Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Quality Assurance

Checklist: Human Error Classification and Hierarchy of Controls CAPA Selection

A plug-and-play checklist for classifying a human-involved deviation as a slip, lapse, rule-based mistake, knowledge-based mistake, or violation, applying the human-error filter, identifying the failed barrier, and selecting a CAPA at the highest reasonable rank on the hierarchy of controls, with a block on retrain-only closures.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use checklist. Replace every <<FILL: ...>> placeholder with your own specifics and attach it to the deviation or investigation record once a candidate root cause involves a person’s action. A worked filled specimen follows the template. This tool classifies the error’s type, for CAPA design, not the person’s culpability. For the separate accountability question, honest error versus at-risk behavior versus falsification versus fraud, use the complementary Work instruction: just-culture classification of a data integrity event; use both together, this checklist first to shape a sound CAPA, the just-culture tool alongside it if an accountability decision is also needed. It is an educational aid to adapt and verify, not legal or disciplinary advice.

Document control header

FieldEntry
Document titleHuman Error Classification and Hierarchy of Controls CAPA Selection
Document number<<FILL: CHK-ID, e.g. CHK-QA-034>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Linked SOP<<FILL: deviation / investigation SOP-ID>>
Used by<<FILL: role, e.g. investigation owner, confirmed by QA>>

Purpose and when to use

Once an investigation has a candidate cause that involves a person’s action, this checklist forces four things in sequence: name the error type, apply the human-error filter, identify the barrier that failed or was missing, and select a corrective action at the highest reasonable rank on the hierarchy of controls. Use it after the timeline and evidence are assembled and before the CAPA is drafted, so the CAPA is built from the classification rather than reached for out of habit. See Human error in deviations for the full reasoning behind each step.

Section 1: Classify the error type

Work through every row. Mark Pass where the marker described is present and supported by evidence in this event, Fail where it is ruled out, and NA where the question does not apply (for example, there was no procedure step at all to apply incorrectly). More than one row can legitimately Pass; record the primary type and any secondary contributing type.

MarkerPass / Fail / NAEvidence
Slip: right intention, wrong action, an attention failure during a routine, well-practiced task<<FILL>><<FILL>>
Lapse: right intention, a step was forgotten, a memory failure<<FILL>><<FILL>>
Rule-based mistake: the person applied a plausible procedure or rule, but it was the wrong one for this situation<<FILL>><<FILL>>
Knowledge-based mistake: no applicable rule existed; the person reasoned through an unfamiliar situation and got it wrong<<FILL>><<FILL>>
Routine violation: a deliberate departure from the written method that has become normal practice because the official way is impractical<<FILL>><<FILL>>
Situational violation: a deliberate departure forced by an immediate condition (broken tool, no coverage, no safe alternative)<<FILL>><<FILL>>

Primary error type identified: <<FILL>> Secondary or contributing type, if any: <<FILL: or "none">>

Section 2: Apply the human-error filter

Work through all six questions in order; do not skip ahead to a conclusion. Mark Pass when the answer points to a systemic or conditions-based factor, Fail when that factor is genuinely ruled out by the evidence.

#Filter questionPass / FailEvidence
1Substitution test: would a different, competent, well-rested person have plausibly made the same error under the same conditions?<<FILL>><<FILL>>
2Ease-of-error test: could the task have been done wrong easily, that is, are the right and wrong actions one keystroke apart, look alike, or physically interchangeable?<<FILL>><<FILL>>
3Barrier test: should a second check, a system validation, or a review have caught this, and did that barrier fail or was it absent?<<FILL>><<FILL>>
4Procedure test: was there a deficiency in the procedure (out of date, ambiguous, unavailable, or physically impossible to follow as written)?<<FILL>><<FILL>>
5Violation test: if this was a departure from the written method, is it a routine or situational violation driven by an impractical procedure or forcing conditions, rather than an isolated personal choice?<<FILL>><<FILL>>
6Repeat test: has this same or a materially similar error occurred before, especially involving a different person?<<FILL>><<FILL>>

Rule: if any item above is marked Pass, at least part of the cause is systemic and the CAPA in Section 4 must include a system-level action; retraining alone is not an acceptable closure. Only if all six items are marked Fail may a narrow, individual human-performance cause be considered, and even then the CAPA is a new or strengthened barrier, never retraining alone.

Filter outcome: <<FILL: at least one Pass, systemic factor confirmed / all six Fail, narrow performance cause considered>>

Section 3: Identify the barrier that failed or was missing

List every control that should reasonably have caught this error before it reached product, a record, or a downstream step. A blank row with no status looks like the barrier was never considered; mark every plausible barrier even to rule it out.

