ICH Q9 Risk Priority Calculator
Guided FMEA risk assessment aligned to ICH Q9(R1). Enter severity, occurrence, and detectability for each failure mode to generate risk bands, mitigation priorities, and a copy-ready rationale.
WHAT THIS CALCULATES
A Risk Priority Number for each failure mode — severity × occurrence × detectability on a 1–5 scale — plus a band, and an escalation for the severe-but-rare modes that pure RPN ranking is known to hide.
THE METHOD
RPN = S × O × D High if RPN ≥ 60, or S = 5, or (S ≥ 4 and D ≥ 4) Medium if RPN ≥ 25- S
- severity — how bad the effect is if the failure occurs (1 negligible … 5 potential patient harm)
- O
- occurrence — how likely the failure is (1 remote … 5 frequent)
- D
- detectability — how likely it is to reach the patient undetected (1 almost certainly caught … 5 almost certainly missed)
- RPN
- the product, from 1 to 125 on this scale
The two severity overrides exist because RPN alone ranks badly: S5·O1·D1 = 5 would otherwise sit below S3·O3·D3 = 27, ranking a potential patient harm beneath a routine nuisance. SPEQ’s own FMEA template states the rule these implement — treat any high-severity failure mode as a priority regardless of RPN. Escalated rows are marked ↑. The 60 and 25 thresholds are SPEQ defaults for a 1–5 scale; a site with an approved scale and threshold should use its own.
THE INPUTS, AND WHAT THEY MEAN
- Failure mode
- What can go wrong, stated as a specific failure rather than a topic — "operator does not perform the intervention as qualified", not "aseptic technique".
- Severity (1–5)
- The consequence if it happens, assessed at the patient, not at the batch. Severity is a property of the effect and does not improve because you added a control.
- Occurrence (1–5)
- How often it happens with current controls in place. Use deviation and trend data where you have it; team consensus is where scoring drifts most.
- Detectability (1–5)
- The chance it escapes undetected — high is bad. Score the controls that exist today, not the ones the CAPA will introduce.
Unlock ICH Q9 Risk Priority Calculator
This tool is part of the SPEQ resource library. Sign in to run the workflow and generate the output while the information hub is open.
- WHAT IT PRODUCES
- RPN table + Rationale
- TYPICAL TIME
- ~45 min
- STANDARDS IT IMPLEMENTS
- ICH Q9(R1)EU GMP Annex 1
SPEQ tools are analytical aids, not validated systems. Reproduce any result in your own qualified system before it supports a GxP decision.
HOW TO READ THE OUTPUT
- ›Rank by band first, then by RPN within the band, and look at anything marked ↑ before anything else — those are the modes RPN would have buried.
- ›RPN is ordinal, not a measurement. An RPN of 60 is not twice as risky as 30, values are not continuous, and two failure modes with the same RPN can carry very different risk. Use it to sort, never to arithmetic.
- ›Severity should not fall after mitigation. Controls change occurrence and detectability; the consequence of the failure is unchanged unless you redesigned the process so the failure can no longer have that effect.
- ›Re-score after mitigation and keep both scores. Residual risk with a documented acceptance is the output an inspector expects, not a table where every RPN has quietly become green.
WORKED EXAMPLE
Two failure modes on an aseptic line: an intervention not performed as qualified, and an EM excursion not escalated within the procedural timeline.
- Intervention not performed as qualified
- S 5 · O 3 · D 4
- EM excursion not escalated in time
- S 4 · O 2 · D 3
The first mode reaches High on RPN alone, and would also have been escalated by its severity of 5 — a potential patient harm stays a priority however well controlled. The second scores 24 and bands Low, which is the answer the model intends: serious but infrequent and reasonably detectable. Mitigation effort goes to the first, and the rationale for accepting the second is what gets documented.
REGULATORY BASIS
- ICH Q9(R1) — Quality Risk Management
- The framework this implements: risk assessment, the principle that formality should be proportionate to risk, and the explicit warning about subjectivity in risk scoring.
- EU GMP Annex 1 (2022)
- Requires a contamination control strategy built on documented risk assessment — FMEA is one of the accepted methods for producing it.
- ICH Q9(R1) §5 on subjectivity
- Notes that subjectivity cannot be eliminated from risk assessment and must be managed — the reason a defined scale and a second reviewer matter more than the arithmetic.
LIMITATIONS — READ BEFORE YOU RELY ON THIS
- ›This is an analytical aid, not a validated system. Reproduce the scoring in your own quality risk management process — the formula, the band thresholds and both severity overrides are published above so you can.
- ›RPN is widely criticised and the criticism is fair: the values are not continuous, equal RPNs can mean very different risks, and thresholds invite gaming. The severity overrides mitigate the worst of it; they do not make RPN a measurement.
- ›Scores are only as good as the scale definitions behind them. Without anchored, written definitions of each level, two teams will score the same failure mode differently and neither will be wrong.
- ›It has no view of your process. It cannot tell you which failure modes you failed to think of, and an FMEA’s biggest risk is always the mode nobody listed.
Get the regulatory signal behind the calculation
New guidance, enforcement, and inspection findings touching ICH Q9(R1) and its neighbours — distilled into the free Weekly GxP Briefing.