· QUALITY RISK MANAGEMENT

Quality Risk Management (ICH Q9)

Quality Risk Management (QRM) is a systematic process for the assessment, control, communication, and review of risks to product quality across the product lifecycle. ICH Q9 made it a formal expectation; the 2023 R1 revision sharpened it by tackling the two things that most undermine it in practice — subjectivity and poorly justified risk-based decisions. QRM is the risk method that runs underneath validation, contamination control, data integrity, and the quality system as a whole.

What an explainer is not

A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 27 LINKS

QRM is the method underneath the adjacent subjects: three disciplines apply it, and its outputs size the CCS, the PPQ batch count, CSV scope, and data-integrity controls — which is why ICH Q9(R1) polices its subjectivity.

06 · QUALITY MATURITY — QUALITY RISK MANAGEMENT (ICH Q9), REACTIVE TO ADAPTIVE

L1
Reactive

Risk assessments are written after the decision, to justify it; scores depend on who was in the room.

L2
Defined

A QRM SOP and toolbox exist, but the same heavyweight FMEA is applied to everything regardless of stakes.

L3
Controlled

Formality scales with uncertainty, importance, and complexity; assessments name assumptions and use calibrated scales.

L4
Predictive

Risk review is scheduled and fed by monitoring data; subjectivity is actively managed through team composition and framing.

L5
Adaptive

Risk knowledge compounds: QRM outputs drive the CCS, validation scope, and design decisions, and reviews sharpen the scales.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 4

Derived from the 4 standards SPEQ maps to this subject, across 2 regulatory bodies: ICH, ISO.

RECORDS & OBJECTIVE EVIDENCE

  • Risk assessments naming the team, assumptions, and scoring basis
  • A documented rationale for the formality level of each assessment
  • A living risk register with scheduled review dates
  • Records of risk-based decisions with the reasoning, not just the score
  • Evidence that risk controls were implemented and verified effective

COMMON INSPECTION FINDINGS

  • Risk assessments authored after the decision they support
  • Scoring scales undefined or applied inconsistently across assessments
  • Risk reviews never performed after the initial assessment
  • The same tool applied by reflex regardless of risk or novelty
  • Risk controls accepted on paper but never verified in practice
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

The QRM process and its two principles

ICH Q9 defines a process — risk assessment (identification, analysis, evaluation), risk control (reduction and acceptance), risk communication, and risk review — and rests it on two principles: the evaluation of risk should be based on scientific knowledge and ultimately link to protection of the patient; and the level of effort, formality, and documentation should be commensurate with the level of risk.

That second principle is doing enormous work. It is the licence to be light-touch where risk is low and rigorous where it is high — and the reason a QRM programme that applies the same heavyweight FMEA to everything is misapplying the standard.

Tackling subjectivity — the R1 revision

The 2023 ICH Q9(R1) revision was prompted by a candid observation: risk assessments were too often subjective, and "risk-based" was being used to justify decisions that were not genuinely risk-based. R1 adds explicit attention to subjectivity — the influence of who is in the room, how scoring scales are built, and how hazards are framed — and to formality (how to decide how formal an assessment needs to be) and risk-based decision-making.

The practical takeaway: a defensible risk assessment names its assumptions, uses scales that mean the same thing to everyone, includes the right expertise, and documents the reasoning behind the decision — not just the score.

R1 also reframes formality as a **spectrum, not a binary**, and names the factors that place a decision on it: the degree of **uncertainty** (how well the situation is understood), the **importance** of the problem (its potential impact on the patient and product), and its **complexity**. The result is a practical ladder. **Informal** QRM is the risk-based thinking embedded in routine, well-understood work — no standalone assessment, just competent judgement within established procedures. **Semi-formal** applies a structured but lightweight method — a risk ranking, a filter — where the stakes or uncertainty rise. **Formal** QRM brings a documented tool, a cross-functional team, and a recorded rationale for a novel, high-impact, or high-uncertainty question. The error the ladder prevents runs both ways: a full FMEA on a like-for-like change wastes effort and buries the real risks, while an informal judgement on a novel sterile process under-resources a decision the patient depends on.

The toolbox — and choosing the right tool

ICH Q9 is tool-agnostic but references a toolbox: FMEA/FMECA, HACCP, fault tree analysis, HAZOP, PHA, and simple supporting methods like risk ranking and filtering. For medical devices, ISO 14971 provides the parallel, device-specific risk-management standard across the product lifecycle.

The skill is matching the tool to the question. A quick, informal risk-ranking may be the correct level for a low-stakes change; a full HACCP or FMECA is warranted for a novel sterile process. Reaching for the heaviest tool by reflex is a common way to produce impressive-looking but low-value risk documents.

