[ ENTERPRISE PILLAR 01 ]

Governance, Quality Management & Compliance

Keep accountability, decisions, changes, records, and improvement inside a demonstrable state of control.

What this pillar does not claim

This is the enterprise governance system. Its E24 quality capabilities remain canonical functions and are referenced rather than recreated here.

The capability framing below, its failure modes and the boundary with neighbouring pillars are SPEQ’s practitioner reading — not a regulatory requirement, and not an assessment of any organization.

THE CAPABILITY

What this capability is

Every other pillar produces something an organization can point at — a characterized process, a qualified utility, a released lot, a dispatched dossier. This one produces the conditions under which those things can be relied on, and the record that lets a stranger reconstruct how each was settled. That is why it reads as abstract right up until it is missing. Its material is not procedures; it is decision rights — the standing question of who may say yes to what, on whose evidence, and what happens when the answer is contested. The document hierarchy, the investigation, the audit and the review forum are instruments for holding that question open and answerable over time rather than ends in themselves. Read that way, a management review and a single departure record are the same capability at two altitudes: one asks whether one departure was understood, the other asks whether the organization is still able to understand its departures at all.

Why it is hard

This capability is judged almost entirely by artifacts it produces about itself. A departure record is simultaneously the work and the evidence of the work, so the measurement is endogenous: the cheapest route to a better indicator is to change what gets written rather than what gets done, and that shift is nearly invisible from inside, because each individual record remains defensible. Its raw material makes the problem worse. A laboratory receives its samples whether or not anyone likes the analyst; this function receives cases only when somebody chooses to open one. Disclosure is discretionary, so input volume is a lagging function of how the last person who disclosed something was treated — and a quarter in which fewer problems were raised looks identical, in every chart, to a quarter in which fewer problems happened. The third difficulty is positional. The function carries authority over work it does not perform and often could not perform, judging calls made by people who understand the subject better than it does. Defer, and it becomes a stamp that adds latency and no scrutiny; overrule, and it becomes an obstacle that operations learn to route around informally. The right posture moves case by case and cannot be written into a procedure, which is why fluency in every constituent process still leaves the hardest part of the job undelegated.

How it fails

Each of these happens with the individual branches below being run competently. That is what makes them capability failures rather than performance problems.

Everything closes on time and nothing changes

Closure rates are strong, investigations are timely, effectiveness checks are signed, and the three most common problem statements this year are the three from three years ago. No single record is wrong, which is exactly why nobody is accountable: the failure exists only in the aggregate, and the aggregate is reviewed by a forum reading trend charts built from those same records. The reliable tell is a repeat finding whose previous corrective action was itself closed as effective.

Investigation depth follows the outcome, not the signal

The same departure earns a paragraph when the lot passed and a full causal analysis when it did not. Across a year this biases the record population toward consequences rather than mechanisms, so the organization accumulates detailed knowledge of its bad luck and almost none of the near misses that share a cause with it. Nothing in the procedure permits this. The triage question is simply being asked after the result is already known.

The quality system hardens into a permission queue

Every route into the function is a request for approval, so throughput becomes the measure of its value and its backlog becomes a constraint on operations. Work then organizes itself around the queue: pre-alignment conversations that leave no record, proposals shaped to need the fewest signatures, and classifications argued downward at the edge of a shift because the honest one costs a week nobody has.

A quiet reporting climate is read as a healthy one

Escalation counts fall and the fall is presented as improvement. Silence and safety have the same shape in a metric, and the only instruments that can separate them — how the last raised concern was handled, and whether anyone ended up worse off for raising it — are not the ones on the dashboard. The organization reduces its own visibility and books the reduction as progress.

