Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Term of the Day

Natural history study

A natural history study is a preplanned observational study intended to track the course of a disease over time, identifying demographic, genetic, environmental and other variables that correlate with its development and outcomes in the absence of intervention, or under standard of care. Designs may be retrospective (chart review of existing records) or prospective (longitudinal follow-up of a cohort or registry).

Natural history data is particularly important in rare and paediatric diseases, where randomised placebo-controlled trials may be infeasible or unethical. The FDA (guidance on rare disease natural history studies, 2019) and the EMA accept well-designed natural history studies to define endpoints and biomarkers, identify patient subgroups, estimate sample sizes and, in some cases, serve as external or historical control arms for single-arm trials supporting orphan products.

Because they are non-interventional, natural history studies fall outside the CTR and are governed by national law (for example France's MR-003 or MR-004 reference methodologies) and by the GDPR. They typically involve secondary use of medical records, long-term follow-up, genetic data and small populations in which anonymisation is rarely achievable, so pseudonymisation, a DPIA and a robust research legal basis under Art. 9(2)(j) are essential. Registries maintained by patient organisations or academic consortia raise additional questions of joint controllership and data access governance.

V

Vendor assessment (third-party risk management)

Vendor assessment is the structured evaluation of a third-party supplier before engagement and periodically thereafter, to verify that it provides sufficient guarantees of compliance, security and quality for the services it delivers. Under Art. 28(1) GDPR a controller may only use processors providing sufficient guarantees to implement appropriate technical and organisational measures; under ICH GCP section 5.2 and Art. 71 CTR the sponsor remains responsible for tasks delegated to CROs and vendors and must oversee them; under Art. 21(2)(d) of the NIS2 Directive supply chain security is a mandatory risk management measure; and ISO 13485 and ISO 27001 both require supplier evaluation and control.

A proportionate assessment programme tiers vendors by the sensitivity and volume of data they handle and the criticality of the service (an EDC or safety database vendor is high tier; a translation agency handling anonymised documents is low tier). For each tier it defines the evidence to collect: a completed questionnaire, certifications (ISO 27001, SOC 2 Type II, HDS, ISO 13485, ISO 42001 for AI vendors), penetration test summaries, breach history, sub-processor lists, hosting locations and transfer mechanisms, business continuity arrangements, and for regulated systems the validation package. Findings feed the risk register, the DPIA (where iliomad scores each actor's security measures on a three-point scale) and the negotiation of the data processing agreement and, where needed, SCCs with a transfer impact assessment.

Assessment is not a one-off. Ongoing oversight includes review of audit reports and certification renewals, monitoring of sub-processor changes and incidents, periodic re-assessment (annually for high-tier vendors), audit rights exercised proportionately, and a clear exit plan covering return and deletion of data. Vendor files are among the first documents requested in GCP inspections, supervisory authority investigations and investor due diligence. iliomad runs vendor assessments and maintains vendor registers for sponsors and HealthTech companies; see vendor assessment services and the third-party risk management domain page.