Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Quality Assurance

Checklist: PQS Annual Self-Assessment Against ICH Q10 Elements

A plug-and-play annual self-assessment checklist that scores your pharmaceutical quality system against all four ICH Q10 elements and both enablers, with pass criteria, evidence to capture, a maturity rating, a filled specimen, and the regulations it satisfies.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use annual self-assessment for the pharmaceutical quality system, scored against all four ICH Q10 elements (process performance and product quality monitoring, CAPA, change management, management review) and the two enablers (knowledge management, quality risk management). Run it site-wide, or once per major product line if your PQS is not uniform across products. Replace every <<FILL: ...>> placeholder, capture the evidence named in each row, and record a result of Pass, Gap, or N/A, then rate the maturity level. A worked filled specimen follows. Verify each cited regulation against the current source before you rely on it.

Document control header

FieldEntry
Document titlePQS Annual Self-Assessment Against ICH Q10 Elements
Document number<<FILL: CHK-ID, e.g. CHK-QA-020>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Document owner<<FILL: role, e.g. Head of Quality>>
Applies to<<FILL: site(s) / product line(s) in scope>>

How to use this checklist

  1. For each element and enabler, decide Pass, Gap, or N/A on every line, and record where the evidence is (record reference, report, meeting minutes). A “Pass” with no evidence is not a pass.
  2. Log every Gap in the gap summary with a risk rating and an owner.
  3. Rate the maturity level (Reactive, Defined, Managed, Optimizing) for each element and enabler based on the evidence, not on what the governing SOP claims to target. See pharmaceutical quality system for the definitions behind each level.
  4. The assessment supports management review; present the overall result and any open high-risk gaps at the next scheduled review.
  5. Re-run annually and after any material restructuring of the quality system.

Scoring legend:

  • Pass: control is in place and evidence supports it.
  • Gap: control is missing, partial, or unevidenced. Must be logged and rated.
  • N/A: line does not apply to this scope (state why).

Maturity levels (rate once per element/enabler, using the strongest supporting evidence, not the aspiration):

  • Reactive: exists on paper; activates only after a failure forces it to.
  • Defined: runs on schedule with assigned owners, but decisions are inconsistent across reviewers.
  • Managed: runs on schedule, decisions are consistent, and outputs feed the other elements.
  • Optimizing: used to drive improvement ahead of failure, not just to stay compliant.

Assessment context

FieldEntry
Site / product line<<FILL>>
Assessment period covered<<FILL: e.g. calendar year 2026>>
Assessor(s) (name, date)<<FILL>>

1. Process performance and product quality monitoring

#CheckPass criterionEvidence to captureResult
M1Parameters trace to criticalityMonitored CPPs/CQAs trace to the control strategy and risk assessmentMonitoring plan; risk assessment cross-reference<<FILL>>
M2Alert and action limits definedLimits are documented, tighter than specification, and statistically derivedLimit derivation record<<FILL>>
M3Reviews occur on scheduleTrend reviews happened at the defined cadence for the full periodReview records / meeting minutes<<FILL>>
M4Limit crossings generate actionEvery documented alert/action crossing has a traceable follow-upDeviation/CAPA cross-reference<<FILL>>
M5Output feeds management review and PQRTrend summaries appear in management review minutes and the annual product reviewManagement review minutes; PQR<<FILL>>

Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>

2. CAPA

#CheckPass criterionEvidence to captureResult
C1Root cause supported by evidenceSampled CAPAs show a structured root cause method, not “operator error” aloneCAPA records sample<<FILL>>
C2Effectiveness checks defined and closedEvery closed CAPA has an objective metric, a measurement window, and a documented resultEffectiveness check register<<FILL>>
C3No hollow closuresSampled effectiveness checks are not closed on “no recurrence noted” with no metric or windowCAPA record sample<<FILL>>
C4Repeat-event rate trackedThe rate of recurring problems after CAPA closure is trended, not assumed to be zeroTrend report<<FILL>>

Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>

3. Change management

#CheckPass criterionEvidence to captureResult
CH1No undocumented changesSampled systems/processes show no gap between the qualified/validated baseline and the current stateChange control log vs system configuration<<FILL>>
CH2Impact assessment is genuineImpact assessments address product, process, validation, and regulatory filing, not a checkboxChange record sample<<FILL>>
CH3Established conditions identified where applicableFor products with a Q12-style filing, established conditions are documented and distinguished from supporting informationEstablished conditions list / regulatory filing cross-reference<<FILL>>
CH4Closure verifiedChanges are verified as implemented as intended before closure, not closed on approval aloneChange record verification evidence<<FILL>>

Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>

4. Management review

#CheckPass criterionEvidence to captureResult
R1Defined frequency metReviews occurred at the frequency the governing procedure requiresMeeting schedule vs minutes<<FILL>>
R2Decision-makers presentAttendees include people with authority to allocate resources, not delegates onlyAttendance record<<FILL>>
R3Decisions recorded, not just attendanceMinutes show specific decisions, owners, and due datesMeeting minutes<<FILL>>
R4Prior actions tracked to closureActions from the previous review appear with status in the current reviewAction tracker<<FILL>>

Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>

5. Knowledge management (enabler)

#CheckPass criterionEvidence to captureResult
K1Knowledge captured at the sourceInvestigations, transfers, and departures generate retrievable knowledge entries, not only informal handoffKnowledge management log<<FILL>>
K2Knowledge queried before decisionsTechnology transfer, major change, and risk assessment procedures require a check of prior knowledgeProcedure text; sample query evidence<<FILL>>
K3Cross-system learning demonstratedAt least one example exists of a finding on one system or process protecting another before recurrenceKnowledge log entry linked to a proactive risk assessment update<<FILL>>

Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>

6. Quality risk management (enabler)

#CheckPass criterionEvidence to captureResult
Q1Risk assessments use a consistent, documented methodSampled risk assessments (FMEA or equivalent) follow a defined, ICH Q9(R1)-aligned methodRisk assessment sample<<FILL>>
Q2Risk drives effort allocationHigher-risk systems and changes receive visibly more scrutiny than lower-risk onesComparison of monitoring/review intensity across risk tiers<<FILL>>
Q3Risk register is current and reviewedThe quality risk register is reviewed on a defined cadence and reflects current, not historical, riskQuality risk register with review dates<<FILL>>
Q4Subjectivity is controlledRisk ratings are calibrated across assessors (for example through a shared scoring guide or peer check)Calibration record or scoring guide<<FILL>>

Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>

Gap summary

Gap refElement/enablerCheck #DescriptionRisk (H/M/L)OwnerRemediation / due dateStatus
<<FILL: G1>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

Overall result

Element / enablerLines PassLines GapMaturity level
Process performance and product quality monitoring<<FILL>><<FILL>><<FILL>>
CAPA<<FILL>><<FILL>><<FILL>>
Change management<<FILL>><<FILL>><<FILL>>
Management review<<FILL>><<FILL>><<FILL>>
Knowledge management<<FILL>><<FILL>><<FILL>>
Quality risk management<<FILL>><<FILL>><<FILL>>
FieldEntry
Highest open risk<<FILL: H / M / L>>
Overall verdictPass / Conditional (gaps with plan) / Fail
Assessor (name, signature, date)<<FILL>>
QA review (name, signature, date)<<FILL>>
Presented to management review on<<FILL: date>>

References

ICH Q10, Pharmaceutical Quality System (2008), for the four elements and two enablers assessed here. ICH Q9(R1), Quality Risk Management, for the risk management enabler. ICH Q12, Technical and Regulatory Considerations for Pharmaceutical Product Lifecycle Management, for established conditions. 21 CFR 211.180(e) (annual review of records).

Confirm the current version of each reference before issue.

Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Filled specimen

The following shows part of a completed assessment for an illustrative mid-size biologics site, so you can see the level of detail expected. Site, references, and findings are illustrative; replace them with your own.

Assessment context:

FieldEntry
Site / product lineIllustrative biologics drug product site, Product Y
Assessment period coveredCalendar year 2026
Assessor(s) (name, date)R. Kowalski, QA Systems, 15 Aug 2026

Sample of completed lines:

#CheckResultEvidence / note
M4Limit crossings generate actionPass3 of 3 sampled alert crossings traced to a deviation
C3No hollow closuresGap2 of 8 sampled CAPAs closed on “no recurrence noted” with no measurement window
CH1No undocumented changesPassSampled CDS configuration matches the change control log for the period
K2Knowledge queried before decisionsGapTechnology transfer procedure does not reference the knowledge management log
Q3Risk register is current and reviewedPassRegister reviewed quarterly; last review 10 Jul 2026

Maturity ratings assigned: Process monitoring, Managed. CAPA, Defined (pulled down by the hollow-closure gap). Change management, Managed. Management review, Managed. Knowledge management, Reactive (no query requirement built into procedures). Quality risk management, Managed.

Gap summary:

Gap refElement/enablerCheck #DescriptionRiskOwnerRemediation / due dateStatus
G1CAPAC3Effectiveness checks closed without a measurement window on 2 of 8 sampled CAPAsMCAPA Program LeadRetrain CAPA owners; reopen the 2 checks with a defined window; CAPA-2026-0091Open
G2Knowledge managementK2Technology transfer SOP does not require a knowledge log queryLQuality SystemsAdd step to SOP-TT-002 at next revisionOpen

Overall verdict: Conditional. No high-risk gaps open; two medium/low gaps with dispositioned plans. Presented to the Q3 2026 management review, which funded the CAPA owner retraining. That is the honest picture a self-assessment should produce: mostly Managed, one enabler still Reactive, with named owners and dates rather than a clean sheet.

Common inspection findings this checklist prevents

  • A site can describe the four Q10 elements in an interview but has never formally scored its own system against them with evidence.
  • CAPA effectiveness checks are closed without a measurement window, a gap that only surfaces when an inspector samples records, not when the site last looked.
  • Knowledge management is treated as informal handoff with no register and no query requirement, so the same failure recurs on a related system.
  • A self-assessment exists but shows all “Pass” with no gaps, which itself reads as a paper exercise rather than a genuine review.
  • Maturity is assumed uniform across elements when the evidence shows real variation, and the weakest element is exactly where the next finding originates.

How to adapt this checklist

  1. Set your document number, owner, and effective date in the header.
  2. Adjust the sample size behind each check to your site’s actual record volume; a large site should sample more than three CAPAs per line.
  3. Feed every open gap into your real CAPA or action-tracking system, not just the table here, so remediation is tracked and effectiveness is verified.
  4. Present the overall result and any high-risk gaps at management review, so the assessment itself demonstrates the management review element working.
  5. Confirm every regulation in the references against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.