Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Policy Plug-and-play starting point Quality Assurance

Policy: Quality Risk Management Integration into the Pharmaceutical Quality System

A plug-and-play policy that establishes quality risk management as a mandatory enabler across the PQS: when a formal QRM assessment is required, which methods are approved, escalation thresholds, and how QRM connects to CAPA, change control, and monitoring, with a filled specimen.

Document type: Policy

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use corporate policy. It states that quality risk management, the ICH Q9(R1)-based enabler ICH Q10 names alongside knowledge management, is mandatory across the pharmaceutical quality system, not an optional tool reached for occasionally. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through your normal document control, review, and approval. A worked filled specimen follows. Verify each cited regulation against the current source before you rely on it.

Document control header

FieldEntry
Document titleQuality Risk Management Integration Policy
Document number<<FILL: POL-ID, e.g. POL-QA-012>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Supersedes<<FILL: prior version or "New">>
Policy owner<<FILL: role, e.g. Head of Quality>>
Applies to<<FILL: all sites, functions, and contracted parties in scope>>
Review cycle<<FILL: e.g. every 2 years or on regulatory change>>

1. Purpose

This policy establishes that quality risk management (QRM), consistent with ICH Q9(R1), is applied systematically across the four ICH Q10 elements, process performance and product quality monitoring, CAPA, change management, and management review, rather than treated as a document produced only when a template requires one. The objective is that effort and control are scaled to risk, that risk decisions are made with a consistent, documented method, and that the resulting risk register is a living input to the quality system rather than an archived report.

2. Policy statement

<<FILL: COMPANY NAME>> requires a documented quality risk assessment, using an approved method, for every decision listed in section 4, and requires that the outcome of that assessment visibly changes what happens next (the scope of a validation, the frequency of a review, the priority of a CAPA, the acceptability of a proposed change). A risk assessment that is filed but does not change a downstream decision does not meet this policy.

This policy is binding on all employees, contractors, and contracted organizations that perform or approve risk assessments, changes, investigations, or monitoring activities on behalf of the company.

3. Scope

This policy applies to quality risk management activity in support of GxP decisions across development, technology transfer, commercial manufacturing, and discontinuation, consistent with the ICH Q10 lifecycle. It covers formal documented risk assessments (FMEA or an equivalent structured method) and the informal risk-based judgment that sets monitoring frequency, sampling, and review depth. It does not itself define the technical content of any individual risk assessment; that is governed by the process- or system-specific procedures referenced in section 9.

4. When a formal, documented risk assessment is mandatory

TriggerExamplesMinimum method
New or significantly changed process, system, or facilityNew product introduction, new equipment, new computerized systemFMEA or equivalent structured method
Change classified as major or significantProcess parameter change outside established conditions, supplier change for a critical materialStructured impact and risk assessment per <<FILL: SOP-ID for change control>>
Investigation of a critical or major deviation, OOS, or recurring eventRepeat deviation, product-impacting OOSRoot cause analysis with documented risk ranking
Setting or revising alert/action limits or review frequencyMonitoring program design or revisionRisk-based frequency justification
Establishing established conditions for a regulatory filingQ12-aligned submission contentRisk assessment distinguishing established conditions from supporting information
Supplier or CDMO qualification and periodic reassessmentInitial qualification, tier reassignmentRisk-based supplier criticality assessment

Activities not listed here may still warrant a documented assessment; the process owner and Quality Assurance jointly decide, and the default when in doubt is to document the assessment rather than skip it.

5. Approved methods and rating consistency

  1. Use <<FILL: name the approved method(s), e.g. FMEA with a site-standard severity/occurrence/detectability scale>> for structured assessments, so ratings are comparable across assessments and across assessors.
  2. Maintain a single scoring guide that defines what each severity, occurrence, and detectability (or equivalent) level means in concrete terms, so two assessors scoring the same scenario reach the same rating. Calibrate assessors against this guide at <<FILL: frequency>>.
  3. Record the assessment team’s composition (process/technical SME, QA, and where relevant statistics or a patient-safety perspective); a risk assessment run by one person alone is not acceptable for the triggers in section 4.
  4. State assumptions and their basis explicitly; an assumption stated without basis is a gap in the assessment, not a neutral placeholder.

6. Risk rating and escalation thresholds

Risk ratingResponse requiredEscalation
HighImmediate action or a documented interim control before proceeding; risk owner namedQuality Assurance and, for product-impacting risk, site leadership notified
MediumAction plan with a due date; may proceed with the interim control in placeTracked in the quality risk register; reviewed at the cadence in section 7
LowDocumented and accepted, or actioned as resource allowsLogged; no mandatory escalation unless it later trends upward

A residual risk that remains High after mitigation is not closed by re-rating it; it requires a documented risk acceptance signed by a role with the authority to accept it, per <<FILL: SOP-ID or reference for residual risk acceptance>>.

