This is a ready-to-use risk assessment for one hybrid record, or for a defined group of hybrids that share the same architecture. Replace every <<FILL: ...>> placeholder, set your document numbers and dates, and route it through your normal document control, review, and approval. A worked filled specimen with fully scored rows follows. The scales below are deliberately five-point rather than ten-point, because a ten-point scale invites false precision that two assessors cannot reproduce. Verify each cited regulation against the current source before you rely on it, and treat this as general guidance to adapt rather than legal or regulatory advice.
The output of this assessment feeds two other documents: the risk class column of the hybrid system inventory register, and the prioritisation score in the hybrid retirement plan. Keep the three consistent.
Document control header
| Field | Entry |
|---|---|
| Document title | Hybrid Record Data Integrity Risk Assessment for <<FILL: hybrid or hybrid group>> |
| Document number | <<FILL: RA-ID, e.g. RA-DI-018>> |
| Version | <<FILL: version, e.g. 1.0>> |
| Effective date | <<FILL: effective date>> |
| Supersedes | <<FILL: prior version or "New">> |
| Document owner | <<FILL: role, e.g. Process / System Owner>> |
| Hybrid inventory reference | <<FILL: HYB-ID or group>> |
| Linked retirement plan | <<FILL: plan document number>> |
| Assessment team | <<FILL: names and roles, including QA and an SME who has executed the process>> |
1. Purpose
This assessment identifies how the paper-and-electronic seam of <<FILL: hybrid or hybrid group>> can fail, scores each failure mode for severity, occurrence, and detectability, assigns a risk class, defines the mitigations that reduce the risk, and records the residual risk that <<FILL: COMPANY NAME>> accepts. The output determines the controls applied to the hybrid now and its position in the retirement sequence.
2. Scope
This assessment covers the creation, execution, review, correction, retention, and retrieval of the hybrid record identified in the header, including both halves and the mechanism that links them. It covers failure modes arising from the seam between the halves, from the electronic component, and from the paper component where the paper carries part of the original record.
It does not replace the validation risk assessment for the electronic component, governed by <<FILL: SOP-ID for CSV risk assessment>>, nor the product quality risk assessment for the process itself. Where this assessment and a system-level assessment reach different conclusions about the same control, the difference is reconciled and the reason recorded rather than left standing.
3. Responsibilities
| Role | Responsibility |
|---|---|
| Process / system owner | Owns the assessment, convenes the team, provides the factual description of how the record is actually created, and owns the resulting actions. |
| Subject matter expert (executor) | Describes what really happens during execution, including workarounds. An assessment built only from the procedure will score occurrence too low. |
| Quality Assurance | Approves the scoring logic, challenges optimistic detectability scores, and approves the residual risk acceptance. |
| Validation / CSV | Confirms the technical capability of the electronic component, including audit trail scope, account model, and clock control. |
| IT / instrument support | Confirms what is technically possible on the system, including what a privileged user can do outside the application audit trail. |
| Data integrity lead | Maintains consistency of scoring across hybrids so that risk classes are comparable between assessments. |
4. Definitions
- Failure mode: a specific, observable way the hybrid record can stop being a trustworthy account of what happened.
- Severity: the consequence if the failure mode occurs and is not detected, judged against product quality, patient or subject safety, and the reconstructability of the record.
- Occurrence: how likely the failure mode is to arise in the current process, before considering whether anything would catch it.
- Detectability: the likelihood that an existing, operating control would catch the failure before the record is used to support a decision. A high detectability score means the failure would probably not be caught.
- Risk priority number (RPN): severity multiplied by occurrence multiplied by detectability, ranging from 1 to 125.
- Risk class: the band the risk falls into after applying the thresholds and the override rules in section 5.5.
- Residual risk: the risk remaining after the agreed mitigations are in place and operating.
5. Method
5.1 Sequence
- Describe the hybrid factually, by observing an execution, not by reading the procedure. Record who does what, on which half, in what order.
