Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here

Deviation Management in GxP: Classification, Investigation, and Resolution

How GMP deviations move from first report through closure: classification criteria, investigation depth, impact assessment, batch disposition, trending, and what separates a real investigation from a paperwork exercise.

A deviation is any departure from an approved procedure, specification, or established standard during a GxP activity. They happen in every regulated operation, drug manufacturing, biologics, cell and gene therapy, combination-product assembly, clinical trial conduct, and analytical testing, because the work involves people, equipment, and materials that do not always behave as planned.

The measure of a quality system is not whether deviations occur. It is whether they are captured, understood, and resolved in a way that protects product quality and prevents recurrence. A facility with no deviations in its records is not operating deviation-free. It is failing to report them, which is worse. Inspectors know this, and a suspiciously clean deviation log invites harder questions than a busy one.

This article walks the full path of a deviation: what opens one, how it gets classified, what a real investigation answers, how the batch fate is decided, who owns each decision, and how the pattern across many deviations tells you whether your quality system is actually working. Read it once and you should be able to triage an event at the bench, write a defensible investigation, defend a disposition to an inspector, and answer the deviation questions in an interview.


What a Deviation Is, and Why the Regulation Requires Investigation

Before the mechanics, fix the regulatory basis, because every step downstream is anchored to it.

21 CFR 211.192: “Any unexplained discrepancy … or the failure of a batch or any of its components to meet any of its specifications shall be thoroughly investigated, whether or not the batch has already been distributed.”

That single sentence is the legal spine of deviation management in the US. The word “deviation” does not appear in the regulation, but the obligation to investigate any discrepancy, thoroughly, and regardless of whether product already shipped, is unambiguous. EU GMP (EudraLex Volume 4, Part I, Chapter 1) requires that deviations are recorded, investigated, and resolved with corrective and preventive action as a core element of the pharmaceutical quality system. ICH Q10 frames CAPA and management review as continuous quality system activities. For the device-constituent part of a combination product, the same expectation flows through nonconformance and CAPA processes under 21 CFR 820, now aligning to the Quality Management System Regulation, the QMSR, which incorporates ISO 13485 effective February 2026.

The quality rationale is simpler than the citations. Every deviation is a moment where reality diverged from the controlled, validated state you committed to in your filing. If you do not investigate it, you do not know whether the product is safe, whether the data is trustworthy, or whether the same gap is sitting in the next batch. The investigation converts an uncertain event into a bounded, defensible decision.


What Triggers a Deviation

Deviations get opened when something departs from the approved way of working. Common triggers:

  • A step in a batch manufacturing record was not performed as written
  • A process parameter went outside its specified range during manufacturing
  • A raw material or product was stored at the wrong temperature
  • Equipment was used in production after going out of calibration, and the issue was caught later
  • A step was performed in the wrong order
  • The wrong document or document version was used
  • A sample was handled incorrectly before testing
  • Environmental monitoring results exceeded alert or action limits
  • A utility, system, or instrument failed during a production run
  • A computerized system produced an unexpected result, lost data, or behaved outside its validated state

The triggering event must be documented at the time it is discovered, or as close to it as the situation allows. Deviations written hours or days after the fact raise data integrity concerns, because the contemporaneous record is the one a regulator trusts. The initial report does not need to be complete on day one, but it must capture the time of discovery, who found it, and a factual description of what was seen. Detail can follow; the timestamp cannot be reconstructed later without undermining the record. This is the same ALCOA+ logic that governs all GxP records, covered in ALCOA+ in detail.

A useful discipline for new staff: when you are unsure whether something counts as a deviation, open one anyway. It is always defensible to investigate an event that turned out to be nothing. It is never defensible to have stayed silent about an event that turned out to matter. When you are unsure whether an event is a deviation, a complaint, a quality event, or an out-of-specification result, the quality event classification and triage process routes it; do not let routing ambiguity become a reason to delay opening a record.

