Written and maintained by CASRAI Editorial Board
Last updated
A deviation is any departure from an approved procedure, specification, or established standard — a temperature excursion during storage, a step performed out of sequence, an instrument that drifted out of its qualified range mid-run, a raw material substituted without prior authorization. Deviation management is the quality-system process that catches those departures, classifies how serious each one is, and scales the investigation to match — and it is a distinct process from CAPA and from an out-of-specification (OOS) investigation, even though all three routinely interact on the same event.
The regulatory anchor for this in the United States is 21 CFR 211.192, which requires that “any unexplained discrepancy… or the failure of a batch or any of its components to meet any of its specifications shall be thoroughly investigated” and that the investigation “extend to other batches of the same drug product and other drug products that may have been associated with the specific failure or discrepancy.” That single sentence is why deviation management can’t be an afterthought bolted onto CAPA: a discrepancy has to be identified, classified, and scoped for its investigation before anyone can decide whether a corrective action is even warranted.
What counts as a deviation
A deviation is procedural or process-level: something that happened (or was about to happen) differently from what an approved document said should happen. That’s a narrower, more operational concept than nonconformity in the ISO 9000:2015 sense, which covers non-fulfilment of any requirement — product, process, or system — including things like a missing training signature that never touched a live process. Every GMP deviation is a nonconformity in the ISO 9000 sense, but plenty of nonconformities (a document-control gap, an expired calibration sticker discovered during an audit) aren’t deviations, because nothing was actually executed differently from the approved instruction.
A deviation is also distinct from a nonconforming product finding: a deviation is the event (the process step that went off-script), while the nonconforming product, if there is one, is a possible consequence of that event that still has to be assessed and dispositioned separately.
Planned vs. unplanned deviations
Deviation management covers two operationally different situations, and conflating them is a common source of confusion:
- Planned (foreseen) deviations are proposed and approved before they happen. A site knows in advance it needs to run a process outside a validated parameter for a specific, justified reason — a documented risk assessment goes to QA, and the deviation is approved in advance, with the disposition and monitoring conditions already agreed. This is proactive risk control, closer in spirit to change control than to an investigation, though it still generates a deviation record because the executed process still departs from the approved baseline.
- Unplanned deviations are discovered during or after execution — an operator error, an equipment malfunction, an environmental monitoring excursion, an in-process check that comes back unexpected. This is the reactive case, and it’s what most deviation records actually are: nobody decided in advance to depart from the procedure, and the investigation exists specifically to reconstruct what happened and why.
Both paths still get run through the same classification step below. A planned deviation approved for a low-risk parameter change can still turn out to have a major or critical impact if the assumptions behind the risk assessment were wrong; an unplanned deviation can turn out to be genuinely minor once investigated. Classification is a judgment made about the deviation’s actual or potential impact, not a label automatically assigned by which of the two paths it came from.
Classification: minor, major, critical
No single ICH guideline or FDA regulation defines “minor,” “major,” and “critical” as fixed, universally harmonized categories with numeric thresholds — the way audit findings get labeled major/minor under ISO 17025 is a scheme-owner convention, not a fixed standard either. What’s consistent across pharmaceutical and lab quality systems is the underlying logic, grounded in the risk-based approach ICH Q10 expects a Pharmaceutical Quality System to apply: classify by actual or potential impact, then scale the investigation to that impact.
| Tier | Typical criteria | Example |
|---|---|---|
| Minor | No impact on product quality, safety, efficacy, or data integrity; a documentation- or administrative-level departure with no plausible downstream consequence. | A logbook entry made a few minutes after the activity it records, with no data-integrity implication. |
| Major | Potential to affect product quality, process control, or a GMP requirement, without confirmed direct harm to patient safety or an already-released batch. | An environmental monitoring excursion in a controlled area during production, with the batch still in process and impact not yet ruled out. |
| Critical | Direct or high-probability impact on patient safety, product sterility/quality, or data integrity; or a departure affecting a batch already released or distributed. | A sterility-critical step performed out of sequence on a batch already in distribution. |
The classification isn’t cosmetic — it’s what determines everything downstream: who has authority to approve the classification and the closure, how deep the investigation has to go, what the closure timeline is, whether a batch gets held, and whether the deviation escalates into a change-control action, a CAPA, or (for a critical deviation tied to a distributed batch) a regulatory notification decision.
How classification drives investigation depth
This is the part a generic CAPA overview usually skips, because it’s specific to deviation management as its own upstream process:
- Minor deviations typically get a streamlined, single-record investigation — describe what happened, confirm no product/process impact, close at the supervisor or line-QA level, usually within days. No formal root-cause methodology is normally required, though the record still has to justify the “no impact” conclusion, not just assert it.
- Major deviations require a formal investigation with a structured root-cause method (5-Whys, fishbone/Ishikawa, or an equivalent template), documented impact assessment against the batch and any related batches, cross-functional QA review, and a defined closure timeline (commonly 30 calendar days, extendable with documented justification). A recurring or systemic major deviation is a strong trigger for a formal CAPA.
