[ ENTERPRISE PILLAR 14 ]

People, Knowledge & Organizational Capability

Place competent people in clear roles, sustain human performance, and preserve critical knowledge through growth, change, and turnover.

What this pillar does not claim

This pillar concerns the operating organization and its capability; it does not replace HR administration or the learner-facing Navigator taxonomy.

The capability framing below, its failure modes and the boundary with neighbouring pillars are SPEQ’s practitioner reading — not a regulatory requirement, and not an assessment of any organization.

THE CAPABILITY

What this capability is

This is the capability that lets a regulated operation survive the people who built it. In regulated work the organization is itself part of the control strategy: a decision is only valid because a named person with defined authority made it, a procedure is only reproducible because someone can still explain why its limits sit where they do, and an investigation only reaches a cause because somebody in the room had seen the failure before. Read as one thing, the pillar answers three questions that the organization chart cannot — who is authorized to decide what, whether the people holding those authorities can demonstrably do the work rather than having been shown it, and whether the reasoning behind the operation exists anywhere other than inside the heads of the people currently doing it. That is why it is not personnel administration. Employment, pay and performance management are a different obligation with a different owner. What sits here is the part of the workforce question that an inspector, a receiving site or a new owner would have to reconstruct: capability as something demonstrable, and knowledge as an evidence problem rather than a morale one.

Why it is hard

Every artifact this capability produces describes a person at a moment, and everything that matters about the person is a disposition over time. A completion record proves exposure to material on a date; what the operation depends on is judgment applied to the situation the record could not anticipate, and judgment is only observable in the hard cases, which are rare by design. Somebody who has never met an ambiguous result looks identical on paper to somebody who has resolved fifty. The second half of the problem is worse, because the most valuable holdings are the ones with no artifact at all: the rejected alternative, the reason a range was narrowed, the equipment behaviour that is not in any manual. That knowledge is invisible while its holder is present and is discovered missing only years later, when a question arrives that the file cannot answer and the person who could have is gone. And the capability is never achieved, only sustained at a rate, because the population turns over continuously. Every intake resets part of the estate to novice while the documented system reads exactly as it did the month before — the paperwork is stable precisely while the competence behind it churns. Branch competence does not touch any of this. A curriculum that is well designed, delivered and assessed still measures the thing that can be measured.

How it fails

Each of these happens with the individual branches below being run competently. That is what makes them capability failures rather than performance problems.

Completion is recorded where competence was meant to be

The curriculum is assigned, the records are current, and the assessment is a question set the reader can pass by having read carefully. Nothing in the chain asks whether the person can do the task under the conditions the task actually occurs in. The tell is an investigation in which the operator who missed a signal held a complete and in-date record for exactly the procedure that describes it.

One retirement removes a process nobody knew was undocumented

A long-serving person leaves on good terms after a proper handover of everything that was written down. Months later a deviation or a transfer raises a question the file cannot answer, because the rationale was never a deliverable for anyone and the handover covered tasks rather than reasoning. The loss is unbudgeted, undated and attributed to something else entirely by the time its cost lands.

Authority exists on paper and is never exercised

Escalation triggers are defined, stop-work authority is written into the role, and the only evidence that either works would be events that did not happen. When nobody has halted an operation in three years, that reading is ambiguous between an unusually stable process and an organization where raising a concern costs more than absorbing it, and nothing in the record distinguishes the two.

Growth dilutes capability faster than it can be rebuilt

A site doubles its headcount for a launch. The training system scales, because it is a system; mentoring capacity does not, because the experienced people are the ones running the launch. The ratio of supervised to unsupervised work quietly inverts, every individual record stays complete, and the aggregate depth of the operation falls with no measure anywhere that would show it.

