Resources  /  Checklists  /  ICH Q10

ICH Q10 PQS audit checklist

Practising auditors wrote these 78 audit questions, covering the full standard. Each item names the objective evidence to request, the nonconformities most often raised against it, and what to sample. It is free to read, with no sign-up required.

Download the PDF

Includes all 78 items, formatted for a clipboard.

You will get one email with the file. We will not send anything else.

78 items6 hours estimated, end to end 4 sectionsICH Q10 · updated 2026-06-22

What each item gives you

This is what an auditor needs at each item. You already hold the standard itself.

The question

Phrases it the way you would ask it in the room.

Objective evidence

Names the specific artefacts that satisfy the item, and how to tell a real one from a placeholder.

Common nonconformities

Lists the findings most often raised here, in the words they get written up in.

Auditor tips

Shows where the item usually goes wrong, and what a mature answer sounds like against a rehearsed one.

What to sample

Explains how many to take, how to choose them, and what to cross-reference them against.

Follow-up questions

Gives the second and third questions to ask when the first answer is too smooth.

All 78 items on this page

Questions below are grouped by section, and you can check items off as you go — this browser remembers your progress. Open any row for its evidence, common nonconformities and auditor tips.

§1 Pharmaceutical quality system 19 items · ~95 min
1.2 Does the PQS scope explicitly cover both drug substances (APIs) and drug products, and is it adapted to each product's lifecycle stage rather than applied identically everywhere?
Objective evidence
  • PQS scope statement covering drug substances and drug products
  • Lifecycle stage identification for each product
  • Evidence of PQS adaptation by lifecycle stage
  • Product portfolio with lifecycle stage mapping
  • Scope exclusions documented with justification
  • Periodic scope review records
  • Board-level or executive endorsement of PQS scope boundaries
Common nonconformities
  • PQS scope does not mention drug substances separately
  • Same PQS applied identically across all lifecycle stages
  • No documented scope statement
  • Biotechnology/biological products excluded without justification
  • Scope not reviewed when new products or stages are added
  • Discontinued products still consuming PQS resources without reassessment
Auditor tip

The PQS scope must explicitly cover both drug substances and drug products, and must be adapted to the lifecycle stage. A development-stage PQS will look different from a commercial manufacturing PQS. The scope statement should be documented and periodically reviewed.

1.2(a) Is drug substance (API) manufacturing - synthesis, fermentation, cell culture, extraction - explicitly within the PQS scope?
Objective evidence
  • PQS scope explicitly listing drug substance operations
  • Drug substance manufacturing sites included in quality system
  • API supplier quality agreements referencing PQS requirements
  • ICH Q11 compliance assessment for drug substance development
  • Drug substance process validation within PQS framework
  • Contract drug substance manufacturer oversight records
  • Fermentation or cell culture process lifecycle documentation
Common nonconformities
  • Drug substance operations excluded from PQS
  • API manufacturing managed outside quality system
  • No ICH Q11 linkage in development activities
  • Contract API manufacturers not covered by quality agreements
  • No traceability between drug substance batches and PQS records
  • Intermediate hold-time studies absent from validation scope
Auditor tip

Drug substance (API) manufacturing must be within PQS scope. This includes chemical synthesis, fermentation, cell culture, and extraction processes. ICH Q11 linkage ensures development and manufacturing of APIs are covered.

1.2(b) Is drug product manufacturing, packaging, labeling, and testing within the PQS scope, with Quality-by-Design (ICH Q8) principles integrated?
Objective evidence
  • PQS scope explicitly listing drug product operations
  • All dosage forms and product types covered
  • Packaging and labeling operations within PQS
  • ICH Q8 compliance for drug product development
  • Drug product lifecycle tracking within PQS
  • Container closure system qualification records under PQS
  • Stability program integration with product lifecycle management
Common nonconformities
  • Some dosage forms or product lines excluded from PQS
  • Packaging/labeling operations managed outside PQS
  • No ICH Q8 linkage in product development
  • Combination products omitted from PQS scope without rationale
  • Serialization and track-and-trace not governed by PQS
  • No formal handoff between development and commercial PQS for new products
Auditor tip

Drug product (finished dosage form) manufacturing, packaging, labeling, and testing must all be within PQS scope. ICH Q8 linkage ensures Quality by Design principles are integrated. Auditors should confirm that all dosage forms in the portfolio are explicitly listed, and that the PQS governs the full chain from formulation through distribution, including any outsourced packaging or labeling operations.

1.3 Can the organization show it meets regional GMP (EU GMP / FDA cGMP / PIC/S) as the baseline, with ICH Q10 building on top rather than replacing it?
Objective evidence
  • Documented relationship between PQS and applicable GMP regulations
  • GMP compliance demonstrated alongside ICH Q10 implementation
  • Regulatory requirements matrix mapping GMP to ICH Q10
  • Gap analysis between regional GMP and ICH Q10
  • Evidence of ICH Q10 elements enhancing baseline GMP
  • Site master file referencing both GMP and ICH Q10
  • Training records demonstrating staff awareness of GMP-Q10 distinctions
Common nonconformities
  • ICH Q10 treated as replacement for GMP
  • No documentation of GMP-Q10 relationship
  • ICH Q10 implemented without baseline GMP compliance
  • Confusion between GMP requirements and Q10 enhancements
  • PIC/S or EU GMP annex updates not reflected in PQS alignment reviews
  • Regional GMP deviations not cross-referenced against ICH Q10 expectations
Auditor tip

ICH Q10 does NOT replace GMP — it builds on top of it. Organizations must be compliant with regional GMP (EU GMP, FDA cGMP, PIC/S, etc.) as the baseline, and use ICH Q10 to enhance their PQS beyond minimum GMP. The relationship between Q10 and regional GMP should be documented.

1.4 Where the PQS is mature, is it leveraged for enhanced approaches (e.g. real-time release, reduced post-approval submissions, science-based flexibility) where appropriate?
Objective evidence
  • Documentation of how PQS supports regulatory confidence
  • Examples of science-based regulatory approaches enabled by PQS
  • Risk-based approaches documented and shared with regulators
  • Real-time release testing programs (where applicable)
  • Post-approval change management protocols (ICH Q12 linkage)
  • Regulatory interaction records demonstrating PQS maturity
  • Established condition assessment reports leveraging PQS data
Common nonconformities
  • PQS not leveraged for any regulatory flexibility
  • No science-based or risk-based approaches to regulatory submissions
  • Purely compliance-driven quality system with no strategic value
  • Post-approval change submissions lack PQS performance data to support risk arguments
  • No mechanism to capture regulatory commitments and track fulfilment within PQS
  • Regulatory inspection findings repeatedly cite same PQS gaps across cycles
Auditor tip

A mature ICH Q10 implementation can enable enhanced regulatory approaches such as real-time release testing, reduced post-approval submissions, and science-based regulatory flexibility. The PQS should demonstrate how it supports regulatory confidence.

1.5 Can the organization demonstrate its PQS actually achieves all three ICH Q10 objectives - consistent product realisation, a maintained state of control, and continual improvement - with evidence, not just a statement?
Objective evidence
  • PQS policy statement referencing all three objectives
  • Quality objectives aligned with product realisation
  • State of control metrics and dashboards
  • Continual improvement program documentation
  • Management review minutes referencing objectives
  • Annual PQS performance reports
  • Quality planning documents
  • Process performance trending data
Common nonconformities
  • PQS policy does not reference ICH Q10 objectives
  • No measurable quality objectives defined
  • State of control not defined or monitored
  • No evidence of continual improvement activities
  • Objectives only on paper, no active tracking
  • Objectives not cascaded to site or departmental level
Auditor tip

Organizations must demonstrate their PQS achieves all three ICH Q10 objectives. This is the overarching framework: products must be realized consistently, processes must be in a validated state of control, and mechanisms for continual improvement must be active and measurable.

1.5.1 Can the organization show every batch consistently meets the quality attributes defined in its regulatory filings, from raw materials through release?
Objective evidence
  • Product quality review (PQR) / Annual Product Review (APR)
  • Batch release records showing consistent quality
  • Stability data demonstrating shelf-life compliance
  • Specification compliance trending
  • Customer complaint trends showing product quality
  • Regulatory filing commitments mapped to controls
  • Process capability indices (Cpk, Ppk)
  • Right-first-time metrics
Common nonconformities
  • High batch failure rates
  • Recurring OOS/OOT results for same product
  • No product quality review process
  • Specification drift without justification
  • Customer complaints about product quality
  • Supply chain disruptions impacting consistent delivery timelines
Auditor tip

Product realisation means consistently manufacturing products that meet all quality attributes defined in regulatory filings. The PQS must ensure every batch meets specifications, from raw materials through final release.

1.5.2 Does the organization maintain a documented state of control - validated processes running within established parameters, continuously monitored - with a way to detect and respond to deviations from it?
Objective evidence
  • Process validation lifecycle documentation
  • Continued process verification (CPV) program
  • Control strategy documents
  • Process monitoring plans with alert/action limits
  • Control charts and statistical process control (SPC)
  • Environmental monitoring programs
  • Equipment qualification and calibration records
  • Risk assessments informing monitoring strategies
Common nonconformities
  • No ongoing process monitoring after validation
  • Alert/action limits not defined or not responded to
  • Validated state not maintained after changes
  • No statistical trending of process parameters
  • Risk management not linked to monitoring strategy
  • Equipment requalification not triggered after major maintenance events
Auditor tip

State of control means validated processes operating within established parameters, monitored continuously. Organizations must have systems to detect deviations from the controlled state and respond appropriately. Quality risk management informs what to monitor and how.

1.5.3 Is continual improvement systematic - drawing opportunities from CAPA, deviations, process data, complaints, and audits - rather than purely reactive?
Objective evidence
  • Continual improvement program documentation
  • Improvement project tracking and metrics
  • Variability reduction initiatives
  • Innovation pipeline for quality improvements
  • PQS enhancement proposals and outcomes
  • Trend analysis reports driving improvements
  • Management review improvement actions
  • Benchmarking studies
Common nonconformities
  • No formal continual improvement program
  • Improvement is only reactive (post-CAPA)
  • Same issues recurring without systemic improvement
  • No metrics tracking improvement effectiveness
  • Innovation not considered for quality systems
  • Improvement initiatives limited to corrective actions with no proactive projects
Auditor tip

Continual improvement must be systematic, not just reactive. Organizations should identify improvement opportunities from multiple data sources (CAPA, deviations, process data, complaints, audits) and implement changes that measurably reduce variability and enhance quality.

