AIThis post was created with the assistance of artificial intelligence (AI).

Meta: See how QAtrial supports risk management with structured records, interactive risk views, linked quality workflows, and AI-assisted classification support.

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get monitors, keyboards and dev gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Why Regulated Teams Need Structured Risk Management

Risk management in regulated industries is not optional — it is a regulatory expectation. ISO 14971 requires it for medical devices. ICH Q9 requires it for pharmaceuticals. GAMP 5 expects it for computerized system validation. Yet in practice, risk management is often the quality activity most likely to end up in a side spreadsheet, disconnected from the requirements and tests it should inform.

QAtrial – Risk Management
QAtrial · Quality Process
Risk
Management
Risk is not a standalone spreadsheet in QAtrial — it is a field on every requirement, a live dimension in the dashboard, a factor in compliance scoring, and a context for CAPA analysis. Identify, estimate, control, and document with enough rigour that an auditor can follow the reasoning.
5×5
Interactive severity × likelihood matrix, live from requirement data
5
Risk taxonomies: ISO 14971, ICH Q9, GAMP 5, FMEA, Generic
15%
Weight of “Risk Assessed” in the Compliance Readiness Score
Interactive 5×5 Risk Matrix — Live View · Click Any Cell to Drill In
← Severity →
50 reqs
102 reqs
150 reqs
201 req
250 reqs
40 reqs
84 reqs
123 reqs
162 reqs
200 reqs
31 req
65 reqs
96 reqs
124 reqs
151 req
23 reqs
47 reqs
68 reqs
83 reqs
102 reqs
15 reqs
24 reqs
33 reqs
42 reqs
50 reqs
5 Almost Certain
4 Likely
3 Moderate
2 Unlikely
1 Rare
1 Negligible
2 Minor
3 Serious
4 Critical
5 Catastrophic
Low (1–3)
Medium (4–8)
High (9–15)
Critical (16–25)
Summary
3
Critical
16
High
24
Medium
18
Low
Scoring Model
Severity × Likelihood = Risk Score
Score Range Risk Level Severity
1 – 3 Low
4 – 8 Medium
9 – 15 High
16 – 25 Critical
Critical risk penalty: If any requirement carries a “critical” risk level, the overall Compliance Readiness Score receives an automatic −10 point penalty. This incentivises teams to address critical risks rather than ignore them.
Three-Factor FMEA Model
For Aerospace, Labs & Manufacturing
FMEA — Failure Mode and Effects Analysis
Severity
S
×
Occurrence
O
×
Detectability
D
=
RPN
RPN
The third factor — detectability — asks: how likely is it that the failure will be detected before it causes harm? Low detectability means even a low-likelihood risk deserves more attention. Standard in aerospace (ISO 26262), clinical laboratories, logistics/GDP, and chemical/environmental projects. Produces a Risk Priority Number (1–125) rather than a simple two-factor score (1–25).
Risk Taxonomies
Five Frameworks — Selected by Project Vertical
ISO 14971
Medical Devices
Focuses on patient safety, user safety, and environmental safety. Severity categories: negligible injury → minor → serious → death.
Medical Devices vertical
ICH Q9
Pharma & Biotech
ICH quality risk management guideline. Severity in terms of impact on product quality and patient outcomes. Data integrity included.
Pharmaceuticals · Biotechnology · CRO
GAMP 5
Software & CSV
Good Automated Manufacturing Practice. Categorizes systems by complexity (Cat 1–5). Risk focuses on impact of software failures on GxP processes.
Software & IT (GAMP/CSV) vertical
FMEA
Aerospace & Mfg
Three-factor model: Severity × Occurrence × Detectability = RPN. Standard in aerospace, clinical labs, logistics, and chemical industries.
Aerospace · Clinical Labs · Logistics
Generic
All Other Verticals
Simplified severity-by-likelihood model without industry-specific severity categories. No domain standard required.
Cosmetics/Chemical · Others
AI Risk Classification
Single or Bulk — Human Accepts or Rejects
🎯 Risk Classification Result REQ-042
Severity 4 / 5 — Critical. Audit trail failure directly violates 21 CFR 11.10(e). Regulatory submission impact is high.
Likelihood 3 / 5 — Moderate. Risk materialises if data store is tampered with or audit log exceeds retention.
Risk Score 12 — HIGH
Safety Class Class II Medical Device · IEC 62304 SIL-B
Confidence
82%
Provenance
model claude-sonnet-4 taxonomy ISO 14971 tokens 648 reviewed sarah.chen
How it works
1
Reads requirement context
Title, description, regulatory reference, tags, project vertical, and country. The taxonomy for the vertical determines the scoring criteria sent to the LLM.
2
Returns scored proposal
Severity (1–5), likelihood (1–5), computed score, risk level, applicable safety class, and confidence percentage — each with rationale.
3
Human reviews and decides
Accept → saves risk level to requirement, logs ai_accept in audit trail. Reject → logs ai_reject. Provenance preserved regardless.
4
Bulk: “Classify All Unassessed”
Risk dashboard button processes all unassessed requirements in sequence. Results are a starting point — review is required before treating as final risk determinations.
Risk Connectivity
How Risk Flows Through the Quality System
📋
Requirements
Every requirement carries a riskLevel field (low / medium / high / critical). Template requirements arrive with pre-assigned levels based on regulatory criticality.
riskLevel field
🧪
Tests
Higher-risk requirements need more thorough test coverage. Evidence dashboard highlights requirements with a risk assessment but no linked tests.
Coverage gap signal
📎
Evidence
Evidence tab tracks three dimensions per requirement: linked tests, risk assessment, and approval signature. Critical risk + no tests = visible gap.
Completeness tracking
🔁
CAPA
When a high-risk requirement’s test fails, the CAPA dashboard surfaces it prominently. AI CAPA suggestions incorporate the risk level and applicable standards.
Context-aware RCA
📊
Compliance Score
“Risk Assessed” is 15% of the Compliance Readiness Score. Any critical-risk requirement with no mitigation triggers an additional −10 point penalty.
15% weight + penalty
Compliance Readiness Score
Risk Assessed — one of five weighted components
15%
Weight of Risk Assessed
Requirement Coverage
Are requirements Active or Closed?
25%
Test Coverage
Does every requirement have a linked test?
25%
Test Pass Rate
Have linked tests been executed and passed?
20%
Risk Assessed ←
Does every requirement have a risk level?
15%
Signature Completeness
Have requirements been formally approved?
15%
⚠️
Critical risk penalty: −10 points. If any requirement has a “critical” risk level, the overall score is reduced by 10 points regardless of the weighted component scores. Unassessed requirements also appear as a flagged gap in the dashboard — a high unassessed count signals incomplete risk identification to auditors.

