1. What is Quality Risk Management?
Quality Risk Management is a systematic process for assessing, controlling, communicating and reviewing risks to the quality of a drug product across its lifecycle.
The basic process is:
Initiate QRM → Risk Assessment
Risk Identification → Risk Analysis → Risk Evaluation → Risk Control
Risk Reduction → Risk Acceptance → Result / Decision → Risk Review
Risk communication occurs throughout the process.
QRM can be applied to development, manufacturing, laboratory operations, facilities, utilities, suppliers, distribution, computerized systems, deviations, CAPA, validation, change control and many other pharmaceutical Quality activities. ICH explicitly recognizes computerized systems, advanced manufacturing, analytical methods and digital technologies as areas where QRM is important.
2. The Two Primary Principles of ICH Q9(R1)
ICH Q9 establishes two fundamental principles.
Principle 1: Risk to Quality Should Ultimately Link to Patient Protection
Risk evaluation should be based on scientific knowledge and ultimately connect to protection of the patient. Q9(R1) explicitly notes that Quality risk can also include product-availability situations that may result in patient harm.
This means the question is not simply:
How important is this system to the company?
The better question is:
If this process, control, material, equipment or computerized-system function fails, what could happen to product quality and ultimately to the patient?
Example
An ERP invoice-reporting function may be highly important to the business.
A small spreadsheet calculating the concentration of a cleaning solution may have greater direct Quality risk.
Business criticality and Quality risk are not the same thing.
3. What Changed With Q9(R1)?
The R1 revision was targeted primarily at four areas where QRM implementation was not consistently achieving its intended purpose.
| Area | Problem | Q9(R1) emphasis |
|---|---|---|
| Subjectivity | Risk assessments can depend too heavily on individual judgment | Manage and reduce subjectivity |
| Formality | Teams often equate QRM with a formal risk-assessment tool | Use an appropriate level of formality |
| Risk-based decisions | Risk assessments are completed but not meaningfully used | Connect QRM to decisions |
| Product availability | Quality failures can contribute to shortages | Consider availability-related patient risk |
These four concepts should be visible throughout a modern QRM program.
4. Initiating a QRM Activity
Before selecting FMEA, HAZOP or another tool, define the problem.
A useful QRM initiation should answer:
What decision are we trying to make?
What is the scope?
What assumptions are being made?
What information is available?
What information is missing?
Who should participate?
How formal should the assessment be?
When should the risk be reviewed?
This avoids a common failure:
The procedure requires FMEA, so the team immediately starts filling out an FMEA table without first defining the decision.
5. Example: Starting a QRM Assessment
Situation
A LIMS-to-ERP interface will be modified.
Poor QRM objective
Assess the interface risk.
Better QRM objective
Determine the Quality risks associated with changing the transfer of approved laboratory results from LIMS to ERP and define the controls and verification needed before production release.
Scope
Include:
- approved result
- units
- specification/status
- sample
- batch/material
- mapping
- transfer
- retry
- reconciliation
- exception handling
Now the risk assessment has a useful purpose.
6. Risk Assessment
Risk assessment consists of three activities:
Risk Identification
What might go wrong?
Risk Analysis
What is the nature and significance of the risk?
Risk Evaluation
Is the risk acceptable, or does additional control need to be considered?
7. Risk Identification
Risk identification asks:
What might go wrong?
Potential sources of information include:
- scientific knowledge
- process knowledge
- deviations
- complaints
- audit findings
- CAPA
- supplier history
- validation results
- process-monitoring data
- equipment history
- regulatory findings
- laboratory investigations
- computerized-system incidents
The risk statement should describe a meaningful Quality failure.
8. Writing Better Risk Statements
Weak
LIMS failure.
Better
Approved laboratory result may be transferred to ERP with an incorrect unit.
9. Risk Analysis
Risk analysis estimates or characterizes the identified risk.
Depending on the approved methodology, factors can include:
Severity
How serious would the consequence be?
Probability
How likely is the failure or sequence of events?
Detectability
Can the failure be detected before the relevant consequence occurs?
Not every QRM method must use all three factors.
ICH Q9 does not mandate one universal numerical formula.
10. Severity
Severity should represent the consequence of the failure.
Example
Incorrect dashboard font:
Potential consequence: little or no impact to product quality.
Incorrect potency calculation used for batch disposition:
Potential consequence: inappropriate product disposition.
The complexity of the software does not determine severity.
11. Probability
Probability should use available knowledge whenever practical.
Potential evidence:
- historical deviations
- complaint rates
- process capability
- equipment history
- supplier data
- validation results
- failure rates
- scientific knowledge
- production experience
Weak rationale
Probability = 2 because the team considers it unlikely.
Better rationale
One comparable transfer failure occurred across approximately 150,000 transactions during the previous 24 months, and automated reconciliation detected the failure before batch disposition.
Now the rating has a basis.
12. Detectability
Detectability concerns the ability of existing controls to identify the failure.
