1
Quality Risk Management
QRM
Part-1
2
Speaker – Mohamed Ismail,
Pharmaceutical Quality Consultant
• Industry Expert in Pharma Manufacturing and Quality at
Multi-national pharmaceutical companies
• Work experience:
• Pharmaceutical Process Development & quality system compliance
• Design of Pharma Plants (Project Head)
• Designed plants for Rameda, Mash, Adwia, Otsuka etc.
• Project Manager for the first decontamination process in Egypt for
cephalosporin area of GSK
3
INTRODUCTION
•Risk management principles are effectively utilized in many areas of business and government
including finance, insurance, occupational safety, pharmacovigilance, public health.
•Importance of quality systems has been recognized in the pharmaceutical industry and it is becoming
evident that quality risk management is a valuable component of an effective quality system.
•The manufacturing and use of a drug product, including its components necessary entail some degree
of risk, among them the quality risk is just one component..
•Effective QRM can facilitate better and more informed decisions, can provide regulators with greater
assurance of a company’s potential risks and can beneficially affect the extent and level of direct
regulatory oversight.
4
SCOPE
•The QRM can be applied to various pharmaceutical aspects throughout the product lifecyle
of drug substances, drug products, biological and biotechnological products.
•The different aspects are :-
development,
manufacturing,
distribution,
inspection,
process and submission process.
5
PRINCIPLES OF QRM
Two primary principles of QRM are :
•The evaluation of the risk to quality should be based on scientific knowledge and
ultimately link to the protection of the patient ;
•The level of effort, formality, and documentation of the quality risk management
process should be commensurate with the level of risk.
SOURCES OF QULAITY RISKS:
•System risk(facility & people) - e.g. interfaces, operation risks
•System risk(organization) -e.g. quality systems, controls
•Process risk - e.g. process operations and quality parameters
•Product risk(safety and efficacy) - e.g. quality attributes
6
Overview of QRM process
Initiate Quality Risk
Management Process
RISK ASSESSMENT
•Risk identification
RISK MANAGEMENT TOOLS
•Risk analysis
RISK COMMUNICATION
•Risk evaluation
unacceptable
RISK CONTROL
•Risk reduction
•Risk acceptance
Output/result of the quality risk
management process
RISK REVIEW
Review events
7
GENERAL QUALITY RISK MANAGEMENT PROCESS
Quality risk management is a systematic process for the assessment, control,
communication, and review of risks to the quality of the drug product across the product
lifecycle.
It includes:-
•Responsibilities
•Initiating a QRM process
•Risk assessment
•Risk control
•Risk communication
•Risk review
8
RESPONSIBILITIES
When teams are formed, they should include experts from the appropriate areas, in
addition to individuals who are knowledgeable about the QRM process.
Decision makers should –
•Take responsibility for coordinating QRM across various functions and departments
of their organization;
•Assure that a QRM process id defined, deployed, and reviewed that adequate
resources are available.
9
INITIATING QUALITY RISK MANAGEMENT PROCESS
QRM should include systematic processes designed to coordinate, facilitate and
improve science-based decision making with respect to risk.
Possible steps used to initiate and plan a QRM are :-
•Define the problem/risk, including pertinent assumptions identifying the potential for
risk.;
•Assemble background information and/or data on the potential hazard, harm or
human health impact relevant to the risk assessment;
•Identify a leader and necessary resources;
•Specify a timeline, deliverables and appropriate level of decision making for the risk
management process.
10
RISK ASSESSMENT
Risk assessment consists of identification of the hazards and the analysis and
evaluation of potential [Link] process begins with a well defined problem
description or risk questions. The fundamental questions are :
1. What might go wrong?
2. What is the likelihood (probability) it will go wrong?
3. What are the consequences (severity)?
Risk identification is a systematic use of information to identify hazards referring
to the risk question or problem description.
Risk analysis is the estimation of the risk associated with the identified hazards. It
is the qualitative or quantitative process of linking the likelihood of occurrence and
severity of hazards.
