This guide covers the CHRC topic areas — human subjects regulatory frameworks, compliance program structure, informed consent, IRB operations, research misconduct, and data integrity — through scenario-based teaching. You get two worked scenarios with common missteps, a review-pathway decision table, a mock regulatory binder audit with a scoring rubric, and a four-week preparation sequence with concrete readiness milestones. Administrative details such as eligibility, scheduling, and fees are set by the certifying body; see the issuer pages listed at the end for current requirements.
Which rulebook applies: the Common Rule, FDA rules, or both
Scope determines the framework. Federally supported human subjects research implicates 45 CFR 46 (the Common Rule); research involving FDA-regulated articles implicates 21 CFR Parts 50 and 56; ICH-GCP is an international good-practice standard many institutions adopt voluntarily.
Sorting frameworks starts with two scope questions. First, does the activity meet the definition of human subjects research — a systematic investigation designed to develop generalizable knowledge involving living individuals about whom an investigator obtains data or specimens through intervention or interaction? Second, which framework's jurisdictional hook is present: HHS support or conduct for the Common Rule, or use of a drug, device, biologic, or other FDA-regulated article for the FDA rules. A single oncology trial can sit under both simultaneously, and the requirements overlap without being identical.
Build a personal crosswalk document with one column per framework and one row per concept: consent elements, IRB composition, review categories, continuing review, and recordkeeping. Where the frameworks align, write 'aligned'; where they differ, write the difference in one sentence. This crosswalk becomes your primary study artifact, because every later topic — consent, IRB operations, reporting — can be drilled by asking which column a scenario falls into and checking your written difference.
Informed consent: required elements, documentation, and the re-consent trigger
Valid consent contains the federally required elements — purpose, procedures, risks, benefits, alternatives, confidentiality, costs, contacts, and voluntariness — documented on the currently IRB-approved form, and it is a continuing duty that triggers re-consent when new information could affect willingness.
Study the elements as a checklist you can reconstruct from memory, then study the process requirements that sit around the checklist: consent must be obtained by authorized study personnel, the participant must have adequate time to consider, coercion and undue influence are prohibited, and the signed document must match the IRB-approved version. Emergency-use and waiver circumstances exist under both frameworks, but they are narrow, institution-determined exceptions, not defaults you can assume in a scenario.
Worked scenario 1: A coordinator discovers that a revised consent form was IRB-approved two weeks ago, but three participants signed the prior version after that date. The tempting mistake is to quietly swap the form, restart use of the new version, and tell no one — a compound error, because it leaves unapproved documentation in the record and conceals a deviation. The better decision is to document the facts, notify the IRB through the institution's reportable-event process, assess whether the content difference affected those three participants, and re-consent them if the IRB directs. Why it matters: the compliance professional's value is surfacing and routing the problem with a factual record, and the fix chosen by the IRB — re-consent, notification, or no action — must be the board's call, not the study team's.
Re-consent deserves its own line in your notes, tied directly to its trigger: new risk information, new findings, or material changes to the protocol that might bear on a participant's willingness to continue. Drill it by writing three short scenarios in which each trigger appears, then state what the re-consent step would look like in each.
Exempt, expedited, or full board: choosing and justifying the IRB review pathway
Review level follows risk and the applicable category lists, and the determination belongs to the IRB or the institution — investigators proposing an exemption is itself a scenario red flag. Match each pathway to its fit, examples, and ongoing obligations.
Exempt status depends on meeting specific minimal-risk category definitions and is determined by the institution, not self-declared by the investigator in most institutional policies. Expedited review fits minimal-risk research appearing on the expedited category lists, plus minor changes to previously approved research. Full board review covers greater-than-minimal-risk research, studies involving vulnerable populations, and anything not fitting a lesser pathway. A useful comparison point across frameworks is continuing review: whether it is required depends on the framework and the risk level, so record the rule per column in your crosswalk rather than assuming one universal answer.
