Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Form Plug-and-play starting point Quality Assurance

Form: Root Cause Statement Defensibility Check Worksheet

A plug-and-play worksheet an investigator or reviewer runs against a drafted root cause statement before it is finalized, testing whether it explains the event, traces to evidence, and would actually prevent recurrence, with a filled specimen.

Document type: Form

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use worksheet. It does not replace a root cause analysis method (fishbone, five whys, fault tree); it is a final writing-quality gate run on the root cause statement after the analysis is done, before it is written into the investigation record. Replace every <<FILL: ...>> placeholder with your own specifics. A filled specimen follows.

Worksheet control header

FieldEntry
Worksheet number<<FILL: FORM-ID, e.g. FORM-QA-044>>
Governing SOP<<FILL: SOP-ID for deviation / investigation management>>
Parent deviation / investigation reference<<FILL: DEV/INV-ID>>
Version<<FILL: version>>

1. Draft root cause statement

FieldEntry
Draft root cause statement (as currently written)<<FILL: paste the exact sentence or passage>>
Root cause analysis method used<<FILL: five whys / fishbone / fault tree / other>>
Drafted by (name, date)<<FILL>>

2. The three-question defensibility test

Answer each question against the draft statement in section 1. A No on any question means the statement is not yet ready to finalize.

#QuestionYes / NoIf No, what is missing
1Does the statement explain why the failure was possible as a system property (a missing check, an ambiguous instruction, a design or maintenance gap), not only what the individual did?<<FILL>>
2Is every claim in the statement traceable to evidence already shown in the investigation’s timeline or evidence section?<<FILL>>
3Would the corrective action associated with this root cause prevent the same failure from recurring the same way?<<FILL>>

3. The “operator error” trap check

Complete this section whenever the draft statement names an individual’s action as the cause, in whole or in part.

CheckYes / No
The statement names a system condition that made the individual’s action possible or likely (workload, ambiguous instruction, missing independent check, equipment design, fatigue, training gap).
The statement does not stop at naming the action itself (“selected the wrong lot,” “entered the wrong value”) without going on to explain why that action was not caught or was easy to make.
The proposed corrective action is something other than retraining alone (a design change, an added check, a procedure clarification, a system control).

If any answer above is No, the statement is very likely a symptom description, not a root cause, and should return to analysis.

4. Candidate causes considered

List every candidate cause the investigation considered, whether accepted or ruled out. A root cause statement built from a single considered cause, with no alternatives shown, is a common finding pattern.

Candidate causeRuled in / ruled outEvidence
<<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>>

5. Confidence and undetermined-cause path

Complete this section only if the root cause could not be conclusively determined.

FieldEntry
Most probable cause, with supporting evidence<<FILL>>
Confidence level (high / moderate / low) and basis<<FILL>>
Monitoring or additional evidence plan that will confirm or rule out this cause<<FILL>>

An honest, well-supported “most probable cause, moderate confidence, monitored going forward” statement is stronger and more defensible than a confident but unsupported definitive cause.

6. Disposition

FieldEntry
All three defensibility questions (section 2) answered YesYes / No
Operator error trap check (section 3) passed, if applicableYes / No / N/A
At least one alternative candidate cause documented (section 4)Yes / No
Final root cause statement (revised if needed)<<FILL>>
Reviewed by (name, role, date)<<FILL>>
QA concurrence (name, signature, date)<<FILL>>

A No anywhere in this disposition means the statement returns to analysis before it is written into the investigation record.

7. References

21 CFR 211.192 (thorough investigation of discrepancies and failures, including extension to other batches where applicable), the underlying requirement this worksheet’s three-question test is built to satisfy. FDA guidance, Data Integrity and Compliance With Drug CGMP: Questions and Answers (December 2018), on predetermined conclusions and objective evidence.

Confirm the current version of each reference before you rely on it.


Filled specimen

The following shows the worksheet completed for an example deviation, so you can see the level of rigor expected. The company, system, and numbers are illustrative.

Draft root cause statement (section 1): “Analyst entered the wrong dilution factor during sample preparation, causing the reported result to be out of specification.”

#QuestionResultNote
1Explains why the failure was possibleNoStates only what the analyst did; does not explain why the wrong factor was entered or why nothing caught it.
2Every claim traces to evidenceYesThe wrong entry is confirmed by the LIMS audit trail.
3Corrective action would prevent recurrenceNoNo corrective action beyond “counsel the analyst” was proposed; would not survive recurrence.

Operator error trap check (section 3): No system condition named; statement stops at the individual action; proposed action was retraining alone. All three checks failed, confirming this is a symptom description.

Candidate causes considered (section 4):

Candidate causeRuled in / ruled outEvidence
Analyst manually keyed the dilution factor with no independent verification stepRuled inLIMS workflow confirmed no second-person check exists for this field
LIMS calculation template itself was in errorRuled outTemplate formula verified correct against three other results from the same batch
Training gap on the dilution procedureRuled outAnalyst’s training record current; procedure itself does not require a check

Revised root cause statement (section 6): “The LIMS workflow for this assay does not require an independent verification of the manually entered dilution factor before the result calculates, so a single keying error was not caught before reporting. Corrective action: add a mandatory second-person verification step for manually entered calculation inputs in this LIMS workflow.”

Disposition: All three defensibility questions now Yes; operator error trap check passed; one ruled-out alternative documented. Reviewed by R. Alvarez, QA, 26 August 2026.

This is the value of the worksheet: the first draft was a fluent, plausible-sounding sentence that named a person and a symptom. It failed the recurrence test because retraining alone would not stop the next keying error. The revised statement, built from the same evidence, points at the missing verification step, a fix that actually closes the gap.

Common inspection findings this worksheet prevents

  • A root cause statement that names an individual’s action with no explanation of why the system allowed it.
  • A CAPA whose only action is retraining, attached to a root cause that was never actually systemic.
  • An investigation narrative that shows a single considered cause, with no evidence that alternatives were examined.
  • A confident, definitive root cause claim with no evidence trail supporting it.
  • An investigation closed with an unstated or unmonitored “probable cause,” leaving no way to confirm the analysis later.

How to adapt this worksheet

  1. Set your worksheet number and governing SOP reference in the header.
  2. Fold this worksheet into your existing investigation record as a mandatory step before the root cause section is finalized, rather than a separate standalone document, if your system prefers a single-document flow.
  3. Add your own site’s common false-root-cause phrases to section 3 as your reviews identify recurring patterns.
  4. Route the completed worksheet to the same reviewer who checks the investigation narrative overall, so the defensibility check is not a duplicate review cycle.
  5. Confirm every reference in section 7 against its current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.