What goes in the initial report

The opening record does not investigate anything. It freezes the facts. A good initial deviation report contains:

FieldWhat goes in itWhy it matters
Unique IDAuto-assigned record numberTraceability, trending, audit pull
Date/time of discoveryWhen it was found, not when it was writtenContemporaneity, scope of affected window
Date/time of occurrenceWhen the event happened, if knownDefines the affected batch/period
Discovered byName and roleAttributability, follow-up
Product/batch/lotWhat was affectedDisposition scope
Area/process/systemWhere it happenedRouting to the right owner, trending
Factual descriptionWhat was observed, no speculation, no conclusionThe record an inspector reads first
Immediate actions takenQuarantine, line stop, segregationShows containment
Provisional classificationCritical/Major/Minor pending assessmentSets urgency

The single most common opening defect is editorializing. “Operator carelessly skipped the mix step” is a conclusion and an accusation. “Mix step 7.3 was not recorded as performed; operator states it was performed but not documented” is a fact. Write the fact.


Planned vs. Unplanned Deviations

Unplanned deviations are what most people picture. Something went wrong unexpectedly: equipment malfunctioned, an operator made an error, a reagent was added in the wrong sequence, a power dip stopped a mixer mid-cycle.

Planned deviations are intentional, pre-approved departures from a procedure. If a process step needs to be modified for a specific batch because of known circumstances, a planned deviation (sometimes called a temporary change or a temporary exception) documents the change before it happens. A planned deviation should require Quality Assurance approval before the batch is manufactured, state the specific modification and its rationale, define the duration or number of batches it covers, and include an impact assessment for that scope.

Planned deviations are not a workaround for weak procedures. If the same planned deviation is requested again and again, that is a signal the underlying procedure needs to be fixed through change control, not patched repeatedly. Regulators read a stack of identical planned deviations the same way: as evidence the official procedure no longer describes how the work is actually done.

Some quality systems have moved away from the term “planned deviation” entirely, preferring “temporary change” handled within change control, because the word “deviation” implies an unforeseen problem. The naming matters less than the control: the change must be assessed and authorized before execution, with a defined end point.


Classification: Critical, Major, Minor

Classification determines the urgency and the depth of investigation. Exact definitions vary by site, but the typical three-tier framework is consistent across the industry.

ClassDefinitionExamplesTypical response
CriticalCould directly affect patient safety, product efficacy, or data integrity in a way that may not be remediableSterile product made after a major air-handling failure; batch made with an unapproved substituted API; confirmed contamination of filled product; deletion of GMP data with no recoverable recordImmediate QA escalation, possible batch rejection, full root cause investigation, senior management notification
MajorA significant GMP departure that may affect product quality or the integrity of records, but the risk can be assessed and may be manageableProcess parameter exceeded its limit but stayed within a wider justified range; a required signature missing although the activity was performed correctly; a calibration overdue but instrument later confirmed in toleranceFull investigation, batch disposition based on impact assessment, CAPA where root cause requires a change
MinorLow-risk procedural error with no likely impact on product quality, safety, or critical recordsDate written in the wrong format; a transcription error on a non-critical field that does not affect the result; minor administrative slipDocumented and investigated briefly; action may be retraining or a note for trending

How to classify, in sequence

Classification is a decision, not a label you reach for. Work it in order:

  1. Could this affect the patient or the product? If yes, you are at least Major, and you go to step 2. If genuinely no impact is plausible (a clerical slip on a non-critical field), you are Minor.
  2. Is the potential harm remediable and boundable? If the risk can be tested, quantified, and contained, Major. If it may be undetectable, irreversible, or affects a sterility/identity/strength attribute you cannot fully verify, Critical.
  3. Does it touch data integrity? Loss, alteration, or unattributable change of a GMP record pushes the classification up regardless of the product impact, because the trustworthiness of the record itself is in question.
  4. When in doubt, classify up. It is cheap to downgrade later with documented justification. It is expensive, and looks deliberate, to be caught having classified down.

