This is a ready-to-use annual self-assessment for the pharmaceutical quality system, scored against all four ICH Q10 elements (process performance and product quality monitoring, CAPA, change management, management review) and the two enablers (knowledge management, quality risk management). Run it site-wide, or once per major product line if your PQS is not uniform across products. Replace every <<FILL: ...>> placeholder, capture the evidence named in each row, and record a result of Pass, Gap, or N/A, then rate the maturity level. A worked filled specimen follows. Verify each cited regulation against the current source before you rely on it.
Document control header
| Field | Entry |
|---|---|
| Document title | PQS Annual Self-Assessment Against ICH Q10 Elements |
| Document number | <<FILL: CHK-ID, e.g. CHK-QA-020>> |
| Version | <<FILL: version, e.g. 1.0>> |
| Effective date | <<FILL: effective date>> |
| Document owner | <<FILL: role, e.g. Head of Quality>> |
| Applies to | <<FILL: site(s) / product line(s) in scope>> |
How to use this checklist
- For each element and enabler, decide Pass, Gap, or N/A on every line, and record where the evidence is (record reference, report, meeting minutes). A “Pass” with no evidence is not a pass.
- Log every Gap in the gap summary with a risk rating and an owner.
- Rate the maturity level (Reactive, Defined, Managed, Optimizing) for each element and enabler based on the evidence, not on what the governing SOP claims to target. See pharmaceutical quality system for the definitions behind each level.
- The assessment supports management review; present the overall result and any open high-risk gaps at the next scheduled review.
- Re-run annually and after any material restructuring of the quality system.
Scoring legend:
- Pass: control is in place and evidence supports it.
- Gap: control is missing, partial, or unevidenced. Must be logged and rated.
- N/A: line does not apply to this scope (state why).
Maturity levels (rate once per element/enabler, using the strongest supporting evidence, not the aspiration):
- Reactive: exists on paper; activates only after a failure forces it to.
- Defined: runs on schedule with assigned owners, but decisions are inconsistent across reviewers.
- Managed: runs on schedule, decisions are consistent, and outputs feed the other elements.
- Optimizing: used to drive improvement ahead of failure, not just to stay compliant.
Assessment context
| Field | Entry |
|---|---|
| Site / product line | <<FILL>> |
| Assessment period covered | <<FILL: e.g. calendar year 2026>> |
| Assessor(s) (name, date) | <<FILL>> |
1. Process performance and product quality monitoring
| # | Check | Pass criterion | Evidence to capture | Result |
|---|---|---|---|---|
| M1 | Parameters trace to criticality | Monitored CPPs/CQAs trace to the control strategy and risk assessment | Monitoring plan; risk assessment cross-reference | <<FILL>> |
| M2 | Alert and action limits defined | Limits are documented, tighter than specification, and statistically derived | Limit derivation record | <<FILL>> |
| M3 | Reviews occur on schedule | Trend reviews happened at the defined cadence for the full period | Review records / meeting minutes | <<FILL>> |
| M4 | Limit crossings generate action | Every documented alert/action crossing has a traceable follow-up | Deviation/CAPA cross-reference | <<FILL>> |
| M5 | Output feeds management review and PQR | Trend summaries appear in management review minutes and the annual product review | Management review minutes; PQR | <<FILL>> |
Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>
2. CAPA
| # | Check | Pass criterion | Evidence to capture | Result |
|---|---|---|---|---|
| C1 | Root cause supported by evidence | Sampled CAPAs show a structured root cause method, not “operator error” alone | CAPA records sample | <<FILL>> |
| C2 | Effectiveness checks defined and closed | Every closed CAPA has an objective metric, a measurement window, and a documented result | Effectiveness check register | <<FILL>> |
| C3 | No hollow closures | Sampled effectiveness checks are not closed on “no recurrence noted” with no metric or window | CAPA record sample | <<FILL>> |
| C4 | Repeat-event rate tracked | The rate of recurring problems after CAPA closure is trended, not assumed to be zero | Trend report | <<FILL>> |
Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>
3. Change management
| # | Check | Pass criterion | Evidence to capture | Result |
|---|---|---|---|---|
