Case Study: Risk Register Not Updated → System Failure
Scenario Overview
A pharmaceutical manufacturer implements a formal Quality Risk Management program.
The organization maintains a risk register containing:
process risks
supplier risks
quality system risks
validation risks
compliance risks
The register is initially well designed.
Risks are:
documented
scored
assigned owners
linked to mitigation plans
Following implementation, the system receives positive internal feedback and management support.
Over time, however, the risk register gradually becomes a static document rather than an active governance tool.
Several years later, the organization experiences a significant quality system failure involving recurring deviations, ineffective CAPAs, supplier performance deterioration, and delayed management response.
A subsequent review reveals that warning signs had been visible long before the failure occurred.
The problem was not absence of risk information.
The problem was failure to maintain and update the organization’s evolving risk picture.
Initial Risk Register Design
At implementation, the register includes risk such as:
| Risk Area | Initial Status |
|---|---|
| Supplier reliability | Controlled |
| Deviation recurrence | Controlled |
| CAPA effectiveness | Controlled |
| Documentation compliance | Controlled |
| Training effectiveness | Controlled |
Mitigations are assigned.
Owners are identified.
Review schedules are established.
The framework appears robust.
Early Changes Begin to Appear
Over the following two years, operational conditions change.
Examples include:
increasing deviation volume
recurring CAPA delays
growing supplier quality concerns
higher employee turnover
expanding production demand
Each issue is managed within its respective quality system.
However, updates to the risk register occur infrequently.
Most risks retain their original classifications despite changing evidence.
The Register Becomes Historical
Gradually, the risk register shifts from:
current risk picture
to
historical risk picture
Several risks remain classified as controlled because:
no formal reassessment occurred
owners changed roles
reviews were postponed
risk updates became administrative exercises
The register continues to exist.
The problem is that it no longer accurately reflects operational reality.
Warning Signals Accumulate
Numerous signals become visible:
recurring audit observations
delayed investigations
ineffective CAPAs
supplier performance deterioration
increasing training gaps
Each issue is known.
Each issue is documented somewhere.
However, the information remains fragmented.
No mechanism consistently integrates these signals into updated risk evaluations.
As discussed in Using QRM Data for Predictive Analysis, disconnected information often prevents recognition of emerging exposure.
Bayesian Updating Never Occurs
The organization originally classified several risks as low or moderate.
Over time, new evidence emerges.
For example:
supplier performance declines
repeat CAPAs appear
recurrence increases
Yet risk ratings remain unchanged.
The organization continues operating according to historical assumptions.
As discussed in Bayesian Approaches for Quality Systems, risk understanding should evolve as evidence emerges.
In this case, evolving evidence never meaningfully influenced risk conclusions.
Escalation Opportunities Are Missed
Because risk ratings remain unchanged:
escalation thresholds are not triggered
management attention remains limited
resources are not reallocated
oversight intensity does not increase
The organization believes risk remains stable because the register says risk remains stable.
The register is no longer functioning as an assessment tool.
It is functioning as a reassurance tool.
The System Failure
Eventually, a significant event occurs.
A critical supplier quality issue coincides with:
delayed CAPA implementation
ineffective investigation follow-up
unresolved training gaps
The combined impact creates:
multiple affected batches
supply disruption
management escalation
regulatory reporting obligations
The organization now faces a system-level failure rather than an isolated event.
What the Review Revealed
Following the event, a cross-functional review is performed.
The review concludes:
warning signals existed for years
risk indicators were visible
trends were available
reassessment opportunities were missed
The organization did not fail because risks were unknown.
The organization failed because known risks were not reevaluated as conditions changed.
Where Governance Broke Down
The root cause analysis identifies several governance weaknesses:
risk review schedules not maintained
weak ownership accountability
limited management challenge
poor integration of trend information
risk register disconnected from operational systems
The register was treated as a repository.
It was not treated as a decision-making tool.
Corrective Actions
The organization implements:
mandatory risk review triggers
recurrence-based reassessment criteria
ownership accountability requirements
integration with management review
linkage between trends and risk ratings
escalation based on changing exposure
The objective is not creating a larger register.
The objective is ensuring the register remains connected to operational reality.
Outcome
Over the following years:
risk reviews become more frequent
emerging vulnerabilities become visible earlier
escalation improves
resource allocation becomes more targeted
management review becomes more predictive
The register evolves from a compliance artifact into an active governance framework.
Lessons Learned
Several lessons emerge:
Risk registers lose value when they become static.
Historical risk ratings should not be treated as permanent conclusions.
Warning signals require integration, not just documentation.
Escalation depends on updated risk understanding.
Governance failures often occur despite abundant information.
Most importantly:
The organization’s problem was not lack of data.
The problem was failure to update its understanding of what the data meant.
What Good Looks Like
A mature risk register process:
updates risk ratings as evidence evolves
integrates trend information
supports escalation decisions
maintains ownership accountability
remains connected to operational systems
informs management review activities
Within Quality Risk Management (ICH Q9), risk registers should function as living governance tools rather than historical inventories of past assessments.
Operational Perspective
Many organizations believe risk registers fail because risks were not identified correctly.
More commonly, risk registers fail because identified risks are never reevaluated after operating conditions change.
The strongest QRM systems continuously ask:
“If we assessed this risk today using current evidence, would we assign the same rating?”
When that question is no longer asked, the register may remain complete, current, and fully documented while becoming progressively less accurate.
That is often how preventable system failures develop.
Explore more on Quality Risk Management
Browse VerethiQ resources on risk identification, risk analysis, risk control, risk acceptance, risk communication, and risk review in GMP systems.