Root Cause Analysis in Pharmaceutical Industry: 5 Whys, Fishbone, Examples & CAPA
Root cause analysis in the pharmaceutical industry is a structured, evidence-based investigation process used to understand why a quality problem occurred, how far its impact extends, and what must change to prevent recurrence.
A strong pharmaceutical root cause analysis does more than name a person, machine, or event. It defines the problem precisely, preserves and reviews evidence, evaluates the full scope, develops scientifically plausible causes, tests those causes where possible, distinguishes root causes from contributing factors, and connects the conclusion to appropriate corrective and preventive action (CAPA) and effectiveness checks.
21 CFR 211.192 requires a thorough investigation of unexplained discrepancies and specification failures, including extension to potentially associated batches and written conclusions and follow-up. The regulation does not require a specific tool such as 5 Whys or a Fishbone diagram. ICH Q10 recommends a structured investigation approach with the objective of determining root cause, while Health Canada GUI-0001 explicitly calls for an appropriate level of root cause analysis based on quality risk management.
- What Is Root Cause Analysis?
- FDA, ICH & Health Canada Expectations
- Root Cause vs Direct Cause vs Contributing Factor
- When Is RCA Used?
- RCA Investigation Workflow
- Define the Problem Correctly
- Evidence & Scope Assessment
- 5 Whys
- Fishbone Diagram
- Other RCA Tools
- Human Error as a Root Cause
- Hypothesis Testing
- RCA in OOS Investigations
- From RCA to CAPA
- CAPA Effectiveness Checks
- Practical RCA Examples
- Recent FDA Warning Letter Lessons
- Common RCA Mistakes
- Interview Questions
- FAQ
What Is Root Cause Analysis in the Pharmaceutical Industry?
Root Cause Analysis (RCA) is a structured investigation approach used to identify the underlying cause or causes that allowed a quality problem to occur. In pharmaceutical manufacturing and quality control, RCA is commonly used for deviations, OOS results, complaints, contamination events, equipment failures, recurring documentation errors, audit findings and other quality-system problems.
The goal is not merely to answer what happened. A useful investigation should also explain why it happened, what conditions made it possible, whether the same weakness exists elsewhere, and what actions will reduce the chance of recurrence.
An RCA conclusion should be supported by evidence. A convenient explanation is not the same as a demonstrated cause.
FDA, ICH and Health Canada Expectations for Root Cause Analysis
FDA - 21 CFR 211.192
For finished pharmaceuticals, 21 CFR 211.192 requires unexplained discrepancies and batch or component specification failures to be thoroughly investigated, whether or not the batch has already been distributed. The investigation must extend to other potentially associated batches and drug products, and a written record must include conclusions and follow-up.
The regulation itself does not prescribe 5 Whys, Fishbone, fault-tree analysis or any other named RCA tool. FDA inspection findings, however, repeatedly criticize investigations that close with unsupported causes, fail to assess manufacturing causes, do not evaluate recurrence, or implement ineffective CAPA.
ICH Q10 - Structured Investigation and CAPA
ICH Q10 describes CAPA as a pharmaceutical quality-system element and recommends a structured approach to the investigation process with the objective of determining root cause. It also states that the effort, formality and documentation of an investigation should be commensurate with risk, consistent with ICH Q9.
ICH Q9(R1) - Risk, Evidence and Subjectivity
ICH Q9(R1) reinforces risk-based decision-making and emphasizes appropriate use of evidence, science and knowledge. It also warns that subjectivity can affect risk assessment and decisions, so assumptions and bias should be recognized and controlled.
Health Canada GUI-0001
Health Canada explicitly states that an appropriate level of root cause analysis should be applied when investigating deviations, suspected product defects and other problems. The level can be determined using quality risk management principles. Importantly, if the true root cause cannot be determined, Health Canada says the most likely root cause or causes should be identified and addressed.
Health Canada also specifically warns against casually assigning human error: when human error is suspected or identified, it should be justified with objective evidence, and process, procedural or system-based issues should not be overlooked.