1.6 Are knowledge management and quality risk management genuinely integrated into the PQS processes (CAPA, change management, monitoring), rather than run as standalone activities?
Objective evidence
  • Knowledge management policy or framework
  • Quality risk management policy referencing ICH Q9
  • Integration of KM and QRM into PQS processes
  • Examples of science-based and risk-based decisions
  • Technology transfer knowledge packages
  • Lessons learned databases
  • Cross-functional process team charters referencing KM and QRM deliverables
Common nonconformities
  • Knowledge management not formalized
  • Risk management done only for regulatory submissions
  • No integration between KM/QRM and daily operations
  • Enabler effectiveness never assessed during management review
  • KM and QRM treated as separate projects rather than embedded PQS capabilities
  • No documented criteria for when to invoke formal risk assessment versus informal review
Auditor tip

Knowledge management and quality risk management are the two foundational enablers of the PQS. They are not standalone activities but must be integrated into all PQS processes (CAPA, change management, process monitoring, management review).

1.6.1 Is there a system to capture, store, retrieve, and share product and process knowledge across the full lifecycle, including tacit knowledge from experienced staff?
Objective evidence
  • Knowledge management system or database
  • Technology transfer protocols and reports
  • Development-to-manufacturing knowledge packages
  • Lessons learned from deviations and CAPAs
  • Process understanding documents (design space, CPPs, CQAs)
  • Prior knowledge assessments
  • Knowledge sharing mechanisms (communities of practice)
  • Retirement/succession knowledge capture plans
  • Product lifecycle knowledge maps
Common nonconformities
  • No systematic knowledge capture process
  • Knowledge lost during personnel changes
  • Technology transfer without formal knowledge packages
  • No lessons learned program
  • Process understanding limited to validation reports
  • Tacit knowledge of retiring subject matter experts not captured before departure
Auditor tip

Knowledge management must cover the entire product lifecycle. Organizations must have systems to capture, store, retrieve, and share product and process knowledge. This includes tacit knowledge from experienced personnel, not just documented procedures.

1.6.2 Is quality risk management (ICH Q9) applied throughout the PQS, so risk assessments actually inform monitoring strategy, change priorities, CAPA, and management-review focus?
Objective evidence
  • Quality risk management SOPs referencing ICH Q9
  • Risk assessment tools (FMEA, HACCP, fault tree analysis)
  • Risk assessments for process changes
  • Risk-based approaches to process monitoring
  • Supplier risk assessments
  • Risk communication records
  • Risk review and update documentation
  • Risk-based audit planning
  • Risk registers with periodic reviews
Common nonconformities
  • Risk management limited to regulatory submissions only
  • FMEA completed once and never updated
  • No risk-based approach to change management
  • Risk assessments not referenced in CAPA investigations
  • No formal risk communication process
  • Risk register reviews overdue by more than one assessment cycle
Auditor tip

QRM per ICH Q9 must be integrated throughout the PQS. Risk assessments should inform process monitoring strategies, change control priorities, CAPA root cause analysis, and management review focus areas. Risk management should be proactive, not just reactive.

1.7 Is the PQS right-sized and justified for the organization's scale and complexity, and is that design periodically reassessed as the company changes?
Objective evidence
  • PQS design rationale document
  • Complexity assessment for PQS scope
  • Risk-based justification for PQS structure
  • Periodic PQS design review records
  • Scalability considerations documented
  • Comparison of PQS complexity to operational complexity
  • Benchmarking against peer organizations with similar product portfolios
Common nonconformities
  • Overly complex PQS for a simple operation
  • Overly simplistic PQS for complex multi-site operations
  • PQS design never reassessed since initial implementation
  • No risk management integrated into PQS design
  • One-size-fits-all PQS across diverse product lines
  • PQS structure unchanged despite acquisition of new manufacturing sites
Auditor tip

The PQS must be right-sized. A small single-product company does not need the same complexity as a global multi-site corporation. The system design should be justified and periodically reassessed as the organization evolves.

1.7(a) Does the organization chart give the quality unit adequate authority and independence, with reporting lines that let quality issues escalate to senior management?
Objective evidence
  • Organizational chart showing quality function
  • Quality unit authority and independence documentation
  • Role descriptions with quality responsibilities
  • Reporting line documentation for quality escalation
  • Resource allocation records for PQS activities
  • Competency requirements for quality roles
  • Delegation of authority matrix for quality decisions
Common nonconformities
  • Quality unit lacks independence from production
  • Quality responsibilities not in job descriptions
  • Inadequate staffing for quality functions
  • No clear reporting line to senior management for quality
  • Quality unit budget cuts not assessed for PQS impact
  • Cross-site quality responsibilities undefined in multi-site organizations
Auditor tip

The organization chart must reflect quality responsibilities. The quality unit must have adequate authority and independence. Reporting lines must support escalation of quality issues to senior management.

1.8 Is there a quality manual (or equivalent) that describes the full PQS scope, structure, processes, and their interactions, and the responsibilities within it?
Objective evidence
  • Quality manual or PQS description document
  • Quality policy statement within the manual
  • PQS scope statement
  • Process maps showing PQS process interactions
  • Organizational charts with quality responsibilities
  • Document hierarchy description
  • Cross-reference to detailed SOPs and procedures
  • Site master file (where applicable)
Common nonconformities
  • No quality manual or equivalent document
  • Quality manual outdated or does not reflect current operations
  • PQS scope not clearly defined
  • Process interactions not described
  • Management responsibilities not defined
  • Quality manual not distributed to or accessible by relevant site personnel
Auditor tip

The quality manual (or equivalent) must describe the entire PQS scope, structure, and processes. It serves as the top-level document that provides an overview of how the quality system operates and who is responsible for what.

1.8(a) Is the quality policy included in or referenced by the quality manual, and is it specific to pharmaceutical manufacturing rather than generic boilerplate?
Objective evidence
  • Quality policy statement within quality manual
  • Policy approved and dated by senior management
  • Policy referencing pharmaceutical quality and patient safety
  • Evidence of policy review and update cycle
  • Communication records showing policy dissemination to all sites
  • Employee awareness assessment results for quality policy content
  • Policy revision history log with change rationale
Common nonconformities
  • Quality policy absent from quality manual
  • Policy is generic, not pharmaceutical-specific
  • Policy not signed or dated by management
  • Policy not communicated beyond quality department
  • No mention of patient safety or product lifecycle in policy text
  • Policy unchanged for multiple years despite significant operational changes
Auditor tip

The quality policy must be included in or referenced by the quality manual. It should be specific to pharmaceutical manufacturing, not generic boilerplate. The policy should articulate commitments to patient safety, regulatory compliance, and continual improvement. Auditors should verify that the policy is communicated to all levels of the organization and that employees can describe how their work relates to it.

1.8(b) Does the quality manual clearly define the PQS boundaries (products, sites, operations, lifecycle stages) with any exclusions justified, and is the scope kept current?
Objective evidence
  • PQS scope statement in quality manual
  • Product and site coverage defined
  • Lifecycle stages covered per product
  • Exclusions documented with justification
  • Scope revision records triggered by portfolio or site changes
  • Contract manufacturing and outsourced activity coverage matrix
  • Annual scope adequacy review minutes
Common nonconformities
  • No scope statement in quality manual
  • Scope is vague or undefined
  • Exclusions not justified
  • Recently acquired sites or products not yet reflected in scope
  • Outsourced activities omitted from PQS scope boundaries
  • Scope statement has not been revised since original quality manual issuance
Auditor tip

The scope section must clearly define boundaries: which products, sites, operations, and lifecycle stages are included. Any exclusions must be justified. Auditors should verify that the scope is updated when new products are launched, sites are acquired or divested, or contract manufacturing arrangements change. A stale scope creates blind spots where products or processes may operate outside PQS governance.

1.8(c) Does the quality manual show how the PQS processes interact (process maps or flow charts with inputs, outputs, and linkages), not just list them?
Objective evidence
  • PQS process interaction diagrams
  • Process maps or flow charts in quality manual
  • Input/output definitions for each PQS process
  • Linkage descriptions between CAPA, change, monitoring, review
  • Turtle diagrams for key processes
  • Data flow diagrams between PQS elements and supporting IT systems
  • Cross-functional SIPOC charts for core pharmaceutical processes
Common nonconformities
  • No process maps or interaction diagrams
  • Processes listed but linkages not shown
  • Process maps outdated or do not reflect current operations
  • Critical handoffs between quality, production, and regulatory not depicted
  • Feedback loops from CAPA and management review absent from process maps
  • Outsourced process steps not shown in interaction diagrams
Auditor tip

The quality manual must show how PQS processes interact — not just list them. Visual tools (process maps, flow charts, turtle diagrams) should show inputs, outputs, and linkages between processes like CAPA, change management, monitoring, and management review.

1.8(d) Does the quality manual clearly define who is responsible for what across the PQS - quality unit authority, production responsibilities, and senior-management obligations?
Objective evidence
  • Management responsibility section in quality manual
  • Organizational chart showing quality-related roles
  • Authority matrix for quality decisions
  • Role descriptions referenced in quality manual
  • Delegation of authority documentation
  • Management review attendance records confirming executive participation
  • Succession planning documents for key quality leadership roles
Common nonconformities
  • No management responsibility section in manual
  • Responsibilities vague or undefined
  • Organizational chart missing or outdated
  • Authority for quality decisions not documented
  • Senior management absent from management review meetings
  • No contingency for quality decision authority when key personnel are unavailable
Auditor tip

The quality manual must clearly define who is responsible for what within the PQS. This includes quality unit authority, production management responsibilities, and senior management obligations. Organizational charts should support these definitions.

