Manage Risks and Conduct Assessments in the RACT

This article is currently being updated. Please come back later for updates.

Permissions: RACT Assessment Read Only: Provides access to view assessments and export reports.
RACT Assessment Read Write: Provides access to create, edit, archive, and finalize assessments and manage risks. 
Risk Management Configuration: Provides access to configure and manage CTQs, Considerations, Risk Libraries, KRIs, QTLs, Functional Plans, Critical Data, Critical Processes, and Alerts.

Assessments use an Assessment Setting defined in Risk Management Configuration. The Assessment Setting determines the CTQs and Considerations, Risk Assessment form fields, and Risk scoring used for the assessment. Other configured items, including Critical Data, Critical Processes, KRIs, QTLs, Functional Plans, and Risk Libraries, are also available for use during the assessment.

Create an Assessment or Reassessment

RACT provides separate options for creating a new assessment and creating a reassessment:
Assessment Versions listing showing Create Reassessment and Create New Assessment options

  • Create New Assessment: Creates an assessment without carrying forward Risks from a finalized assessment.
  • Create Reassessment: Creates a reassessment based on a finalized assessment and carries forward its Risks.

Important: If a draft assessment exists, creating a new assessment or reassessment cancels the current draft and all progress in the draft is lost.

Create a New Assessment

Create a new assessment to start an assessment without carrying forward Risks from a finalized assessment.

  1. From the All view, click Create New Assessment. The Create New Assessment window opens.
    Create New Assessment window showing Assessment Team and Assessment Setting options
  2. Configure the Assessment Team:
    • Select or add the applicable team members.
    • Enter the Function for each team member.
    • Assign the applicable Participant, Owner, Reviewer, and Approver roles.
  3. Select an Assessment Setting. The Risk Assessment Form Preview displays the form associated with the selected setting.
  4. Click Create. The assessment opens with a status of In Progress.

Create a Reassessment

Create a reassessment to carry forward Risks from a finalized assessment and continue Risk tracking across assessment versions. Carried-forward Risks retain their Risk identity and content. Risks that do not have a valid Consideration in the selected Assessment Setting are placed under the system-defined Unaffiliated CTQ.

  1. From the All view, click Create Reassessment. The Create Reassessment window opens.
    Create Reassessment window showing Carry Forward Risks, Assessment Team, and Assessment Setting options
  2. Select the finalized assessment to carry forward from Carry Forward Risks. All Risks from the selected assessment are carried forward to the reassessment.
  3. Configure the Assessment Team:
    • Select or add the applicable team members.
    • Enter the Function for each team member.
    • Assign the applicable Participant, Owner, Reviewer, and Approver roles.
  4. Select an Assessment Setting. The Risk Assessment Form Preview displays the form associated with the selected setting.
  5. Click Create. The reassessment opens with a status of In Progress.

Note: Carried-forward Risks remain under their existing CTQs and Considerations when the Considerations are valid in the selected Assessment Setting. Risks without valid Considerations are placed under the Unaffiliated CTQ.

Note: Carried-forward Risks retain their Risk identity, content, and associated IDRPs where applicable.

Note: If the Risk scoring configuration differs in the selected Assessment Setting, existing score selections are cleared and must be completed again. Other Risk information that can be carried forward remains populated.

Configure Assessment Team

Configure the Assessment Team to assign roles for the assessment and optional review and approval workflow. At least one Participant and one Owner are required. The Owner must also be assigned as a Participant.

Reviewers and Approvers are optional and do not need to be Participants. When Reviewers or Approvers are assigned, all required review and approval steps must be completed before the assessment can be finalized.

The Assessment Team can also be updated from the Review and Approval panel after the assessment is created. All users can view the panel, but only Owners can add users, assign roles, or update the Assessment Team. At least one Owner must remain assigned.

To configure the Assessment Team:

  1. Click Add to add a team member.
  2. Complete the team member details:
    • User: Select the user from the drop-down.
    • Function: Enter the function.
    • Assign one or more applicable roles:
      • Participant
      • Owner
      • Reviewer
      • Approver
  3. Repeat the steps to add additional team members as needed.
  4. Click the Delete icon to remove a team member, if needed.

Select Assessment Setting

Select the Assessment Setting for the assessment. The Assessment Setting determines the CTQs and Considerations, Risk Assessment form fields, and Risk scoring used for the assessment. The Risk Assessment Form Preview displays the form associated with the selected setting.

Define the Assessment Version

After a new assessment or reassessment is created, the Assessment Version page opens with a status of In Progress. To open an existing assessment version, click the link in the Version column in the Assessment Versions listing.

