Summary
- The problem
- A deviation record often mixes the observation, the containment and a guessed cause, and closing it is taken to mean the problem is solved.
- Seal’s approach
- The deviation links the batch, sample and procedure version behind the event. Containment, competing explanations and disposition are separate records, each with its own evidence and authority.
- Neil
- Seal’s AI agent assembles the chronology and source evidence, compares earlier events and drafts the corrective change with its verification. Your team decides cause, impact and closure. About Neil.
- Evidence
- Skye Biologics recorded 40% fewer non-conformances with guided batch records in Seal.
- Where to start
- One recurring deviation type: the procedure, a representative event and the records it touches. Book a demo.
A traditional eQMS files the deviation. Seal starts from the work.
A traditional eQMS is a system of record. Its deviation form holds what was observed, a classification and a root-cause field, with the batch values retyped from other systems, and its corrective action often ends as a revised document.
| A traditional eQMS | Seal | |
|---|---|---|
| The event | A form completed afterwards | Linked to the batch, step and sample |
| Evidence | Values retyped from exports | Source records, with their times |
| Containment | A note on the form | A separate record, with its owner |
| Root cause | A required field | Tested explanations, or inconclusive |
| Affected batches | Listed by hand | Traced through recorded links |
| Corrective action | A revised document | A verified change to the workflow |
| Effectiveness | A closed task | Measured on the runs that follow |
| AI | Text to paste elsewhere | Neil assembles the evidence |
A deviation record often combines three things: what was observed, what was done about it and a guess at why. Once they are merged, closing the record reads as proof that the problem is solved, and the next batch runs the same workflow that produced the event.
Seal links the deviation to the batch, sample and records behind the event, so the investigator starts from the execution record rather than from values retyped into a form. Containment, competing explanations, the impact assessment and the disposition are separate records, each with its own evidence and authority. A corrective action can then change the workflow that produced the event, under change control, rather than ending as a revised document.
The regulations ask for the same separation. In the US, any deviation from written procedures is recorded and justified,¹ and an unexplained discrepancy is thoroughly investigated, extending to other batches that may be associated with it, with a written record of the conclusions and follow-up.² EU GMP asks for significant deviations to be fully recorded and investigated with the objective of determining the root cause, and for appropriate corrective and preventive action to be implemented.³
Figure 1 is the deviation the QMS page follows. DEV-018 records a 52-minute post-mix hold on batch B-041 against a 45-minute limit, and links B-041 and sample IPC-041. That establishes the departure from the procedure. It does not explain the delay or show its effect on the batch, so cause and batch impact remain open. The sections below follow DEV-018 from its first record through the investigation to CAPA-012, the change it leads to and the review of whether that change worked.
You can start with one deviation type, alongside the eQMS you already run: Seal connects to the documents, deviations, CAPAs and change controls in systems such as Veeva Vault QMS, MasterControl, Qualio and ETQ Reliance. The advantage grows as quality, manufacturing and laboratory work run on the same connected records: less reconstruction between teams, and a clearer path from a finding to an improvement that can be verified.
Record the event before explaining it.
The deviation opens with what was observed, linked to the records that show it. Containment and correction are recorded beside it, and neither replaces the original observation.

DEV-018 concerns a 52-minute post-mix hold against a 45-minute limit. Mixing ended at 10:12 and the transfer completed at 11:04, so the hold exceeded the limit by seven minutes. The deviation links batch B-041, its process and temperature readings, and sample IPC-041, taken at 10:16. These are the source records for the timings and measurements in Figure 1.
Record containment separately: what was restricted, who acted, when and what must be checked before the restriction changes. An immediate correction does not replace the original observation or close the investigation. Each action keeps its scope, actor, time and reason, its verification and, where it is temporary, its expiry.
Classification follows the facts rather than preceding them. The deviation records its type, impact, severity, recurrence and the level of investigation it needs, with the due date, escalation and approval. Configured and verified automations can create or propose a deviation from a connected event, retaining the recorded values and source references; authorised people assess its classification and operational meaning.
Test explanations against the evidence.
