Ad Code

CAPA Risk Assessment

Assess • Prioritize • Control • Review

CAPA Risk Assessment: FMEA, RPN, and Priority Decisions

A complete pharmaceutical guide to risk-based CAPA decisions using Failure Mode and Effects Analysis, severity–occurrence–detection scoring, Risk Priority Number, qualitative overrides, action prioritization, residual risk, effectiveness review, and lifecycle governance.

FMEA / FMECARPN ScoringPriority OverridesResidual Risk

What is CAPA risk assessment?

CAPA risk assessment is the structured evaluation of a quality problem’s potential patient, product, process, data, compliance, and supply consequences so the organization can scale containment, investigation, action, oversight, and effectiveness checks. FMEA organizes failure modes, effects, causes, and controls; RPN compares relative risk, while severity, uncertainty, recurrence, systemic reach, and mandatory obligations guide final priority.

Risk protects the patientScores support judgment; they do not replace scientific assessment of harm and quality.
RPN is relativeThe number is meaningful only within a defined, consistently applied scoring system.
Severity can override RPNA credible critical harm requires escalation even when occurrence appears low.
Residual risk needs reviewActions are acceptable only when remaining risk is justified, controlled, and monitored.

Risk informs rigor and urgency

Purpose of risk assessment in the CAPA lifecycle

Risk assessment should help teams make transparent, consistent decisions at initiation, investigation, action planning, implementation, effectiveness, and closure. It is not a mechanism for downgrading inconvenient work or justifying a practice that fails applicable requirements.

TRI

Triage and containment

Determine immediate control, material or batch status, distribution hold, escalation, reporting, expert involvement, and whether a formal CAPA is necessary.

RCA

Investigation rigor

Scale team expertise, evidence depth, formality, cross-product scope, testing, review, and management visibility to risk, uncertainty, and complexity.

ACT

Action and effectiveness

Prioritize stronger controls, sequence resources, maintain interim protection, define residual-risk acceptance, and select measures capable of demonstrating risk reduction.

ICH Q9(R1) foundation: risk evaluation should be based on scientific knowledge and ultimately link to patient protection, while effort, formality, and documentation should be proportionate to risk. Uncertainty, importance, and complexity also affect the rigor needed.

Use consistent definitions

Essential FMEA and CAPA risk terminology

TermPractical meaningKey question
HazardA potential source of harm, including quality failures that could affect patient protection, product availability, data reliability, or control.What can cause harm?
HarmDamage to health or another defined adverse consequence resulting from a hazard.What adverse outcome could occur?
RiskA combination of the probability of occurrence of harm and the severity of that harm; some FMEA systems also score detectability as a prioritization factor.How serious and how likely is the consequence?
Failure modeThe specific way a product, process, equipment item, method, control, or system could fail to perform its intended function.How can this step fail?
EffectThe local, downstream, product, patient, data, regulatory, or supply consequence if the failure mode occurs.What happens if it fails?
Cause or mechanismThe condition or mechanism that creates the failure mode.Why might the failure occur?
Current controlAn existing preventive or detective barrier that reduces occurrence, exposure, or escape.What currently prevents or detects the failure?
Severity (S)The seriousness of the credible effect or harm, normally assessed without assuming a downstream detection control will work.How serious is the credible consequence?
Occurrence (O)The estimated likelihood or frequency of the cause or failure mode under the defined current state and exposure.How often could it occur?
Detection (D)The likelihood that current controls will detect the failure before the defined harm or release point; many scales assign a higher number to poorer detectability.How likely is escape before harm?
RPNA relative Risk Priority Number commonly calculated as severity × occurrence × detection within one approved scoring system.How does this failure compare with others scored consistently?
Residual riskThe risk remaining after approved controls have been implemented and verified.Is the remaining risk acceptable and adequately monitored?

Systematically examine failure pathways

What is FMEA in pharmaceutical CAPA?

