Week 2 — Sep 21: Risk Management
(Lecture 2.) Week 1 argued that a method is a hypothesis about a molecule and that the discipline is built to revise it when the evidence says so. This week asks the question that sits underneath every method, every specification, and every study design in the course: how much evidence is enough, and how do you decide? The answer is risk — assessed explicitly, not by reflex.
The one idea
Two principles govern quality risk management: the evaluation of risk is grounded in scientific knowledge and ultimately links to protection of the patient; and the level of effort, formality, and documentation is proportionate to the level of risk.
Every analytical decision spends a finite budget of time, money, and attention. Risk management is how you point that budget at the failures that would actually hurt a patient, and stop gold-plating the ones that wouldn’t. It is the machinery behind “scientifically justified” — the phrase that appears in almost every ICH guideline and is doing a lot of quiet work.
The ICH Q9 framework
ICH Q9(R1) — Quality Risk Management (the R1 revision, adopted 2023, added guidance on subjectivity, the hazard-versus-risk distinction, formality, and risk-based decision-making). The process is a loop, not a form:
| Stage | What happens | Analytical example |
|---|---|---|
| Risk assessment — identification | What could go wrong? | A co-eluting degradant is not resolved from the API |
| Risk assessment — analysis | How likely, how severe, how detectable? | Estimate occurrence from forced-degradation data; severity from the degradant’s qualification threshold; detection from method specificity |
| Risk assessment — evaluation | Is that acceptable against defined criteria? | Compare against a risk threshold agreed before the assessment |
| Risk control — reduction | Change the design to lower likelihood or raise detection | Switch to an orthogonal column; add a peak-purity check |
| Risk control — acceptance | Some residual risk is accepted, explicitly and on the record | Document the residual and the justification |
| Risk communication | The assessment and decisions are shared with everyone who acts on them | The control strategy, the filing, the SOP |
| Risk review | Revisit when something changes | A new impurity at month 9 of stability reopens the assessment |
Two ideas from Q9(R1) matter for the analyst:
- Hazard is not risk. A hazard is the potential to cause harm; risk combines the probability of that harm with its severity. “This solvent is toxic” is a hazard statement; “at the residual level this method can detect, the exposure is X% of the PDE” is a risk statement.
- Formality is a dial, not a switch. A one-line rationale, a risk-ranking table, and a full cross-functional FMEA are all valid quality risk management — the guideline asks you to match the formality to what is at stake, and to say why.
The toolbox
| Tool | Best for | Notes |
|---|---|---|
| FMEA / FMECA | Failures of a process or method built from many steps | The workhorse in analytical development — detailed below |
| Fault tree analysis (FTA) | Working backward from one defined failure to its contributing causes | Good for OOS root-cause work |
| HACCP | Identifying and controlling critical points in a process | Origin in food safety; maps well to manufacturing |
| HAZOP | Deviations from design intent, guided-word by guided-word | More common in process/engineering than in the QC lab |
| Risk ranking and filtering | Comparing many risks that don’t share a scale | Portfolio-level and site-level decisions |
| Ishikawa (fishbone) / PHA | Structuring a first-pass hazard identification | Often the front end of an FMEA |
FMEA in detail
Failure Mode and Effects Analysis decomposes a method or process into steps, and for each step asks: what could fail (failure mode), what would that do (effect), why would it happen (cause), and how would we catch it (controls). Each mode is scored:
Risk Priority Number = Severity × Occurrence × Detection
- Severity — how bad the effect is for the patient or the decision (a wrong release decision scores high; a re-run scores low).
- Occurrence — how often the cause is expected to produce the failure.
- Detection — how likely the existing controls are to catch it before it matters. High detection score = poorly detected — this scale runs backward, and it is where most FMEAs go wrong.
Modes with a high RPN, or a high severity regardless of RPN, get an action; then the mode is re-scored to show the action worked.
Known weaknesses — worth teaching so students don’t over-trust the number:
- RPN is an ordinal product treated as if it were interval data; an RPN of 100 is not “twice as bad” as 50, and different (S, O, D) triples give the same RPN with very different meaning.