A formal severity-times-detectability rationale ties classification to quality risk management and to the broader audit finding classification logic; the same risk thinking applies.

Two practical cautions sit on top of the table.

First, the real danger is under-classification to avoid the workload of a full investigation. An inspector who finds critical process deviations sitting in the records as “minor,” with no meaningful investigation behind them, will escalate that finding hard, because it suggests the whole classification step is being used to dodge work rather than to manage risk.

Second, classification can be provisional at opening. You may open a deviation as “major” pending the impact assessment and later, with documented justification, reclassify it. What you should never do is start with the answer you want (minor, quick close) and reason backward. Classify on what you know, escalate readily, and let the investigation confirm or downgrade.


The Investigation Process

A deviation investigation has to answer a specific set of questions. The quality of the investigation depends on actually answering them with evidence, not on filling every box in the form.

What happened? Describe the event factually and specifically. Not “environmental monitoring exceedance” but “viable airborne count at sample point EM-04 in filling room Zone B returned 12 CFU on 2026-06-01 against an action limit of 5 CFU.” Specificity here sets the scope for everything downstream.

What was the actual vs. expected? State the requirement that was not met: the numerical limit, the procedural step, the required condition. This frames the gap precisely and stops the investigation from drifting into unrelated territory.

Was product or process affected? The impact assessment determines the fate of the batch. It addresses whether product was at risk, whether the event was isolated to one point or potentially broader (other batches, other lines, the same shift), and whether the product is suitable for release. This is where manufacturing and QA often disagree, and QA’s conclusion is the one that controls.

What was the root cause? Root cause is not the same as immediate cause. The immediate cause of a filling room exceedance might be “personnel traffic exceeded the defined threshold during filling.” The root cause might be “gowning records did not capture headcount, so the traffic limit was never actually enforced.” Common structured methods include 5-Why analysis, fishbone (Ishikawa) diagrams sorted by the classic categories (people, process, equipment, materials, environment, measurement), and fault tree analysis for more complex failures. The method matters less than the rigor and the willingness to keep asking why until the answer points to something the organization controls. The full toolkit is in root cause analysis techniques, and the specific trap of stopping at the operator is covered in human error in deviations.

What corrective action was taken? Corrective action addresses the situation in front of you right now. For the exceedance: re-sampling, additional cleaning, cleaning verification, holding the affected units. Corrective action is immediate and specific to this event.

What preventive action is needed? Preventive action stops recurrence. If the root cause was untracked headcount, the action might be to add a headcount log to the gowning procedure and to include headcount in the environmental monitoring trend review. When the fix requires a real process, system, or document change, the deviation should feed a formal CAPA so the change is tracked to completion and later checked for effectiveness through CAPA effectiveness verification.

When is the deviation closed? A deviation cannot close until the impact assessment is complete, the affected batch disposition is decided, corrective actions are done, and any required CAPA is opened. QA owns the close decision.

A step-by-step procedure

The questions above are answered through a sequence. A workable flow:

  1. Contain. Quarantine affected product, segregate suspect material, stop the line or system if the event may still be propagating. Containment happens before investigation, not after.
  2. Open and describe. Record the facts (the initial report fields above) and assign provisional classification.
  3. Assess immediate impact. Decide what is at risk right now: which batch, which lot, which data set.
  4. Define scope. Ask “what else could be affected?” not only “is this batch affected?” Same equipment since last verified clean, same raw material lot, same shift, same configured system.
  5. Investigate root cause. Apply a structured method. Gather evidence: records, audit trails, interviews, retained samples, calibration history.
  6. Confirm impact and disposition. Targeted testing or analysis to bound the risk; QA makes the disposition call.
  7. Define CAPA. Corrective action for the event, preventive action for the cause, each with an owner and due date.
  8. Close. QA verifies all elements are complete and approves closure. CAPA continues to its own timeline with an effectiveness check.