WHERE THIS STOPS

Ours or theirs

This capability establishes whether the organization can demonstrate competence and hold knowledge; it does not make the individual decision. Judging that a named person is ready to work unsupervised belongs to the accountable line manager, and a capability function that issues that judgment centrally has taken over an accountability it cannot carry. It stops short of employment administration entirely, and short of the learner-facing curricula SPEQ publishes for practitioners, which are a product rather than an operating obligation. Two seams cause most of the argument. The first is with investigations: when a deviation lands on a person, the question of whether that person could reasonably have succeeded — given the procedure, the interface, the workload and the hour — is owned here, while the disposition of the deviation and its corrective action is governance work, and the failure mode is that retraining gets recorded as the action because it is the one both sides accept. The second is with operations over work design. A task that is error-likely is a design defect, not a competence gap, and the boundary is that this pillar owns the diagnosis while the process owner owns the redesign — which is exactly the split that lets both sides believe the other is holding it.

Questions practitioners ask

What separates training from qualification in a regulated operation?

Training is delivery: the material reached the person. Qualification is a decision by an accountable person that this individual may now perform this task without supervision, and it needs something observed behind it — witnessed execution, a worked case, a demonstration under realistic conditions. An operation that records only the first has evidence of effort and none of capability.

Why is knowledge continuity treated as an evidence problem rather than a culture one?

Because the only workable test is whether an outsider can reconstruct the reasoning. Culture determines whether people are willing to share what they know; evidence determines whether what they shared is retrievable by someone who does not know it exists. A generous, communicative team can still leave nothing behind, and that is the failure this pillar is built to prevent.

Human error keeps appearing as a root cause. Is that a failure of this pillar?

Usually it signals that the investigation stopped one step early. Human error names where the sequence became visible, not why it was available. The useful question is what made the correct action harder than the incorrect one on that shift, and an operation whose investigations end at the person will keep generating retraining actions against a design that has not moved.

How can an organization tell whether its escalation route actually works?

By looking at what travelled it rather than at whether it is documented. A route that carries only formal, unambiguous events is not carrying the weak signals it exists for. Useful indicators are how often a concern was raised and closed as a non-issue, how long the path took, and whether anyone who used it can describe what happened next.

CAPABILITY BRANCH MAP

What this pillar contains

01

Organization design & operating model

How the organisation is arranged to do regulated work: structures, accountability, decision rights, spans of control, the interfaces between functions, governance and whether capacity matches the load.

Structure decides which decisions are easy and which require a meeting. Where quality reports into the function whose output it judges, no amount of procedure restores the independence the arrangement removed.

HOW IT FAILS

  • Quality oversight reports into operations at site level, so independence exists only on the corporate chart.
  • Spans of control widen through headcount reduction until supervision is nominal on the shifts that need it most.
  • Interfaces between functions have no owner, so work that belongs to two departments belongs to neither.

WHAT CONTAINS IT

  • Quality authority with a reporting line independent of the function it judges, at every level it operates.
  • Span of control assessed against supervision actually required, not against budget alone.
  • Named ownership for each cross-functional interface, reviewed when the structure changes.

EVIDENCE IT OPERATES

  • Organisation charts with reporting lines and quality independence visible.
  • Delegation of authority and decision-rights documentation.
  • Interface ownership definitions and their review records.
02

Workforce planning & talent supply

Having the right people available: demand forecasting, role definition, staffing models, recruitment pipelines, critical-skill identification, succession, contractor use and resilience to departure.

Qualification takes months, so staffing gaps cannot be closed at the speed they open. A site running on a qualified population smaller than its schedule assumes is carrying a risk that shows up as deviations rather than as a vacancy report.

HOW IT FAILS

  • Plans count headcount rather than qualified headcount, so an approved establishment full of untrained people reads as fully staffed.
  • Critical single-person dependencies are known informally and never recorded, so departure is a surprise.
  • Contractors perform regulated work under oversight arrangements designed for permanent staff.

WHAT CONTAINS IT

  • Capacity planning based on qualified and currently authorised staff, not on approved positions.
  • Explicit identification of single-person dependencies with deliberate cover-building.
  • Contractor qualification, oversight and access defined for the work they actually perform.