The problem with spreadsheet-based risk management is not the format. It is the isolation. When risk assessments live separately from requirements, there is no structural connection between “this requirement is high risk” and “this requirement needs more test coverage.” Teams perform risk assessments as a documentation exercise, then file the spreadsheet and move on. The assessment does not influence testing priorities, CAPA urgency, or audit preparation because it is not connected to those workflows.

Structured risk management means risk assessments are part of the quality record — persisted, auditable, linked to the entities they assess, and visible in dashboards that drive decision-making.


Amazon

risk management software for regulated industries

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Where Risk Lives Inside QAtrial

Risk Management is one of QAtrial’s 15 composable quality modules. When selected during project setup, it adds requirements covering hazard identification, risk estimation, and risk control. But risk management in QAtrial extends beyond the module templates — it is built into the core data model.

Every requirement in QAtrial has a riskLevel field that can be set to low, medium, high, or critical. Risk assessments are persisted as durable entities with their own lifecycle and audit trail. The Risk dashboard provides an interactive visualization of the project’s risk profile. AI can classify unassessed requirements. And risk data flows into reports, compliance scores, and evidence completeness tracking.

Risk is not a standalone feature. It is woven through requirements, tests, CAPA, evidence, and reporting.


Amazon

interactive risk matrix tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Risk Identification, Estimation, and Control

QAtrial follows a standard risk management flow: identify, estimate, control.

