Guide
A modern guide to pharmaceutical deviation investigation

In brief
A deviation investigation asks four questions: What happened? What was affected? Why? What should change? Answering them means gathering and assembling evidence that already exists: the batch history, the related events, the material lots, the equipment, the records. Better access to that evidence can free investigators to focus on judgment rather than searching. This guide covers what belongs in an investigation, why assembling it takes so long, how batch genealogy supports it, and how governed agents can assemble the evidence without replacing expert judgment.
Key takeaways
- Most of an investigation's time goes to finding and assembling evidence, not to judging it.
- Scale root cause analysis to the risk. Rule out process, procedure, and system causes before naming human error
- Tie conclusions and follow-up to batch records, results, material lots, and equipment history.
- An investigation report that cites its sources is one a quality team can inspect.
What is a deviation investigation?
A deviation investigation is a structured review of a departure from an approved process or instruction. It asks what happened, what may have been affected, why it happened and what should change. The purpose is to support a sound decision about the product and prevent the problem from recurring.
A missed hold time or an out-of-range parameter may first appear in one batch record. To understand it, the investigator may also need test results, material and equipment history, and records from other batches. Those records help test possible explanations and show whether the issue reaches beyond the batch where it was found.
The investigation ends with a written account of the evidence, the conclusion and any follow-up action. Its depth should fit the risk, and a reviewer should be able to see how the team reached its decision. The specific GMP requirements are linked in Sources.
Why deviation investigations take so long
Putting that account together can take far longer than the hands-on work itself. In a 2017 BioPhorum survey, a minor deviation took about 29 calendar days to close but about 18 hours of active work. The figures are dated and do not explain every delay, but they show the difference between work time and elapsed time.
One source of effort is finding records, reconciling differences and documenting a trail a reviewer can follow. Depending on the event, that may involve:
- The executed batch record, often on paper or as a scan
- In-process and release results in a LIMS or lab reports
- Raw material lots and their certificates of analysis
- Equipment logs, calibration and maintenance records
- Environmental monitoring data
- Earlier deviations, changes and CAPAs for the same product, line or material
Those records may sit with different teams and in different systems. The investigator has to connect them.
The investigation, step by step
- Describe the event. What happened, when, where, on which batch, and what was done immediately.
- Assess impact and risk. Classify the deviation, decide whether product is affected and set the depth of investigation in proportion to the risk.
- Assemble the batch history. Gather the records for the affected batch and for any batches that share materials, equipment or timing.
- Identify possible causes. Generate explanations and list the evidence that would confirm or rule out each one.
- Test the explanations against the evidence. Compare the affected batch with similar batches and check the process, the materials, the equipment and the procedure.
- Determine the root cause. Conclude on the most likely cause, supported by evidence, or document why the cause could not be determined.
- Define corrective and preventive action. Address the cause, not only the symptom, and link the action to the CAPA system.
- Write and approve the report. Document the evidence, the reasoning, the conclusion and the actions for quality approval.
The batch history package
A standard batch history package gives each investigation a clear starting point. It helps the team see what is available, what is missing and what a reviewer will need.
| Evidence | What to look for | Typical location |
|---|---|---|
| Executed batch record | Step timing, parameters, corrections, comments, signatures | Paper or scanned record, or an electronic batch record |
| In-process and release results | Trends against specification and against similar batches | LIMS, lab reports |
| Raw material lots | Which lots were charged, their certificates, in-house testing | ERP, supplier certificates of analysis |
| Equipment records | Calibration status, maintenance, alarms, cleaning | Maintenance systems, logbooks |
| Environmental data | Excursions during the relevant time window | Monitoring systems |
| Related quality events | Earlier deviations, changes and CAPAs on the same product, line or material | Quality management system |
| Procedures | The version of the SOP and recipe in force at the time | Document management system |
Genealogy: following a material across batches
A material or equipment issue may reach beyond one batch. Genealogy helps identify batches that share a lot, equipment or intermediate so the investigator can assess the wider impact.
The trace can be difficult to build: material lots, batch use and supplier certificates often live in separate places. Connecting them lets an investigator follow a lot to the batches that used it and to its source certificate. The [Page on this site: Context Layer] is designed to support that view.