EVIDENCE IT OPERATES

  • Qualified-staffing levels against operational demand.
  • Critical-skill and succession registers with cover status.
  • Contractor qualification and oversight records.
03

Roles, competencies & qualification

What each role must be able to do and how that is established: expectations, knowledge, skill, judgement, formal authorisation, demonstrated performance and periodic requalification.

Qualification is the organisation asserting that a named person may perform a regulated task. Where it rests on training completion alone, the assertion is about attendance rather than capability — a distinction inspectors probe by asking someone to explain what they did.

HOW IT FAILS

  • Qualification is granted on course completion without any demonstration of the task itself.
  • Authorisation lists drift from reality, so people perform tasks they are not currently authorised for.
  • Requalification is a re-read of the procedure rather than a re-demonstration of the skill.

WHAT CONTAINS IT

  • Qualification requiring demonstrated performance for tasks where skill, not knowledge, is the risk.
  • Authorisation records reconciled against who actually performs each task.
  • Requalification proportionate to risk and to how often the task is performed.

EVIDENCE IT OPERATES

  • Role competency definitions with required demonstrations.
  • Individual qualification and authorisation records with dates.
  • Requalification records including demonstration outcomes.
04

Learning, training & effectiveness

How capability is built: curricula and prerequisites, delivery, opportunity to practise, assessment, transfer into the job, effectiveness evaluation and retraining when something goes wrong.

Training is the most common corrective action and one of the least effective, because retraining a person who already knew the procedure addresses nothing. Effectiveness evaluation is what separates a genuine capability gap from a convenient CAPA.

HOW IT FAILS

  • Retraining is assigned as the corrective action for errors whose cause was workload, procedure or system design.
  • Effectiveness is measured by completion and quiz scores rather than by performance in the work.
  • Read-and-understand is used for content that requires practice, so the record exists and the capability does not.

WHAT CONTAINS IT

  • Training rejected as a corrective action unless the investigation established a genuine knowledge gap.
  • Effectiveness measured in the work — error rates, observed performance — not at the end of the course.
  • Delivery method matched to what is being learned, with practice where skill is required.

EVIDENCE IT OPERATES

  • Curricula with prerequisites and delivery method rationale.
  • Training effectiveness evaluations against job performance.
  • Retraining actions with the knowledge-gap evidence that justified them.
05

Human performance & work design

Designing work so people can do it correctly: task and procedure design, interfaces, workload, fatigue, recognition of error-likely situations, defences in depth and learning from what nearly happened.

Human error is an outcome, not a cause. Treating it as a cause ends the investigation exactly where the useful information starts — in the conditions that made the error likely and will make it likely again for the next person.

HOW IT FAILS

  • Procedures are written by people who do not perform the task, so following them exactly is impractical and workarounds become normal.
  • Error-likely conditions — night shift, first run after changeover, time pressure — are visible in the data and never analysed as a set.
  • Near misses are not reported because nothing happened, so the free lesson is lost.

WHAT CONTAINS IT

  • Procedures authored or verified with the people who perform the task, under real conditions.
  • Analysis of when errors occur, not only what they were, so error-likely conditions become visible.
  • Near-miss reporting that is actively valued, with feedback to the reporter.

EVIDENCE IT OPERATES

  • Procedure usability verification records.
  • Error and deviation analysis by condition, shift and task context.
  • Near-miss reports and the work-design changes arising from them.
06

Leadership, culture & psychological safety

The behaviours leaders actually reward: speak-up climate, just culture, stop-work authority, the trust that makes reporting safe, and accountability that distinguishes error from recklessness.

Culture is what determines whether the quality system receives an accurate picture of its own operation. Every control depends on someone raising something, and that decision is made by reading how the last person who did was treated.

HOW IT FAILS

  • Leaders ask for bad news and respond to it with pressure, so the request is discounted within one cycle.
  • Stop-work authority is stated in policy and has never been exercised, which is a measurement rather than a reassurance.
  • Metrics reward low deviation counts, creating an incentive not to record rather than not to deviate.