Identification

Risk identification begins with requirements. Each requirement in QAtrial can carry a risk level, tags, and a regulatory reference. When templates are loaded during project setup, many requirements arrive with pre-assigned risk levels based on their regulatory criticality. For example, a requirement referencing “21 CFR 11.10(e) — audit trail” might be tagged as “high” because audit trail failures have direct regulatory consequences.

Requirements without an assigned risk level are flagged as “unassessed” in the Risk dashboard. This visibility ensures that risk identification gaps are visible to the team rather than silently ignored.

Estimation

Risk estimation in QAtrial uses a severity-by-likelihood model. Each requirement can be scored on two dimensions:

  • Severity (1-5): How serious is the impact if this risk materializes? 1 = Negligible, 5 = Critical.
  • Likelihood (1-5): How probable is it that this risk will occur? 1 = Rare, 5 = Almost Certain.

The risk score is the product of severity and likelihood, yielding a value from 1 to 25. This score maps to a risk level:

Score RangeRisk Level
1-3Low
4-8Medium
9-15High
16-25Critical

For verticals that use FMEA (Failure Mode and Effects Analysis), a third dimension is available: detectability — how likely is it that the failure will be detected before it causes harm? This three-factor model (severity x likelihood x detectability) is standard in aerospace, clinical laboratory, and manufacturing contexts.

Control

Risk control in QAtrial is implicit in the quality workflow. A high-risk requirement should have more tests (higher coverage), a risk assessment with documented mitigations, evidence of verification, and potentially a CAPA record if the risk materializes. The Evidence dashboard tracks whether each requirement has its risk assessment, linked tests, and approval signatures — creating visibility into whether risk controls are actually in place.


Amazon

quality workflow management system

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

The Interactive 5×5 Risk Matrix Dashboard

The Risk tab in the Evaluation dashboard displays an interactive 5×5 risk matrix. This is not a static image — it is a live view of your project’s risk profile.

Reading the Matrix

The X-axis represents severity (1 = Negligible to 5 = Critical). The Y-axis represents likelihood (1 = Rare to 5 = Almost Certain). Each cell displays a number indicating how many requirements fall into that severity-likelihood combination.

Cells are color-coded by risk zone:

  • Green (scores 1-3): Low risk. These requirements are unlikely to cause significant harm.
  • Yellow (scores 4-8): Medium risk. Monitor these, but they are not urgent.
  • Orange (scores 9-15): High risk. These require active mitigation and thorough test coverage.
  • Red (scores 16-25): Critical risk. These demand immediate attention, comprehensive testing, and documented risk controls.

Clicking a Cell

Click any cell to see the list of requirements in that risk zone. This is useful during risk review meetings — you can quickly drill into the high-risk and critical-risk zones to see which requirements are driving the risk profile and whether they have adequate test coverage.

Summary Statistics

Below the matrix, summary statistics show counts of critical, high, medium, and low risk requirements, plus the number of unassessed requirements. The unassessed count is a signal: if it is high, the team has not completed its risk identification.


Amazon

AI-assisted risk classification software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Risk Taxonomies Explained

Different industries use different risk frameworks. QAtrial supports five risk taxonomies, and the appropriate one is selected based on the project’s vertical:

ISO 14971 — Medical Devices

The standard for risk management of medical devices. Focuses on patient safety, user safety, and environmental safety. Severity categories include negligible injury, minor injury, serious injury, and death. Used when the vertical is “Medical Devices.”

ICH Q9 — Pharmaceuticals

The International Council for Harmonisation guideline on quality risk management. Focuses on product quality, patient safety, and data integrity. Severity is assessed in terms of impact on product quality and patient outcomes. Used for “Pharmaceuticals,” “Biotechnology,” and “Clinical Research (CRO)” verticals.

GAMP 5 — Software and Computerized Systems

Good Automated Manufacturing Practice, 2nd Edition. Categorizes systems by their complexity and configurability (Categories 1, 3, 4, 5). Risk assessment focuses on the impact of software failures on GxP processes. Used for the “Software and IT (GAMP/CSV)” vertical.

FMEA — Failure Mode and Effects Analysis

A general-purpose risk assessment method that evaluates severity, occurrence (likelihood), and detectability. Commonly used in aerospace, clinical laboratories, logistics, and chemical/environmental industries. The three-factor model produces a Risk Priority Number (RPN) rather than a simple two-factor score.

