Risk-based regulation is vague regulation
And vague regulation breeds safetyism
Rules designed to prevent bad behavior can make things even worse. When Medicare penalized hospitals with higher re-admission rates, hospitals gamed the metrics by sending patients home instead of readmitting them, or bringing them in for “observation stays” that didn’t count as readmissions. More famously, landowners have killed endangered species to avoid having their property declared a protected habitat, a practice called “shoot, shovel, and shut up.”
But regulators don’t have to set rules this way. Instead, agencies can establish a general goal – fewer accidents, safer manufacturing processes, patient protection, fraud prevention, etc. – and give firms flexibility on how to achieve it. These regulations sound like a great idea, but they have their own unintended consequences. In my previous post, I wrote about the regulatory cascade: a tendency for vague, firm-based regulations to transform into overregulation at the company level. If you’ve ever worked at an organization dominated by a stifling compliance bureaucracy that enforces legalistic, overbearing documentation requirements, audits, and arcane rules, you’ve seen this problem firsthand.
If you want to learn more about how the regulatory cascade works, read my earlier post. But today, I’m going to focus on a specific type of regulation that was designed to solve this problem but has failed – and perhaps made the problem even worse.
A regulatory mystery
To start, I want to highlight an excellent piece by Ruxandra Teslo, in which she explores how scientists fear being punished by their institutions for speaking out against nonsensical policies and rules. Her story of institutional repression reveals an interesting regulatory mystery.
The mystery starts with a seemingly restrictive FDA regulation. In her piece, Ruxandra shares a policy recommendation she received from an immuno-oncologist about the requirement for formal Good Manufacturing Practice (GMP) standards in academic early-stage trials:
He immediately suggested that in his field of cell therapy, small, bespoke phase I trials are encumbered by onerous requirements for full-GMP standards of each reagent. While such standards make sense for larger, industrial scale trials, they are not necessary for the kind of academic trials that he carries out, as careful testing of the final product has to be done anyway in a bespoke fashion, something that is not feasible when manufacturing at large scale.
The scientist was not the only one to make this suggestion. The proposal echoes a recommendation that Joe Lonsdale’s venture capital firm 8VC made in their white paper, “Make the FDA Great Again,” in which they write: “In the U.S., anyone running a clinical trial must manufacture their product under full Good Manufacturing Practices (GMP) regardless of stage. This adds enormous cost (often $10M+) and more importantly, as much as a year’s delay to early-stage research.”
For small-scale academic studies, full GMP would in fact be overkill - its requirements are designed for large-scale industrial production, and these academic trials are typically one-off affairs in which manufacturing is iteratively adjusted.1 You might wonder why the FDA requires such an elaborate manufacturing setup for an experimental drug in an academic setting. But in fact, they don’t! As Ruxandra points out later in her article, the FDA doesn’t actually require “full GMP” for early phase trials. Instead, the agency has a more “flexible” approach. According to regulation and agency guidance, companies must “consider carefully the hazards and associated risks from the manufacturing environment that might adversely affect the quality of a phase 1 investigational drug.” They don’t need to comply with the full GMP.
So why does the misperception exist? Because in practice, institutions are doing full GMP for phase I drugs anyway! And that brings us to Ruxandra’s real target in her essay: the administrative bureaucracies that are responsible for the continuation of this practice. Not only are they making unreasonable demands of researchers, but they are also stifling dissent:
“Nobody wants to… put their names behind an idea that might have (gasp!) trade-offs, because, usually, it would involve getting their name associated with said idea and risk being further slowed down in their research by whatever admin facility is trying to already squash research under overly burdensome compliance requirements.”
On its surface, this situation seems very odd. Why would so many institutions be overcomplying with FDA regulations and then suppressing critical views? Whose interest does this serve?