- Identify failure modes. Start from the catalogue in section 6, which covers the failure modes that recur across hybrids, then add anything specific to this record.
- Score each failure mode for severity, occurrence, and detectability using the anchored scales in sections 5.2 to 5.4. Score the current state, before any mitigation you intend to add.
- Calculate the RPN, apply the thresholds and override rules in section 5.5, and assign a risk class.
- Define mitigations for every failure mode above the acceptance threshold. Re-score with the mitigations assumed in place and operating.
- Record the residual risk and route it for acceptance.
- Record actions, owners, and target dates, and feed the outcome into the hybrid inventory register and the retirement plan.
5.2 Severity scale
Score the consequence assuming the failure occurred and nothing caught it. Do not discount severity because you believe the failure is unlikely; that belongs in occurrence.
| Score | Anchor | Description |
|---|---|---|
| 5 | Product, patient, or subject | The failure could allow an incorrect result or an incomplete record to support a batch disposition, a release, a safety report, or a clinical decision. The record could not be reconstructed to prove otherwise. |
| 4 | Reconstructability lost | The activity can no longer be fully reconstructed. Original data or its metadata is missing, altered without trace, or unattributable, so the firm cannot demonstrate what happened even if the product was in fact acceptable. |
| 3 | Result or decision affected but recoverable | The record contains an error that could change a reported value or a decision, but the original evidence still exists and the error can be corrected and impact assessed. |
| 2 | Record quality affected | The record is incomplete, ambiguous, or inconsistent in a way that does not change any result or decision, but weakens the documentation. |
| 1 | Negligible | No effect on any result, decision, or the ability to reconstruct the activity. |
5.3 Occurrence scale
Score how often the failure mode arises in the current process as it is actually executed. Where you hold data, use it: deviation history, prior audit findings, and reconciliation exception rates are all better evidence than opinion.
| Score | Anchor | Description |
|---|---|---|
| 5 | Structural | The failure is inherent to the current design and will occur whenever the activity runs. There is no control preventing it, only controls that may notice it afterwards. |
| 4 | Frequent | Observed or expected multiple times per <<FILL: period, e.g. quarter>>, or the process depends on a manual step with no forcing function. |
| 3 | Occasional | Observed or expected a few times per year. A manual step exists but the process makes it visible if omitted. |
| 2 | Rare | Observed less than once per year. A preventive control exists and operates, and omitting the step requires an unusual sequence of events. |
| 1 | Remote | Not observed, and the design makes it very difficult to occur. |
5.4 Detectability scale
Score the probability that an existing, operating control catches the failure before the record supports a decision. Score the controls that actually run, not the controls in the procedure. If second-person review is defined but the reviewer signs without opening the audit trail, that is not detection.
| Score | Anchor | Description |
|---|---|---|
| 5 | Not detectable | No control would catch it. Detection depends on chance, on an external party, or on someone volunteering the information. |
| 4 | Unlikely to be detected | Detection depends on a single manual step performed by one person with no independent confirmation, or on a periodic review that samples a small fraction of records. |
| 3 | Possibly detected | A defined review would probably catch it if performed carefully, but the check is not explicit, so detection depends on reviewer diligence rather than a stated step. |
| 2 | Likely detected | An explicit, documented check exists at a defined point, is performed on every record, and the failure would be visible to it. |
| 1 | Almost certainly detected | The system prevents the failure or flags it automatically, or a reconciliation makes it impossible to complete the record without noticing. |
Detectability is where assessments most often flatter themselves. The test to apply: name the control, name the person or system that performs it, and name the record that proves it was performed on the last five occasions. If that cannot be done, the score is 4 or 5.