An investigation starts from what each piece of evidence can and cannot show. Competing explanations stay open, with the evidence for and against each, until the evidence distinguishes them.
| Evidence | What it shows | What it cannot show |
|---|---|---|
| B-041 hold, 10:12 to 11:04 | 52 minutes against 45 | Why the transfer was late |
| Three temperature readings | Points within 2–8 °C | Continuous coverage |
| IPC-041, sampled at 10:16 | Condition before the limit | The condition at 11:04 |
Start with the transfer handoff, the complete temperature history and the applicable hold-time evidence. The three recorded temperatures are within 2–8 °C, but they do not establish continuous coverage. The 10:16 sample predates the overrun; it cannot describe the later condition by itself.
Retain competing explanations, supporting and contradicting observations, and what would distinguish them. If the evidence is inconclusive, record the uncertainty and next controls. A required root-cause field is not a reason to invent a conclusion. EU GMP asks for an appropriate level of root cause analysis and, where the true cause cannot be determined, for the most likely cause to be identified and addressed.⁴
Keep the observed action separate from the explanation for it. Where a human contribution is suspected, the investigation plan assesses task design, procedure, interface, tools, workload and other relevant conditions, and records supporting and contradicting evidence. EU GMP asks for human error to be justified, having taken care that process, procedural or system-based errors have not been overlooked.⁴ A “human error” label alone does not explain the mechanism.
An investigation can end without a root cause. The record then keeps the tested hypotheses, the available and missing evidence, the uncertainty, the residual risk, the interim controls, the product decision, any additional monitoring and its approval, rather than forcing an unsupported cause. Repeat events are found by similarity of failure mode, process, equipment, material, method, shift, site, supplier, cause, context and time; proposed matches stay reviewable and link to the exact prior events and actions.
Follow the impact to every batch it could reach.
The affected population is traced, not remembered. Approved trace rules follow the recorded relationships from the event to the batches, samples, data and inventory it could reach, and each keeps its own state.
| State | What it means |
|---|---|
| Potentially affected | Reached by a trace rule; not yet assessed |
| Assessed unaffected | Assessed, with the evidence kept |
| Confirmed affected | Included in the product decision |
| Unknown | Evidence missing; it stays visible |
Trace rules follow material, process, equipment-use, room, sample, result, data and inventory relationships backward and forward. In the US, the investigation of an unexplained discrepancy extends to other batches of the same product and to other products that may have been associated with it.² Keeping the four states distinct stops a trace that could not be completed from reading as a clean one.
For DEV-018 the impact assessment on B-041 is open. The 10:16 sample predates the overrun and does not establish the later batch condition. The disposition review waits for the required evidence and authorisation; no batch release is represented.
Product and data decisions are records of their own: the affected population, the requirements, the evidence, the risk, the disposition, any corrections and the approvers. Closing a deviation does not, by itself, release the affected batch.
An investigation that needs longer is extended on the record. Each extension keeps the original date, the reason, the progress, the remaining work, the current product or data state, the risk, the interim controls and the new date, with its approval and escalation. Repeated extensions stay visible.
Neil prepares the investigation. Your team decides.
Neil is Seal’s AI agent. Bring it a deviation and it assembles the process, sample, equipment and quality records the requester is permitted to see into a source-backed assessment, with the missing evidence and the work to obtain it.
| Neil prepares | Your team decides | |
|---|---|---|
| Chronology | Source times, with their gaps | Whether it is complete |
| Explanations | Candidates, for and against | The cause, or inconclusive |
| Recurrence | Similar events and their sources | Whether it is a pattern |
| Corrective action | The draft CAPA and configured change | Approval and release |
| Effectiveness | Population, measure and window | Whether the change worked |
Reconstruct DEV-018 from the batch, handoff and sample records, with each source time and every gap.
Neil
- Mixing ended 10:12; transfer at 11:04, from B-041.
- Limit of 45 minutes, from MBR-014 v04.
- Three temperature points; no continuous trace.
- IPC-041 sampled at 10:16, before the limit.
- Requests: handoff, temperature trace, hold-time data.
- Chronology (met)Assembled, with sources
- Cause (not met)For the investigator
- Impact (not met)For the investigator
To reconstruct the chronology, ask Neil: “Reconstruct DEV-018 from the batch, handoff and sample records. Keep source times and identify gaps before proposing an explanation.” Neil can assemble attributable events and link each observation to its source. Ask it to create evidence requests for the incomplete temperature history, the transfer handoff and the hold-time support, without replacing missing data with a narrative.
To compare explanations: “Compare plausible reasons for the extended hold with prior deviations. Show evidence for, evidence against and what would distinguish them.” Neil can compare permitted process, equipment and quality records, rank candidate explanations and prepare a linked investigation plan. A recurring pattern is a question to test, not an established mechanism or product-impact decision.
