All blueprints

Find what happened. Prove what follows.

Deviation and investigation software that opens each event with its batch, sample and original evidence. Neil investigates history and tests explanations; corrective changes are released with their own verification.

Illustration of a seal examining a circled change in a trace alongside run, sample and procedure records.
Deviations › DEV-018
assessment pending

B-041, post-mix hold

  • Hold time (met)52 minutes against a 45-minute limit
  • Temperature (not met)Three readings, no continuous trace
  • Sample IPC-041 (not met)Taken at 10:16, before the limit

Figure 1. DEV-018 records a 52-minute hold; the evidence so far leaves cause and batch impact open.

Summary

The problem
A deviation record often mixes the observation, the containment and a guessed cause, and closing it is taken to mean the problem is solved.
Seal’s approach
The deviation links the batch, sample and procedure version behind the event. Containment, competing explanations and disposition are separate records, each with its own evidence and authority.
Neil
Seal’s AI agent assembles the chronology and source evidence, compares earlier events and drafts the corrective change with its verification. Your team decides cause, impact and closure. About Neil.
Evidence
Skye Biologics recorded 40% fewer non-conformances with guided batch records in Seal.
Where to start
One recurring deviation type: the procedure, a representative event and the records it touches. Book a demo.

A traditional eQMS files the deviation. Seal starts from the work.

A traditional eQMS is a system of record. Its deviation form holds what was observed, a classification and a root-cause field, with the batch values retyped from other systems, and its corrective action often ends as a revised document.

A traditional eQMSSeal
The eventA form completed afterwardsLinked to the batch, step and sample
EvidenceValues retyped from exportsSource records, with their times
ContainmentA note on the formA separate record, with its owner
Root causeA required fieldTested explanations, or inconclusive
Affected batchesListed by handTraced through recorded links
Corrective actionA revised documentA verified change to the workflow
EffectivenessA closed taskMeasured on the runs that follow
AIText to paste elsewhereNeil assembles the evidence

A deviation record often combines three things: what was observed, what was done about it and a guess at why. Once they are merged, closing the record reads as proof that the problem is solved, and the next batch runs the same workflow that produced the event.

Seal links the deviation to the batch, sample and records behind the event, so the investigator starts from the execution record rather than from values retyped into a form. Containment, competing explanations, the impact assessment and the disposition are separate records, each with its own evidence and authority. A corrective action can then change the workflow that produced the event, under change control, rather than ending as a revised document.

The regulations ask for the same separation. In the US, any deviation from written procedures is recorded and justified,¹ and an unexplained discrepancy is thoroughly investigated, extending to other batches that may be associated with it, with a written record of the conclusions and follow-up.² EU GMP asks for significant deviations to be fully recorded and investigated with the objective of determining the root cause, and for appropriate corrective and preventive action to be implemented.³

Figure 1 is the deviation the QMS page follows. DEV-⁠018 records a 52-minute post-mix hold on batch B-⁠041 against a 45-minute limit, and links B-⁠041 and sample IPC-⁠041. That establishes the departure from the procedure. It does not explain the delay or show its effect on the batch, so cause and batch impact remain open. The sections below follow DEV-⁠018 from its first record through the investigation to CAPA-⁠012, the change it leads to and the review of whether that change worked.

You can start with one deviation type, alongside the eQMS you already run: Seal connects to the documents, deviations, CAPAs and change controls in systems such as Veeva Vault QMS, MasterControl, Qualio and ETQ Reliance. The advantage grows as quality, manufacturing and laboratory work run on the same connected records: less reconstruction between teams, and a clearer path from a finding to an improvement that can be verified.

Record the event before explaining it.

The deviation opens with what was observed, linked to the records that show it. Containment and correction are recorded beside it, and neither replaces the original observation.

DEV-018 links B-041 and IPC-041, records the 52-minute hold and leaves the investigation open, in Seal with fictional records
Figure 2. DEV-⁠018 links B-⁠041 and IPC-⁠041, records the 52-minute hold and leaves the investigation open

DEV-⁠018 concerns a 52-minute post-mix hold against a 45-minute limit. Mixing ended at 10:12 and the transfer completed at 11:04, so the hold exceeded the limit by seven minutes. The deviation links batch B-⁠041, its process and temperature readings, and sample IPC-⁠041, taken at 10:16. These are the source records for the timings and measurements in Figure 1.