Failure Mode and Effects Analysis is a structured method for identifying how a process or system can fail, what the effects may be, why the failures could occur, and which controls currently prevent or detect them. It breaks complex operations into manageable steps and creates a common view of risk for cross-functional decision-making.

FMEA

FMEA focuses on

  • Process step or system function
  • Potential failure modes
  • Local and downstream effects
  • Potential causes and mechanisms
  • Existing prevention and detection controls
  • Risk reduction opportunities and responsibilities
FMEC

FMECA extends the analysis

  • Severity of consequences
  • Probability or frequency of occurrence
  • Detectability or escape potential
  • Relative criticality or risk ranking
  • Priority for additional preventive action
  • Comparison of initial and residual risk
Official guidance perspective: ICH Q9(R1) describes FMEA as a tool that evaluates potential failure modes and likely effects, then uses risk reduction to eliminate, contain, reduce, or control them. It can prioritize risk, monitor controls, guide design, and support resource deployment—but no single risk tool fits every situation.

Where CAPA teams can use FMEA

MFG

Manufacturing

Granulation, blending, compression, coating, filling, sterilization, cleaning, hold times, changeover, and in-process controls.

LAB

Laboratory

Sampling, preparation, methods, instruments, calculations, standards, data review, transfer, stability, and OOS pathways.

SYS

Systems

Computerized systems, data flow, access, audit trails, interfaces, backup, master data, workflows, and exception handling.

SUP

Supply and support

Materials, suppliers, utilities, storage, distribution, packaging, maintenance, facilities, training, and outsourced operations.

From risk question to controlled residual risk

Step-by-step FMEA workflow for CAPA decisions

01

Define the risk question and decision

State the problem, patient or quality concern, decision needed, lifecycle stage, assessment boundary, current state, time horizon, and intended use of the output.

Output: focused risk question
02

Set scope and assumptions

Identify products, batches, markets, processes, equipment, methods, data, suppliers, sites, users, interfaces, and exclusions. Record knowledge gaps and assumptions.

Output: transparent boundaries
03

Assemble a knowledgeable team

Include process owners, operators, Quality, technical experts, validation, engineering, laboratory, IT, regulatory, medical, supply, or human-factors expertise according to the risk.

Output: competent cross-functional review
04

Map functions and process steps

Describe what each step, component, control, or interface is intended to do. Use process maps, specifications, control strategy, validation knowledge, and actual execution data.

Output: agreed process model
05

Identify failure modes and effects

Ask how each function can fail and trace local, downstream, product, patient, data, regulatory, and supply consequences. Avoid vague entries such as “machine failure.”

Output: specific failure–effect pairs
06

Assign severity from credible harm

Use an approved, anchored scale and the most credible consequence supported by product and process knowledge. Apply severity overrides and mandatory escalation rules before relying on RPN.

Output: justified severity score
07

Identify causes and current controls

List causal mechanisms and distinguish prevention controls from detection controls. Confirm that controls are implemented, capable, used, and supported by reliable evidence.

Output: cause–control structure
08

Score occurrence and detection

Use exposure-normalized history, capability, validation, maintenance, complaints, deviations, controls, and uncertainty. Avoid treating “no reports” as proof of low occurrence.

Output: evidence-based O and D
09

Calculate RPN and apply decision rules

Calculate the relative score consistently, then review individual severity, occurrence, and detection values, uncertainty, recurrence, systemic reach, distribution, and regulatory obligations.

Output: reasoned priority tier
10

Select and approve risk controls

Prefer elimination, simplification, design, engineering, automation, interlocks, and robust prevention before relying on administrative or detection controls alone.

Output: risk-control plan
11

Reassess residual risk

After implementation evidence is available, rescore the controlled state using the same anchors. Explain what changed, what did not, and whether new failure modes or unintended consequences appeared.

Output: residual-risk decision
12

Monitor, communicate, and review

Link effectiveness criteria to control performance, recurrence, and risk reduction. Define review triggers such as failure, trend, change, new knowledge, complaint, audit, or regulatory signal.