Vague regulations breed overcompliance
I’d like to offer a solution to this mystery: the regulations are too vague. When the FDA said that GMP wasn’t required, they didn’t do enough to specify exactly what researchers needed to do instead. One sign that a regulation is vague is that you can’t get people to agree on what it requires.
The vagueness is deliberate. The 2008 guidance is one of a broad swath of policies issued by FDA and other regulatory agencies that invite companies to apply a “risk-based” approach to compliance. In other words, rather than explicitly telling companies what to do, FDA suggests that companies categorize their activities by level of risk and put stricter controls in place for riskier activities. In theory - and from the regulator’s perspective - a risk-based regulation is more flexible than a more prescriptive approach. While companies are expected to put strict controls into place to avoid serious risks (e.g., avoiding cross-contamination), lower-risk activities can proceed with less oversight.
In practice, it’s quite different. Almost inevitably, when risk-based regulations are put in place, the hoped-for flexibility doesn’t materialize. Industry instead takes the maximally risk-averse approach. Worse yet, the regulations create the illusion of flexibility, which makes us more complacent about the real problems they perpetuate.
There are plenty of other examples of risk-based regulation failing to provide its promised flexibility. Take clinical trial data verification. Before 2013, FDA expected drug companies to compare every single data element captured at a clinical trial site against the data they had collected in their own electronic systems to make sure everything was transcribed correctly - a process called 100% source data verification. In 2013, FDA, realizing that 100% source data verification was expensive and wasteful, started to encourage “risk-based monitoring” – companies could focus their verification on the high-risk data collected in the trial. Yet despite repeated FDA urgings, uptake of risk-based monitoring remains limited.
A similar pattern appears in institutional review board (IRB) regulations. IRBs are bodies responsible for overseeing human subjects research at universities and other research sites. When research imposes minimal risk, they are supposed to be exempted from IRB review and oversight. Yet universities frequently route low-risk research through IRBs anyway and make the exemption process far more onerous than the regulations seem to require. In 2018, the rule that governs IRBs was modified to further broaden the scope of activities that are exempt from IRB review, but overcompliance persists.
Despite its failures, risk-based regulation remains popular. The latest example is the new guidelines that govern global clinical trials, called the Good Clinical Practice (GCP) guidelines. For years, clinical trial experts have recognized that trials are excessively inefficient and procedure-laden. To combat that, the latest version of GCP (ICH E6(R3)), released this year, embraces “flexible, risk-based approaches” to clinical trial conduct. The new GCP is similar to the old version, but the text has been amended throughout to include the words “proportionate” and “risk-based”. Given how long clinical research takes, it will be many years before we are able to see whether the changes to the guideline have any impact, but I’ll venture a guess now: the odds that these new guidelines change researcher behavior is nearly zero. I fear that as we wait in vain for the promised flexibility of the new guidelines to take effect, we will lose valuable time that could be spent finding a better approach.
How to stop safety culture from becoming safetyism
What can we do about this? In her article, Ruxandra asked a former FDA staffer why its rules were “implemented in the most maximalist and safetyist possible way by local compliance shrugging within the agency; most FDA staff struggle to understand why its rules are so often met with “over-compliance” and they genuinely want companies to be less rule-bound and more innovative. So, in the interest of doing more than just shrugging, I’d like to offer up a couple of suggestions.
First, I agree with Ruxandra that we need culture change, which means empowering brave people to speak out against corporate and institutional practices that don’t make any sense. But I’d like to add one more point. To fix our institutions, we need to understand how they got so repressive in the first place. I would argue that the culture of repression that Ruxandra describes is an unintended result of the vague and expansive safety regulations.
Safety regulation is deliberately designed to impart a “safety culture” in regulated industry. Safety culture is not the same as “safetyism” and is not necessarily a bad thing. I want my drug manufacturers and airlines to have strong safety cultures! But as a first order consequence, the regulations create an incentive to minimize dissent from established safety practices in your company or institution – after all, the presence of dissent from your safety practices is prima facie evidence that you do not have a safety culture. Moreover, the presence of dissenting views, no matter how reasonable, may undermine the safety culture you’re trying to put in place. When FDA put its safety regulations in place, I doubt they intended to suppress reasonable discussions of tradeoffs or objections to safety clutter, but in practice, suppression is a common response to a desire to establish a safety culture.
