Risk assessment in pharma has moved from a best-practice recommendation to a formally named, checked requirement. Revised Schedule M (notified December 2023) explicitly introduces Quality Risk Management (QRM) as one of its core new pillars, alongside the Pharmaceutical Quality System and Product Quality Review.
What real QRM looks like, vs. a narrative paragraph
Many quality systems have a risk-management SOP that describes the concept of risk assessment in prose, without ever producing a structured, trackable risk record tied to a specific decision. Real QRM, per ICH Q9's framework (the model revised Schedule M draws from), means:
- A structured method (risk matrix, FMEA, or similar) applied consistently, not ad hoc.
- Risk identification tied to a specific decision — a change control, a supplier qualification, a deviation — not a standalone annual exercise disconnected from real operations.
- Documented risk scoring (severity, likelihood, detectability) rather than a subjective "low/medium/high" label with no visible reasoning.
- A risk-based decision that's traceable — why was this action taken, given this assessed risk level?
Where QRM should actually appear
The places risk assessment most concretely belongs — and where its absence is most visible to an inspector — are change control (does this change require re-qualification, and how risky is it if it doesn't get one?), supplier qualification (how much oversight does this supplier's risk profile warrant?), and deviation handling (how significant is this deviation's potential impact?).
A generic risk-assessment SOP isn't QRM
A document stating "we assess risk" without a structured, repeatable method and a visible trail of actual risk decisions doesn't satisfy what revised Schedule M's QRM requirement is checking for. Inspectors increasingly ask to see the risk assessment behind a specific decision, not the policy that describes risk assessment in the abstract.
Ready to see this in your own lab? Book a free ValiCore demo.