Risk evaluation compares the identified and analyzed risk against given criteria.
Risk evaluation consider the strength of evidence of all three of the fundamental
questions.
In doing an effective risk assessment , the robustness of the data set is
important because it determines the quality of the output.
11
RISK CONTROL
Risk control includes decision making to reduce and/or accept risks. The purpose of
risk control is to reduce the risk to an acceptance level. The amount of effort used for
risk control should be proportional to the significance of the risk.
Risk control might focus on the following points :-
•Is the risk above an acceptable level?
•What can be done to reduce or eliminate risks ?
•What is the appropriate balance among benefits, risks and resources ?
•Are new risks introduced as a result of the identified risks being controlled ?
Risk reduction focuses on process for mitigation or avoidance of quality risk when
it exceeds a specified level. It might include actions taken to mitigate the severity and
probability of harm, processes that improve the detect ability of hazards and quality
risks .
Risk acceptance is a decision to accept risk. Risk acceptance can be a formal
decision to accept the residual risk or it can be a passive decision in which residual
risks are not specified.
12
RISK COMMUNICATION
Risk communication is the sharing of information about risk and risk management
between the decision makers and the others. The output/result of the QRM process
should be appropriately communicated and documented.
Communications might include those among interested parties e.g. Regulators and
industry, industry and the patient, within a company, industry or regulatory authority,
etc.
RISK REVIEW:
•Risk management should be an ongoing part of the quality management system. A
mechanism to review or monitor events should be implemented. The outputs/results of
the risk management should be reviewed to take into account new knowledge and
experience.
•The frequency of any review should be based upon the level of risk. Risk review
might include reconsideration of risk acceptance decisions.
13
RISK MANAGEMENT METHODOLOGY
•Quality risk management provides a scientific and practical approach to decision
making.
•It provides documented, transparent and reproducible methods to accomplish steps of
the QRM process based on current knowledge about assessing the probability,
severity, and sometimes detectability of the risk.
•Traditionally, risks of quality have been assessed and managed in various informal
ways(empirical and/or internal procedures) based on, compilation of observations,
trends, and other information.
•In addition , the pharmaceutical industry and regulators can assess and manage risk
using recognized risk management tools such as standard operating procedures
(SOPs).
14
RISK MANAGEMENT TOOLS
Basic risk management facilitation methods
(flowcharts, check sheets, etc.)
Failure mode effect analysis (FMEA)
Fault tree analysis (FTA)
Hazard analysis and critical control points (HACCP)
Hazard Operability Analysis (HAZOP)
Preliminary hazard analysis (PHA)
Risk ranking and filtering
Supporting statistical tools.
15
Failure Modes Effect
Analysis
(FMEA)
16
Learning Objectives
To understand the use of Failure Modes
Effect Analysis (FMEA)
To learn the steps to developing FMEAs
To summarize the different types of FMEAs
To learn how to link the FMEA to other
Process tools
17
Benefits
Allows us to identify areas of our process that most
impact our customers
Helps us identify how our process is most likely to fail
Points to process failures that are most difficult to
detect
18
Application Examples
Manufacturing: A manager is responsible for moving a
manufacturing operation to a new facility. He/she wants
to be sure the move goes as smoothly as possible and
that there are no surprises.
Design: A design engineer wants to think of all the
possible ways a product being designed could fail so
that robustness can be built into the product.
Software: A software engineer wants to think of possible
problems a software product could fail when scaled up
to large databases. This is a core issue for the Internet.
19
What Is A Failure Mode? What Can Go
Wrong?
