QRM Terminology Explained
In Quality Risk Management, terminology is not just descriptive.
It determines how decisions are made.
Terms such as severity, likelihood, and detectability are used across risk assessments.
If they are interpreted inconsistently, decisions become inconsistent.
This directly affects:
Risk scoring
Control strategies
Escalation decisions
Inspection outcomes
Consistent terminology is a requirement for consistent decision-making within Quality Risk Management (ICH Q9).
What QRM Terminology Is Not
Terminology in QRM is often treated as:
Fixed definitions
Generic descriptions
Interchangeable terms
This approach creates problems.
Terminology is not static.
It must be defined within the context of decision-making.
Generic definitions do not ensure consistency.
Operational interpretation does.
Severity: What Impact Means in Practice
Severity refers to the impact of a failure.
However, severity must be defined clearly.
Impact may relate to:
Patient safety
Product quality
Data integrity
Regulatory compliance
Without defining what “impact” refers to, severity scoring becomes inconsistent.
For example:
A documentation error may be low severity for product quality
But high severity for data integrity
Severity must therefore be:
Context specific
Consistently interpreted
Aligned with defined criteria
Likelihood: What Probability Is Based On
Likelihood refers to the probability that a failure will occur.
This must be based on:
Historical data
Process performance
Known variability
Prior deviations
Likelihood should not be:
Assumed without data
Assigned based on convenience
Defaulted due to lack of information
When likelihood is not grounded in data, risk assessments become unreliable.
This is particularly relevant when distinguishing risk from uncertainty as explored in Risk vs Uncertainty in GMP.
Detectability: What Detection Actually Means
Detectability refers to the ability to identify a failure before it impacts product quality.
This must reflect:
Actual detection mechanisms
Real monitoring capability
Timing of detection
Common misinterpretations include:
Assuming detection exists because a control is defined
Overestimating detection capability
Ignoring delays in detection
For example:
A deviation detected during batch review is not early detection
A control that identifies failure after impact does not reduce risk effectively
Detectability must reflect real system performance, not intended design.
Risk Level: What “High”, “Medium”, and “Low” Mean
Risk levels are often expressed as categories.
However, these categories are only meaningful if:
Scoring criteria are defined
Thresholds are consistent
Actions are linked to levels
Without this:
“High risk” may be treated differently across teams
Escalation decisions become inconsistent
Control strategies vary without justification
Risk levels must be tied to defined decision criteria, not labels.
How Terminology Drives Decision-Making
Terminology is not used in isolation.
It directly influences decisions.
For example:
Severity affects impact assessment
Likelihood affects prioritization
Detectability affects control strategy
If these terms are interpreted differently:
Similar risks receive different scores
Similar situations result in different actions
This leads to inconsistency that is difficult to justify during inspection.
The role of structured decision-making in this process is outlined in Risk Management Process Steps.
Where Terminology Fails in Practice
Common issues include:
Undefined scoring scales
Inconsistent interpretation across teams
Mixing qualitative and quantitative definitions
Using terms without linking them to decisions
These failures result in:
Inconsistent risk scoring
Unclear justification
Weak alignment between risk and action
Terminology failure is often the root cause of decision inconsistency.
How Inspectors Evaluate Use of Terminology
Inspectors do not evaluate terminology definitions directly.
They evaluate how terminology is applied.
They assess whether:
Similar situations are scored consistently
Definitions align with actual decisions
Terminology reflects real system behavior
A common concern arises when:
Scoring appears structured
But decisions are inconsistent
This indicates that terminology is not being applied consistently.
Expectations for how risk is demonstrated are further outlined in Risk Demonstration in GMP.
Evidence of Effective Terminology Use
Effective systems demonstrate:
Clearly defined scoring criteria
Consistent interpretation across teams
Alignment between terminology and decisions
Linkage between risk levels and actions
Over time, this results in:
Predictable decision patterns
Reduced variability in risk assessment
Stronger inspection defensibility
Terminology is effective when it produces consistent decisions, not consistent definitions.
Regulatory Perspective
Regulators do not expect standardized terminology across all organizations.
They expect internal consistency.
Terminology should:
Support decision-making
Reflect actual system behavior
Be applied consistently across functions
When terminology is clearly defined and consistently applied, risk assessments become easier to justify.
When terminology is inconsistent, risk assessments lose credibility - even when tools are used correctly.