This is a ready-to-use work instruction. Replace every <<FILL: ...>> placeholder with your own specifics and reference it from your parent deviation and investigation SOP. A worked filled specimen follows the template. This work instruction covers writing the narrative itself; it does not cover interviewing people involved in the event, which is covered by a separate blame-free investigative interview work instruction.
Control header
| Field | Entry |
|---|---|
| Work instruction number | <<FILL: WI-ID, e.g. WI-QA-042>> |
| Parent SOP | <<FILL: deviation / investigation SOP-ID>> |
| Version | <<FILL: version>> |
| Effective date | <<FILL: date>> |
| Owner | <<FILL: role, e.g. Head of Quality Assurance>> |
Purpose
Give an investigation owner a repeatable method for writing a deviation statement and investigation narrative that a skeptical reader who was not present can follow, verify against the evidence, and reach the stated conclusion from. The method produces a document where the root cause explains the event rather than relabels it, and where every claim traces to a source already shown in the document.
When to use
Use this work instruction whenever a deviation, out-of-specification, out-of-trend, or complaint investigation reaches the point of drafting the deviation statement or the investigation narrative. Use it alongside, not instead of, your risk-based investigation depth and root cause analysis methods; see root cause analysis techniques for the analytical methods this work instruction assumes have already been applied before the writing begins.
Definitions
- Deviation statement: the initial factual record of a departure from a requirement, stated as two facts side by side: what was required, and what actually happened, quantified.
- Root cause statement: the sentence or short passage stating the systemic reason a failure was possible, as distinct from the individual action that triggered it.
- Ruled in / ruled out: a candidate cause the investigation considered, together with the specific evidence that supported or eliminated it.
Procedure
Step 1: Build the timeline before writing a word of narrative
- Pull the objective sources first: audit trails, logbooks, batch records, alarm histories, badge access, instrument data, maintenance logs.
- Assemble a chronological timeline from these sources alone, not from memory or assumption.
- Flag any gap in the timeline (a period with no record) as something the narrative must address, not something to write around.
Per-step acceptance: a timeline table exists, built entirely from named sources, before any narrative prose is drafted.
Step 2: Write the deviation statement as two facts
- State the requirement first, with its document and section reference: “SOP-XXX section Y.Z specifies…”
- State the departure second, quantified: the actual value, time, and quantity versus the required one.
- State the time the event happened and the time it was discovered, both, and note the gap if there is one.
- State the containment action taken (hold, quarantine, segregate) as a fact.
- Do not add a third clause about impact, criticality conclusion, or blame. If you find yourself writing “so there is no impact” or naming a cause, stop; that content belongs later, after the investigation.
Per-step acceptance: the deviation statement contains a requirement, a quantified departure, both times, and the containment action, and contains no impact or root cause language.
Step 3: State the initial criticality with a one-line basis
- State the initial criticality rating (for example minor, major, critical) and one or two sentences of basis tied to the facts already stated.
- Do not anchor the rating to a desired investigation depth; a rating chosen to avoid a full investigation is a finding pattern regulators cite.
Per-step acceptance: the initial criticality basis references a fact already in the deviation statement, not a conclusion not yet reached.
Step 4: Write the investigation-performed section as ruled in and ruled out
- List each candidate cause the investigation considered.
- For each one, state the specific evidence that supports or eliminates it, with a reference to the timeline or a named source.
- Include causes that were ruled out, with the reason, not only the one that was ultimately accepted. A narrative that shows only the accepted cause reads as though alternatives were never considered.
Per-step acceptance: at least one candidate cause other than the accepted one appears in the narrative, with the evidence that ruled it out.
Step 5: Write the root cause statement to pass the recurrence test
- State why the failure was possible as a system property (a missing check, an ambiguous instruction, a design gap, a maintenance interval gap), not only what the individual did.
- Confirm every claim in the statement traces to evidence already shown in Step 4 or the timeline.