Output: lifecycle risk governance

Anchor numbers to observable evidence

Illustrative 1–5 FMEA scoring scales

The table below is educational, not a universal pharmaceutical standard. Each company should approve definitions suited to its products, processes, patients, and regulatory obligations. Every score should be justified with evidence and used consistently within the same assessment.

ScoreSeverity: credible consequenceOccurrence: estimated frequencyDetection: chance of escape
1Negligible quality effect; no credible patient impact; easily corrected within normal control.Remote under defined exposure; robust evidence and capable prevention controls support rarity.Almost certain detection at source before affected material progresses; automatic prevention or validated interlock.
2Minor, contained effect without meaningful impact on critical quality attributes or intended use.Unlikely; isolated history with strong process capability and effective prevention.High detection probability through a reliable, timely control before release or use.
3Moderate quality or compliance effect requiring investigation, rejection, rework, or temporary supply disruption; patient impact remains limited or unlikely.Occasional under relevant opportunities or process conditions; mixed capability or moderate uncertainty.Moderate detection; manual sampling, periodic review, or controls that may not cover every failure opportunity.
4Major effect with credible impact on a critical quality attribute, significant compliance, clinical performance, data reliability, or supply continuity.Likely or recurring; adverse trend, weak capability, repeated deviations, or important control vulnerability.Low detection probability before release, distribution, or use; controls are indirect, delayed, limited, or poorly sensitive.
5Critical consequence with credible serious patient harm, sterility or contamination failure, strength or identity mix-up, severe data-integrity impact, or equivalent critical concern.Frequent or expected under current conditions; failure mechanism uncontrolled or repeatedly demonstrated.Failure is unlikely to be detected before patient use or defined harm; no effective control or detection depends on chance.
Direction matters: many FMEA systems use a higher detection score for poorer detectability, but some organizations use different conventions. The approved SOP must define the direction clearly, and all calculations, training, and electronic systems must use it consistently.

A comparison aid—not the decision itself

How to calculate and interpret RPN

RPN = Severity × Occurrence × DetectionS = 1–5O = 1–5D = 1–5Illustrative range = 1–125

Example: a failure mode scored Severity 5, Occurrence 2, and Detection 4 has an RPN of 5 × 2 × 4 = 40. That number can help compare failure modes assessed by the same team under the same scale, but it does not mean the risk is “moderate” or acceptable without considering the individual scores and context.

Why equal RPN values do not mean equal risk

Failure modeSODRPNPriority interpretation
Wrong strength printed foil could be applied and escape until use52440Severity-led escalation and immediate control are appropriate despite the same RPN shown below.
Minor cosmetic carton scuff detected after packing25440High frequency may justify process improvement, but the credible harm and urgency are different.
Sensor drift can shift a blend endpoint and is difficult to detect42540Poor detectability and potential CQA impact warrant strong technical review and monitoring.
Routine documentation delay with no effect on product decision24540Compliance and data-governance context must still be assessed, but patient-risk priority may be lower.
Never rank by RPN alone. Multiplying ordinal ratings compresses different risk profiles into one number. A low-occurrence catastrophic hazard can receive the same RPN as a frequent minor issue. Always review severity, detectability, uncertainty, regulatory significance, recurrence, and systemic exposure separately.

Know what the number cannot do

Limitations of RPN scoring

ORD

Ordinal arithmetic

The difference between ratings 1 and 2 may not equal the difference between 4 and 5. Multiplication creates precision that the underlying categories may not support.

TIE

Different profiles, same score

Many combinations produce identical RPN values even though the severity, preventability, escape path, and required controls differ substantially.

BIAS

Scoring subjectivity

Poorly anchored scales, dominant participants, optimism, incomplete data, and inconsistent interpretation can move scores without any real change in risk.

