CAPA Risk Assessment: FMEA, RPN, and Priority Decisions
A complete pharmaceutical guide to risk-based CAPA decisions using Failure Mode and Effects Analysis, severity–occurrence–detection scoring, Risk Priority Number, qualitative overrides, action prioritization, residual risk, effectiveness review, and lifecycle governance.
What is CAPA risk assessment?
CAPA risk assessment is the structured evaluation of a quality problem’s potential patient, product, process, data, compliance, and supply consequences so the organization can scale containment, investigation, action, oversight, and effectiveness checks. FMEA organizes failure modes, effects, causes, and controls; RPN compares relative risk, while severity, uncertainty, recurrence, systemic reach, and mandatory obligations guide final priority.
Risk informs rigor and urgency
Purpose of risk assessment in the CAPA lifecycle
Risk assessment should help teams make transparent, consistent decisions at initiation, investigation, action planning, implementation, effectiveness, and closure. It is not a mechanism for downgrading inconvenient work or justifying a practice that fails applicable requirements.
Triage and containment
Determine immediate control, material or batch status, distribution hold, escalation, reporting, expert involvement, and whether a formal CAPA is necessary.
Investigation rigor
Scale team expertise, evidence depth, formality, cross-product scope, testing, review, and management visibility to risk, uncertainty, and complexity.
Action and effectiveness
Prioritize stronger controls, sequence resources, maintain interim protection, define residual-risk acceptance, and select measures capable of demonstrating risk reduction.
Use consistent definitions
Essential FMEA and CAPA risk terminology
| Term | Practical meaning | Key question |
|---|---|---|
| Hazard | A potential source of harm, including quality failures that could affect patient protection, product availability, data reliability, or control. | What can cause harm? |
| Harm | Damage to health or another defined adverse consequence resulting from a hazard. | What adverse outcome could occur? |
| Risk | A combination of the probability of occurrence of harm and the severity of that harm; some FMEA systems also score detectability as a prioritization factor. | How serious and how likely is the consequence? |
| Failure mode | The specific way a product, process, equipment item, method, control, or system could fail to perform its intended function. | How can this step fail? |
| Effect | The local, downstream, product, patient, data, regulatory, or supply consequence if the failure mode occurs. | What happens if it fails? |
| Cause or mechanism | The condition or mechanism that creates the failure mode. | Why might the failure occur? |
| Current control | An existing preventive or detective barrier that reduces occurrence, exposure, or escape. | What currently prevents or detects the failure? |
| Severity (S) | The seriousness of the credible effect or harm, normally assessed without assuming a downstream detection control will work. | How serious is the credible consequence? |
| Occurrence (O) | The estimated likelihood or frequency of the cause or failure mode under the defined current state and exposure. | How often could it occur? |
| Detection (D) | The likelihood that current controls will detect the failure before the defined harm or release point; many scales assign a higher number to poorer detectability. | How likely is escape before harm? |
| RPN | A relative Risk Priority Number commonly calculated as severity × occurrence × detection within one approved scoring system. | How does this failure compare with others scored consistently? |
| Residual risk | The risk remaining after approved controls have been implemented and verified. | Is the remaining risk acceptable and adequately monitored? |
Systematically examine failure pathways
What is FMEA in pharmaceutical CAPA?
Failure Mode and Effects Analysis is a structured method for identifying how a process or system can fail, what the effects may be, why the failures could occur, and which controls currently prevent or detect them. It breaks complex operations into manageable steps and creates a common view of risk for cross-functional decision-making.
FMEA focuses on
- Process step or system function
- Potential failure modes
- Local and downstream effects
- Potential causes and mechanisms
- Existing prevention and detection controls
- Risk reduction opportunities and responsibilities
FMECA extends the analysis
- Severity of consequences
- Probability or frequency of occurrence
- Detectability or escape potential
- Relative criticality or risk ranking
- Priority for additional preventive action
- Comparison of initial and residual risk
Where CAPA teams can use FMEA
Manufacturing
Granulation, blending, compression, coating, filling, sterilization, cleaning, hold times, changeover, and in-process controls.
