Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Risk Assessment Plug-and-play starting point Data Integrity

Risk Assessment: Hybrid Record Data Integrity

A plug-and-play risk assessment for paper-and-electronic hybrid records: a defined method, anchored 1 to 5 scales for severity, occurrence, and detectability, a populated failure-mode table covering shared logins, printouts treated as originals, unverified transcription, clock control, fading printouts, missing reconciliation, uncontrolled split fields, page removal, and orphan electronic events, with risk class thresholds, mitigations, residual risk, approvals, and a scored filled specimen.

Document type: Risk Assessment

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use risk assessment for one hybrid record, or for a defined group of hybrids that share the same architecture. Replace every <<FILL: ...>> placeholder, set your document numbers and dates, and route it through your normal document control, review, and approval. A worked filled specimen with fully scored rows follows. The scales below are deliberately five-point rather than ten-point, because a ten-point scale invites false precision that two assessors cannot reproduce. Verify each cited regulation against the current source before you rely on it, and treat this as general guidance to adapt rather than legal or regulatory advice.

The output of this assessment feeds two other documents: the risk class column of the hybrid system inventory register, and the prioritisation score in the hybrid retirement plan. Keep the three consistent.

Document control header

FieldEntry
Document titleHybrid Record Data Integrity Risk Assessment for <<FILL: hybrid or hybrid group>>
Document number<<FILL: RA-ID, e.g. RA-DI-018>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Supersedes<<FILL: prior version or "New">>
Document owner<<FILL: role, e.g. Process / System Owner>>
Hybrid inventory reference<<FILL: HYB-ID or group>>
Linked retirement plan<<FILL: plan document number>>
Assessment team<<FILL: names and roles, including QA and an SME who has executed the process>>

1. Purpose

This assessment identifies how the paper-and-electronic seam of <<FILL: hybrid or hybrid group>> can fail, scores each failure mode for severity, occurrence, and detectability, assigns a risk class, defines the mitigations that reduce the risk, and records the residual risk that <<FILL: COMPANY NAME>> accepts. The output determines the controls applied to the hybrid now and its position in the retirement sequence.

2. Scope

This assessment covers the creation, execution, review, correction, retention, and retrieval of the hybrid record identified in the header, including both halves and the mechanism that links them. It covers failure modes arising from the seam between the halves, from the electronic component, and from the paper component where the paper carries part of the original record.

It does not replace the validation risk assessment for the electronic component, governed by <<FILL: SOP-ID for CSV risk assessment>>, nor the product quality risk assessment for the process itself. Where this assessment and a system-level assessment reach different conclusions about the same control, the difference is reconciled and the reason recorded rather than left standing.

3. Responsibilities

RoleResponsibility
Process / system ownerOwns the assessment, convenes the team, provides the factual description of how the record is actually created, and owns the resulting actions.
Subject matter expert (executor)Describes what really happens during execution, including workarounds. An assessment built only from the procedure will score occurrence too low.
Quality AssuranceApproves the scoring logic, challenges optimistic detectability scores, and approves the residual risk acceptance.
Validation / CSVConfirms the technical capability of the electronic component, including audit trail scope, account model, and clock control.
IT / instrument supportConfirms what is technically possible on the system, including what a privileged user can do outside the application audit trail.
Data integrity leadMaintains consistency of scoring across hybrids so that risk classes are comparable between assessments.

4. Definitions

  • Failure mode: a specific, observable way the hybrid record can stop being a trustworthy account of what happened.
  • Severity: the consequence if the failure mode occurs and is not detected, judged against product quality, patient or subject safety, and the reconstructability of the record.
  • Occurrence: how likely the failure mode is to arise in the current process, before considering whether anything would catch it.
  • Detectability: the likelihood that an existing, operating control would catch the failure before the record is used to support a decision. A high detectability score means the failure would probably not be caught.
  • Risk priority number (RPN): severity multiplied by occurrence multiplied by detectability, ranging from 1 to 125.
  • Risk class: the band the risk falls into after applying the thresholds and the override rules in section 5.5.
  • Residual risk: the risk remaining after the agreed mitigations are in place and operating.