- Apply the test: if the proposed corrective action were implemented, would the same failure be prevented from recurring the same way? If the answer is no, return to Step 4; the analysis has not reached root cause.
- If the root cause cannot be conclusively determined, state that honestly, name the most probable cause with its supporting evidence and confidence level, and state what ongoing monitoring will confirm or rule it out.
Per-step acceptance: the root cause statement passes the three-question test in the technical writing for GxP root cause decision tree, or, where undetermined, states the most probable cause, the confidence level, and the monitoring plan.
Step 6: Write the impact assessment with reasoning, not assertion
- State the impact on the directly affected product or batch, with the evidence and reasoning that supports it (a stability study, a re-test, a comparison against a validated range).
- Widen the lens deliberately: state which other batches, campaigns, equipment, or sites were checked for the same exposure, and the evidence used to rule them in or out of scope.
- Never write “no impact” as the first appearance of that phrase in the document; it may only appear here, after the evidence that supports it.
Per-step acceptance: every impact statement, including “no impact,” cites a specific piece of evidence in the same sentence or the sentence immediately before it.
Step 7: Write the CAPA and its effectiveness check
- State the correction (the immediate fix), the corrective action (addressing the root cause), and the preventive action (addressing the broader pattern), each as a specific action with an owner and a due date.
- Write the effectiveness check as a measurable outcome: name the metric, the baseline, the observation window, and the result that would reopen the CAPA. Do not write an effectiveness check that only restates that the action was completed.
Per-step acceptance: the effectiveness check names a metric, a baseline, a window, and a reopening trigger.
Step 8: Read the finished narrative as the inspector will
- Start at the conclusion and walk backward through the document, asking at each claim “where is this proven?”
- Anywhere the answer is not a specific reference already in the document, add the reference or remove the claim.
- Confirm no new fact appears in the conclusion that was not established earlier in the body.
Per-step acceptance: every claim in the conclusion section has already appeared, with its supporting evidence, earlier in the document.
Acceptance criteria
A completed narrative is acceptable when all of the following are true:
- The timeline was built from named sources before the narrative was drafted.
- The deviation statement contains a requirement, a quantified departure, both times, and containment, with no impact or root cause language.
- At least one ruled-out candidate cause appears with its evidence.
- The root cause statement passes the recurrence test, or the undetermined-cause path is honestly documented.
- Every impact statement, including “no impact,” cites specific evidence.
- The CAPA effectiveness check names a metric, baseline, window, and reopening trigger.
- No claim in the conclusion appears for the first time there.
References
21 CFR 211.100(b) (deviations recorded and justified) and 21 CFR 211.192 (thorough investigation of discrepancies and failures, including the requirement to extend the investigation to other batches where applicable). FDA guidance, Data Integrity and Compliance With Drug CGMP: Questions and Answers (December 2018), on predetermined conclusions and objective evidence. ICH Q10 (Pharmaceutical Quality System), for CAPA effectiveness as an input to continual improvement.
Confirm the current version of each reference before issue.
Record generated: investigation narrative
| Field | Entry |
|---|---|
| Deviation reference | <<FILL>> |
| Deviation statement (requirement, departure, times, containment) | <<FILL>> |
| Initial criticality and basis | <<FILL>> |
| Timeline (attached or embedded) | <<FILL>> |
| Candidate causes ruled in / ruled out, with evidence | <<FILL>> |
| Root cause statement | <<FILL>> |
| Impact assessment (direct and widened scope) | <<FILL>> |
| CAPA actions and effectiveness check | <<FILL>> |
| Conclusion and disposition | <<FILL>> |
| Investigation owner (name, date) | <<FILL>> |
| QA approval (name, signature, date) | <<FILL>> |
Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Author | <<FILL>> | ||
| Reviewer (QA) | <<FILL>> | ||
| Approver (Quality Head) | <<FILL>> |
Filled specimen
The following shows the method applied to an example event, so you can see the level of detail expected. The company, system, and numbers are illustrative and generic.