Laboratory
Sampling, preparation, methods, instruments, calculations, standards, data review, transfer, stability, and OOS pathways.
Systems
Computerized systems, data flow, access, audit trails, interfaces, backup, master data, workflows, and exception handling.
Supply and support
Materials, suppliers, utilities, storage, distribution, packaging, maintenance, facilities, training, and outsourced operations.
From risk question to controlled residual risk
Step-by-step FMEA workflow for CAPA decisions
Define the risk question and decision
State the problem, patient or quality concern, decision needed, lifecycle stage, assessment boundary, current state, time horizon, and intended use of the output.
Output: focused risk questionSet scope and assumptions
Identify products, batches, markets, processes, equipment, methods, data, suppliers, sites, users, interfaces, and exclusions. Record knowledge gaps and assumptions.
Output: transparent boundariesAssemble a knowledgeable team
Include process owners, operators, Quality, technical experts, validation, engineering, laboratory, IT, regulatory, medical, supply, or human-factors expertise according to the risk.
Output: competent cross-functional reviewMap functions and process steps
Describe what each step, component, control, or interface is intended to do. Use process maps, specifications, control strategy, validation knowledge, and actual execution data.
Output: agreed process modelIdentify failure modes and effects
Ask how each function can fail and trace local, downstream, product, patient, data, regulatory, and supply consequences. Avoid vague entries such as “machine failure.”
Output: specific failure–effect pairsAssign severity from credible harm
Use an approved, anchored scale and the most credible consequence supported by product and process knowledge. Apply severity overrides and mandatory escalation rules before relying on RPN.
Output: justified severity scoreIdentify causes and current controls
List causal mechanisms and distinguish prevention controls from detection controls. Confirm that controls are implemented, capable, used, and supported by reliable evidence.
Output: cause–control structureScore occurrence and detection
Use exposure-normalized history, capability, validation, maintenance, complaints, deviations, controls, and uncertainty. Avoid treating “no reports” as proof of low occurrence.
Output: evidence-based O and DCalculate RPN and apply decision rules
Calculate the relative score consistently, then review individual severity, occurrence, and detection values, uncertainty, recurrence, systemic reach, distribution, and regulatory obligations.
Output: reasoned priority tierSelect and approve risk controls
Prefer elimination, simplification, design, engineering, automation, interlocks, and robust prevention before relying on administrative or detection controls alone.
Output: risk-control planReassess residual risk
After implementation evidence is available, rescore the controlled state using the same anchors. Explain what changed, what did not, and whether new failure modes or unintended consequences appeared.
Output: residual-risk decisionMonitor, communicate, and review
Link effectiveness criteria to control performance, recurrence, and risk reduction. Define review triggers such as failure, trend, change, new knowledge, complaint, audit, or regulatory signal.
Output: lifecycle risk governanceAnchor numbers to observable evidence
Illustrative 1–5 FMEA scoring scales
The table below is educational, not a universal pharmaceutical standard. Each company should approve definitions suited to its products, processes, patients, and regulatory obligations. Every score should be justified with evidence and used consistently within the same assessment.