5. Method

5.1 Sequence

  1. Describe the hybrid factually, by observing an execution, not by reading the procedure. Record who does what, on which half, in what order.
  2. Identify failure modes. Start from the catalogue in section 6, which covers the failure modes that recur across hybrids, then add anything specific to this record.
  3. Score each failure mode for severity, occurrence, and detectability using the anchored scales in sections 5.2 to 5.4. Score the current state, before any mitigation you intend to add.
  4. Calculate the RPN, apply the thresholds and override rules in section 5.5, and assign a risk class.
  5. Define mitigations for every failure mode above the acceptance threshold. Re-score with the mitigations assumed in place and operating.
  6. Record the residual risk and route it for acceptance.
  7. Record actions, owners, and target dates, and feed the outcome into the hybrid inventory register and the retirement plan.

5.2 Severity scale

Score the consequence assuming the failure occurred and nothing caught it. Do not discount severity because you believe the failure is unlikely; that belongs in occurrence.

ScoreAnchorDescription
5Product, patient, or subjectThe failure could allow an incorrect result or an incomplete record to support a batch disposition, a release, a safety report, or a clinical decision. The record could not be reconstructed to prove otherwise.
4Reconstructability lostThe activity can no longer be fully reconstructed. Original data or its metadata is missing, altered without trace, or unattributable, so the firm cannot demonstrate what happened even if the product was in fact acceptable.
3Result or decision affected but recoverableThe record contains an error that could change a reported value or a decision, but the original evidence still exists and the error can be corrected and impact assessed.
2Record quality affectedThe record is incomplete, ambiguous, or inconsistent in a way that does not change any result or decision, but weakens the documentation.
1NegligibleNo effect on any result, decision, or the ability to reconstruct the activity.

5.3 Occurrence scale

Score how often the failure mode arises in the current process as it is actually executed. Where you hold data, use it: deviation history, prior audit findings, and reconciliation exception rates are all better evidence than opinion.

ScoreAnchorDescription
5StructuralThe failure is inherent to the current design and will occur whenever the activity runs. There is no control preventing it, only controls that may notice it afterwards.
4FrequentObserved or expected multiple times per <<FILL: period, e.g. quarter>>, or the process depends on a manual step with no forcing function.
3OccasionalObserved or expected a few times per year. A manual step exists but the process makes it visible if omitted.
2RareObserved less than once per year. A preventive control exists and operates, and omitting the step requires an unusual sequence of events.
1RemoteNot observed, and the design makes it very difficult to occur.

5.4 Detectability scale

Score the probability that an existing, operating control catches the failure before the record supports a decision. Score the controls that actually run, not the controls in the procedure. If second-person review is defined but the reviewer signs without opening the audit trail, that is not detection.

ScoreAnchorDescription
5Not detectableNo control would catch it. Detection depends on chance, on an external party, or on someone volunteering the information.
4Unlikely to be detectedDetection depends on a single manual step performed by one person with no independent confirmation, or on a periodic review that samples a small fraction of records.
3Possibly detectedA defined review would probably catch it if performed carefully, but the check is not explicit, so detection depends on reviewer diligence rather than a stated step.
2Likely detectedAn explicit, documented check exists at a defined point, is performed on every record, and the failure would be visible to it.
1Almost certainly detectedThe system prevents the failure or flags it automatically, or a reconciliation makes it impossible to complete the record without noticing.

Detectability is where assessments most often flatter themselves. The test to apply: name the control, name the person or system that performs it, and name the record that proves it was performed on the last five occasions. If that cannot be done, the score is 4 or 5.

5.5 Risk class thresholds and override rules

Risk classRPN bandMeaning and required response
Critical60 to 125Not acceptable. Mitigate before the hybrid continues in routine use, or stop the activity. Requires Quality Head approval of any interim operation with compensating controls, with an end date.
High36 to 59Mitigation required. Interim compensating controls may allow continued operation while the mitigation is implemented, with a dated plan and QA approval.
Medium16 to 35Mitigation required where practicable. Where it is not practicable before migration, record the compensating control and the residual risk explicitly.
Low1 to 15Acceptable with the existing controls. Monitor at periodic review.

Two override rules apply regardless of the calculated RPN, because a low occurrence score should not be allowed to hide a failure whose consequence is unrecoverable:

  1. Severity 5 with detectability 4 or 5 is classified Critical. A failure that could reach product, patient, or subject and that nothing would catch is not made acceptable by being rare.
  2. Severity 4 with detectability 5 is classified High or above. Loss of reconstructability that no control would notice cannot be accepted on the basis of low occurrence, because the absence of detection also means the occurrence estimate is unverifiable.