Acceptance criteria: what good looks like

You know an investigation is done correctly when:

  • The description is specific enough that a stranger could understand the event without asking you.
  • The stated root cause, if removed, would have prevented the event, and it points to something the organization controls (not “operator carelessness”).
  • The scope explicitly addresses other potentially affected batches, lots, and records, and either includes or excludes them with a reason.
  • The disposition reads like an argument (risk, evidence, conclusion), not a verdict.
  • The CAPA addresses the root cause, not just the symptom, and has an owner and a date.
  • The whole record is internally consistent: the classification matches the impact, the CAPA matches the root cause, the disposition matches the impact assessment.

A worked example ties these together. A blend uniformity step was run for 12 minutes instead of the validated 15. Immediate cause: the operator misread the batch record timer field. Impact assessment: additional blend uniformity and content uniformity samples pulled and tested; results within specification. Root cause: the batch record listed the mix time in a column adjacent to a similar field, and three prior near-misses on the same form were never trended. Corrective action: this batch tested and held pending disposition. Preventive action via CAPA: redesign the batch record field layout and add the form to a periodic human-factors review. Notice the retraining everyone reaches for first (“retrain the operator”) is not the fix here, because the form invites the error from anyone.

A second worked example, a combination product

The framework carries across modalities. A prefilled-syringe combination product line records a deviation: the break-loose and glide force on a critical fill-finish step logged outside its qualified range because the crimping force on the plunger-stopper had drifted. Immediate cause: the crimp-force sensor had drifted out of calibration. Scope: every unit assembled on that station since the last verified-good calibration check, 14 days prior, roughly 4,100 units. Root cause: the calibration interval was set on a fixed annual schedule with no in-use verification, so two weeks of drift went undetected. Disposition: units in inventory re-tested for container-closure integrity and dose-delivery performance; units already distributed assessed through product complaint handling and a possible field action. CAPA: add a daily station-level crimp-force verification and shorten the calibration interval based on observed drift, fed through the calibration and metrology program. Same logic, different modality.


Impact Assessment and Batch Disposition

This is the most consequential output of a deviation. The question is whether product made during or after the deviation meets its specifications and can be released.

For some deviations the answer is straightforward. A typographical error on a batch record with no bearing on manufacturing execution does not affect product quality; the batch is released with the deviation documented and closed.

For others, additional testing is needed. If a process parameter went out of range, the impact assessment should identify the specific quality attributes that could be affected and call for testing targeted at that risk. The testing is designed to answer the specific question raised by the deviation, not to re-test everything in the hope that a clean result excuses the event. Over-testing to “prove” a batch is fine, then releasing on a single passing result, is a pattern inspectors watch for, and it overlaps with the logic that governs out-of-specification investigations.

For critical deviations, or any deviation where testing cannot adequately bound the risk, rejection is the right outcome. Product that may be compromised must not enter distribution, regardless of commercial pressure. The disposition decision and its rationale belong in the record. A defensible disposition reads like an argument: here is the risk, here is the evidence, here is why the evidence supports (or does not support) release. A weak disposition reads like a conclusion with nothing behind it. Disposition sits within the wider discipline of batch record review and the formal batch disposition decisions process, where the deviation, its investigation, and its conclusion are confirmed before any release. In the EU, the Qualified Person carries personal legal responsibility for that release; see QP batch release under Annex 16.

A worked disposition rationale

A defensible disposition reads roughly like this:

Risk: Mixing time was 3 minutes short of the validated 15-minute blend, which could under-blend the active and produce non-uniform content. Evidence: 10 additional blend uniformity samples (top, middle, bottom, drum positions) returned a mean of 99.2% with RSD 1.8%, within the validated acceptance of 90 to 110% and RSD not more than 5%; content uniformity on 30 dosage units met USP <905>. Prior validation showed the blend reaches uniformity by minute 9. Conclusion: the evidence bounds the risk; the 12-minute blend achieved acceptable uniformity. Disposition: release. CAPA addresses the batch-record layout that caused the misread.

