Case Study: Underestimated Risk → Inspection Finding
Scenario Overview
A pharmaceutical manufacturer operates a mature oral solid dosage facility with a long history of successful inspections.
The site experiences occasional deviations involving:
incomplete investigations
delayed CAPA implementation
recurring documentation errors
overdue effectiveness checks
The events are generally classified as low risk because:
no product defects are identified
no customer complaints occur
no batch rejections result
no immediate patient impact is evident
Over time, management becomes increasingly comfortable with these recurring issues.
The organization gradually concludes that the associated risks are minor and manageable.
Several years later, a regulatory inspection identifies significant concerns related to quality system effectiveness.
The inspection observations are not based on a single major event.
They are based on a pattern of weaknesses that the organization had gradually normalized.
Initial Risk Evaluation
The original assessment of individual events appears reasonable.
Examples include:
| Event | Initial Assessment |
|---|---|
| Documentation error | Minor |
| CAPA delay | Minor |
| Investigation overdue | Minor |
| Effectiveness check incomplete | Minor |
Viewed individually, the conclusions are understandable.
Each event appears administrative rather than critical.
The problem emerges when recurring events are repeatedly evaluated in isolation.
The Normalization Process
Over time, recurring issues become familiar.
Personnel begin hearing statements such as:
“This happens occasionally.”
“We’ve never had product impact.”
“The last inspection did not focus on this.”
“We can address it later.”
Gradually, repeated exposure reduces perceived significance.
The organization begins treating warning signals as normal operating conditions.
The risk itself has not changed.
The organization’s perception of the risk has changed.
Where Risk Evaluation Failed
The organization focused heavily on:
immediate product impact
short-term consequences
individual event severity
Less attention was given to:
recurrence
trend development
governance effectiveness
cumulative exposure
The assumption becomes:
No major consequence means low risk.
This assumption overlooks an important principle.
Some risks emerge through accumulation rather than individual severity.
As discussed in Using QRM Data for Predictive Analysis, multiple low-level signals may collectively indicate meaningful operational exposure.
Escalation Thresholds Never Changed
The recurring issues remain below formal escalation criteria.
As a result:
management review receives limited visibility
oversight intensity remains unchanged
resources are not reassigned
deeper investigation never occurs
The organization continues responding to events individually.
No mechanism exists to evaluate the broader pattern.
Significant exposure may arise from recurring weaknesses that individually appear low risk.
Detectability Creates False Reassurance
The organization believes its controls are functioning effectively because issues continue to be detected.
Examples include:
audit findings identified
deviations documented
CAPAs initiated
reviews completed
Management interprets visibility as evidence of control.
However, detectability alone does not eliminate exposure.
The recurring nature of the findings suggests that underlying weaknesses remain unresolved.
Visibility becomes less valuable when identified issues repeatedly fail to influence risk decisions.
Inspection Perspective
During a regulatory inspection, investigators review:
audit history
CAPA records
deviation trends
management review outputs
Inspectors identify several recurring observations:
ineffective CAPA implementation
repeated documentation failures
delayed quality system activities
recurring procedural nonconformities
The concern is not any individual event.
The concern is that the organization repeatedly identified the same weaknesses without reducing recurrence.
The Inspection Finding
The resulting inspection observations focus on:
quality system effectiveness
management oversight
CAPA effectiveness
investigation quality
The inspection report notes that:
recurring issues remained visible for years
corrective actions produced limited improvement
risk significance appeared underestimated
The organization realizes that many of the warning signals had been available long before the inspection occurred.
Reassessment of Risk
Following the inspection, the organization performs a broader QRM review.
The assessment identifies:
recurring governance weaknesses
ineffective escalation criteria
insufficient trend analysis
limited focus on cumulative exposure
The revised conclusion is:
Individual events were low risk, but the pattern of recurrence represented meaningful system risk.
This distinction becomes critical.
Corrective Actions
The organization implements:
revised escalation criteria
recurrence-based risk triggers
expanded management review metrics
enhanced CAPA effectiveness monitoring
trend-based quality system oversight
The focus shifts from evaluating isolated events to evaluating patterns.
Outcome
Over the following years:
recurrence visibility improves
escalation occurs earlier
management oversight increases
CAPA effectiveness strengthens
quality system performance becomes more stable
The organization becomes better at identifying changing risk conditions before inspectors do.
Lessons Learned
Several lessons emerge:
Low severity does not always mean low risk.
Recurrence can change risk significance.
Normalization may weak risk perception.
Detectability alone does not demonstrate control.
Inspection findings often reflect cumulative exposure rather than isolated events.
Most importantly:
Risks are sometimes underestimated not because information is missing, but because familiar problems gradually become accepted as normal.
What Good Looks Like
A mature QRM system:
evaluates recurrence alongside severity
monitors cumulative exposure
reassesses normalized conditions periodically
escalates meaningful patterns
challenges long-standing assumptions
Within Quality Risk Management (ICH Q9), risk evaluation should remain sensitive to changing conditions rather than becoming anchored to historic comfort levels.
Operational Perspective
Many significant inspection observations originate from weaknesses that organizations already knew existed.
The challenge is rarely identifying the issue.
The challenge is recognizing when recurring low-level concerns have accumulated into evidence of a broader governance problem.
Strong quality systems periodically challenge familiar assumptions and ask:
“If we observed this pattern for the first time today, would we still consider it low risk?”
That question often reveals underestimation long before an inspector arrives.
Explore more on Quality Risk Management
Browse VerethiQ resources on risk identification, risk analysis, risk control, risk acceptance, risk communication, and risk review in GMP systems.