Record any application of an override rule explicitly in the assessment table, so a reviewer can see the class was set by rule rather than by arithmetic.

5.6 Re-scoring after mitigation

Re-score with the mitigation assumed to be in place and operating, and be honest about which score it moves. Most mitigations for hybrids move detectability, not occurrence. A reconciliation step does not stop a transcription error from being made; it catches it. Only a design change, such as removing the transcription entirely by interfacing the instrument, moves occurrence. An assessment in which every mitigation conveniently reduces all three scores has not been challenged.

6. Assessment table

Complete one row per failure mode. The rows below are pre-populated with the failure modes that recur across hybrids; add, remove, and adapt them for the specific record. Scores are left blank because they are specific to your process.

#Failure modeHow it happens hereALCOA+ attribute at riskSODRPNClassMitigationResidual SResidual OResidual DResidual RPNResidual classOwner, target date
1Shared login on the electronic half, so electronic actions cannot be attributed to a person<<FILL>>Attributable<<FILL>><<FILL>>
2A printout is treated as the original for dynamic electronic data, and the electronic data is uncontrolled, overwritten, or deleted<<FILL>>Original, Complete<<FILL>><<FILL>>
3A value is transcribed from the electronic source to paper with no independent verification<<FILL>>Accurate<<FILL>><<FILL>>
4The instrument or system clock is not controlled, so contemporaneity and sequence cannot be proven<<FILL>>Contemporaneous, Consistent<<FILL>><<FILL>>
5Thermal printouts fade, or paper degrades, before the end of the retention period<<FILL>>Enduring, Legible<<FILL>><<FILL>>
6No reconciliation is performed between the halves, so the two drift apart undetected<<FILL>>Complete, Consistent<<FILL>><<FILL>>
7Split-field fields that exist on only one half are uncontrolled because the record was declared as a single governing half<<FILL>>Complete, Original<<FILL>><<FILL>>
8A page is removed from the paper half and the removal is not detectable<<FILL>>Complete, Enduring<<FILL>><<FILL>>
9Orphan electronic events exist with no paper counterpart, including aborted, deleted, or renamed runs<<FILL>>Complete<<FILL>><<FILL>>
10The electronic half becomes unreadable after the system is decommissioned, while the paper half is still filed<<FILL>>Available, Enduring<<FILL>><<FILL>>
11A correction is applied to one half and not propagated to the other<<FILL>>Consistent, Accurate<<FILL>><<FILL>>
12The ink signature approving an electronic record is not linked to that specific record and could be transferred to another<<FILL>>Attributable, Original<<FILL>><<FILL>>
13The audit trail is absent, cannot be reviewed by the people who need it, or can be disabled by an ordinary user<<FILL>>Complete, Attributable<<FILL>><<FILL>>
14The paper record is completed after the fact from memory while the electronic time stamp is real time<<FILL>>Contemporaneous<<FILL>><<FILL>>
<<FILL>><<FILL: failure mode specific to this hybrid>><<FILL>><<FILL>><<FILL>><<FILL>>

7. Mitigation catalogue

Select from these where they fit, and write the specific implementation rather than the generic name. A mitigation recorded as “improve access control” cannot be verified as complete.

