Risk Management & CAPA
Quality risk management as the engine of the PQS, and CAPA that actually prevents.
What a domain score is not
A domain is one of the axes SPEQ’s assessment scores, on SPEQ’s own five-stage progression. It is a labelled synthesis, not the FDA’s Quality Management Maturity rating, and a score here is a self-assessment — nobody but you has rated your organization.
Quality risk management (ICH Q9) is the engine of a modern pharmaceutical quality system, and CAPA is where a problem becomes prevention. A system that logs corrective actions but never verifies effectiveness — and keeps seeing the same deviation — is the textbook signature of a reactive operation. Maturity here is what turns single failures into system-wide immunity.
The mature version of this domain is not more risk assessments; it is risk assessment that changes a decision. At low maturity, risk is scored after the decision is made, in a workshop, to document it. At high maturity the assessment precedes the decision, its assumptions are recorded, and it is revisited when the process it describes changes. On the CAPA side, the shift is from closing actions to demonstrating prevention — and the honest signal is an organisation that has seen an effectiveness check fail and acted on it.
- Ban "human error" as a terminal root cause. It describes the event; the useful question is what made the error available — the procedure, the layout, the workload, the interface.
- Make effectiveness checks falsifiable and give them a window long enough for the failure to recur. A check measured over four weeks on a quarterly failure mode cannot detect anything.
- Separate correction from corrective action in the record. An organisation that logs repairs as corrective actions will show a healthy CAPA system and a static failure rate.
- Look across, not only down: when a cause is confirmed, ask where else it could operate. Extension is what turns one investigation into system-wide immunity.
Repeat rate by root cause is the measure that matters, and it is the one most systems cannot produce because causes are recorded as free text. The second is the age profile of open CAPAs — a system whose oldest items are its most significant has an escalation problem, not a resourcing one. The third is how many effectiveness checks have ever failed: zero is not excellence.
The observable behaviours that place a site at each level — what a practitioner or inspector would actually see — and the concrete move that carries it to the next.
- ·The same problems come back under different names
- ·Fixes are corrections (re-clean, re-train) recorded as if they were corrective actions
- ·No root-cause discipline; "operator error" closes investigations
TO ADVANCE →Stand up a CAPA process that distinguishes correction from corrective/preventive action and requires a root cause.
- ·CAPAs are opened but close on "action implemented"
- ·Root-cause tools are used superficially, stopping at the first plausible answer
- ·A growing backlog of aging open CAPAs
TO ADVANCE →Require an effectiveness check against a predefined criterion before any CAPA closes.
- ·Root causes name system deficiencies and drive systemic actions
- ·CAPAs close only after a verified effectiveness check
- ·Risk-based triage keeps the system focused; minor events are trended, not over-processed
TO ADVANCE →Trend CAPA metrics and feed them to management review so the system is steered by data.
- ·Recurrence, ageing, and effectiveness-pass rate are trended and acted on
- ·Risk assessments are proportionate and drive where attention goes
- ·Cross-event patterns are detected before they become findings
TO ADVANCE →Shift from corrective to predictive — use trends and QRM to prevent events, not just close them.
- ·Preventive actions are taken on trends and near-misses before failure
- ·QRM is embedded in daily decisions with proportionate formality
- ·CAPA volume falls because the system stops creating the problems
- A CAPA with a genuine root cause (a system deficiency, not "human error") and a passed effectiveness check
- Evidence of risk-based triage — why a given event became a CAPA and another did not
- CAPA metrics presented at management review: open count, ageing, recurrence, effectiveness-pass rate
Want the specific artifacts that move your score up? The Comprehensive assessment turns your domain scores into a prioritised, personalised remediation plan.
The observable evidence a practitioner — or an inspector — would expect at each maturity level. Drawn from the assessment questions themselves.
How are quality risks identified and managed across your operations?
Risks identified reactively after events occur
Risk assessments performed for major changes only
Proactive risk assessments using formal ICH Q9 methodology for processes and changes
Site-wide risk register with periodic review; risk metrics reported to quality council
Enterprise risk model with leading indicators and predictive analytics; risk posture continuously optimised and reviewed at board level
How does your CAPA system operate?
CAPAs logged but effectiveness rarely verified
CAPAs have defined owners and due dates; effectiveness check is inconsistent
Formal CAPA process with root cause analysis, implementation verification, and effectiveness check
CAPA system metrics trended and presented at management review; repeat deviations tracked
Self-improving CAPA system: predictive analytics pre-empt recurrence and feed prevention back into design and process controls
- ›CAPA effectiveness checks absent or perfunctory; repeat deviations recur for the same root cause.
- ›Root-cause analysis stops at "operator error" and retraining without addressing the system that allowed it.
- ›Risk assessments performed only for major changes, or scored subjectively without ICH Q9(R1) rigour.
- ›CAPAs and investigations routinely exceed their own defined timelines.
Recent FDA recalls whose reason SPEQ maps to this domain — a SPEQ editorial interpretation of the recall reason, not an official FDA classification.