Complex assurance scenario
SaaS eQMS with weekly releases
A risk-based release decision when software cannot be frozen.
Context
A global quality organization uses a multi-tenant eQMS for deviations and CAPA. The supplier deploys weekly and exposes release notes five days before production.
Intended Use
Create, investigate, approve, retain, and retrieve controlled deviation and CAPA records.
Boundary
Configured workflows, identity federation, notifications, reporting, exports, audit trails, and the customer release-intelligence process.
Failure Chain
A shared component changes → approval state is displayed incorrectly → reviewer acts on stale status → an incomplete investigation is approved.
Existing Controls
- Vendor SDLC and automated regression
- Configuration inventory
- Role-based access
- Audit trails
- Daily exception reporting
Evidence
- Supplier release note and defect summary
- Configuration comparison
- Targeted workflow challenge
- Production monitoring trend
Evidence Gaps
Release notes do not state whether the shared record-view component changed.
Test Design
Time-boxed exploratory charter across long records, parallel edits, approval transitions, audit trail, and browser variants; script the approval-state control points.
Decision
Permit release with targeted evidence and intensified seven-day monitoring; no broad regression.
Residual Risk
An undocumented supplier change may affect an uncommon browser or record state.
Monitoring
Approval exception rate, client errors, audit-trail discrepancies, and help-desk signals.
Reassessment Triggers
- Critical supplier incident
- Workflow or identity configuration change
- Monitoring threshold breach
Inspection Questions
- How was impact determined?
- Why was broad regression unnecessary?
- How are silent changes detected?