WHAT CONTAINS IT

  • A just-culture framework applied consistently, distinguishing error, at-risk behaviour and recklessness.
  • Stop-work events tracked and reviewed for how the organisation responded, not only whether it was justified.
  • Metric design reviewed for perverse incentives before a target is set on it.

EVIDENCE IT OPERATES

  • Just-culture framework and examples of its consistent application.
  • Stop-work and hold records with the organisational response.
  • Reporting rates trended alongside deviation rates.
07

Organizational change & adoption

Making an organisational change actually take: stakeholder analysis, impact assessment, readiness, communication, participation, transition support, reinforcement and whether the intended benefit arrived.

A change that is implemented but not adopted produces the worst of both states — the old way is prohibited and the new way is not established, so people improvise in the gap. In regulated work that gap is where undocumented practice appears.

HOW IT FAILS

  • Go-live is treated as completion, so support ends exactly when people start meeting real cases.
  • Impact assessment covers process and systems but not the workload the change adds at the front line.
  • Old and new ways run in parallel indefinitely because withdrawal of the old was never planned.

WHAT CONTAINS IT

  • Support planned to extend well past go-live, sized to the difficulty of the transition.
  • Impact assessment including front-line workload and the procedures people actually follow.
  • A defined and enforced withdrawal point for superseded ways of working.

EVIDENCE IT OPERATES

  • Change impact and readiness assessments including front-line effects.
  • Adoption measures after go-live, not only implementation completion.
  • Withdrawal records for superseded processes and documents.
08

Knowledge capture, transfer & continuity

Keeping what the organisation knows: tacit and explicit knowledge, communities of practice, handovers, lessons learned, resilience to turnover, succession and the ability to retrieve any of it later.

Regulated organisations lose knowledge faster than they lose documents. When the person who understood why a parameter was set leaves, the rationale becomes folklore — and the next team either cannot change it safely or changes it without knowing what it protected.

HOW IT FAILS

  • Handover is a document produced in the leaver’s final week, covering tasks rather than judgement.
  • Lessons learned are captured per project and never reach the standard that would prevent recurrence.
  • Knowledge is retrievable only by asking someone, so retrieval depends on knowing who to ask.

WHAT CONTAINS IT

  • Handover planned across a period long enough to transfer judgement, not only task lists.
  • A defined route from a lesson learned into the procedure or standard it should change.
  • Knowledge stored so it can be found by someone who does not already know it exists.

EVIDENCE IT OPERATES

  • Handover records covering rationale and judgement, not only responsibilities.
  • Lessons-learned entries traceable to the standards they changed.
  • Retrieval demonstrations by people outside the originating team.
09

Cross-functional collaboration & escalation

How functions work across boundaries: interfaces, decision boundaries, escalation triggers, shared situational awareness and the resolution of genuine disagreement.

Most regulated failures cross a functional boundary. The organisation usually has all the information somewhere and has not assembled it in one place — which is a collaboration failure rather than a knowledge failure.

HOW IT FAILS

  • Escalation depends on judgement with no defined trigger, so similar issues escalate or do not depending on who holds them.
  • Disagreement between functions is resolved by seniority rather than by evidence, and the losing view is not recorded.
  • Each function holds part of a picture and no forum exists where the parts are combined before a decision.

WHAT CONTAINS IT

  • Defined escalation triggers and timeframes, so escalation is obligatory rather than brave.
  • A documented route for unresolved technical disagreement, with dissent recorded.
  • Forums that combine cross-functional information before decisions rather than after them.

EVIDENCE IT OPERATES

  • Escalation criteria and records of issues escalated against them.
  • Decision records including dissenting positions and their resolution.
  • Cross-functional review records for decisions spanning boundaries.
10

Early-career development & leadership pipeline

Building the next generation of practitioners: industry orientation, systems literacy, entry pathways, mentoring, deliberate breadth, supervised experience and progression into responsibility.

