QMSdesk

RegulationsICH

ICH Q10 pharmaceutical quality system: the four elements, mapped

The ICH Q10 pharmaceutical quality system is a harmonized model for an effective quality management system across the whole product lifecycle, from development and technology transfer through commercial manufacturing to product discontinuation. It applies to drug substances and drug products, including biotechnology and biological products. ICH Q10 is a guideline, not a regulation. It reached Step 4 of the ICH process on June 4, 2008. FDA issued it as guidance in April 2009. In the EU it is reproduced in Part III of the GMP Guide (EudraLex Volume 4), and Chapter 1 of the GMP Guide was revised to align with its concepts, in operation since January 31, 2013. It builds on regional GMP requirements, ICH Q7 and ISO quality concepts, and where it goes beyond regional GMP requirements, it is optional.

The PQS elements and enablers of an ICH Q10 pharmaceutical quality system

ICH Q10 §3.2 names four elements that a pharmaceutical quality system should run, applied in proportion to each lifecycle stage:

  1. Step 1 of 4

    Process performance and product quality monitoring

    (§3.2.1): a planned way to show your processes stay in a state of control, and to find where to improve.

  2. Step 2 of 4

    Corrective action and preventive action (CAPA)

    (§3.2.2): acting on complaints, rejections, nonconformances, recalls, deviations, audits, inspections and trends, with investigation effort in proportion to risk.

  3. Step 3 of 4

    Change management

    (§3.2.3): evaluating, approving, implementing and then reviewing changes, with risk setting the level of effort.

  4. Step 4 of 4

    Management review of process performance and product quality

    (§3.2.4): assurance that process performance and product quality are managed over the lifecycle, with quality issues escalated to senior management.

Two enablers make the elements work (§1.6): knowledge management, managing product and process knowledge through the lifecycle, and quality risk management, which ICH Q10 links to ICH Q9.

ICH Q10 CAPA and change management: why they're peer systems

ICH Q10 lists the CAPA system and the change management system as separate elements, each with its own purpose. A CAPA is a commitment to fix a cause and prove the fix held. A change is a controlled modification to a process, product, system or document. Q10 also lists CAPA among the things that drive change, so the two need to connect without being merged.

That's how QMSdesk™ models them. A CAPA is its own record, a peer of change control, not a stage inside a deviation. It can start from a deviation, a complaint, an audit finding, a trend, a management review or an observation, with a typed link to its source. When QA approves an action plan that calls for a document change or training, QMSdesk raises the linked change control and training before implementation starts. The change then runs its own lifecycle, with its own approvals and its own independent verification. After the CAPA closes, a scheduled check confirms the effect held. If it didn't, a new CAPA is raised and linked, and the signed record stays exactly as it was.

