Human Error vs System Error

Human error is one of the most common conclusions in deviation investigations.

It is also one of the easiest conclusions to misuse.

A person may have missed a step, entered the wrong value, selected the wrong material, skipped a verification, or failed to follow an instruction. Those facts may be true. But they do not automatically explain why the deviation occurred.

In GMP investigations, “human error” should not be treated as the end of the investigation. It should be treated as the point where better questions begin.

What made the error possible?
Why did the existing controls not prevent it?
Why was the issue not detected earlier?
Was the procedure clear?
Was the task designed well?
Was the batch record usable?
Were handoffs, workload, equipment setup, labeling, or verification controls involved?
Was this event truly isolated, or has the same pattern appeared before?

These questions help distinguish individual action from system weakness.

A strong investigation does not only identify what happened. It shows why the event occurred, how the impact was assessed, and what action is appropriate to prevent recurrence.

 

Why Human Error Is Not Enough

Human error describes a behavior. It does not always explain a cause.

For example:

  • An operator forgot to record a value.

  • An analyst used the wrong standard.

  • A technician missed a cleaning step.

  • A reviewer failed to detect an incomplete entry.

Each statement describes something a person did or did not do. But each one leaves the main investigation question unanswered.

Why did that happen?

If the investigation stops at the behavior, the CAPA usually becomes predictable:

  • retrain the person

  • remind the team

  • revise awareness

Sometimes training may be appropriate. But if the real problem is unclear instructions, poor workflow, confusing form design, weak verification, similar-looking materials, inadequate segregation, unrealistic workload, or a fragile manual control, retraining will not address the condition that allowed the deviation.

That is why human error is often a weak root cause when used alone.

It may be part of the event sequence, but it rarely explains the full failure mechanism.

 

What System Error Means

A system error does not mean “the system is bad”.

It means the investigation looks beyond the individual action and evaluates the conditions that shaped the work.

Those conditions may include:

  • procedure clarity

  • training effectiveness

  • batch record or form design

  • equipment interface

  • material labeling or segregation

  • workload and staffing

  • line setup

  • room layout

  • handoffs between shifts or departments

  • supervision and oversight

  • verification or review controls

  • alarm, alert, or system design

  • recurring trends or prior related events

A system view asks how the process allowed the error to occur or remain undetected.

For example, if an operator selected the wrong material, the investigation should not stop at “operator selected incorrect material”. It should examine whether materials looked similar, were stored near each other, had similar item codes, lacked clear visual differentiation, were not scanned, or were not independently verified before use.

The person’s action is still part of the event.

But the system conditions explain why the action was possible.

 

The Problem with Blame-Based Investigations

A blame-based investigation can look complete.

The event is assigned to the person closest to the work. The CAPA is assigned quickly. The deviation is closed.

But the underlying vulnerability remains active.

This creates several problems.

First, the same type of event may happen again with a different person.

Second, the CAPA may not match the actual failure condition.

Third, repeated “human error” conclusions may signal that the organization is not investigating deeply enough.

Fourth, inspectors may challenge whether the company is using retraining as a default response instead of correcting system weaknesses.

A strong investigation does not remove accountability. It places accountability in the right place.

People are responsible for following procedures.
Supervisors are responsible for oversight.
QA is responsible for review.
The organization is responsible for designing processes that are clear, controlled, and capable of being executed reliably.

Human performance and system design are connected.

A good investigation respects both.

 

When Human Error May Be a Valid Root Cause

Human error should not be banned from investigations.

There are cases where individual action is a legitimate part of the cause.

For example, a trained and qualified person may knowingly bypass a required step. A person may fail to follow a clear instruction under normal working conditions. A person may perform an action outside procedure despite available controls.

Even then, the investigation should still ask whether the system response was adequate.

Was the procedure clear?
Was the person trained and qualified?
Was the requirement practical under actual working conditions?
Were there prior similar events?
Was supervision adequate?
Was the deviation detected by the expected control?
Were there warning signs that were missed?

A valid human error conclusion should be supported by evidence.

It should not be assumed because a person was involved.

The investigation record should show why other plausible causes were ruled out and why the selected conclusion is reasonable.

The report must make the reasoning visible. A reviewer should not have to rely on verbal explanation to understand why the root cause was selected.

 

How to Test Human Error Logic

A useful way to test human error logic is to ask whether another trained person could make the same error under the same conditions.

If the answer is yes, the investigation should look harder at the system.

Could the form design lead to missed entries?
Could the instruction be interpreted more than one way?
Could similar materials be confused?
Could the step be missed during a busy transition?
Could the verification control fail to detect the issue?
Could the same error occur on another shift, line, room, product, or batch?

This does not excuse the error. It helps identify the control weakness.

Another useful question is:

What would have prevented or detected the error before it affected the process or record?

If the answer is only “the person should have been more careful”, the investigation is probably not deep enough.

GMP systems should not depend entirely on perfect human attention. Manual steps may be necessary, but critical steps need appropriate controls, clear instructions, usable records, and effective verification.

 

Evidence Needed Before Concluding Human Error

A human error conclusion should be supported by evidence.

Depending on the event, useful evidence may include:

  • training and qualification records

  • procedure or batch record review

  • interview information

  • observation of the task or workflow

  • review of workload or shift conditions

  • equipment, system, or interface checks

  • review of related deviations or prior occurrences

  • assessment of supervision or independent verification

  • review of environmental, material, or process conditions

The point is not to collect every possible record. The point is to collect evidence that tests the most plausible causes.