Record containment separately: what was restricted, who acted, when and what must be checked before the restriction changes. An immediate correction does not replace the original observation or close the investigation. Each action keeps its scope, actor, time and reason, its verification and, where it is temporary, its expiry.

Classification follows the facts rather than preceding them. The deviation records its type, impact, severity, recurrence and the level of investigation it needs, with the due date, escalation and approval. Configured and verified automations can create or propose a deviation from a connected event, retaining the recorded values and source references; authorised people assess its classification and operational meaning.

Test explanations against the evidence.

An investigation starts from what each piece of evidence can and cannot show. Competing explanations stay open, with the evidence for and against each, until the evidence distinguishes them.

EvidenceWhat it showsWhat it cannot show
B-⁠041 hold, 10:12 to 11:0452 minutes against 45Why the transfer was late
Three temperature readingsPoints within 2–8 °CContinuous coverage
IPC-⁠041, sampled at 10:16Condition before the limitThe condition at 11:04

Start with the transfer handoff, the complete temperature history and the applicable hold-time evidence. The three recorded temperatures are within 2–8 °C, but they do not establish continuous coverage. The 10:16 sample predates the overrun; it cannot describe the later condition by itself.

Retain competing explanations, supporting and contradicting observations, and what would distinguish them. If the evidence is inconclusive, record the uncertainty and next controls. A required root-cause field is not a reason to invent a conclusion. EU GMP asks for an appropriate level of root cause analysis and, where the true cause cannot be determined, for the most likely cause to be identified and addressed.⁴

Keep the observed action separate from the explanation for it. Where a human contribution is suspected, the investigation plan assesses task design, procedure, interface, tools, workload and other relevant conditions, and records supporting and contradicting evidence. EU GMP asks for human error to be justified, having taken care that process, procedural or system-based errors have not been overlooked.⁴ A “human error” label alone does not explain the mechanism.

An investigation can end without a root cause. The record then keeps the tested hypotheses, the available and missing evidence, the uncertainty, the residual risk, the interim controls, the product decision, any additional monitoring and its approval, rather than forcing an unsupported cause. Repeat events are found by similarity of failure mode, process, equipment, material, method, shift, site, supplier, cause, context and time; proposed matches stay reviewable and link to the exact prior events and actions.

Follow the impact to every batch it could reach.

The affected population is traced, not remembered. Approved trace rules follow the recorded relationships from the event to the batches, samples, data and inventory it could reach, and each keeps its own state.

StateWhat it means
Potentially affectedReached by a trace rule; not yet assessed
Assessed unaffectedAssessed, with the evidence kept
Confirmed affectedIncluded in the product decision
UnknownEvidence missing; it stays visible

Trace rules follow material, process, equipment-use, room, sample, result, data and inventory relationships backward and forward. In the US, the investigation of an unexplained discrepancy extends to other batches of the same product and to other products that may have been associated with it.² Keeping the four states distinct stops a trace that could not be completed from reading as a clean one.

For DEV-⁠018 the impact assessment on B-⁠041 is open. The 10:16 sample predates the overrun and does not establish the later batch condition. The disposition review waits for the required evidence and authorisation; no batch release is represented.

Product and data decisions are records of their own: the affected population, the requirements, the evidence, the risk, the disposition, any corrections and the approvers. Closing a deviation does not, by itself, release the affected batch.

An investigation that needs longer is extended on the record. Each extension keeps the original date, the reason, the progress, the remaining work, the current product or data state, the risk, the interim controls and the new date, with its approval and escalation. Repeated extensions stay visible.

Neil prepares the investigation. Your team decides.

Neil is Seal’s AI agent. Bring it a deviation and it assembles the process, sample, equipment and quality records the requester is permitted to see into a source-backed assessment, with the missing evidence and the work to obtain it.

Neil preparesYour team decides
ChronologySource times, with their gapsWhether it is complete
ExplanationsCandidates, for and againstThe cause, or inconclusive
RecurrenceSimilar events and their sourcesWhether it is a pattern
Corrective actionThe draft CAPA and configured changeApproval and release
EffectivenessPopulation, measure and windowWhether the change worked
Deviations › DEV-018
assessment pending

Reconstruct DEV-018 from the batch, handoff and sample records, with each source time and every gap.