§2 Management responsibility 18 items · ~90 min
2.1 Is senior management visibly and actively engaged with the PQS - allocating resources, participating in reviews, championing quality - rather than just approving documents?
Objective evidence
  • Management commitment statement
  • Management participation in quality reviews (minutes/attendance)
  • Resource allocation records for quality initiatives
  • Organizational chart with quality roles defined
  • Escalation procedures for quality issues
  • Management presentations on quality performance
  • Quality KPIs reviewed by senior management
  • Annual quality plan approved by management
Common nonconformities
  • Management absent from quality reviews
  • Quality function under-resourced
  • No escalation pathway for critical quality issues
  • Quality objectives not set by senior management
  • Management only involved during regulatory inspections
  • Quality budget reduced without risk assessment justification
Auditor tip

Senior management must be visibly and actively engaged with the PQS, not merely approving documents. They must demonstrate commitment through resource allocation, participation in reviews, and championing improvement.

2.1(a) Is senior management personally involved in PQS design decisions (workshops, implementation reviews), not just signing off what the quality department proposes?
Objective evidence
  • Management participation in PQS design workshops
  • Sign-off on PQS architecture and structure
  • Management involvement in PQS implementation milestones
  • Periodic PQS maintenance reviews with management attendance
  • Management input into PQS improvement initiatives
  • Steering committee charter for PQS governance
  • Gap analysis reports reviewed and approved by senior leadership
Common nonconformities
  • PQS designed entirely by quality department without management input
  • Management signs off without understanding PQS design
  • No management involvement in PQS updates or changes
  • PQS architecture unchanged despite organizational restructuring
  • No documented management attendance at PQS milestone gate reviews
  • PQS governance delegated entirely to mid-level managers
Auditor tip

Senior management must be personally involved in PQS design decisions, not just approving what the quality department proposes. Evidence of participation in design workshops, implementation reviews, and ongoing PQS governance is expected.

2.1(b) Can employees point to visible management support for quality (attending quality events, communicating priorities, allocating resources, holding people accountable) that sets the tone from the top?
Objective evidence
  • Management communications on quality (emails, town halls, newsletters)
  • Management attendance at quality events and training
  • Budget approvals for quality improvement projects
  • Management walkabouts/gemba walks in production areas
  • Quality integrated into performance evaluations
  • Executive sponsorship records for CAPA initiatives
  • Board-level quality performance reporting decks
Common nonconformities
  • Quality communication only flows from QA, not management
  • Management prioritizes schedule/cost over quality
  • No visible management engagement with quality activities
  • Quality improvement projects chronically deferred for production targets
  • Employee surveys indicate lack of management quality commitment
  • No executive sponsor assigned to critical quality programs
Auditor tip

Visible support means management actions that employees can observe: attending quality events, communicating quality priorities, allocating resources, and holding people accountable for quality. 'Tone at the top' must be demonstrable.

2.1(c) Is there a formal escalation process with defined triggers, timeframes, and levels, so critical quality issues (recalls, serious deviations, safety concerns) reach senior management quickly?
Objective evidence
  • Quality issue escalation SOP
  • Escalation matrix with triggers and timeframes
  • Records of escalated quality issues
  • Timeliness metrics for quality escalations
  • After-action reviews for escalated events
  • Evidence that escalation pathway was used effectively
  • Field alert and product recall notification logs
Common nonconformities
  • No formal escalation procedure
  • Critical quality issues delayed in reaching management
  • Escalation pathway exists on paper but not used
  • Management unaware of significant quality events
  • Batch disposition decisions made without escalation of OOS results
  • No after-action review conducted following escalated safety events
Auditor tip

A formal escalation process must exist with defined triggers, timeframes, and escalation levels. Critical quality issues (recalls, serious deviations, safety concerns) must reach senior management within defined timeframes.

2.1(d) Does every unit involved in the PQS (quality, production, engineering, regulatory, supply chain) have clearly defined roles and authority?
Objective evidence
  • Role descriptions with quality-related responsibilities
  • Authority matrix for quality decisions
  • Organizational chart showing PQS-related units
  • RACI matrix for key PQS processes
  • Communication of roles and authorities (training records)
  • Interrelationship diagrams between functional units
  • Delegation of authority letters for batch release and deviation closure
Common nonconformities
  • Quality responsibilities missing from non-QA job descriptions
  • Ambiguous authority for quality decisions (e.g., batch release)
  • Interrelationships not defined between QA and production
  • Roles documented but not communicated
  • Conflicting authority between site quality head and corporate quality
  • No designated person responsible for pharmacovigilance liaison
Auditor tip

Every unit involved in the PQS must have clearly defined roles and authority. This includes quality, production, engineering, regulatory, supply chain, and any other function that impacts product quality. Interrelationships between units must be documented.

2.2 Does the quality policy specifically address pharmaceutical quality, regulatory compliance, and continual-improvement commitment, and is it communicated and understood across the organization?
Objective evidence
  • Documented quality policy statement
  • Evidence of policy communication (training records, postings)
  • Policy references to regulatory compliance
  • Policy references to continual improvement
  • Periodic review records of quality policy
  • Employee awareness of quality policy (interviews/surveys)
  • Translation of quality policy into local languages for multi-site operations
Common nonconformities
  • Generic quality policy not specific to pharmaceutical manufacturing
  • Policy not communicated to shop floor personnel
  • Policy not reviewed since initial creation
  • No reference to continual improvement
  • Policy contradicts actual practices
  • Quality policy does not address patient safety or product lifecycle
Auditor tip

The quality policy must be more than a generic statement. It should specifically address pharmaceutical quality, regulatory compliance, and continual improvement commitment. It must be communicated to and understood by all personnel.

2.3 Are quality objectives SMART and cascaded through the organization, with quality plans detailing how each will be achieved, by whom, and by when?
Objective evidence
  • Documented quality objectives (site and department level)
  • Quality plans with timelines and responsibilities
  • Quality objectives aligned with quality policy
  • Departmental quality objectives derived from site objectives
  • Progress tracking against quality objectives
  • Communication records of quality objectives
  • Annual product quality review targets linked to quality plan
Common nonconformities
  • Quality objectives not measurable
  • Same objectives year after year with no progress
  • Objectives not cascaded to department level
  • No quality plan to achieve objectives
  • Objectives not linked to quality policy
  • No interim milestone reviews for multi-year quality initiatives
Auditor tip

Quality objectives must be SMART (specific, measurable, achievable, relevant, time-bound) and cascaded throughout the organization. Quality plans should detail how objectives will be achieved, by whom, and by when.

2.4 Does management ensure the PQS has adequate resources (people, facilities, equipment, knowledge), reviewed periodically, so quality activities are not compromised by resource constraints?
Objective evidence
  • Resource allocation plans for quality operations
  • Staffing levels assessment for quality functions
  • Training and competency development budgets
  • Capital investment in quality infrastructure
  • Equipment and facility maintenance budgets
  • Resource adequacy assessments
  • Workforce planning for quality roles
Common nonconformities
  • Quality function chronically understaffed
  • Equipment maintenance deferred due to budget
  • Training programs cut or delayed
  • Quality lab capacity insufficient for workload
  • No resource planning for quality activities
  • Critical analytical instrument qualification lapsed due to funding gaps
Auditor tip

Resource management encompasses all types of resources needed for the PQS. Management must ensure that quality activities are not compromised by resource constraints. Resource adequacy should be periodically assessed.

2.5 Is PQS communication genuinely bidirectional - policy and objectives flowing down, quality issues and escalations flowing up - and timely for issues affecting marketed product?
Objective evidence
  • Communication procedures for quality information
  • Quality escalation SOPs with defined timeframes
  • Meeting minutes (quality councils, cross-functional)
  • Quality bulletin boards or digital communications
  • Shift handover procedures for quality issues
  • Quality alert systems
  • Town hall or all-hands quality updates
Common nonconformities
  • Quality issues not escalated in timely manner
  • Shop floor unaware of quality decisions
  • No formal escalation procedures
  • Communication silos between departments
  • Quality information only flows top-down
  • Shift-to-shift handover omits pending quality holds
Auditor tip

Communication must be bidirectional — top-down for policy/objectives and bottom-up for quality issues/escalations. Timeliness is critical for quality escalations that may affect product on the market.

2.6 Is management review a formal governance mechanism at a defined frequency, systematically evaluating PQS performance against defined inputs and producing actionable outputs?
Objective evidence
  • Management review procedure
  • Management review meeting minutes
  • Management review agenda with all required inputs
  • Action items from management review with follow-up
  • Trending data presented at management review
  • External assessment results reviewed
  • PQS effectiveness assessment
  • Innovation and improvement proposals reviewed
  • Management review schedule
Common nonconformities
  • Management review not conducted at defined frequency
  • Required inputs not all covered
  • No action items generated from review
  • Action items not followed up
  • Review is a rubber-stamp exercise
  • External factors not considered
Auditor tip

Management review is a formal governance mechanism. It must systematically evaluate PQS performance using defined inputs, and produce actionable outputs. Reviews should occur at a defined frequency (typically annual at minimum) and cover all required input topics.

2.6(a) Are all regulatory inspection outcomes, internal and external audit results, and periodic PQS assessments reviewed by management, with trends analyzed across sources?
Objective evidence
  • Regulatory inspection results summarized for management review
  • Internal audit reports presented at management review
  • External audit findings and responses tracked
  • Trend analysis of audit findings over time
  • CAPA status for inspection/audit observations
  • Regulatory commitment tracker with completion milestones
  • Customer and partner audit finding closure reports
Common nonconformities
  • Inspection results not presented at management review
  • Repeat audit findings indicating unresolved issues
  • No tracking of audit finding trends
  • Overdue regulatory commitments not escalated to senior management
  • Internal audit schedule coverage gaps for GMP-critical areas
  • Audit findings downgraded in severity without documented rationale
Auditor tip

All regulatory inspection outcomes, internal and external audit results, and periodic PQS assessments must be presented to and reviewed by management. Trends in findings should be analyzed across multiple inspection cycles to identify systemic weaknesses. Management must demonstrate awareness of open commitments made to regulatory authorities and track their timely closure.