| Score | Severity: credible consequence | Occurrence: estimated frequency | Detection: chance of escape |
|---|---|---|---|
| 1 | Negligible quality effect; no credible patient impact; easily corrected within normal control. | Remote under defined exposure; robust evidence and capable prevention controls support rarity. | Almost certain detection at source before affected material progresses; automatic prevention or validated interlock. |
| 2 | Minor, contained effect without meaningful impact on critical quality attributes or intended use. | Unlikely; isolated history with strong process capability and effective prevention. | High detection probability through a reliable, timely control before release or use. |
| 3 | Moderate quality or compliance effect requiring investigation, rejection, rework, or temporary supply disruption; patient impact remains limited or unlikely. | Occasional under relevant opportunities or process conditions; mixed capability or moderate uncertainty. | Moderate detection; manual sampling, periodic review, or controls that may not cover every failure opportunity. |
| 4 | Major effect with credible impact on a critical quality attribute, significant compliance, clinical performance, data reliability, or supply continuity. | Likely or recurring; adverse trend, weak capability, repeated deviations, or important control vulnerability. | Low detection probability before release, distribution, or use; controls are indirect, delayed, limited, or poorly sensitive. |
| 5 | Critical consequence with credible serious patient harm, sterility or contamination failure, strength or identity mix-up, severe data-integrity impact, or equivalent critical concern. | Frequent or expected under current conditions; failure mechanism uncontrolled or repeatedly demonstrated. | Failure is unlikely to be detected before patient use or defined harm; no effective control or detection depends on chance. |
A comparison aid—not the decision itself
How to calculate and interpret RPN
Example: a failure mode scored Severity 5, Occurrence 2, and Detection 4 has an RPN of 5 × 2 × 4 = 40. That number can help compare failure modes assessed by the same team under the same scale, but it does not mean the risk is “moderate” or acceptable without considering the individual scores and context.
Why equal RPN values do not mean equal risk
| Failure mode | S | O | D | RPN | Priority interpretation |
|---|---|---|---|---|---|
| Wrong strength printed foil could be applied and escape until use | 5 | 2 | 4 | 40 | Severity-led escalation and immediate control are appropriate despite the same RPN shown below. |
| Minor cosmetic carton scuff detected after packing | 2 | 5 | 4 | 40 | High frequency may justify process improvement, but the credible harm and urgency are different. |
| Sensor drift can shift a blend endpoint and is difficult to detect | 4 | 2 | 5 | 40 | Poor detectability and potential CQA impact warrant strong technical review and monitoring. |
| Routine documentation delay with no effect on product decision | 2 | 4 | 5 | 40 | Compliance and data-governance context must still be assessed, but patient-risk priority may be lower. |
Know what the number cannot do
Limitations of RPN scoring
Ordinal arithmetic
The difference between ratings 1 and 2 may not equal the difference between 4 and 5. Multiplication creates precision that the underlying categories may not support.
Different profiles, same score
Many combinations produce identical RPN values even though the severity, preventability, escape path, and required controls differ substantially.
Scoring subjectivity
Poorly anchored scales, dominant participants, optimism, incomplete data, and inconsistent interpretation can move scores without any real change in risk.
Artificial thresholds
A score just below a cutoff is not automatically acceptable, and a score just above it is not scientifically different without supporting rationale.
Missing dimensions
Standard RPN may not explicitly capture uncertainty, exposure, speed of harm, reversibility, distributed status, systemic reach, or regulatory obligation.
Score manipulation
Teams may lower ratings to obtain approval or closure. Scores should follow evidence and approved definitions, not the desired administrative outcome.
Combine scores with explicit decision rules
CAPA priority decisions beyond RPN
A mature system specifies conditions that override numerical ranking. These rules ensure that low-frequency but severe hazards, legal duties, distributed-product concerns, and major uncertainty receive the attention they require.
Convert assessment into governance
Illustrative CAPA priority tiers
Priority tiers should be defined in the approved quality system and may use severity overrides, score bands, qualitative criteria, and external obligations. The examples below show the kinds of decisions each tier can control; they are not universal regulatory categories.