The ICH Q10 section-to-control map

ICH Q10 section (paraphrased) How QMSdesk supports it Evidence the system produces What you still own
§1.8, §2.1–2.5 Quality manual, management commitment, quality policy, planning, resources, communication Document control holds your quality manual and policy, with signed authoring, review and approval. The author never reviews or approves their own document, and training is assigned on approval. Signed document history with each signature's meaning; training records. The content: your policy, objectives, plans and resourcing decisions.
§1.6.1 Knowledge management Controlled and reference documents with typed cross-references; typed, attributed links between quality records; global search across documents, events, changes, audits, suppliers, training and risks. A navigable record of what's linked to what, by whom and why. Product and process knowledge from development, technology transfer and validation, much of which lives outside a QMS.
§1.6.2 Quality risk management A risk register built on ISO 14971 and ICH Q9(R1) principles: 5×5 or FMEA scoring, severity dominance, signed assessments and signed residual risk. Event investigation depth scales with severity. Signed risk assessments and residual-risk decisions in the audit trail. Your risk-management procedure and the scientific judgment behind each assessment.
§2.7 Outsourced activities and purchased materials Supplier qualification by risk tier, with review every 6, 12 or 24 months; corrective-action requests answered through a single-use link; quality agreements held as reference documents. The Contract operations profile adds QA-agreement deviation events. Signed supplier status decisions; a supplier scorecard; SCAR history. Supplier audits, the written agreements themselves, and incoming-material controls.
§2.8 Change in product ownership No dedicated workflow. Change control can record the transfer as a planned change. The change record, if you use one. Defining each company's ongoing responsibilities and transferring the information needed.
§3.2.1(a)–(d), (f) Control strategy; measuring and analyzing parameters and attributes; sources of variation; process knowledge Outside QMSdesk's scope. QMSdesk doesn't hold batch, process or in-process data. None. Your control strategy, and the batch, process, statistical and stability data in your manufacturing and laboratory systems.
§3.2.1(e) Feedback from complaints, rejections, nonconformances, recalls, deviations, audits and regulatory inspections Complaints, deviations and audit findings are recorded in QMSdesk, nonconformances with signed disposition and recalls under the GMP profile. Events trend by type, severity, site, product and root cause. OOS lab-error invalidations trend by method, analyst and instrument. Trend views by type, severity, site, product and root cause, and the lab-error trend. Deciding what the feedback and trends mean for your processes, including inspection findings, and acting on them.
§3.2.2 CAPA from complaints, rejections, nonconformances, recalls, deviations, audits, inspections and trends; root cause; effort in proportion to risk CAPA as its own record, raised from events, audit findings, trends, reviews or directly. Root cause and category recorded. QA reviews each action item for moderate, major and critical CAPAs. Signed action-plan review, verification and closure; action items with evidence. Your CAPA procedure and the quality of each investigation.
§3.2.2 (Table II) Evaluate CAPA effectiveness Effectiveness verification can't be skipped. After closure, a scheduled check confirms the effect held, over an interval you set. Scheduled checks and their outcomes; a new linked CAPA if a fix didn't hold. Setting the effectiveness criteria for each CAPA, and the check interval.
§3.2.3(a), (c) Evaluate changes by risk, with the right expertise Risk-based approval routing: high-impact changes need the Change Manager and the Quality Manager. Classification can raise a tier, never lower it. Approvers can be added, never removed. Signed approvals, each with its recorded meaning. Choosing the experts, and setting prospective evaluation criteria.
§3.2.3(b) Assess whether a change affects the regulatory filing Your procedure. The Assessment stage records the change's impact and risk. The assessment on the change record. The regulatory-filing determination and any submission.
§3.2.3(d) Evaluate the change after implementation A Verification stage, signed by someone other than the implementer. When a change affects training, training for affected roles is assigned on implementation. Signed verification; training assignments linked to the change. Confirming the change met its objectives without harming product quality.
§3.2.4, §2.6 Management review of process performance and product quality A signed, frozen snapshot of your quality records, taken across your whole organization as of the period end: CAPA aging, events trending, training compliance, audit findings, the risk register, the supplier scorecard and document status. Minutes and decisions signed at closure; follow-up actions tracked afterwards. The snapshot, signed minutes and decisions, and open follow-ups. Conclusions on process performance and product quality, such as product quality review outcomes and the effectiveness of changes, and your leadership's decisions.
§4.1 Management review of the PQS itself The same snapshot covers complaint, deviation, CAPA and audit performance. A CAPA can be raised from a review with no triggering event. A CAPA linked back to the review. Your quality objectives and performance indicators.
§4.2 Monitoring of internal and external factors Reference documents record external standards and guidance with their issuing body and version, and a periodic currency check asks whether each is still the current issue. Reference documents with their provenance and currency checks. Watching for new regulations, guidance, quality issues, innovations and business changes, and acting on them.
§4.3 Outcomes of management review and monitoring Minutes and decisions signed at closure; follow-up actions stay assignable after closure until they're done. Signed minutes and decisions; follow-up actions. Improvements, resource and training decisions, revisions to your quality policy and objectives, and communicating the results.

