· QUALITY CAPABILITY

Quality Risk Management

GMPQMS

Quality risk management is the organisation's ability to make decisions about product quality on a systematic, science-based assessment of risk to the patient — and to keep those assessments alive as knowledge accumulates. ICH Q9(R1) defines the process — risk identification, analysis, evaluation, control, communication, and review — and its revision sharpened precisely the parts organisations do worst: managing the subjectivity of assessors, choosing the level of formality a decision actually needs, and recognising product availability itself as a dimension of risk to patients. For medical devices, ISO 14971 runs the parallel discipline across the device lifecycle, with harm and severity analysed to the patient rather than to the process.

All 16 capabilities →

What this page does not claim

A capability is something an organization must be able to do; it is not a maturity score and not an assessment domain. The scored domains measure how consistently capabilities are performed, they do not map one-to-one, and nothing on this page rates your organization.

What this capability is

Quality risk management is the organisation's ability to make decisions about product quality on a systematic, science-based assessment of risk to the patient — and to keep those assessments alive as knowledge accumulates. ICH Q9(R1) defines the process — risk identification, analysis, evaluation, control, communication, and review — and its revision sharpened precisely the parts organisations do worst: managing the subjectivity of assessors, choosing the level of formality a decision actually needs, and recognising product availability itself as a dimension of risk to patients. For medical devices, ISO 14971 runs the parallel discipline across the device lifecycle, with harm and severity analysed to the patient rather than to the process.

The capability is not the ability to produce risk assessments; it is the ability to make risk-based decisions. That distinction is where most organisations sit on the wrong side of the line: risk tools deployed after the decision to justify it, scoring scales tuned until the answer is acceptable, and hundred-line FMEAs in which every risk is medium. A working QRM capability shows up as differentiated effort — validation deeper where risk is higher, sampling heavier where knowledge is thinner, review more frequent where the assessment is older — and as living documents that change when a deviation proves an assumption wrong.

WHY IT MATTERS

  • QRM is the allocation mechanism for every other capability. Validation depth, supplier oversight intensity, monitoring frequency, and investigation rigour are all supposed to be risk-proportionate — which is only possible if the risk assessment underneath them is honest.
  • The Q9 revision exists because the first two decades of QRM produced ritual: assessments justifying decisions already made, and formality applied uniformly instead of proportionately. Regulators now look for evidence of risk-based decision-making, not for the existence of risk documents.
  • Subjectivity is the silent failure mode. Two teams scoring the same risk differently is normal; not knowing that, and not managing it with better data, anchored scales, and structured challenge, is how a risk register becomes a record of optimism.
  • Q9(R1) names risk to product availability as a dimension of patient harm — a shortage caused by an over-cautious or mishandled quality decision harms the patients who never receive the medicine, and the capability must weigh both sides of that ledger.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 25 LINKS

Quality risk management is the framework's allocation mechanism: it sets how deep validation goes, how hard suppliers are watched, and how much formality a decision needs — risk to the patient directing effort across every phase and system.

06 · QUALITY MATURITY — QUALITY RISK MANAGEMENT, REACTIVE TO ADAPTIVE

L1
Reactive

Risk assessments exist where an auditor or a template demanded them, written after the decision they nominally support. Scales are improvised, everything scores medium, and no assessment has ever changed because a deviation proved one of its assumptions wrong.

L2
Defined

A QRM procedure defines tools and when to use them, and assessments precede major decisions. Formality is uniform rather than proportionate — small decisions over-documented, large ones under-analysed — and review of existing assessments happens on paper anniversaries rather than on evidence.

L3
Controlled

Formality is chosen deliberately per decision; assessors are trained, scales are anchored to defined harm, and subjectivity is managed through diverse teams and data. Assessments demonstrably drive differentiated effort, and deviations and changes trigger review of the assessments they touch.

L4
Predictive

Risk knowledge is integrated: assessments draw on a living model of the product and process rather than starting blank, monitoring data updates likelihood estimates, and the organisation can point to decisions it changed because the risk picture changed — in both directions, tightening and relaxing.