Failure mode addressedMitigationWhat it movesNotes on strength
1Individual named accounts at application level, even where the operating system login is sharedOccurrence and detectabilityPartial: file-level actions outside the application remain unattributable
1Individual named accounts at operating system and application level, workstation joined to the managed domainOccurrenceStrong. This is usually the real fix and usually requires networking the system
1Controlled physical access with a logged entry record for the instrument areaDetectabilityCompensating only. Narrows who could have acted; does not attribute the action
2Declare the dynamic electronic data as the governing record, apply retention, backup, and review to itSeverity and occurrenceStrong, and it is a documentation act, so it can be done immediately
2Retain the raw data files and audit trail on backed-up storage with a tested restore that includes reprocessing a recordSeverityStrong. Restore that has never been tested is a hypothesis
3Second-person verification of every transcribed value, recorded on the recordDetectabilityModerate. Depends on the check being real
3Remove the transcription by interfacing the instrument to the receiving systemOccurrenceStrong. The only mitigation that removes rather than catches the error
4Synchronise the clock to a controlled time source, remove user rights to change it, capture any change in the audit trailOccurrenceStrong
4Where the instrument clock cannot be protected, record wall-clock time on the paper and verify agreement at reviewDetectabilityCompensating only. State the residual risk
5Photocopy or scan thermal output as a verified certified copy on the day it is produced, retain the copy with the originalSeverityStrong, provided the copy is verified rather than merely made
5Replace thermal printers with non-thermal output, or interface the instrumentOccurrenceStrong
6Define and perform reconciliation at the point of review, with a checklist and a recorded outcomeDetectabilityStrong when performed on every record; weak when performed on a sample
7Declare the record split-field and declare each field individually; apply controls per fieldSeverity and detectabilityStrong. Costs nothing but analysis
8Controlled, pre-numbered forms issued and reconciled; page numbering as “page N of M” with the record identifier on every pageDetectabilityStrong
9Count reconciliation including blanks, standards, aborted runs, and repeats, started from the electronic sideDetectabilityStrong
9Machine-generated sequential identifier printed on output and recorded on paper, so gaps are visibleDetectabilityStrong, and cheap
10Decide the archive strategy before decommissioning: migrate, export to a durable readable format preserving metadata, or retain the system read-onlySeverity and occurrenceStrong if decided in advance; options narrow sharply once the workstation is wiped
11Procedure requires corrections to be propagated to both halves and cross-referenced, and re-reconciledDetectabilityModerate
12Machine-generated identifier on both halves, no detachable signature page, signature meaning stated on the paperOccurrence and detectabilityStrong, and it is the control 21 CFR 11.70 is asking about
13Enable the audit trail, remove the ability of ordinary users to disable it, grant reviewers read accessOccurrence and detectabilityStrong. Where the instrument cannot produce an audit trail at all, no mitigation reaches strong and replacement is the answer
14Contemporaneous recording enforced at the point of activity; controlled late entry procedure for genuine exceptionsOccurrenceModerate. Behavioural controls need supervision and sampling to stay real

8. Residual risk statement

FieldEntry
Failure modes assessed<<FILL: count>>
Critical before mitigation<<FILL: count>>
High before mitigation<<FILL: count>>
Critical remaining after mitigation<<FILL: count, expected zero>>
High remaining after mitigation<<FILL: count, each justified below>>
Compensating controls relied on<<FILL: list, with the record that evidences each>>
Residual risk statement<<FILL: plain-language statement of what risk remains, why it cannot be further reduced before migration, and what would change the conclusion>>
Date the residual risk is re-evaluated<<FILL: date, and the trigger events that force earlier re-evaluation>>
Retirement plan wave assigned<<FILL: wave number>>

State the residual risk in language a reader outside the assessment team can evaluate. “Residual risk is acceptable” is not a statement; it is a conclusion with the reasoning removed.

9. References

21 CFR 211.68, 211.180, 211.194. 21 CFR Part 11, in particular 11.10, 11.50 (signature manifestations), and 11.70 (signature and record linking, including handwritten signatures executed to electronic records). EU GMP Annex 11 (Computerised Systems) and EU GMP Chapter 4 (Documentation). FDA guidance, Data Integrity and Compliance With Drug CGMP, Questions and Answers (December 2018). MHRA GXP Data Integrity Guidance and Definitions (March 2018). PIC/S PI 041, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments. ICH Q9, Quality Risk Management, for the risk management framework and the expectation that the effort is proportionate to the risk.

Confirm the current version and clause numbers of each reference before issue.

10. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

11. Approvals

RoleNameSignatureDate
Author (process / system owner)<<FILL>>
Subject matter expert<<FILL>>
Validation / CSV<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality Head), required where any Critical or High residual risk is accepted<<FILL>>

Filled specimen

The following shows four rows fully scored for an example standalone chromatography workstation used for release testing, hybrid inventory reference HYB-001. Company, names, dates, and scores are illustrative; the reasoning is the part worth copying.

