01
Organization design & operating model
How the organisation is arranged to do regulated work: structures, accountability, decision rights, spans of control, the interfaces between functions, governance and whether capacity matches the load.
Structure decides which decisions are easy and which require a meeting. Where quality reports into the function whose output it judges, no amount of procedure restores the independence the arrangement removed.
HOW IT FAILS
- Quality oversight reports into operations at site level, so independence exists only on the corporate chart.
- Spans of control widen through headcount reduction until supervision is nominal on the shifts that need it most.
- Interfaces between functions have no owner, so work that belongs to two departments belongs to neither.
WHAT CONTAINS IT
- Quality authority with a reporting line independent of the function it judges, at every level it operates.
- Span of control assessed against supervision actually required, not against budget alone.
- Named ownership for each cross-functional interface, reviewed when the structure changes.
EVIDENCE IT OPERATES
- Organisation charts with reporting lines and quality independence visible.
- Delegation of authority and decision-rights documentation.
- Interface ownership definitions and their review records.
02
Workforce planning & talent supply
Having the right people available: demand forecasting, role definition, staffing models, recruitment pipelines, critical-skill identification, succession, contractor use and resilience to departure.
Qualification takes months, so staffing gaps cannot be closed at the speed they open. A site running on a qualified population smaller than its schedule assumes is carrying a risk that shows up as deviations rather than as a vacancy report.
HOW IT FAILS
- Plans count headcount rather than qualified headcount, so an approved establishment full of untrained people reads as fully staffed.
- Critical single-person dependencies are known informally and never recorded, so departure is a surprise.
- Contractors perform regulated work under oversight arrangements designed for permanent staff.
WHAT CONTAINS IT
- Capacity planning based on qualified and currently authorised staff, not on approved positions.
- Explicit identification of single-person dependencies with deliberate cover-building.
- Contractor qualification, oversight and access defined for the work they actually perform.
EVIDENCE IT OPERATES
- Qualified-staffing levels against operational demand.
- Critical-skill and succession registers with cover status.
- Contractor qualification and oversight records.
03
Roles, competencies & qualification
What each role must be able to do and how that is established: expectations, knowledge, skill, judgement, formal authorisation, demonstrated performance and periodic requalification.
Qualification is the organisation asserting that a named person may perform a regulated task. Where it rests on training completion alone, the assertion is about attendance rather than capability — a distinction inspectors probe by asking someone to explain what they did.
HOW IT FAILS
- Qualification is granted on course completion without any demonstration of the task itself.
- Authorisation lists drift from reality, so people perform tasks they are not currently authorised for.
- Requalification is a re-read of the procedure rather than a re-demonstration of the skill.
WHAT CONTAINS IT
- Qualification requiring demonstrated performance for tasks where skill, not knowledge, is the risk.
- Authorisation records reconciled against who actually performs each task.
- Requalification proportionate to risk and to how often the task is performed.
EVIDENCE IT OPERATES
- Role competency definitions with required demonstrations.
- Individual qualification and authorisation records with dates.
- Requalification records including demonstration outcomes.
04
Learning, training & effectiveness
How capability is built: curricula and prerequisites, delivery, opportunity to practise, assessment, transfer into the job, effectiveness evaluation and retraining when something goes wrong.
Training is the most common corrective action and one of the least effective, because retraining a person who already knew the procedure addresses nothing. Effectiveness evaluation is what separates a genuine capability gap from a convenient CAPA.
HOW IT FAILS
- Retraining is assigned as the corrective action for errors whose cause was workload, procedure or system design.
- Effectiveness is measured by completion and quiz scores rather than by performance in the work.
- Read-and-understand is used for content that requires practice, so the record exists and the capability does not.
WHAT CONTAINS IT
- Training rejected as a corrective action unless the investigation established a genuine knowledge gap.
- Effectiveness measured in the work — error rates, observed performance — not at the end of the course.
- Delivery method matched to what is being learned, with practice where skill is required.
EVIDENCE IT OPERATES
- Curricula with prerequisites and delivery method rationale.
- Training effectiveness evaluations against job performance.
- Retraining actions with the knowledge-gap evidence that justified them.
05
Human performance & work design
Designing work so people can do it correctly: task and procedure design, interfaces, workload, fatigue, recognition of error-likely situations, defences in depth and learning from what nearly happened.
Human error is an outcome, not a cause. Treating it as a cause ends the investigation exactly where the useful information starts — in the conditions that made the error likely and will make it likely again for the next person.
HOW IT FAILS
- Procedures are written by people who do not perform the task, so following them exactly is impractical and workarounds become normal.
- Error-likely conditions — night shift, first run after changeover, time pressure — are visible in the data and never analysed as a set.
- Near misses are not reported because nothing happened, so the free lesson is lost.
WHAT CONTAINS IT
- Procedures authored or verified with the people who perform the task, under real conditions.
- Analysis of when errors occur, not only what they were, so error-likely conditions become visible.
- Near-miss reporting that is actively valued, with feedback to the reporter.
EVIDENCE IT OPERATES
- Procedure usability verification records.
- Error and deviation analysis by condition, shift and task context.
- Near-miss reports and the work-design changes arising from them.
