Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Risk Assessment Plug-and-play starting point Data Integrity

Risk Assessment: Microbiology QC Data Integrity Gap Assessment

A plug-and-play risk assessment for microbiology QC data integrity: a defined method, anchored 1 to 5 scales, a populated failure-mode table covering manual counting, plate retention and imaging, EM/bioburden/sterility/BET record integrity, media fill accountability, and review-by-exception feasibility for automated and rapid methods, with a scored filled specimen.

Document type: Risk Assessment

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use risk assessment for a microbiology QC laboratory’s data integrity controls, scoped to the manual and hybrid record types that carry the most risk in that lab. Replace every <<FILL: ...>> placeholder, set your document numbers and dates, and route it through your normal document control, review, and approval. A worked filled specimen with fully scored rows follows. The scales are the same five-point anchored scales used across this site’s risk assessment templates, so results are comparable across systems. Verify each cited regulation against the current source before you rely on it, and treat this as general guidance to adapt rather than legal or regulatory advice.

Document control header

FieldEntry
Document titleMicrobiology QC Data Integrity Gap Assessment for <<FILL: lab / site>>
Document number<<FILL: RA-ID, e.g. RA-QC-022>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Supersedes<<FILL: prior version or "New">>
Document owner<<FILL: role, e.g. QC Microbiology Manager>>
Assessment team<<FILL: names and roles, including at least one bench analyst>>

1. Purpose

This assessment identifies how data integrity can fail in the microbiology QC laboratory covered by the header, scores each failure mode for severity, occurrence, and detectability, assigns a risk class, defines mitigations, and records the residual risk <<FILL: COMPANY NAME>> accepts. It also evaluates, for each manual process assessed, whether migrating to an automated or imaging system, or applying review by exception, is feasible and would move the risk profile.

2. Scope

This assessment covers manual and hybrid microbiological testing performed at the site: environmental monitoring, bioburden, sterility, bacterial endotoxin testing, media fill data, growth promotion testing, and microbial identification, including the chain of custody for recovered isolates. It covers the human observation, the paper or electronic record, and any instrument data generated alongside it. It does not replace the computer system validation risk assessment for any specific instrument or LIMS, governed by <<FILL: SOP-ID for CSV risk assessment>>.

3. Responsibilities

RoleResponsibility
QC Microbiology ManagerOwns the assessment, convenes the team, and owns the resulting actions.
Bench analyst (SME)Describes what actually happens at the bench, including workarounds; an assessment built only from the procedure underestimates occurrence.
Quality AssuranceApproves the scoring logic, challenges optimistic detectability scores, and approves residual risk acceptance.
Validation / CSVConfirms the technical capability of any instrument or software involved (imaging counters, BET readers, LIMS).
Data integrity leadMaintains consistency of scoring with other risk assessments across the site.

4. Definitions

  • Failure mode: a specific, observable way a microbiology record can stop being a trustworthy account of what was observed.
  • Severity: the consequence if the failure mode occurs and is not detected, judged against product quality, patient or subject safety, and whether the observation can ever be reconstructed.
  • Occurrence: how likely the failure mode is to arise in the process as actually executed, not as written in the procedure.
  • Detectability: the likelihood an existing, operating control catches the failure before the result supports a decision.
  • Risk priority number (RPN): severity multiplied by occurrence multiplied by detectability, 1 to 125.
  • Review by exception: a method where a validated tool or rule set filters routine data so reviewers focus only on the entries that carry risk, rather than reviewing every record line by line.

5. Method

5.1 Sequence

  1. Observe an execution of each process being assessed; do not score from the procedure alone.
  2. Identify failure modes, starting from the catalogue in section 6 and adding anything specific to this lab.
  3. Score severity, occurrence, and detectability per the scales in 5.2 to 5.4, for the current state.
  4. Apply the thresholds and override rules in section 5.5 to assign a risk class.
  5. Define mitigations for every failure mode above the acceptance threshold, and re-score assuming the mitigation is in place and operating.
  6. For each manual process, complete the automation/review-by-exception feasibility assessment in section 6.1.
  7. Record residual risk and route for acceptance.

5.2 Severity scale

ScoreAnchorDescription
5Product, patient, or subjectThe failure could allow an incorrect microbiological result to support a batch disposition or release decision, and the observation cannot be reconstructed once the plate is gone.
4Reconstructability lostThe activity cannot be fully reconstructed; the original observation or its link to the sample is missing or unattributable.
3Result affected but recoverableThe record contains an error that could change a reported count or result, but evidence (the plate, an image, an instrument file) still exists to correct it.
2Record quality affectedThe record is incomplete or inconsistent in a way that does not change a result or decision.
1NegligibleNo effect on any result, decision, or reconstructability.