To configure the control and its verification: “Prepare a change to the hold-and-transfer workflow, with source-time capture, escalation and tests for missing or late events.” Neil can author proposed fields, workflow states and verification cases, then assemble the change and training-impact work for review. Ask it to define the source population and recurrence measure for the effectiveness follow-up. Authorised people verify and publish the change.
These are illustrative requests and the work they prepare, not a recorded Neil session. Each returns proposed records, links and configuration that the investigator reviews; none of them decides the cause, the product impact or the batch disposition.
In line with the EU’s draft GMP Annex 22 on AI, Neil is not used in GMP execution. It helps set up configuration, which your team verifies and releases under change control. Customer data is not used to train AI models, and the requester’s permissions govern what Neil can read. See how Neil fits Annex 22 and more about Neil.
Carry the corrective action into the workflow.
When the investigation finds that the workflow allowed the problem, the corrective action changes the workflow. The change is verified before release, and the next batch runs it.

For DEV-018, CAPA-012’s action is to show the elapsed hold time on the step. Change control carries it as CC-019: MBR-014 v05 calculates the elapsed time from the start and transfer timestamps, keeps the limit at 45 minutes and routes holds over it for assessment. A missing timestamp reports neither a duration nor a pass. CC-019 is verified with holds of 44, 45 and 46 minutes before release, and B-042 then runs the released version, with a 31-minute hold inside the limit.
The original limit and the earlier batch’s decision are kept separately. Changing the workflow for the next batch does not settle the disposition of B-041, which remains its own review.
Approved causes and residual risks create actions tied to the expected outcome. CAPA, engineering, document, training, supplier, validation or change records retain the source deviation and return their implementation and effectiveness evidence to it. ICH Q10 asks for a structured investigation aimed at the root cause, with effort proportionate to the risk, and for CAPA to result in product and process improvements.⁵ EU GMP asks for the effectiveness of those actions to be monitored and assessed.⁴
Close the deviation on evidence.
Product disposition, investigation closure and action effectiveness are different decisions. Seal keeps the evidence and authority for each, and closure gates check that none is skipped.
| Decision | It rests on |
|---|---|
| Batch disposition | The impact assessment and its authority |
| Investigation closure | A cause, or an inconclusive rationale |
| Action effectiveness | Recurrence on a defined population |
Configured gates can require an approved impact assessment, a cause or inconclusive rationale, product and data decisions, corrections and linked actions before closure. Commitments, extension status, the effectiveness plan, required communications and signatures can be checked as well, and no mandatory branch may be left unresolved.
Closure keeps the impact, cause, actions, decisions, CAPAs, changes, commitments, effectiveness plan and signatures together, with the rules for reopening it. For DEV-018, impact, cause and the required follow-up decisions are not complete, so the deviation stays open.
Check that the change worked.
A completed action shows implementation, not effect. Effectiveness is measured on the work that follows the change, against a population and window defined before the result is known.

A procedure revision or completed training task shows implementation; it does not establish that recurrence has changed. Compare a defined event population and its operating exposure before and after a change; a lower count over fewer runs is not, by itself, an improvement.
The example above is a separate fictional CAPA, not a completed action for DEV-018. Normalised for 150 runs before the change and 60 after, the failure rate has not fallen: 8.0 failures per 100 runs before and 8.3 after. For CC-019, the review counts hold exceptions over the agreed period on the batches that run MBR-014 v05.
Keep the time window, exclusions and unresolved evidence with the review. When a criterion is not met, create the follow-up and retain the earlier conclusion. The CAPA stays linked to the deviation that started it, so the review reads back to the original finding instead of inferring success from completed tasks.
Start with one deviation type.
Bring one recurring deviation type: the procedure, a representative event and the records it touches.
Neil prepares the deviation workflow from the procedure: links to the affected batches and samples, fields for the immediate response and impact assessment, assigned investigation work, action records and the required review. Your quality team inspects it against how the work should run. Start with sample material or arrange an NDA before sharing confidential records.
Follow one representative event from its original evidence through investigation and the required decisions. Test missing sources, an inconclusive result, an extension and an attempted premature closure. Verify the linked action and change workflows, including what happens when an effectiveness criterion is not met.
