Practical guidance · Reviewed 14 September 2026

ICH Q9(R1) Quality Risk Management

Practical guide for pharmaceutical Quality, validation, CSV/CSA and GxP systems

  • Patient protection
  • Proportionate formality
  • Evidence-based decisions

ICH adopted Q9(R1) on January 18, 2023; FDA issued its final guidance in May 2023. The current ICH document records a minor typographical correction dated January 15, 2025. The revision emphasizes subjectivity, appropriate formality, risk-based decision-making, and product-availability risks arising from manufacturing quality issues.

ICH Q9(R1) · January 2025 correction · FDA final guidance · May 2023 ↗

The examples illustrate practitioner reasoning. They are fictional and do not represent regulatory authorizations, approved risk assessments, or executed validation evidence. Apply the source to the specific product, process and jurisdiction.

37 topics · Jump to a section

1. What is Quality Risk Management?

Quality Risk Management is a systematic process for assessing, controlling, communicating and reviewing risks to the quality of a drug product across its lifecycle.

The basic process is:

Initiate QRM → Risk Assessment
Risk Identification → Risk Analysis → Risk Evaluation → Risk Control
Risk Reduction → Risk Acceptance → Result / Decision → Risk Review

Risk communication occurs throughout the process.

QRM can be applied to development, manufacturing, laboratory operations, facilities, utilities, suppliers, distribution, computerized systems, deviations, CAPA, validation, change control and many other pharmaceutical Quality activities. ICH explicitly recognizes computerized systems, advanced manufacturing, analytical methods and digital technologies as areas where QRM is important.

Source context: ICH Q9(R1).

2. The Two Primary Principles of ICH Q9(R1)

ICH Q9 establishes two fundamental principles.

Principle 1: Risk to Quality Should Ultimately Link to Patient Protection

Risk evaluation should be based on scientific knowledge and ultimately connect to protection of the patient. Q9(R1) explicitly notes that Quality risk can also include product-availability situations that may result in patient harm.

This means the question is not simply:

How important is this system to the company?

The better question is:

If this process, control, material, equipment or computerized-system function fails, what could happen to product quality and ultimately to the patient?

Example

An ERP invoice-reporting function may be highly important to the business.

A small spreadsheet calculating the concentration of a cleaning solution may have greater direct Quality risk.

Business criticality and Quality risk are not the same thing.

Source context: ICH Q9(R1).

3. What Changed With Q9(R1)?

The R1 revision was targeted primarily at four areas where QRM implementation was not consistently achieving its intended purpose.

AreaProblemQ9(R1) emphasis
SubjectivityRisk assessments can depend too heavily on individual judgmentManage and reduce subjectivity
FormalityTeams often equate QRM with a formal risk-assessment toolUse an appropriate level of formality
Risk-based decisionsRisk assessments are completed but not meaningfully usedConnect QRM to decisions
Product availabilityQuality failures can contribute to shortagesConsider availability-related patient risk

These four concepts should be visible throughout a modern QRM program.

Source context: ICH Q9(R1).

4. Initiating a QRM Activity

Before selecting FMEA, HAZOP or another tool, define the problem.

A useful QRM initiation should answer:

What decision are we trying to make?

What is the scope?

What assumptions are being made?

What information is available?

What information is missing?

Who should participate?

How formal should the assessment be?

When should the risk be reviewed?

This avoids a common failure:

The procedure requires FMEA, so the team immediately starts filling out an FMEA table without first defining the decision.

5. Example: Starting a QRM Assessment

Situation

A LIMS-to-ERP interface will be modified.

Poor QRM objective

Assess the interface risk.

Better QRM objective

Determine the Quality risks associated with changing the transfer of approved laboratory results from LIMS to ERP and define the controls and verification needed before production release.

Scope

Include:

  • approved result
  • units
  • specification/status
  • sample
  • batch/material
  • mapping
  • transfer
  • retry
  • reconciliation
  • exception handling

Now the risk assessment has a useful purpose.

6. Risk Assessment

Risk assessment consists of three activities:

Risk Identification

What might go wrong?

Risk Analysis

What is the nature and significance of the risk?

