QMS & eQMS

If CAPA, Change Control, and Controlled Documents Don't Talk to Each Other, the Next Deviation Falls Through the Cracks

Quality processes rarely operate in isolation. Learn how disconnected deviations, CAPAs, changes, controlled documents, training, and effectiveness checks create gaps that allow the same problems to return.

A deviation rarely exists by itself. An employee follows an outdated inspection method. The investigation finds an unclear procedure. Corrective action changes the inspection process, which requires an SOP revision, training for affected staff, and follow-up to see whether the problem stopped.

That is one continuous quality story. In many organizations, though, it is spread across a deviation tracker, CAPA spreadsheet, email approvals, change-control form, document library, training matrix, and calendar reminders. Each process may exist. The risk appears when the process that comes next cannot see what happened before it, and a handoff depends on someone remembering to reconcile the records.

The central idea

Separate quality processes are appropriate. Separate quality stories are not.

Quality processes should be separate, but the story should not be

A deviation records and investigates an unexpected event. A CAPA addresses causes that warrant broader corrective action. Change control evaluates a planned change. Document control governs an approved procedure. Training helps affected people understand or perform the revised process. An effectiveness check evaluates whether the actions worked.

These processes have different purposes and decision points. A quality management workflow should preserve those distinctions while making relationships visible. Not every event requires every step. A minor event may need correction only; a systemic issue may require most of the chain.

The quality event chain

  1. Deviation / nonconformance
  2. Investigation
  3. Root cause
  4. Corrective action / CAPA, when warranted
  5. Risk assessment
  6. Change control, when needed
  7. Controlled document revision, if affected
  8. Training or qualification, as appropriate
  9. Implementation
  10. Effectiveness check
  11. Trending and management oversight

The point is not to make every event follow every box. It is to make the handoff visible whenever one activity triggers another, including the owner, status, due date, and evidence needed to close it.

Five places the chain commonly breaks

  1. CAPA says “revise the SOP,” but nobody owns the revision.The action is marked complete when a request is submitted, although the document is still a draft, approval is pending, or the old version remains active. Initiating a change is not implementing it.
  2. The SOP changes, but training does not follow.Someone must identify affected roles, decide whether retraining is needed, assign it, and establish whether training must precede the changed work. A controlled revision alone does not complete that handoff. See training versus demonstrated competency.
  3. Change control closes before implementation is complete.The document is approved and a system updated, but validation, supplier communication, qualification, training, or monitoring remains open. A status label should reflect the defined implementation criteria.
  4. The effectiveness check lives somewhere else.A six-month follow-up is put on one person’s calendar. The CAPA closes, the reminder owner changes roles, and evidence that the action worked is never collected. The check needs an owner, timing, method, and linked result.
  5. The same problem returns under a different name.“Incorrect inspection technique,” “procedure not followed,” and “training issue” may describe the same recurring failure mode. Linked records and consistent categorization help quality teams see patterns. Effective root cause analysis looks beyond the label.

A broken quality chain in practice

An operator uses an outdated acceptance criterion. The investigation discovers that the procedure was revised and training assigned, but one employee had not completed it. An obsolete reference sheet also remained at the workstation.

CAPA actions include removing obsolete sheets, improving document access at point of use, revising the training-assignment process, and checking similar procedures for the same risk. The CAPA is in one spreadsheet, the SOP in SharePoint, training in another tracker, and workstation cleanup is handled informally. The effectiveness date sits on a calendar.

Four months later, the CAPA says closed. The revision is effective. Most employees are trained. Yet obsolete material remains in another area, and another deviation occurs. The issue was not necessarily the CAPA method. No record or review showed that every relevant action in the corrective-action chain was complete.

CAPA completion is not the same as effectiveness

A weak check asks: “Was the SOP revised and training completed?” Those are implementation measures. A stronger check asks whether the intended result occurred: Are current criteria used at every point of use? Have affected employees demonstrated the required task, where appropriate? Did comparable deviations recur during a defined period or sample? Were there enough opportunities to judge the outcome?

Define the method when the action is planned. Depending on risk, evidence might include record sampling, observation, trend review, or a targeted audit. Set a period and acceptance criteria that make sense for the process. If the sample is too small or the issue has not had a chance to recur, the result may be inconclusive rather than effective.

Not every CAPA needs a formal change-control record, and not every corrective action requires an SOP revision. Use documented, risk-based criteria to determine the right path. The key is to show what was decided, why, and how implementation and effectiveness were evaluated.

What should an integrated QMS let you see?

A reviewer should be able to follow the relationships: this deviation led to this investigation; this cause supported this action; this action required this change; the change revised these documents; these people required training; this check evaluated the result. The record should show ownership, approvals, dates, open dependencies, and evidence without relying on institutional memory.

If answering “which procedure changed?” or “how was effectiveness established?” means opening several trackers and asking multiple people, the information may exist but traceability is fragile. That can complicate oversight and QMS audit readiness. A QMS can use multiple systems; the important question is whether relationships and controls are maintained reliably.

Make each handoff explicit

For every transition, define the trigger, the accountable owner, the decision to be recorded, and the evidence that permits closure. For example, a CAPA action that requires a document change should link to the change record and remain open until the defined implementation criteria are met. If training is required, identify affected roles and capture completion before people perform the changed work when risk calls for it.

Also decide how exceptions are handled. A justified decision that no change or retraining is needed can be recorded with its rationale, instead of leaving an unexplained gap. A delayed dependency should stay visible, with an owner and due date. These simple controls work whether records are held in one application or several governed systems.

Five signs your processes may be too disconnected

  1. CAPAs say “update SOP” without linking to the revision.
  2. Quality manually checks several systems to decide whether actions are complete.
  3. Document revisions and training assignments need manual reconciliation.
  4. Effectiveness checks depend on calendars or individual reminders.
  5. Similar events are classified differently, making recurrence hard to identify.
Self-check

If these patterns are common, the issue may be the handoffs between processes rather than missing individual procedures.

Integration should support judgment, not force bureaucracy

An integrated QMS does not mean deviation → mandatory CAPA → mandatory change → mandatory SOP → mandatory training for every event. A minor deviation may need correction only. A training misunderstanding may call for targeted support. A systemic process failure may warrant investigation, CAPA, controlled change, training, and effectiveness monitoring. A supplier issue may need supplier corrective action and risk reassessment.

Not every document change requires retraining, and training does not always require a formal competency qualification. Decisions should match the risk, process, and applicable requirements. Separate tools are not automatically a compliance problem, and no particular software platform is required for compliance. Risk rises when important handoffs rely mainly on memory and manual reconciliation.

The real value of an eQMS is not putting forms online

Digitizing a paper form can help. A broader opportunity is connecting quality processes so the organization can understand how an issue moves through the system. Replacing five spreadsheets with five electronic forms still leaves five separate stories if the records cannot show their relationships.

Athyrion is being designed around connected quality workflows. The intent is to connect related records across deviations, corrective actions, change control, document control, training, risk, audits, and supplier management. Product capabilities should be evaluated according to their current availability; this article describes the platform’s design direction, not a promise that every planned function is generally available today.

Follow the problem from detection to proof

  1. Detection
  2. Investigation
  3. Correction
  4. Change, when warranted
  5. Implementation
  6. Proof that the change worked

The individual processes can remain distinct. Their records should still tell one coherent story, so an unfinished handoff does not quietly allow the original problem to happen again.

Are your quality processes connected, or just stored in different places?

Athyrion is being designed to connect quality processes so deviations, corrective actions, change control, controlled documents, training, risk, audits, and supplier quality can tell one continuous quality story.