Read in

ICH Q9: written risk ≠ managed risk

ICH Q9QRMGxPEBRData Integrity
ICH Q9: written risk ≠ managed riskICH Q9: written risk ≠ managed risk

Some plants have impeccable QRM in the archive and almost none on the shift. The process risk protocol was written at validation, signed, filed. Two years later a mixing deviation, an excipient supplier change, or a range tweak in the EBR follows the "usual" flow — without reopening the question the protocol had already answered.

In most cases this is not a "lack of QRM." It is something else: written risk treated as managed risk. The text exists. Management, in the sense of ICH Q9(R1), has not yet reached the floor.

What Q9(R1) actually pushes

The current guideline — ICH Q9(R1), adopted at Step 4 in January 2023 and effective in Europe since 26 Jul 2023 — does not invent the idea of managing risk. It deepens what industry already knew and still does halfway: formality proportional to risk, risk-based decision-making (not only a "completed analysis"), and explicit care with subjectivity.

On the plant floor, that usually means three shifts:

  1. Report size does not define management quality. A sixty-page FMEA on a low risk and a loose paragraph on a high risk are the opposite of what Q9(R1) describes as proportionate formality.
  2. Assessing is not controlling. Mapping failure modes without tying what the system (or the procedure) does when the mode appears leaves the risk in the PowerPoint.
  3. Risk ages. Change, recurring deviation, new material, new equipment, new release path: the point at which risk must be reviewed matters as much as the point at which it was first assessed.

None of that asks anyone to "guarantee compliance" with a slide. It asks that the assessment stay alive where decisions happen.

The shop-floor hook we see every day

The protocol already wrote that relative humidity at weighing is critical for attribute X; that mixer charge sequence matters; that the second person on material-lot check is not ceremony. In operations the deviation arrives like this: "humidity ran a bit high, but the batch passed"; "we swapped two charge steps because the silo was busy"; "the pharmacist confirmed later, on paper."

If deviation and change flows do not reopen the risk the protocol already named, the plant is running on two truths: the archive's and the shift's. Q9(R1) does not fix that alone. It makes clear that risk communication and review are part of the process — not an audit appendix.

The useful question is not "do we have QRM?" It is: when something changes or goes off path, does the matching risk return to the table — or only the deviation form?

ALCOA+ as a risk decision (not a poster)

Data integrity belongs here as a system and risk choice, not as a solo compliance poster. If a critical process value depends on late typing, the risk is not only "keystroke error": it is weak contemporaneity, fragile attributability, and a second person who exists precisely because data provenance is poor.

When we decide a parameter is critical enough to enter the FMEA, it usually makes sense to ask at the same time: where does this value come from, with what timestamp, and what does the system do if it is out? That is Q9 talking to record design — ALCOA+ as a consequence of the assessment, not a checklist taped to the wall.

Formality without theatre

Q9(R1) talks about formality. On the floor, too much formality without focus becomes theatre; too little on high risk becomes a surprise at inspection. The middle that tends to work is tying the level of effort to the level of patient and product-quality harm — and making that visible in the flow itself.

In practice we see three patterns:

  • High risk, loose control in the system. The document says "critical"; the EBR only warns and the shift closes and moves on. Assessment and execution diverge.
  • Low risk, high bureaucracy. Every minimal change demands the same package. People work around it. The workaround disappears from the audit trail — and the real risk (the shortcut) was never in the FMEA.
  • Well-written risk, no owner. The matrix exists; at change time nobody knows who reopens the assessment. It becomes an email queue.

The antidote is not another template. It is owner, trigger, and evidence: who decides, what fires the review, and where that is recorded in a recoverable way.

Subjectivity: the elephant Q9(R1) names

One of the most useful contributions of the R1 revision is facing subjectivity head-on. Dominant facilitator, "we have always done it this way," lead-time pressure: these bias severity scores and what counts as acceptable.

Human judgement cannot be eliminated. It can be made visible and revisable: pre-agreed criteria, process data when they exist, and the habit of asking "what would change this score if the next batch failed?" In an electronic system that usually shows up as decision history in change control — not as a loose comment in the analysis spreadsheet.

Where the system of record helps (without overclaim)

ICH Q9 does not require an MES. It requires management. What a well-designed system of record — for example an EBR with change and deviation tied to the batch — can do is shrink the space where risk lives only in the archive:

  • prevent (or at least evidence) execution outside the range the assessment treated as critical;
  • force limit, sequence, or material changes through a stateful flow — not silent email and reconfiguration;
  • keep a trail of who changed what, when, and with what justification;
  • link recurring deviation back to the same risk family instead of treating each occurrence as an island.

That does not "implement Q9." It implements conditions under which Q9 stops being a PDF. The science of risk stays with people; the system holds the shortcut.

What not to confuse

  • Having an FMEA ≠ managing risk. Without review in the change/deviation cycle, it is a photograph.
  • Tool ≠ method. FTA, HACCP, FMEA are means. Q9's question is whether the control decision follows the assessment.
  • Zero risk. That is not the target. The target is known risk, controlled to what the product requires, and revisited when context changes.
  • Inspection as the only customer. If QRM only "wakes up" for inspection prep, it is not integrated into operations — and Q9(R1) is explicit about integration.

An honest sequence for the team

No transformation romance:

  1. Take the last three serious (or recurring) deviations and ask whether the matching protocol risk was reopened. If the answer is "no," the gap is not a template gap.
  2. List the parameters the FMEA calls critical and check what the EBR/MES actually does: hard block, ignorable warning, or nothing.
  3. In change control, make "risk reviewed? reference?" a required field — and treat chronic "N/A" as a signal, not a time saver.
  4. Reduce formality where risk is low on purpose, so capacity remains where risk is high. Proportionate formality is also smart relief.
  5. Treat integrity of critical data as part of the same risk package, not a parallel "DI" project.

Closing

ICH Q9(R1) does not ask for more risk paper. It asks that written risk keep governing decisions when the plant moves — change, deviation, new knowledge. While the assessment sleeps in the archive and the shift improvises with good intent, we do not have managed QRM: we have archived QRM.

If in your plant the risk protocol is truly reopened when the deviation arrives — or only at the next validation campaign — that is usually the question that separates documentary compliance from management.

At T2, when we talk about electronic batch records and change control in the same system of record, the point is not "buying Q9." It is removing the shortcut that turns written risk into dead letter on the second shift.

Get the next article by email

Practical writing on GxP, MES, data integrity and shop-floor systems. A few times a month, no noise.

By subscribing you agree to receive T2 Software content by email. Unsubscribe at any time from any message.

More from the blog

All articles →