Root Cause vs Direct Cause vs Contributing Factor vs Correction
Weak investigations often mix these terms. Keeping them separate makes the final conclusion much stronger.
| Term | Meaning | Example |
|---|---|---|
| Direct / immediate cause | The event directly preceding the failure. | A valve was left open during transfer. |
| Root cause | The underlying controllable weakness that explains why the event was allowed to occur. | The procedure did not define valve-lineup verification and the design provided no status indication. |
| Contributing factor | A condition that increased likelihood or severity but may not alone explain the event. | High workload and poor valve labeling. |
| Correction | Immediate action to fix or contain the observed problem. | Close the valve and quarantine affected material. |
| CAPA | Actions designed to correct the underlying issue and prevent recurrence or related problems. | Revise line-clearance controls, improve labeling, add independent verification and assess similar systems. |
A root cause may be accompanied by several contributing factors. Complex events may also have multiple interacting causes; forcing every investigation into a single-cause explanation can oversimplify the real system failure.
When Is Root Cause Analysis Used in Pharma?
RCA can support investigations involving:
- manufacturing deviations and unexplained discrepancies;
- OOS and significant OOT results;
- product complaints and suspected quality defects;
- microbiological or environmental-monitoring excursions;
- equipment breakdowns or repeated alarms;
- cleaning failures or cross-contamination risks;
- data-integrity or documentation failures;
- recurring audit or inspection observations;
- supplier-related quality events;
- CAPA effectiveness failures or repeated deviations.
The depth of the RCA should be proportionate to the risk and complexity. A minor, well-understood event with clear evidence may need a simpler investigation than a sterility failure, recurring OOS trend, data-integrity concern or potentially distributed product defect.
For the broader deviation lifecycle, see Deviation in Pharmaceutical Industry.
Root Cause Analysis Workflow - Step by Step
Contain
Define
Gather Evidence
Map Causes
Test Hypotheses
Confirm Cause
CAPA
Verify Effectiveness
A useful workflow typically includes:
- Immediate control: protect product, patient, data and process while the investigation is open.
- Problem definition: describe exactly what failed, where, when and under what conditions.
- Evidence collection: review original records, raw data, equipment status, materials, procedures, training, environmental data and relevant history.
- Scope assessment: determine whether other batches, products, methods, equipment or sites may share the same failure mechanism.
- Cause generation: identify plausible causes without prematurely selecting a favorite explanation.
- Cause evaluation: compare hypotheses against evidence and perform scientifically justified tests when useful.
- Conclusion: classify the cause as confirmed, most probable, contributing, or unresolved based on evidence.
- CAPA and follow-up: select actions that address the causal mechanism and verify they are effective.
Step 1 - Define the Problem Correctly
A vague problem statement creates a vague investigation. “Tablet issue,” “analyst error” or “machine problem” does not define enough facts to investigate scientifically.
A stronger problem statement answers:
- What happened?
- Where did it occur?
- When did it occur?
- Which product, batch, method, instrument, line or process was involved?
- How much deviation from normal or specification occurred?
- What changed relative to normal performance?
- What is not affected, based on available evidence?
“Dissolution failed because of an analyst problem.”
Stronger statement:“Batch X produced one Stage 1 dissolution unit below the registered acceptance criterion during QC testing on Instrument HPLC-03 on 17 August, while system suitability passed and the previous three batches tested by the same method were within historical range.”
Step 2 - Collect Evidence and Determine Investigation Scope
Evidence should be gathered before the team locks onto a root cause. Depending on the event, useful evidence can include:
- original batch and laboratory records;
- raw chromatographic or electronic data;
- audit trails and sequence information;
- equipment logbooks, alarms, calibration and maintenance history;
- environmental and utility data;
- material lot history and supplier information;
- SOPs, methods, specifications and approved instructions;
- training and qualification records;
- deviation, complaint, OOS and OOT history;
- change-control history;
- trend and process-capability data;
- interviews conducted against documentary evidence.
21 CFR 211.192 is especially important for scope: the investigation must extend to other batches of the same drug product and other drug products that may have been associated with the specific failure or discrepancy.
Operator and analyst interviews are useful, but memory can be incomplete. Whenever possible, statements should be checked against timestamps, records, audit trails, equipment history and other contemporaneous data.
5 Whys Root Cause Analysis in Pharma
5 Whys is a simple questioning technique in which the investigator repeatedly asks why an event occurred until the causal chain reaches a deeper, actionable process or system issue.
The name does not mean every investigation must contain exactly five questions. Some causal chains require fewer; complex failures may require several branches and other tools.
