This is a ready-to-use corporate policy. It states that quality risk management, the ICH Q9(R1)-based enabler ICH Q10 names alongside knowledge management, is mandatory across the pharmaceutical quality system, not an optional tool reached for occasionally. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through your normal document control, review, and approval. A worked filled specimen follows. Verify each cited regulation against the current source before you rely on it.
Document control header
| Field | Entry |
|---|---|
| Document title | Quality Risk Management Integration Policy |
| Document number | <<FILL: POL-ID, e.g. POL-QA-012>> |
| Version | <<FILL: version, e.g. 1.0>> |
| Effective date | <<FILL: effective date>> |
| Supersedes | <<FILL: prior version or "New">> |
| Policy owner | <<FILL: role, e.g. Head of Quality>> |
| Applies to | <<FILL: all sites, functions, and contracted parties in scope>> |
| Review cycle | <<FILL: e.g. every 2 years or on regulatory change>> |
1. Purpose
This policy establishes that quality risk management (QRM), consistent with ICH Q9(R1), is applied systematically across the four ICH Q10 elements, process performance and product quality monitoring, CAPA, change management, and management review, rather than treated as a document produced only when a template requires one. The objective is that effort and control are scaled to risk, that risk decisions are made with a consistent, documented method, and that the resulting risk register is a living input to the quality system rather than an archived report.
2. Policy statement
<<FILL: COMPANY NAME>> requires a documented quality risk assessment, using an approved method, for every decision listed in section 4, and requires that the outcome of that assessment visibly changes what happens next (the scope of a validation, the frequency of a review, the priority of a CAPA, the acceptability of a proposed change). A risk assessment that is filed but does not change a downstream decision does not meet this policy.
This policy is binding on all employees, contractors, and contracted organizations that perform or approve risk assessments, changes, investigations, or monitoring activities on behalf of the company.
3. Scope
This policy applies to quality risk management activity in support of GxP decisions across development, technology transfer, commercial manufacturing, and discontinuation, consistent with the ICH Q10 lifecycle. It covers formal documented risk assessments (FMEA or an equivalent structured method) and the informal risk-based judgment that sets monitoring frequency, sampling, and review depth. It does not itself define the technical content of any individual risk assessment; that is governed by the process- or system-specific procedures referenced in section 9.
4. When a formal, documented risk assessment is mandatory
| Trigger | Examples | Minimum method |
|---|---|---|
| New or significantly changed process, system, or facility | New product introduction, new equipment, new computerized system | FMEA or equivalent structured method |
| Change classified as major or significant | Process parameter change outside established conditions, supplier change for a critical material | Structured impact and risk assessment per <<FILL: SOP-ID for change control>> |
| Investigation of a critical or major deviation, OOS, or recurring event | Repeat deviation, product-impacting OOS | Root cause analysis with documented risk ranking |
| Setting or revising alert/action limits or review frequency | Monitoring program design or revision | Risk-based frequency justification |
| Establishing established conditions for a regulatory filing | Q12-aligned submission content | Risk assessment distinguishing established conditions from supporting information |
| Supplier or CDMO qualification and periodic reassessment | Initial qualification, tier reassignment | Risk-based supplier criticality assessment |
Activities not listed here may still warrant a documented assessment; the process owner and Quality Assurance jointly decide, and the default when in doubt is to document the assessment rather than skip it.
5. Approved methods and rating consistency
- Use
<<FILL: name the approved method(s), e.g. FMEA with a site-standard severity/occurrence/detectability scale>>for structured assessments, so ratings are comparable across assessments and across assessors. - Maintain a single scoring guide that defines what each severity, occurrence, and detectability (or equivalent) level means in concrete terms, so two assessors scoring the same scenario reach the same rating. Calibrate assessors against this guide at
<<FILL: frequency>>. - Record the assessment team’s composition (process/technical SME, QA, and where relevant statistics or a patient-safety perspective); a risk assessment run by one person alone is not acceptable for the triggers in section 4.
- State assumptions and their basis explicitly; an assumption stated without basis is a gap in the assessment, not a neutral placeholder.
6. Risk rating and escalation thresholds
| Risk rating | Response required | Escalation |
|---|---|---|
| High | Immediate action or a documented interim control before proceeding; risk owner named | Quality Assurance and, for product-impacting risk, site leadership notified |
| Medium | Action plan with a due date; may proceed with the interim control in place | Tracked in the quality risk register; reviewed at the cadence in section 7 |
| Low | Documented and accepted, or actioned as resource allows | Logged; no mandatory escalation unless it later trends upward |
A residual risk that remains High after mitigation is not closed by re-rating it; it requires a documented risk acceptance signed by a role with the authority to accept it, per <<FILL: SOP-ID or reference for residual risk acceptance>>.