A Failure Mode is:
The way in which the component, subassembly,
product, input, or process could fail to perform its
intended function
Failure modes may be the result of upstream
operations or may cause downstream operations
to fail
Things that could go wrong
20
FMEA
Why
Methodology that facilitates process improvement
Identifies and eliminates concerns early in the development
of a process or design
Improve internal and external customer satisfaction
Focuses on prevention
FMEA may be a customer requirement (likely contractual)
FMEA may be required by an applicable
Quality Management System Standard (possibly ISO)
21
FMEA
A structured approach to:
Identifying the ways in which a product or process can fail
Estimating risk associated with specific causes
Prioritizing the actions that should be taken to reduce risk
Evaluating design validation plan (design FMEA) or current
control plan (process FMEA)
22
When to Conduct an FMEA
Early in the process improvement investigation
When new systems, products, and processes are being
designed
When existing designs or processes are being changed
When carry-over designs are used in new applications
After system, product, or process functions are defined, but
before specific hardware is selected or released to
manufacturing
23
History of FMEA
Examples
First used in the 1960’s in the Aerospace industry during
the Apollo missions
In 1974, the Navy developed MIL-STD-1629 regarding the
use of FMEA
In the late 1970’s, the automotive industry was driven by
liability costs to use FMEA
Later, the automotive industry saw the advantages of
using this tool to reduce risks related to poor quality
A Closer Look
24
The FMEA Form
Identify failure modes Identify causes of the Prioritize Determine and assess
and their effects failure modes actions
and controls
25
Types of FMEAs Specialized
Uses
Design
Analyzes product design before release to production, with
a focus on product function
Analyzes systems and subsystems in early concept and
design stages
Process
Used to analyze manufacturing and assembly processes
after they are implemented
26
FMEA: A Team Tool Team Input
Required
A team approach is necessary.
Team should be led by the Process Owner who is the
responsible manufacturing engineer or technical person,
or other similar individual familiar with FMEA.
The following should be considered for team members:
– Design Engineers – Operators
– Process Engineers – Reliability
– Materials Suppliers – Suppliers
– Customers
27
FMEA Procedure Process Steps
1. For each process input (start with high value inputs),
determine the ways in which the input can go wrong
(failure mode)
2. For each failure mode, determine effects
• Select a severity level for each effect
3. Identify potential causes of each failure mode
• Select an occurrence level for each cause
4. List current controls for each cause
• Select a detection level for each cause
28
FMEA Procedure (Cont.) Process Steps
5. Calculate the Risk Priority Number (RPN)
6. Develop recommended actions, assign responsible
persons, and take actions
• Give priority to high RPNs
• MUST look at severities rated a 10
7. Assign the predicted severity, occurrence, and detection
levels and compare RPNs
29
FMEA Inputs and Outputs Information
Flow
Inputs Outputs
C&E Matrix List of actions to
Process Map prevent causes or
Process History detect failure
Procedures FMEA modes
Knowledge
Experience History of actions
taken
30
Severity, Occurrence, and Detection Analyzing
Failure &
Effects
Severity
Importance of the effect on customer requirements
Occurrence
Frequency with which a given cause occurs and
creates failure modes (obtain from past data if possible)
Detection
The ability of the current control scheme to detect
(then prevent) a given cause (may be difficult to estimate early in
process operations).
31
Rating Scales Assigning
Rating Weights
There are a wide variety of scoring “anchors”, both
quantitative or qualitative
Two types of scales are 1-5 or 1-10
The 1-5 scale makes it easier for the teams to decide on
scores
The 1-10 scale may allow for better precision in estimates
and a wide variation in scores (most common)
32
Rating Scales Assigning
Rating Weights
Severity
1 = Not Severe, 10 = Very Severe
Occurrence
1 = Not Likely, 10 = Very Likely
Detection
1 = Easy to Detect, 10 = Not easy to Detect
33
Risk Priority Number (RPN) Calculating a
Composite Score
RPN is the product of the severity, occurrence, and detection
scores.
Severity X Occurrence X Detection = RPN
34
Summary Key Points
An FMEA:
Identifies the ways in which a product or process can fail
Estimates the risk associated with specific causes
Prioritizes the actions that should be taken to reduce risk
FMEA is a team tool
There are two different types of FMEAs:
Design
Process
Inputs to the FMEA include several other Process tools such as C&E
Matrix and Process Map.