2.6(b) Does management periodically assess the PQS itself - is the quality system working, are processes effective, are resources adequate - not just product quality?
Objective evidence
  • PQS self-assessment or maturity assessment records
  • PQS effectiveness metrics and trends
  • Gap analysis against ICH Q10 requirements
  • PQS suitability assessment documented in management review
  • Comparison against industry benchmarks
  • Process capability indices (Cpk/Ppk) trend summaries feeding PQS review
  • Third-party PQS maturity audit reports
Common nonconformities
  • PQS never assessed as a system (only individual processes reviewed)
  • No PQS effectiveness metrics defined
  • Assessment is superficial or check-the-box
  • PQS maturity score stagnant across consecutive review periods
  • No linkage between PQS assessment outcomes and improvement plans
  • Lifecycle stage changes not triggering PQS re-evaluation
Auditor tip

The PQS itself must be periodically assessed — not just product quality. This is a meta-review: Is the quality system working? Are processes effective? Are resources adequate? This feeds into Section 4 (PQS continual improvement).

2.6(c) Does management monitor and discuss external factors that could affect the PQS (new regulations, updated guidelines, emerging science, competitor recalls, supply-chain disruption)?
Objective evidence
  • External factors assessment in management review agenda
  • Regulatory intelligence reports
  • Industry guidance updates reviewed
  • Technology assessment and adoption roadmap
  • Competitor recall or industry quality event analysis
  • Pharmacopeial monograph change impact assessments
  • Supply chain risk monitoring reports for critical raw materials
Common nonconformities
  • Management review agenda does not include external factors
  • No regulatory intelligence monitoring process
  • Significant regulatory changes missed
  • ICH or WHO guideline revisions not assessed for site impact
  • No supply chain disruption contingency reviewed by management
  • Competitor product recalls in same therapeutic area not discussed
Auditor tip

Management must monitor and discuss external factors that could impact the PQS: new regulations, updated guidelines, emerging science, technological advances, competitor recalls, supply chain disruptions. A structured horizon-scanning process should feed into management review so that the organization can proactively adapt its PQS before external changes become compliance gaps.

2.6(d) Do the outputs of the four PQS elements (monitoring, CAPA, change management, management review) feed management review, with metrics like CAPA closure rates, change backlogs, and process-capability trends?
Objective evidence
  • CAPA metrics and trending in management review
  • Change management summary and backlog status
  • Process performance trending reports
  • Process monitoring KPI dashboards
  • Integration of all four PQS element outputs in review agenda
  • Deviation rate categorization summaries by root cause type
  • Annual product quality review conclusions feeding management review
Common nonconformities
  • Management review missing one or more PQS element outputs
  • CAPA metrics not tracked or presented
  • Change backlog growing without management awareness
  • Process performance trends not compared against validated acceptance criteria
  • Overdue CAPA items exceeding target closure dates without escalation
  • Deviation recurrence data absent from management review package
Auditor tip

The four PQS elements (monitoring, CAPA, change management, management review) must feed into management review. Key metrics: CAPA closure rates, change control backlogs, process capability trends, deviation rates.

2.7 For outsourced GMP activities, does the organization maintain robust qualification, monitoring, and oversight of its contract organizations - recognizing outsourcing does not transfer quality responsibility?
Objective evidence
  • Outsourced activities management SOP
  • Contract acceptor qualification records
  • Quality agreements with contract organizations
  • Supplier qualification and approval process
  • Contract acceptor audit reports
  • Performance monitoring metrics for outsourced activities
  • Incoming material testing/verification records
  • Supplier change notification agreements
  • Outsourcing risk assessments
Common nonconformities
  • No quality agreements with contract organizations
  • Contract acceptors not audited
  • No incoming material testing or verification
  • Outsourced activities not included in PQS scope
  • No performance monitoring of contract acceptors
  • Supplier change notifications not triggering impact assessment at contract giver
Auditor tip

Outsourcing does not absolve the pharmaceutical company of quality responsibility. Robust qualification, monitoring, and oversight of contract organizations (CMOs, CROs, testing labs) must be maintained. Purchased materials must be controlled through qualified suppliers.

2.7(a) Before outsourcing a GMP activity, is the contract acceptor qualified (on-site audit, capability assessment, regulatory-history review, documented approval), with re-qualification on a defined basis?
Objective evidence
  • Contract acceptor qualification procedure
  • Pre-qualification audit reports
  • Capability assessment documentation
  • Regulatory inspection history of contract acceptor
  • Approved supplier/contractor list
  • Re-qualification schedule and records
  • Risk-based classification of contract acceptors by GMP criticality
Common nonconformities
  • Outsourced activities started before qualification complete
  • No on-site audit of contract acceptors performing GMP activities
  • Qualification based solely on self-assessment questionnaire
  • No re-qualification process
  • Contract acceptor warning letters or consent decrees not reviewed before engagement
  • Qualification dossier lacks evaluation of analytical method transfer readiness
Auditor tip

Before outsourcing any GMP activity, the contract acceptor must be qualified. This includes on-site audits, capability assessment, regulatory history review, and documented approval. Re-qualification should occur periodically.

2.7(b) Are there quality agreements that clearly define who does what, how quality issues (deviations, changes, complaints) are communicated, and the escalation process?
Objective evidence
  • Quality agreements with defined responsibilities
  • Communication protocols for quality issues
  • Deviation notification requirements and timeframes
  • Change notification agreements
  • Complaint and recall coordination procedures
  • Regular quality review meetings with contractors
  • Joint investigation reports for shared root cause deviations
Common nonconformities
  • Quality agreement missing or incomplete
  • No defined process for deviation notification from contractor
  • Changes at contractor not communicated to contract giver
  • No regular quality review meetings
  • Out-of-specification results at CMO not reported within contractual timeframes
  • Annual product quality review data from contract acceptor not obtained
Auditor tip

Quality agreements must clearly define who does what, how quality issues are communicated, and what the escalation process is. This includes deviation notification, change notification, complaint handling, and recall coordination.

2.7(c) Is the contractor's ongoing performance monitored with KPIs (quality, timeliness, deviation rates, CAPA effectiveness), with action taken on poor performance - not relying on qualification alone?
Objective evidence
  • Contractor performance KPIs and scorecard
  • Periodic performance review records
  • Deviation rate trending for outsourced activities
  • CAPA effectiveness at contractor sites
  • Improvement action plans for underperforming contractors
  • De-qualification criteria and process
  • Comparative benchmarking across multiple contract sites for same service
Common nonconformities
  • No ongoing performance monitoring of contractors
  • Performance data collected but not acted upon
  • Same quality issues recurring at contractor without improvement
  • No defined criteria for contractor de-qualification
  • Batch rejection rate at contract site trending upward without corrective action
  • Contractor re-audit findings not tracked through to verified closure
Auditor tip

Ongoing performance monitoring is required — qualification alone is not sufficient. KPIs should track quality, timeliness, deviation rates, and CAPA effectiveness at the contractor. Poor performance must trigger improvement actions or de-qualification.

§3 Continual improvement of process performance and product quality 28 items · ~140 min
3.1 Does the PQS address all four lifecycle stages (development, technology transfer, commercial manufacturing, discontinuation), with the PQS elements focused appropriately for each stage?
Objective evidence
  • Product lifecycle management framework
  • Stage-specific quality plans
  • Technology transfer protocols
  • Product discontinuation procedures
  • Lifecycle risk assessments
  • Stage gate criteria for lifecycle transitions
  • Cross-functional lifecycle governance committee charter
Common nonconformities
  • No lifecycle approach to product quality
  • Technology transfer treated as one-time event
  • No product discontinuation planning
  • Same quality approach for all lifecycle stages
  • Post-approval lifecycle activities not linked to development knowledge
  • No formal stage gate reviews between lifecycle phases
Auditor tip

The PQS must address all four lifecycle stages. Goals for each stage inform what PQS elements (CAPA, change management, monitoring, review) need to focus on. Products at different lifecycle stages have different quality risks and knowledge levels.

3.1.1 Does development use Quality-by-Design principles where applicable, building the product and process understanding that forms the basis of the commercial control strategy?
Objective evidence
  • Pharmaceutical development reports (per ICH Q8)
  • Quality Target Product Profile (QTPP)
  • Critical Quality Attributes (CQA) identification
  • Design of Experiments (DoE) studies
  • Control strategy based on process understanding
  • Design space definition (where applicable)
  • Risk assessments during development
  • Development knowledge transfer documents
Common nonconformities
  • No systematic approach to development
  • CQAs not identified or justified
  • Control strategy not based on process understanding
  • Development knowledge not captured for transfer
  • No formal linkage between CQAs and process design decisions
  • Risk assessments from development not updated through clinical phases
Auditor tip

Development must use Quality by Design (QbD) principles where applicable. Product and process understanding gained during development forms the foundation for commercial manufacturing control strategy.

3.1.1(a) Are critical quality attributes identified through systematic scientific evaluation (with documented justification for what is and is not critical), and linked to the control strategy?
Objective evidence
  • CQA identification and justification documents
  • Risk assessment linking CQAs to patient impact
  • CQA criticality analysis (e.g., FMEA for quality attributes)
  • CQA list linked to specifications and control strategy
  • Periodic CQA review as knowledge grows
  • FMEA or risk ranking worksheets for quality attribute prioritization
  • Traceability matrix linking CQAs to clinical performance endpoints
Common nonconformities
  • CQAs not formally identified
  • No justification for CQA designation
  • CQAs identified but not linked to control strategy
  • CQA list never updated as process knowledge evolves
  • Criticality designations copied from predicate products without product-specific evaluation
  • No documented rationale for attributes excluded from CQA list
Auditor tip

CQAs must be identified through systematic scientific evaluation, not assumed. The justification for each CQA (and for attributes not designated as critical) should be documented. CQAs link directly to patient safety and efficacy.