Scope should follow the failure pathway. If the event involved manual execution, the scope should consider the conditions of manual execution, not only the person who performed the task.

Training records are a common example.

Completed training may show that the person was trained. It does not automatically prove that training was effective, that the procedure was clear, or that the task was designed reliably.

A retraining CAPA should be based on a confirmed training or knowledge gap.

Without that evidence, retraining becomes a weak default action.

 

Human Error and Procedure Problems

Many human error investigations eventually point back to procedure design.

A procedure may be technically accurate but difficult to use.

It may include too much information, bury critical steps, use unclear language, fail to match actual workflow, or require decisions that are not well defined.

In those cases, “failure to follow procedure” may not be the full root cause.

The deeper issue may be that the procedure did not support consistent execution.

A strong investigation should ask:

  • Was the instruction clear?

  • Was the sequence logical?

  • Was the acceptance criterion defined?

  • Was the required action observable?

  • Did the procedure match the actual process?

  • Were roles and responsibilities clear?

  • Was the required documentation easy to complete correctly?

If the procedure is unclear or poorly aligned with the work, retraining alone will not fix the problem. The CAPA should address the procedure, the record, or the control design.

 

Human Error and Verification Controls

Many deviations involve a missed check, incomplete review, or failed verification.

In these cases, the investigation should not only ask why the first person made the error. It should also ask why the verification process did not detect it.

Verification controls exist because human error is expected to some degree. If the verification control also fails, that is important evidence.

The investigation should consider:

  • Was the verification step clearly defined?

  • Was the reviewer independent where required?

  • Was the expected evidence available?

  • Was the review rushed or overloaded?

  • Was the batch record or form easy to review?

  • Was the review process designed to detect this type of error?

  • Did the reviewer understand what they were verifying?

A failed verification may point to a system weakness rather than a simple individual oversight.

If the CAPA only retrains the person who made the original error and ignores the failed detection control, the investigation may remain incomplete.

 

CAPA Implications

The distinction between human error and system error directly affects CAPA design.

If the investigation concludes that:

  • the cause is a knowledge gap, training may be appropriate

  • the cause is procedure ambiguity, the CAPA should address the procedure

  • the cause is poor form design, the CAPA should address the record or system design

  • the cause is weak verification, the CAPA should address the control

  • the cause is material confusion, the CAPA may involve labeling, segregation, scanning, visual controls, or process redesign

  • the cause is workload or handoff vulnerability, the CAPA may need to address staffing, scheduling, communication, or shift-transition controls

A CAPA becomes difficult to defend when it addresses the visible behavior but not the condition that allowed the behavior to occur.

This is why human error conclusions matter. A shallow conclusion leads to shallow action.

 

Common Weak Human Error Conclusions

Several human error conclusions appear repeatedly in GMP investigations.

Examples include:

  • “Operator did not follow procedure”

  • “Analyst error caused the result”

  • “Reviewer oversight caused the discrepancy”

  • “Technician failed to perform the step”

  • “Personnel were retrained”

These statements may describe part of the event, but they are not strong root causes by themselves.

A stronger conclusion should identify the specific failure condition.

For example:

The batch record verification instruction did not clearly define the required timing of the second-person check, allowing the step to proceed before verification was completed.

The material labels used similar naming conventions and were stored in adjacent locations without an independent barcode verification step.

The procedure required manual transcription of a critical value without an independent review point before batch continuation.

The cleaning checklist grouped multiple critical steps under one signoff, making it difficult to verify which individual step was missed.

These conclusions are stronger because they point to a condition that can be corrected.

 

Reviewer Questions for Human Error Findings

A QA reviewer should challenge human error conclusions carefully.

Useful reviewer questions include:

  • What evidence supports human error as the most probable cause?

  • Was the procedure clear and aligned with actual workflow?

  • Was the person trained, qualified, and experienced for the task?

  • Was the task easy to perform correctly under actual conditions?

  • Were workload, timing, handoff, layout, equipment, or material conditions relevant?

  • Were similar errors found in prior deviations or trends?

  • Did existing controls prevent or detect the issue as intended?

  • If retraining is proposed, what training or knowledge gap was confirmed?

  • What system change, if any, is needed to prevent recurrence?

  • Would the same error be likely with another trained person?

These questions do not assume that every human error conclusion is wrong. They test whether the conclusion is supported.

 

Final Thought

Human error is often visible. System weakness is often less visible.

That is why investigations need to look beyond the person closest to the event.

A defensible investigation does not ignore human action, and it does not automatically blame the system. It evaluates both. It asks whether the person’s action explains the event fully, or whether the process, procedure, control, design, workload, verification, or environment made the error possible.

The goal is not to remove responsibility.

The goal is to identify the condition that must change.

When investigations stop at human error, CAPAs often become retraining exercises. When investigations examine the system around the error, CAPAs become more specific, more useful, and easier to defend.

 

Explore more on Investigations & CAPA Excellence

Browse VerethiQ resources on deviation handling, root cause analysis, investigation quality, CAPA design, effectiveness checks, recurrence prevention, and investigation governance.

 
Next
Next

Writing Defensible Investigation Reports