CUT

Artificial thresholds

A score just below a cutoff is not automatically acceptable, and a score just above it is not scientifically different without supporting rationale.

MISS

Missing dimensions

Standard RPN may not explicitly capture uncertainty, exposure, speed of harm, reversibility, distributed status, systemic reach, or regulatory obligation.

GAME

Score manipulation

Teams may lower ratings to obtain approval or closure. Scores should follow evidence and approved definitions, not the desired administrative outcome.

ICH Q9(R1) warning: subjectivity can arise from inadequately defined risk questions and poorly designed scoring scales. Control it by exposing assumptions, using relevant data and knowledge, applying trained facilitation, and independently challenging the rationale.

Combine scores with explicit decision rules

CAPA priority decisions beyond RPN

A mature system specifies conditions that override numerical ranking. These rules ensure that low-frequency but severe hazards, legal duties, distributed-product concerns, and major uncertainty receive the attention they require.

Patient and user protectionCredible serious harm, sterility failure, cross-contamination, identity or strength mix-up, counterfeit risk, or other critical safety concern requires prompt containment and senior Quality escalation.
Regulatory or legal obligationReporting timelines, recall duties, inspection commitments, marketing-authorization conditions, data-integrity requirements, or explicit procedure rules override an RPN threshold.
High severityEstablish a severity override so critical consequences receive formal review even when occurrence is remote or detection appears strong.
Poor detectability or late discoveryFailures that can escape release, distribution, or patient use deserve stronger prevention and wider scope than easily contained failures.
Recurrence and adverse trendRepeated events, ineffective prior CAPA, recurring complaints, or deteriorating process capability indicate control-system weakness beyond a single score.
Systemic extentA vulnerability shared across products, equipment, methods, suppliers, computerized systems, documents, or sites can amplify exposure and resource needs.
Uncertainty and missing knowledgeUncertain occurrence, unverified control capability, incomplete data, or an unknown failure mechanism may require more conservative controls and greater investigation formality.
Immediacy and reversibilityRapid, irreversible, or difficult-to-recover harm warrants faster escalation than a detectable, reversible, well-contained effect with the same numerical rank.
Supply and availabilityQuality/manufacturing failures that threaten medically necessary product availability can create patient harm and should be included in the risk question.
Control reliabilityA documented control is not necessarily effective. Consider validation, capability, independence, coverage, alarm response, human reliance, and historical performance.
Resource constraints do not reduce risk. Limited budget, staffing, equipment availability, or vendor lead time may affect implementation planning and interim controls, but should not be used to lower scores or choose less rigorous risk management.

Convert assessment into governance

Illustrative CAPA priority tiers

Priority tiers should be defined in the approved quality system and may use severity overrides, score bands, qualitative criteria, and external obligations. The examples below show the kinds of decisions each tier can control; they are not universal regulatory categories.

Illustrative tierTypical triggersGovernance response
Critical / immediateCredible serious patient harm, distributed critical defect, sterility or cross-contamination concern, wrong identity/strength, significant data-integrity risk, recall or urgent reporting potential.Immediate containment and executive/Quality escalation; rapid health-hazard and regulatory assessment; dedicated cross-functional team; frequent status review; strong interim controls.
High / expeditedMajor CQA or compliance impact, recurring or systemic failure, poor detection, ineffective prior CAPA, broad product/site exposure, substantial uncertainty, or important commitment.Prompt formal investigation and CAPA; senior oversight; defined phase milestones; cross-functional expertise; horizontal review; robust effectiveness criteria.
Standard / controlledMeaningful but contained issue with established evidence, capable interim controls, limited scope, and no credible critical consequence.Normal CAPA governance with risk-based milestones, approved actions, implementation evidence, and effectiveness review.
Lower / local correction and monitoringIsolated, low-consequence event with clear cause, reliable detection, no systemic signal, and correction fully managed in the source quality record.Documented correction, rationale for no separate CAPA, trend code, monitoring, and Quality approval according to the site procedure.