3.1.1(b) Is there a control strategy that bridges development and manufacturing, defining how critical process parameters are controlled to ensure CQAs are met?
Objective evidence
  • Control strategy document linking CPPs to CQAs
  • Process parameter ranges and proven acceptable ranges
  • Design space definition (where applicable)
  • Control strategy review and updates as knowledge grows
  • Technology transfer of control strategy to manufacturing
  • Multivariate interaction studies supporting CPP range selection
  • Scale-up risk assessment for control strategy applicability
Common nonconformities
  • No documented control strategy
  • Control strategy not linked to CPP-CQA relationships
  • Control strategy not transferred to manufacturing
  • No updates to control strategy post-development
  • Proven acceptable ranges not supported by experimental data
  • Control strategy relies solely on end-product testing without in-process controls
Auditor tip

The control strategy must bridge development and manufacturing. It defines how CPPs are controlled to ensure CQAs are met. This is the primary deliverable of QbD that carries into commercial manufacturing.

3.1.2 Is technology transfer treated as comprehensive knowledge transfer verified by successful process execution at the receiving site, not just moving documents?
Objective evidence
  • Technology transfer protocols and reports
  • Transfer acceptance criteria
  • Knowledge package documentation
  • Receiving site process validation
  • Gap analysis between development and manufacturing
  • Comparability studies
  • Training records for receiving site
  • Transfer risk assessments
Common nonconformities
  • Technology transfer without formal protocol
  • No acceptance criteria for successful transfer
  • Knowledge gaps between development and manufacturing
  • Receiving site unable to reproduce development results
  • Critical process parameters not clearly identified in transfer package
  • No formal gap closure mechanism when receiving site identifies knowledge deficiencies
Auditor tip

Technology transfer is not just moving documents — it requires comprehensive knowledge transfer verified through successful process execution at the receiving site. The knowledge transferred should be sufficient to establish and maintain a state of control.

3.1.3 During commercial manufacturing, do all four PQS elements work together to maintain the state of control and drive improvement?
Objective evidence
  • Manufacturing SOPs and batch records
  • Process validation and continued process verification
  • Annual Product Review / Product Quality Review
  • Process monitoring data and trending
  • Deviation and CAPA trending
  • Change control records
  • Batch disposition records
  • Environmental monitoring data
  • Equipment qualification and calibration
Common nonconformities
  • No ongoing process monitoring after validation
  • No annual product review
  • Process improvements not implemented
  • Knowledge from manufacturing not captured
  • Continued process verification program absent or inactive
  • Batch disposition decisions not linked to in-process monitoring results
Auditor tip

Commercial manufacturing is where the PQS is most actively applied. All four PQS elements (CAPA, change management, process monitoring, management review) must work together to maintain quality during routine production.

3.1.3(a) Is a periodic product review (APR/PQR) performed covering all batches in the period - results, deviations, changes, stability, complaints, returns, recalls, OOS/OOT - and used to identify trends?
Objective evidence
  • APR/PQR procedure
  • Completed APR/PQR reports for each product
  • Batch data trending (yield, impurities, dissolution)
  • Process capability indices (Cpk, Ppk) in APR
  • Deviation and OOS trending in APR
  • Stability data review in APR
  • Complaint trending in APR
  • CAPA actions generated from APR findings
Common nonconformities
  • No APR/PQR performed
  • APR/PQR performed but no trending analysis
  • No CAPA actions from APR findings
  • Process capability declining without investigation
  • APR completed late (beyond regulatory timeframes)
  • Stability data omitted from annual review scope
Auditor tip

APR/PQR is a mandatory periodic review of all batches manufactured during the review period. It must cover: batch results, deviations, changes, stability data, complaints, returns, recalls, OOS/OOT results, and process capability. Trending must identify emerging issues.

3.1.3(b) Is continued process verification (Stage 3) performed using statistical tools to monitor parameters and quality attributes on an ongoing basis, complementing (not replacing) the APR?
Objective evidence
  • CPV program procedure
  • CPV protocols for each product/process
  • Statistical monitoring plans (SPC, trend analysis)
  • Control charts for CPPs and CQAs
  • CPV periodic reports with trend assessment
  • Trigger criteria for process revalidation
  • CPV-driven improvement actions
Common nonconformities
  • No CPV program after process validation
  • CPV exists but no statistical analysis
  • Control chart signals not investigated
  • Process monitoring stopped after initial validation
  • No documented trigger criteria for revalidation based on CPV signals
  • Intra-batch variability not captured in monitoring plan
Auditor tip

CPV is Stage 3 of the FDA process validation lifecycle. It must use statistical tools to monitor process parameters and quality attributes on an ongoing basis. CPV complements but does not replace APR/PQR.

3.1.4 Is product discontinuation planned and managed, with post-cessation obligations (stability monitoring, complaint handling, regulatory reporting, record retention) maintained?
Objective evidence
  • Product discontinuation procedure
  • Product discontinuation plan (product-specific)
  • Retained sample management post-discontinuation
  • Stability monitoring continuation plan
  • Complaint handling continuation plan
  • Regulatory notification records
  • Document retention schedule compliance
Common nonconformities
  • No product discontinuation procedure
  • Stability monitoring stopped prematurely
  • Retained samples destroyed before retention period
  • No plan for ongoing complaint handling
  • Supply chain notification to downstream customers not documented
  • Recall-readiness plan not maintained through discontinuation
Auditor tip

Product discontinuation must be planned and managed. Key obligations continue after manufacturing ceases: stability monitoring, complaint handling, regulatory reporting, and document retention must continue for the required retention periods.

3.2 Do the four PQS elements (process monitoring, CAPA, change management, management review) operate as an integrated system where each feeds the others, rather than as isolated processes?
Objective evidence
  • PQS description showing four elements and their interactions
  • Process interaction diagrams
  • Data flow between PQS elements
  • Integrated quality metrics covering all four elements
  • Documented escalation pathways from monitoring to CAPA to change control
  • Procedure describing how management review outputs feed back into PQS elements
  • Cross-element performance dashboard or summary report
Common nonconformities
  • PQS elements operate in silos
  • No integration between monitoring, CAPA, change, and review
  • Missing one or more PQS elements entirely
  • CAPA outputs not feeding into change management system
  • Management review does not reference process monitoring data
  • No documented linkage between monitoring signals and CAPA initiation criteria
Auditor tip

The four PQS elements are the operational backbone of ICH Q10. They must work as an integrated system, not as isolated processes. Output from one element feeds into others (e.g., monitoring triggers CAPA, CAPA drives change management, all reviewed in management review).

3.2.1 Is there an ongoing process and product monitoring system using appropriate statistical tools (SPC, PAT), a risk-based strategy, and feedback/feedforward loops?
Objective evidence
  • Process monitoring SOPs
  • Statistical process control (SPC) charts and programs
  • Process Analytical Technology (PAT) implementation
  • Continued Process Verification (CPV) protocols
  • Product quality trending reports
  • Control charts with alert and action limits
  • Environmental monitoring trending
  • Stability trending data
  • Process capability indices (Cpk)
  • Feedback/feedforward process adjustments
Common nonconformities
  • No ongoing process monitoring program
  • SPC charts maintained but not reviewed or acted upon
  • Alert limits breached without investigation
  • No risk-based approach to monitoring frequency
  • Monitoring data not trended or analyzed
  • Environmental monitoring excursions not escalated per defined criteria
Auditor tip

This is the ongoing vigilance system for process and product quality. It combines statistical tools (SPC, PAT), risk-based monitoring strategies, and feedback/feedforward loops. Monitoring should be proactive, not just reactive detection of failures.

3.2.1(a) Is the monitoring strategy risk-informed, with higher-risk parameters monitored more tightly and the choice of what and how often justified by risk assessment?
Objective evidence
  • Risk assessment driving monitoring strategy
  • Monitoring parameters justified by risk analysis
  • Alert and action limits with risk-based rationale
  • Monitoring frequency justified by risk level
  • Periodic review of monitoring strategy adequacy
  • FMEA or hazard analysis used to prioritize monitored parameters
  • Documented acceptance criteria for alert and action limit derivation
Common nonconformities
  • Monitoring parameters chosen arbitrarily, not risk-based
  • No alert/action limits defined
  • Same monitoring frequency for all parameters regardless of risk
  • Risk assessment for monitoring strategy not updated after process changes
  • Critical process parameters excluded from routine monitoring without justification
  • Alert limits set at specification limits rather than tighter process capability boundaries
Auditor tip

Monitoring strategy must be risk-informed. High-risk parameters need tighter monitoring frequency and limits. Risk assessments should justify what is monitored, how often, and what constitutes an alert vs. action.

3.2.1(b) Are appropriate statistical or analytical tools (SPC charts, PAT, trending) actually deployed and analyzed, not just raw data collected without interpretation?
Objective evidence
  • SPC program with control charts for key parameters
  • PAT implementation where applicable
  • Statistical trending analysis reports
  • Training records for SPC/PAT practitioners
  • Tool selection rationale based on process characteristics
  • Capability study reports (Cpk/Ppk calculations) for monitored parameters
  • Out-of-trend investigation records triggered by SPC rule violations
Common nonconformities
  • Data collected but no statistical analysis performed
  • SPC charts generated but not reviewed or acted upon
  • No appropriate monitoring tools for critical processes
  • Western Electric or Nelson rules not applied to control charts
  • PAT instruments not calibrated or qualified per established schedule
  • Statistical methods applied without verification of underlying data distribution assumptions
Auditor tip

Appropriate statistical or analytical tools must be deployed. SPC charts, PAT instruments, and trending analysis should be used based on the nature of the process. Raw data collection without statistical analysis is insufficient.

3.2.1(c) Does process monitoring close the loop - triggering corrective (feedback) and predictive (feedforward) adjustments - acting on trends before they become out-of-specification?
Objective evidence
  • Feedback loops documented for key process parameters
  • Feedforward controls based on incoming material attributes
  • Proactive process adjustment procedures
  • Examples of trend-based corrective actions taken before failure
  • Process adjustment records linked to monitoring data
  • Feedforward adjustment criteria based on raw material lot variability
  • Documented decision trees for operator-initiated process corrections
Common nonconformities
  • Monitoring is passive — data collected but no feedback mechanism
  • No proactive response to trends approaching limits
  • Feedback loops exist only for automated systems, not manual processes
  • Incoming material variability not used for feedforward parameter adjustment
  • Process adjustments made ad hoc without documented criteria
  • No evidence of trend-based interventions preventing OOS results
Auditor tip

Process monitoring must close the loop: monitoring data should trigger corrective adjustments (feedback) and predictive adjustments (feedforward). Proactive means acting on trends before out-of-specification occurs.