Risk Evaluation

Is the risk acceptable, or does additional control need to be considered?

Source context: ICH Q9(R1).

7. Risk Identification

Risk identification asks:

What might go wrong?

Potential sources of information include:

  • scientific knowledge
  • process knowledge
  • deviations
  • complaints
  • audit findings
  • CAPA
  • supplier history
  • validation results
  • process-monitoring data
  • equipment history
  • regulatory findings
  • laboratory investigations
  • computerized-system incidents

The risk statement should describe a meaningful Quality failure.

8. Writing Better Risk Statements

Weak

LIMS failure.

Better

Approved laboratory result may be transferred to ERP with an incorrect unit.

9. Risk Analysis

Risk analysis estimates or characterizes the identified risk.

Depending on the approved methodology, factors can include:

Severity

How serious would the consequence be?

Probability

How likely is the failure or sequence of events?

Detectability

Can the failure be detected before the relevant consequence occurs?

Not every QRM method must use all three factors.

ICH Q9 does not mandate one universal numerical formula.

Source context: ICH Q9(R1).

10. Severity

Severity should represent the consequence of the failure.

Example

Incorrect dashboard font:

Potential consequence: little or no impact to product quality.

Incorrect potency calculation used for batch disposition:

Potential consequence: inappropriate product disposition.

The complexity of the software does not determine severity.

11. Probability

Probability should use available knowledge whenever practical.

Potential evidence:

  • historical deviations
  • complaint rates
  • process capability
  • equipment history
  • supplier data
  • validation results
  • failure rates
  • scientific knowledge
  • production experience

Weak rationale

Probability = 2 because the team considers it unlikely.

Better rationale

One comparable transfer failure occurred across approximately 150,000 transactions during the previous 24 months, and automated reconciliation detected the failure before batch disposition.

Now the rating has a basis.

12. Detectability

Detectability concerns the ability of existing controls to identify the failure.

Example

Failure:

LIMS result is not transferred to ERP.

Control:

ERP reconciliation compares expected approved results against received transactions and generates an exception.

This improves the ability to detect the failure.

However:

“A human reviews it”

should not automatically receive a strong detectability rating.

The review must actually be capable of detecting the relevant failure.

13. Risk Evaluation

Risk evaluation compares the analyzed risk with defined acceptance criteria.

Possible conclusions include:

Acceptable

Existing controls are adequate.

Risk reduction required

Additional control is needed.

Additional information required

There is too much uncertainty to make a justified decision.

That third result is important.

QRM does not require every meeting to end with a definitive risk rating.

Sometimes the correct conclusion is:

We do not have enough information yet.

Source context: ICH Q9(R1).

14. Risk Control

Risk control asks:

What should we do about the risk?

It includes:

Risk Reduction

and

Risk Acceptance.

Source context: ICH Q9(R1).

15. Risk Reduction

Risk reduction can use different types of controls.

Technical controls

  • interlocks
  • access restrictions
  • alarms
  • automated calculations
  • reconciliation
  • system-enforced workflow
  • error handling
  • automated checks

Procedural controls

  • independent review
  • approval
  • SOP
  • training
  • manual verification

Monitoring controls

  • exception reports
  • process monitoring
  • audit-trail review
  • trending
  • periodic review

Controls should address the actual failure.

16. Worked Example: Electronic Batch Release

Failure

Unauthorized user releases a batch.

Potential impact

Batch may be released without required Quality authorization.

Controls

Role-based access

Only authorized Quality personnel receive release permission.

Workflow control

Release is blocked until required prerequisites are complete.

Electronic signature

Authorized user signs the disposition.

Audit trail

Release action is attributable.

Verification

Test:

ScenarioExpected result
Authorized Quality user with all prerequisites satisfiedRelease permitted
Warehouse userRelease blocked
Administrator without release roleRelease blocked
Missing required testRelease blocked
Required approval incompleteRelease blocked

The QRM result directly informs testing.

17. Risk Acceptance

Risk acceptance means that the remaining risk is considered acceptable according to defined criteria.

It does not mean:

We know the risk is unacceptable but have decided not to fix it.