| Illustrative tier | Typical triggers | Governance response |
|---|---|---|
| Critical / immediate | Credible serious patient harm, distributed critical defect, sterility or cross-contamination concern, wrong identity/strength, significant data-integrity risk, recall or urgent reporting potential. | Immediate containment and executive/Quality escalation; rapid health-hazard and regulatory assessment; dedicated cross-functional team; frequent status review; strong interim controls. |
| High / expedited | Major CQA or compliance impact, recurring or systemic failure, poor detection, ineffective prior CAPA, broad product/site exposure, substantial uncertainty, or important commitment. | Prompt formal investigation and CAPA; senior oversight; defined phase milestones; cross-functional expertise; horizontal review; robust effectiveness criteria. |
| Standard / controlled | Meaningful but contained issue with established evidence, capable interim controls, limited scope, and no credible critical consequence. | Normal CAPA governance with risk-based milestones, approved actions, implementation evidence, and effectiveness review. |
| Lower / local correction and monitoring | Isolated, low-consequence event with clear cause, reliable detection, no systemic signal, and correction fully managed in the source quality record. | Documented correction, rationale for no separate CAPA, trend code, monitoring, and Quality approval according to the site procedure. |
Reduce risk at its source
Selecting CAPA risk controls
The strongest action is not necessarily the most expensive; it is the action that reliably interrupts the supported failure pathway without creating unacceptable new risk. Prioritize prevention before depending on detection or human vigilance.
Eliminate or simplify
Remove the hazardous step, unnecessary choice, duplicate data entry, manual transfer, ambiguous component, or unstable condition where feasible.
Design and engineering
Use error-proofing, dedicated connections, segregation, interlocks, automation, closed systems, robust equipment design, and controlled configurations.
Process prevention
Control material attributes, parameters, maintenance, setup, cleaning, sampling, access, suppliers, specifications, and standard work at the source.
Reliable detection
Use validated inspection, alarms, independent verification, barcode or vision systems, continuous monitoring, reconciliation, and exception review.
Administrative control
Improve procedures, checklists, scheduling, supervision, communication, and training when the causal analysis shows they can reliably reduce risk.
Containment and recovery
Maintain segregation, holds, enhanced testing, fallback plans, business-continuity controls, and rapid escalation until permanent controls are effective.
Reassess the controlled future state
Initial risk, residual risk, and risk acceptance
Initial risk
Assess the current or as-found state using controls that were actually implemented and effective when the event occurred. Do not credit planned actions or informal practices.
Residual risk
After implementation and verification, reassess the future state using evidence that the new controls work. State remaining risk, uncertainty, monitoring, ownership, and review triggers.
Questions before accepting residual risk
- Were approved actions fully implemented through change control, validation, document, training, supplier, and regulatory pathways?
- Does objective evidence show that each prevention or detection control operates as designed?
- Are rescored values supported by the same definitions and evidence standard used initially?
- Was severity changed only because the credible consequence itself changed—not merely because detection improved?
- Were new hazards, failure modes, interfaces, workarounds, or unintended consequences assessed?
- Is residual risk within approved acceptance criteria, including severity overrides and regulatory obligations?
- Are interim controls removed only after permanent controls are proven operational?
- Do effectiveness measures confirm both risk-control performance and the intended quality outcome?
- Are uncertainty, open dependencies, monitoring frequency, alert limits, escalation, and re-review triggers documented?
- Has authorized Quality and required technical or management governance approved the decision?
Worked pharmaceutical example
FMEA example: incorrect printed foil on a blister line
This simplified example uses an illustrative 1–5 scale. Actual ratings, controls, and decisions require site-approved criteria, product knowledge, market and patient assessment, validation evidence, and authorized Quality review.
