What Belongs in a GMP Deviation

A strong GMP deviation record begins with a clear event description.

The opening deviation record does not need to prove root cause, finalize product impact, or define CAPA before the investigation has reviewed the evidence. But it does need to describe the event clearly enough to support triage, containment, scope, evidence collection, and investigation planning.

In the broader Pharmaceutical Investigations & CAPA process, the deviation record is often the starting point for the investigation lifecycle. If the event is described vaguely or with premature conclusions, the investigation can begin in the wrong direction.

As discussed in GMP Investigation Lifecycle: Step-by-Step, each investigation step should support the next. The opening deviation record should give the investigation enough factual grounding to proceed logically.

 

Deviation Record vs Investigation Record

The deviation record and investigation record are closely connected, but they do not serve the same purpose.

The opening deviation record should capture the event: what happened, what was expected, what was found, where and when it was detected, what may be affected, and what immediate actions were taken.

The investigation record then builds on that foundation. It evaluates scope, evidence, product and process impact, root cause, CAPA, effectiveness checks, and closure rationale.

A deviation record should not try to complete the investigation at the point of opening.

For example,

The required reconciliation entry for Component X was missing from Batch Record BR-102 during QA review.

The investigation may later determine why the entry was missed, whether other batches were affected, whether product impact exists, and whether CAPA is needed.

That distinction helps prevent premature conclusions.

 

Start With a Clear Event Description

The first purpose of a deviation record is to document what happened.

A good event description usually includes:

  • what was expected

  • what actually occurred

  • where it occurred

  • when it occurred or was detected

  • how it was detected

  • product, batch, lot, equipment, system, record, sample, room, or process involved

  • immediate status of the affected product, process, equipment, or material

The event description should not assume the root cause.

Weak example:

Operator failed to follow SOP.

Stronger example:

During QA review of Batch Record BR-102, the reconciliation entry for Component X was missing from the completed record.

The stronger version describes the observed departure. It does not decide why it happened.

If the deviation is opened as “operator failed to follow SOP”, the investigation may focus too quickly on the person. It may miss questions about record design, workflow, verification timing, training effectiveness, interruptions, or similar prior events.

A strong deviation record begins with the observed facts.

 

Include the Expected State and Actual State

A deviation record needs a reference point.

The record should explain what requirement, instruction, specification, limit, or approved condition was not met.

Examples include:

  • SOP requirement

  • batch record instruction

  • test method requirement

  • specification limit

  • environmental monitoring alert or action level

  • approved process parameter

  • cleaning requirement

  • equipment operating range

  • data integrity or documentation requirement

The deviation record should also clearly state what was actually found.

Clear example:

SOP-123 requires component reconciliation to be completed before QA batch record review. The reconciliation entry for Component X was incomplete at the time of QA review.

This wording shows both the expected state and the actual state. It gives the investigation a clearer basis for triage, impact assessment, and evidence collection.

Weak wording:

Document issue found.

Stronger wording:

The second-person verification signature was missing from the dispensing record for Material M-245 during QA review.

The stronger wording identifies what was missing, where it was missing, and when it was detected.

 

Document Detection Point and Timing

The deviation record should explain when and how the event was detected.

This may include:

  • date and time of occurrence, if known

  • data and time of detection

  • detection point

  • person or function detecting the event

  • whether the event was detected during processing, testing, review, release, audit, complaint review, or trending

Detection timing matters because it affects containment, impact, scope, and urgency.

For example, an issue detected during an in-process check may have a different risk profile than the same issue detected after batch completion or after product release.

The detection point helps the investigation understand how long the condition may have existed and which controls did or did not detect it earlier.

 

Identify What May Be Affected

The deviation record should identify what is potentially affected.

Depending on the event, this may include:

  • product name or code

  • batch or lot number

  • material or component

  • equipment or instrument

  • room or area

  • process step

  • system or software

  • document or record

  • sample or test

  • supplier or contract laboratory

  • relevant date or time range

This information supports containment and scope decisions.

For example, if a deviation involves a missing verification step, the affected batch and process step should be clear. If the deviation involves an environmental monitoring excursion, the room, sample location, date, time, organism information where available, and operational safety may matter.

The opening record should not leave QA guessing what may need to be controlled or investigated.

 

Capture Immediate Actions and Initial Status

A deviation record should document immediate actions taken to control the current situation.

Examples include:

  • product placed on hold

  • material segregated

  • process paused

  • equipment removed from service

  • QA notified

  • additional review initiated

  • samples secured

  • records preserved

  • access restricted

  • temporary control added

  • additional inspection performed

Immediate actions are not the same as CAPA.

Immediate actions control the current situation. CAPA addresses the supported cause or recurrence risk after investigation.

The deviation record should also state the current status at the time the event is opened.

Examples include:

  • batch in process

  • batch completed but not released

  • product released

  • material quarantined

  • equipment still in use

  • equipment removed from service

  • sample under testing

  • result pending confirmation

  • production paused

  • additional lots potentially under review

Initial status helps QA determine urgency. It does not need to be the final disposition.

 

Include Initial Risk Considerations

The opening deviation record does not need the final impact conclusion.

But it should identify obvious initial risk considerations, such as:

  • possible product quality impact

  • possible data integrity impact

  • possible patient or user risk

  • possible process control concern

  • possible repeat event

  • possible released product exposure

  • possible contamination or mix-up risk

  • possible effect on other batches, records, systems, or areas

Initial risk consideration helps determine investigation level and urgency. It should be based on available facts and updated if new evidence changes the understanding.

Weak wording:

No impact.

Stronger wording:

Final product impact assessment is pending. Batch remains on QA hold while the investigation evaluates whether the missing reconciliation entry affects component accountability or batch disposition.