WHERE THIS STOPS

Ours or theirs

This pillar owns the rules of decision and the durability of the record; it does not own the decisions those rules govern. A process owner decides what to do about a departure in their area, and a function that drafts the conclusion on their behalf has quietly taken over the judgement it exists to test. Nor is it assurance of a technical claim: whether a system, method or process is fit for its declared use belongs to the assurance pillar, and whether a promise made to an authority has been honoured belongs to regulatory. The seam that generates the most argument is ownership of an investigation. Quality wants the area that ran the process to investigate, because they understand it; the area wants quality to write it, because quality understands the form a later reader expects — and the document that results was drafted, in each half, by whoever knew that half least well. The second is the four-o-clock-on-Friday question of whether a departure is a departure at all. That classification is made at the end of a shift by the person with the least time and the most to lose from the honest answer, and no sentence in a policy has ever settled it.

Questions practitioners ask

Is the quality system the same thing as the quality unit?

No, and conflating them is the most common structural error in this pillar. The quality system is how the whole organization makes and records controlled decisions; the quality unit is one function inside it holding specific reserved authorities. When the two are treated as identical, every process owner is quietly relieved of ownership of their own controls, and the unit carries responsibility for work it cannot see.

What makes a corrective action effective rather than merely closed?

Closure asks whether the planned action was completed. Effectiveness asks whether the mechanism that produced the problem can still produce it. Answering the second requires naming that mechanism explicitly during the investigation, deciding in advance what observation would show it has changed, and then looking for that observation after enough operating time has passed for the problem to have had a fair chance to return.

Who owns a risk that sits between two functions?

Somebody has to, by name, or it is owned by the calendar. The convention that works is that the function able to act on the risk owns it while the function that would bear the consequence reviews it, with the pairing written down rather than assumed. Risks handed to a joint forum without a named owner are reliably the ones that survive several reviews unchanged.

How much of this capability can an electronic quality platform carry?

It can carry the workflow, the record and the timing, which is most of the mechanical burden and none of the judgement. Routing, locking and time-stamping make a record defensible; they cannot tell whether the investigation asked the right question or whether the classification was honest. A well configured platform makes a weak quality system faster, not stronger, and the speed is often mistaken for the strength.

CAPABILITY BRANCH MAP

What this pillar contains

01

Management accountability & governance

The named allocation of decision rights: who may approve, who must be consulted, who can stop work, and where a disagreement goes when two functions cannot resolve it. It is expressed in delegations, forum terms of reference, and escalation paths rather than in an org chart.

Regulators hold an organisation to decisions, not intentions. When a batch is released or a study is closed, someone with defined authority made that call against defined criteria — and the absence of that clarity is why "everyone assumed someone else had checked" appears in so many investigations.

HOW IT FAILS

  • Release or approval authority sits with a role under schedule pressure, so the independence that protects the decision is structural on paper only.
  • Escalation has no defined trigger, so issues rise only when someone feels strongly enough, and quiet problems never reach a forum.
  • Delegations are stale: the named approver has changed role, and signatures continue under an authority that no longer exists.

WHAT CONTAINS IT

  • Documented decision rights with named accountable roles, refreshed when the organisation changes.
  • Defined escalation triggers and timeframes, so raising an issue is a rule rather than an act of courage.
  • Quality authority that reports independently of the function whose output it judges.

EVIDENCE IT OPERATES

  • Current delegation of authority, with effective dates traceable to role changes.
  • Governance forum minutes showing decisions, dissent and follow-through.
  • Escalated issues with the trigger that raised them and the decision that closed them.
02

Quality-system architecture

The process model itself: which processes exist, who owns each, how they interface, and how the policy, procedure and record layers relate. It is the map that makes every other branch findable.

A quality system that exists only as a folder of procedures cannot be assessed, improved or handed over. Architecture is what lets an organisation answer "what happens when X changes" without convening the people who happen to remember.

HOW IT FAILS

  • Procedures accumulate faster than the model they belong to, so two documents govern the same activity differently and both are current.
  • Process interfaces are unowned: each function operates correctly and the handoff between them belongs to nobody.
  • The documented system describes an operating model the organisation abandoned, so real work runs on undocumented workarounds.