5.5 Risk class thresholds and override rules
| Risk class | RPN band | Meaning and required response |
|---|---|---|
| Critical | 60 to 125 | Not acceptable. Mitigate before the hybrid continues in routine use, or stop the activity. Requires Quality Head approval of any interim operation with compensating controls, with an end date. |
| High | 36 to 59 | Mitigation required. Interim compensating controls may allow continued operation while the mitigation is implemented, with a dated plan and QA approval. |
| Medium | 16 to 35 | Mitigation required where practicable. Where it is not practicable before migration, record the compensating control and the residual risk explicitly. |
| Low | 1 to 15 | Acceptable with the existing controls. Monitor at periodic review. |
Two override rules apply regardless of the calculated RPN, because a low occurrence score should not be allowed to hide a failure whose consequence is unrecoverable:
- Severity 5 with detectability 4 or 5 is classified Critical. A failure that could reach product, patient, or subject and that nothing would catch is not made acceptable by being rare.
- Severity 4 with detectability 5 is classified High or above. Loss of reconstructability that no control would notice cannot be accepted on the basis of low occurrence, because the absence of detection also means the occurrence estimate is unverifiable.
Record any application of an override rule explicitly in the assessment table, so a reviewer can see the class was set by rule rather than by arithmetic.
5.6 Re-scoring after mitigation
Re-score with the mitigation assumed to be in place and operating, and be honest about which score it moves. Most mitigations for hybrids move detectability, not occurrence. A reconciliation step does not stop a transcription error from being made; it catches it. Only a design change, such as removing the transcription entirely by interfacing the instrument, moves occurrence. An assessment in which every mitigation conveniently reduces all three scores has not been challenged.
6. Assessment table
Complete one row per failure mode. The rows below are pre-populated with the failure modes that recur across hybrids; add, remove, and adapt them for the specific record. Scores are left blank because they are specific to your process.
| # | Failure mode | How it happens here | ALCOA+ attribute at risk | S | O | D | RPN | Class | Mitigation | Residual S | Residual O | Residual D | Residual RPN | Residual class | Owner, target date |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Shared login on the electronic half, so electronic actions cannot be attributed to a person | <<FILL>> | Attributable | <<FILL>> | <<FILL>> | ||||||||||
| 2 | A printout is treated as the original for dynamic electronic data, and the electronic data is uncontrolled, overwritten, or deleted | <<FILL>> | Original, Complete | <<FILL>> | <<FILL>> | ||||||||||
| 3 | A value is transcribed from the electronic source to paper with no independent verification | <<FILL>> | Accurate | <<FILL>> | <<FILL>> | ||||||||||
| 4 | The instrument or system clock is not controlled, so contemporaneity and sequence cannot be proven | <<FILL>> | Contemporaneous, Consistent | <<FILL>> | <<FILL>> | ||||||||||
| 5 | Thermal printouts fade, or paper degrades, before the end of the retention period | <<FILL>> | Enduring, Legible | <<FILL>> | <<FILL>> | ||||||||||
| 6 | No reconciliation is performed between the halves, so the two drift apart undetected | <<FILL>> | Complete, Consistent | <<FILL>> | <<FILL>> | ||||||||||
| 7 | Split-field fields that exist on only one half are uncontrolled because the record was declared as a single governing half | <<FILL>> | Complete, Original | <<FILL>> | <<FILL>> | ||||||||||
| 8 | A page is removed from the paper half and the removal is not detectable | <<FILL>> | Complete, Enduring | <<FILL>> | <<FILL>> | ||||||||||
| 9 | Orphan electronic events exist with no paper counterpart, including aborted, deleted, or renamed runs | <<FILL>> | Complete | <<FILL>> | <<FILL>> | ||||||||||
| 10 | The electronic half becomes unreadable after the system is decommissioned, while the paper half is still filed | <<FILL>> | Available, Enduring | <<FILL>> | <<FILL>> | ||||||||||
| 11 | A correction is applied to one half and not propagated to the other | <<FILL>> | Consistent, Accurate | <<FILL>> | <<FILL>> | ||||||||||
| 12 | The ink signature approving an electronic record is not linked to that specific record and could be transferred to another | <<FILL>> | Attributable, Original | <<FILL>> | <<FILL>> | ||||||||||
| 13 | The audit trail is absent, cannot be reviewed by the people who need it, or can be disabled by an ordinary user | <<FILL>> | Complete, Attributable | <<FILL>> | <<FILL>> | ||||||||||
| 14 | The paper record is completed after the fact from memory while the electronic time stamp is real time | <<FILL>> | Contemporaneous | <<FILL>> | <<FILL>> | ||||||||||
<<FILL>> | <<FILL: failure mode specific to this hybrid>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
7. Mitigation catalogue
Select from these where they fit, and write the specific implementation rather than the generic name. A mitigation recorded as “improve access control” cannot be verified as complete.
