Skip to main content

The Deviation Register

All deviations are listed with severity (Critical/High/Medium/Low), status, source, and date opened. Deviations are the backbone of your quality system — regulators look at how quickly you detect, investigate, and resolve them. Filter by severity to prioritize Critical and High items, and review aging regularly so long-running investigations don’t stall.

Create the deviation

  1. Go to Deviations → New deviation.
  2. Enter a title and description of what happened.
  3. Save. The deviation is created in open status and the creation is captured in the audit trail.

Classify

Classify the deviation (planned / unplanned) with a rationale. Classification is a signed action.

Start the investigation & assign the owner

When you start the investigation you assign the initial investigator who owns it (defaulting to you), so every deviation has a responsible owner from the moment investigation begins. Use Reassign investigator later to hand ownership to someone else — that reassignment is audit-logged with a reason for change.

Investigate & document root cause

Record a structured RCA (5-Whys or Fishbone): problem statement, contributing factors, and a root-cause conclusion.
A deviation cannot be closed without a documented RCA conclusion and a linked disposition (CAPA). This is an enforced completeness gate, not a convention.

Close

Closure requires an independent approver (the author/owner cannot self-close) and an electronic signature. This creates a Part 11-style signature manifestation linking the signer, meaning, timestamp, and record transition — do not close a deviation while evidence, containment, impact assessment, or linked CAPA decisions are still unresolved. Reopening a closed deviation also requires an independent signer and a reason for change.