Note what makes it defensible: the testing was chosen to answer the exact question the deviation raised (uniformity), the acceptance criteria are stated, and the conclusion follows from the data rather than from a desire to ship.


Common Investigation Failures

These are the patterns that turn up repeatedly in inspection findings and internal audits.

Root cause that isn’t a root cause. “Human error” is an immediate cause, not a root cause. The real question is what allowed or enabled the error: inadequate training, an unclear or badly laid out procedure, excessive workload, poor workspace design, a missing safeguard, a confusing interface. An investigation that ends at “operator error” has stopped one question too early. A useful test: if your stated root cause cannot be addressed by anything other than telling a person to try harder, you have not found it.

CAPA that doesn’t address the root cause. A retraining action against a deviation caused by an ambiguous procedure fixes nothing. The procedure is still ambiguous, and the next person to use it makes the same mistake. Retraining is legitimate when a competent person genuinely did not know the requirement; it is a fig leaf when the system itself produced the error.

Investigations completed too slowly. Regulators expect investigations to be timely. 21 CFR 211.192 sets the expectation that discrepancies and batch failures are thoroughly investigated, but it sets no numerical deadline. The 30-day target many firms align deviation closure to is a widely used internal practice borrowed from the FDA out-of-specification guidance, not a CFR requirement, so cite it as an internal commitment rather than a regulatory rule. Whatever the target, extend it only with a documented, justified rationale. Investigations that drift for months with no rationale become findings in their own right, and a backlog of open deviations signals a quality unit that cannot keep up.

Copy-paste investigations. When similar deviations across a site carry nearly identical investigation text, it usually means the investigations are not being done substantively. Each event happened under specific circumstances; each investigation should reflect them. Boilerplate root causes (“operator did not follow procedure”) repeated across dozens of records are a red flag for both auditors and trending.

Batch released without completing the investigation. There is sometimes commercial pressure to release product before the investigation closes. A batch can be released against an open investigation only when QA has made a documented, risk-based determination that the work done so far supports release. “We need to ship” is not that determination. The standard is whether the evidence in hand bounds the risk, with the remaining investigation steps unable to reverse a release decision.

Scope set too narrow. A deviation found on one batch may apply to every batch made on the same equipment since the last verified clean point, or to every lot of a shared raw material. An investigation that asks “is this batch affected?” without asking “what else is affected?” can leave compromised product in distribution. Scope is part of the impact assessment, not an afterthought.

No CAPA on a recurring event. When the same root cause appears for the third time and the record still closes with “retrain,” trending has failed and so has the quality system. A recurrence is direct evidence that an earlier CAPA was ineffective and must escalate, not repeat.


Deviations and Computerized Systems

A growing share of deviations now originate from computerized systems rather than from a bench operator or a piece of mechanical equipment, and they need a slightly different lens.

When a validated system behaves outside its expected state, the deviation has to consider data integrity as a first-class concern, not just product quality. Questions that belong in these investigations: Was any GMP record lost, altered, or rendered unattributable? Does the audit trail explain what happened? Could the same fault have silently affected earlier records that no one flagged? A transient calculation error in a laboratory data system, for instance, may have produced wrong results on prior runs that already passed review, which widens the scope well beyond the batch in front of you.

A few categories show up often:

  • Unexpected results or calculations from a configured system, where the question is whether the configuration drifted from its validated state
  • Data not saved, partially saved, or saved to the wrong location, where the integrity of the affected records must be confirmed before any disposition
  • Access or permission events, where someone performed an action their role should not have allowed, raising both an integrity and a CSV access control question
  • Interface or transfer failures between two systems, where a record may exist correctly in one and be missing or corrupted in the other

Treat the audit trail as primary evidence here. A well-designed system records who did what and when; the investigation should reconcile that trail against what the people involved describe. Where the two disagree, the contemporaneous system record usually wins, which is exactly why audit trail design and review and the principles in data integrity foundations sit so close to deviation management. If a system fault keeps generating deviations, the fix is rarely a procedure: it is usually a configuration correction or a re-validation handled through change control, consistent with 21 CFR Part 11 and EU Annex 11.


