← Drug Development Suite Execute · Vitalis Therapeutics Inc.

Clinical Study Report Summary

Download Word
2
CSRs final
3
Not yet started
12w
Lock to final
16
ICH E3 sections
Contents
  1. The Definitive Account, Not a Summary
  2. The Structure
  3. What Exists Today
  4. Where the Numbers Come From
  5. CSRs Are Not the Integrated Summaries
  6. What Makes a CSR Fail Review

1. The Definitive Account, Not a Summary

A clinical study report is the complete account of one trial: what was planned, what was done, what happened, and what the sponsor concludes from it. It is written to ICH E3, it runs to thousands of pages with its appendices, and it is the document a reviewer reads when they want to know what the submission's summaries are based on.

It is notBecause
A summary of the protocolThe protocol says what was intended. The CSR says what occurred, including every deviation from that intention.
A presentation of results⚠ It reports the pre-specified analyses in the pre-specified order, whatever they show. A report that leads with its best finding has stopped being a CSR.
Written after the factIts analyses were fixed in the statistical analysis plan, signed before the database was locked. The CSR executes a plan; it does not design one.
The submissionThe NDA contains the CSRs and also contains new analyses across them — see §5.
The single discipline that makes a CSR trustworthy: it reports what was pre-specified, in the order it was pre-specified, including the parts that did not work.

Every element of that is checkable by a reviewer. The objectives are quoted from the protocol rather than paraphrased. The analysis populations were assigned during blind data review, before anyone was unblinded. The testing hierarchy is followed to the point of first failure, and everything below that point is presented as descriptive rather than as a claim.

A CSR is not persuasive because it argues well. It is persuasive because its structure makes selective reporting visible.

2. The Structure

ICH E3SectionWhat it containsThe part that matters
1-5Title page through ethics and administrative structureSynopsis, ethics committee record, investigators and administrative structureThe synopsis is the most-read part of the entire report and is often written last.
6Investigators and study administrative structureEvery investigator, site and vendor with a role in conductReconciles to the site list and the transfer of obligations.
7-8Introduction and study objectivesRationale and the objectives exactly as the protocol stated them⚠ Objectives are quoted from the protocol, not restated. A CSR that paraphrases its own objectives has begun to drift from what was pre-specified.
9Investigational planDesign, randomization, blinding, treatments, and every protocol amendment with its effectThe amendment sub-section is where a reviewer looks first for changes made after the data started arriving.
10Study participantsDisposition, protocol deviations, and the analysis populations⚠ Populations are assigned during blind data review, BEFORE unblinding. This section is where that sequence is evidenced.
11Efficacy evaluationThe pre-specified analyses in the pre-specified order, following the testing hierarchyTesting stops at the first failure; everything below becomes descriptive.
12Safety evaluationExposure, adverse events, deaths and serious events, laboratory findingsReconciles exactly to the safety database. Two systems, one truth.
13Discussion and overall conclusionsThe sponsor's interpretation, clearly labeled as interpretation⚠ The only section where the sponsor argues rather than reports, and the one a reviewer reads most skeptically.
14Tables, figures and graphs referred to but not in the textThe full TLF packageProduced from the analysis datasets, traceable back through ADaM and SDTM to source.
15Reference listLiterature citedShort, and routinely wrong if left to the end.
16AppendicesProtocol and amendments, sample CRF, IRB list, investigator CVs, randomization scheme, audit certificates, participant data listings⚠ Larger than the report itself. Appendix 16.1 is effectively a second Trial Master File.
Section 13 is the only place in the document where the sponsor argues, and it is labeled as such.

Everything from section 7 to section 12 is reporting: this was the plan, this is what the analysis produced. Section 13 is where the sponsor says what it believes that means — and separating the two is what allows a reviewer to accept the first while disagreeing with the second.

A CSR that threads interpretation through its results sections has made itself harder to accept, not easier, because a reviewer who distrusts one conclusion now has to re-examine every number it was mixed into.

Appendix 16 is larger than the report. It carries the protocol and every amendment, the sample case report form, the investigator list, the randomization scheme, audit certificates and participant data listings — effectively a second Trial Master File, assembled for one study. It is also where a reviewer goes when a number in section 11 does not look right.

3. What Exists Today

Two reports are final. Three do not exist and cannot.

StudyStatus at 15 Oct 2026FinalNote
Phase 1 SAD/MADFinal2024-05Signed by the medical monitor and the statistician.
Phase 2 dose-rangingFinal2026-02The report the End-of-Phase-2 meeting and the Gate 4 case were built on.
Pivotal 301Not startedplanned 2028-08⚠ Cannot begin before database lock. Draft to final is budgeted at 12 weeks.
Pivotal 302Not startedplanned 2028-08As above, produced in parallel.
CV sub-studyNot startedplanned 2028-09Nested in Pivotal 301; reported separately because CR-02 scoped it separately.
No pivotal report can begin before its own database lock, which is 21 months away.

This is not a resourcing choice or a sequencing preference — it is arithmetic. The CSR reports analyses run on a locked database, and a database that is still accruing data has no analyses to report. The fact base asserts it: a report marked final before its lock date fails the build.