Example - Repeated Line-Clearance Documentation Error
| Question | Evidence-Based Answer |
|---|---|
| Why 1: Why was the line-clearance record incomplete? | The operator omitted the component-verification entry. |
| Why 2: Why was the entry omitted? | The verification step was performed during a shift handover but responsibility for recording it was unclear. |
| Why 3: Why was responsibility unclear? | The SOP did not assign ownership when line clearance crossed shifts. |
| Why 4: Why did the SOP lack this control? | The process was originally designed for same-shift clearance and had not been updated after staffing patterns changed. |
| Why 5: Why was the change not reflected? | The staffing/process change was implemented without a documented assessment of affected GMP procedures. |
In this example, “operator forgot” is an immediate explanation. The deeper system weakness is that a process change occurred without evaluating the procedural controls needed for the new way of working.
When 5 Whys Works Well
- relatively simple events with a clear causal chain;
- documentation or procedural breakdowns;
- equipment or process events where each link can be supported by evidence.
When 5 Whys Is Not Enough
For complex contamination, sterility, cross-contamination, computerized-system, process-variability or multi-factor events, a single linear chain can be too simplistic. Fishbone, process mapping, fault-tree analysis, trending or cross-functional investigation may be more appropriate.
Fishbone Diagram (Ishikawa) for Pharmaceutical Investigations
A Fishbone diagram helps an investigation team organize possible causes into categories before evidence is used to confirm or reject them. A commonly used version is the 6M framework:
The Fishbone diagram is a cause-generation tool, not proof. Listing “Machine” or “Method” on a diagram does not establish root cause; each meaningful hypothesis still needs to be evaluated against evidence.
Other Root Cause Analysis Tools Used in Pharma
| Tool | Best Use | Important Limitation |
|---|---|---|
| Process mapping | Find where the actual process diverged from intended workflow. | Needs accurate reconstruction of what actually occurred. |
| Timeline analysis | Sequence alarms, actions, samples, changes and decisions. | Timing alone does not prove causation. |
| Is / Is Not analysis | Compare affected vs unaffected products, equipment, operators, periods or conditions. | Comparison groups must be scientifically relevant. |
| Fault Tree Analysis (FTA) | Analyze complex logical combinations of failures that can lead to a top event. | Can become complex and requires good system knowledge. |
| Pareto analysis | Prioritize frequent categories, defects or recurring causes. | Prioritizes problems; it does not by itself prove root cause. |
| FMEA | Proactively assess failure modes and risks; can support investigation scope and CAPA prioritization. | Primarily a risk-management tool, not a substitute for evidence-based RCA. |
ICH Q9(R1) supports risk-management tools in pharmaceutical quality but does not require one universal tool for every problem. Tool selection should match the event, available knowledge, uncertainty and risk.
Is “Human Error” an Acceptable Root Cause?
Sometimes - but only when supported by evidence and after deeper system factors have been considered.
Health Canada GUI-0001 is explicit: where human error is suspected or identified, it should be justified with objective evidence, and process, procedural or system-based errors should not be overlooked.
A recent FDA warning letter to Pharmathen International in May 2026 similarly criticized investigations that did not analyze the conditions that created the circumstances for human error and emphasized in-depth root-cause analysis to identify effective CAPA, including design remediation where appropriate.
Was the instruction clear? Was the operator trained and qualified? Was the task unnecessarily complex? Did the interface encourage the mistake? Was staffing appropriate? Were alarms visible? Did similar errors occur previously? Was the process changed without updating controls?
A purely individual lapse may occasionally be the most defensible explanation, but assigning human error without examining system design usually produces weak CAPA such as “retrain the operator,” which may not prevent recurrence.
Hypothesis Testing in Pharmaceutical Root Cause Analysis
Hypothesis testing can be useful when a suspected cause can be recreated or scientifically challenged. Health Canada GUI-0001 notes that hypothesis testing may be required to demonstrate a presumptive root cause in OOS investigations.
A scientifically useful hypothesis should be:
- based on a plausible failure mechanism;
- defined before the test is run;
- designed to discriminate between competing explanations where possible;
- performed under controlled, documented conditions;
- interpreted together with the original data, not used to erase inconvenient evidence.
If an OOS assay is suspected to result from incomplete sample extraction, a controlled study may compare the original preparation conditions with a scientifically justified extended extraction condition. The study should test whether the suspected mechanism can reproduce or explain the original pattern - not simply generate a passing result.
FDA's June 2026 warning letter to Huons illustrates the risk of poorly designed hypothesis testing: FDA criticized the use of a passing hypothesis experiment as justification to invalidate an original failing result when the test did not scientifically establish causation.