FMECA- FMEA can be extended to incorporate an investigation of the degree of
severity of the consequences, their respective probabilities of occurrence, and their
detectability, thereby becoming a Failure Mode, Effects and Criticality Analysis
(FMECA).
35
The Hazard Analysis
Critical Control Point
(HACCP)
36
What is HACCP??
A systematic approach to the identification, evaluation, and
control of food safety hazards.
system is based on assessing the natural hazards or risks in a
particular product or process and designing a system to control
them.
37
38
The HACCP Plan
The HACCP Plan is the written document which is based upon
the principles of HACCP and which delineates the
procedures to be followed.
39
Developing a HACCP Plan
The format of HACCP plans will vary depending on the
product and process.
In the development of a HACCP plan, five preliminary tasks
need to be accomplished before the application of the
HACCP principles to a specific product and process.
40
The five preliminary tasks are
Assemble the HACCP Team
Describe the Food and its Distribution
Describe the Intended Use and Consumers of the Food
Develop a Flow Diagram Which Describes the Process
Verify the Flow Diagram
41
42
The general principles of HACCP
1. Hazard Analysis
2. Identify Critical Control Points .
3. Establish Critical Limits
4. Monitor the CCP's
5. Establish Corrective Action
6. Record keeping
7. Verification
43
44
Hazard Analysis
Hazards :biological, chemical, and physical which are
conditions cause a health risk to the consumer.
In order to conduct the hazard analysis a flow diagram of the
complete process is important.
45
Identify critical control points
CCP’S are the points in a food's production (from its raw state
To consumption) at which the potential hazard can be
controlled or eliminated.
46
Establish Critical Limits
Establish preventive measures with critical limits for each
control point.
47
Monitor the CCP's
Monitoring: is a planned sequence of measurements
or observations to ensure the product or process is in
control.
48
Establish Corrective Action
Establish corrective actions ( for the product or process)
when monitoring shows that a critical limit has loss of
control .
49
Record keeping
The HACCP system requires the preparation and
maintenance of a written HACCP plan together with other
documentation. This must include all records generated
during the monitoring of each CCP and notations of
corrective actions taken.
50
Verification
Verification :is the activities that determine the validity of the
HACCP plan and that the system is operating according to the
plan .
Verification activities are carried out by individuals within a
company, experts team, and regulatory agencies
51
Fault Tree Analysis
(FTA)
52
Fault Tree Analysis (FTA)
Assumes failure of the functionality of a product or process
Identifies all potential root causes of an assumed failure or
problem that it is thought to be important to prevent
Evaluates system (or sub-system) failures one at a time
Can combine multiple causes by identifying causal chains
ICH Q9
53
Fault Tree Analysis (FTA)
How to perform?
Results are represented
pictorially
in the form of a tree of fault
modes
At each level in the tree,
combinations of fault modes
are described with logical
operators (AND, OR, etc.)