Neil

  • Mixing ended 10:12; transfer at 11:04, from B-041.
  • Limit of 45 minutes, from MBR-014 v04.
  • Three temperature points; no continuous trace.
  • IPC-041 sampled at 10:16, before the limit.
  • Requests: handoff, temperature trace, hold-time data.
  • Chronology (met)Assembled, with sources
  • Cause (not met)For the investigator
  • Impact (not met)For the investigator
Figure 3. Neil reconstructs DEV-⁠018 from its source records and leaves cause and impact to the investigator

To reconstruct the chronology, ask Neil: “Reconstruct DEV-⁠018 from the batch, handoff and sample records. Keep source times and identify gaps before proposing an explanation.” Neil can assemble attributable events and link each observation to its source. Ask it to create evidence requests for the incomplete temperature history, the transfer handoff and the hold-time support, without replacing missing data with a narrative.

To compare explanations: “Compare plausible reasons for the extended hold with prior deviations. Show evidence for, evidence against and what would distinguish them.” Neil can compare permitted process, equipment and quality records, rank candidate explanations and prepare a linked investigation plan. A recurring pattern is a question to test, not an established mechanism or product-impact decision.

To configure the control and its verification: “Prepare a change to the hold-and-transfer workflow, with source-time capture, escalation and tests for missing or late events.” Neil can author proposed fields, workflow states and verification cases, then assemble the change and training-impact work for review. Ask it to define the source population and recurrence measure for the effectiveness follow-up. Authorised people verify and publish the change.

These are illustrative requests and the work they prepare, not a recorded Neil session. Each returns proposed records, links and configuration that the investigator reviews; none of them decides the cause, the product impact or the batch disposition.

In line with the EU’s draft GMP Annex 22 on AI, Neil is not used in GMP execution. It helps set up configuration, which your team verifies and releases under change control. Customer data is not used to train AI models, and the requester’s permissions govern what Neil can read. See how Neil fits Annex 22 and more about Neil.

Carry the corrective action into the workflow.

When the investigation finds that the workflow allowed the problem, the corrective action changes the workflow. The change is verified before release, and the next batch runs it.

CC-019 carries CAPA-012’s action into MBR-014 v05, with its verification plan and release review, in Seal with fictional records
Figure 4. CC-⁠019 carries CAPA-⁠012’s action into MBR-⁠014 v05, with its verification plan and release review

For DEV-⁠018, CAPA-⁠012’s action is to show the elapsed hold time on the step. Change control carries it as CC-⁠019: MBR-⁠014 v05 calculates the elapsed time from the start and transfer timestamps, keeps the limit at 45 minutes and routes holds over it for assessment. A missing timestamp reports neither a duration nor a pass. CC-⁠019 is verified with holds of 44, 45 and 46 minutes before release, and B-⁠042 then runs the released version, with a 31-minute hold inside the limit.

The original limit and the earlier batch’s decision are kept separately. Changing the workflow for the next batch does not settle the disposition of B-⁠041, which remains its own review.

Approved causes and residual risks create actions tied to the expected outcome. CAPA, engineering, document, training, supplier, validation or change records retain the source deviation and return their implementation and effectiveness evidence to it. ICH Q10 asks for a structured investigation aimed at the root cause, with effort proportionate to the risk, and for CAPA to result in product and process improvements.⁵ EU GMP asks for the effectiveness of those actions to be monitored and assessed.⁴

Close the deviation on evidence.

Product disposition, investigation closure and action effectiveness are different decisions. Seal keeps the evidence and authority for each, and closure gates check that none is skipped.

DecisionIt rests on
Batch dispositionThe impact assessment and its authority
Investigation closureA cause, or an inconclusive rationale
Action effectivenessRecurrence on a defined population

Configured gates can require an approved impact assessment, a cause or inconclusive rationale, product and data decisions, corrections and linked actions before closure. Commitments, extension status, the effectiveness plan, required communications and signatures can be checked as well, and no mandatory branch may be left unresolved.

Closure keeps the impact, cause, actions, decisions, CAPAs, changes, commitments, effectiveness plan and signatures together, with the rules for reopening it. For DEV-⁠018, impact, cause and the required follow-up decisions are not complete, so the deviation stays open.

Check that the change worked.

A completed action shows implementation, not effect. Effectiveness is measured on the work that follows the change, against a population and window defined before the result is known.

A separate CAPA example: per 100 runs, the failure rate has not fallen after the change, in Seal with fictional records
Figure 5. A separate CAPA example: per 100 runs, the failure rate has not fallen after the change

A procedure revision or completed training task shows implementation; it does not establish that recurrence has changed. Compare a defined event population and its operating exposure before and after a change; a lower count over fewer runs is not, by itself, an improvement.