The Phase 2 report, by contrast, is final and load-bearing. It is the document the End-of-Phase-2 meeting was built on and the evidence the Gate 4 business case rests on — which is why the 5.1% gastrointestinal discontinuation figure in it has been quoted in nearly every artifact since.

Lock to final CSR is budgeted at 12 weeks, and that is already aggressive for a report of this size. It sits directly on the critical path: database lock July 2028, submission October 2028, and almost nothing between them that can be compressed. The two pivotal reports are produced in parallel by separate teams for exactly that reason.

4. Where the Numbers Come From

Every figure in a CSR is traceable back through four transformations to a mark somebody made on paper at a site.

StageWhat it isWho can re-derive it
SourceThe clinical record at the site — the nurse's note, the scale reading, the laboratory reportThe site, and a monitor comparing source to eCRF
eCRFTranscribed into the electronic case report formData management, through the audit trail
SDTMStandardized study data tabulation model — the raw data in a regulator-defined structure⚠ The reviewer, independently
ADaMAnalysis datasets, one row per analysis-ready observation, with derivations documented⚠ The reviewer, independently
TLFsThe tables, listings and figures in sections 11, 12 and 14Anyone with the ADaM datasets and the SAP
SDTM and ADaM exist so that a reviewer can re-run the sponsor's analysis without the sponsor's help.

That is the entire point of standardized submission data, and it changes what a CSR is for. The report is not the evidence — the datasets are. The report is the sponsor's account of what the datasets show, offered alongside the datasets so that the account can be checked.

Which means the most consequential thing about a CSR is that everything in it can be falsified. A number that cannot be re-derived from the analysis datasets is not a finding; it is an assertion, and it will be treated as one.

The define.xml that accompanies the datasets is not documentation about them — it is how they are read. It carries the derivation for every variable, and without it the datasets are a large amount of data nobody can interpret.

5. CSRs Are Not the Integrated Summaries

DocumentHow manyWhat it actually is
Clinical study reportOne per studyReports what happened in that study, against that study's protocol and SAP.
Integrated Summary of SafetyOne per submission⚠ A NEW ANALYSIS pooling participants across studies. Not a compilation of the CSRs — it re-analyzes pooled data and can surface findings no individual CSR contains.
Integrated Summary of EfficacyOne per submissionAs above, for efficacy. Both are written from the analysis datasets, not from the reports.
Clinical Overview (Module 2.5)One per submissionThe sponsor's argument, ~30 pages. The part of the dossier most likely to be read in full.
The Integrated Summary of Safety is a new analysis, not a compilation of the reports.

It pools participants across every study in the program and re-analyzes them together. That produces things no individual CSR can contain: a rare event appearing three times across three trials, none of which was notable in isolation; an exposure-response relationship visible only at the pooled sample size; a subgroup finding underpowered in every study and adequately powered across all of them.

This is the most common misunderstanding about NDA content, and it has a schedule consequence. Teams that treat the integrated summaries as an assembly task budget days for them. They are original statistical work, they are written from the analysis datasets rather than from the reports, and they take months.

It also explains a sequencing constraint. The integrated summaries cannot be produced before the individual studies' analysis datasets are final — which is after lock, in parallel with the CSRs rather than after them. The submission is not assembled sequentially from finished reports; several of its most demanding components are being written simultaneously from the same datasets.

6. What Makes a CSR Fail Review

Not wrong results — those are a program problem. These are reporting failures, and they are avoidable.

FailureWhat it looks likeWhy it is fatal to credibility
Post hoc analysis presented as pre-specifiedAn analysis that does not appear in the signed SAP, reported in section 11 alongside those that do⚠ The reviewer compares the CSR against the SAP. Anything extra is immediately visible, and it casts doubt on every analysis that was legitimate.
Populations assigned after unblindingAnalysis population definitions dated after the unblinding authorizationTwo dates in the file settle it. The result becomes unfalsifiable, and unfalsifiable is not a synonym for favorable.
Deviations under-reportedSection 10 listing fewer deviations than the monitoring reports in the TMF containReconciliation against Zone 5 is routine. A gap is read as concealment even when it was carelessness.
Safety numbers that do not reconcileSection 12 disagreeing with the safety database⚠ The two are maintained separately by design. A discrepancy means one of them is wrong and the sponsor did not notice.
Conclusions unsupported by the hierarchyA claim in section 13 for an endpoint below the first failure in the testing sequenceTesting stops at first failure. A claim below that point is not a strong claim — it is not a claim.
Every failure on that list is a failure of sequence or of reconciliation, not of science.

Each is detectable by comparing the report against a document that already exists — the SAP, the unblinding record, the monitoring reports, the safety database. None requires the reviewer to re-run a single analysis.

Which is the argument for why the lock sequence and the trial master file are program-management concerns rather than clinical ones. The credibility of a $243 million evidence package rests on a set of dates being in the right order and a set of numbers agreeing with each other, and both of those are things a program manager can actually control.