Reduce risk at its source

Selecting CAPA risk controls

The strongest action is not necessarily the most expensive; it is the action that reliably interrupts the supported failure pathway without creating unacceptable new risk. Prioritize prevention before depending on detection or human vigilance.

1

Eliminate or simplify

Remove the hazardous step, unnecessary choice, duplicate data entry, manual transfer, ambiguous component, or unstable condition where feasible.

2

Design and engineering

Use error-proofing, dedicated connections, segregation, interlocks, automation, closed systems, robust equipment design, and controlled configurations.

3

Process prevention

Control material attributes, parameters, maintenance, setup, cleaning, sampling, access, suppliers, specifications, and standard work at the source.

4

Reliable detection

Use validated inspection, alarms, independent verification, barcode or vision systems, continuous monitoring, reconciliation, and exception review.

5

Administrative control

Improve procedures, checklists, scheduling, supervision, communication, and training when the causal analysis shows they can reliably reduce risk.

6

Containment and recovery

Maintain segregation, holds, enhanced testing, fallback plans, business-continuity controls, and rapid escalation until permanent controls are effective.

Detection does not remove the failure mode. A new inspection may lower the probability of escape, but it normally does not reduce the inherent severity of the consequence if the failure reaches the patient. Prevention and detection should be scored and justified separately.

Reassess the controlled future state

Initial risk, residual risk, and risk acceptance

PRE

Initial risk

Assess the current or as-found state using controls that were actually implemented and effective when the event occurred. Do not credit planned actions or informal practices.

POST

Residual risk

After implementation and verification, reassess the future state using evidence that the new controls work. State remaining risk, uncertainty, monitoring, ownership, and review triggers.

Questions before accepting residual risk

  • Were approved actions fully implemented through change control, validation, document, training, supplier, and regulatory pathways?
  • Does objective evidence show that each prevention or detection control operates as designed?
  • Are rescored values supported by the same definitions and evidence standard used initially?
  • Was severity changed only because the credible consequence itself changed—not merely because detection improved?
  • Were new hazards, failure modes, interfaces, workarounds, or unintended consequences assessed?
  • Is residual risk within approved acceptance criteria, including severity overrides and regulatory obligations?
  • Are interim controls removed only after permanent controls are proven operational?
  • Do effectiveness measures confirm both risk-control performance and the intended quality outcome?
  • Are uncertainty, open dependencies, monitoring frequency, alert limits, escalation, and re-review triggers documented?
  • Has authorized Quality and required technical or management governance approved the decision?

Worked pharmaceutical example

FMEA example: incorrect printed foil on a blister line

This simplified example uses an illustrative 1–5 scale. Actual ratings, controls, and decisions require site-approved criteria, product knowledge, market and patient assessment, validation evidence, and authorized Quality review.

FMEA fieldExample entry
Process functionLoad and verify the approved printed foil corresponding to the product, strength, market, and packaging order.
Failure modePrinted foil for another strength is loaded and used.
Potential effectsIncorrect strength identification, product–label mismatch, potential medication error, batch rejection or recall, and significant compliance impact.
Potential causesLook-alike rolls staged together; incomplete line clearance; barcode override after scanner communication loss; master-data mapping error; manual selection under time pressure.
Current controlsMaterial issuance, line clearance, operator barcode scan, reconciliation, in-process visual checks, and QA batch-record review.
Initial ratingSeverity 5, Occurrence 2, Detection 3; RPN = 30. Severity override classifies the failure as expedited/high priority despite the modest numerical score.
Investigation findingsThe scanner allowed an authorized bypass during intermittent network loss, and the line-side rack physically permitted two similar foil rolls. Visual verification relied on small text and did not independently confirm encoded product and strength.
Corrective actionsRemove uncontrolled bypass; add a validated fail-safe interlock and escalation path; segregate one order at a time; improve human-readable differentiation; verify master-data mapping; revise line clearance and recovery procedure; train and qualify affected personnel.
Implementation evidenceApproved change control, tested interlock and communication-failure challenge, revised layout and SOP, qualification report, master-data verification, training competence, and retirement of the legacy override.
Residual ratingSeverity remains 5 because the consequence of an escaped wrong-strength label is unchanged. Occurrence falls to 1 and Detection to 1 after verified prevention and detection controls; residual RPN = 5.
EffectivenessChallenge interlock scenarios, audit order staging and line clearance, review scan failures and attempted overrides, trend foil discrepancies, and confirm no unintended downtime workaround during a justified number of packaging opportunities.
Key lesson: the initial RPN of 30 must not hide Severity 5. The priority decision is driven by credible patient harm and escape potential, while the residual score remains acceptable only after strong controls are implemented, verified, challenged, and monitored.