3.2.2 Is the CAPA system fed by multiple data sources (not just deviations), driven by genuine root-cause analysis, risk-proportionate, and closed with effectiveness verification?
Objective evidence
  • CAPA SOP
  • CAPA records with root cause analysis
  • Root cause analysis tools (5-Why, fishbone, fault tree)
  • CAPA effectiveness checks
  • CAPA trending and metrics
  • Sources of CAPA input (complaints, deviations, audits, etc.)
  • Risk-based categorization of CAPA events
  • CAPA timeliness metrics
  • Cross-product/process impact assessments
  • CAPA closure documentation
Common nonconformities
  • Root cause analysis superficial (e.g., always 'human error')
  • No effectiveness checks performed
  • CAPA backlog growing without resolution
  • Same root causes recurring
  • CAPA not triggered by audit or inspection findings
  • No trending of CAPA data
Auditor tip

The CAPA system is the engine of improvement. It must be fed by multiple sources (not just deviations), use root cause analysis, and include effectiveness verification. CAPAs should be risk-proportionate — not every event needs a full investigation.

3.2.2(a) Do all quality data sources feed the CAPA system, with trending across sources used to surface systemic issues that individual events do not reveal?
Objective evidence
  • CAPA source categories defined in procedure
  • Evidence of CAPAs initiated from each source type
  • Trending analysis across multiple CAPA sources
  • Audit/inspection findings converted to CAPAs
  • Complaint-driven CAPAs
  • Process monitoring trend-driven CAPAs
  • Management review action items escalated to CAPA when systemic
Common nonconformities
  • CAPAs only triggered by deviations, other sources ignored
  • Audit findings not tracked through CAPA system
  • No trend-driven CAPAs (only reactive)
  • Complaints handled outside CAPA system
  • Stability OOT signals not escalated to CAPA evaluation
  • Process monitoring trend excursions not linked to CAPA initiation
Auditor tip

CAPA must not be limited to deviations alone. All quality data sources must feed into the CAPA system. Trending of multiple data sources should identify systemic issues that individual events do not reveal.

3.2.2(b) Does root-cause analysis use structured tools (5-Why, fishbone, fault tree) rather than narrative, and avoid stopping at 'human error' without finding the systemic cause?
Objective evidence
  • Root cause analysis tools defined in CAPA procedure
  • Completed root cause analyses using structured tools
  • Training records for investigation personnel on RCA tools
  • Evidence of going beyond 'human error' to systemic causes
  • Investigation reports with tool selection rationale
  • Causal factor charting or barrier analysis records
  • Investigation timeliness tracking against SOP-defined deadlines
Common nonconformities
  • Root cause listed as 'human error' without further analysis
  • No structured RCA tools used
  • Investigations superficial or incomplete
  • Same root causes recurring (indicating ineffective RCA)
  • Investigation timelines repeatedly exceed procedure-defined targets
  • No evaluation of contributing factors beyond the immediate root cause
Auditor tip

Root cause analysis must use structured tools (5-Why, fishbone/Ishikawa, fault tree analysis, etc.), not just narrative descriptions. 'Human error' as a root cause is almost always insufficient — the investigation should identify why the human error occurred (system, training, design).

3.2.2(c) Is investigation depth driven by risk categorization - critical events getting formal root-cause analysis, low-risk events a proportionate response?
Objective evidence
  • CAPA risk categorization procedure
  • Evidence of risk-based investigation depth
  • Critical events with comprehensive investigations
  • Low-risk events with proportionate assessments
  • Risk categorization criteria documented
  • Investigation template tiers aligned to risk category
  • Documented examples of abbreviated assessments for low-risk events
Common nonconformities
  • Same investigation depth for all events regardless of risk
  • High-risk events with shallow investigations
  • No risk categorization for CAPA events
  • Low-risk events subjected to full investigation causing resource diversion
  • Risk categorization performed after investigation instead of before
  • No documented criteria distinguishing investigation tiers
Auditor tip

Not every CAPA needs a full-scale investigation. Risk categorization should drive investigation depth: critical events need formal root cause analysis with full documentation, while low-risk events may need only basic assessment. The categorization system must be documented.

3.2.2(d) Does every investigation assess whether the root cause could affect other products, processes, or sites, to prevent the same failure recurring elsewhere?
Objective evidence
  • Cross-product/process impact assessment in CAPA records
  • Horizontal deployment of corrective actions
  • Impact assessment procedure for multi-product applicability
  • Evidence of actions extended to other affected products/sites
  • Cross-site applicability assessment for multi-plant operations
  • Shared-equipment or shared-material impact evaluation records
  • Horizontal deployment tracking log with completion dates
Common nonconformities
  • Impact assessment limited to the specific product/process involved
  • No horizontal deployment of corrective actions
  • Recurring same-root-cause events across different products
  • Multi-site operations with no cross-site CAPA communication protocol
  • Shared raw material or excipient suppliers not evaluated during impact assessment
  • Contract manufacturing sites excluded from cross-product reviews
Auditor tip

Every investigation must assess whether the root cause could affect other products, processes, or sites. This is critical for preventing the same failure mode from occurring elsewhere in the organization.

3.2.2(e) Does every CAPA include a planned effectiveness check performed after enough time/data, verifying the action worked and introduced no unintended consequences?
Objective evidence
  • Effectiveness check criteria defined at CAPA initiation
  • Completed effectiveness verification records
  • Timeframe for effectiveness check documented
  • Evidence that unintended consequences were assessed
  • Failed effectiveness checks leading to revised CAPAs
  • Statistical before-and-after comparison data for key metrics
  • Documented timeframe rationale for when effectiveness check is due
Common nonconformities
  • No effectiveness checks performed
  • Effectiveness checks are rubber-stamp approvals
  • Same issue recurs after CAPA closure (indicating ineffective CAPA)
  • No assessment for unintended consequences
  • Effectiveness check performed immediately after implementation without allowing sufficient data accumulation
  • No re-opened CAPA records despite known recurring issues
Auditor tip

Every CAPA must include a planned effectiveness check. The check must occur after sufficient time/data to evaluate whether the action worked. It must also verify no unintended consequences were introduced.

3.2.3 Is change management structured and risk-based, with cross-functional review and a post-implementation review, covering changes from CAPA, improvement, innovation, or regulation?
Objective evidence
  • Change management/change control SOP
  • Change request forms and approvals
  • Impact assessments (quality, regulatory, process)
  • Risk assessments for proposed changes
  • Expert review documentation
  • Post-implementation review records
  • Regulatory assessment of changes (variation classification)
  • Change effectiveness evaluation
  • Change trending reports
  • Change categorization (minor/major/critical)
Common nonconformities
  • Changes implemented without formal approval
  • No risk assessment for changes
  • Post-implementation reviews not conducted
  • Regulatory impact not assessed
  • Change backlog growing without resolution
  • No categorization of changes by risk
Auditor tip

Change management must be structured, risk-based, and include post-implementation review. Changes can be driven by CAPA, process improvement, innovation, or regulatory requirements. All changes must be evaluated for regulatory impact (marketing authorisation).

3.2.3(a) Is every proposed change risk-assessed before approval (impact on quality, validated state, stability, supply chain), with higher-risk changes getting deeper evaluation?
Objective evidence
  • Risk assessment procedure for change evaluation
  • Completed risk assessments for proposed changes
  • Risk-based change categorization (minor/major/critical)
  • Evidence of risk assessment informing change decision
  • Risk mitigation plans for high-risk changes
  • Change risk scoring matrix linking severity and likelihood
  • Escalation thresholds defining which changes require senior management approval
Common nonconformities
  • Changes approved without risk assessment
  • Risk assessment is pro-forma with no real evaluation
  • No risk-based categorization of changes
  • High-risk changes approved at same authority level as minor changes
  • Risk assessment does not consider impact on validated state
  • No stability assessment required for formulation or process changes
Auditor tip

Every proposed change must be risk-assessed before approval. The risk assessment should evaluate impact on product quality, validated state, stability, and supply chain. Higher-risk changes need more rigorous evaluation and controls.

3.2.3(b) Is every change evaluated for regulatory impact (variation/supplement, annual-report notification, or no filing), documented, and involving regulatory expertise?
Objective evidence
  • Regulatory impact assessment in change records
  • Variation classification (Type IA, IB, II or US equivalent)
  • Regulatory affairs review of proposed changes
  • Filing decisions documented with rationale
  • Post-approval change management protocol (PACMP) where applicable
  • Comparability protocol outcomes for post-approval analytical method changes
  • Regulatory submission tracking log linked to change control records
Common nonconformities
  • Changes implemented without regulatory impact assessment
  • Regulatory affairs not consulted on process changes
  • Changes requiring filings made without submissions
  • Variation classification not documented or inconsistent across similar changes
  • No tracking of pending regulatory submissions tied to implemented changes
  • Annual report or periodic safety update obligations missed for process changes
Auditor tip

Every change must be evaluated for regulatory impact: does it require a variation/supplement, annual report notification, or no filing? This assessment must be documented and should involve regulatory affairs.

3.2.3(c) Is change review cross-functional - QA, production, engineering, regulatory, validation, stability - rather than limited to the initiating department?
Objective evidence
  • Cross-functional change review board or team
  • Expert review signatures on change records
  • Meeting minutes from change review discussions
  • Discipline-specific impact assessments
  • Expert reviewer qualifications documented
  • Validation and stability SME sign-off records for process changes
  • Escalation criteria for engaging external subject matter experts
Common nonconformities
  • Changes reviewed only by initiating department
  • No cross-functional review process
  • Expert reviewers lack relevant qualifications
  • Validation team not included in review of process parameter changes
  • Stability function not consulted on packaging or storage condition changes
  • No documented criteria for which disciplines must review each change category
Auditor tip

Change review must be cross-functional, not limited to the initiating department. Relevant experts (QA, production, engineering, regulatory, validation, stability) must evaluate each change within their domain.