The Assessment Version page displays CTQ Considerations grouped by CTQ in the left panel and Risk cards on the right side. Selecting a Consideration displays the associated Risk cards. A gray badge indicates the number of Risks assigned to each Consideration.

  1. Select a CTQ Consideration from the left panel and add the applicable Risks. Considerations that do not apply can be skipped. The assessment can be finalized when all required fields for included Risks are complete, even when some selected Considerations have no Risks.

    Note: General Risk(s) is automatically added as the last consideration under each CTQ to capture risks not linked to a specific consideration.

    Note: The system-defined Study Specific and Unaffiliated CTQs provide locations for study-specific Risks and Risks that do not align with another CTQ. These CTQs and their Considerations cannot be modified.

    Tip: Click the Details icon next to a CTQ header to view details for all Considerations under that CTQ on the right side.

Add a Risk

Add Risks to applicable CTQ Considerations in a new assessment or reassessment.

  1. Select a Consideration in the left panel. The selected Consideration displays at the top of the page.
  2. Click Add Risk. The Add Risk window opens.
    Assessment Version page showing a selected CTQ Consideration and the Add Risk option
  3. Complete the Risk details manually or select a Risk from the Risk Library.
    Add Risk window showing Risk Identification and Critical Data and Processes fields

Note: Fields with a red asterisk are required. Use the scrollbar to view all fields.

Note: The Risk Management Configuration privilege allows new options to be added directly from supported multi-select fields. Enter a value that does not exist, then click + Add to create and select the entry. Newly created entries are available for reuse across studies.

Add a Risk Manually

Enter the required fields in the Add Risk window to define and evaluate the Risk.

  • Risk Assessment ID: System-generated. Displays 0 until the Risk is saved.
  • Complete all required fields based on the configured Risk Assessment form.

Add a Risk from the Risk Library

Use the Risk Library to add a preconfigured Risk and standardize Risk definitions.

  1. Click Select Risk from Library. The Select Risk window opens.
    Select Risk window showing available Risks from the Risk Library
  2. Use the Search field to locate a Risk.
  3. Select a Risk from the list.
  4. Click Apply.

Risks associated with the selected CTQ are prioritized at the top of the list.

The selected Risk populates configured fields in the Add Risk window. Risk Library reference information displays under Risk Identification to provide traceability to the source Risk.

Add Risk window showing a Risk selected from the Risk Library

The Risk Description is read-only while the Risk remains linked to the Risk Library. To modify the Risk Description, click Unlink from Risk Library.

Continue scrolling to review populated fields and available recommendations.

Add Risk window showing Monitoring Metrics recommendations and mitigation actions

Review and Update Populated Fields

Review populated values and recommendations to ensure they align with the study context.

Fields populated from the Risk Library may include:

  • Functional Plans
  • Pre-Study Mitigation Actions
  • During-Study Mitigation Actions
  • Contingency Actions

The Recommendations section under Monitoring Metrics may display recommended Key Risk Indicators and Quality Tolerance Limits. Select the applicable KRIs and QTLs as needed.

Complete any remaining required fields before saving.

Generate an AI Risk Statement

Use AI-assisted generation to create a structured Risk Statement based on the Risk Description.

Click Generate Statement.

Add Risk window showing the Generate Statement option for a Risk selected from the Risk Library

The system:

  • Parses the Risk Description
  • Populates the Event, Cause, and Impact fields.
  • Generates a structured if / due to / then Risk Statement.

To generate an alternative suggestion, click Generate Statement again. When the Risk Description changes, the generated content updates automatically. AI-generated actions are logged for auditing.

Note: AI-assisted generation requires Allow Machine Learning to be enabled. The quality of generated content depends on the clarity and completeness of the Risk Description. Review and edit the generated content as needed.

Note: AI-generated content includes a disclaimer indicating that the content requires review. Editing the generated content removes the disclaimer.

Critical Data and Processes

Identify the Critical Data and Critical Processes impacted by the Risk to support Risk evaluation and monitoring.

Critical Data and Processes fields in the Add Risk window
  • Critical Data: Select one or more values, or enter a new value and click Add. Newly created entries are available for reuse.
  • Critical Processes: Select one or more values, or enter a new value and click Add. Newly created entries are available for reuse.

Risk Evaluation

Define how the Risk is assessed by assigning scores that determine the Overall Risk Score (Risk Priority Number).

Risk Evaluation fields showing scoring options, Weight, Risk Control Threshold, and Critical Risk
  • Impact: Select the severity of the Risk.
  • Likelihood: Select the probability of occurrence.
  • Detectability: Select how easily the Risk can be detected.