The sector competes for a limited pool of experienced practitioners and does comparatively little to enlarge it. Early-career design determines whether someone leaves with GxP judgement or only with the ability to follow one site’s procedures.

HOW IT FAILS

  • New entrants are trained on their immediate task with no orientation to why the regulated system exists, so rules read as arbitrary.
  • Mentoring is informal and therefore unevenly distributed, favouring those who already know how to ask.
  • Breadth is never designed, producing specialists who cannot assess impact outside their own area.

WHAT CONTAINS IT

  • Structured orientation covering the purpose of regulated work before task-level training.
  • Mentoring assigned deliberately rather than left to emerge, with expectations of both parties.
  • Planned exposure across functions for roles that will eventually assess cross-functional impact.

EVIDENCE IT OPERATES

  • Onboarding curricula including regulatory-purpose orientation.
  • Mentoring assignments and progression reviews.
  • Development plans showing deliberate breadth and supervised experience.

Why it matters in regulated work

  • Training alone does not establish competence or effective performance.
  • Role clarity and escalation determine whether weak signals reach accountable decision makers.
  • Knowledge continuity protects operations during transfer, succession, and transformation.

Principal failure modes

  • Roles or decision rights are ambiguous
  • Training completion is mistaken for competence
  • Critical knowledge leaves with individuals or vendors

Control objectives

  • Define roles, competencies, authority, and escalation
  • Develop and verify capability in the context of work
  • Capture, transfer, and improve organizational knowledge

Evidence families

  • Organization, role, responsibility, and competency records
  • Learning, qualification, observation, and performance evidence
  • Knowledge maps, succession, handover, and lessons-learned records

CONNECTED OPERATING MODEL

Where this capability connects

Lifecycle reach

  • Research & Discovery
  • Nonclinical Development
  • Clinical Development
  • Regulatory Submission & Approval
  • Technology Transfer
  • Process Development & Characterisation
  • Commissioning & Qualification
  • Validation
  • Commercial Manufacturing
  • Laboratory Control
  • Packaging & Serialisation
  • Storage & Distribution
  • Pharmacovigilance
  • Post-Market Surveillance
  • Discontinuation & Record Retention

Quality capabilities

  • Training & Qualification
  • Knowledge Management
  • Quality Culture
  • Management Review
  • Document & Record Control
  • Quality Metrics

System classes

  • eQMS
  • ERP & Warehouse Management

Roles to start with

  • Quality Assurance Associate
  • Manufacturing Operator
  • Internal Auditor (Quality Systems)

MATURITY ORIENTATION · SPEQ SYNTHESIS

What stronger operation looks like

  1. 01ReactiveOwnership and evidence are reconstructed after events; controls depend on individuals.
  2. 02DefinedScope, roles, methods, records, and escalation are documented for routine use.
  3. 03ControlledCritical controls are risk-based, verified, monitored, and governed through change.
  4. 04PredictiveLeading signals connect performance, drift, capacity, risk, and intervention.
  5. 05AdaptiveLearning improves the operating model without weakening accountability or evidence.

HIGH-VALUE INTERSECTIONS

SOURCE BASIS

REGULATORY BASIS

What governs this capability

The 11 standards SPEQ maps to this pillar, and the 7 regulatory bodies behind them. Which standards belong to a pillar is a SPEQ judgement; the bodies, disciplines and industries below are read from the standards themselves.

Also reached through the systems this pillar runs on

These 9 standards govern the system classes this pillar depends on rather than the pillar itself. The distinction matters: a standard that governs a system is not thereby a standard of every capability that uses it.

ICH Q9(R1)21 CFR Part 82021 CFR Part 11EU GMP Annex 11ISPE GAMP 5 (2022)2013/C 343/01WHO TRS 957, Annex 5MHRA GDPDSCSA (FD&C Act §§581–585)

PROFESSIONAL · READINESS ORIENTATION

Turn the pillar into a bounded operating conversation.

Rate observable operation from 0 (not established) to 4 (adaptive). The protected output prioritizes operating dimensions and evidence—not a compliance score.