Root cause analysis methods and the evidence each needs
| Method | Best for | Evidence it depends on |
|---|---|---|
| Five whys | Simple, linear events | A clear sequence of events and the records that confirm each step |
| Fishbone (Ishikawa) diagram | Organizing possible causes by category: materials, methods, machines, people, measurement, environment | Evidence in each category to confirm or rule out causes |
| Fault tree analysis | Events with several contributing conditions | Data on the conditions that must occur together |
| Failure mode and effects analysis | Anticipating failures and prioritizing prevention | Process knowledge and historical failure data |
| Comparative (is / is not) analysis | Finding what distinguishes the affected batch from normal batches | Comparable data for affected and unaffected batches |
Every method is only as good as its evidence. A fishbone diagram with an empty "materials" branch is not a conclusion that materials were not involved; it may mean nobody pulled the certificates.
Common evidence gaps
- Human error as the default. Naming operator error without ruling out procedural or system causes, which EU GMP Chapter 1 explicitly discourages.
- Too narrow a search. Looking only at the affected batch and missing batches that share a material or equipment.
- Missing comparisons. Concluding a parameter was the cause without checking whether it varied the same way in batches that did not deviate.
- Unread paper. Missing a margin note or correction in the executed batch record that explains the event.
- Repeat events treated as new. Not linking the deviation to earlier ones with the same cause.
How AI could help investigators assemble and review evidence
AI could help with the time-consuming work of finding, organizing and comparing records. It might assemble a batch history, identify other batches that used the same material lot, or flag a missing result for the investigator to follow up.
It could also draft a summary that links each finding to its source and separates observed facts from possible explanations. That draft would need careful review. A missed note, poor scan or incorrect match could change the interpretation, and an unresolved gap should stay visible.
The investigator determines what the evidence means, whether other batches are affected, the cause and the response. Quality reviews and approves the investigation through the organization's process. AI supports that work; it does not make or approve the decision.
Measuring investigation performance
Track a small set of measures consistently, and look at the distribution rather than only the average.
- Time from deviation opened to investigation closed, by classification
- Time spent assembling evidence versus analyzing it
- Share of investigations extended past their due date
- Share of root causes attributed to human error
- Repeat deviation rate for the same cause
- CAPA effectiveness at the defined check
Questions
- What is the difference between a deviation investigation and a CAPA?
- The investigation establishes what happened, its impact and its root cause. Corrective and preventive action is what the organization does about it. ICH Q10 expects investigations of deviations to feed the CAPA system, so the two are linked but distinct steps.
- Must every deviation be investigated to the same depth?
- No. ICH Q9(R1) supports scaling the formality of quality risk management to the risk, and EU GMP Chapter 1 asks for an appropriate level of root cause analysis. A minor deviation with no product impact typically needs less depth than a major one, but the classification and the rationale should be documented.
- When can human error be named as the root cause?
- EU GMP Chapter 1 says human error should be justified as the cause only after process, procedural and system-based errors have been ruled out. Naming human error by default tends to lead to retraining as the only action, and to repeat events.
- Why does an investigation have to look at other batches?
- 21 CFR 211.192 requires the investigation of an unexplained discrepancy to extend to other batches of the same product and other products that may have been associated with it. Genealogy across materials and equipment is how teams find them.
- Could AI help draft a deviation report?
- Potentially. AI could assemble a source-linked first draft and flag gaps. The investigator must verify it, draw the conclusions and determine actions; Quality reviews and approves the final report.
Sources
- 21 CFR Part 211 (211.100, 211.192), U.S. Code of Federal Regulations, September 25, 2026
- EudraLex Volume 4, Part I, Chapter 1: Pharmaceutical Quality System, European Commission, January 13, 2013
- Q10 Pharmaceutical Quality System., ICH, June 8, 2008
- Q9(R1) Quality Risk Management, ICH, January 18, 2023
- Investigating Out-of-Specification (OOS) Test Results for Pharmaceutical Production, Revision 1, U.S. FDA, May 1, 2022
- Transforming Deviation Management. BioProcess International, Chviruk et al., BioPhorum Operations Group, September 16, 2017
In this guide
- Why unstructured records slow regulated operationsIn pharmaceutical operations, much of the evidence behind a batch sits in unstructured records: paper batch records, supplier certificates of analysis, lab reports and deviation records that no system can query. The records are complete and controlled, but answering a question across them means finding, reading, and retyping them by hand. That slows investigations, supplier qualification, and batch review, and it keeps experts on assembly work. Turning those records into structured, source-linked data removes that step without replacing the systems that hold them.
Read next
Agentic Solutions
Katalyze performing a defined operational job, within governed workflows.
See the Solutions