These values are defined in Risk Management Configuration > Risk Levels.

  • Weight: Adjust the value to scale the Overall Risk Score, if needed.
  • Risk Control Threshold: Displays the configured threshold for Risk control.
  • Overall Risk Score (Risk Priority Number): Automatically calculates based on Impact Score × Likelihood Score × Detectability Score × Weight.
  • Critical Risk: Select Yes or No to indicate whether the Risk is critical.

Risk Control

Define how the Risk is managed and assign responsibility for Risk control.

Risk Control fields showing Risk Control Action, Risk ownership, Functional Plans, and ongoing monitoring
  • Risk Control Action: Select Accept or Mitigate.
  • Risk Owner Name: Enter the name of the individual responsible for the Risk.
  • Risk Owner Role: Enter the associated role.
  • Functional Plans: Select one or more Functional Plans, or enter a new value and click Add. Newly created entries are available for reuse.
  • Detectable via ongoing monitoring?: Select the applicable value to indicate whether the Risk can be detected through ongoing monitoring.

Available plans are maintained in Risk Management Configuration > Functional Plans.

Monitoring Metrics

Define how the Risk is monitored and managed during the study.

Monitoring Metrics fields showing recommendations, monitoring ownership, mitigation actions, and Contingency Actions

The Recommendations section displays recommended KRIs and QTLs when recommendations are available from the selected Risk Library entry.

  • Quality Tolerance Limits: Select or add QTLs used to monitor study-level quality performance. Enter the applicable Data Source.
  • Key Risk Indicators: Select or add KRIs used to monitor ongoing Risk. Enter the applicable Data Source.
  • Include into Review Plan: Select Yes to make the Risk available for linking to Review Objectives in Data Central.
  • Monitoring Owner Name: Enter the name of the individual responsible for monitoring the Risk.
  • Monitoring Owner Role: Enter the associated role.
  • Pre-Study Mitigation Actions: Select one or more actions performed before study start, or enter a new value and click Add. Newly created entries are available for reuse.
  • During-Study Mitigation Actions: Select one or more actions performed during study execution, or enter a new value and click Add. Newly created entries are available for reuse.
  • Contingency Actions: Select one or more actions to support response planning if the Risk occurs, or enter a new value and click Add. Newly created entries are available for reuse.

Use Add to include additional QTLs or KRIs as needed.

Note: The Contingency Actions field is configurable and may not display if it is not enabled in Risk Management Configuration.

Risk Review and More Details

Document Risk realization, follow-up actions, closure, and transfer details.

Risk Review and More Details fields for Risk realization, closure, and CRO transfer

Under Risk Review:

  • Risk Realized: Select Yes or No to indicate whether the Risk occurred.
  • Date Risk Realized: Enter the date the Risk occurred.
  • Require adjustments of risk controls: Select Yes or No to indicate whether Risk controls require adjustment.
  • Causes (if Risk Realized): Enter the identified causes of the realized Risk.
  • Impact (if Risk Realized): Enter the impact of the realized Risk.
  • Realization Comments: Enter additional information about the realized Risk.
  • CAPA, if applicable: Enter applicable corrective and preventive actions.

Under More Details:

  • Reason for Closure: Enter the reason for closing the Risk.
  • Close Date: Enter the date the Risk is closed.
  • Transferred to CRO: Select Yes or No to indicate whether the Risk was transferred to a CRO.
  • Date of Transfer to CRO: Enter the date the Risk was transferred to the CRO.

Save the Risk

Click Save.

The Risk is added to the assessment, and the system assigns the study-level Risk Assessment ID.

Note: The Risk Assessment ID identifies the Risk within the study and differs from the global Risk ID used to maintain Risk identity and traceability.

Edit a Risk

Use the Edit Risk window to update Risk details, mitigation actions, monitoring metrics, and evaluation fields during an assessment.

Click a Risk card, or click the Comments icon on a Risk card to open the Edit Risk window with the Comments panel open.

Risk card showing the Comments icon

Update the available fields as needed, then click Save to apply changes.

Edit Risk window showing Risk Identification and Critical Data and Processes fields

The Risk Assessment ID is system-generated and cannot be edited.

Note: For Risks carried forward from a finalized assessment, the Risk Description and Risk Statement fields are read-only.

Note: For Risks linked to the Risk Library, the Risk Description field remains read-only until the Risk is unlinked from the Risk Library.

Note: In finalized assessments, the Edit Risk window is read-only.

Move a Risk

Use Move Risk to move a Risk to another Consideration within the same assessment. The Risk retains its content and Risk ID when moved.