Risk acceptance should consider:

  • remaining risk
  • effectiveness of controls
  • uncertainty
  • applicable requirements
  • scientific knowledge

The rationale should be documented proportionately.

Source context: ICH Q9(R1).

18. Risk Communication

Risk information should reach the people who need it.

Depending on the situation, this may include:

  • Quality
  • Manufacturing
  • Laboratory
  • Engineering
  • Validation
  • IT
  • Supply Chain
  • Supplier Quality
  • Regulatory
  • senior management

Communication occurs throughout QRM, not only when the risk assessment is completed.

Source context: ICH Q9(R1).

19. Risk Review

Risk is not static.

A risk assessment may need review after:

  • change
  • deviation
  • complaint
  • CAPA
  • audit
  • supplier issue
  • process trend
  • new scientific knowledge
  • regulatory change
  • software release
  • cybersecurity vulnerability
  • AI/model change

The review frequency and trigger should be appropriate to the risk.

Source context: ICH Q9(R1).

20. Formality in QRM

One of the most important Q9(R1) clarifications is that formality is a continuum, not simply “formal” versus “informal.” ICH identifies three useful considerations when deciding the level of formality:

Uncertainty

Importance

Complexity.

Higher levels of these factors generally support greater formality.

Source context: ICH Q9(R1).

21. Low-Formality Example

Change

Correct a spelling error in a report heading.

No:

  • calculation
  • data
  • workflow
  • interface
  • record meaning
  • approval

is affected.

A concise documented impact assessment may be sufficient.

A 30-row FMEA would add little value.

22. Higher-Formality Example

Change

Modify environmental-monitoring alert limits used for sterile manufacturing.

Potential implications include:

  • microbiological control
  • alert/action decisions
  • batch impact
  • investigations
  • trend analysis

Appropriate assessment may require:

  • Quality
  • Microbiology
  • Engineering
  • Manufacturing
  • Validation

and a more formal QRM activity.

23. Formality Decision Table

FactorLower formalityHigher formality
UncertaintyWell understoodSignificant unknowns
ImportanceLimited consequenceMajor Quality/patient consequence
ComplexitySimple relationshipMultiple interacting systems/processes
KnowledgeStrong historical evidenceLimited data
DecisionEasily reversibleDifficult or costly to reverse

The tool should fit the decision.

Uncertainty, importance and complexity are the three considerations identified in Q9(R1). The knowledge and reversibility rows are practical decision prompts in this guide, not additional named ICH factors.

24. Subjectivity in QRM

QRM involves judgment.

The goal is not to eliminate judgment but to control inappropriate subjectivity.

Potential sources include:

  • incomplete knowledge
  • individual experience
  • confirmation bias
  • organizational pressure
  • anchoring
  • poorly defined scoring criteria
  • desired project outcome

Source context: ICH Q9(R1).

25. Example of Risk-Score Manipulation

Suppose the organization’s threshold is:

Risk score ≥15 requires formal mitigation.

Assessment:

Severity = 5 Probability = 3

Score = 15.

Someone argues:

Probability should really be 2.

New score:

5 × 2 = 10.

Nothing about the actual failure changed.

If the rating was adjusted primarily to avoid mitigation, the risk matrix has become a decision-justification tool rather than a QRM tool.

26. Reducing Subjectivity

Practical controls include:

  • clearly defined criteria
  • multidisciplinary participation
  • objective data
  • scientific evidence
  • documented assumptions
  • independent challenge
  • experienced facilitation
  • periodic reassessment

Ask:

Would another qualified team understand why we reached this conclusion?

Source context: ICH Q9(R1).

27. Risk-Based Decision Making

QRM should inform actual decisions.

Examples include:

Validation

What testing is needed?

Change control

What is affected?

Deviation

How significant is the event?

CAPA

How much investigation and corrective action are warranted?

Supplier management

How much supplier oversight is appropriate?

Audit

Where should audit resources be focused?

Process validation

Which variables and failure modes require greater attention?

Source context: ICH Q9(R1).

28. Risk-Based Decision Making Does Not Mean Risk-Based Compliance

QRM should not be used to justify a practice that is otherwise unacceptable under applicable requirements. ICH explicitly cautions that QRM facilitates decisions but does not remove the obligation to comply with regulatory requirements.