Example
Failure:
LIMS result is not transferred to ERP.
Control:
ERP reconciliation compares expected approved results against received transactions and generates an exception.
This improves the ability to detect the failure.
However:
“A human reviews it”
should not automatically receive a strong detectability rating.
The review must actually be capable of detecting the relevant failure.
13. Risk Evaluation
Risk evaluation compares the analyzed risk with defined acceptance criteria.
Possible conclusions include:
Acceptable
Existing controls are adequate.
Risk reduction required
Additional control is needed.
Additional information required
There is too much uncertainty to make a justified decision.
That third result is important.
QRM does not require every meeting to end with a definitive risk rating.
Sometimes the correct conclusion is:
We do not have enough information yet.
14. Risk Control
Risk control asks:
What should we do about the risk?
It includes:
Risk Reduction
and
Risk Acceptance.
15. Risk Reduction
Risk reduction can use different types of controls.
Technical controls
- interlocks
- access restrictions
- alarms
- automated calculations
- reconciliation
- system-enforced workflow
- error handling
- automated checks
Procedural controls
- independent review
- approval
- SOP
- training
- manual verification
Monitoring controls
- exception reports
- process monitoring
- audit-trail review
- trending
- periodic review
Controls should address the actual failure.
16. Worked Example: Electronic Batch Release
Failure
Unauthorized user releases a batch.
Potential impact
Batch may be released without required Quality authorization.
Controls
Role-based access
Only authorized Quality personnel receive release permission.
Workflow control
Release is blocked until required prerequisites are complete.
Electronic signature
Authorized user signs the disposition.
Audit trail
Release action is attributable.
Verification
Test:
| Scenario | Expected result |
|---|---|
| Authorized Quality user with all prerequisites satisfied | Release permitted |
| Warehouse user | Release blocked |
| Administrator without release role | Release blocked |
| Missing required test | Release blocked |
| Required approval incomplete | Release blocked |
The QRM result directly informs testing.
17. Risk Acceptance
Risk acceptance means that the remaining risk is considered acceptable according to defined criteria.
It does not mean:
We know the risk is unacceptable but have decided not to fix it.
Risk acceptance should consider:
- remaining risk
- effectiveness of controls
- uncertainty
- applicable requirements
- scientific knowledge
The rationale should be documented proportionately.
18. Risk Communication
Risk information should reach the people who need it.
Depending on the situation, this may include:
- Quality
- Manufacturing
- Laboratory
- Engineering
- Validation
- IT
- Supply Chain
- Supplier Quality
- Regulatory
- senior management
Communication occurs throughout QRM, not only when the risk assessment is completed.
19. Risk Review
Risk is not static.
A risk assessment may need review after:
- change
- deviation
- complaint
- CAPA
- audit
- supplier issue
- process trend
- new scientific knowledge
- regulatory change
- software release
- cybersecurity vulnerability
- AI/model change
The review frequency and trigger should be appropriate to the risk.
20. Formality in QRM
One of the most important Q9(R1) clarifications is that formality is a continuum, not simply “formal” versus “informal.” ICH identifies three useful considerations when deciding the level of formality:
Uncertainty
Importance
Complexity.
Higher levels of these factors generally support greater formality.
21. Low-Formality Example
Change
Correct a spelling error in a report heading.
No:
- calculation
- data
- workflow
- interface
- record meaning
- approval
is affected.
A concise documented impact assessment may be sufficient.
A 30-row FMEA would add little value.
22. Higher-Formality Example
Change
Modify environmental-monitoring alert limits used for sterile manufacturing.
Potential implications include:
- microbiological control
- alert/action decisions
- batch impact
- investigations
- trend analysis
Appropriate assessment may require:
- Quality
- Microbiology
- Engineering
- Manufacturing
- Validation
and a more formal QRM activity.
23. Formality Decision Table
| Factor | Lower formality | Higher formality |
|---|---|---|
| Uncertainty | Well understood | Significant unknowns |
| Importance | Limited consequence | Major Quality/patient consequence |
| Complexity | Simple relationship | Multiple interacting systems/processes |
| Knowledge | Strong historical evidence | Limited data |
| Decision | Easily reversible | Difficult or costly to reverse |
The tool should fit the decision.
Uncertainty, importance and complexity are the three considerations identified in Q9(R1). The knowledge and reversibility rows are practical decision prompts in this guide, not additional named ICH factors.
24. Subjectivity in QRM
QRM involves judgment.
The goal is not to eliminate judgment but to control inappropriate subjectivity.
Potential sources include:
- incomplete knowledge
- individual experience
- confirmation bias
- organizational pressure
- anchoring
- poorly defined scoring criteria
- desired project outcome
25. Example of Risk-Score Manipulation
Suppose the organization’s threshold is:
Risk score ≥15 requires formal mitigation.
Assessment:
Severity = 5 Probability = 3
Score = 15.
Someone argues:
Probability should really be 2.