| Failure mode addressed | Mitigation | What it moves | Notes on strength |
|---|---|---|---|
| 1 | Individual named accounts at application level, even where the operating system login is shared | Occurrence and detectability | Partial: file-level actions outside the application remain unattributable |
| 1 | Individual named accounts at operating system and application level, workstation joined to the managed domain | Occurrence | Strong. This is usually the real fix and usually requires networking the system |
| 1 | Controlled physical access with a logged entry record for the instrument area | Detectability | Compensating only. Narrows who could have acted; does not attribute the action |
| 2 | Declare the dynamic electronic data as the governing record, apply retention, backup, and review to it | Severity and occurrence | Strong, and it is a documentation act, so it can be done immediately |
| 2 | Retain the raw data files and audit trail on backed-up storage with a tested restore that includes reprocessing a record | Severity | Strong. Restore that has never been tested is a hypothesis |
| 3 | Second-person verification of every transcribed value, recorded on the record | Detectability | Moderate. Depends on the check being real |
| 3 | Remove the transcription by interfacing the instrument to the receiving system | Occurrence | Strong. The only mitigation that removes rather than catches the error |
| 4 | Synchronise the clock to a controlled time source, remove user rights to change it, capture any change in the audit trail | Occurrence | Strong |
| 4 | Where the instrument clock cannot be protected, record wall-clock time on the paper and verify agreement at review | Detectability | Compensating only. State the residual risk |
| 5 | Photocopy or scan thermal output as a verified certified copy on the day it is produced, retain the copy with the original | Severity | Strong, provided the copy is verified rather than merely made |
| 5 | Replace thermal printers with non-thermal output, or interface the instrument | Occurrence | Strong |
| 6 | Define and perform reconciliation at the point of review, with a checklist and a recorded outcome | Detectability | Strong when performed on every record; weak when performed on a sample |
| 7 | Declare the record split-field and declare each field individually; apply controls per field | Severity and detectability | Strong. Costs nothing but analysis |
| 8 | Controlled, pre-numbered forms issued and reconciled; page numbering as “page N of M” with the record identifier on every page | Detectability | Strong |
| 9 | Count reconciliation including blanks, standards, aborted runs, and repeats, started from the electronic side | Detectability | Strong |
| 9 | Machine-generated sequential identifier printed on output and recorded on paper, so gaps are visible | Detectability | Strong, and cheap |
| 10 | Decide the archive strategy before decommissioning: migrate, export to a durable readable format preserving metadata, or retain the system read-only | Severity and occurrence | Strong if decided in advance; options narrow sharply once the workstation is wiped |
| 11 | Procedure requires corrections to be propagated to both halves and cross-referenced, and re-reconciled | Detectability | Moderate |
| 12 | Machine-generated identifier on both halves, no detachable signature page, signature meaning stated on the paper | Occurrence and detectability | Strong, and it is the control 21 CFR 11.70 is asking about |
| 13 | Enable the audit trail, remove the ability of ordinary users to disable it, grant reviewers read access | Occurrence and detectability | Strong. Where the instrument cannot produce an audit trail at all, no mitigation reaches strong and replacement is the answer |
| 14 | Contemporaneous recording enforced at the point of activity; controlled late entry procedure for genuine exceptions | Occurrence | Moderate. Behavioural controls need supervision and sampling to stay real |
8. Residual risk statement
| Field | Entry |
|---|---|
| Failure modes assessed | <<FILL: count>> |
| Critical before mitigation | <<FILL: count>> |
| High before mitigation | <<FILL: count>> |
| Critical remaining after mitigation | <<FILL: count, expected zero>> |
| High remaining after mitigation | <<FILL: count, each justified below>> |
| Compensating controls relied on | <<FILL: list, with the record that evidences each>> |
| Residual risk statement | <<FILL: plain-language statement of what risk remains, why it cannot be further reduced before migration, and what would change the conclusion>> |
| Date the residual risk is re-evaluated | <<FILL: date, and the trigger events that force earlier re-evaluation>> |
| Retirement plan wave assigned | <<FILL: wave number>> |
State the residual risk in language a reader outside the assessment team can evaluate. “Residual risk is acceptable” is not a statement; it is a conclusion with the reasoning removed.
