2019_1203.pdf
- [7]TransCelerate BioPharma. "Clinical Content and Reuse Initiative." TransCelerate, 2024. https://www.transceleratebiopharmainc.com/initiatives/clinical-content-reuse/
- [8]Advarra. "What Protocol Amendments Reveal About Trial Design." Advarra Blog, May 2026. https://www.advarra.com/blog/what-protocol-amendments-reveal-about-trial-design/
- [9]Tweag. "Introduction to the Dependency Graph." Tweag Blog, September 2025. https://www.tweag.io/blog/2025-09-04-introduction-to-dependency-graph/
- [10]DiCicco R. "Digital Data Flow: From A Common Protocol Template To True Digital Automation." Clinical Leader, 2018. https://www.clinicalleader.com/doc/digital-data-flow-from-a-common-protocol-template-to-true-digital-automation-0001
- [11]ICH. "ICH E6(R3) Guideline on Good Clinical Practice (GCP), Step 4/Final Guideline." ICH, January 6, 2025. https://database.ich.org/sites/default/files/ICH_E6%28R3%29_Step4_FinalGuideline_2025_0106.pdf
- [12]European Medicines Agency. "ICH E6 Good Clinical Practice, Scientific Guideline." EMA, July 2025. https://www.ema.europa.eu/en/ich-e6-good-clinical-practice-scientific-guideline
- [13]ICH. "ICH E3: Structure and Content of Clinical Study Reports." ICH, 1995. https://database.ich.org/sites/default/files/E3_Guideline.pdf
- [14]U.S. Food and Drug Administration. "21 CFR Part 11: Electronic Records; Electronic Signatures." FDA. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11
- [15]European Medicines Agency. "Clinical Trials Regulation." EMA Human Regulatory Overview, 2024. https://www.ema.europa.eu/en/human-regulatory-overview/research-development/clinical-trials-human-medicines/clinical-trials-regulation