L5
Adaptive

Risk thinking is how the organisation reasons, not a step it performs: new knowledge propagates to every assessment that depends on it, formality flexes fluently from a documented judgement to a full formal study, and quality, compliance, and availability risk are weighed in one frame rather than competing ones.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 5

Derived from the 5 standards SPEQ maps to this subject, across 3 regulatory bodies: FDA, ICH, ISO.

RECORDS & OBJECTIVE EVIDENCE

  • A QRM procedure defining tools and the formality each decision class needs
  • Risk assessments dated before the decisions they support
  • Scoring scales anchored to defined harm, with assessor training records
  • Risk reviews triggered by deviations and changes that touch assumptions
  • Risk-control implementation and residual-risk acceptance records

COMMON INSPECTION FINDINGS

  • Risk assessments written after the decision, to justify it
  • FMEAs where every risk scores medium — scales that discriminate nothing
  • Assessments never revised when deviations disprove their assumptions
  • Uniform formality: small decisions over-documented, large ones under-analysed
  • Risk controls declared without evidence they were implemented
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

HOW YOU’D SEE WHERE YOU SIT

  • The date order of decision and assessment: pull a significant change and check whether the risk assessment preceded and shaped it, or was written afterwards to file behind it.
  • Whether any risk assessment has been revised in the last year because a deviation or new data contradicted it — a register that only ever grows is not being used.
  • The distribution of scores in the FMEAs: a wall of mediums means the scales are not discriminating and the tool is not deciding anything.
  • Ask what the organisation does differently because of a named assessment — where validation went deeper, where monitoring was reduced — and whether anyone can point to the link.
  • How disagreement between assessors is handled: surfaced and resolved with data, or averaged away.

Observable behaviours, not a self-rating — what a capability looks like from the outside, the same way SPEQ’s Quality Culture assessment reads behaviour rather than felt safety.

FREQUENTLY ASKED

What did the ICH Q9(R1) revision change?

Not the process — identification, analysis, evaluation, control, communication, review all stand. The revision deepened four areas where practice had gone wrong. Subjectivity: risk scoring is judgement, and the guideline now expects it to be acknowledged and actively managed. Formality: a spectrum to be chosen deliberately per decision, not a fixed ceremony — high formality where uncertainty and impact are high, less where they are not. Risk-based decision-making: assessments should shape decisions, not decorate them. And product availability: a shortage caused by a quality decision is itself a harm to patients, and belongs inside the risk calculus rather than outside it.

Is FMEA required for quality risk management?

No tool is mandated. ICH Q9(R1) offers a toolbox — FMEA among them, alongside hazard analysis, fault trees, risk ranking, and simpler structured approaches — and expects the choice to fit the decision. FMEA suits systems with identifiable failure modes and meaningful detection controls; it suits far less well the broad, knowledge-poor questions organisations often force into it, which is how hundred-line spreadsheets of medium risks get made. For many decisions, a well-documented structured judgement by the right people is both sufficient and more honest than a numerically dressed one. Formality should follow the decision's stakes, not the template cupboard.

How is quality risk management measured in the maturity assessment?

Through the Risk Management & CAPA domain, which scores whether risk assessment demonstrably shapes decisions and effort — not whether risk documents exist. That is the capability-versus-domain distinction in action: the capability is the function, the organisation's ability to reason about and act on risk; the domain is the measurement axis that observes how consistently the function is performed, through scored questions about real behaviour. Read this page to understand what mature QRM looks like across the reactive-to-adaptive ladder, then take the assessment to establish where your organisation actually sits.

MEASURED THROUGH THE MATURITY ASSESSMENT

This capability is about what you must be able to do. How consistently you do it is what the maturity assessment scores — through the domain below.

Contributes to the FDA QMM practice area Advanced Pharmaceutical Quality System (a SPEQ mapping).

Score your quality system →