Root Cause Analysis in OOS Investigations
OOS investigations need particularly disciplined RCA because an initial failing result cannot be dismissed simply because retesting later passes.
FDA's OOS guidance establishes a staged investigation concept: first evaluate whether the laboratory can identify a clear assignable cause; if the laboratory investigation does not establish a cause, the investigation should expand beyond the laboratory and evaluate manufacturing and other possible contributors.
A sound OOS RCA may examine:
- analytical procedure execution;
- calculations, standards, reagents and sample preparation;
- instrument condition, system suitability and raw data;
- chromatographic processing and audit trails where applicable;
- sampling and sample handling;
- batch manufacturing records;
- equipment and process performance;
- raw-material variability;
- deviation, complaint and previous OOS/OOT history;
- stability trends when the event occurs during stability testing.
For a dedicated investigation workflow, see OOS in Pharmaceutical Industry: Investigation, Phase I & II. For abnormal trends that remain within specification, see OOT Results in Pharmaceutical Industry.
From Root Cause Analysis to CAPA
RCA has little value if the resulting action does not address the causal mechanism. ICH Q10 links structured investigation directly to the CAPA system and states that CAPA should lead to product and process improvement and enhanced understanding.
| Root Cause | Weak CAPA | Stronger CAPA Direction |
|---|---|---|
| Procedure is ambiguous at shift handover. | Retrain operator. | Redesign handover step, assign ownership, revise form and train affected staff. |
| Equipment control allows wrong set point without independent confirmation. | Remind operators to be careful. | Add engineered or procedural verification and assess similar equipment. |
| Recurring HPLC issue caused by inadequate maintenance control. | Replace one column and close. | Correct immediate equipment issue, revise maintenance/monitoring strategy, assess similar instruments and trend recurrence. |
For the full quality-system process, see CAPA in Pharmaceutical Industry.
CAPA Effectiveness Checks - Did the Root Cause Really Get Controlled?
Closing a CAPA because all actions were completed is not the same as demonstrating effectiveness.
An effectiveness check should be designed around the original failure mechanism. Depending on the issue, it may include:
- absence or reduction of recurrence over a justified period;
- review of several subsequent batches or campaigns;
- trend improvement;
- successful audit of revised process execution;
- performance of equipment or system after modification;
- reduction in alarms, documentation errors or defects;
- verification that related processes were also remediated when scope was broader.
Health Canada GUI-0001 specifically expects corrective/preventive actions to be monitored and their effectiveness assessed. ICH Q10 likewise states that CAPA effectiveness should be evaluated.
Practical Root Cause Analysis Examples in Pharma
Example 1 - HPLC Assay OOS
Event: An assay result is below specification while system suitability passes.
Weak conclusion: “Analyst error.”
Stronger investigation: Review sample preparation, calculation, standard preparation, instrument sequence, chromatograms, integrations, audit trails, column and instrument history, sample handling, manufacturing data and related trends. If a specific preparation error is suspected, test the mechanism under a predefined hypothesis.
Possible evidence-supported conclusion: The sample was incompletely extracted because the method instruction did not specify a required mixing sequence after a recent formulation matrix change. The issue is therefore procedural/method-related, with the analyst action as a contributing factor rather than the entire root cause.
For chromatography-specific controls, see HPLC in Pharmaceutical Quality Control.
Example 2 - Repeated Tablet Weight Variation
Event: Several batches show intermittent weight variation near the in-process action limit.
Evidence: The events cluster after feeder disassembly and reassembly. Maintenance records show different setup practices between technicians. The equipment manual provides a dimensional setting but the site SOP does not define a verification step.
Root cause: Inadequate standardized setup and verification after feeder reassembly.
Contributing factor: The equipment design permits multiple acceptable-looking assembly positions.
CAPA direction: Standardize assembly, add measurable setup verification, train technicians, evaluate an engineering poka-yoke or design improvement, and review similar presses.
If equipment design or qualified state is implicated, see Equipment Qualification in Pharmaceutical Industry.
Example 3 - Recurring Documentation Error
Event: Operators repeatedly miss a second-person verification field.
Weak CAPA: Retrain all operators.
RCA finding: The verification is required at a point where the second operator is commonly assigned to another room, causing workarounds and delayed documentation.
Stronger CAPA: Redesign the workflow, define when the verifier must be available, revise the procedure/form, assess staffing and then train on the new control.