Roles and Responsibilities

Deviation management only works when responsibilities are clear, and a common cause of weak investigations is that no single owner was ever assigned. The table below shows the typical split. Titles vary, but the separation of duties does not.

RoleResponsibility in a deviation
Discoverer (any GxP staff)Contain, open the record, capture facts contemporaneously
Area owner (Manufacturing, Lab, Warehouse, Engineering, QC)Lead the investigation, supply process knowledge, propose impact and disposition
Subject matter expertsContribute to root cause and impact analysis (validation, microbiology, automation, metrology)
Investigation ownerDrive the investigation to a real root cause, coordinate CAPA, hit the timeline
Quality AssuranceReview for rigor, own classification, own disposition, approve close, own CAPA oversight
Site/quality leadershipNotified on critical events, resource the investigation, own management review of trends
Qualified Person (EU)Cannot certify a batch for release with an unresolved relevant deviation

The principle that holds it all together is the independence and final authority of the quality unit.

21 CFR 211.22(a): the quality control unit has “the responsibility and authority to approve or reject all components, drug product containers, closures, in-process materials, packaging material, labeling, and drug products.”

In a deviation, that translates to a simple rule: the area that performed the work may propose a disposition, but QA decides it, and QA can reject a release that the business badly wants. An investigation where production both diagnoses the problem and clears its own product, with QA rubber-stamping, is a governance weakness an auditor will probe. For the wider map of who does what across a quality organization, see GxP roles and responsibilities.


Individual deviations are events. The pattern of deviations across a facility over time is information about the health of the manufacturing process and the quality system.

Trending typically examines:

  • Deviation rate by area, process, system, or product
  • Deviation rate by category (procedure deviation, equipment failure, documentation error, material issue, computerized system event)
  • Recurrence of deviations sharing the same or a similar root cause
  • Time-to-closure by classification, and the size of the open backlog
  • Deviations clustered around a specific shift, team, instrument, or supplier

A small worked trend makes the point. Suppose the EM program logs the following over a quarter:

Root cause categoryQ1Q2Q3
Untracked personnel traffic247
Sampling technique323
Equipment/HVAC110

The flat lines are noise. The rising line (untracked traffic, 2 to 4 to 7) is signal: an earlier CAPA, if one was opened, is not holding, and the next action must escalate rather than repeat. That is exactly the effectiveness-check failure trending exists to catch.

Trending is a management review input and a required feed into the pharmaceutical quality system and management review under ICH Q10. It also feeds the site quality metrics and KPIs. A manufacturing area with a rising deviation rate, or a persistent recurrence of the same root cause, signals that the CAPAs opened against earlier events were not effective. That is an effectiveness-check failure, and it should generate a new, escalated CAPA rather than another round of the same retraining. A single deviation that keeps recurring on a slow drift, rather than failing a hard limit, may be better surfaced through out-of-trend investigations.

The cultural read matters as much as the numbers. A rise in minor deviations after a reporting push can be a good sign: people are surfacing things they used to hide. A flat line of zero in a busy area is almost always a reporting problem, not a quality triumph. Read the trend in context, and pair it with the broader signals discussed in quality culture and data integrity failures.


Regulatory Expectations

21 CFR 211.192 requires a thorough investigation of any unexplained discrepancy or the failure of a batch or any of its components to meet its specifications, whether or not the batch was already distributed. The regulation does not use the word “deviation,” but the requirement to investigate is unambiguous, and it is the anchor most US inspectors cite.