QRM as connective tissue

QRM is not a standalone activity — it is the method underneath the other cornerstones. The Contamination Control Strategy is a QRM output; the number of PPQ batches is a QRM decision; the scope of computer-system validation is set by risk; data-integrity controls are sized by risk. ICH Q10 places QRM alongside knowledge management as an enabler of the entire Pharmaceutical Quality System.

WORKED EXAMPLE — SPEQ SYNTHESIS

A hypothetical sterile manufacturer proposes to change the supplier of a single-use filter assembly used on a commercial aseptic fill line. Procurement wants the change in place within a quarter. The question put to the quality unit is whether a risk assessment is needed and, if so, how formal it should be.

  1. Fix the risk question in one sentence, and get it agreed before anything is scored

    Not "is the new filter acceptable" but something answerable: what is the risk to product sterility and to patient safety from changing this assembly on this line. A vague question is the single most common reason a risk assessment ends up unusable, because every participant answers a slightly different one.

  2. Decide the formality before the method, and record why

    Formality is proportionate to risk and to the uncertainty, not to the size of the purchase order. A change touching a sterility-assuring component with limited comparative data sits at the formal end; the decision on where it sits is itself a determination the organisation makes and records.

  3. Assemble a team that can see the failure modes

    Microbiology, engineering, production and quality at minimum. A single-function assessment finds single-function failure modes: procurement sees supply risk, engineering sees fit, and nobody sees the extractables question unless someone in the room owns it.

  4. Define the scoring scales before scoring, and use them unchanged

    Severity, occurrence and detectability need written anchors agreed in advance. Scales adjusted mid-assessment — usually to move an uncomfortable score — destroy comparability with every other assessment the site has run.

  5. Rank on risk, then override on severity

    A rare, undetectable failure that reaches the patient outranks a frequent nuisance with a high arithmetic score. Treating the ranking as the answer rather than as an input is how a sterility risk gets filed below a labelling risk.

  6. Decide controls, re-score residual risk, and record what is being accepted

    The assessment is not finished when the risks are listed. It is finished when the controls are defined, the residual risk is re-evaluated with those controls in place, and a named person has accepted what remains — in writing, with the rationale.

A risk assessment with a stated question, a justified formality, a documented team, fixed scales, a severity-aware ranking, defined controls and a recorded acceptance of residual risk. What it is not is an approval of the supplier change: the change control decision is a separate determination that reads this assessment as one input.

WHAT WOULD CHANGE THIS

  • If comparative data on the new assembly is unavailable rather than merely incomplete, the honest output is a decision to generate data, not a lower score on detectability.
  • If the line is not aseptic — a terminally sterilised product, say — the severity anchors change and with them the whole formality judgement.
  • If the site has a qualified equivalent already in use on another line, the assessment is comparative rather than de novo, and the evidence burden shifts accordingly.

FREQUENTLY ASKED

What is ICH Q9?

ICH Q9 is the international guideline on Quality Risk Management — a systematic process for the assessment, control, communication, and review of risks to product quality across the lifecycle. Its 2023 R1 revision added explicit treatment of subjectivity, formality, and risk-based decision-making.

What are the two primary principles of QRM?

First, the evaluation of risk to quality should be based on scientific knowledge and ultimately link to the protection of the patient. Second, the level of effort, formality, and documentation of the QRM process should be commensurate with the level of risk.

Which risk tool should I use?

ICH Q9 is tool-agnostic — FMEA/FMECA, HACCP, FTA, HAZOP, PHA, and risk ranking are all valid. Match the tool to the risk: a light risk-ranking for low-stakes decisions, a full FMECA or HACCP for high-stakes novel processes. For medical devices, ISO 14971 is the dedicated risk-management standard.

Why was ICH Q9 revised to R1?

Because risk assessments in practice were often subjective and "risk-based" was being used to justify decisions that were not genuinely risk-based. ICH Q9(R1), finalised in 2023, added guidance on managing subjectivity, deciding the appropriate level of formality, and making — and documenting — sound risk-based decisions.

How do you decide how formal a risk assessment needs to be?

ICH Q9(R1) treats formality as a spectrum set by three factors: the degree of uncertainty (how well the situation is understood), the importance of the problem (its potential impact on patient and product), and its complexity. That yields a ladder — informal risk-based thinking within routine procedures for well-understood, low-impact work; semi-formal methods like risk ranking or filtering as stakes or uncertainty rise; and formal QRM with a documented tool, a cross-functional team, and a recorded rationale for novel, high-impact, or high-uncertainty questions. Over-formalising a like-for-like change and under-resourcing a novel high-risk one are both misapplications.

PROFESSIONAL · INSPECTION PLAYBOOK · SPEQ SYNTHESIS

The inspection-readiness playbook for this topic

CHECKING ACCESS

Checking your Professional access…