Drill the pathway decision with boundary cases. Is a records-only study of existing charts identifiable? That pushes toward exempt or expedited depending on category and data handling. Does the same study add an investigational device? That generally removes the lesser pathways. Writing your own five boundary cases and labeling them is faster than rereading category lists, because the lists only make sense once you can see the risk logic underneath them.
See the decision table below for a summary you should reproduce from memory by the end of your study plan.
| Review pathway | Typical fit | Examples | Key ongoing considerations |
|---|---|---|---|
| Exempt | Minimal-risk research within defined institutional categories | Anonymous surveys, certain records-only studies | Determined by the institution; limited changes can remove exempt status |
| Expedited | Minimal-risk research on expedited category lists; minor changes | Non-invasive data collection, small chart reviews | Whether continuing review applies depends on framework and category |
| Full board | Greater-than-minimal-risk or not fitting lesser pathways | Investigational drug trials, research with vulnerable populations | Scheduled continuing review where required; reportable-event reporting |
| Waiver/alteration | Consent not feasible or not practicable | Emergency research, certain records studies | Must meet specific waiver criteria; privacy approval may still be needed |
Reporting triggers: separating adverse events, unanticipated problems, and deviations
Classification drives timing and route. An adverse event harms a participant; a protocol deviation departs from approved procedures; an unanticipated problem is unexpected, related or possibly related, and suggests greater risk — and it demands the fastest reporting path.
Practice the classification in this order: what happened, was it unexpected, was it related to the research, does it suggest new or increased risk to current or future participants. A known side effect listed in the consent form is an expected adverse event. The same side effect at a severity far beyond what was described, in a participant whose exposure plausibly caused it, has the signature of an unanticipated problem. A missed blood draw is a deviation even if no one is harmed. Each label points to a different reporting destination and urgency under institutional policy.
Worked scenario 2: A participant is unexpectedly hospitalized overnight, and the coordinator cannot rule out a relationship to the study intervention. The tempting mistake is to log it as a routine deviation and bundle it into the annual review packet, reasoning that the hospital resolved the issue. The better decision is immediate escalation through the expedited reportable-event channel to the IRB and the sponsor per policy, because the combination of unexpectedness, possible relatedness, and new risk is precisely what the unanticipated-problem definition captures. Why it matters: the classification, not the eventual outcome, sets the reporting clock, and a compliance professional who mislabels the event delays every downstream protection — IRB assessment, potential consent-form changes, and participant safety actions.
Add a fourth classification to your notes: non-compliance findings, which trigger institutional review of root cause and corrective action rather than a per-event report.
Research misconduct under the federal definition — and what is not misconduct
The federal definition covers fabrication, falsification, and plagiarism in proposing, performing, or reviewing research, committed intentionally or recklessly and representing a significant departure from accepted practices; honest error and legitimate differences of interpretation are expressly excluded.
Learn the three behaviors with one-sentence definitions: fabrication is making up data or results, falsification is manipulating materials or processes so the record misrepresents what occurred, and plagiarism is appropriating another's ideas or words without attribution. The qualifying conditions matter as much as the definitions — a finding requires proof by a preponderance of the evidence of intentional or reckless significant departure from accepted practice. That is why a transcription error caught and corrected with a clear audit trail is a data-quality event, not misconduct, and a disputed analytic choice between qualified researchers is a difference of opinion, not plagiarism.
Whistleblower protections are the program-side counterpart. Good-faith reporters of suspected misconduct or non-compliance are protected from retaliation, and the compliance professional's role is to protect the reporting channel: accept concerns, route them to the designated institutional official for inquiry and investigation where warranted, keep the reporter's identity handled per policy, and document the process. Scenario practice should include a report that turns out to be honest error, because handling that outcome professionally — correcting the record without punishing the reporter — is the concept the definition exists to protect.