7. Governance and the risk register

Every formal risk assessment under this policy is logged in the quality risk register, reviewed at <<FILL: e.g. quarterly>>, and summarized for management review so that risk posture, not just activity count, reaches leadership. A risk register that is populated but never reviewed does not meet this policy.

8. Accountability

RoleAccountability under this policy
Executive managementResources the QRM program and reviews aggregate risk posture in management review
Policy owner / QualityOwns this policy, the approved method and scoring guide, and confirms assessments are performed for the triggers in section 4
Process/system ownerInitiates and leads the risk assessment for changes and decisions they own
QA reviewerConfirms the assessment used the approved method, the team was appropriate, and the outcome changed the downstream decision where warranted
All GxP staffEscalate risk-relevant information (a near miss, a signal, a supplier concern) into the process rather than absorbing it informally

9. Supporting procedures

ProcedureReference
Risk assessment method and scoring guide<<FILL: SOP-ID>>
Change control<<FILL: SOP-ID>>
Deviation and CAPA<<FILL: SOP-ID>>
Process performance and product quality monitoring<<FILL: SOP-ID or plan reference>>
Supplier and vendor qualification<<FILL: SOP-ID>>
Residual risk acceptance<<FILL: SOP-ID>>

10. Compliance and exceptions

Proceeding with a change, investigation, or monitoring decision listed in section 4 without the required documented risk assessment is a policy breach and is itself logged as a quality event. An exception (proceeding ahead of the assessment under a documented interim control, in a genuine urgent-safety situation) requires QA approval in advance and retrospective completion of the assessment within <<FILL: number>> working days.

11. Acceptance criteria

  • Every trigger in section 4 has a documented risk assessment using the approved method, with a named team.
  • Ratings are consistent across assessors, evidenced by a current scoring guide and calibration record.
  • The risk register is current, reviewed on the defined cadence, and reaches management review.
  • No open High risk lacks either a mitigation plan or a signed residual risk acceptance.
  • At least one example exists where a risk assessment outcome measurably changed a downstream decision (scope, frequency, priority, or acceptability).

12. References

ICH Q9(R1), Quality Risk Management. ICH Q10, Pharmaceutical Quality System, quality risk management enabler. ICH Q12, Technical and Regulatory Considerations for Pharmaceutical Product Lifecycle Management, for established conditions risk assessment. 21 CFR Part 211 (drug CGMP) for the underlying process and change controls QRM supports. ICH training material on Q9(R1) implementation.

Confirm the current version of each reference before issue.

13. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

14. Approvals

RoleNameSignatureDate
Author<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality Head)<<FILL>>

Filled specimen

The following shows the header and one worked risk assessment episode completed for an illustrative cell therapy manufacturing site, so you can see the level of specificity expected. The company, numbers, and references are illustrative; replace them with your own.

FieldEntry
Document titleQuality Risk Management Integration Policy
Document numberPOL-QA-012
Version1.0
Effective date01 Aug 2026
Policy ownerHead of Quality
Applies toAll manufacturing and testing sites; contracted testing laboratories
Review cycleEvery 2 years

Specimen of one triggered assessment (section 4, supplier change for a critical material):

A single-use bioreactor bag supplier proposed a resin-grade change. The process owner and QA convened an FMEA team (process engineering, QA, and the incoming supplier quality lead) and rated the extractables profile change as Medium occurrence, High severity given direct product contact, giving a High overall rating. The team required an extractables comparison study before the change could proceed and rated the residual risk Medium pending that data. The change control was held open until the study confirmed no new extractable of concern, at which point the residual rating was reduced to Low and the change control closed. The risk register entry, the study, and the change control cross-reference each other, which is exactly the traceable chain this policy requires.

Common inspection findings this policy prevents

  • Risk assessments exist for some decisions but there is no policy establishing when one is mandatory, so coverage is inconsistent and depends on who is asked.
  • Different assessors rate the same type of risk differently because no shared scoring guide exists.
  • A risk register is maintained but never reaches management review, so leadership has no aggregate view of risk posture.
  • A risk assessment is completed and filed, but the decision it was meant to inform (validation scope, review frequency, change acceptability) proceeds unchanged, so the assessment had no real effect.
  • A residual High risk is quietly re-rated to Medium with no documented rationale or accountable sign-off.

How to adapt this policy

  1. Set your document number, owner, and review cycle in the header.
  2. Name your actual approved risk assessment method(s) and point to your scoring guide in section 5.
  3. Adjust the trigger table in section 4 to your actual process; a small-molecule solid-dose site and a cell therapy site will not have identical triggers.
  4. Point every <<FILL: SOP-ID>> cross-reference to your real supporting procedures.
  5. Confirm every regulation in section 12 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.