Start with a sentence
A useful risk statement connects cause, failure, consequence, and context: “If the LIMS interface drops the dilution factor, the receiving calculation may understate the result and support an incorrect acceptance decision.”
“LIMS is high risk” gives the team much less information. A system can contain different functions, dependencies, and failure consequences.
A practical assessment sequence
Identify the use. Describe credible failure. Explain the process consequence. Identify preventive and detective controls. Assess whether the controls can be relied on. Then use your organization’s approved rating method, if one is required. Decide what additional assurance is needed and record who accepts the remaining uncertainty.
Three failures in one eQMS
| Function | Failure | Decision-relevant question |
|---|---|---|
| Home dashboard | Widget sorts overdue items incorrectly | Is it a convenience view or the only operational escalation list? |
| CAPA approval | Required approval is skipped | Can the CAPA become effective or close without the required decision? |
| Electronic signature | Signature is associated with the wrong revision | Can a reviewer reconstruct what was approved? |
The dashboard might deserve more attention than its appearance suggests if it controls daily work. The approval and signature examples require examination of workflow state, authority, and record linkage.
Do not over-credit detection
“A person reviews it” is incomplete. State who reviews what, using which source, before which decision, with what training and time. A reviewer checking a spreadsheet total against another sheet using the same faulty formula may not provide independent detection.
Completed assessment extract — fictional: “An incorrect material status could permit use of quarantined material. A warehouse operator currently sees the same status value as the issue logic, so the visual check is not independent evidence of correctness. Local assurance will challenge the source mapping, blocked transaction paths, and recovery after delayed updates.”
When to reassess
Revisit the assessment if intended use expands, a control becomes unreliable, a new interface appears, users develop a workaround, or an incident demonstrates an unconsidered failure. Repeating last year’s score without checking these conditions does not establish that the conclusion is still valid.
Exercise: A calculation is described as lower risk because every output is reviewed. The reviewer checks only that the number is present. Is that control strong enough?
Answer: It detects missing output, not necessarily incorrect output. Clarify the review’s actual coverage and assess the calculation error separately.