Recent FDA Warning Letter Lessons for RCA
Recent FDA warning letters continue to show that investigation quality remains a significant inspection focus.
The common lesson is that a plausible story is not enough. The conclusion needs scientific rationale, appropriate scope, documented evidence and CAPA that addresses the actual failure mechanism.
Common Root Cause Analysis Mistakes
Root Cause Analysis Interview Questions
What is root cause analysis in pharma?
It is a structured, evidence-based investigation used to identify the underlying cause or causes of a quality problem, assess its scope and impact, and support effective CAPA.
What is the difference between root cause and contributing factor?
A root cause is an underlying weakness that explains why the problem was allowed to occur, while a contributing factor increases the likelihood or severity but may not independently explain the event.
Does FDA require 5 Whys or Fishbone?
No. FDA requires appropriate and thorough investigation under applicable CGMP requirements, but it does not mandate one specific RCA tool for every investigation.
Can human error be a root cause?
It can be part of the conclusion when supported by objective evidence, but investigators should also examine process, procedure, design and system factors rather than stopping at the person involved.
What if no definitive root cause is found?
Do not invent one. Document the evidence and uncertainty, identify the most likely causes where justified, assess risk and scope, and implement controls appropriate to the remaining risk. Health Canada specifically recognizes this situation.
How do you know a CAPA is effective?
The effectiveness check should demonstrate that the original failure mechanism has been controlled, for example through recurrence monitoring, trend improvement, successful process execution or verified equipment/system performance.
Contain → define the problem → preserve evidence → assess scope → generate possible causes → test against evidence → determine confirmed or most probable root cause → implement targeted CAPA → verify effectiveness.
Frequently Asked Questions
Is root cause analysis mandatory for every deviation?
The depth of investigation should be proportionate to risk and governed by the site's quality system and applicable GMP requirements. Significant deviations and quality failures require appropriate investigation; not every minor event necessarily needs the same level of formal RCA.
Is retraining a CAPA?
Retraining can be part of CAPA when a demonstrated knowledge or execution gap exists, but it is weak when the underlying cause is an unclear procedure, poor process design, equipment weakness, workload issue or missing control.
Can an investigation have more than one root cause?
Yes. Complex failures can result from multiple interacting causes and contributing factors. The investigation should reflect the evidence rather than force a single-cause model.
What is the difference between 5 Whys and Fishbone?
5 Whys follows a causal questioning chain and works well for relatively simple problems. Fishbone organizes multiple possible causes by categories and is more useful when several pathways need to be explored.
Is FMEA a root cause analysis tool?
FMEA is primarily a proactive quality-risk-management tool used to identify and prioritize potential failure modes. It can support investigation and CAPA decisions, but it does not replace evidence-based root cause analysis.
Can a passing retest prove laboratory error?
No. A passing retest by itself does not establish the cause of the original failure. The original result must be evaluated through a scientifically sound investigation and any invalidation must be supported by evidence.
Related Pharma Quality Guides
- Deviation in Pharmaceutical Industry
- CAPA in Pharmaceutical Industry
- OOS in Pharmaceutical Industry
- OOT Results in Pharmaceutical Industry
- HPLC in Pharmaceutical Quality Control
- Equipment Qualification in Pharmaceutical Industry
- Change Control in Pharmaceutical Industry
- Data Integrity in Pharmaceutical Industry
- GMP in Pharmaceutical Industry
Official and Authoritative Sources
- 21 CFR 211.192 — Production Record Review and Investigations
- FDA — Investigating Out-of-Specification (OOS) Test Results for Pharmaceutical Production
- FDA / ICH Q10 — Pharmaceutical Quality System
- FDA / ICH Q9(R1) — Quality Risk Management
- FDA — Quality Systems Approach to Pharmaceutical CGMP Regulations
- Health Canada — Good Manufacturing Practices Guide for Drug Products (GUI-0001)
- FDA Warning Letter — Pharmathen International S.A. (May 2026)
- FDA Warning Letter — Medical Products Laboratories, Inc. (April 2026)
- FDA Warning Letter — Huons Co., Ltd. (June 2026)
Strong pharmaceutical RCA is not about filling a Fishbone diagram or writing “human error.” It is about using evidence to understand the failure mechanism, defining the full scope and impact, distinguishing confirmed causes from assumptions, and implementing CAPA that changes the system enough to prevent the problem from recurring.








Comments
Post a Comment