ICH Q9
54
Fault Tree Analysis (FTA)
Basic symbols: Basic Flow
• Fault in a box indicates
FAULT that it is a result of previous faults
• Connects preceding fault with a subsequent
OR fault that could cause a failure
• Connects two or more faults that must occur
AND simultaneously to cause the preceding fault
ICH Q9
55
Fault Tree Analysis (FTA)
Basic symbols: End Points & Connector
Root cause
• Root cause (= basic fault)
(e.g. part failure, software error, human error)
• Fault to be further analyzed with more time or
information if needed
• Transfer-in and transfer-out events
ICH Q9
56
Fault Tree Analysis (FTA)
Additional Symbols
• Exclusive OR Gate:
Fault occurs if only one of the input faults
occurs
• Priority AND Gate:
Fault occurs if all inputs occur in a certain
order
• Voting OR Gate:
m Fault occurs if “m” or more out of “n” input
faults occurs
57
Fault Tree Analysis (FTA)
Potential Areas of Use(s)
Establish the pathway to the root cause of the failure
While investigating complaints or deviations to fully
understand their root cause
Ensure that intended improvements will fully resolve the
issue and not lead to other issues
Evaluating how multiple factors affect a given issue
ICH Q9
58
Fault Tree Analysis (FTA)
Investigation of laboratory failures
Production outlier Calibration
Out of specification
result or Lab error or systematic or Interfaces
others random other
ICH Q9
59
Fault Tree Analysis (FTA)
Hard to open
or
Producti Stabilit
on
Cap Bottle
y
or Bad fit and
Formulati Processi Packagin
on ng g
Solidify Ageing
or
Too Change closing torque ICH Q9
Supply and calibrate periodically
tightly
Defect
Closed
60
Fault Tree Analysis (FTA)
Experiences
Better as a retrospective tool
Visually focused: aid for showing linkages
Limitations
Only as good as input
Time and resource consuming (needs FMEA as a complement )
Need skilled leader to focus on what is really important
Need significant amount of information
Human errors may be difficult to predict
Many potential fault trees for a system
- Some more useful than others
- Need to evaluate contribution
ICH Q9
61
Failure Mode Effects Analysis (FMEA)
Fault Tree Analysis (FTA)
FTA FMEA
Assumes Assumes
failure of the functionality component failure
of a product
Identifies the root cause Identifies functional
of functional failure failure as a result of
component failure
Top down Bottom up
62
Preliminary Hazard
Analysis
(PHA)
63
Preliminary Hazard Analysis
(PHA)
(Analysis based on applying prior experience or knowledge
of a hazard or failure to identify future hazards, hazardous
situations and events that can cause harm
In estimating their probability of occurrence for a given
activity, facility, product or system
How to perform?
Identification of the possibilities that the risk event happens
Qualitative evaluation of the extent of possible
injury or damage to health that could result
Identification of possible remedial measures
ICH Q9
64
Preliminary Hazard Analysis
(PHA)
One aspect worth highlighting is the development of a risk matrix to
facilitate categorization of risks identified during the risk assessment phase. In
order to prioritize a risk, it is essential to agree upon its significance. The risk
associated with any situation or event can be represented as the impact of that
event multiplied by the probability of its occurrence; in other words: how likely is
it to happen? and how severe would it be if it did happen? Impact and
probability
can each be classified, e.g. into 5 levels (1–5) or with a weighting towards the
higher probability and impact ratings (e.g. 1, 3, 5, 7, 10, etc.), so that a grid or
matrix can be constructed (Table 1).
WHO-trs-981
Annex-2
65
Preliminary Hazard Analysis
(PHA)
Table 1
An example of a probability versus impact matrix
Impact
Probability Negligible Marginal Moderate Critical Catastrophic
(1) (2) (3) (4) (5)
Almost certain (5) 5 10 15 20 25
Likely (4) 4 8 12 16 20
Possible (3) 3 6 9 12 15
Unlikely (2) 2 4 6 8 10
Rare (1) 1 2 3 4 5
Low Risk Medium Risk High Risk
WHO-trs-981
Annex-2
66
Preliminary Hazard Analysis
(PHA)
The shading in the table represents an example of how the risk
values (sometimes called composite risk indices or risk index
values) can be assigned a high, medium or low status. The
definition for each status should be predetermined in the QRM
process after consideration of the specific consequences for the
process undergoing risk assessment. These consequences can be
split according to the probability and impact scores, as
exemplified in Table 2.