The stronger wording avoids closing the impact question too early.

 

Preserve Important Evidence Early

Some evidence is time-sensitive.

The deviation record should help identify records, data, samples, or conditions that need to be preserved early.

Examples include:

  • batch record

  • logbook

  • audit trail

  • alarm history

  • sample

  • label or component

  • equipment state

  • environmental condition

  • system report

  • access log

  • raw data

  • photographs, where allowed by procedure

As discussed in Evidence Collection and Analysis in GMP Investigations, evidence should support the investigation’s claims, root cause logic, and impact decisions. If critical evidence is lost, overwritten, consumed, or changed before review, the investigation may become limited.

When evidence cannot be preserved, the limitation should be documented.

 

Identify Notifications and Needed Input

The deviation record should show appropriate notification and ownership.

Depending on the event, this may include:

  • QA

  • manufacturing supervisor

  • QC laboratory

  • engineering or maintenance

  • warehouse or materials

  • microbiology or environmental monitoring

  • validation

  • automation or computerized systems

  • supplier quality

  • contract laboratory or external partner

  • process owner

  • quality systems owner

Notification should match the event type and risk.

The opening deviation record may also identify who needs to provide process knowledge or investigation input. As discussed in Interviewing SMEs for GMP Investigations, SME input can help explain process reality, task conditions, handoffs, and controls that may not be fully visible in records alone.

 

Document Initial Classification, If Required

If the company procedure requires classification at opening, the deviation record should document the initial classification or investigation level.

Examples include:

  • minor, major, or critical

  • low, medium, or high risk

  • simple investigation or full investigation

  • quality event or deviation

  • product impact suspected or not suspected

  • potentially reportable or escalated category, where applicable

Initial classification should support triage. It should not lock the investigation into a conclusion before evidence is reviewed.

Classification may need to change if new information becomes available. For example, a deviation opened as low risk may require escalation if the event is repeated, product impact expands, or new evidence shows that the issue was not isolated as explained in Deviation Triage and Immediate Actions.

 

What Does Not Belong in the Opening Deviation Record

A deviation record should be factual. It should not turn the opening event description into a premature investigation conclusion.

Avoid including:

  • unsupported root cause

  • blame-based language

  • “operator error” before investigation

  • CAPA before cause is known

  • vague phrases such as “procedure not followed” without facts

  • final no-impact conclusions before assessment

  • assumptions that the event is isolated before scope or trend review

  • emotionally loaded wording

  • excessive unrelated detail

Weak wording:

Operator did not pay attention and failed to follow SOP.

Stronger wording:

The required second-person verification signature was missing from the dispensing record at QA review.

Opening a deviation record with a premature conclusion can create bias. The investigation may then look for evidence that confirms the early assumption rather than testing what actually happened. Cognitive Bias in GMP Investigations explains how the first explanation becomes the explanation that the investigation follows.

 

Short Deviation Example

Event: Missing reconciliation entry in a completed batch record.

A strong opening deviation record may state:

During QA review of Batch Record BR-102 on 12 March 2026, the reconciliation entry for Component X was found incomplete. SOP-123 requires component reconciliation to be completed before QA batch record review. Batch BR-102 is complete and remains on QA hold. QA and Manufacturing were notified. The batch record, component usage log, and material reconciliation worksheet were secured for investigation. Final product impact assessment and root cause analysis are pending.

This example includes the event, expected state, actual state, detection point, batch status, notification, evidence preservation, and pending investigation decisions.

It does not state that the operator caused the issue. It does not conclude “no impact”. It does not define CAPA before root cause is understood.

 

Practical Deviation Opening Checklist

Deviation Element What the Record Should Capture
Event description What happened, stated factually
Expected state Requirement, procedure, specification, or approved condition
Actual state What was observed or found
Detection point When, where, and how the event was detected
Affected item Product, batch, record, equipment, system, room, sample, or process
Immediate actions Containment, hold, segregation, notification, preservation, or temporary control
Initial status Current product, process, equipment, or material status
Initial risk Obvious product, process, data, patient, or recurrence concerns
Evidence preserved Records, data, samples, labels, logs, or system information secured
Notifications Functions informed or involved
Initial classification Risk level or investigation level, if required
 

QA Review Questions

QA Review Question What QA Should Confirm
Is the event factual? The description does not assume root cause
Is the requirement clear? The record explains what expectation was not met
Is the actual condition specific? The observed problem can be understood by a reviewer
Is detection timing documented? Occurrence and detection points are clear where known
Is the affected item identified? Product, batch, system, record, equipment, or process is clear
Were immediate actions appropriate? Current risk was contained or controlled
Was key evidence preserved? Time-sensitive evidence was secured or limitations documented
Is classification justified? Initial risk or investigation level matches available facts
Are premature conclusions avoided? RCA, impact, and CAPA are not finalized before evidence supports them
 

QA Review Perspective

What belongs in a deviation record is enough factual information to support triage, containment, scope, evidence collection, and investigation planning.

A strong deviation record does not need to answer every investigation question at opening. It needs to define the event clearly enough that the investigation can proceed in the right direction.

The best deviation records are specific, factual, and careful about what is known versus what still needs to be determined. They describe the departure, identify the expected and actual state, capture immediate control, preserve important evidence, and avoid premature root cause or impact conclusions.

That foundation makes the investigation easier to scope, easier to review, and easier to defend.

 

Explore more on Investigations & CAPA Excellence

Browse VerethiQ resources on deviation handling, root cause analysis, investigation quality, CAPA design, effectiveness checks, recurrence prevention, and investigation governance.

 
 
Next
Next

When to Reopen a GMP Investigation