WHAT CONTAINS IT

  • A maintained process model with a single named owner per process and explicit interfaces.
  • A policy hierarchy that resolves conflicts by precedence rather than by document date.
  • Periodic reconciliation of documented process against observed practice.

EVIDENCE IT OPERATES

  • Process map with owners, interfaces and revision history.
  • Document hierarchy showing precedence and controlled cross-references.
  • Internal audit findings on process-to-practice alignment.
03

Quality & enterprise risk management

Identifying what could go wrong, judging how much it matters, deciding what to do about it, and revisiting that judgement as the operation changes — at product, process and enterprise level.

Risk is the mechanism that decides how much rigour each activity deserves. Without it, an organisation either validates everything to the same depth and runs out of capacity, or picks depth by habit and under-controls the thing that actually harms a patient.

HOW IT FAILS

  • Risk assessments are performed to satisfy a procedure and never revisited, so the register describes the operation as it was at assessment time.
  • Scores are tuned until the result matches the decision already taken, which makes the assessment a record of preference rather than analysis.
  • Accepted risks have no owner and no review date, so acceptance quietly becomes permanent.

WHAT CONTAINS IT

  • A defined risk process with consistent criteria, so two teams assessing the same hazard reach comparable conclusions.
  • Risk acceptance recorded with a named owner, a rationale and a review trigger.
  • Re-assessment tied to change, deviation and periodic review rather than to a calendar alone.

EVIDENCE IT OPERATES

  • Risk assessments with method, participants, rationale and residual risk.
  • Risk register showing ownership, acceptance decisions and review dates.
  • Evidence that a change or deviation triggered re-assessment.
04

Document & record governance

Control over the instructions people work to and the records they generate: issue, revision, approval, retention, retrieval, archival and eventual disposal, across paper and electronic systems.

The record is the only thing that survives the people. When an investigation reopens a decision made four years ago, the organisation can either produce the contemporaneous record or it cannot — and "we always did it correctly" is not an assertion a regulator can accept.

HOW IT FAILS

  • Superseded versions stay in circulation at the point of use, so the controlled copy and the working copy diverge.
  • Records are retrievable in principle and not in practice: the retention period is met, the retrieval time is not.
  • Hybrid paper-and-electronic processes leave the authoritative record ambiguous, so two versions of the truth are both defensible.

WHAT CONTAINS IT

  • Controlled issue and withdrawal at the point of use, not only in the document system.
  • Defined retention, archival and disposal rules with retrieval tested rather than assumed.
  • An explicit statement of which record is authoritative wherever a process spans media.

EVIDENCE IT OPERATES

  • Document control records showing issue, revision, approval and withdrawal.
  • A demonstrated retrieval of an archived record within its stated timeframe.
  • Audit-trail review records for electronic systems holding regulated records.
05

Change, deviation, investigation & CAPA

The three coupled loops that keep an operation in control: change assessed before it happens, departures investigated when they do, and corrective action verified to have worked.

This is where a quality system is judged most often, because it is where the organisation demonstrates that it notices problems, understands them, and does something that lasts. Repeat findings are read as evidence that the loop is decorative.

HOW IT FAILS

  • Investigations stop at the first plausible cause, so the corrective action addresses a symptom and the deviation recurs.
  • "Human error" closes an investigation, which names the person who was present rather than the condition that made the error likely.
  • Effectiveness checks are scheduled and then closed on the absence of recurrence within a window too short to mean anything.
  • Changes are classified low-impact to avoid the assessment burden, so the assessment depth reflects workload rather than risk.

WHAT CONTAINS IT

  • Investigation depth scaled to risk, with a method that can reach beyond the immediate cause.
  • Change classification criteria applied by someone other than the change requester.
  • Effectiveness verification with a defined measure and a window justified by the failure rate.