Process performance and product quality monitoring: what QMSdesk does, and what it doesn't

Be clear-eyed about this element. Much of it runs on data QMSdesk doesn't hold.

What QMSdesk does. It captures the kinds of quality feedback Q10 §3.2.1(e) names, such as complaints, nonconformances, recalls (under the GMP profile), deviations and audit findings, and also OOS and OOT results. Events trend by type, severity, site, product and root cause, and OOS lab-error invalidations trend by method, analyst and instrument. The Command Center shows where your quality system stands today, and its figures open the records behind them. When a trend needs action, a CAPA starts from the trend itself.

What it doesn't do. QMSdesk holds no batch records, process parameters, in-process controls, statistical process control or stability data, and it doesn't compile your annual product quality review. Those stay in your manufacturing, laboratory and data systems, and your procedure for bringing their conclusions to management review stays yours.

Where ICH Q10 sits in QMSdesk

ICH Q10 is carried by three of QMSdesk's regulatory profiles: GMP, GCP and Contract operations, which draws on §2.7 for work done under a client's quality system. QMSdesk is designed to support the CAPA, change management and management review elements of your pharmaceutical quality system, and its risk engine is built on ISO 14971 and ICH Q9(R1) principles. Your pharmaceutical quality system is established and proven by you, in your organization.

Kept current

What changed recently

  1. ICH Q10 itself is unchanged

    The current version is still the Step 4 guideline dated June 4, 2008. ICH Q10 guideline

  2. October 30, 2024

    The ICH Assembly approved revision 5 of the ICH Q8, Q9 and Q10 Questions and Answers. ICH Q&As (R5)

  3. January 18, 2023

    ICH adopted ICH Q9(R1), the revised quality risk management guideline behind Q10's risk enabler. ICH Q9(R1)

  4. Status in the EU, checked September 24, 2026

    ICH Q10 remains listed in Part III of EudraLex Volume 4. EudraLex Volume 4

PDF and Excel

Regulation checklist

The tables from this page, with a column for your own evidence. No form to fill in.

ICH Q10 FAQ

What are the four PQS elements in ICH Q10?

Process performance and product quality monitoring, corrective and preventive action (CAPA), change management, and management review of process performance and product quality. Knowledge management and quality risk management are the two enablers.

Is ICH Q10 mandatory?

ICH Q10 is a guideline. It builds on regional GMP requirements, which are mandatory where they apply, and states that its content beyond them is optional. In the US it is FDA guidance, which is not binding. In the EU, Chapter 1 of the GMP Guide was aligned with its concepts. Q10 §1.4 also notes that the effectiveness of a pharmaceutical quality system can normally be evaluated during a regulatory inspection at the manufacturing site.

Should CAPA be separate from deviations and change control?

ICH Q10 treats the CAPA system and change management as separate elements. In QMSdesk, a CAPA is its own record, linked to the deviation or other source that prompted it, and its approved action plan raises the change control it needs.

Can QMSdesk run our annual product quality review?

No. QMSdesk doesn't hold batch or process data and doesn't compile a product quality review. It does supply the complaint, deviation, CAPA, change and audit records that feed one, and the trends across quality events.

How does QMSdesk support ICH Q10 management review?

With a signed, frozen snapshot of your quality system as of the period end, signed minutes and decisions, and follow-up actions that stay open until they're done. A reviewer can open a CAPA from a review decision and link it back to the review.

Reviewed by a practitioner

Abdul Azam, Founder & CEO, 25 years in regulated life-sciences quality. Last reviewed September 26, 2026. Next review December 2026. This guide is general information, not legal or regulatory advice.

Bring one workflow. We'll show you QMSdesk running it.

Bring a deviation that became a CAPA and a change. We'll show you QMSdesk running all three, linked, from the first signal to the effectiveness check.