3.2.3(d) After implementation, is there a post-implementation review confirming the change met its objectives and introduced no unintended consequences, using data over an adequate period?
Objective evidence
  • Post-implementation review procedure
  • Completed post-implementation review records
  • Data analysis comparing pre- and post-change performance
  • Confirmation that change objectives were met
  • Assessment of unintended consequences
  • Number of batches or time period for review defined
  • Stability data comparison before and after the implemented change
Common nonconformities
  • No post-implementation reviews conducted
  • Reviews conducted but no data analysis
  • Unintended consequences not assessed
  • Changes closed without confirming objectives met
  • Minimum batch count for post-implementation evaluation not defined in procedure
  • Post-implementation review delayed beyond defined timeframe without justification
Auditor tip

After a change is implemented, a post-implementation review must verify that it achieved its objectives and did not introduce unintended consequences. The review should include data analysis over an appropriate number of batches or time period.

3.2.4 Is there a management review specific to process performance and product quality (complementing Section 2.6) with defined KPIs and metrics?
Objective evidence
  • Management review procedure specific to PQS
  • Management review meeting minutes and records
  • PQS performance KPIs and dashboards
  • Quality metrics reports (complaints, recalls, deviations, CAPA)
  • Process performance trending presented to management
  • Product quality trending presented to management
  • Regulatory inspection history and status
  • Action items from management review with follow-up
  • Management review schedule and attendance records
Common nonconformities
  • Management reviews skipped or delayed
  • KPIs not defined or not measured
  • No action items generated
  • Same issues discussed repeatedly without resolution
  • Management review does not cover all PQS elements
  • Action items from prior reviews not tracked to closure
Auditor tip

This is the detailed management review requirement specific to process performance and product quality (complementing the broader Section 2.6 management review). It requires specific KPIs and metrics covering all PQS elements to be reviewed by management.

3.2.4(a) Does this management review formally assess whether the quality objectives (from 2.3) have been met, using measurable targets and actual performance?
Objective evidence
  • Quality objectives scorecard in management review
  • Target vs. actual performance for each objective
  • Trend of objective achievement over time
  • Action plans for objectives not met
  • Revised objectives based on review outcomes
  • Site-level and corporate-level objective alignment evidence
  • Documented escalation when objectives are missed for consecutive periods
Common nonconformities
  • Quality objectives not measured or tracked
  • No target vs. actual comparison
  • Objectives always met (targets too easy)
  • Objectives never met (targets unrealistic, no action taken)
  • Objectives not cascaded from corporate quality policy to site-level metrics
  • No management action plans documented when objectives are missed
Auditor tip

The management review must include a formal assessment of whether quality objectives (set per Section 2.3) have been met. This requires measurable objectives with defined targets and actual performance data.

3.2.4(b) Is a defined set of KPIs tracked and presented (complaints, recalls, deviation rates, CAPA metrics, process capability), covering the breadth of the PQS?
Objective evidence
  • Defined KPI set for PQS effectiveness
  • KPI dashboard or report for management review
  • Complaint rate and trending
  • Deviation rate and categorization trending
  • CAPA metrics (open, overdue, closure rate, effectiveness rate)
  • Change control metrics (backlog, approval time)
  • Product quality trending (batch pass rate, Cpk, stability)
  • Regulatory inspection status and finding trends
Common nonconformities
  • No defined KPIs for PQS
  • KPIs collected but not trended or analyzed
  • Management review without quantitative performance data
  • KPIs all showing positive when quality issues persist
  • Recall and field alert metrics absent from management review package
  • No benchmarking of KPIs against industry or internal site comparisons
Auditor tip

A defined set of KPIs must be tracked and presented at management review. These should cover all aspects of the PQS: complaints (rate, trending), recalls, deviation rates, CAPA metrics (open, overdue, effectiveness), change control metrics, product quality trends, and regulatory status.

§4 Continual improvement of the pharmaceutical quality system 13 items · ~65 min
4 Does the organization improve the PQS itself - not just products and processes - using inputs from management review, internal/external factors, and the Section 3 elements?
Objective evidence
  • PQS self-assessment or maturity assessment
  • PQS improvement plan
  • Internal and external benchmarking results
  • Quality culture assessments
  • PQS improvement project tracking
  • PQS metrics trending (efficiency, effectiveness)
  • Lessons learned from regulatory inspections applied to PQS
  • Technology adoption for PQS improvement (e.g., eQMS)
  • Communication records of PQS improvements
  • PQS review meeting records
Common nonconformities
  • PQS itself never reviewed for improvement
  • Same quality system issues recurring year after year
  • No benchmarking against industry standards
  • Quality system improvements not tracked
  • Management review does not include PQS effectiveness
  • No quality culture assessment
Auditor tip

Section 4 closes the loop: the PQS must improve itself, not just products and processes. This meta-level improvement uses inputs from management review, internal/external factors, and outputs from Section 3 PQS elements to identify ways to make the quality system more effective. Key distinction from Section 3: Section 3 improves products/processes; Section 4 improves the quality system that manages those products/processes.

4.1 Is there a PQS-level management review (distinct from the product/process review) where management asks whether the quality system itself is working and whether structural changes are needed?
Objective evidence
  • PQS management review procedure (distinct from product quality review)
  • PQS management review meeting records
  • PQS suitability and effectiveness assessment
  • Improvement opportunities identified and prioritized
  • Changes to quality policy or objectives proposed
  • Action items with owners and deadlines
  • PQS maturity scorecard reviewed by senior leadership
  • Cross-functional attendance roster for PQS governance sessions
  • Trend charts comparing PQS KPIs across review periods
Common nonconformities
  • No PQS-level management review conducted (only product quality reviewed)
  • PQS review conflated with routine product quality review
  • Review conducted but no improvement actions generated
  • Same PQS weaknesses identified year after year without resolution
  • Senior management absent from PQS governance meetings
  • PQS review agenda lacks suitability or adequacy assessment criteria
Auditor tip

This is a PQS-level management review, distinct from the product/process review in Section 2.6/3.2.4. Here, management asks: 'Is our quality system itself working? Do we need structural changes?' This review evaluates the quality system architecture, not product quality metrics.

4.1(a) Are inspection and audit findings analyzed for what they reveal about PQS weaknesses (patterns indicating systemic gaps), not just closed as individual CAPAs?
Objective evidence
  • Audit finding trend analysis in PQS review
  • Regulatory inspection outcomes summarized for PQS impact
  • Systemic issues identified from multiple audit findings
  • PQS improvement actions derived from audit patterns
  • Cross-site audit comparison matrix highlighting common deficiencies
  • Third-party certification body observation summaries
  • Pareto chart of recurring audit nonconformity categories
Common nonconformities
  • Audit findings addressed individually but patterns not analyzed
  • Inspection results not fed into PQS review
  • No trending of audit observations across multiple review cycles
  • Third-party audit reports filed but never discussed in management review
  • Repeat regulatory citations for the same PQS element
  • Audit corrective actions limited to local fixes without systemic root cause investigation
Auditor tip

Inspection and audit findings should be analyzed not just for individual CAPAs but for what they reveal about PQS weaknesses. Patterns in audit findings indicate systemic PQS gaps. A mature pharmaceutical organization performs cross-site and multi-cycle trending of audit observations to identify recurring themes — such as persistent document control deficiencies or training gaps — that point to structural PQS shortcomings rather than isolated incidents.

4.1(b) Are complaint trends analyzed for what they reveal about PQS effectiveness, with rising rates or new categories treated as signals of structural gaps?
Objective evidence
  • Complaint trend analysis in PQS review
  • Complaint root cause categories linked to PQS elements
  • PQS improvement actions from complaint analysis
  • Comparison of complaint rates to industry benchmarks
  • Heat map of complaint categories by product family and site
  • Complaint recurrence rate tracker per PQS element
  • Correlation analysis between complaint spikes and manufacturing changes
Common nonconformities
  • Complaints handled individually but not analyzed for PQS implications
  • Rising complaint trends without PQS-level response
  • Complaint root cause analysis limited to proximate cause without systemic review
  • No linkage between complaint categories and PQS process owners
  • Absence of complaint benchmarking against pharmacopeial or industry norms
  • Customer feedback loops closed at site level without escalation to PQS governance
Auditor tip

Complaint trends should be analyzed for what they reveal about PQS effectiveness. Rising complaint rates or new complaint categories may indicate PQS gaps that need structural changes. The analysis should go beyond individual CAPA resolution to identify whether clusters of complaints point to deficiencies in change control, supplier qualification, or process validation elements of the PQS. Benchmarking complaint rates against industry peers provides an external reference for PQS adequacy.

4.1(c) Does process-performance data inform PQS design - e.g. if change control is too slow or the CAPA backlog is growing, are those treated as PQS improvement opportunities?
Objective evidence
  • PQS process performance metrics in management review
  • CAPA system effectiveness metrics (closure time, recurrence rate)
  • Change control timeliness metrics
  • Process monitoring system effectiveness assessment
  • PQS improvements derived from process performance data
  • Batch disposition cycle-time trending across quarters
  • Deviation recurrence rate stratified by root cause category
Common nonconformities
  • No PQS process performance metrics tracked
  • Process performance data not linked to PQS improvement
  • CAPA backlog growing without management escalation or resource reallocation
  • Change control cycle times exceeding internal targets with no corrective action
  • Deviation trending performed but results never presented at PQS management review
  • Process capability indices declining without triggering PQS reassessment
Auditor tip

Process performance data should inform PQS design. If monitoring reveals that certain PQS processes are not effective (e.g., change control too slow, CAPA backlog growing), these are PQS improvement opportunities. Metrics such as deviation recurrence rates, CAPA closure timelines, batch rejection trending, and process capability indices should be reviewed collectively to assess whether the PQS elements governing these processes need structural redesign or additional resources.