| CH1 | No undocumented changes | Sampled systems/processes show no gap between the qualified/validated baseline and the current state | Change control log vs system configuration | <<FILL>> |
| CH2 | Impact assessment is genuine | Impact assessments address product, process, validation, and regulatory filing, not a checkbox | Change record sample | <<FILL>> |
| CH3 | Established conditions identified where applicable | For products with a Q12-style filing, established conditions are documented and distinguished from supporting information | Established conditions list / regulatory filing cross-reference | <<FILL>> |
| CH4 | Closure verified | Changes are verified as implemented as intended before closure, not closed on approval alone | Change record verification evidence | <<FILL>> |
Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>
4. Management review
| # | Check | Pass criterion | Evidence to capture | Result |
|---|---|---|---|---|
| R1 | Defined frequency met | Reviews occurred at the frequency the governing procedure requires | Meeting schedule vs minutes | <<FILL>> |
| R2 | Decision-makers present | Attendees include people with authority to allocate resources, not delegates only | Attendance record | <<FILL>> |
| R3 | Decisions recorded, not just attendance | Minutes show specific decisions, owners, and due dates | Meeting minutes | <<FILL>> |
| R4 | Prior actions tracked to closure | Actions from the previous review appear with status in the current review | Action tracker | <<FILL>> |
Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>
5. Knowledge management (enabler)
| # | Check | Pass criterion | Evidence to capture | Result |
|---|---|---|---|---|
| K1 | Knowledge captured at the source | Investigations, transfers, and departures generate retrievable knowledge entries, not only informal handoff | Knowledge management log | <<FILL>> |
| K2 | Knowledge queried before decisions | Technology transfer, major change, and risk assessment procedures require a check of prior knowledge | Procedure text; sample query evidence | <<FILL>> |
| K3 | Cross-system learning demonstrated | At least one example exists of a finding on one system or process protecting another before recurrence | Knowledge log entry linked to a proactive risk assessment update | <<FILL>> |
Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>
6. Quality risk management (enabler)
| # | Check | Pass criterion | Evidence to capture | Result |
|---|---|---|---|---|
| Q1 | Risk assessments use a consistent, documented method | Sampled risk assessments (FMEA or equivalent) follow a defined, ICH Q9(R1)-aligned method | Risk assessment sample | <<FILL>> |
| Q2 | Risk drives effort allocation | Higher-risk systems and changes receive visibly more scrutiny than lower-risk ones | Comparison of monitoring/review intensity across risk tiers | <<FILL>> |
| Q3 | Risk register is current and reviewed | The quality risk register is reviewed on a defined cadence and reflects current, not historical, risk | Quality risk register with review dates | <<FILL>> |
| Q4 | Subjectivity is controlled | Risk ratings are calibrated across assessors (for example through a shared scoring guide or peer check) | Calibration record or scoring guide | <<FILL>> |
Maturity level: <<FILL: Reactive / Defined / Managed / Optimizing>>, basis: <<FILL>>
Gap summary
| Gap ref | Element/enabler | Check # | Description | Risk (H/M/L) | Owner | Remediation / due date | Status |
|---|---|---|---|---|---|---|---|
<<FILL: G1>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
Overall result
| Element / enabler | Lines Pass | Lines Gap | Maturity level |
|---|---|---|---|
| Process performance and product quality monitoring | <<FILL>> | <<FILL>> | <<FILL>> |
| CAPA | <<FILL>> | <<FILL>> | <<FILL>> |
| Change management | <<FILL>> | <<FILL>> | <<FILL>> |
| Management review | <<FILL>> | <<FILL>> | <<FILL>> |
| Knowledge management | <<FILL>> | <<FILL>> | <<FILL>> |
| Quality risk management | <<FILL>> | <<FILL>> | <<FILL>> |
| Field | Entry |
|---|---|
| Highest open risk | <<FILL: H / M / L>> |
| Overall verdict | Pass / Conditional (gaps with plan) / Fail |
| Assessor (name, signature, date) | <<FILL>> |
| QA review (name, signature, date) | <<FILL>> |
| Presented to management review on | <<FILL: date>> |
References
ICH Q10, Pharmaceutical Quality System (2008), for the four elements and two enablers assessed here. ICH Q9(R1), Quality Risk Management, for the risk management enabler. ICH Q12, Technical and Regulatory Considerations for Pharmaceutical Product Lifecycle Management, for established conditions. 21 CFR 211.180(e) (annual review of records).