The example above is a separate fictional CAPA, not a completed action for DEV-⁠018. Normalised for 150 runs before the change and 60 after, the failure rate has not fallen: 8.0 failures per 100 runs before and 8.3 after. For CC-⁠019, the review counts hold exceptions over the agreed period on the batches that run MBR-⁠014 v05.

Keep the time window, exclusions and unresolved evidence with the review. When a criterion is not met, create the follow-up and retain the earlier conclusion. The CAPA stays linked to the deviation that started it, so the review reads back to the original finding instead of inferring success from completed tasks.

Start with one deviation type.

Bring one recurring deviation type: the procedure, a representative event and the records it touches.

Neil prepares the deviation workflow from the procedure: links to the affected batches and samples, fields for the immediate response and impact assessment, assigned investigation work, action records and the required review. Your quality team inspects it against how the work should run. Start with sample material or arrange an NDA before sharing confidential records.

Follow one representative event from its original evidence through investigation and the required decisions. Test missing sources, an inconclusive result, an extension and an attempted premature closure. Verify the linked action and change workflows, including what happens when an effectiveness criterion is not met.

Seal can run beside the eQMS you already use. Agree which system owns the deviation record, which records Seal reads and how status crosses the boundary. To scope the first deviation type with us, book a demo.

References

  1. 121 CFR 211.100(b), Written procedures; deviations: written production and process control procedures are followed and documented at the time of performance, and any deviation from them is recorded and justified. eCFR
  2. 221 CFR 211.192, Production record review: an unexplained discrepancy is thoroughly investigated, whether or not the batch has been distributed; the investigation extends to other batches of the same drug product and other drug products that may have been associated with it, and its written record includes the conclusions and follow-up. eCFR
  3. 3EudraLex Volume 4, Chapter 1, Pharmaceutical Quality System (2013), section 1.8 (vii): significant deviations are fully recorded, investigated with the objective of determining the root cause, and appropriate corrective and preventive action is implemented. European Commission
  4. 4EudraLex Volume 4, Chapter 1 (2013), section 1.4 (xiv): an appropriate level of root cause analysis; where the true root cause cannot be determined, the most likely cause identified and addressed; human error justified having ensured that process, procedural or system-based errors have not been overlooked; and the effectiveness of corrective and preventive actions monitored and assessed. European Commission
  5. 5ICH Q10, Pharmaceutical Quality System (2008), section 3.2.2 (corrective action and preventive action system): a structured approach to investigation with the objective of determining the root cause, with effort commensurate with the level of risk; CAPA should result in product and process improvements. ICH

AConnected records

Entity
What it records
Kind
GxP Deviation
Observed and expected condition, source, context, risk, classification, owner, dates and state.
type
Manufacturing Process Deviation
Batch and operation event with process signals, materials, equipment, containment and impact.
template
DEV-018
Illustrative 52-minute post-mix hold against a 45-minute limit. Cause and batch impact remain open.
instance
Immediate Action
Containment or safe correction, scope, actor, time, reason, verification, expiry and state.
type
Deviation Classification
Type, impact, severity, recurrence, investigation level, due date, escalation and approval.
type
Deviation Chronology
Attributed process, system, material, equipment, sample, communication and decision events.
type
Deviation Impact Assessment
Trace rule, population, potentially and confirmed affected items, evidence, uncertainty and decision.
type
Batch and Inventory Impact Assessment
Process interval, equipment usage, batches, pools, samples, inventory, distribution, evidence and decision.
template
B-041 / impact assessment
Illustrative open assessment of B-041 after the hold overrun.
instance
Investigation Plan
Problem, scope, team, hypotheses, evidence, interviews, experiments, dates and approval.
type
Cross-Functional Investigation
Manufacturing, engineering, QC and quality hypotheses, evidence, experiments, milestones and reviews.
template
DEV-018 / investigation plan
Proposed investigation into the transfer handoff, full temperature history and applicable hold-time evidence.
instance
Investigation Hypothesis
Potential mechanism, predicted evidence, test, support, contradiction, result, confidence and state.
type
Investigation Evidence
Source, version, population, selection, observation, file, calculation, limitation and review.
type
Investigation Interview
Participant, role, timing, questions, responses, demonstrated evidence, review and follow-up.
type
Root Cause Conclusion
Direct, contributing and systemic causes, mechanism, alternatives, evidence, confidence and approval.
type
Evidence-Based Root Cause Analysis
Mechanism, direct and systemic causes, alternatives, support, contradictions, confidence and approval.
template
DEV-018 / cause assessment
Illustrative pending assessment of candidate explanations, supporting evidence and unresolved gaps. No cause is established.
instance
Deviation Recurrence Assessment
Similarity rules, prior events, shared factors, patterns, prior actions, conclusion and escalation.
type
Deviation Product or Data Decision
Affected population, requirements, evidence, risk, disposition, corrections, approvers and state.
type
Deviation Batch Disposition
Affected batch scope, specifications, process evidence, risk, investigation, disposition and approval.
template
B-041 / disposition review
Illustrative review awaiting the required evidence and authorisation. No batch release is represented.
instance
Investigation Extension
Original date, reason, progress, remaining work, risk, interim control, new date and approval.
type
Deviation Closure
Impact, cause, actions, decisions, CAPAs, changes, commitments, effectiveness, signatures and reopen rules.
type
GxP Deviation Closure
Complete investigation, decisions, corrections, CAPA, change, effectiveness plan, signatures and reopen.
template
DEV-018 / closure review
Illustrative open investigation. Impact, cause and required follow-up decisions are not complete.
instance