EVIDENCE IT OPERATES

  • Investigations showing scope, causal reasoning, impact on product and other batches, and CAPA linkage.
  • Change records with impact assessment, approvals, implementation and closure verification.
  • Recurrence trending that would expose an ineffective corrective action.
06

Audit, inspection & assurance

Planned internal audit, supplier and external audit, and readiness for unannounced regulatory inspection — including how observations are answered and how commitments made to an authority are tracked to closure.

Audit is the organisation looking at itself before someone with enforcement power does. An audit programme that never finds anything significant is not evidence of control; it is evidence that the programme is not looking where the risk is.

HOW IT FAILS

  • Audit scope avoids the areas known to be weak, so the programme reports comfort it has not tested.
  • Responses to observations commit to actions with no capacity behind them, and the commitment quietly lapses.
  • Inspection readiness is a project run before an expected visit rather than a property of the operation.

WHAT CONTAINS IT

  • Risk-based audit planning with coverage tracked across the whole system over a defined cycle.
  • Auditor independence and demonstrated competence for the area audited.
  • A commitment register tracking every undertaking made to an authority through to verified closure.

EVIDENCE IT OPERATES

  • Audit schedule, reports, findings and closure records across a full cycle.
  • Regulatory correspondence with responses and the evidence of completion behind each.
  • Commitment tracking showing what was promised, to whom, and when it closed.
07

Quality metrics & management review

The indicators leadership uses to see whether the quality system is working, and the forum where those indicators produce decisions — including resource, capacity and improvement decisions.

Management review is the designed feedback loop of a quality system. Where it functions, systemic signals reach the people who control resources; where it does not, the same deviation recurs across three sites and nobody is positioned to notice.

HOW IT FAILS

  • Metrics measure activity rather than outcome — investigations closed on time, rather than whether they were closed correctly.
  • Review produces a presentation and no decision record, so nothing is traceable to it afterwards.
  • Leading indicators are absent, so the system reports harm after it has occurred and never before.

WHAT CONTAINS IT

  • A defined indicator set covering outcome and leading signals, with thresholds agreed in advance.
  • Management review at a defined frequency with a documented decision and owner for each action.
  • Aggregation across sites and products so a systemic signal is visible above local noise.

EVIDENCE IT OPERATES

  • Management review inputs, minutes, decisions and action follow-through.
  • Trended quality indicators with thresholds and the response when one was breached.
  • Evidence that a review decision changed resourcing, priority or process.
08

Quality culture & speak-up systems

The observable conditions that determine whether problems surface early: whether stopping the line is genuinely available, how the organisation responds to the person who reports, and whether reporting is followed by action.

Every control in this pillar depends on someone raising something. Where reporting carries personal cost, the quality system receives a filtered view of its own operation, and the filtering is invisible from inside it.

HOW IT FAILS

  • Stop-work authority exists in a procedure and has never been exercised, which is a measurement, not a reassurance.
  • Investigations name individuals as root cause, teaching the organisation that reporting is personally risky.
  • Speak-up channels collect reports that produce no visible outcome, so use decays to zero and is read as absence of problems.

WHAT CONTAINS IT

  • A just-culture framework distinguishing error, at-risk behaviour and reckless conduct, applied consistently.
  • Feedback to the reporter as a defined step, so raising an issue has a visible consequence.
  • Behavioural rather than sentiment measures — how problems surfaced, not how safe people say they feel.

EVIDENCE IT OPERATES

  • Records of stop-work or hold decisions and how they were handled.
  • Investigations demonstrating causal reasoning that goes past the individual.
  • Reporting-channel volume and outcome trends over time.
09

Knowledge management & improvement

Capturing what the organisation has learned — from development, deviations, transfers and inspections — so it is reusable by people who were not there, and converting it into standard practice.

Regulated organisations lose knowledge faster than they lose documents. When the person who understood why a parameter was set leaves, the rationale becomes folklore, and the next team either cannot change it safely or changes it without understanding what it protected.