Generic

A simplified risk taxonomy for verticals that do not have a domain-specific standard. Uses the basic severity-by-likelihood model without industry-specific severity categories. Used for “Cosmetics/Chemical” and any vertical without a more specific framework.

The taxonomy determines the labels and scoring criteria used in AI risk classification and in the risk matrix display. It also influences which standards the AI references when proposing risk levels.


How Risk Connects to Requirements, Tests, Evidence, and CAPA

Risk is not an isolated assessment. In QAtrial, it connects to the broader quality workflow:

  • Requirements: Every requirement carries a riskLevel field. Requirements loaded from templates often arrive with pre-assigned risk levels based on regulatory criticality. Risk classification (manual or AI-assisted) updates this field.
  • Tests: Higher-risk requirements should have more thorough test coverage. The Evidence dashboard highlights requirements that have a risk assessment but lack linked tests — a gap that auditors will notice.
  • Evidence: The Evidence tab tracks per-requirement completeness across three dimensions: linked tests, risk assessment, and approval signature. A requirement with a “critical” risk level but no linked tests is a visible gap.
  • CAPA: When a test linked to a high-risk requirement fails, the CAPA dashboard surfaces it prominently. The AI’s CAPA suggestion incorporates the risk level and applicable standards from the requirement, producing context-aware root cause proposals.
  • Compliance Score: The Compliance Readiness Score includes “Risk Assessed” as one of its five weighted components (15% weight). Additionally, if any requirement has a “critical” risk level, the overall score receives a 10-point penalty. This incentivizes teams to address critical risks rather than ignoring them.

How AI Risk Classification Works

QAtrial’s AI can classify the risk of individual requirements or perform bulk classification across all unassessed requirements.

Single Requirement Classification

On the Requirements tab, each requirement row has a “Classify Risk (AI)” button. Clicking it opens the Risk Classification Panel, which sends the requirement’s title, description, regulatory reference, tags, and the project’s vertical and country context to the configured LLM provider.

The AI returns:

  • Severity score (1-5) with rationale
  • Likelihood score (1-5) with rationale
  • Computed risk score (severity x likelihood)
  • Risk level (Low / Medium / High / Critical)
  • Safety class (when applicable for the vertical — for example, Class I/II/III for medical devices)
  • Confidence score (0-100%) indicating how certain the AI is about the classification

The team member reviews the classification and either accepts it (saving the risk level to the requirement and creating an “ai_accept” audit trail entry) or rejects it (creating an “ai_reject” entry). The AI’s reasoning is preserved as part of the provenance record.

Bulk Classification: “Classify All Unassessed”

On the Risk dashboard, if unassessed requirements exist, a “Classify All Unassessed” button appears. This sends each unassessed requirement to the AI in sequence, classifying them one by one. Results are saved directly to the requirements as they complete.

Bulk classification is useful when starting a new project with many template-generated requirements that need initial risk assessment. However, teams should review the results afterward — bulk AI classification is a starting point, not a final risk determination.


Final Takeaway

Risk management works when it is connected to the data it informs. In QAtrial, risk is not a standalone spreadsheet — it is a field on every requirement, a dimension on the dashboard, a factor in compliance scoring, and a context for CAPA analysis. The 5×5 matrix provides at-a-glance visibility. Five risk taxonomies ensure the framework matches the industry. AI classification accelerates initial assessment but does not replace human judgment.

The goal is not to eliminate risk. It is to identify it, assess it honestly, control it through adequate test coverage and mitigations, and document the process thoroughly enough that an auditor can follow the reasoning.


  • Requirements Management — How requirements carry risk levels, tags, and regulatory references
  • Audit Readiness — How risk assessment coverage contributes to the Compliance Readiness Score
  • How AI Works in QAtrial — How AI risk classification uses provenance tracking and confidence scoring

Explore the risk dashboard. QAtrial is developed privately and is not publicly available. Navigate to the Evaluation tab and open the Risk sub-tab to see the interactive 5×5 matrix and risk distribution across your project’s requirements.

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.