9. References
21 CFR 211.68, 211.180, 211.194. 21 CFR Part 11, in particular 11.10, 11.50 (signature manifestations), and 11.70 (signature and record linking, including handwritten signatures executed to electronic records). EU GMP Annex 11 (Computerised Systems) and EU GMP Chapter 4 (Documentation). FDA guidance, Data Integrity and Compliance With Drug CGMP, Questions and Answers (December 2018). MHRA GXP Data Integrity Guidance and Definitions (March 2018). PIC/S PI 041, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments. ICH Q9, Quality Risk Management, for the risk management framework and the expectation that the effort is proportionate to the risk.
Confirm the current version and clause numbers of each reference before issue.
10. Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
11. Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Author (process / system owner) | <<FILL>> | ||
| Subject matter expert | <<FILL>> | ||
| Validation / CSV | <<FILL>> | ||
| Reviewer (QA) | <<FILL>> | ||
| Approver (Quality Head), required where any Critical or High residual risk is accepted | <<FILL>> |
Filled specimen
The following shows four rows fully scored for an example standalone chromatography workstation used for release testing, hybrid inventory reference HYB-001. Company, names, dates, and scores are illustrative; the reasoning is the part worth copying.
Row 1: shared operating system login on the acquisition workstation
| Field | Entry |
|---|---|
| How it happens here | Three analysts share one Windows account on HPLC-07. Individual accounts exist inside the chromatography application, so acquisitions and reprocessing are attributable, but any file-level action taken outside the application, including moving or deleting a project folder, is attributable only to the shared account. |
| ALCOA+ attribute at risk | Attributable, Original |
| Severity | 4. A file-level deletion outside the application would remove data with no attributable trace, so the activity could not be fully reconstructed. |
| Occurrence | 2. No instance observed in three years of audit history; the action requires deliberate use of the file system rather than the application. |
| Detectability | 4. The application audit trail does not capture file-system actions. Detection depends on the reconciliation count noticing a missing result, which would only work if the paper worksheet already recorded it. |
| RPN before | 4 x 2 x 4 = 32, band Medium |
| Class before | High, by deliberate uplift from the calculated band of Medium. Override rule 2 does not strictly apply, because detectability is 4 rather than 5. The team uplifted the class anyway, on the reasoning that an occurrence score of 2 is unverifiable precisely because detection is weak: the absence of file-system logging is also the reason nobody could say whether it had ever happened. The uplift and its reason are recorded here rather than being achieved by quietly inflating the occurrence score. |
| Mitigation | Interim: instrument room card access with a logged entry record, reconciled against acquisition times at review. Permanent: migrate acquisition to the networked CDS server with individual domain accounts, removing the shared login. |
| Residual scores | S 4, O 1, D 2, RPN 8 |
| Residual class | Low, after the permanent mitigation |
| Owner, target date | R. Okonkwo (Lab Systems), 31 December 2026. Until then the interim compensating control operates and the residual class is High. |
Row 2: printout treated as the original for dynamic chromatographic data
| Field | Entry |
|---|---|
| How it happens here | Historically the signed printed report was filed as the record and the electronic project folder was left on the local disk with no defined retention. The governing record has now been declared electronic, but records created before March 2026 were managed under the previous practice. |
| ALCOA+ attribute at risk | Original, Complete |
| Severity | 5. Without the electronic data and its audit trail, a reintegrated or deleted injection cannot be detected, and the affected results supported batch dispositions. |
| Occurrence | 5. Structural for the historical period: the practice applied to every record created before the declaration was issued. |
| Detectability | 4. Detection depends on someone going back to the local disk and confirming the data still exists, which was not a defined check. |
| RPN before | 5 x 5 x 4 = 100, band Critical |
| Class before | Critical, also caught by override rule 1 (severity 5 with detectability 4). |
