QRM Terminology Explained

In Quality Risk Management, terminology is not just descriptive.
It determines how decisions are made.

Terms such as severity, likelihood, and detectability are used across risk assessments.
If they are interpreted inconsistently, decisions become inconsistent.

This directly affects:

  • Risk scoring

  • Control strategies

  • Escalation decisions

  • Inspection outcomes

Consistent terminology is a requirement for consistent decision-making within Quality Risk Management (ICH Q9).

What QRM Terminology Is Not

Terminology in QRM is often treated as:

  • Fixed definitions

  • Generic descriptions

  • Interchangeable terms

This approach creates problems.

Terminology is not static.
It must be defined within the context of decision-making.

Generic definitions do not ensure consistency.
Operational interpretation does.

Severity: What Impact Means in Practice

Severity refers to the impact of a failure.

However, severity must be defined clearly.

Impact may relate to:

  • Patient safety

  • Product quality

  • Data integrity

  • Regulatory compliance

Without defining what “impact” refers to, severity scoring becomes inconsistent.

For example:

  • A documentation error may be low severity for product quality

  • But high severity for data integrity

Severity must therefore be:

  • Context specific

  • Consistently interpreted

  • Aligned with defined criteria

Likelihood: What Probability Is Based On

Likelihood refers to the probability that a failure will occur.

This must be based on:

  • Historical data

  • Process performance

  • Known variability

  • Prior deviations

Likelihood should not be:

  • Assumed without data

  • Assigned based on convenience

  • Defaulted due to lack of information

When likelihood is not grounded in data, risk assessments become unreliable.

This is particularly relevant when distinguishing risk from uncertainty as explored in Risk vs Uncertainty in GMP.

Detectability: What Detection Actually Means

Detectability refers to the ability to identify a failure before it impacts product quality.

This must reflect:

  • Actual detection mechanisms

  • Real monitoring capability

  • Timing of detection

Common misinterpretations include:

  • Assuming detection exists because a control is defined

  • Overestimating detection capability

  • Ignoring delays in detection

For example:

  • A deviation detected during batch review is not early detection

  • A control that identifies failure after impact does not reduce risk effectively

Detectability must reflect real system performance, not intended design.

Risk Level: What “High”, “Medium”, and “Low” Mean

Risk levels are often expressed as categories.

However, these categories are only meaningful if:

  • Scoring criteria are defined

  • Thresholds are consistent

  • Actions are linked to levels

Without this:

  • “High risk” may be treated differently across teams

  • Escalation decisions become inconsistent

  • Control strategies vary without justification

Risk levels must be tied to defined decision criteria, not labels.

How Terminology Drives Decision-Making

Terminology is not used in isolation.
It directly influences decisions.

For example:

  • Severity affects impact assessment

  • Likelihood affects prioritization

  • Detectability affects control strategy

If these terms are interpreted differently:

  • Similar risks receive different scores

  • Similar situations result in different actions

This leads to inconsistency that is difficult to justify during inspection.

The role of structured decision-making in this process is outlined in Risk Management Process Steps.

Where Terminology Fails in Practice

Common issues include:

  • Undefined scoring scales

  • Inconsistent interpretation across teams

  • Mixing qualitative and quantitative definitions

  • Using terms without linking them to decisions

These failures result in:

  • Inconsistent risk scoring

  • Unclear justification

  • Weak alignment between risk and action

Terminology failure is often the root cause of decision inconsistency.

How Inspectors Evaluate Use of Terminology

Inspectors do not evaluate terminology definitions directly.
They evaluate how terminology is applied.

They assess whether:

  • Similar situations are scored consistently

  • Definitions align with actual decisions

  • Terminology reflects real system behavior

A common concern arises when:

  • Scoring appears structured

  • But decisions are inconsistent

This indicates that terminology is not being applied consistently.

Expectations for how risk is demonstrated are further outlined in Risk Demonstration in GMP.

Evidence of Effective Terminology Use

Effective systems demonstrate:

  • Clearly defined scoring criteria

  • Consistent interpretation across teams

  • Alignment between terminology and decisions

  • Linkage between risk levels and actions

Over time, this results in:

  • Predictable decision patterns

  • Reduced variability in risk assessment

  • Stronger inspection defensibility

Terminology is effective when it produces consistent decisions, not consistent definitions.

Regulatory Perspective

Regulators do not expect standardized terminology across all organizations.
They expect internal consistency.

Terminology should:

  • Support decision-making

  • Reflect actual system behavior

  • Be applied consistently across functions

When terminology is clearly defined and consistently applied, risk assessments become easier to justify.

When terminology is inconsistent, risk assessments lose credibility - even when tools are used correctly.


Previous
Previous

Risk Demonstration in GMP

Next
Next

Risk Management Process Steps