Row 1: shared operating system login on the acquisition workstation

FieldEntry
How it happens hereThree analysts share one Windows account on HPLC-07. Individual accounts exist inside the chromatography application, so acquisitions and reprocessing are attributable, but any file-level action taken outside the application, including moving or deleting a project folder, is attributable only to the shared account.
ALCOA+ attribute at riskAttributable, Original
Severity4. A file-level deletion outside the application would remove data with no attributable trace, so the activity could not be fully reconstructed.
Occurrence2. No instance observed in three years of audit history; the action requires deliberate use of the file system rather than the application.
Detectability4. The application audit trail does not capture file-system actions. Detection depends on the reconciliation count noticing a missing result, which would only work if the paper worksheet already recorded it.
RPN before4 x 2 x 4 = 32, band Medium
Class beforeHigh, by deliberate uplift from the calculated band of Medium. Override rule 2 does not strictly apply, because detectability is 4 rather than 5. The team uplifted the class anyway, on the reasoning that an occurrence score of 2 is unverifiable precisely because detection is weak: the absence of file-system logging is also the reason nobody could say whether it had ever happened. The uplift and its reason are recorded here rather than being achieved by quietly inflating the occurrence score.
MitigationInterim: instrument room card access with a logged entry record, reconciled against acquisition times at review. Permanent: migrate acquisition to the networked CDS server with individual domain accounts, removing the shared login.
Residual scoresS 4, O 1, D 2, RPN 8
Residual classLow, after the permanent mitigation
Owner, target dateR. Okonkwo (Lab Systems), 31 December 2026. Until then the interim compensating control operates and the residual class is High.

Row 2: printout treated as the original for dynamic chromatographic data

FieldEntry
How it happens hereHistorically the signed printed report was filed as the record and the electronic project folder was left on the local disk with no defined retention. The governing record has now been declared electronic, but records created before March 2026 were managed under the previous practice.
ALCOA+ attribute at riskOriginal, Complete
Severity5. Without the electronic data and its audit trail, a reintegrated or deleted injection cannot be detected, and the affected results supported batch dispositions.
Occurrence5. Structural for the historical period: the practice applied to every record created before the declaration was issued.
Detectability4. Detection depends on someone going back to the local disk and confirming the data still exists, which was not a defined check.
RPN before5 x 5 x 4 = 100, band Critical
Class beforeCritical, also caught by override rule 1 (severity 5 with detectability 4).
MitigationGoverning record declared electronic and approved by QA on 03 March 2026. Full copy of the historical project folders taken to the validated file store with a verified inventory against the archived worksheets. Retention, backup, and audit trail review now applied to the electronic data. Gap assessment performed on the historical period to confirm what data still exists.
Residual scoresS 5, O 1, D 2, RPN 10
Residual classLow for records created after the declaration. For the historical period the residual class is recorded separately as Medium, because the gap assessment confirmed the data exists but the audit trail for the earliest six months of that period was configured with a shorter retention than the data. That limitation is stated in the residual risk statement rather than scored away.
Owner, target dateL. Fernandes (QA), declaration complete; historical gap assessment closed 30 June 2026.

Row 3: unverified transcription of results to the worksheet

FieldEntry
How it happens hereThe analyst reads six reportable results from the chromatography report and writes them on the worksheet, where the assay calculation is performed by hand.
ALCOA+ attribute at riskAccurate
Severity5. A transcription error in a reportable result feeds the assay calculation and could support an incorrect disposition.
Occurrence3. Manual transcription of numeric values occurs on every record. Two transcription errors were found and corrected by second-person review in the previous twelve months, both caught.
Detectability2. Second-person verification of every transcribed value is a defined, recorded step performed on every record, and the last twelve months of review records evidence it.
RPN before5 x 3 x 2 = 30, band Medium
Class beforeMedium. Note that severity 5 does not trigger override rule 1 here, because detectability is 2 rather than 4 or 5. This is the intended behaviour of the rule: a severe failure with a real, evidenced detection control is a different situation from a severe failure nobody would catch.
MitigationInterim: retain 100 percent second-person verification and monitor the exception rate quarterly. Permanent: configure the chromatography system to calculate and report the final assay value, removing the manual calculation and the transcription.
Residual scoresS 5, O 1, D 2, RPN 10
Residual classLow, after the permanent mitigation removes the transcription
Owner, target dateA. Ferreira (QC Systems), 31 March 2027

Row 4: no reconciliation between the electronic sequence and the worksheet

FieldEntry
How it happens hereBefore the reconciliation procedure was issued, review consisted of checking the worksheet for completeness and signing it. The electronic sequence count was not compared to the worksheet and the audit trail was not opened.
ALCOA+ attribute at riskComplete, Consistent
Severity5. An aborted or deleted injection would not appear on the paper and would not be looked for, so a discarded failing result could support a passing disposition.
Occurrence5. Structural: with no reconciliation defined, the control did not exist on any record.
Detectability5. Nothing else would catch it. Detection would depend on an audit or an inspection.
RPN before5 x 5 x 5 = 125, band Critical
Class beforeCritical, and caught by override rule 1.
MitigationReconciliation defined in the hybrid control SOP and executed on every record using the reconciliation checklist, starting from the electronic side. Reviewer signature meaning amended to state that reconciliation and audit trail review were performed. Quarterly QA sample verifies the reconciliation was performed as described.
Residual scoresS 5, O 1, D 2, RPN 10
Residual classLow
Owner, target dateM. Haddad (QA), implemented 01 April 2026; effectiveness verified in the Q2 2026 QA sample.

