How should deviations be classified and closed during validation?
Classify by whether the deviation affects a GxP-critical requirement's outcome, impacts data integrity, and whether a compensating control exists. Investigate to find the actual root cause, not just retest and move on. Open a CAPA only when the cause points to a systemic or recurring risk, and close it only after an effectiveness check confirms the fix worked.
A deviation closed with "retested, passed" and nothing else looks resolved. It isn't — it's just undocumented, which is a different and worse problem when the same failure shows up on a different system six months later.
Purpose and Trigger
A validation deviation is any unexpected result or departure from the approved protocol during IQ, OQ, or PQ execution — a failed test step, an unexpected system response, steps executed out of sequence, or an environmental condition outside what the protocol assumed. It doesn't need to change the final pass/fail outcome to count; anything that diverged from what the protocol specified gets documented.
Risk-Based Classification
| Class | Criteria | Response |
|---|---|---|
| Critical | Affects a GxP-critical requirement's outcome; no compensating control | Full investigation, broad impact assessment, likely CAPA |
| Major | Affects data integrity or a secondary requirement; partial compensating control | Root cause investigation, retest, CAPA if pattern suggests recurrence |
| Minor | No GxP impact; workaround or compensating control available | Documented correction and retest, closed without CAPA |
Step-by-Step Closure Workflow
- Document immediately. Record what happened before memory fades or the test environment resets.
- Classify by risk. Apply the criteria above before deciding investigation depth.
- Investigate the root cause. Not "what failed" but "why it failed" — a script error, a configuration issue, a genuine defect.
- Implement the correction. Fix the actual cause, not just the symptom that surfaced during testing.
- Retest and verify. Confirm the correction resolves the issue under the same conditions that revealed it.
- Close with evidence. Record the root cause, correction, and retest result — not just "resolved."
When Does a Deviation Need a CAPA?
Not every deviation does. A CAPA is warranted when the root cause points to something systemic — a flawed test script affecting multiple cases, a configuration error likely to recur on similar systems, a training gap touching more than one person. An isolated deviation with a clean, contained cause can be closed with a documented correction and retest alone.
Closing a CAPA is not the same as implementing the fix. An effectiveness check — a successful retest, a monitoring period showing no recurrence — has to confirm the correction actually worked before the CAPA closes. A CAPA closed the moment the fix ships, with no verification it held, leaves the same risk open under a closed label.
Required Records
- ✓ Unique deviation ID linked to the specific test step it interrupted.
- ✓ Risk classification with the reasoning behind it, not just the tier.
- ✓ Documented root cause, not a description of the symptom.
- ✓ Corrective action and retest evidence confirming resolution.
- ✓ Approver and closure date, with a reference to any linked CAPA.
How GoVal Supports Deviation Management
GoVal links every validation deviation directly to the test case it interrupted, capturing classification, root cause, corrective action, and retest evidence as one connected record rather than a form filed elsewhere. Effectiveness checks are tracked against the original deviation, so a CAPA can't be closed without the evidence confirming the fix actually worked.
Related Topics
Frequently Asked Questions
What counts as a deviation during computer system validation? +
How are validation deviations classified by risk? +
Does every validation deviation require a CAPA? +
What's required to close a CAPA opened from a validation deviation? +
What records does a validation deviation need? +
How does GoVal support validation deviation management? +
Close every deviation with evidence, not just a status update
Classification, root cause, and CAPA effectiveness checks — linked to the test itself, in GoVal.
