· QUICK SCAN

Risk Management & CAPA

Quality risk management as the engine of the PQS, and CAPA that actually prevents.

QMM · Advanced Pharmaceutical Quality SystemQMSQuality Management Systems
Assess this domain →

What a domain score is not

A domain is one of the axes SPEQ’s assessment scores, on SPEQ’s own five-stage progression. It is a labelled synthesis, not the FDA’s Quality Management Maturity rating, and a score here is a self-assessment — nobody but you has rated your organization.

WHY IT MATTERS

Quality risk management (ICH Q9) is the engine of a modern pharmaceutical quality system, and CAPA is where a problem becomes prevention. A system that logs corrective actions but never verifies effectiveness — and keeps seeing the same deviation — is the textbook signature of a reactive operation. Maturity here is what turns single failures into system-wide immunity.

WHAT CHANGES WITH MATURITY

The mature version of this domain is not more risk assessments; it is risk assessment that changes a decision. At low maturity, risk is scored after the decision is made, in a workshop, to document it. At high maturity the assessment precedes the decision, its assumptions are recorded, and it is revisited when the process it describes changes. On the CAPA side, the shift is from closing actions to demonstrating prevention — and the honest signal is an organisation that has seen an effectiveness check fail and acted on it.

WHERE TO START · 4
  1. Ban "human error" as a terminal root cause. It describes the event; the useful question is what made the error available — the procedure, the layout, the workload, the interface.
  2. Make effectiveness checks falsifiable and give them a window long enough for the failure to recur. A check measured over four weeks on a quarterly failure mode cannot detect anything.
  3. Separate correction from corrective action in the record. An organisation that logs repairs as corrective actions will show a healthy CAPA system and a static failure rate.
  4. Look across, not only down: when a cause is confirmed, ask where else it could operate. Extension is what turns one investigation into system-wide immunity.
HOW YOU WOULD KNOW IT IS WORKING

Repeat rate by root cause is the measure that matters, and it is the one most systems cannot produce because causes are recorded as free text. The second is the age profile of open CAPAs — a system whose oldest items are its most significant has an escalation problem, not a resourcing one. The third is how many effectiveness checks have ever failed: zero is not excellence.

THE MATURITY LADDER

The observable behaviours that place a site at each level — what a practitioner or inspector would actually see — and the concrete move that carries it to the next.

1FoundationalProblems are firefought; there is no functioning CAPA system and issues recur.
  • ·The same problems come back under different names
  • ·Fixes are corrections (re-clean, re-train) recorded as if they were corrective actions
  • ·No root-cause discipline; "operator error" closes investigations

TO ADVANCE →Stand up a CAPA process that distinguishes correction from corrective/preventive action and requires a root cause.

2DefinedA CAPA log exists but most entries fix symptoms and close without verification.
  • ·CAPAs are opened but close on "action implemented"
  • ·Root-cause tools are used superficially, stopping at the first plausible answer
  • ·A growing backlog of aging open CAPAs

TO ADVANCE →Require an effectiveness check against a predefined criterion before any CAPA closes.

3ManagedRoot cause is taken seriously, effectiveness checks are real, and risk decides investigation depth (ICH Q9).
  • ·Root causes name system deficiencies and drive systemic actions
  • ·CAPAs close only after a verified effectiveness check
  • ·Risk-based triage keeps the system focused; minor events are trended, not over-processed

TO ADVANCE →Trend CAPA metrics and feed them to management review so the system is steered by data.

4QuantifiedCAPA and risk performance is quantified and reviewed; recurrence and effectiveness are managed numbers.
  • ·Recurrence, ageing, and effectiveness-pass rate are trended and acted on
  • ·Risk assessments are proportionate and drive where attention goes
  • ·Cross-event patterns are detected before they become findings

TO ADVANCE →Shift from corrective to predictive — use trends and QRM to prevent events, not just close them.

5OptimizedThe system is preventive and predictive; risk management is the operating system, not a form.
  • ·Preventive actions are taken on trends and near-misses before failure
  • ·QRM is embedded in daily decisions with proportionate formality
  • ·CAPA volume falls because the system stops creating the problems
WHAT AN ASSESSOR WOULD ASK TO SEE
  • A CAPA with a genuine root cause (a system deficiency, not "human error") and a passed effectiveness check
  • Evidence of risk-based triage — why a given event became a CAPA and another did not
  • CAPA metrics presented at management review: open count, ageing, recurrence, effectiveness-pass rate

Want the specific artifacts that move your score up? The Comprehensive assessment turns your domain scores into a prioritised, personalised remediation plan.

WHAT GOOD LOOKS LIKE

The observable evidence a practitioner — or an inspector — would expect at each maturity level. Drawn from the assessment questions themselves.

How are quality risks identified and managed across your operations?

1Foundational

Risks identified reactively after events occur

2Defined

Risk assessments performed for major changes only

3Managed

Proactive risk assessments using formal ICH Q9 methodology for processes and changes

4Quantified

Site-wide risk register with periodic review; risk metrics reported to quality council

5Optimized

Enterprise risk model with leading indicators and predictive analytics; risk posture continuously optimised and reviewed at board level

How does your CAPA system operate?

1Foundational

CAPAs logged but effectiveness rarely verified

2Defined

CAPAs have defined owners and due dates; effectiveness check is inconsistent

3Managed

Formal CAPA process with root cause analysis, implementation verification, and effectiveness check

4Quantified

CAPA system metrics trended and presented at management review; repeat deviations tracked

5Optimized

Self-improving CAPA system: predictive analytics pre-empt recurrence and feed prevention back into design and process controls

COMMON INSPECTION FINDINGS
  • CAPA effectiveness checks absent or perfunctory; repeat deviations recur for the same root cause.
  • Root-cause analysis stops at "operator error" and retraining without addressing the system that allowed it.
  • Risk assessments performed only for major changes, or scored subjectively without ICH Q9(R1) rigour.
  • CAPAs and investigations routinely exceed their own defined timelines.