New score:
5 × 2 = 10.
Nothing about the actual failure changed.
If the rating was adjusted primarily to avoid mitigation, the risk matrix has become a decision-justification tool rather than a QRM tool.
26. Reducing Subjectivity
Practical controls include:
- clearly defined criteria
- multidisciplinary participation
- objective data
- scientific evidence
- documented assumptions
- independent challenge
- experienced facilitation
- periodic reassessment
Ask:
Would another qualified team understand why we reached this conclusion?
27. Risk-Based Decision Making
QRM should inform actual decisions.
Examples include:
Validation
What testing is needed?
Change control
What is affected?
Deviation
How significant is the event?
CAPA
How much investigation and corrective action are warranted?
Supplier management
How much supplier oversight is appropriate?
Audit
Where should audit resources be focused?
Process validation
Which variables and failure modes require greater attention?
28. Risk-Based Decision Making Does Not Mean Risk-Based Compliance
QRM should not be used to justify a practice that is otherwise unacceptable under applicable requirements. ICH explicitly cautions that QRM facilitates decisions but does not remove the obligation to comply with regulatory requirements.
Example:
“Electronic records are low risk, therefore we do not need required controls.”
is not appropriate QRM.
Risk determines how controls and evidence are applied within the applicable regulatory framework.
29. Product Availability
Q9(R1) explicitly recognizes that manufacturing Quality problems can affect product availability and ultimately harm patients.
Example
A single qualified supplier provides a critical sterile component.
Supplier Quality performance begins deteriorating.
Traditional assessment:
Can incoming inspection detect defective components?
Broader QRM assessment:
Could supplier failure interrupt production of a medically necessary product?
Possible controls:
- supplier remediation
- increased monitoring
- inventory strategy
- second-source qualification
- capacity planning
- business continuity
Quality and supply reliability can intersect.
30. QRM and Pharmaceutical Development
QRM can help identify:
- Critical Quality Attributes
- Critical Process Parameters
- material attributes
- control strategy
- areas requiring additional experimentation
FDA’s Q8/Q9/Q10 training material emphasizes the use of scientific rationale and QRM in establishing CQAs and CPPs and linking them to the control strategy.
Source context: FDA Q8/Q9/Q10 training questions and answers ↗.
31. QRM and Process Validation
QRM can support:
- validation planning
- identification of critical variables
- sampling strategy
- monitoring
- change evaluation
- continued process verification
Example:
For a sterile filling process, QRM may identify:
fill volume
sterilization conditions
environmental controls
line interventions
as areas requiring different levels of control and verification.
32. QRM and Cleaning Validation
Situation
Shared manufacturing equipment.
Risk question
Could residue from Product A contaminate Product B at a level that affects product quality or patient safety?
Consider:
- potency
- toxicity
- solubility
- cleanability
- equipment design
- batch sequence
- analytical capability
Controls can include:
- cleaning process
- validated cleaning parameters
- inspection
- analytical testing
- campaign controls
33. QRM and Deviations
Example
Cold-room temperature exceeds the approved limit for 18 minutes.
Do not automatically conclude:
Temperature excursion = batch rejection.
Assess:
- actual temperature
- duration
- product location
- product stability
- packaging
- monitoring accuracy
- historical data
- scientific evidence
The Quality decision should follow the evidence.
34. QRM and CAPA
QRM can support:
- investigation depth
- action priority
- escalation
- effectiveness-check rigor
But QRM should not be used to avoid CAPA when systemic corrective action is warranted.
Example
One isolated data-entry error with immediate detection may require correction and local action.
Repeated data-entry failures caused by poor interface design may indicate a systemic issue requiring CAPA.
35. QRM and Supplier Management
Not every supplier requires the same oversight.
Consider:
- material/service criticality
- supplier performance
- process complexity
- detectability
- alternatives
- regulatory history
- supply continuity
Example
Office stationery supplier:
low Quality relevance.
Sterilization provider:
high potential impact and higher oversight.
36. QRM and Computerized Systems
ICH Q9(R1) specifically recognizes the importance of QRM when applying digitalization, emerging technologies, advanced data analysis and computerized systems.
A practical computerized-system sequence is:
Intended Use → GxP Function → Failure Scenario → Potential Impact → Existing Controls → Existing Evidence → Additional Testing → Validation Conclusion
This is a practitioner connection to risk-based software assurance. ICH Q9(R1) addresses pharmaceutical quality; FDA’s CSA guidance has its own medical-device production and quality-system scope.
37. Worked Example: GxP Spreadsheet
Intended use
Calculate cleaning-agent concentration.
Failure
Formula calculates incorrect concentration.
Potential impact
Cleaning solution may be outside the validated range.
Existing controls
- controlled template
- protected formulas
- restricted editing
- independent verification
Testing
- normal calculation
- boundary values
- invalid inputs
- known calculation
- protected-cell challenge
The risk is based on the intended use.
Not:
Does the spreadsheet contain macros?