- Detection and occurrence are often guessed. Q9(R1) explicitly flags this subjectivity and asks for it to be managed (defined scales, cross-functional scoring, documented assumptions).
- Many programs now supplement or replace RPN with a severity-first criticality matrix, or with risk ranking and filtering.
From risk assessment to control strategy
A control strategy is the planned set of controls — derived from current product and process understanding — that assures performance and quality. It is the output of risk management, not a separate exercise:
- Attribute risk assessment decides which quality attributes are critical (CQAs) and therefore need a specification and a method.
- Method risk assessment (an FMEA against the analytical target profile) decides which method parameters need to be controlled, and how tightly — this is where a robustness study is a risk-control activity, not a validation checkbox.
- The specification (Q6) and the stability program (Q1) are risk decisions in numeric form.
- Under the analytical procedure lifecycle, what counts as a reportable change to a method is set by the risk it carries.
Worked example — nitrosamine risk assessments. Between 2018 and 2023 every marketing authorization holder had to assess every product for the risk of N-nitrosamine impurities (NDMA, NDEA, and drug-specific nitrosamines), triggered by the valsartan recalls. The assessment is a textbook QRM: identify the hazard (potent mutagenic carcinogens), analyze the risk (synthetic route, nitrite sources, secondary amines, recovered solvents, water; then confirmatory testing), control it (route changes, nitrite scavengers, tightened limits at ppb levels), and communicate it (to the agency, on a deadline). It also shows the analyst’s exposure directly: the risk conclusion depended entirely on whether a method existed that could see a nitrosamine at its acceptable intake — a detection problem.
The risk-homework thread
Several of the technique weeks that follow — elemental impurities, molecular spectroscopy, mass spectrometry — carry a risk-assessment assignment: take the method taught that week and build a method FMEA against a stated analytical target profile. The point is repetition: by the machine-learning week, scoring detectability should be a habit.
Where the analyst sits
In almost every method FMEA, the analyst is the only person in the room who knows the true detection score. A project manager can estimate severity; a process chemist can estimate occurrence; but whether the current controls would actually catch a failed extraction, a mis-integrated peak, a drifting calibration, or a co-eluting impurity before it reached a release decision is analytical knowledge, and if the analyst rounds it toward “we’d probably catch it,” the whole assessment is quietly wrong.
This is the STEAM “A” again: judgment about what the evidence can and cannot rule out. The refrain for the term — science → evidence → reduced uncertainty → control → regulatory confidence → patient trust — runs through the risk assessment. Risk management is just the accounting that keeps the reduction in uncertainty pointed at the patient.
For discussion
- A method FMEA gives a mis-integration failure mode an RPN of 90 (S=9, O=2, D=5) and a wrong-diluent failure mode an RPN of 90 (S=5, O=3, D=6). Should they get the same attention? What does RPN hide here?
- Your detection score for “co-eluting unknown degradant” depends on data you don’t have yet (forced degradation isn’t finished). How do you score it now, and what do you commit to?
- “Level of formality proportionate to risk” — give an analytical decision you would document in one sentence, and one you would take to a formal cross-functional FMEA. What separates them?
- The nitrosamine assessments concluded “no risk” for many products on the strength of a purge argument, with no confirmatory testing. When is a scientific argument enough, and when do you need the number?
- A robustness study is often run at the end of validation, as a formality. What changes if you run it during development as a risk-control activity instead?
- Who should own the residual risk that a risk assessment explicitly accepts — the analyst, QA, the project? What goes wrong with each answer?
Source note. Anchored in ICH Q9(R1) Quality Risk Management, with ICH Q8(R2), Q10, and Q14 for how risk feeds the control strategy and the analytical procedure lifecycle. FMEA methodology follows IEC 60812 and the AIAG-VDA FMEA handbook. The nitrosamine case follows the EMA/FDA guidance and Article 5(3) referral outcomes. (Instructor: confirm the Q9(R1) adoption date and the current EMA nitrosamine guidance revision before lecture; check whether a “risk homework” assignment is being carried this year.)