Case Study: Underestimated Risk → Inspection Finding

Scenario Overview

A pharmaceutical manufacturer operates a mature oral solid dosage facility with a long history of successful inspections.

The site experiences occasional deviations involving:

  • incomplete investigations

  • delayed CAPA implementation

  • recurring documentation errors

  • overdue effectiveness checks

The events are generally classified as low risk because:

  • no product defects are identified

  • no customer complaints occur

  • no batch rejections result

  • no immediate patient impact is evident

Over time, management becomes increasingly comfortable with these recurring issues.

The organization gradually concludes that the associated risks are minor and manageable.

Several years later, a regulatory inspection identifies significant concerns related to quality system effectiveness.

The inspection observations are not based on a single major event.

They are based on a pattern of weaknesses that the organization had gradually normalized.

 

Initial Risk Evaluation

The original assessment of individual events appears reasonable.

Examples include:

Event Initial Assessment
Documentation error Minor
CAPA delay Minor
Investigation overdue Minor
Effectiveness check incomplete Minor

Viewed individually, the conclusions are understandable.

Each event appears administrative rather than critical.

The problem emerges when recurring events are repeatedly evaluated in isolation.

 

The Normalization Process

Over time, recurring issues become familiar.

Personnel begin hearing statements such as:

  • “This happens occasionally.”

  • “We’ve never had product impact.”

  • “The last inspection did not focus on this.”

  • “We can address it later.”

Gradually, repeated exposure reduces perceived significance.

The organization begins treating warning signals as normal operating conditions.

The risk itself has not changed.

The organization’s perception of the risk has changed.

 

Where Risk Evaluation Failed

The organization focused heavily on:

  • immediate product impact

  • short-term consequences

  • individual event severity

Less attention was given to:

  • recurrence

  • trend development

  • governance effectiveness

  • cumulative exposure

The assumption becomes:

No major consequence means low risk.

This assumption overlooks an important principle.

Some risks emerge through accumulation rather than individual severity.

As discussed in Using QRM Data for Predictive Analysis, multiple low-level signals may collectively indicate meaningful operational exposure.

 

Escalation Thresholds Never Changed

The recurring issues remain below formal escalation criteria.

As a result:

  • management review receives limited visibility

  • oversight intensity remains unchanged

  • resources are not reassigned

  • deeper investigation never occurs

The organization continues responding to events individually.

No mechanism exists to evaluate the broader pattern.

Significant exposure may arise from recurring weaknesses that individually appear low risk.

 

Detectability Creates False Reassurance

The organization believes its controls are functioning effectively because issues continue to be detected.

Examples include:

  • audit findings identified

  • deviations documented

  • CAPAs initiated

  • reviews completed

Management interprets visibility as evidence of control.

However, detectability alone does not eliminate exposure.

The recurring nature of the findings suggests that underlying weaknesses remain unresolved.

Visibility becomes less valuable when identified issues repeatedly fail to influence risk decisions.

 

Inspection Perspective

During a regulatory inspection, investigators review:

  • audit history

  • CAPA records

  • deviation trends

  • management review outputs

Inspectors identify several recurring observations:

  • ineffective CAPA implementation

  • repeated documentation failures

  • delayed quality system activities

  • recurring procedural nonconformities

The concern is not any individual event.

The concern is that the organization repeatedly identified the same weaknesses without reducing recurrence.

 

The Inspection Finding

The resulting inspection observations focus on:

  • quality system effectiveness

  • management oversight

  • CAPA effectiveness

  • investigation quality

The inspection report notes that:

  • recurring issues remained visible for years

  • corrective actions produced limited improvement

  • risk significance appeared underestimated

The organization realizes that many of the warning signals had been available long before the inspection occurred.

 

Reassessment of Risk

Following the inspection, the organization performs a broader QRM review.

The assessment identifies:

  • recurring governance weaknesses

  • ineffective escalation criteria

  • insufficient trend analysis

  • limited focus on cumulative exposure

The revised conclusion is:

Individual events were low risk, but the pattern of recurrence represented meaningful system risk.

This distinction becomes critical.

 

Corrective Actions

The organization implements:

  • revised escalation criteria

  • recurrence-based risk triggers

  • expanded management review metrics

  • enhanced CAPA effectiveness monitoring

  • trend-based quality system oversight

The focus shifts from evaluating isolated events to evaluating patterns.

 

Outcome

Over the following years:

  • recurrence visibility improves

  • escalation occurs earlier

  • management oversight increases

  • CAPA effectiveness strengthens

  • quality system performance becomes more stable

The organization becomes better at identifying changing risk conditions before inspectors do.

 

Lessons Learned

Several lessons emerge:

  • Low severity does not always mean low risk.

  • Recurrence can change risk significance.

  • Normalization may weak risk perception.

  • Detectability alone does not demonstrate control.

  • Inspection findings often reflect cumulative exposure rather than isolated events.

Most importantly:

Risks are sometimes underestimated not because information is missing, but because familiar problems gradually become accepted as normal.

 

What Good Looks Like

A mature QRM system:

  • evaluates recurrence alongside severity

  • monitors cumulative exposure

  • reassesses normalized conditions periodically

  • escalates meaningful patterns

  • challenges long-standing assumptions

Within Quality Risk Management (ICH Q9), risk evaluation should remain sensitive to changing conditions rather than becoming anchored to historic comfort levels.

 

Operational Perspective

Many significant inspection observations originate from weaknesses that organizations already knew existed.

The challenge is rarely identifying the issue.

The challenge is recognizing when recurring low-level concerns have accumulated into evidence of a broader governance problem.

Strong quality systems periodically challenge familiar assumptions and ask:

“If we observed this pattern for the first time today, would we still consider it low risk?”

That question often reveals underestimation long before an inspector arrives.

 

Explore more on Quality Risk Management

Browse VerethiQ resources on risk identification, risk analysis, risk control, risk acceptance, risk communication, and risk review in GMP systems.

 
Previous
Previous

Case Study: Risk Register Not Updated → System Failure

Next
Next

Case Study: Overestimated Risk → Over Control