Make the decision reproducible

CAPA risk-assessment documentation requirements

A reviewer should be able to reconstruct the risk question, evidence available at the time, scoring logic, dissent, selected controls, residual-risk decision, and review obligations. Apply ALCOA+ principles to source data, calculations, tables, approvals, attachments, audit trails, and revisions.

  • Assessment title, unique ID, CAPA/source records, product or system, site, dates, version, status, and owner
  • Clear risk question, decision needed, patient or quality endpoint, scope, exclusions, assumptions, and time horizon
  • Team members, roles, relevant expertise, facilitator, approvers, and conflicts or dissent
  • Process map, intended functions, specifications, control strategy, validation state, and knowledge sources
  • Failure modes, effects, credible harms, causes, current prevention and detection controls, and evidence references
  • Approved scale definitions, scoring direction, individual S/O/D rationale, RPN calculation, overrides, and priority tier
  • Uncertainty, limitations, data gaps, subjectivity controls, alternative interpretations, and sensitivity analysis where useful
  • Initial risk, immediate controls, risk-control options considered, selected actions, owners, dates, dependencies, and implementation evidence
  • Residual scores and rationale, acceptance authority, open monitoring, escalation, communication, and review triggers
  • Effectiveness criteria, data sources, sampling or opportunity, review period, results, conclusion, and Quality approval

Strengthen scoring consistency

How to reduce subjectivity in FMEA and RPN

ControlPractical application
Define the risk question firstState the harm endpoint, population, failure opportunity, scope, current state, and decision. Do not start by choosing the desired priority.
Use anchored scalesConnect ratings to observable consequences, frequencies, exposure, control performance, and examples rather than adjectives alone.
Separate dimensionsDiscuss severity, occurrence, and detection independently before viewing the multiplied RPN so the total does not anchor individual judgments.
Use current, reliable dataNormalize events by meaningful opportunities; include complaints, deviations, maintenance, alarms, trend, capability, validation, and similar-system history.
Document uncertaintyDistinguish absence of evidence from evidence of absence. Use conservative control or additional data collection when uncertainty affects an important decision.
Facilitate cross-functionallyCollect independent ratings or rationales before group discussion; prevent hierarchy, familiarity, and groupthink from determining the score.
Calibrate assessorsUse training cases and periodic reviews to compare how teams apply definitions across products, sites, and failure types.
Challenge outliers and changesRequire rationale when ratings differ materially from history, similar FMEAs, or earlier versions—especially when the change lowers priority.
Review the componentsPresent S, O, D, evidence, and overrides beside the RPN; never report the total alone.
Independent Quality reviewVerify source data, scale use, control credit, patient linkage, priority, residual-risk acceptance, and alignment with the quality system.

Interactive educational tool

Initial and residual RPN calculator

Select illustrative 1–5 ratings. The calculator shows arithmetic and relative bands only; it does not classify a real CAPA, determine acceptability, or replace site-approved scales, severity overrides, scientific review, or Quality authorization.

