This is a ready-to-use checklist for assessing an existing QMS document hierarchy or designing a new one. It operationalizes the eight-step method of mapping requirements to processes, confirming a document exists at every tier for every process, and checking traceability in both directions. Run it as a structured self-inspection or as the first pass when standing up a QMS from scratch. Replace every <<FILL: ...>> placeholder, score each line, and treat any Fail as a gap to close, not a note to revisit someday. A worked filled specimen follows the template.
Document control header
| Field | Entry |
|---|---|
| Document title | QMS Document Hierarchy Gap Assessment |
| Document number | <<FILL: reference, e.g. GAP-QA-2026-03>> |
| Site / scope assessed | <<FILL>> |
| Date of assessment | <<FILL>> |
| Assessed by | <<FILL>> |
1. Purpose
This checklist confirms that a QMS document hierarchy is complete top to bottom: every applicable requirement is mapped to a process, every process has a current governing document at each tier that needs one, and the links between tiers hold in both directions. It surfaces exactly the gaps an inspector would find, so the company finds them first.
2. Assessment checklist
| # | Item | Evidence to check | Result (Pass/Fail/NA) | Comment |
|---|---|---|---|---|
| 1 | Every applicable regulation, standard, and guidance for this operation is identified and listed | Regulatory applicability assessment | <<FILL>> | |
| 2 | Every requirement from that list is mapped to a named QMS process | Requirement-to-procedure cross-reference matrix | <<FILL>> | |
| 3 | A current, approved quality policy exists, is signed by top management, and quality objectives trace back to it | Quality policy, objectives record | <<FILL>> | |
| 4 | A current quality manual (or equivalent, e.g. Site Master File) exists, describes the actual operation (not a generic restatement of a standard), and cross-references the governing procedures | Quality manual | <<FILL>> | |
| 5 | Every QMS process named in the manual has a current, approved tier 2 procedure with unambiguous roles | Tier 2 procedure set | <<FILL>> | |
| 6 | Every operational task that needs consistency has a tier 3 SOP or work instruction, and none is overdue for periodic review | Tier 3 procedure set, periodic review log | <<FILL>> | |
| 7 | Every procedure that should generate evidence has a defined, controlled tier 4 form or log with a stated retention period | Form/record inventory, retention schedule | <<FILL>> | |
| 8 | Downward traceability holds: pick 3 policy commitments and confirm each traces to a procedure, to steps, to a record | Spot-check trace | <<FILL>> | |
| 9 | Upward traceability holds: pick 3 records and confirm each traces back to its form version, its SOP, and the policy or regulation behind it | Spot-check trace | <<FILL>> | |
| 10 | Document control is functioning: version control, approval-before-effect, controlled distribution, obsolete-copy control | Document control system review | <<FILL>> | |
| 11 | No uncontrolled copies are in use at points of work | Floor walk / point-of-use check | <<FILL>> | |
| 12 | For electronic documents and signatures, Part 11 / Annex 11 controls (audit trail, access, e-signature) are in place and verified | Electronic system validation and access review | <<FILL>> | |
| 13 | The hierarchy is right-sized: depth follows process complexity and risk, not an arbitrary standard | Reviewer judgment against operation size and risk | <<FILL>> |
3. Gap disposition
For every line scored Fail, record a disposition below. A Fail with no disposition is not a completed assessment.
| Gap # | Checklist item | Description of gap | Risk if unaddressed | Owner | Target closure date | CAPA / action reference |
|---|---|---|---|---|---|---|
<<FILL: G-01>> | <<FILL: item #>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
4. Acceptance criteria
The assessment is complete when every line is scored, every Fail has a documented gap, owner, and target closure date, and the disposition table is reviewed and approved by QA. A gap assessment that finds zero gaps on a first pass at a mature, multi-site operation should itself be questioned; genuinely clean results are more common on a narrow, recently built hierarchy than on a large legacy one.
5. References
ICH Q10, Pharmaceutical Quality System, for the connected-process model this checklist verifies. EU GMP Chapter 4 (Documentation), for document type and control expectations. ISO 13485:2016 clause 4.2, where a device constituent is in scope, for quality manual and documented-procedure requirements (incorporated into the US QMSR effective 2 February 2026).
Confirm the current version of each reference before issue.
6. Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
Filled specimen
The following shows an excerpt from an example gap assessment at a mid-size biologics site, so you can see the level of detail expected. The company and findings are illustrative; replace them with your own.
| # | Item | Result | Comment |
|---|---|---|---|
| 1 | Applicable requirements identified | Pass | 21 CFR 210/211, EU GMP, ICH Q10, Part 11/Annex 11 confirmed as the applicable set |
| 2 | Requirements mapped to processes | Pass | Cross-reference matrix XREF-QA-001 current as of 2026-07 |
| 4 | Quality manual current and specific | Fail | Manual QM-001 v2.0 restates ISO 9001 clause language nearly verbatim with little site-specific description |
| 8 | Downward traceability | Pass | 3 policy commitments traced cleanly to procedure to record |
| 11 | No uncontrolled copies in use | Fail | One printed SOP found taped at a workstation, one revision behind current |
| Gap # | Item | Description | Risk | Owner | Target | Reference |
|---|---|---|---|---|---|---|
| G-01 | 4 | Quality manual is generic, not specific to site operations | Inspector reads it as content-free, questions whether management understands its own QMS | Head of Quality | 2026-09-30 | CAPA-2026-0088 |
| G-02 | 11 | Uncontrolled printed copy found in use | Obsolete version could be followed instead of current | Area Supervisor | 2026-08-25 | CAPA-2026-0089 |
Common inspection findings this checklist prevents
- A quality manual that is generic and content-free, discovered only when an inspector asks a specific question the manual cannot answer.
- A QMS process with no governing procedure, found live because nobody had checked the full requirement-to-process map recently.
- Broken traceability, a form referencing an SOP that no longer exists, or a manual referencing retired procedures.
- Uncontrolled copies at points of work, the single most commonly cited document-control finding.
- Overdue periodic reviews across a swath of SOPs, signaling the system is not actively maintained.
How to adapt this checklist
- Set the scope (site, department, or whole company) and assessor in the header before starting.
- Add lines specific to your operation: a cell and gene therapy site may need a line for chain-of-identity/chain-of-custody procedures, a combination-product site for the device-constituent document set.
- Do not close the assessment until every Fail has a disposition with an owner and a date; an assessment with open, undispositioned gaps is itself a finding.
- Run this checklist on a defined cycle (annually is typical) and after any material QMS restructuring (new site, acquisition, reorganized quality unit).