- Critical deviations get the deepest treatment: immediate escalation to the quality unit head, a documented batch/product disposition decision before release (or, if already released, a market-impact and recall-risk assessment), an investigation that explicitly extends to other batches and products that could share the same cause — the exact scope 21 CFR 211.192 requires — and, where the deviation affects a distributed product, an assessment of whether a regulatory notification obligation applies. A CAPA is close to mandatory here, not optional.
The common failure mode across all three tiers isn’t skipping the investigation — it’s under-classifying a deviation to avoid the deeper, slower process a major or critical classification requires. An investigator or inspector reviewing the record later asks whether the classification was justified by evidence available at the time, not whether it turned out to be convenient.
Deviation management vs. CAPA vs. OOS
These three terms get used almost interchangeably in casual conversation, but each is a distinct process with its own starting trigger, scope, and exit condition:
| Deviation management | CAPA | OOS investigation | |
|---|---|---|---|
| Trigger | A departure from an approved procedure, specification, or standard — planned or unplanned. | A finding that needs a root cause identified and eliminated — often a deviation, but also an audit observation, a complaint, or a trend. | A laboratory test result that falls outside a specification — a narrower, lab-data-specific trigger. |
| Core question | What happened, how serious is it, and what does it affect? | Why did it happen at the root, and how do we stop it recurring? | Is the result a true out-of-spec finding, or an assignable laboratory error? |
| Typical exit | Closure with documented impact/disposition, or escalation into CAPA and/or change control. | Verified-effective corrective and preventive action, closed with evidence. | A Phase I (lab-error) or Phase II (full manufacturing) investigation outcome, feeding back into deviation management if manufacturing is implicated. |
The relationships aren’t one-directional. A deviation doesn’t automatically require a CAPA — a well-classified minor deviation with no systemic cause can close on its own. An OOS result doesn’t automatically originate from a known deviation — the whole reason FDA’s OOS investigation framework runs Phase I before Phase II is to determine whether a manufacturing deviation is even implicated, or whether the result is a laboratory artifact. And a deviation can occur with no testable result at all — a documentation sequencing error, for instance — so it never touches the OOS process. Treating deviation management as a superset that automatically includes CAPA and OOS collapses three separate records, three separate timelines, and three separate closure criteria into one, which is exactly the kind of structural gap an inspector is trained to look for. See CAPA Report and Plan Structure for what a CAPA record specifically needs once a deviation escalates into one, and Change Control in Pharma for the proactive-proposal side of the same three-way distinction (change control governs a proposed change before it happens; deviation management governs what already happened, planned or not).
Building a deviation SOP: the required elements
A deviation management procedure that actually functions under inspection needs, at minimum:
- Initiation and immediate action — how and by whom a deviation gets logged the moment it’s identified, plus any immediate containment or correction (distinct from CAPA’s systemic corrective action) needed to prevent the situation from getting worse while the investigation proceeds.
- A classification/risk-assessment step — the criteria and authority level for assigning minor/major/critical, applied consistently rather than case-by-case.
- An investigation and root-cause requirement, scaled by classification as above.
- A batch/product impact and disposition decision — explicitly documented, not implied by the deviation simply being closed.
- Defined closure timelines and escalation triggers, including who has authority to approve closure at each tier.
- A trending mechanism — deviation data feeding into the quality system’s periodic review, which ICH Q10 expects as part of its Process Performance and Product Quality Monitoring element. A deviation that looks isolated in a single record can be the third occurrence of the same root cause across a quarter — trending is what catches that a single-record review can’t.
Deviation and change management also show up as a named element of a validation program specifically: EU GMP Annex 15 §1.5(iv) lists “change control and deviation management for qualification and validation” as one of the required contents of a site’s Validation Master Plan, and Annex 15 §2.8 treats a failed qualification/validation acceptance criterion as a deviation requiring full investigation — the same classification-and-investigation-depth logic applies inside a validation exercise as on the manufacturing floor.
Frequently asked questions
Is a deviation the same as a nonconformity?
Not exactly. Every GMP deviation is a nonconformity in the broader ISO 9000:2015 sense (a requirement wasn’t fulfilled), but nonconformity is the wider category — it also covers things like document-control or training-record gaps that never touched an actual process execution. Deviation specifically means an approved procedure or specification was departed from during execution.
Does every deviation need a CAPA?
No. A deviation that’s investigated, classified (often minor), and closed with a documented conclusion that it has no systemic cause and no product impact does not automatically require a CAPA. CAPA becomes warranted when the investigation identifies a root cause that could recur, or when trending shows a pattern across multiple deviations.
What’s the difference between a deviation and an out-of-specification result?
An OOS result is specifically a laboratory test result falling outside its specification — a narrower, data-driven trigger with its own two-phase investigation framework. A deviation is broader: any departure from an approved procedure or standard, which may or may not produce a testable result at all.
Who decides the classification of a deviation?
Site SOPs vary, but the classification (and especially any downgrade of an initial classification) is typically approved by the quality unit, not by the person or department that identified the deviation — the same separation of duties that governs batch release generally.
Can a deviation be closed without a documented root-cause investigation?
Only for the minor tier, and even then the record has to document the basis for concluding “no impact,” not simply assert it. Major and critical deviations require a documented, structured root-cause investigation before closure.