Residual risk statement for the specimen

FieldEntry
Failure modes assessed14
Critical before mitigation3
High before mitigation4
Critical remaining after mitigation0
High remaining after mitigation1 (row 1, until the networked CDS migration completes on 31 December 2026)
Compensating controls relied onInstrument room card-access log CF-QC-009, reconciled against acquisition times at each review; 100 percent second-person verification of transcribed values, recorded on the worksheet
Residual risk statementFor records created after 03 March 2026, the dynamic electronic data is the declared governing record, is retained on backed-up storage with a tested restore, and is reconciled and audit-trail reviewed on every record. The remaining High risk is that a privileged file-system action on HPLC-07 would not be attributable to an individual, because the operating system login is shared. This cannot be reduced further without networking the workstation, which is scheduled for 31 December 2026. Until then the compensating control narrows the population of possible actors to those who entered the instrument room during the acquisition window. For records created before 03 March 2026, the electronic data has been recovered and inventoried, but audit trail retention on the earliest six months of that period was shorter than data retention, so reprocessing history for that window cannot be fully reconstructed. This limitation is stated rather than mitigated, and it is included in the pre-approval inspection preparation brief.
Re-evaluation date and triggers31 January 2027, or earlier on any of: completion or delay of the networked CDS migration, any deviation involving data attribution on HPLC-07, any change to the account model or audit trail configuration.
Retirement plan wave assignedWave 1

Two things in this specimen are worth copying. The first is row 3, where a severity of 5 does not produce a Critical class because a real and evidenced detection control exists; the override rules are written so that severity alone does not drive everything, which is what keeps the scale usable. The second is the residual risk statement, which names a limitation on historical audit trail retention that no mitigation fixes, and says so plainly instead of scoring it down to Low.

Common inspection findings this risk assessment prevents

  • Hybrid records are operated with no documented assessment of how the seam between the halves could fail.
  • Every hybrid receives the same controls regardless of what depends on the data, so effort is spread evenly and the highest-risk hybrids are undercontrolled.
  • Detectability scores assume controls that are written down but not performed, so the assessment concludes that risks are managed when the evidence shows otherwise.
  • A severe failure mode is scored down to an acceptable class purely because occurrence was judged low, with no evidence supporting the occurrence estimate and no control that would have detected the failure.
  • Residual risk is recorded as “acceptable” with no statement of what risk remains or what would change the conclusion.
  • Mitigations are recorded in general terms that cannot be verified as implemented.
  • The assessment was written from the procedure rather than from an observed execution, so the workarounds that create the real risk are absent from it.
  • The risk assessment, the hybrid inventory, and the migration plan disagree about which hybrids are highest risk.

How to adapt this risk assessment

  1. Set the document number, owner, and the hybrid inventory reference in the header, and name the assessment team including at least one person who executes the process.
  2. Observe an execution before scoring. Budget the time for it. The difference between an assessment written at a desk and one written after watching the activity is usually two points of occurrence on at least one row.
  3. Keep the scales exactly as written across every hybrid assessment you perform, or change them once, centrally, and re-baseline. Scales that vary between assessments make risk classes incomparable, which defeats the prioritisation the retirement plan depends on.
  4. Add failure modes specific to your record. A cell and gene therapy chain of identity record will have failure modes around subject and product identity linkage that no chromatography hybrid has. A distribution hybrid will have failure modes around temperature record continuity during transfer.
  5. For each mitigation you select, write the specific implementation, the owner as a named individual, and the record that will evidence it. Then check in six months whether that record exists.
  6. Where a mitigation is compensating rather than preventive, say so in the notes column and carry the difference into the residual risk statement.
  7. Feed the final risk class into the hybrid inventory register and the prioritisation score in the retirement plan on the same day, so the three documents cannot drift.
  8. Confirm every regulation in section 9 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.