5.3 Occurrence scale

ScoreAnchorDescription
5StructuralInherent to the current design; occurs whenever the activity runs, with no preventive control.
4FrequentObserved or expected multiple times per <<FILL: period>>, or depends on a manual step with no forcing function.
3OccasionalObserved or expected a few times a year; a manual step exists and omission would be visible.
2RareObserved less than once a year; a preventive control exists and operates.
1RemoteNot observed, and the design makes it very difficult to occur.

5.4 Detectability scale

ScoreAnchorDescription
5Not detectableNo control would catch it; detection depends on chance.
4Unlikely to be detectedDetection depends on a single manual step by one person, with no independent confirmation.
3Possibly detectedA defined review would probably catch it if performed carefully, but the check is not explicit.
2Likely detectedAn explicit, documented check exists at a defined point, performed on every record.
1Almost certainly detectedThe process or system prevents the failure, or a reconciliation makes it impossible to complete the record without noticing.

Name the control, the person or system that performs it, and the record proving it was performed on the last five occasions; if that cannot be done, score 4 or 5.

5.5 Risk class thresholds and override rules

Risk classRPN bandRequired response
Critical60 to 125Not acceptable; mitigate before continuing routine use, or stop the activity.
High36 to 59Mitigation required; interim compensating controls may allow continued operation with a dated plan and QA approval.
Medium16 to 35Mitigation required where practicable.
Low1 to 15Acceptable with existing controls; monitor at periodic review.

Override rules: severity 5 with detectability 4 or 5 is classified Critical regardless of occurrence; severity 4 with detectability 5 is classified High or above regardless of occurrence, since the absence of detection also makes the occurrence estimate unverifiable.

5.6 Automation and review-by-exception feasibility (per process)

For each manual process assessed, record: whether an automated or imaging alternative exists and has been evaluated; whether review by exception is technically feasible given the process’s data volume and structure; and, where full automation is not near-term feasible, what compensating control (second-person verification, imaging, reconciliation) substitutes in the interim. A “not feasible” conclusion is only defensible when it states what was actually evaluated and why it was rejected, not simply asserted.

6. Assessment table

#Failure modeHow it happens hereALCOA+ attribute at riskSODRPNClassMitigationResidual SResidual OResidual DResidual RPNResidual classOwner, target date
1A colony count is recorded from memory after leaving the reading station<<FILL>>Contemporaneous<<FILL>><<FILL>>
2Second-person verification is performed after the plate is discarded<<FILL>>Accurate<<FILL>><<FILL>>
3No documented counting method, so two analysts count the same plate differently<<FILL>>Accurate, Consistent<<FILL>><<FILL>>
4Excursion or near-limit plates are not imaged before disposal<<FILL>>Complete, Original<<FILL>><<FILL>>
5Incubator temperature over the incubation period is evidenced only by a setpoint label<<FILL>>Accurate, Complete<<FILL>><<FILL>>
6A media lot is used before its growth promotion test result is available<<FILL>>Complete<<FILL>><<FILL>>
7Media fill filled/incubated/rejected unit counts do not reconcile<<FILL>>Complete, Consistent<<FILL>><<FILL>>
8A recovered isolate has no unique identifier tying it back to its originating plate<<FILL>>Attributable, Complete<<FILL>><<FILL>>
9An instrument-generated file (BET reader, imaging counter, rapid method platform) is discarded after a single value is transcribed to paper<<FILL>>Original, Complete<<FILL>><<FILL>>
10An instrument audit trail exists but is never reviewed<<FILL>>Complete, Attributable<<FILL>><<FILL>>
11Sterility tests started do not reconcile against results reported<<FILL>>Complete<<FILL>><<FILL>>
12A sterility or EM result is invalidated as “probable lab error” with no objective assignable-cause evidence<<FILL>>Accurate<<FILL>><<FILL>>
<<FILL>><<FILL: failure mode specific to this lab>><<FILL>><<FILL>><<FILL>><<FILL>>

7. Automation / review-by-exception feasibility table

ProcessAutomated alternative evaluated?Review-by-exception feasible?Interim compensating controlTarget state and date
Manual colony counting (EM, bioburden)<<FILL: yes/no, what was evaluated>><<FILL>><<FILL: second-person verification, imaging>><<FILL>>
Sterility observation<<FILL>><<FILL>><<FILL>><<FILL>>
BET reader result review<<FILL>><<FILL>><<FILL>><<FILL>>
Media fill unit reconciliation<<FILL>><<FILL>><<FILL>><<FILL>>

8. Residual risk statement

FieldEntry
Failure modes assessed<<FILL: count>>
Critical before mitigation<<FILL: count>>
High before mitigation<<FILL: count>>
Critical remaining after mitigation<<FILL: count, expected zero>>
High remaining after mitigation<<FILL: count, each justified>>
Residual risk statement<<FILL: plain-language statement of what risk remains and why>>
Re-evaluation date and triggers<<FILL>>

9. References

21 CFR 211.194, 211.160(b). USP <61>, <62>, <71>, <1117>, <1223> (consult current chapters for method and validation detail). FDA guidance, Data Integrity and Compliance With Drug CGMP, Questions and Answers (December 2018). MHRA GXP Data Integrity Guidance and Definitions (March 2018). PIC/S PI 041, Good Practices for Data Management and Integrity. ICH Q9, Quality Risk Management.