BarrierExpected to catch this error?Status (present and worked / present but failed / missing entirely)Evidence
Procedure step or check<<FILL>><<FILL>><<FILL>>
Second-person verification<<FILL>><<FILL>><<FILL>>
System-enforced field, validation, or interlock<<FILL>><<FILL>><<FILL>>
Line clearance or changeover gate<<FILL>><<FILL>><<FILL>>
Supervisory or QA review<<FILL>><<FILL>><<FILL>>
Alarm or system prompt<<FILL>><<FILL>><<FILL>>
Other: <<FILL>><<FILL>><<FILL>><<FILL>>

Primary barrier that failed or was missing (the target for CAPA): <<FILL>>

Section 4: Select the CAPA at the highest reasonable rank

Evaluate every rank from the top down before settling on a lower one. Record why each higher rank was or was not used; do not skip straight to Rank 5.

RankControl typeWhat it would look like for this eventEvaluated: feasible / infeasible, whySelected?
1 (strongest)Eliminate: remove the error opportunity entirely<<FILL>><<FILL>><<FILL: Y/N>>
2Substitute / engineer out: make the wrong action physically or systematically impossible<<FILL>><<FILL>><<FILL: Y/N>>
3Forcing function / poka-yoke: the system refuses to proceed until the step is done right<<FILL>><<FILL>><<FILL: Y/N>>
4Detection: catch the error immediately, before it reaches product or the record is used<<FILL>><<FILL>><<FILL: Y/N>>
5 (weakest)Administrative / training: procedure update, retraining, reminders<<FILL>><<FILL>><<FILL: Y/N>>

The retrain-only block

Retraining may not be the sole corrective action unless every item below is true and documented. If any box is unchecked, go back to Section 4 and select a higher-rank action instead, or pair the training with one.

  • Ranks 1 through 4 were genuinely evaluated for this specific error and found infeasible, already at maximum practical strength, or disproportionate to the risk, with the reason recorded above, not just asserted.
  • Section 1 and Section 2 support a genuine knowledge-based or rule-based gap (not a slip, lapse, or violation) as the primary or a material contributing type.
  • The specific knowledge or rule gap is named (what the person did not know, or which rule was missing or unclear), not just “needs more training.”
  • A higher-rank action is not being deferred for cost, schedule, or convenience reasons dressed up as infeasibility.
  • If retraining is used, it is paired with the deficient element it targets (a corrected SOP, a clarified decision aid, an updated competency assessment), not delivered against the same material that already failed to prevent the error.

Final CAPA selected (rank and description): <<FILL>> If Rank 5 (administrative/training) is any part of the CAPA, is the block above fully satisfied and documented? <<FILL: Yes / No, if No this CAPA is not acceptable as drafted>>

Acceptance criteria

A completed classification and CAPA selection is acceptable when all of the following are true:

  • Section 1 names a primary error type; the record does not say “human error” or “operator error” as the type.
  • All six Section 2 filter questions were worked and recorded, in order, with evidence, not assumed.
  • Section 3 identifies at least one specific barrier that failed or was missing, tied to this event.
  • Section 4 shows every rank was genuinely evaluated top-down, with a documented reason for each rank not selected.
  • If the CAPA includes retraining, the retrain-only block is fully checked and documented; otherwise retraining is paired with a higher-rank action or not used at all.
  • The completed checklist is signed and dated, and referenced from the deviation or investigation record.

References

21 CFR 211.192 (thorough investigation of discrepancies and failures). ICH Q9(R1), Quality Risk Management (risk-based investigation depth and CAPA selection; subjectivity in risk decisions). ICH Q10, Pharmaceutical Quality System (CAPA and effectiveness within the quality system). The human-error taxonomy (slip, lapse, mistake, violation) developed in James Reason’s human-error research, and the skill-, rule-, and knowledge-based performance model developed by Jens Rasmussen. Poka-yoke (mistake-proofing) as developed by Shigeo Shingo, applied here as the hierarchy-of-controls framing borrowed from occupational safety practice.

Confirm the current version of each reference before you rely on it.

Record generated: classification and CAPA-selection record

FieldEntry
Deviation / investigation reference<<FILL>>
Event summary (one line, factual)<<FILL>>
Primary error type<<FILL>>
Filter outcome (systemic factor confirmed / narrow performance cause)<<FILL>>
Primary barrier that failed or was missing<<FILL>>
CAPA rank selected and description<<FILL>>
Retrain-only block satisfied (if applicable)<<FILL: Yes / No / N/A>>
Completed by (name, signature, date)<<FILL>>
QA concurrence (name, signature, date)<<FILL>>

Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Approvals

RoleNameSignatureDate
Author<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality Head)<<FILL>>

Filled specimen

The following shows the checklist completed for an example event, so you can see the level of detail expected. The company and numbers are illustrative; replace them with your own.

