Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Quality Assurance

Checklist: QMS Document Hierarchy Gap Assessment

A plug-and-play checklist for assessing or designing a QMS document hierarchy end to end: applicable requirements mapped to processes, a tier 1 description, current tier 2 through tier 4 documents for every process, bidirectional traceability, and document control health, with pass/fail/NA scoring, a filled specimen, and the findings it prevents.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use checklist for assessing an existing QMS document hierarchy or designing a new one. It operationalizes the eight-step method of mapping requirements to processes, confirming a document exists at every tier for every process, and checking traceability in both directions. Run it as a structured self-inspection or as the first pass when standing up a QMS from scratch. Replace every <<FILL: ...>> placeholder, score each line, and treat any Fail as a gap to close, not a note to revisit someday. A worked filled specimen follows the template.

Document control header

FieldEntry
Document titleQMS Document Hierarchy Gap Assessment
Document number<<FILL: reference, e.g. GAP-QA-2026-03>>
Site / scope assessed<<FILL>>
Date of assessment<<FILL>>
Assessed by<<FILL>>

1. Purpose

This checklist confirms that a QMS document hierarchy is complete top to bottom: every applicable requirement is mapped to a process, every process has a current governing document at each tier that needs one, and the links between tiers hold in both directions. It surfaces exactly the gaps an inspector would find, so the company finds them first.

2. Assessment checklist

#ItemEvidence to checkResult (Pass/Fail/NA)Comment
1Every applicable regulation, standard, and guidance for this operation is identified and listedRegulatory applicability assessment<<FILL>>
2Every requirement from that list is mapped to a named QMS processRequirement-to-procedure cross-reference matrix<<FILL>>
3A current, approved quality policy exists, is signed by top management, and quality objectives trace back to itQuality policy, objectives record<<FILL>>
4A current quality manual (or equivalent, e.g. Site Master File) exists, describes the actual operation (not a generic restatement of a standard), and cross-references the governing proceduresQuality manual<<FILL>>
5Every QMS process named in the manual has a current, approved tier 2 procedure with unambiguous rolesTier 2 procedure set<<FILL>>
6Every operational task that needs consistency has a tier 3 SOP or work instruction, and none is overdue for periodic reviewTier 3 procedure set, periodic review log<<FILL>>
7Every procedure that should generate evidence has a defined, controlled tier 4 form or log with a stated retention periodForm/record inventory, retention schedule<<FILL>>
8Downward traceability holds: pick 3 policy commitments and confirm each traces to a procedure, to steps, to a recordSpot-check trace<<FILL>>
9Upward traceability holds: pick 3 records and confirm each traces back to its form version, its SOP, and the policy or regulation behind itSpot-check trace<<FILL>>
10Document control is functioning: version control, approval-before-effect, controlled distribution, obsolete-copy controlDocument control system review<<FILL>>
11No uncontrolled copies are in use at points of workFloor walk / point-of-use check<<FILL>>
12For electronic documents and signatures, Part 11 / Annex 11 controls (audit trail, access, e-signature) are in place and verifiedElectronic system validation and access review<<FILL>>
13The hierarchy is right-sized: depth follows process complexity and risk, not an arbitrary standardReviewer judgment against operation size and risk<<FILL>>

3. Gap disposition

For every line scored Fail, record a disposition below. A Fail with no disposition is not a completed assessment.

Gap #Checklist itemDescription of gapRisk if unaddressedOwnerTarget closure dateCAPA / action reference
<<FILL: G-01>><<FILL: item #>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

4. Acceptance criteria

The assessment is complete when every line is scored, every Fail has a documented gap, owner, and target closure date, and the disposition table is reviewed and approved by QA. A gap assessment that finds zero gaps on a first pass at a mature, multi-site operation should itself be questioned; genuinely clean results are more common on a narrow, recently built hierarchy than on a large legacy one.

5. References

ICH Q10, Pharmaceutical Quality System, for the connected-process model this checklist verifies. EU GMP Chapter 4 (Documentation), for document type and control expectations. ISO 13485:2016 clause 4.2, where a device constituent is in scope, for quality manual and documented-procedure requirements (incorporated into the US QMSR effective 2 February 2026).

Confirm the current version of each reference before issue.

6. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Filled specimen

The following shows an excerpt from an example gap assessment at a mid-size biologics site, so you can see the level of detail expected. The company and findings are illustrative; replace them with your own.

#ItemResultComment
1Applicable requirements identifiedPass21 CFR 210/211, EU GMP, ICH Q10, Part 11/Annex 11 confirmed as the applicable set
2Requirements mapped to processesPassCross-reference matrix XREF-QA-001 current as of 2026-07
4Quality manual current and specificFailManual QM-001 v2.0 restates ISO 9001 clause language nearly verbatim with little site-specific description
8Downward traceabilityPass3 policy commitments traced cleanly to procedure to record
11No uncontrolled copies in useFailOne printed SOP found taped at a workstation, one revision behind current
Gap #ItemDescriptionRiskOwnerTargetReference
G-014Quality manual is generic, not specific to site operationsInspector reads it as content-free, questions whether management understands its own QMSHead of Quality2026-09-30CAPA-2026-0088
G-0211Uncontrolled printed copy found in useObsolete version could be followed instead of currentArea Supervisor2026-08-25CAPA-2026-0089

Common inspection findings this checklist prevents

  • A quality manual that is generic and content-free, discovered only when an inspector asks a specific question the manual cannot answer.
  • A QMS process with no governing procedure, found live because nobody had checked the full requirement-to-process map recently.
  • Broken traceability, a form referencing an SOP that no longer exists, or a manual referencing retired procedures.
  • Uncontrolled copies at points of work, the single most commonly cited document-control finding.
  • Overdue periodic reviews across a swath of SOPs, signaling the system is not actively maintained.

How to adapt this checklist

  1. Set the scope (site, department, or whole company) and assessor in the header before starting.
  2. Add lines specific to your operation: a cell and gene therapy site may need a line for chain-of-identity/chain-of-custody procedures, a combination-product site for the device-constituent document set.
  3. Do not close the assessment until every Fail has a disposition with an owner and a date; an assessment with open, undispositioned gaps is itself a finding.
  4. Run this checklist on a defined cycle (annually is typical) and after any material QMS restructuring (new site, acquisition, reorganized quality unit).
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.