WHO-trs-981
Annex-2
67
Preliminary Hazard Analysis
(PHA)
Table 2
Example of a consequences table for probability and impact
Score Probability Example Score Impact Consequence
1 Seen every 1 - No regulatory issue
Rare 10-30 years Negligible - No effect on and not noticeable by
patient
2 Seen every 2 - May require EDA notification
Unlikely 5-10 years Marginal - Decision to release product not
compromised
3 Seen every 3 - EDA inspection may identify a major
1-5 years concern but deficiency quite easily
Possible Moderate
resolved
- Limited product recall possible
4 Seen to occur more 4 - EDA inspection may conclude serious
than once a year non-compliance
Likely Critical
- Likely product recall form one or more
markets
5 Seen several times a 5 - Enforcement action by EDA such as
Almost
year Catastrophic consent decree, product seizure
certain
- Global product recall
WHO-trs-981
Annex-2
68
Preliminary Hazard Analysis
(PHA)
This table is a very basic example and would need to be
customized for the specific process in question to enable a better
and more practical definition of the consequence categories. It
should be cautioned that the value of a risk matrix relies very
heavily upon input information and should only be used by staff
with a good understanding of the embedded judgements and,
as such, the resolution of the low, medium or high categorization.
Risk Index Value (RIV) (for immediate action & mitigation)
Risk Index Value (RIV) = Consequence (Impact of Risk Event) X Likelihood (Probability of occurrence)
WHO-trs-981
Annex-2
69
RISK MANAGEMENT TOOLS
Risk ranking and filtering is a tool for comparing and ranking risks. Risk ranking of
complex systems typically involves evaluation of multiple diverse quantitative and
qualitative factors for each risk.
Supporting tools can support and facilitate QRM .Commonly used tools in the
industry are:
•Control charts
•Design of experiments (DOE)
•Histograms
•Pareto charts
•Process capability analysis.
QRM methods and the supporting statistical tools can be used in combination
(e.g. Probabilistic Risk Assessment).The degree of rigor and formality of QRM
should reflect available knowledge and can be commensurate with the complexity
and/or criticality of the issue to be addressed.
70
Integration of QRM into Industry And Regulatory
Operations
•QRM is a process that supports science based and practical decisions
when integrated into quality systems.
•Training of both industry and regulatory personnel in quality risk
management processes provides for greater understanding of decision
making processes and builds confidence QRM outcomes.
•QRM should be integrated into existing operations and documented
appropriately.
71
POTENTIAL APPLICATIONS FOR QRM
• Quality risk management as part of Integrated quality management
• Quality risk management as part of Regulatory operations
• Quality risk management as part of Development
• Quality risk management for Facilities, Equipment and Utilities
• Quality risk management as part of Materials Management
• Quality risk management as part of Production
• Quality risk management as part of Laboratory control and Stability studies
• Quality risk management as part of Packaging and Labelling
72
QRM as a part of Regulatory Operations
Inspection and assessment activities
•To assist with resource allocation including inspection planning and frequency and
inspection and assessment intensity.
•To evaluate the significance of quality defects, potentials recalls, and inspectional
findings.
•To determine the appropriateness and type of post inspection regulatory follow-up.
•To evaluate information submitted by industry including pharmaceutical
development information.
•To evaluate impact of proposed variations or changes .
•To identify risks that should be communicated between inspectors and assessors to
facilitate better understanding of how to control the risks.
73
CONCLUSION
While regulatory decisions will continue to be taken in a regional basis, a
common understanding and application of quality risk management
principles could facilitate mutual confidence and promote more consistent
decisions among regulators. So by following a common guideline and
process of Quality Risk Management an effective practice can be
performed in the industry and throughout various nations.
74
REFRENCES
• ICH Harmonized Tripartite Guideline – Quality Risk Management-Q9
([Link]/Q9/Q9_Guideline)
• Quality Risk Management ICH Q9 Annex I : Method & Tools.
• Quality Risk Management ICH Q9 Annex II: Potential Applications.
• ICH Q9 Guideline on Quality Risk – European Medicines Agency- Europa EU
([Link])
• ICH Q9 & ISO 14791 – By Michael Kerr ([Link]/chapters/ireland)
• WHO trs-981 Annex-2
75
THANKYOU