· QUICK SCAN

Documentation & Change Control

Controlled records and a change process that keeps a validated state validated.

QMM · Advanced Pharmaceutical Quality SystemQMSQuality Management Systems
Assess this domain →

What a domain score is not

A domain is one of the axes SPEQ’s assessment scores, on SPEQ’s own five-stage progression. It is a labelled synthesis, not the FDA’s Quality Management Maturity rating, and a score here is a self-assessment — nobody but you has rated your organization.

WHY IT MATTERS

Records are the evidence a regulated operation ran as intended, and change control is how a validated state survives change. When either fails, an inspector cannot trust anything downstream — which is why uncontrolled documents and unassessed changes are among the most frequently cited GMP deficiencies. This domain is the connective tissue of the whole quality system.

WHAT CHANGES WITH MATURITY

What changes with maturity is not how many documents exist but what a change is allowed to touch before anyone notices. A reactive operation controls documents and reacts to change; a mature one assesses a proposed change against everything downstream of it — validation status, registered details, supplier qualification, training, the equipment’s qualified state — before it is approved, and can show the assessment. The visible tell is direction: in a weak system, changes are recorded after they are implemented and documents are corrected after they are found wrong.

WHERE TO START · 4
  1. Make the change-impact assessment a real question with a real answer. A form that asks "regulatory impact? Y/N" and is always answered N is not an assessment; ask what registered detail, validated state or qualified system this touches, and require the answer to name them.
  2. Close the loop between change and validation. Most uncontrolled drift is a change that was approved correctly and never triggered the revalidation it implied.
  3. Put version control where the work happens, not where the documents are stored. An obsolete copy at the line is a document-control failure regardless of how good the repository is.
  4. Add an effectiveness check to changes, not only to CAPAs — and let it be capable of failing.
HOW YOU WOULD KNOW IT IS WORKING

Watch the lag between a change being decided and being recorded — if records are consistently created after implementation, the system is documenting rather than governing. Watch the proportion of changes whose impact assessment names a downstream object rather than asserting none. And watch how often a document is found wrong at the point of use rather than at review: that ratio says whether control reaches the floor.

THE MATURITY LADDER

The observable behaviours that place a site at each level — what a practitioner or inspector would actually see — and the concrete move that carries it to the next.

1FoundationalDocuments exist but are not controlled; changes happen and are recorded after the fact, if at all.
  • ·Uncontrolled copies and unofficial "working" documents circulate
  • ·Changes are made first and documented later, or not at all
  • ·No single owner can say which version is current

TO ADVANCE →Stand up a document register with version control and a basic change-request form approved before any change is made.

2DefinedSOPs and a change form exist, but execution is inconsistent and impact assessment is thin.
  • ·Controlled SOPs exist but staff still use memory or shortcuts
  • ·Change requests are raised but impact assessment is a checkbox
  • ·Linked updates (training, validation) are missed or lag the change

TO ADVANCE →Make impact assessment substantive — force each change to identify and close its downstream actions before closure.

3ManagedFormal change control with real impact assessment and approval before implementation; documents are reliably current.
  • ·Every change carries a risk-rated impact assessment and pre-approval
  • ·Downstream actions (training, validation, regulatory) are tracked to closure
  • ·The effective version is unambiguous and retrieval is fast

TO ADVANCE →Instrument the system — trend change volume, lead time, and overdue actions so management review acts on data.

4QuantifiedChange and document performance is measured and trended; management review acts on the metrics.
  • ·Change lead time, backlog, and recurrence are trended and reviewed
  • ·Overdue linked actions trigger escalation, not just a reminder
  • ·Effectiveness of significant changes is verified, not assumed

TO ADVANCE →Close the loop — use trends to prevent the next change problem and manage document knowledge across the lifecycle.

5OptimizedChange management is predictive and knowledge-managed; the system prevents documentation failure by design.
  • ·Change data feeds proactive risk decisions, not just reporting
  • ·Knowledge from changes is captured and reused across sites and transfers
  • ·Documentation and change control run as one connected, self-improving system
WHAT AN ASSESSOR WOULD ASK TO SEE
  • A change-control log with impact assessments, approvals dated before implementation, and closure evidence
  • The current, effective version of a named SOP and its revision history
  • Evidence that a recent change drove the linked updates (training, validation, filings) it should have

Want the specific artifacts that move your score up? The Comprehensive assessment turns your domain scores into a prioritised, personalised remediation plan.

WHAT GOOD LOOKS LIKE

The observable evidence a practitioner — or an inspector — would expect at each maturity level. Drawn from the assessment questions themselves.

How are your quality documents controlled and version-managed?

1Foundational

No formal system — printed copies, email distribution

2Defined

Documented SOPs exist but reviews are ad hoc

3Managed

Formal DMS with scheduled review cycles and training records

4Quantified

Validated electronic DMS with metrics, trending, and periodic effectiveness review

5Optimized

Predictive, self-service DMS: automated review scheduling, real-time control metrics, and continuous-improvement feedback across the network

How is change control managed across your site?

1Foundational

Changes tracked informally — no formal review board

2Defined

Change control SOP exists; review is inconsistent

3Managed

Formal change control with cross-functional review and regulatory impact assessment

4Quantified

Integrated change management linked to risk register, CAPA, and regulatory intelligence

5Optimized

Predictive change management: automated risk-based routing, live regulatory-impact intelligence, and network-wide effectiveness benchmarking

COMMON INSPECTION FINDINGS
  • Obsolete or uncontrolled documents in use at the point of work — no effective version control.
  • Changes implemented without a documented impact / risk assessment or a regulatory-impact evaluation.
  • Records not completed contemporaneously; entries missing, backdated, or lacking a second-person review.
  • Change controls closed without an effectiveness check, or with implementation actions left overdue.