Example:

“Electronic records are low risk, therefore we do not need required controls.”

is not appropriate QRM.

Risk determines how controls and evidence are applied within the applicable regulatory framework.

Source context: ICH Q9(R1).

29. Product Availability

Q9(R1) explicitly recognizes that manufacturing Quality problems can affect product availability and ultimately harm patients.

Example

A single qualified supplier provides a critical sterile component.

Supplier Quality performance begins deteriorating.

Traditional assessment:

Can incoming inspection detect defective components?

Broader QRM assessment:

Could supplier failure interrupt production of a medically necessary product?

Possible controls:

  • supplier remediation
  • increased monitoring
  • inventory strategy
  • second-source qualification
  • capacity planning
  • business continuity

Quality and supply reliability can intersect.

Source context: ICH Q9(R1).

30. QRM and Pharmaceutical Development

QRM can help identify:

  • Critical Quality Attributes
  • Critical Process Parameters
  • material attributes
  • control strategy
  • areas requiring additional experimentation

FDA’s Q8/Q9/Q10 training material emphasizes the use of scientific rationale and QRM in establishing CQAs and CPPs and linking them to the control strategy.

Source context: FDA Q8/Q9/Q10 training questions and answers.

31. QRM and Process Validation

QRM can support:

  • validation planning
  • identification of critical variables
  • sampling strategy
  • monitoring
  • change evaluation
  • continued process verification

Example:

For a sterile filling process, QRM may identify:

fill volume

sterilization conditions

environmental controls

line interventions

as areas requiring different levels of control and verification.

32. QRM and Cleaning Validation

Situation

Shared manufacturing equipment.

Risk question

Could residue from Product A contaminate Product B at a level that affects product quality or patient safety?

Consider:

  • potency
  • toxicity
  • solubility
  • cleanability
  • equipment design
  • batch sequence
  • analytical capability

Controls can include:

  • cleaning process
  • validated cleaning parameters
  • inspection
  • analytical testing
  • campaign controls

33. QRM and Deviations

Example

Cold-room temperature exceeds the approved limit for 18 minutes.

Do not automatically conclude:

Temperature excursion = batch rejection.

Assess:

  • actual temperature
  • duration
  • product location
  • product stability
  • packaging
  • monitoring accuracy
  • historical data
  • scientific evidence

The Quality decision should follow the evidence.

34. QRM and CAPA

QRM can support:

  • investigation depth
  • action priority
  • escalation
  • effectiveness-check rigor

But QRM should not be used to avoid CAPA when systemic corrective action is warranted.

Example

One isolated data-entry error with immediate detection may require correction and local action.

Repeated data-entry failures caused by poor interface design may indicate a systemic issue requiring CAPA.

35. QRM and Supplier Management

Not every supplier requires the same oversight.

Consider:

  • material/service criticality
  • supplier performance
  • process complexity
  • detectability
  • alternatives
  • regulatory history
  • supply continuity

Example

Office stationery supplier:

low Quality relevance.

Sterilization provider:

high potential impact and higher oversight.

36. QRM and Computerized Systems

ICH Q9(R1) specifically recognizes the importance of QRM when applying digitalization, emerging technologies, advanced data analysis and computerized systems.

A practical computerized-system sequence is:

Intended Use → GxP Function → Failure Scenario → Potential Impact → Existing Controls → Existing Evidence → Additional Testing → Validation Conclusion

This is a practitioner connection to risk-based software assurance. ICH Q9(R1) addresses pharmaceutical quality; FDA’s CSA guidance has its own medical-device production and quality-system scope.

Source context: ICH Q9(R1).

37. Worked Example: GxP Spreadsheet

Intended use

Calculate cleaning-agent concentration.

Failure

Formula calculates incorrect concentration.

Potential impact

Cleaning solution may be outside the validated range.

Existing controls

  • controlled template
  • protected formulas
  • restricted editing
  • independent verification

Testing

  • normal calculation
  • boundary values
  • invalid inputs
  • known calculation
  • protected-cell challenge

The risk is based on the intended use.

Not:

Does the spreadsheet contain macros?