| Mitigation | Governing record declared electronic and approved by QA on 03 March 2026. Full copy of the historical project folders taken to the validated file store with a verified inventory against the archived worksheets. Retention, backup, and audit trail review now applied to the electronic data. Gap assessment performed on the historical period to confirm what data still exists. |
| Residual scores | S 5, O 1, D 2, RPN 10 |
| Residual class | Low for records created after the declaration. For the historical period the residual class is recorded separately as Medium, because the gap assessment confirmed the data exists but the audit trail for the earliest six months of that period was configured with a shorter retention than the data. That limitation is stated in the residual risk statement rather than scored away. |
| Owner, target date | L. Fernandes (QA), declaration complete; historical gap assessment closed 30 June 2026. |
Row 3: unverified transcription of results to the worksheet
| Field | Entry |
|---|---|
| How it happens here | The analyst reads six reportable results from the chromatography report and writes them on the worksheet, where the assay calculation is performed by hand. |
| ALCOA+ attribute at risk | Accurate |
| Severity | 5. A transcription error in a reportable result feeds the assay calculation and could support an incorrect disposition. |
| Occurrence | 3. Manual transcription of numeric values occurs on every record. Two transcription errors were found and corrected by second-person review in the previous twelve months, both caught. |
| Detectability | 2. Second-person verification of every transcribed value is a defined, recorded step performed on every record, and the last twelve months of review records evidence it. |
| RPN before | 5 x 3 x 2 = 30, band Medium |
| Class before | Medium. Note that severity 5 does not trigger override rule 1 here, because detectability is 2 rather than 4 or 5. This is the intended behaviour of the rule: a severe failure with a real, evidenced detection control is a different situation from a severe failure nobody would catch. |
| Mitigation | Interim: retain 100 percent second-person verification and monitor the exception rate quarterly. Permanent: configure the chromatography system to calculate and report the final assay value, removing the manual calculation and the transcription. |
| Residual scores | S 5, O 1, D 2, RPN 10 |
| Residual class | Low, after the permanent mitigation removes the transcription |
| Owner, target date | A. Ferreira (QC Systems), 31 March 2027 |
Row 4: no reconciliation between the electronic sequence and the worksheet
| Field | Entry |
|---|---|
| How it happens here | Before the reconciliation procedure was issued, review consisted of checking the worksheet for completeness and signing it. The electronic sequence count was not compared to the worksheet and the audit trail was not opened. |
| ALCOA+ attribute at risk | Complete, Consistent |
| Severity | 5. An aborted or deleted injection would not appear on the paper and would not be looked for, so a discarded failing result could support a passing disposition. |
| Occurrence | 5. Structural: with no reconciliation defined, the control did not exist on any record. |
| Detectability | 5. Nothing else would catch it. Detection would depend on an audit or an inspection. |
| RPN before | 5 x 5 x 5 = 125, band Critical |
| Class before | Critical, and caught by override rule 1. |
| Mitigation | Reconciliation defined in the hybrid control SOP and executed on every record using the reconciliation checklist, starting from the electronic side. Reviewer signature meaning amended to state that reconciliation and audit trail review were performed. Quarterly QA sample verifies the reconciliation was performed as described. |
| Residual scores | S 5, O 1, D 2, RPN 10 |
| Residual class | Low |
| Owner, target date | M. Haddad (QA), implemented 01 April 2026; effectiveness verified in the Q2 2026 QA sample. |
Residual risk statement for the specimen
| Field | Entry |
|---|---|
| Failure modes assessed | 14 |
| Critical before mitigation | 3 |
| High before mitigation | 4 |
| Critical remaining after mitigation | 0 |
| High remaining after mitigation | 1 (row 1, until the networked CDS migration completes on 31 December 2026) |
| Compensating controls relied on | Instrument room card-access log CF-QC-009, reconciled against acquisition times at each review; 100 percent second-person verification of transcribed values, recorded on the worksheet |
