Situation and intended use
A medical-device manufacturer uses an eQMS for controlled documents and CAPA. A weekly supplier release changes dashboard colors, conditional CAPA routing, and the signature block in exported records. The system owner has five working days before deployment.
First question: what is actually affected?
Read the release notes and available evidence. Identify the local routing rules, export uses, open records, integrations, and shared components. Ask whether the color change also alters status labels or accessibility. A visual change can matter if users depend on color alone to identify overdue work.
Failure and evidence plan
| Failure | Proposed assurance activity | Evidence gap addressed |
|---|---|---|
| Severe CAPA bypasses required approval | Test approved routing branches, invalid values, and attempted bypass | Local conditional rules |
| Existing CAPA changes route unexpectedly | Test representative open states before and after update | Transition of existing records |
| Export associates signature with wrong revision | Compare source approval and exported version/context | Local record use and export behavior |
| Status meaning becomes unclear | Focused review with representative users and accessible labels | Operational interpretation |
Supplier workflow-engine evidence may support standard mechanics. It does not automatically support the local conditions.
Worked outcome — fictional
CAPA tests find that records with a blank legacy site field skip a required review. The team prevents affected records from advancing while correcting the mapping and reassessing coverage. Because the defect affects a required control, a general statement that “most tests passed” is insufficient.
After correction, targeted retesting and relevant regression demonstrate the approved behavior. Export checks confirm the expected record associations. The dashboard retains explicit text labels. The authorized owners approve deployment with defined monitoring for routing exceptions.
Residual risk and monitoring
Monitor unexpected route changes, stuck tasks, and export complaints. Assign an owner and response process. If the supplier cannot delay deployment, evaluate operational restrictions and escalation before exposure; a rollback plan must account for data and workflow changes, not just software version.
Questions a reviewer should be able to answer
Why were these branches selected? How were legacy open records represented? What supplier evidence was reused? What happened to the defect? Who approved continued use and under what conditions?
Challenge: Only the dashboard changes next week. Must this entire lab be repeated?
Worked answer: Reassess the actual release and dependencies. Reuse relevant evidence when justified and address the new uncertainty. Do not mechanically repeat or mechanically waive testing.