Case Study: Risk Register Not Updated → System Failure

Scenario Overview

A pharmaceutical manufacturer implements a formal Quality Risk Management program.

The organization maintains a risk register containing:

  • process risks

  • supplier risks

  • quality system risks

  • validation risks

  • compliance risks

The register is initially well designed.

Risks are:

  • documented

  • scored

  • assigned owners

  • linked to mitigation plans

Following implementation, the system receives positive internal feedback and management support.

Over time, however, the risk register gradually becomes a static document rather than an active governance tool.

Several years later, the organization experiences a significant quality system failure involving recurring deviations, ineffective CAPAs, supplier performance deterioration, and delayed management response.

A subsequent review reveals that warning signs had been visible long before the failure occurred.

The problem was not absence of risk information.

The problem was failure to maintain and update the organization’s evolving risk picture.

 

Initial Risk Register Design

At implementation, the register includes risk such as:

Risk Area Initial Status
Supplier reliability Controlled
Deviation recurrence Controlled
CAPA effectiveness Controlled
Documentation compliance Controlled
Training effectiveness Controlled

Mitigations are assigned.

Owners are identified.

Review schedules are established.

The framework appears robust.

 

Early Changes Begin to Appear

Over the following two years, operational conditions change.

Examples include:

  • increasing deviation volume

  • recurring CAPA delays

  • growing supplier quality concerns

  • higher employee turnover

  • expanding production demand

Each issue is managed within its respective quality system.

However, updates to the risk register occur infrequently.

Most risks retain their original classifications despite changing evidence.

 

The Register Becomes Historical

Gradually, the risk register shifts from:

current risk picture

to

historical risk picture

Several risks remain classified as controlled because:

  • no formal reassessment occurred

  • owners changed roles

  • reviews were postponed

  • risk updates became administrative exercises

The register continues to exist.

The problem is that it no longer accurately reflects operational reality.

 

Warning Signals Accumulate

Numerous signals become visible:

  • recurring audit observations

  • delayed investigations

  • ineffective CAPAs

  • supplier performance deterioration

  • increasing training gaps

Each issue is known.

Each issue is documented somewhere.

However, the information remains fragmented.

No mechanism consistently integrates these signals into updated risk evaluations.

As discussed in Using QRM Data for Predictive Analysis, disconnected information often prevents recognition of emerging exposure.

 

Bayesian Updating Never Occurs

The organization originally classified several risks as low or moderate.

Over time, new evidence emerges.

For example:

  • supplier performance declines

  • repeat CAPAs appear

  • recurrence increases

Yet risk ratings remain unchanged.

The organization continues operating according to historical assumptions.

As discussed in Bayesian Approaches for Quality Systems, risk understanding should evolve as evidence emerges.

In this case, evolving evidence never meaningfully influenced risk conclusions.

 

Escalation Opportunities Are Missed

Because risk ratings remain unchanged:

  • escalation thresholds are not triggered

  • management attention remains limited

  • resources are not reallocated

  • oversight intensity does not increase

The organization believes risk remains stable because the register says risk remains stable.

The register is no longer functioning as an assessment tool.

It is functioning as a reassurance tool.

 

The System Failure

Eventually, a significant event occurs.

A critical supplier quality issue coincides with:

  • delayed CAPA implementation

  • ineffective investigation follow-up

  • unresolved training gaps

The combined impact creates:

  • multiple affected batches

  • supply disruption

  • management escalation

  • regulatory reporting obligations

The organization now faces a system-level failure rather than an isolated event.

 

What the Review Revealed

Following the event, a cross-functional review is performed.

The review concludes:

  • warning signals existed for years

  • risk indicators were visible

  • trends were available

  • reassessment opportunities were missed

The organization did not fail because risks were unknown.

The organization failed because known risks were not reevaluated as conditions changed.

 

Where Governance Broke Down

The root cause analysis identifies several governance weaknesses:

  • risk review schedules not maintained

  • weak ownership accountability

  • limited management challenge

  • poor integration of trend information

  • risk register disconnected from operational systems

The register was treated as a repository.

It was not treated as a decision-making tool.

 

Corrective Actions

The organization implements:

  • mandatory risk review triggers

  • recurrence-based reassessment criteria

  • ownership accountability requirements

  • integration with management review

  • linkage between trends and risk ratings

  • escalation based on changing exposure

The objective is not creating a larger register.

The objective is ensuring the register remains connected to operational reality.

 

Outcome

Over the following years:

  • risk reviews become more frequent

  • emerging vulnerabilities become visible earlier

  • escalation improves

  • resource allocation becomes more targeted

  • management review becomes more predictive

The register evolves from a compliance artifact into an active governance framework.

 

Lessons Learned

Several lessons emerge:

  • Risk registers lose value when they become static.

  • Historical risk ratings should not be treated as permanent conclusions.

  • Warning signals require integration, not just documentation.

  • Escalation depends on updated risk understanding.

  • Governance failures often occur despite abundant information.

Most importantly:

The organization’s problem was not lack of data.

The problem was failure to update its understanding of what the data meant.

 

What Good Looks Like

A mature risk register process:

  • updates risk ratings as evidence evolves

  • integrates trend information

  • supports escalation decisions

  • maintains ownership accountability

  • remains connected to operational systems

  • informs management review activities

Within Quality Risk Management (ICH Q9), risk registers should function as living governance tools rather than historical inventories of past assessments.

 

Operational Perspective

Many organizations believe risk registers fail because risks were not identified correctly.

More commonly, risk registers fail because identified risks are never reevaluated after operating conditions change.

The strongest QRM systems continuously ask:

“If we assessed this risk today using current evidence, would we assign the same rating?”

When that question is no longer asked, the register may remain complete, current, and fully documented while becoming progressively less accurate.

That is often how preventable system failures develop.

 

Explore more on Quality Risk Management

Browse VerethiQ resources on risk identification, risk analysis, risk control, risk acceptance, risk communication, and risk review in GMP systems.

 
Previous
Previous

Defining Investigation Scope in GMP Deviations

Next
Next

Case Study: Underestimated Risk → Inspection Finding