| FMEA field | Example entry |
|---|---|
| Process function | Load and verify the approved printed foil corresponding to the product, strength, market, and packaging order. |
| Failure mode | Printed foil for another strength is loaded and used. |
| Potential effects | Incorrect strength identification, product–label mismatch, potential medication error, batch rejection or recall, and significant compliance impact. |
| Potential causes | Look-alike rolls staged together; incomplete line clearance; barcode override after scanner communication loss; master-data mapping error; manual selection under time pressure. |
| Current controls | Material issuance, line clearance, operator barcode scan, reconciliation, in-process visual checks, and QA batch-record review. |
| Initial rating | Severity 5, Occurrence 2, Detection 3; RPN = 30. Severity override classifies the failure as expedited/high priority despite the modest numerical score. |
| Investigation findings | The scanner allowed an authorized bypass during intermittent network loss, and the line-side rack physically permitted two similar foil rolls. Visual verification relied on small text and did not independently confirm encoded product and strength. |
| Corrective actions | Remove uncontrolled bypass; add a validated fail-safe interlock and escalation path; segregate one order at a time; improve human-readable differentiation; verify master-data mapping; revise line clearance and recovery procedure; train and qualify affected personnel. |
| Implementation evidence | Approved change control, tested interlock and communication-failure challenge, revised layout and SOP, qualification report, master-data verification, training competence, and retirement of the legacy override. |
| Residual rating | Severity remains 5 because the consequence of an escaped wrong-strength label is unchanged. Occurrence falls to 1 and Detection to 1 after verified prevention and detection controls; residual RPN = 5. |
| Effectiveness | Challenge interlock scenarios, audit order staging and line clearance, review scan failures and attempted overrides, trend foil discrepancies, and confirm no unintended downtime workaround during a justified number of packaging opportunities. |
Make the decision reproducible
CAPA risk-assessment documentation requirements
A reviewer should be able to reconstruct the risk question, evidence available at the time, scoring logic, dissent, selected controls, residual-risk decision, and review obligations. Apply ALCOA+ principles to source data, calculations, tables, approvals, attachments, audit trails, and revisions.
- Assessment title, unique ID, CAPA/source records, product or system, site, dates, version, status, and owner
- Clear risk question, decision needed, patient or quality endpoint, scope, exclusions, assumptions, and time horizon
- Team members, roles, relevant expertise, facilitator, approvers, and conflicts or dissent
- Process map, intended functions, specifications, control strategy, validation state, and knowledge sources
- Failure modes, effects, credible harms, causes, current prevention and detection controls, and evidence references
- Approved scale definitions, scoring direction, individual S/O/D rationale, RPN calculation, overrides, and priority tier
- Uncertainty, limitations, data gaps, subjectivity controls, alternative interpretations, and sensitivity analysis where useful
- Initial risk, immediate controls, risk-control options considered, selected actions, owners, dates, dependencies, and implementation evidence
- Residual scores and rationale, acceptance authority, open monitoring, escalation, communication, and review triggers
- Effectiveness criteria, data sources, sampling or opportunity, review period, results, conclusion, and Quality approval
Strengthen scoring consistency
How to reduce subjectivity in FMEA and RPN
| Control | Practical application |
|---|---|
| Define the risk question first | State the harm endpoint, population, failure opportunity, scope, current state, and decision. Do not start by choosing the desired priority. |
| Use anchored scales | Connect ratings to observable consequences, frequencies, exposure, control performance, and examples rather than adjectives alone. |
| Separate dimensions | Discuss severity, occurrence, and detection independently before viewing the multiplied RPN so the total does not anchor individual judgments. |
| Use current, reliable data | Normalize events by meaningful opportunities; include complaints, deviations, maintenance, alarms, trend, capability, validation, and similar-system history. |
| Document uncertainty | Distinguish absence of evidence from evidence of absence. Use conservative control or additional data collection when uncertainty affects an important decision. |
| Facilitate cross-functionally | Collect independent ratings or rationales before group discussion; prevent hierarchy, familiarity, and groupthink from determining the score. |
| Calibrate assessors | Use training cases and periodic reviews to compare how teams apply definitions across products, sites, and failure types. |
| Challenge outliers and changes | Require rationale when ratings differ materially from history, similar FMEAs, or earlier versions—especially when the change lowers priority. |
| Review the components | Present S, O, D, evidence, and overrides beside the RPN; never report the total alone. |
| Independent Quality review | Verify source data, scale use, control credit, patient linkage, priority, residual-risk acceptance, and alignment with the quality system. |
Interactive educational tool
Initial and residual RPN calculator
Select illustrative 1–5 ratings. The calculator shows arithmetic and relative bands only; it does not classify a real CAPA, determine acceptability, or replace site-approved scales, severity overrides, scientific review, or Quality authorization.