In the EU framework, the EudraLex Volume 4 GMP guidelines treat deviation handling as a core quality system element. Chapter 1 (Pharmaceutical Quality System) expects deviations to be recorded and investigated with appropriate CAPA, and ICH Q10, “Pharmaceutical Quality System,” frames CAPA and management review as ongoing parts of the quality system rather than reactions to single events. The MHRA and EMA have been consistent in guidance and inspection practice that inadequate investigation of deviations is a significant GMP deficiency. For APIs specifically, ICH Q7 carries the equivalent expectation; see ICH Q7 API GMP. The differences between US and EU inspection emphasis are covered in FDA vs EMA inspection dynamics.

Inspectors will pull a sample of deviation records, usually recent ones plus any tied to the product under inspection, and assess whether the investigation was timely, whether the root cause was genuinely investigated rather than asserted, whether corrective and preventive actions addressed that root cause, and whether the batch disposition was defensible on the evidence. They will also follow a thread: a deviation that names a recurring root cause, then the CAPA, then the effectiveness check, then the trend. If that thread breaks anywhere, the finding widens.

A well-run deviation system is evidence of a quality culture that takes problems seriously: events surface quickly, get classified honestly, get investigated to a real cause, and feed corrections that actually hold. A system full of late closures, generic root causes, and retraining CAPAs tells inspectors the opposite, no matter how clean the front page of the procedure looks. For how this evidence is read during an audit, see FDA inspection readiness.


Interview-Ready: Questions You Will Be Asked

These come up in QA, manufacturing, and validation interviews, and in front of inspectors. Short, correct answers below.

What is the difference between a deviation, an OOS, and a complaint? A deviation is a departure from an approved procedure or condition during a GxP activity. An OOS is a test result that falls outside its specification, investigated under its own process (out-of-specification investigations). A complaint comes from outside, usually a patient, customer, or distributor, reporting a problem with a marketed product (product complaint handling). They can feed each other (an OOS often opens a deviation, a complaint can trigger one) but they are distinct records.

What is the difference between immediate cause and root cause? Immediate cause is what directly produced the event (operator misread the field). Root cause is what allowed it (the form invited the misread and prior near-misses were never trended). If your “root cause” is fixable only by telling someone to be more careful, it is not the root cause.

When can you release a batch with an open deviation? Only when QA makes a documented, risk-based determination that the evidence in hand bounds the risk and no remaining investigation step could reverse a release decision. Commercial pressure is never the justification.

Why is “retraining” a weak CAPA? Because most errors are not knowledge gaps. If a competent, trained person made the error, retraining the same content changes nothing. Retraining is valid only when the person genuinely did not know the requirement.

Who owns the disposition decision? Quality Assurance. The area that did the work can propose, but per 21 CFR 211.22 the quality unit has the authority to approve or reject, and that authority cannot be delegated to the people who made the product.

How do you set the scope of an investigation? Ask “what else could be affected?” not only “is this batch affected?” Same equipment since the last verified clean point, same material lot, same shift, same configured system. Scope is part of the impact assessment.

What regulation requires deviation investigation in the US? 21 CFR 211.192. It does not say “deviation,” but it mandates a thorough investigation of any unexplained discrepancy or batch/specification failure, distributed or not.

What does a good investigation timeline look like? Many firms target 30 days for closure, mirroring OOS timelines, with extensions only on a documented, justified rationale. A backlog of overdue open deviations is itself an inspection finding.


Practical Tips

  • Write the initial description as if the reader has never seen your process. Specificity at opening saves rework at closing.
  • Contain first, investigate second. A line left running while you write the deviation can turn one affected batch into ten.
  • Default to classifying up. Downgrading later with justification is routine; explaining why you classified a critical event as minor is not.
  • Read the audit trail before you interview anyone on a system deviation. The record is your most reliable witness.
  • Treat every recurrence as a failed CAPA, not a fresh event. Escalate it.
  • Keep the disposition rationale and the testing it relied on in the record. “Tested and passed” with no criteria is not a rationale.
  • Cross-link related work: a deviation often spawns a CAPA, draws on root cause analysis techniques, and ends in a batch disposition decision. Knowing those connections is half of doing the job well. For interview preparation across the wider quality domain, see GxP quality interview preparation.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.