7. Governance and the risk register
Every formal risk assessment under this policy is logged in the quality risk register, reviewed at <<FILL: e.g. quarterly>>, and summarized for management review so that risk posture, not just activity count, reaches leadership. A risk register that is populated but never reviewed does not meet this policy.
8. Accountability
| Role | Accountability under this policy |
|---|---|
| Executive management | Resources the QRM program and reviews aggregate risk posture in management review |
| Policy owner / Quality | Owns this policy, the approved method and scoring guide, and confirms assessments are performed for the triggers in section 4 |
| Process/system owner | Initiates and leads the risk assessment for changes and decisions they own |
| QA reviewer | Confirms the assessment used the approved method, the team was appropriate, and the outcome changed the downstream decision where warranted |
| All GxP staff | Escalate risk-relevant information (a near miss, a signal, a supplier concern) into the process rather than absorbing it informally |
9. Supporting procedures
| Procedure | Reference |
|---|---|
| Risk assessment method and scoring guide | <<FILL: SOP-ID>> |
| Change control | <<FILL: SOP-ID>> |
| Deviation and CAPA | <<FILL: SOP-ID>> |
| Process performance and product quality monitoring | <<FILL: SOP-ID or plan reference>> |
| Supplier and vendor qualification | <<FILL: SOP-ID>> |
| Residual risk acceptance | <<FILL: SOP-ID>> |
10. Compliance and exceptions
Proceeding with a change, investigation, or monitoring decision listed in section 4 without the required documented risk assessment is a policy breach and is itself logged as a quality event. An exception (proceeding ahead of the assessment under a documented interim control, in a genuine urgent-safety situation) requires QA approval in advance and retrospective completion of the assessment within <<FILL: number>> working days.
11. Acceptance criteria
- Every trigger in section 4 has a documented risk assessment using the approved method, with a named team.
- Ratings are consistent across assessors, evidenced by a current scoring guide and calibration record.
- The risk register is current, reviewed on the defined cadence, and reaches management review.
- No open High risk lacks either a mitigation plan or a signed residual risk acceptance.
- At least one example exists where a risk assessment outcome measurably changed a downstream decision (scope, frequency, priority, or acceptability).
12. References
ICH Q9(R1), Quality Risk Management. ICH Q10, Pharmaceutical Quality System, quality risk management enabler. ICH Q12, Technical and Regulatory Considerations for Pharmaceutical Product Lifecycle Management, for established conditions risk assessment. 21 CFR Part 211 (drug CGMP) for the underlying process and change controls QRM supports. ICH training material on Q9(R1) implementation.
Confirm the current version of each reference before issue.
13. Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
14. Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Author | <<FILL>> | ||
| Reviewer (QA) | <<FILL>> | ||
| Approver (Quality Head) | <<FILL>> |
Filled specimen
The following shows the header and one worked risk assessment episode completed for an illustrative cell therapy manufacturing site, so you can see the level of specificity expected. The company, numbers, and references are illustrative; replace them with your own.
| Field | Entry |
|---|---|
| Document title | Quality Risk Management Integration Policy |
| Document number | POL-QA-012 |
| Version | 1.0 |
| Effective date | 01 Aug 2026 |
| Policy owner | Head of Quality |
| Applies to | All manufacturing and testing sites; contracted testing laboratories |
| Review cycle | Every 2 years |
Specimen of one triggered assessment (section 4, supplier change for a critical material):
A single-use bioreactor bag supplier proposed a resin-grade change. The process owner and QA convened an FMEA team (process engineering, QA, and the incoming supplier quality lead) and rated the extractables profile change as Medium occurrence, High severity given direct product contact, giving a High overall rating. The team required an extractables comparison study before the change could proceed and rated the residual risk Medium pending that data. The change control was held open until the study confirmed no new extractable of concern, at which point the residual rating was reduced to Low and the change control closed. The risk register entry, the study, and the change control cross-reference each other, which is exactly the traceable chain this policy requires.
Common inspection findings this policy prevents
- Risk assessments exist for some decisions but there is no policy establishing when one is mandatory, so coverage is inconsistent and depends on who is asked.
- Different assessors rate the same type of risk differently because no shared scoring guide exists.
- A risk register is maintained but never reaches management review, so leadership has no aggregate view of risk posture.
- A risk assessment is completed and filed, but the decision it was meant to inform (validation scope, review frequency, change acceptability) proceeds unchanged, so the assessment had no real effect.
- A residual High risk is quietly re-rated to Medium with no documented rationale or accountable sign-off.
How to adapt this policy
- Set your document number, owner, and review cycle in the header.
- Name your actual approved risk assessment method(s) and point to your scoring guide in section 5.
- Adjust the trigger table in section 4 to your actual process; a small-molecule solid-dose site and a cell therapy site will not have identical triggers.
- Point every
<<FILL: SOP-ID>>cross-reference to your real supporting procedures. - Confirm every regulation in section 12 against the current published version before issue.