Confirm the current version of each reference before issue.
Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
Filled specimen
The following shows part of a completed assessment for an illustrative mid-size biologics site, so you can see the level of detail expected. Site, references, and findings are illustrative; replace them with your own.
Assessment context:
| Field | Entry |
|---|---|
| Site / product line | Illustrative biologics drug product site, Product Y |
| Assessment period covered | Calendar year 2026 |
| Assessor(s) (name, date) | R. Kowalski, QA Systems, 15 Aug 2026 |
Sample of completed lines:
| # | Check | Result | Evidence / note |
|---|---|---|---|
| M4 | Limit crossings generate action | Pass | 3 of 3 sampled alert crossings traced to a deviation |
| C3 | No hollow closures | Gap | 2 of 8 sampled CAPAs closed on “no recurrence noted” with no measurement window |
| CH1 | No undocumented changes | Pass | Sampled CDS configuration matches the change control log for the period |
| K2 | Knowledge queried before decisions | Gap | Technology transfer procedure does not reference the knowledge management log |
| Q3 | Risk register is current and reviewed | Pass | Register reviewed quarterly; last review 10 Jul 2026 |
Maturity ratings assigned: Process monitoring, Managed. CAPA, Defined (pulled down by the hollow-closure gap). Change management, Managed. Management review, Managed. Knowledge management, Reactive (no query requirement built into procedures). Quality risk management, Managed.
Gap summary:
| Gap ref | Element/enabler | Check # | Description | Risk | Owner | Remediation / due date | Status |
|---|---|---|---|---|---|---|---|
| G1 | CAPA | C3 | Effectiveness checks closed without a measurement window on 2 of 8 sampled CAPAs | M | CAPA Program Lead | Retrain CAPA owners; reopen the 2 checks with a defined window; CAPA-2026-0091 | Open |
| G2 | Knowledge management | K2 | Technology transfer SOP does not require a knowledge log query | L | Quality Systems | Add step to SOP-TT-002 at next revision | Open |
Overall verdict: Conditional. No high-risk gaps open; two medium/low gaps with dispositioned plans. Presented to the Q3 2026 management review, which funded the CAPA owner retraining. That is the honest picture a self-assessment should produce: mostly Managed, one enabler still Reactive, with named owners and dates rather than a clean sheet.
Common inspection findings this checklist prevents
- A site can describe the four Q10 elements in an interview but has never formally scored its own system against them with evidence.
- CAPA effectiveness checks are closed without a measurement window, a gap that only surfaces when an inspector samples records, not when the site last looked.
- Knowledge management is treated as informal handoff with no register and no query requirement, so the same failure recurs on a related system.
- A self-assessment exists but shows all “Pass” with no gaps, which itself reads as a paper exercise rather than a genuine review.
- Maturity is assumed uniform across elements when the evidence shows real variation, and the weakest element is exactly where the next finding originates.
How to adapt this checklist
- Set your document number, owner, and effective date in the header.
- Adjust the sample size behind each check to your site’s actual record volume; a large site should sample more than three CAPAs per line.
- Feed every open gap into your real CAPA or action-tracking system, not just the table here, so remediation is tracked and effectiveness is verified.
- Present the overall result and any high-risk gaps at management review, so the assessment itself demonstrates the management review element working.
- Confirm every regulation in the references against the current published version before issue.