Initial risk

Initial RPN

Residual risk after controls

Residual RPN
Choose all six ratings to compare initial and residual RPN. Use only scales approved by your site for real quality decisions.

Quality-review checklist

CAPA FMEA audit checklist

  • The risk question identifies the patient or quality endpoint, current state, scope, decision, and time horizon
  • Team expertise and assessment formality are proportionate to risk, uncertainty, importance, and complexity
  • Failure modes are specific and linked to intended functions rather than broad labels such as “operator” or “equipment”
  • Effects extend from local impact through product, patient, data, compliance, supply, and downstream systems where relevant
  • Causes are evidence-supported mechanisms, not merely restatements of the failure mode
  • Current controls are separated into prevention and detection and are credited only when implemented and capable
  • Severity, occurrence, and detection definitions are approved, unambiguous, consistently directed, and supported by examples
  • Occurrence uses meaningful exposure and does not treat missing reports as proof of rarity
  • Detection scoring considers whether the control finds the failure before the defined harm or release point
  • RPN arithmetic is correct, but individual scores, overrides, uncertainty, and mandatory obligations determine priority
  • High-severity and poor-detection failures receive explicit review regardless of the total score
  • Scoring assumptions, source data, uncertainty, dissent, and changes from prior assessments remain traceable
  • Selected controls follow the failure pathway and prioritize prevention over detection where feasible
  • Permanent controls are implemented through appropriate change control, validation, regulatory, supplier, document, and training systems
  • Residual scores are assigned only after objective implementation evidence is available
  • Severity is not lowered merely because a new inspection or detection control was added
  • New hazards and unintended consequences introduced by the action are assessed
  • Risk acceptance, monitoring, effectiveness, communication, review triggers, and Quality approval are documented

Avoid false numerical confidence

Common FMEA and RPN mistakes

Weak practiceWhy it failsBetter control
RPN alone determines priorityCritical severity can be hidden by low occurrence or good detection, and different risk profiles can have the same total.Use explicit severity, compliance, uncertainty, recurrence, systemic, and distribution overrides.
Vague scale words“Rare,” “major,” and “good detection” mean different things to different assessors.Anchor ratings to consequences, exposure-normalized frequency, control capability, and examples.
Scoring planned controls as currentThe initial risk appears lower before action has been implemented or verified.Score the as-found state, then separately assess residual risk after evidence confirms implementation.
Reducing severity after adding inspectionDetection can reduce escape probability but usually does not change the harm if an undetected failure reaches the patient.Keep severity unless the consequence itself changes; revise occurrence or detection with evidence.
No failure opportunity denominatorEvent counts cannot show occurrence without knowing batches, units, cycles, users, or exposure.Normalize history using a meaningful opportunity and state data limitations.
Credit for weak manual controlA procedure or signature may not prevent error under actual workload, interface, or process conditions.Verify control design, coverage, independence, competence, adherence, and performance history.
Lower score to meet the cutoffThe desired administrative result drives the assessment rather than the evidence.Require independent challenge and rationale for changes, especially downward rating changes.
One FMEA copied across productsFormulation, strength, population, process, equipment, market, and control differences may change harms and likelihoods.Use justified families and confirm applicability for each product, process, and site.
Residual RPN proves effectivenessA recalculated number is a prediction, not evidence that controls work in routine use.Verify implementation and use process and outcome data in a separate effectiveness check.
FMEA never reviewedChanges, failures, trends, new knowledge, and ineffective controls make the assessment obsolete.Define periodic and event-driven review triggers with ownership and version control.

AEO quick answers

Frequently asked questions about CAPA risk assessment

What is CAPA risk assessment?

CAPA risk assessment is the structured evaluation of a quality issue's potential patient, product, process, data, compliance, and supply consequences. It supports decisions about containment, investigation rigor, action priority, management oversight, residual-risk acceptance, effectiveness checks, and closure.

What is FMEA in pharmaceutical CAPA?

