Clarix
Quality

Risk Assessments

How to create, score, and approve Risk Assessment records in Clarix — documenting hazard identification, likelihood and severity scoring, and mitigation actions for processes and products.

A Risk Assessment is a documented, systematic evaluation of the risks associated with a process, product, change, or quality event. In pharmaceutical manufacturing, risk assessment is not a one-time exercise — it is an ongoing, living part of your quality system. ICH Q9 (Quality Risk Management) and USP ⟨1790⟩ describe risk management principles that apply directly to 503B compounding operations.

Clarix's Risk Assessment module provides a structured record for identifying hazards, scoring their likelihood and severity, defining mitigation actions, and tracking residual risk. Risk assessments are commonly linked to other QMS records — a Change Control may require a risk assessment, a new product introduction should have one, and a pattern of environmental excursions might trigger one.

Risk assessment list

Role required: Viewing risk assessments requires the QA Technician role or higher. Creating a risk assessment requires QA Officer. Approving a risk assessment requires QA Manager or PIC.

When to conduct a risk assessment

Risk assessments are used across a wide range of situations in your facility:

  • New product introduction — assessing the risks of adding a new formulation, particularly high-potency or hazardous drugs
  • Process changes — before approving a Major change control, understanding what could go wrong with the new process
  • Equipment qualification — as part of IQ/OQ/PQ planning to define the critical parameters to be challenged
  • Environmental excursion patterns — when recurring EM alerts in a room suggest a systemic risk that needs to be formally characterized
  • Supplier changes — assessing the quality risk of moving to a new raw material supplier
  • CAPA effectiveness — as a prospective check that the preventive action does not introduce new risks
  • Annual product review — a formal risk re-evaluation for each product family as part of the annual quality review

Creating a risk assessment

  1. In the sidebar, navigate to Quality → Risk Assessment.
  2. Click New Risk Assessment in the top-right corner.
  3. Complete the required fields:
    • Title — a descriptive name (e.g., "Risk Assessment: Introduction of Bag Compounding Line — ISO 5 Zone Expansion")
    • Scope — the process, product, area, or change being assessed
    • Risk assessment method — the methodology used (Failure Mode and Effects Analysis/FMEA, Hazard Analysis/HAZOP, preliminary hazard analysis, or narrative risk ranking)
    • Related records — link to any associated Change Control, CAPA, Protocol Validation, or Deviation that triggered this assessment
  4. Click Create Risk Assessment.

Clarix assigns a unique number in the format RA-YYYY-NNNN — for example, RA-2026-0001.

Hazard identification

The core of any risk assessment is the hazard table. For each identified hazard, you document:

FieldDescription
HazardThe specific failure mode or adverse event that could occur (e.g., "Microbiological contamination of filled vials due to inadequate LAF airflow")
Potential causeWhat could cause this hazard to occur (e.g., "Blocked HEPA filter, personnel obstruction of airflow, equipment failure")
Potential effectThe consequence if the hazard occurs (e.g., "Contaminated batch dispensed to patient, potential patient infection")
Likelihood score (L)How likely this hazard is to occur, on a scale of 1 to 5 (see below)
Severity score (S)How serious the consequences would be if it occurs, on a scale of 1 to 5 (see below)
Risk Priority Number (RPN)Calculated automatically: RPN = L × S
Mitigation actionsThe specific controls in place or to be put in place to reduce likelihood or severity
Residual likelihood scoreLikelihood after mitigation (1–5)
Residual severity scoreSeverity after mitigation (1–5)
Residual RPNCalculated: residual L × residual S
AcceptabilityWhether the residual risk is Acceptable, Acceptable with monitoring, or Unacceptable

Likelihood and severity scoring

Use the following standard 1–5 scales when scoring. Apply them consistently across all risk assessments in your facility for meaningful trending.

Likelihood (1–5)

ScoreDefinition
1Remote — virtually no chance of occurrence; no known historical incidents
2Unlikely — could occur under unusual circumstances; rare historical precedent
3Possible — might occur in some circumstances; occasional historical occurrence
4Likely — will probably occur in many circumstances; known to occur regularly
5Almost certain — expected to occur in most circumstances; frequent historical occurrence

Severity (1–5)

ScoreDefinition
1Negligible — no significant patient or product impact; cosmetic issue only
2Minor — limited product quality impact; no patient harm expected
3Moderate — significant product quality impact; potential for patient harm with treatment
4Major** — serious patient injury possible; batch rejection likely
5Critical — life-threatening patient harm; regulatory action likely

Interpreting the RPN

RPN rangeRisk levelAction required
1–4LowAcceptable; document and monitor
5–9MediumAcceptable with mitigation controls in place and verified
10–14HighRequires mitigation; re-score after controls; management awareness
15–25CriticalUnacceptable until mitigated below 15; escalate to QA Manager immediately

Any unmitigated Critical RPN (≥ 15) blocks the associated change or product introduction until mitigation is documented and the residual RPN is reduced to an acceptable level.

Risk assessment lifecycle

StateMeaning
DraftThe risk assessment is being developed and can be freely edited.
Under ReviewThe assessment has been submitted for QA Manager or PIC review.
ApprovedThe risk assessment has been reviewed and accepted. It serves as the authorization to proceed with the associated activity.
ReviewedThe risk assessment has been re-evaluated during a periodic review cycle (typically annual). The review date and reviewer are documented.

Periodic review

Risk assessments do not expire, but they should be reviewed periodically — at minimum annually, or whenever the process, product, or environment they assess changes significantly. Clarix tracks the last review date for each risk assessment. Risk assessments that have not been reviewed within 12 months appear on the 483 Readiness report.

To perform a periodic review:

  1. Open the risk assessment record.
  2. Review each hazard row and update scores if conditions have changed.
  3. Add or remove hazards to reflect current understanding.
  4. Click Mark Reviewed and enter your review notes.
  5. The record moves to Reviewed state and the last review date is updated.

On this page