Distinguish institutional research non-compliance, which spans a broad range of protocol and consent violations, from the narrower federal misconduct definition; both matter, and they follow different procedures.
Data integrity and recordkeeping: HIPAA authorization, audit trails, and reconstructable files
Records must let a reviewer reconstruct who did what, when, and why. The compliance professional checks source documentation, the separation of HIPAA authorization from informed consent, and retention practices consistent across the file.
Two documents serve two different laws, and scenarios exploit the confusion. Informed consent operates under the research protections framework and covers the research relationship. HIPAA authorization operates under the Privacy Rule and permits use and disclosure of protected health information for research; alternatively, a privacy board or IRB may grant a waiver when criteria are met. A complete consent form does not substitute for a missing authorization, and a signed authorization does not satisfy consent requirements. In your crosswalk, give privacy its own row so you never assume one document covers both.
Data integrity practice centers on traceability. Corrections to source records should preserve the original entry, identify who made the change and when, and carry a reason — that is the audit-trail habit. Regulatory files should contain protocol versions, approved consent versions, delegation-of-authority documentation, and correspondence sufficient for an external reviewer to follow the study's history without asking questions. When you audit any record set, the test is reconstruction: can you tell from the file alone what happened at each visit and each approval point? If the answer requires memory or phone calls, the recordkeeping failed the test even if nothing unethical occurred.
A four-week CHRC preparation sequence with a self-check rubric
Week one builds the framework crosswalk; week two covers consent and IRB operations; week three covers reporting, misconduct, and records; week four runs scenario drills and a mock regulatory binder audit, scored against explicit milestones.
Follow this sequence in order, because each week uses the prior week's artifact. Week one: draft the crosswalk table across the Common Rule, FDA rules, and privacy requirements, one row per concept. Week two: memorize and self-test consent elements, then drill review-pathway classification with ten boundary cases you write yourself. Week three: build the classification flow for adverse events, unanticipated problems, deviations, and misconduct, plus the HIPAA-authorization row. Week four: run timed scenario sets and the binder audit below, then repair weak rows in your crosswalk. For current domain outlines, scheduling, and eligibility, consult the issuer's certification pages listed in the sources — keep administrative specifics there rather than in your notes.
Practical exercise — mock regulatory binder audit: assemble or borrow a sample regulatory file (a teaching mock, not live records) and check for: current and prior IRB-approved consent versions with approval dates; delegation-of-authority documentation matching who signed documents; at least one protocol deviation record with a documented correction and reason; and evidence of privacy authorization or a documented waiver. Expected observations in a realistic mock: at least one version mismatch or missing date you must flag, because learning to find the flaw is the skill. Score yourself: 3 = flaw found and correctly classified with the right reporting route; 2 = flaw found but misclassified; 1 = flaw missed. Repeat weekly until you consistently score 3.
Readiness checks before you sit the exam: reproduce the consent elements from memory; label ten mixed scenarios by framework and review pathway with at least nine correct; classify ten events into adverse event, unanticipated problem, deviation, or non-compliance with at least eight correct; and restate the misconduct definition including its exclusions. Treat these scores as learning milestones, not predictions of any pass or fail outcome. The site's CHRC practice page offers additional scenario drills for the sorting exercises in this plan, and the study-guide library covers related healthcare compliance credentials.
- Week 1 — build the framework crosswalk (Common Rule vs FDA rules vs privacy): one row per concept, differences stated in one sentence each
- Week 2 — consent elements from memory, then ten self-written IRB pathway boundary cases
- Week 3 — event classification flow (adverse event, unanticipated problem, deviation, non-compliance) plus HIPAA authorization versus consent
- Week 4 — timed scenario drills and the mock regulatory binder audit, scored against the 1–3 rubric
- Milestone targets: 9/10 framework-and-pathway labels, 8/10 event classifications, full consent-element recall, misconduct definition with exclusions
References and further reading
Use these references to explore the concepts and check the latest information from the relevant organizations.