06
Leadership, culture & psychological safety
The behaviours leaders actually reward: speak-up climate, just culture, stop-work authority, the trust that makes reporting safe, and accountability that distinguishes error from recklessness.
Culture is what determines whether the quality system receives an accurate picture of its own operation. Every control depends on someone raising something, and that decision is made by reading how the last person who did was treated.
HOW IT FAILS
- Leaders ask for bad news and respond to it with pressure, so the request is discounted within one cycle.
- Stop-work authority is stated in policy and has never been exercised, which is a measurement rather than a reassurance.
- Metrics reward low deviation counts, creating an incentive not to record rather than not to deviate.
WHAT CONTAINS IT
- A just-culture framework applied consistently, distinguishing error, at-risk behaviour and recklessness.
- Stop-work events tracked and reviewed for how the organisation responded, not only whether it was justified.
- Metric design reviewed for perverse incentives before a target is set on it.
EVIDENCE IT OPERATES
- Just-culture framework and examples of its consistent application.
- Stop-work and hold records with the organisational response.
- Reporting rates trended alongside deviation rates.
07
Organizational change & adoption
Making an organisational change actually take: stakeholder analysis, impact assessment, readiness, communication, participation, transition support, reinforcement and whether the intended benefit arrived.
A change that is implemented but not adopted produces the worst of both states — the old way is prohibited and the new way is not established, so people improvise in the gap. In regulated work that gap is where undocumented practice appears.
HOW IT FAILS
- Go-live is treated as completion, so support ends exactly when people start meeting real cases.
- Impact assessment covers process and systems but not the workload the change adds at the front line.
- Old and new ways run in parallel indefinitely because withdrawal of the old was never planned.
WHAT CONTAINS IT
- Support planned to extend well past go-live, sized to the difficulty of the transition.
- Impact assessment including front-line workload and the procedures people actually follow.
- A defined and enforced withdrawal point for superseded ways of working.
EVIDENCE IT OPERATES
- Change impact and readiness assessments including front-line effects.
- Adoption measures after go-live, not only implementation completion.
- Withdrawal records for superseded processes and documents.
08
Knowledge capture, transfer & continuity
Keeping what the organisation knows: tacit and explicit knowledge, communities of practice, handovers, lessons learned, resilience to turnover, succession and the ability to retrieve any of it later.
Regulated organisations lose knowledge faster than they lose documents. When the person who understood why a parameter was set leaves, the rationale becomes folklore — and the next team either cannot change it safely or changes it without knowing what it protected.
HOW IT FAILS
- Handover is a document produced in the leaver’s final week, covering tasks rather than judgement.
- Lessons learned are captured per project and never reach the standard that would prevent recurrence.
- Knowledge is retrievable only by asking someone, so retrieval depends on knowing who to ask.
WHAT CONTAINS IT
- Handover planned across a period long enough to transfer judgement, not only task lists.
- A defined route from a lesson learned into the procedure or standard it should change.
- Knowledge stored so it can be found by someone who does not already know it exists.
EVIDENCE IT OPERATES
- Handover records covering rationale and judgement, not only responsibilities.
- Lessons-learned entries traceable to the standards they changed.
- Retrieval demonstrations by people outside the originating team.
09
Cross-functional collaboration & escalation
How functions work across boundaries: interfaces, decision boundaries, escalation triggers, shared situational awareness and the resolution of genuine disagreement.
Most regulated failures cross a functional boundary. The organisation usually has all the information somewhere and has not assembled it in one place — which is a collaboration failure rather than a knowledge failure.
HOW IT FAILS
- Escalation depends on judgement with no defined trigger, so similar issues escalate or do not depending on who holds them.
- Disagreement between functions is resolved by seniority rather than by evidence, and the losing view is not recorded.
- Each function holds part of a picture and no forum exists where the parts are combined before a decision.
WHAT CONTAINS IT
- Defined escalation triggers and timeframes, so escalation is obligatory rather than brave.
- A documented route for unresolved technical disagreement, with dissent recorded.
- Forums that combine cross-functional information before decisions rather than after them.
EVIDENCE IT OPERATES
- Escalation criteria and records of issues escalated against them.
- Decision records including dissenting positions and their resolution.
- Cross-functional review records for decisions spanning boundaries.
10
Early-career development & leadership pipeline
Building the next generation of practitioners: industry orientation, systems literacy, entry pathways, mentoring, deliberate breadth, supervised experience and progression into responsibility.
The sector competes for a limited pool of experienced practitioners and does comparatively little to enlarge it. Early-career design determines whether someone leaves with GxP judgement or only with the ability to follow one site’s procedures.
HOW IT FAILS
- New entrants are trained on their immediate task with no orientation to why the regulated system exists, so rules read as arbitrary.
- Mentoring is informal and therefore unevenly distributed, favouring those who already know how to ask.
- Breadth is never designed, producing specialists who cannot assess impact outside their own area.
WHAT CONTAINS IT
- Structured orientation covering the purpose of regulated work before task-level training.
- Mentoring assigned deliberately rather than left to emerge, with expectations of both parties.
- Planned exposure across functions for roles that will eventually assess cross-functional impact.
EVIDENCE IT OPERATES
- Onboarding curricula including regulatory-purpose orientation.
- Mentoring assignments and progression reviews.
- Development plans showing deliberate breadth and supervised experience.