Seal can run beside the eQMS you already use. Agree which system owns the deviation record, which records Seal reads and how status crosses the boundary. To scope the first deviation type with us, book a demo.
References
- 121 CFR 211.100(b), Written procedures; deviations: written production and process control procedures are followed and documented at the time of performance, and any deviation from them is recorded and justified. eCFR
- 221 CFR 211.192, Production record review: an unexplained discrepancy is thoroughly investigated, whether or not the batch has been distributed; the investigation extends to other batches of the same drug product and other drug products that may have been associated with it, and its written record includes the conclusions and follow-up. eCFR
- 3EudraLex Volume 4, Chapter 1, Pharmaceutical Quality System (2013), section 1.8 (vii): significant deviations are fully recorded, investigated with the objective of determining the root cause, and appropriate corrective and preventive action is implemented. European Commission
- 4EudraLex Volume 4, Chapter 1 (2013), section 1.4 (xiv): an appropriate level of root cause analysis; where the true root cause cannot be determined, the most likely cause identified and addressed; human error justified having ensured that process, procedural or system-based errors have not been overlooked; and the effectiveness of corrective and preventive actions monitored and assessed. European Commission
- 5ICH Q10, Pharmaceutical Quality System (2008), section 3.2.2 (corrective action and preventive action system): a structured approach to investigation with the objective of determining the root cause, with effort commensurate with the level of risk; CAPA should result in product and process improvements. ICH
AConnected records
BQuestions and answers
How is Seal different from the deviation module in our eQMS?
A traditional eQMS is a system of record: its deviation form holds what was observed, a classification and a root-cause field, with batch values retyped from other systems. Seal links the deviation to the batch, step and sample behind it, keeps containment, explanations, impact and disposition as separate records, and lets a corrective action change the workflow under change control. You can start with one deviation type alongside the eQMS you run.
How does Neil help?
Neil assembles the chronology from the permitted batch, sample, equipment and quality records, compares earlier events and asks for the evidence that is missing. It can draft the CAPA and the configured change with its verification cases. Cause, impact, disposition and closure stay with your team. In line with the EU’s draft GMP Annex 22 on AI, Neil is not used in GMP execution. It helps set up configuration, which your team verifies and releases under change control.
What is GxP deviation management software?
It manages a deviation from capture and containment through classification, chronology, affected-population assessment and investigation. It records hypotheses, root cause or an inconclusive rationale, product and data decisions, CAPAs, extensions and closure, and supports trending across events.
Can connected events open a deviation?
Configured and verified automations can create or propose deviations from connected events, retaining the recorded values and source references. The source integration, trigger and exception handling must be defined for your workflow. Authorised users assess classification and operational meaning.
How should an investigation assess a human contribution?
Keep the observed action separate from the explanation for it. Use the investigation plan to assess task design, procedure, interface, tools, workload and other relevant conditions. Record supporting and contradicting evidence; a ‘human error’ label alone does not explain the mechanism.
How is the affected population determined?
Approved trace rules follow material, process, equipment-use, room, sample, result, data and inventory relationships backward and forward. Potentially affected, assessed unaffected, confirmed affected and unknown states remain distinct.
Can an investigation be inconclusive?
Yes. The record retains tested hypotheses, available and missing evidence, uncertainty, residual risk, interim controls, product decision, additional monitoring and approval rather than forcing an unsupported root cause.
How are repeat deviations detected?
Similarity can use failure mode, process, equipment, material, method, shift, site, supplier, cause, context and time. Proposed matches remain reviewable, and patterns link to exact prior events and actions.
How are investigation extensions controlled?
Each extension retains the original date, reason, progress, remaining work, current product or data state, risk, interim controls, new date, history, approvals and escalation. Repeated extensions remain visible.
How do deviations connect to CAPA and change control?
Approved causes and residual risks create actions tied to the expected outcome. CAPA, engineering, document, training, supplier, validation or change records retain the source deviation and return implementation and effectiveness evidence.
What prevents premature closure?
Configured gates can require an approved impact assessment, a cause or inconclusive rationale, product and data decisions, corrections and linked actions before closure. Commitments, extension status, the effectiveness plan, required communications and signatures can be checked as well, and no mandatory branch may be left unresolved.
What should the first implementation prove?
Follow one representative event from its original evidence through investigation and the required decisions. Test missing sources, an inconclusive result, an extension and an attempted premature closure. Verify linked action and change workflows, including what happens when an effectiveness criterion is not met.