Failure Mode and Effects Analysis is a systematic method for identifying how process or system functions can fail, the effects of those failures, their possible causes, existing prevention and detection controls, and opportunities for risk reduction and CAPA prioritization.

What is the difference between FMEA and FMECA?

FMEA identifies and evaluates potential failure modes, effects, causes, and controls. FMECA extends the analysis by considering criticality factors such as severity, occurrence probability, and detectability, producing a relative ranking that helps prioritize additional risk controls.

What is RPN in FMEA?

RPN means Risk Priority Number. It is a relative score commonly calculated by multiplying severity, occurrence, and detection ratings. It helps compare failure modes scored under the same approved system, but it should not determine CAPA priority or risk acceptance by itself.

What is the RPN formula?

The common formula is RPN = Severity × Occurrence × Detection. With 1–5 scales, the possible numerical range is 1–125. Scale definitions, direction, evidence, overrides, and decision thresholds must be defined by the approved quality system.

Which FMEA scoring scale should a pharmaceutical company use?

There is no single universal pharmaceutical FMEA scale. A company may use 1–3, 1–5, 1–10, or another justified approach. Definitions should be clearly anchored to credible harm, meaningful occurrence evidence, control capability, and detection before the defined consequence.

What is considered a high RPN?

There is no universal high-RPN cutoff. A score is meaningful only within the approved scale and context. Priority should also consider individual severity and detection scores, patient impact, regulatory duties, recurrence, systemic extent, distributed status, uncertainty, and required escalation rules.

Can two different risks have the same RPN?

Yes. Different severity, occurrence, and detection combinations can produce the same RPN while representing very different hazards. For example, a rare critical labeling failure and a frequent minor cosmetic defect may have identical totals but require different urgency and controls.

Should severity decrease after CAPA actions?

Severity should decrease only when the credible consequence of the failure itself has been reduced. Adding inspection, alarms, or other detection controls normally improves detectability but does not change the harm if an undetected failure reaches the patient.

How should occurrence be scored?

Occurrence should use the likelihood of the cause or failure under the defined current state, supported by meaningful exposure such as batches, units, cycles, users, or time. Consider process capability, validation, deviations, complaints, maintenance, trends, similar systems, and uncertainty.

How should detection be scored?

Detection should reflect the capability of current controls to identify the failure before the defined harm, release, distribution, or use point. Consider coverage, sensitivity, independence, timing, sampling, automation, human reliance, alarm response, validation, and historical control performance.

What factors should override RPN?

Priority overrides commonly include credible serious patient harm, critical severity, sterility or contamination risk, identity or strength mix-up, significant data-integrity concern, regulatory or reporting obligations, recall potential, distributed product, recurrence, ineffective prior CAPA, systemic exposure, and major uncertainty.

What is residual risk in CAPA?

Residual risk is the risk remaining after approved actions have been implemented and verified. It should be reassessed using the same defined scales, supported by objective evidence, evaluated for new hazards, accepted by authorized roles, monitored through effectiveness measures, and reviewed when conditions change.

Does a lower residual RPN prove CAPA effectiveness?

No. A lower residual RPN is a prospective assessment based on expected control performance. CAPA effectiveness requires actual evidence that controls operate as intended, recurrence or escape is reduced, process performance improves, no unacceptable new risk appears, and predefined criteria are met.

When should an FMEA be reviewed or updated?

Review FMEA after significant deviations, complaints, failures, ineffective CAPA, process or product changes, new equipment or suppliers, validation findings, audit or inspection observations, adverse trends, new scientific knowledge, control failure, or at the approved periodic frequency.

What is required before approving a CAPA risk decision?

Confirm that scope, evidence, failure modes, effects, causes, controls, ratings, calculations, uncertainty, overrides, priority, actions, residual risk, monitoring, review triggers, and data integrity are documented; required experts have contributed; and authorized Quality and governance roles have approved the decision.

Primary regulatory references

Official sources for FMEA and CAPA risk decisions