Event: A QA second-person reviewer signed the calculation-verification step on a batch record without independently recalculating the value. The recorded yield calculation contained a decimal-placement error, which was not caught at the time and was only found at a later final review, one step before disposition.

Section 1: Classify the error type

MarkerPass / FailEvidence
SlipFailNot an attention slip; the reviewer did not attempt the calculation at all.
LapseFailNothing was forgotten; the sign-off itself was completed as normal.
Rule-based mistakeFailNo wrong rule was applied.
Knowledge-based mistakeFailThe reviewer knew how to recalculate; this was not a reasoning failure.
Routine violationPassInterviews of three reviewers on this line confirmed independent recalculation is routinely skipped when the shift is behind schedule; this reviewer did what peers normally do.
Situational violationNANot applicable; the shortcut is normal practice, not a one-time forced departure.

Primary error type identified: Routine violation.

Section 2: Apply the human-error filter

#QuestionPass / FailEvidence
1Substitution testPassAll three reviewers interviewed described skipping independent recalculation under time pressure; any of them could have signed this record.
2Ease-of-error testPassThe sign-off field does not distinguish “recalculated independently” from “reviewed the displayed number,” so a rubber-stamp sign-off looks identical to a real verification.
3Barrier testPassSecond-person verification is the only barrier for this calculation and it failed for this record.
4Procedure testFailThe SOP correctly requires independent recalculation; the procedure itself is not deficient.
5Violation testPassConfirmed routine, schedule-driven, not this reviewer’s isolated choice.
6Repeat testPassA retrospective sample of 20 recent calculation sign-offs found 6 with no evidence of independent recalculation.

Filter outcome: At least one Pass; systemic factor confirmed.

Section 3: Identify the barrier that failed or was missing

BarrierExpected to catch this error?StatusEvidence
Second-person verification (manual recalculation)YesPresent but failedSign-off field does not require or capture the independent value.
System-enforced field or validationYes, if it existedMissing entirelyThe calculation is manual on a paper worksheet; no system performs or checks it.

Primary barrier: No system-enforced calculation or independent-value check exists; the manual second-person verification step is indistinguishable from a rubber-stamp sign-off.

Section 4: Select the CAPA

RankEvaluatedSelected?
1, EliminateThe calculation cannot be removed; it is required to determine yield. Not feasible.N
2, Substitute / engineer outMove the calculation into the electronic batch record system so it is computed automatically from entered values, removing manual arithmetic entirely. Feasible.Y
3, Forcing functionUntil the system change is live, require the second reviewer to enter their own independently calculated value into a dedicated field that the system compares to the first entry and flags any mismatch. Feasible as an interim control.Y (interim)
4, DetectionNot needed as primary; superseded by ranks 2 and 3.N
5, AdministrativeReissue the SOP reminding reviewers to recalculate independently. Considered insufficient alone; the retrospective sample shows the current SOP requirement is already not being followed.N (not sole action)

Retrain-only block: Not applicable as drafted; retraining is not the CAPA. If a training element is added, it accompanies the ranks 2 and 3 actions above, not in place of them.

Final CAPA: Rank 2, automate the yield calculation in the electronic batch record (primary); Rank 3 interim, dual independent-entry with system mismatch flag until the system change is validated and live. Effectiveness check: zero unflagged calculation discrepancies across the next defined number of batches after the interim control is live, and confirmation the automated calculation is in production use.

Common inspection findings this checklist prevents

  • A deviation closed as “human error” or “reviewer error” with no error-type classification recorded.
  • A second-person review step that exists on paper but is shown, on inspection, to be a rubber stamp with no independent check actually performed.
  • Retraining used as the sole corrective action for a routine violation, without checking whether the shortcut is normal practice across the team.
  • A CAPA selected at the administrative rank with no documented evaluation of stronger controls.
  • No barrier analysis, so the corrective action does not target the specific control that failed.

How to adapt this checklist

  1. Set your document number, linked SOP, and effective date in the header.
  2. Use this checklist after your investigation has a candidate human-involved cause and before CAPA is finalized; it is a companion to your root-cause tool, not a replacement for it.
  3. If your organization uses different names for violation categories or barrier types, map them onto Sections 1 and 3 and keep the sequence.
  4. Keep the retrain-only block mandatory; it is the part of the tool that stops the reflex administrative closure.
  5. Confirm every regulation in the references against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.