  1. Click the Risk Actions menu on the Risk card and select Move Risk.Risk card showing the Risk Actions menu with Move Risk and Delete Risk options

  2. The Move Risk popout opens.
    Move Risk popout showing CTQs and Considerations available for selection

  3. Select the destination Consideration. Use the Filter field to locate a CTQ or Consideration, if needed.

  4. Click Move Risk.

The Risk moves to the selected Consideration and retains its content and Risk ID.

Delete a Risk

  1. Click the Risk Actions menu on the Risk card and select Delete Risk. The confirmation prompt opens.
  2. Click Delete to remove the Risk, or click Cancel to keep the Risk.

Note: Risks in finalized assessments cannot be deleted.

Conduct an Assessment

Conduct an assessment by reviewing CTQ Considerations, adding or updating Risks, resolving incomplete Risk cards, and using comments to support collaboration.

  • View All Risks: Displays all Risk cards across all CTQ Considerations.
  • View Incomplete: Displays Risk cards with missing required information. Complete all required fields before submitting, approving, or finalizing the assessment.
  • Documentation: Opens the Documentation window to enter version details, protocol changes, and change history during the assessment lifecycle.
  • Comments & Activities: Opens the Comments & Activities panel to add assessment-level comments, use @mentions, and review activity history. Mentioned users receive email notifications.
  • Risk comments: Click the Comments icon on a Risk card to add comments specific to the Risk.

Review and Approval Workflow

RACT assessments support an optional review and approval workflow. The workflow depends on the roles assigned to the Assessment Team.

If only the Owner and Participant roles are assigned, the assessment does not require review or approval. The Owner can finalize the assessment after all required fields are complete.

If one or more Reviewers are assigned, the assessment must move through Pending Review before finalization. All assigned Reviewers must complete their review before the assessment can continue.

If one or more Approvers are assigned, the assessment must move through Pending Approval before finalization. All assigned Approvers must complete their approval before the assessment can continue.

If both Reviewers and Approvers are assigned, the assessment moves through the full workflow:

  • In Progress: Assessment activities and updates are in progress.
  • Pending Review: Assigned Reviewers complete their review.
  • Pending Approval: Assigned Approvers complete their approval.
  • Pending Finalization: The assessment is ready for the Owner to finalize.
  • Finalized: The assessment is locked and read-only.

Owners submit assessments for review and finalize assessments at the Pending Finalization stage. Owners can also withdraw a submission, which resets the workflow progress.

Reviewers and Approvers can complete their assigned step or request revisions. Withdrawing an individual review or approval affects only that user’s progress and does not change the overall assessment status.

The assessment advances to the next workflow status only after all assigned users for the current stage complete their required action.

As the assessment progresses through each stage, assigned users receive email notifications with a link to the assessment, allowing them to access and complete their assigned actions.

Check Review Status

After an assessment is submitted for review, the value in the Status column becomes a hyperlink. From the All view, click the status in the Assessment Versions listing to open the Review Status window and view progress across Reviewers and Approvers.
Assessment Versions listing showing the Pending Review status link

The Review Status window displays assigned Reviewers and Approvers, their current workflow status, and the number of completed reviews or approvals.

Review Status window showing Reviewer and Approver progress

Comments & Activities

Comments support collaboration and traceability throughout the assessment lifecycle.

  • Comments can be added at the assessment level or Risk level.
  • Assessment-level comments apply to the full assessment.
  • Risk-level comments apply to an individual Risk.
  • Use @mentions to notify another elluminate user. Mentioned users receive an email notification. Only users with access to the assessment can be mentioned.
  • Status updates, such as In Progress to Pending Review, display as activities in the panel.

Comments and activity history remain available after finalization.

Add or Review Comments

  1. Click Comments & Activities. The panel opens.
    Comments & Activities panel showing an @mention and assessment status activity
  2. Enter a comment in Add Comment. Use an @mention to notify another user, if needed.
  3. Click Add.
  4. Review existing comments and assessment activities in the panel.
  5. Click Close to close the panel.

Document an Assessment

Use the Documentation window to enter version details, protocol information, change history, and the reassessment interval during the assessment lifecycle.

  1. Click Documentation. The Documentation window opens.
    Documentation window showing version, protocol, and Version History fields

  2. Complete the applicable fields:
    • Version Name: Enter a name for the assessment version.
    • Version Description: Enter a description.
    • Protocol Amendment: Enter the protocol amendment.
    • Protocol Amendment Date: Enter the date or use the calendar picker.
    • Protocol Complexity: Enter the protocol complexity.
  3. Under Version History, complete the applicable fields:
    • Description of the Change: Enter a description of the change.
    • Reason for the Change: Enter the reason for the change.
  4. Under Reassessment Interval, select Week or Day, then enter the number of weeks or days.
  5. Click Save.