| Residual risk statement | For records created after 03 March 2026, the dynamic electronic data is the declared governing record, is retained on backed-up storage with a tested restore, and is reconciled and audit-trail reviewed on every record. The remaining High risk is that a privileged file-system action on HPLC-07 would not be attributable to an individual, because the operating system login is shared. This cannot be reduced further without networking the workstation, which is scheduled for 31 December 2026. Until then the compensating control narrows the population of possible actors to those who entered the instrument room during the acquisition window. For records created before 03 March 2026, the electronic data has been recovered and inventoried, but audit trail retention on the earliest six months of that period was shorter than data retention, so reprocessing history for that window cannot be fully reconstructed. This limitation is stated rather than mitigated, and it is included in the pre-approval inspection preparation brief. |
| Re-evaluation date and triggers | 31 January 2027, or earlier on any of: completion or delay of the networked CDS migration, any deviation involving data attribution on HPLC-07, any change to the account model or audit trail configuration. |
| Retirement plan wave assigned | Wave 1 |
Two things in this specimen are worth copying. The first is row 3, where a severity of 5 does not produce a Critical class because a real and evidenced detection control exists; the override rules are written so that severity alone does not drive everything, which is what keeps the scale usable. The second is the residual risk statement, which names a limitation on historical audit trail retention that no mitigation fixes, and says so plainly instead of scoring it down to Low.
Common inspection findings this risk assessment prevents
- Hybrid records are operated with no documented assessment of how the seam between the halves could fail.
- Every hybrid receives the same controls regardless of what depends on the data, so effort is spread evenly and the highest-risk hybrids are undercontrolled.
- Detectability scores assume controls that are written down but not performed, so the assessment concludes that risks are managed when the evidence shows otherwise.
- A severe failure mode is scored down to an acceptable class purely because occurrence was judged low, with no evidence supporting the occurrence estimate and no control that would have detected the failure.
- Residual risk is recorded as “acceptable” with no statement of what risk remains or what would change the conclusion.
- Mitigations are recorded in general terms that cannot be verified as implemented.
- The assessment was written from the procedure rather than from an observed execution, so the workarounds that create the real risk are absent from it.
- The risk assessment, the hybrid inventory, and the migration plan disagree about which hybrids are highest risk.
How to adapt this risk assessment
- Set the document number, owner, and the hybrid inventory reference in the header, and name the assessment team including at least one person who executes the process.
- Observe an execution before scoring. Budget the time for it. The difference between an assessment written at a desk and one written after watching the activity is usually two points of occurrence on at least one row.
- Keep the scales exactly as written across every hybrid assessment you perform, or change them once, centrally, and re-baseline. Scales that vary between assessments make risk classes incomparable, which defeats the prioritisation the retirement plan depends on.
- Add failure modes specific to your record. A cell and gene therapy chain of identity record will have failure modes around subject and product identity linkage that no chromatography hybrid has. A distribution hybrid will have failure modes around temperature record continuity during transfer.
- For each mitigation you select, write the specific implementation, the owner as a named individual, and the record that will evidence it. Then check in six months whether that record exists.
- Where a mitigation is compensating rather than preventive, say so in the notes column and carry the difference into the residual risk statement.
- Feed the final risk class into the hybrid inventory register and the prioritisation score in the retirement plan on the same day, so the three documents cannot drift.
- Confirm every regulation in section 9 against the current published version before issue.