Quality · Quality system

Quality risk management (QRM)

Quality risk management is the systematic process for assessing, controlling, communicating and reviewing risks to product quality across the lifecycle — set out in ICH Q9 and reproduced in EU GMP Part III.

In one line

Quality risk management is the systematic process for assessing, controlling, communicating and reviewing risks to product quality across the lifecycle — set out in ICH Q9 and reproduced in EU GMP Part III.

Plain-English explanation, then the primary regulation it comes from.

Explanation

Understanding quality risk management (qrm)

ICH Q9 rests on two principles: risk evaluation should be based on scientific knowledge and ultimately linked to protection of the patient, and the effort applied should be proportionate to the level of risk. The second principle is the one that gets ignored, usually by applying the same heavyweight tool to every question regardless of what is at stake.

The revision to ICH Q9 sharpened several points that were being handled loosely, notably subjectivity in risk scoring, the appropriate degree of formality in risk management, and how risk-based decision-making should actually work. Subjectivity is the honest one: scores assigned by a group of people who already know the answer they want are not objective simply because they are numeric.

The common failure is sequence. A decision is taken, then a risk assessment is produced to support it. The give-away is an assessment where nothing was found to be high risk and no option was rejected. A genuine assessment changes at least some decisions, and says so.

Risk assessments are also not one-off documents. New knowledge — a deviation trend, a complaint pattern, a change in the process — should feed back into the assessment. An assessment carrying a date from five years ago and no review history is usually stale rather than stable.

What it requiresThe substance of the requirement, stated plainly.
Two ICH Q9 principles
Science-based evaluation linked to patient protection, and effort proportionate to risk.
Assess, control, communicate, review
The four stages. Review is the one most often skipped.
Formality is a choice
Not every risk question needs a formal tool; the level of formality should be justified.
Subjectivity acknowledged
Scoring is influenced by who is in the room. Diverse input and stated assumptions reduce it.
Feeds other systems
Drives deviation tiering, change routing, supplier scrutiny, validation scope and audit frequency.
Where it goes wrongThe part a definition alone will not tell you.

Common failure modes

  • Risk assessment produced after the decision, to justify it.
  • The same heavyweight tool applied to every question, so the process becomes a formality nobody engages with.
  • Scores tuned until the result falls below the action threshold.
  • Assessments never revisited when deviations or complaints contradict their assumptions.
Primary sourcesAlways verify against the primary source before acting; guidance is revised.

Where this is written down

Related

Read next

Looking for a definition rather than an explanation? The GMP glossary covers the abbreviations in one line each.

Applying this to your site

Knowing the requirement is not the same as closing the gap

If you want to know where your site actually stands against this, the readiness score covers seven quality-system domains in twenty questions, and takes about ten minutes.