Confirm the current version and clause numbers of each reference before issue.

10. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

11. Approvals

RoleNameSignatureDate
Author<<FILL>>
Bench SME<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality Head), required for any Critical or High residual risk accepted<<FILL>>

Filled specimen

Two rows fully scored for an example QC microbiology laboratory, plus one feasibility assessment.

Row 2: second-person verification performed after the plate was discarded

FieldEntry
How it happens hereOn a busy shift, the second analyst sometimes signs the verification column at end of day from the written count sheet, after plates have already been autoclaved.
ALCOA+ attribute at riskAccurate
Severity4. A miscounted or transcribed-wrong result could not be caught, and the plate no longer exists to check it against.
Occurrence3. Observed on high-volume shifts a few times per quarter based on the last twelve months of internal audit sampling.
Detectability4. The only “control” is the verifier’s signature, which does not distinguish a real check from a rubber stamp.
RPN before4 x 3 x 4 = 48, band High
MitigationWorkflow changed so plates route physically to the second analyst before disposal; verification station placed next to the autoclave queue so verification-before-discard is the path of least resistance, not an extra trip.
Residual scoresS 4, O 1, D 2, RPN 8
Residual classLow
Owner, target dateLab supervisor, implemented 01 September 2026.

Row 6: media lot used before growth promotion result is available

FieldEntry
How it happens hereNew media lots are sometimes brought into routine use when stock of the previous lot runs low, before that new lot’s GPT read is complete.
ALCOA+ attribute at riskComplete
Severity4. Any result the unproven lot supports rests on an unconfirmed assumption that the medium can grow the organisms it is meant to detect.
Occurrence2. Observed twice in the past year, both tied to stock-out pressure rather than routine practice.
Detectability3. The GPT log is reviewed weekly, which would probably catch an in-use lot with no GPT record, but the check is not tied to the point of use.
RPN before4 x 2 x 3 = 24, band Medium
MitigationLot release gate added: the LIMS (or a physical quarantine shelf, where no LIMS gate exists) blocks or visibly flags any lot without a passing GPT record from being pulled into routine testing.
Residual scoresS 4, O 1, D 1, RPN 4
Residual classLow
Owner, target dateQC Microbiology Manager, gate live 15 October 2026.

Feasibility assessment: manual colony counting (EM, bioburden)

FieldEntry
Automated alternative evaluated?Yes. An imaging colony counter was piloted for six weeks against manual counts on the same plate set.
Review-by-exception feasible?Partially. The imaging system can flag near-limit and out-of-range counts for mandatory review, but full review by exception (skipping review of in-range counts entirely) was not adopted because the pilot’s false-classification rate on confluent growth was judged too high without a human check on every plate.
Interim compensating controlSecond-person verification remains on every plate; the imaging system runs in parallel to build a longer validation data set.
Target state and dateRe-evaluate full review-by-exception adoption after 12 months of parallel data, target decision Q3 2027.

Common inspection findings this risk assessment prevents

  • No documented data integrity risk assessment exists for the microbiology lab specifically, despite it being flagged as high-risk in general DI programs.
  • Every manual process in the lab receives identical controls regardless of what depends on the result, so effort is spread evenly rather than where risk concentrates.
  • A “review by exception is not feasible” conclusion asserted with no record of what was actually evaluated.
  • Detectability scores assume a verification step is real when the evidence shows it is closer to a signature ritual.

How to adapt this risk assessment

  1. Set the document number, owner, and assessment team, including at least one bench analyst, in the header.
  2. Observe an actual execution of each process before scoring; the difference between a desk-written assessment and one written after watching the bench is usually two points of occurrence on at least one row.
  3. Add failure modes specific to your lab’s actual instruments (a particular imaging counter, a particular rapid method platform).
  4. Complete the feasibility table honestly; a lab under staffing pressure to automate everything should still document why review by exception is or is not ready, rather than skip the analysis.
  5. Feed the final risk classes into your lab’s periodic review and into the site-level data integrity gap assessment.
  6. Confirm every regulation and compendial chapter in section 9 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.