Initial risk
Residual risk after controls
Quality-review checklist
CAPA FMEA audit checklist
- The risk question identifies the patient or quality endpoint, current state, scope, decision, and time horizon
- Team expertise and assessment formality are proportionate to risk, uncertainty, importance, and complexity
- Failure modes are specific and linked to intended functions rather than broad labels such as “operator” or “equipment”
- Effects extend from local impact through product, patient, data, compliance, supply, and downstream systems where relevant
- Causes are evidence-supported mechanisms, not merely restatements of the failure mode
- Current controls are separated into prevention and detection and are credited only when implemented and capable
- Severity, occurrence, and detection definitions are approved, unambiguous, consistently directed, and supported by examples
- Occurrence uses meaningful exposure and does not treat missing reports as proof of rarity
- Detection scoring considers whether the control finds the failure before the defined harm or release point
- RPN arithmetic is correct, but individual scores, overrides, uncertainty, and mandatory obligations determine priority
- High-severity and poor-detection failures receive explicit review regardless of the total score
- Scoring assumptions, source data, uncertainty, dissent, and changes from prior assessments remain traceable
- Selected controls follow the failure pathway and prioritize prevention over detection where feasible
- Permanent controls are implemented through appropriate change control, validation, regulatory, supplier, document, and training systems
- Residual scores are assigned only after objective implementation evidence is available
- Severity is not lowered merely because a new inspection or detection control was added
- New hazards and unintended consequences introduced by the action are assessed
- Risk acceptance, monitoring, effectiveness, communication, review triggers, and Quality approval are documented
Avoid false numerical confidence
Common FMEA and RPN mistakes
| Weak practice | Why it fails | Better control |
|---|---|---|
| RPN alone determines priority | Critical severity can be hidden by low occurrence or good detection, and different risk profiles can have the same total. | Use explicit severity, compliance, uncertainty, recurrence, systemic, and distribution overrides. |
| Vague scale words | “Rare,” “major,” and “good detection” mean different things to different assessors. | Anchor ratings to consequences, exposure-normalized frequency, control capability, and examples. |
| Scoring planned controls as current | The initial risk appears lower before action has been implemented or verified. | Score the as-found state, then separately assess residual risk after evidence confirms implementation. |
| Reducing severity after adding inspection | Detection can reduce escape probability but usually does not change the harm if an undetected failure reaches the patient. | Keep severity unless the consequence itself changes; revise occurrence or detection with evidence. |
| No failure opportunity denominator | Event counts cannot show occurrence without knowing batches, units, cycles, users, or exposure. | Normalize history using a meaningful opportunity and state data limitations. |
| Credit for weak manual control | A procedure or signature may not prevent error under actual workload, interface, or process conditions. | Verify control design, coverage, independence, competence, adherence, and performance history. |
| Lower score to meet the cutoff | The desired administrative result drives the assessment rather than the evidence. | Require independent challenge and rationale for changes, especially downward rating changes. |
| One FMEA copied across products | Formulation, strength, population, process, equipment, market, and control differences may change harms and likelihoods. | Use justified families and confirm applicability for each product, process, and site. |
| Residual RPN proves effectiveness | A recalculated number is a prediction, not evidence that controls work in routine use. | Verify implementation and use process and outcome data in a separate effectiveness check. |
| FMEA never reviewed | Changes, failures, trends, new knowledge, and ineffective controls make the assessment obsolete. | Define periodic and event-driven review triggers with ownership and version control. |
AEO quick answers
Frequently asked questions about CAPA risk assessment
What is CAPA risk assessment?
CAPA risk assessment is the structured evaluation of a quality issue's potential patient, product, process, data, compliance, and supply consequences. It supports decisions about containment, investigation rigor, action priority, management oversight, residual-risk acceptance, effectiveness checks, and closure.
What is FMEA in pharmaceutical CAPA?