BQuestions and answers

How is Seal different from the deviation module in our eQMS?

A traditional eQMS is a system of record: its deviation form holds what was observed, a classification and a root-cause field, with batch values retyped from other systems. Seal links the deviation to the batch, step and sample behind it, keeps containment, explanations, impact and disposition as separate records, and lets a corrective action change the workflow under change control. You can start with one deviation type alongside the eQMS you run.

How does Neil help?

Neil assembles the chronology from the permitted batch, sample, equipment and quality records, compares earlier events and asks for the evidence that is missing. It can draft the CAPA and the configured change with its verification cases. Cause, impact, disposition and closure stay with your team. In line with the EU’s draft GMP Annex 22 on AI, Neil is not used in GMP execution. It helps set up configuration, which your team verifies and releases under change control.

What is GxP deviation management software?

It manages a deviation from capture and containment through classification, chronology, affected-population assessment and investigation. It records hypotheses, root cause or an inconclusive rationale, product and data decisions, CAPAs, extensions and closure, and supports trending across events.

Can connected events open a deviation?

Configured and verified automations can create or propose deviations from connected events, retaining the recorded values and source references. The source integration, trigger and exception handling must be defined for your workflow. Authorised users assess classification and operational meaning.

How should an investigation assess a human contribution?

Keep the observed action separate from the explanation for it. Use the investigation plan to assess task design, procedure, interface, tools, workload and other relevant conditions. Record supporting and contradicting evidence; a ‘human error’ label alone does not explain the mechanism.

How is the affected population determined?

Approved trace rules follow material, process, equipment-use, room, sample, result, data and inventory relationships backward and forward. Potentially affected, assessed unaffected, confirmed affected and unknown states remain distinct.

Can an investigation be inconclusive?

Yes. The record retains tested hypotheses, available and missing evidence, uncertainty, residual risk, interim controls, product decision, additional monitoring and approval rather than forcing an unsupported root cause.

How are repeat deviations detected?

Similarity can use failure mode, process, equipment, material, method, shift, site, supplier, cause, context and time. Proposed matches remain reviewable, and patterns link to exact prior events and actions.

How are investigation extensions controlled?

Each extension retains the original date, reason, progress, remaining work, current product or data state, risk, interim controls, new date, history, approvals and escalation. Repeated extensions remain visible.

How do deviations connect to CAPA and change control?

Approved causes and residual risks create actions tied to the expected outcome. CAPA, engineering, document, training, supplier, validation or change records retain the source deviation and return implementation and effectiveness evidence.

What prevents premature closure?

Configured gates can require an approved impact assessment, a cause or inconclusive rationale, product and data decisions, corrections and linked actions before closure. Commitments, extension status, the effectiveness plan, required communications and signatures can be checked as well, and no mandatory branch may be left unresolved.

What should the first implementation prove?

Follow one representative event from its original evidence through investigation and the required decisions. Test missing sources, an inconclusive result, an extension and an attempted premature closure. Verify linked action and change workflows, including what happens when an effectiveness criterion is not met.

Capabilities

See your process in Seal.

Bring a procedure or a recurring problem. See how your team can use Neil to configure the workflow, investigate the results and improve the next version.

Book a demo