Note: Fields with a red asterisk are required.

Review and Finalize an Assessment

The review and approval workflow is optional and depends on the roles assigned to the Assessment Team. If no Reviewers or Approvers are assigned, the Owner can finalize the assessment directly. When Reviewers or Approvers are assigned, all required review and approval steps must be completed before finalization.

Update the Assessment Team

  1. Click Review and Approval. The Review and Approval window opens.
    Review and Approval window showing Assessment Team roles and workflow actions

  2. Update the Assessment Team, if needed.
  3. Click Save.

Submit for Review

The Owner submits the assessment to begin the review process.

  1. Click Review and Approval.
  2. Click Submit For Review.
  3. Click Continue to confirm.

Reviewers and Approvers receive an email with a link to the assessment.

Complete Review

Assigned Reviewers complete the assessment review.

  1. Open the assessment from the email link.
  2. Review the assessment.
  3. Select Request Revision or Complete Review.

The assessment advances automatically when all Reviewers complete their review.

Request Revision

Reviewers or Approvers can request updates before the assessment proceeds.

  1. Enter a comment. Owners are automatically @mentioned.
  2. Click Submit.

Mentioned users receive an email notification.

Withdraw Review

Reviewers can withdraw their review to update their response.

  1. Click Withdraw Review.
  2. Click Continue.

The withdrawal resets only the Reviewer's progress and does not change the overall assessment status.

Approve

Assigned Approvers complete the approval step for the assessment.

  1. Click Approve.
  2. Click Continue in the Attention window.

Finalize the Assessment

The Owner finalizes the assessment after all required workflow steps are complete. After finalization, the assessment is locked and read-only.

  1. Click Finalize. The Finalize Assessment window opens.
    Finalize Assessment window showing version and protocol fields
    Finalize Assessment window showing Version History, Reassessment Interval, and new version option
  2. Review the Risk Assessment Version Details, then complete the applicable fields:

    • Version Name: Enter a name for the assessment version.

    • Version Description: Enter a description.

    • Protocol Amendment: Enter the protocol amendment.

    • Protocol Amendment Date: Enter the date or use the calendar picker.

    • Protocol Complexity: Enter the protocol complexity.

  3. Under Version History, complete the applicable fields:
    • Description of the Change: Enter a description of the change.
    • Reason for the Change: Enter the reason for the change.
  4. Under Reassessment Interval, select Week or Day, then enter the number of weeks or days. 
  5. Select Create a new version of the assessment with the same settings to finalize the current version and automatically create a new version with a status of In Progress. Leave the checkbox cleared to finalize the current version without creating a new version.

    Note: To carry forward Risks from a specific finalized assessment, use Create Reassessment. from the All view.

  6. Click Finalize.

Integrated Data Review Plan & Risks

RACT integrates with the Integrated Data Review Plan (IDRP) to align identified Risks with Review Objectives defined in Data Central.

Link Risks to the Review Plan: When adding or editing a Risk, set Include into Review Plan to Yes to make the Risk available for selection in Review Objectives in Data Central Configuration. The Risk is linked to the Review Plan after it is selected in one or more Review Objectives. Linkage is based on the latest finalized assessment.

  • Review Plan link: In finalized assessments, Risks linked to the Review Plan display Review Plan (n) on the Risk card, where n represents the number of linked Review Objectives. 
    Risk card showing the Review Plan link and number of linked Review Objectives
  • Click the Review Plan (n) link to open Review Objectives in Data Central Configuration, filtered to the selected Risk. 

    Review Objectives in Data Central Configuration showing the Risk column filtered to the selected Risk

Archive an Assessment

Assessments cannot be deleted for compliance reasons. Only finalized assessments can be archived. Archived assessments are removed from active use and cannot be recovered.

  1. From the All view, select a finalized assessment version and click Archive. The Archive Assessment window opens.
    Assessment Versions listing showing a finalized assessment selected for archiving
  2. Review the Risk Assessment Version Details and enter the Reason for Archive.
    Archive Assessment window showing Risk Assessment Version Details and Reason for Archive

    Note: If the latest finalized assessment contains Risks linked to Review Objectives, a warning message displays before archiving. Archiving the assessment breaks the linkage to the Review Plan, but linked Review Objectives remain available for review before proceeding.

  3. Click Archive Assessment. The assessment version is permanently archived and moved to the Archived view for reference.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request