Failure Mode and Effects Analysis is a systematic method for identifying how process or system functions can fail, the effects of those failures, their possible causes, existing prevention and detection controls, and opportunities for risk reduction and CAPA prioritization.
What is the difference between FMEA and FMECA?
FMEA identifies and evaluates potential failure modes, effects, causes, and controls. FMECA extends the analysis by considering criticality factors such as severity, occurrence probability, and detectability, producing a relative ranking that helps prioritize additional risk controls.
What is RPN in FMEA?
RPN means Risk Priority Number. It is a relative score commonly calculated by multiplying severity, occurrence, and detection ratings. It helps compare failure modes scored under the same approved system, but it should not determine CAPA priority or risk acceptance by itself.
What is the RPN formula?
The common formula is RPN = Severity × Occurrence × Detection. With 1–5 scales, the possible numerical range is 1–125. Scale definitions, direction, evidence, overrides, and decision thresholds must be defined by the approved quality system.
Which FMEA scoring scale should a pharmaceutical company use?
There is no single universal pharmaceutical FMEA scale. A company may use 1–3, 1–5, 1–10, or another justified approach. Definitions should be clearly anchored to credible harm, meaningful occurrence evidence, control capability, and detection before the defined consequence.
What is considered a high RPN?
There is no universal high-RPN cutoff. A score is meaningful only within the approved scale and context. Priority should also consider individual severity and detection scores, patient impact, regulatory duties, recurrence, systemic extent, distributed status, uncertainty, and required escalation rules.
Can two different risks have the same RPN?
Yes. Different severity, occurrence, and detection combinations can produce the same RPN while representing very different hazards. For example, a rare critical labeling failure and a frequent minor cosmetic defect may have identical totals but require different urgency and controls.
Should severity decrease after CAPA actions?
Severity should decrease only when the credible consequence of the failure itself has been reduced. Adding inspection, alarms, or other detection controls normally improves detectability but does not change the harm if an undetected failure reaches the patient.
How should occurrence be scored?
Occurrence should use the likelihood of the cause or failure under the defined current state, supported by meaningful exposure such as batches, units, cycles, users, or time. Consider process capability, validation, deviations, complaints, maintenance, trends, similar systems, and uncertainty.
How should detection be scored?
Detection should reflect the capability of current controls to identify the failure before the defined harm, release, distribution, or use point. Consider coverage, sensitivity, independence, timing, sampling, automation, human reliance, alarm response, validation, and historical control performance.
What factors should override RPN?
Priority overrides commonly include credible serious patient harm, critical severity, sterility or contamination risk, identity or strength mix-up, significant data-integrity concern, regulatory or reporting obligations, recall potential, distributed product, recurrence, ineffective prior CAPA, systemic exposure, and major uncertainty.
What is residual risk in CAPA?
Residual risk is the risk remaining after approved actions have been implemented and verified. It should be reassessed using the same defined scales, supported by objective evidence, evaluated for new hazards, accepted by authorized roles, monitored through effectiveness measures, and reviewed when conditions change.
Does a lower residual RPN prove CAPA effectiveness?
No. A lower residual RPN is a prospective assessment based on expected control performance. CAPA effectiveness requires actual evidence that controls operate as intended, recurrence or escape is reduced, process performance improves, no unacceptable new risk appears, and predefined criteria are met.
When should an FMEA be reviewed or updated?
Review FMEA after significant deviations, complaints, failures, ineffective CAPA, process or product changes, new equipment or suppliers, validation findings, audit or inspection observations, adverse trends, new scientific knowledge, control failure, or at the approved periodic frequency.
What is required before approving a CAPA risk decision?
Confirm that scope, evidence, failure modes, effects, causes, controls, ratings, calculations, uncertainty, overrides, priority, actions, residual risk, monitoring, review triggers, and data integrity are documented; required experts have contributed; and authorized Quality and governance roles have approved the decision.
Primary regulatory references