Unfortunately, the situation gets worse over time. For safety culture to really work, it needs to be more than just skin deep. It’s hard to implement any kind of effective regulatory compliance regime in your organization unless you can convince your employees that they should actually believe in the principles behind the regulation. In practice, that creates a self-reinforcing cultural ratchet. An internal rule that requires “zero tolerance” for safety lapses is going to produce corporate cultures that themselves have zero tolerance for safety lapses. And these cultures are not just enforced from the top-down, but by the rank-and-file. If you are someone who tolerates or even likes taking risks, you probably won’t look for a job at a company that has “zero tolerance” for risk, so the company winds up staffed with those who are personally risk-averse. Eventually, expressing doubts about the existing culture and practices is going to get you ostracized or worse. Safety culture devolves into safetyism.
It’s clear that the policies themselves are not entirely to blame for these problems. In the case Ruxandra highlighted, the vague GMP served as the catalyst, and then university compliance officers made things needlessly worse. But the policies play an important role and we should try to reform them. When you have vague policies, it is hard to stop them from producing overcompliance, and overcompliance is what transforms a reasonable safety culture into safetyism: the accretion of procedure and safety clutter that does not serve the purpose of safety. Recently, I made some broad recommendations for how we can craft regulations that don’t breed overcompliance: more safe harbors, clearer bright-line rules, and a greater investment in smart bureaucrats who can craft sensible, proportional regulations. But I’ll also suggest another, more immediate step: agencies need to stop issuing vague “risk-based” regulations that promise flexibility and don’t deliver. It’s time to admit that this approach is not working.
I’ll make one final recommendation: Regulators are not going to be able to come up with new, better approaches until they better understand how regulations are interpreted and applied on the ground. While FDA faces no shortage of public criticism from academics and social media, it is very difficult for FDA to get frank feedback from the pharmaceutical industry on how its regulations are being interpreted and applied (yet another example of the repression that Ruxandra talked about). Regular FDA employees genuinely want to understand what is happening in industry, as does the new FDA and HHS political leadership, and we should find ways to help them. For their part, FDA ought to invest in real on-the-ground data collection from industry, whether through surveys, interviews, anonymous tip boxes2, or perhaps by analyzing the data they already get from drug companies. They should evaluate their guidance to industry and make sure it is useful and specific. Above all, I hope all regulators and scientific institutions alike come to understand that regulatory burden is as much a product of what the regulations don’t say as what they do say.
This post was written as part of the Roots of Progress Fellowship. Special thanks to Mike Riggs and Deric Tilson for their comments and feedback.
To be fair, there are many cases in which doing “full GMP” for a phase I investigational drug makes good business and scientific sense. If you are planning to commercialize your product and aren’t following GMP from the start, it makes preparing your manufacturing process for future trial phases more difficult.
This could be part of an FDA “safety clutter” campaign, in which the FDA highlights examples of needlessly burdensome safety-related practices that don’t actually contribute to safety. As part of the campaign they could invite university and industry staff to anonymously share examples of safety clutter in their organizations. Then FDA could potentially revise their guidance to industry to explicitly recommend against activities that contribute to safety clutter.



I wonder if its the policy or the enforcement mechanism that is the problem here: lawsuits in the US can be so costly and the cost of non compliance so high that following any and all regulations becomes an existential issue for companies. In addition, mechanisms where you have a single entity determining whether something is allowed or not, also tends to have people overprepare, as the cost of getting it wrong is so high. Are there ways we can defang the enforcement mechanism such that it’s not nearly as harsh to get it wrong?