Risk-based means proportional, scientific, and traceable
ICH Q9(R1) describes quality risk management as a systematic process for assessment, control, communication, and review. Its core principles include basing risk evaluation on scientific knowledge and linking it to patient protection, while making the effort, formality, and documentation proportionate to risk. Those principles are directly useful when deciding how to validate a computerised system.
Frame the risk question first
Do not begin with a generic test catalogue. State what could go wrong, what decision or output could be affected, and what harm could follow. A system supporting a critical release decision needs a different assurance strategy from a system used for a low-impact administrative task. The difference should be visible in the rationale, not just in the number of test cases.
A practical risk workflow
- Define the process, system boundary, intended use, and critical outputs.
- Identify failure modes across configuration, data entry, interfaces, calculations, permissions, audit trails, and reporting.
- Assess severity and likelihood using a method your quality system defines. Include detectability when it is useful and understood.
- Select controls and assurance activities that reduce the important risks.
- Record residual risk and the person or function authorised to accept it.
- Communicate assumptions and open issues to the people who own the process.
- Review the assessment when new evidence, changes, incidents, or process conditions alter the risk.
Do not confuse a risk score with a decision
A numerical score can create false precision. The useful output is the reasoning: why the data or function is critical, which controls matter, how evidence will be gathered, and what remains uncertain. Keep the scale simple enough for reviewers to apply consistently. Use subject-matter expertise and record assumptions instead of hiding them behind arithmetic.
Connect risk to the test design
High-risk functions usually need direct challenge under realistic data and role conditions. Lower-risk functions may be supported by supplier evidence, configuration review, focused testing, or documented verification, depending on the context. Whatever method is selected, the record should explain its limits. A risk assessment that never changes the assurance plan is paperwork, not risk management.
The VLMS validation lifecycle model keeps risk, requirements, evidence, deviations, approvals, and review connected. That makes proportionality easier to explain during an inspection and easier to maintain after go-live.
Turn quality risk into an evidence plan
Start with the system, process, and evidence questions that matter to your team.
Talk with VLMS about your validation programme →