4.1(d) Are changes to the organization, technology, or regulatory landscape used as inputs to adapt the PQS so it stays fit for purpose?
Objective evidence
  • Organizational change impact assessment on PQS
  • New technology adoption impact on PQS processes
  • Regulatory developments assessed for PQS impact
  • PQS adaptation plans for significant changes
  • Site transfer or consolidation PQS readiness evaluation
  • Contract manufacturing organization onboarding impact analysis
  • Post-merger quality system harmonization roadmap
Common nonconformities
  • Major organizational changes without PQS impact assessment
  • New technologies adopted without PQS process updates
  • Regulatory landscape shifts not reflected in quality policy revisions
  • New manufacturing site commissioned without PQS gap analysis
  • Mergers or acquisitions completed with no quality system integration plan
  • Digital transformation initiatives bypassing established change control procedures
Auditor tip

Changes to the organization, technology, or regulatory landscape may require PQS adaptation. This input ensures the PQS remains fit-for-purpose as the environment evolves. Examples include site transfers that introduce new regulatory jurisdictions, adoption of continuous manufacturing or PAT that outpaces existing validation frameworks, mergers that create competing quality systems, and evolving ICH or regional guidance that redefines expectations for process validation or data integrity.

4.1(e) Does each PQS review start by reviewing actions from the previous review, tracking open actions to closure and escalating recurring items?
Objective evidence
  • Action item tracking from prior management reviews
  • Status updates on open improvement actions
  • Effectiveness assessment of completed actions
  • Escalation of overdue actions
  • Closure rate dashboard showing on-time versus late completions
  • Root cause analysis for chronically overdue improvement items
  • Revised target dates with documented justification for extensions
Common nonconformities
  • No follow-up on prior review actions
  • Same actions open across multiple review cycles
  • Completed actions not verified for effectiveness
  • Overdue improvement items lacking documented escalation to senior management
  • Action closure based solely on deliverable submission without outcome verification
  • Prior review minutes missing from subsequent management review agenda packs
Auditor tip

Each PQS management review must start with a review of actions from the previous review. Open actions must be tracked to closure. Recurring open items indicate governance failure. Effectiveness checks should confirm that the improvement achieved its intended outcome — for example, reduced deviation recurrence or shorter CAPA cycle times — rather than merely verifying that a deliverable was produced.

4.2 Does the organization systematically scan internal and external factors that could require PQS changes, assessing and responding to them?
Objective evidence
  • Internal factor monitoring process
  • External factor monitoring process (regulatory intelligence)
  • Environmental scanning reports
  • Factor assessment and response records
  • Industry event monitoring (competitor recalls, FDA warning letters)
  • Technology and innovation monitoring
  • Cross-functional risk committee meeting minutes addressing emerging factors
Common nonconformities
  • No systematic monitoring of internal or external factors
  • Significant regulatory changes missed
  • Industry quality events not monitored or assessed
  • Reactive-only approach to environmental changes
  • Horizon scanning limited to a single regulatory market
  • No designated owner for external factor surveillance
Auditor tip

Environmental scanning is required for both internal and external factors. The organization must have systematic processes to identify, assess, and respond to factors that could require PQS changes. This is about organizational awareness and agility.

4.2(a) Are internal factors that signal PQS stress (new product introductions, organizational changes, failed batches) tracked as triggers for PQS change?
Objective evidence
  • Internal factor tracking log or dashboard
  • New product introduction impact on PQS assessed
  • Failed batch trending linked to PQS assessment
  • Organizational change impact on quality documented
  • Self-inspection program feeding PQS improvements
  • Workforce turnover analysis correlated with quality metric shifts
  • Capital equipment qualification backlog report reviewed in PQS context
Common nonconformities
  • Internal events not systematically tracked
  • New product launches without PQS impact assessment
  • Organizational restructuring without quality impact review
  • High employee turnover in quality-critical roles without succession planning
  • Failed batch root causes not aggregated for systemic PQS trending
  • Self-inspection findings recorded but never escalated to PQS management review
Auditor tip

Internal factors that signal PQS stress or need for change must be tracked. New product introductions stress existing processes, organizational changes can disrupt quality culture, and failed batches may indicate systemic PQS weaknesses.

4.2(b) Is regulatory intelligence maintained - new regulations, revised ICH/FDA/EMA guidelines, competitor recalls and warning letters - and assessed for PQS impact?
Objective evidence
  • Regulatory intelligence monitoring procedure
  • Regulatory change assessment records
  • Industry event monitoring (FDA warning letters, recalls)
  • Technology assessment and adoption roadmap
  • Supply chain risk monitoring
  • ICH guideline update tracking
  • Pharmacopeial monograph revision impact assessments
Common nonconformities
  • No regulatory intelligence process
  • Significant external changes missed (new ICH guidelines, regulatory changes)
  • Competitor quality events not monitored
  • Technology advances not evaluated for PQS applicability
  • Supply chain disruption events not formally assessed for PQS risk
  • Evolving data integrity expectations from health authorities not incorporated into PQS
Auditor tip

Regulatory intelligence is critical: new regulations, revised guidelines (ICH, FDA, EMA), and industry events (competitor recalls, warning letters) must be systematically monitored and assessed for PQS impact.

4.3 Do PQS reviews produce specific, assigned, tracked, and communicated outcomes, rather than vague conclusions or reviews with no action items?
Objective evidence
  • Documented improvement actions from PQS management review
  • Resource allocation decisions documented
  • Quality policy or objective revisions
  • Action item log with owners and deadlines
  • Communication records of review outcomes
  • Tracking of action completion rates
  • Budget approval records for PQS improvement initiatives
Common nonconformities
  • Management review produces no action items
  • Actions identified but not assigned or tracked
  • Review outcomes not communicated to organization
  • Resource requests from PQS review consistently denied
  • Quality policy unchanged for multiple years despite evolving regulatory landscape
  • Improvement proposals documented but lacking prioritization or sponsorship
Auditor tip

PQS reviews must produce actionable outcomes. Vague conclusions or reviews without action items indicate a governance failure. Outcomes must be specific, assigned, tracked, and communicated. Tangible outputs include revised quality objectives with measurable targets, reallocation of budget or headcount to under-resourced PQS elements, updated quality policy language reflecting strategic direction changes, and formal communication cascades that reach shop-floor personnel.

4.3(a) Does every PQS improvement action have an owner, deadline, and effectiveness-verification plan, with overdue actions escalated?
Objective evidence
  • Action tracking system with owners and deadlines
  • Action completion rate metrics
  • Overdue action escalation records
  • Effectiveness verification of completed improvements
  • Action aging reports
  • Risk-ranked prioritization matrix for open improvement items
  • Quarterly executive summary of PQS improvement portfolio status
Common nonconformities
  • No tracking system for improvement actions
  • Actions without owners or deadlines
  • Chronic overdue actions without escalation
  • Completed actions not verified for effectiveness
  • Effectiveness criteria not defined at action initiation
  • Improvement portfolio lacking risk-based prioritization
Auditor tip

Every PQS improvement action must have an owner, deadline, and effectiveness verification plan. Open action aging should be monitored. Overdue actions must be escalated. Effectiveness verification should use predefined success criteria — for example, a measurable reduction in deviation recurrence or improved on-time CAPA closure rates — rather than simply confirming that a document was produced or a training was delivered.

4.3(b) Are PQS improvements communicated to the organization - so personnel understand what changed, why, and how it affects their work - not just minuted?
Objective evidence
  • Communication plan for PQS improvements
  • Records of improvement communications (emails, meetings, bulletins)
  • Training on PQS changes where applicable
  • Feedback mechanisms for communication effectiveness
  • Evidence that communication reached all affected levels
  • Town hall or all-hands presentation slides covering PQS review outcomes
  • Read-and-understood acknowledgment records for revised quality procedures
Common nonconformities
  • PQS improvements not communicated beyond quality department
  • Communication delayed or after-the-fact
  • No evidence that affected personnel are aware of changes
  • Communication limited to email distribution without confirmation of receipt
  • Shop-floor operators unaware of PQS changes that affect their daily procedures
  • No feedback channel for employees to raise questions about PQS changes
Auditor tip

PQS improvements must be communicated to the organization — not just documented in review minutes. Personnel need to understand what changed, why, and how it affects their work. Communication should reach all affected levels.

Each item shows its evidence, common nonconformities and auditor tips. The PDF holds the same content, formatted for a clipboard.

Frequently Asked Questions

What is ICH Q10?

ICH Q10 is the ICH harmonised guideline describing a comprehensive model for a Pharmaceutical Quality System (PQS) across the entire product lifecycle. It builds on ISO quality-management concepts, regional GMP, and ICH Q8 (Pharmaceutical Development) and Q9 (Quality Risk Management), and applies to the development, technology transfer, commercial manufacture, and discontinuation of drug substances and drug products, including biotechnology products.

Is ICH Q10 mandatory?

ICH Q10 is a guideline rather than a standalone binding regulation, but it has been adopted by the major regulators (FDA, EMA, PMDA and others) and is effectively expected. Much of its content overlaps with GMP requirements that are legally binding, and inspectors assess a company's quality system against the Q10 model. In practice, a PQS that does not meet Q10's expectations will struggle in inspection.

What are the four elements of the ICH Q10 PQS?

The four PQS elements are: (1) a process performance and product quality monitoring system, (2) a corrective action and preventive action (CAPA) system, (3) a change management system, and (4) management review of process performance and product quality. ICH Q10 expects each element to operate across all four lifecycle stages, not only during commercial manufacturing.

How does ICH Q10 relate to ICH Q8 and Q9?

Q8 (Pharmaceutical Development), Q9 (Quality Risk Management) and Q10 (PQS) are designed to work together. Q8 provides product and process understanding, Q9 provides the risk-based decision framework, and Q10 provides the quality system that uses both. Auditors look for evidence that risk management and product knowledge actually feed the Q10 systems — for example risk-based change control and a working knowledge-management approach — rather than existing as separate paperwork exercises.

What does an ICH Q10 audit focus on?

A PQS audit examines whether senior management ownership of quality is genuine (quality policy and objectives, resources, and an effective management review), whether the four PQS elements operate and connect to each other, whether quality risk management and knowledge management are used as enablers throughout the lifecycle, and whether the system actually drives continual improvement rather than just documenting events after the fact.
Aligntra also runs this kind of documentation review automatically — see how it works.