HOW IT FAILS

  • Rationale lives in the heads of long-tenured staff and in unversioned files, so a departure removes it.
  • Lessons from one site or product never reach the others, and the same failure is investigated three times.
  • Improvement is a parallel programme with its own metrics rather than an output of the quality system.

WHAT CONTAINS IT

  • Decisions captured with their rationale and assumptions, not only their outcome.
  • A defined route for a lesson learned in one area to reach the standard that governs all of them.
  • Improvement fed by deviation, audit, review and complaint data rather than by separate initiative selection.

EVIDENCE IT OPERATES

  • Knowledge packages carrying rationale through transfer and lifecycle change.
  • Records of a lesson from one product or site changing a shared procedure.
  • Improvement actions traceable to a quality-system input.

Why it matters in regulated work

  • Turns external obligations into an owned management system.
  • Provides independent oversight without transferring process ownership.
  • Connects deviations, change, CAPA, audit, metrics, and management review.

Principal failure modes

  • Fragmented accountability and local workarounds
  • Recurring failures without effective correction
  • Records that cannot support release or inspection decisions

Control objectives

  • Define authority and escalation
  • Control documents, records, change, and investigation
  • Measure effectiveness and govern improvement

Evidence families

  • Quality manual and governance records
  • Deviation, CAPA, change, and audit records
  • Management-review decisions and effectiveness evidence

CONNECTED OPERATING MODEL

Where this capability connects

Lifecycle reach

  • Research & Discovery
  • Nonclinical Development
  • Clinical Development
  • Regulatory Submission & Approval
  • Technology Transfer
  • Process Development & Characterisation
  • Commissioning & Qualification
  • Validation
  • Commercial Manufacturing
  • Laboratory Control
  • Packaging & Serialisation
  • Storage & Distribution
  • Pharmacovigilance
  • Post-Market Surveillance
  • Discontinuation & Record Retention

Quality capabilities

  • Document & Record Control
  • Change Control
  • Deviation & Investigation Management
  • CAPA
  • Quality Risk Management
  • Audit & Inspection Management
  • Management Review
  • Quality Metrics
  • Knowledge Management
  • Quality Culture

System classes

  • eQMS
  • RIM
  • ERP & Warehouse Management

Roles to start with

  • Quality Assurance Associate
  • Internal Auditor (Quality Systems)
  • Supplier Quality Associate

MATURITY ORIENTATION · SPEQ SYNTHESIS

What stronger operation looks like

  1. 01ReactiveOwnership and evidence are reconstructed after events; controls depend on individuals.
  2. 02DefinedScope, roles, methods, records, and escalation are documented for routine use.
  3. 03ControlledCritical controls are risk-based, verified, monitored, and governed through change.
  4. 04PredictiveLeading signals connect performance, drift, capacity, risk, and intervention.
  5. 05AdaptiveLearning improves the operating model without weakening accountability or evidence.

HIGH-VALUE INTERSECTIONS

SOURCE BASIS

REGULATORY BASIS

What governs this capability

The 11 standards SPEQ maps to this pillar, and the 5 regulatory bodies behind them. Which standards belong to a pillar is a SPEQ judgement; the bodies, disciplines and industries below are read from the standards themselves.

Also reached through the systems this pillar runs on

These 10 standards govern the system classes this pillar depends on rather than the pillar itself. The distinction matters: a standard that governs a system is not thereby a standard of every capability that uses it.

21 CFR Part 11EU GMP Annex 11ISPE GAMP 5 (2022)MHRA GxP DI (2018)ICH Q12EU GMP Annex 162013/C 343/01WHO TRS 957, Annex 5MHRA GDPDSCSA (FD&C Act §§581–585)

PROFESSIONAL · READINESS ORIENTATION

Turn the pillar into a bounded operating conversation.

Rate observable operation from 0 (not established) to 4 (adaptive). The protected output prioritizes operating dimensions and evidence—not a compliance score.