Event: An analytical instrument was used for one release test while one day past its scheduled calibration due date.
Timeline (Step 1). Built from the calibration management system, the instrument use log, and the analyst’s login record: calibration due date 20-Aug-2026; instrument used for test TST-4471 on 21-Aug-2026 at 09:10; gap identified at 22-Aug-2026 08:40 during the calibration status cross-check ahead of the next scheduled use.
Deviation statement (Step 2). “SOP-QC-018 section 4.1 requires use of only currently calibrated instruments; the calibration management system shows Instrument INS-0231 had a calibration due date of 20-Aug-2026. On 21-Aug-2026 at 09:10, the instrument was used to perform release test TST-4471, one day past its due date. The discrepancy was identified on 22-Aug-2026 at 08:40 during the routine calibration status cross-check. The result was placed on hold pending investigation.”
Initial criticality (Step 3). “Rated major pending investigation: use of an out-of-calibration instrument on a release test requires assessment of whether the result remains reliable.”
Investigation performed (Step 4). “Candidate causes considered: (a) the calibration due-date alert did not fire, ruled in, confirmed by the alert log showing no notification generated for INS-0231 in the relevant window; (b) the analyst bypassed a fired alert, ruled out, no alert record exists to bypass; (c) the calibration schedule itself was set incorrectly, ruled out, the schedule record shows the correct 20-Aug-2026 due date was set at the prior calibration.”
Root cause (Step 5). “The calibration due-date alert failed to generate for this instrument because of a configuration gap: the alert rule excluded instruments added to the schedule mid-cycle, and INS-0231 was added under that condition. The gap explains why a correctly scheduled due date produced no warning; applying the same alert rule to all instruments regardless of when they were added would have prevented this use.”
Impact assessment (Step 6). “A verification check performed the same day (VER-2026-118) confirmed INS-0231 remained within calibration tolerance when checked on 22-Aug-2026, one day after the missed date; the one-day gap did not put the instrument outside its verified tolerance. Result TST-4471 is confirmed reliable, supported by VER-2026-118. A review of the instrument log identified no other instrument added mid-cycle in the same period, so scope is limited to INS-0231.”
CAPA and effectiveness check (Step 7). “Correction: instrument recalibrated and result TST-4471 confirmed valid (complete). Corrective action: alert rule reconfigured to apply to all instruments regardless of when added to the schedule. Preventive action: quarterly configuration audit of the alert rule set added to the calibration program. Effectiveness check: zero instances of an instrument used past its calibration due date with no fired alert, measured over the six months following the reconfiguration, against a baseline of this one instance in the prior twelve months; any recurrence reopens this CAPA.”
Conclusion. “Result TST-4471 confirmed valid. Root cause identified and addressed. CAPA tracked to completion.”
Notice the impact assessment cites a specific verification result before stating no adverse impact, and the effectiveness check states a metric, baseline, window, and reopening trigger rather than restating that the alert rule was fixed.
Common inspection findings this work instruction prevents
- A deviation statement that states impact or names a cause before any investigation has occurred.
- An investigation narrative that shows only the accepted root cause with no evidence of alternatives considered.
- A root cause statement that restates the event (“instrument was out of calibration”) instead of explaining why it happened.
- An impact assessment asserting “no impact” with no cited evidence.
- A CAPA effectiveness check that only confirms the fix was implemented, with no metric, baseline, or window.
How to adapt this work instruction
- Point the parent-SOP field at your real deviation and investigation procedure, and set your document number and effective date.
- Adjust Step 3’s criticality scale to match your own quality system’s rating labels.
- If your investigations use a formal root cause method (fishbone, five whys, fault tree), reference it explicitly in Step 4 and 5 alongside this work instruction; the two are complementary, not competing.
- Keep the Step 8 read-backward technique as a mandatory final check; it is the fastest way to catch a conclusion the body does not actually support.
- Confirm every reference against its current published version before issue.