What is in Arc D
- What makes a root cause "conclusive" — the difference between FDA's "probable cause" floor and the bar a defensible CAPA actually needs
- CAPA impact assessment: how far it has to reach — why "no product impact" is a conclusion that has to be earned, not assumed
- Does every CAPA need an effectiveness check? — what ICH Q10 actually says, and what a real effectiveness check looks like
- Putting it together: what a valid CAPA requires — three pillars, each capable of failing on its own, mapped to Arc E's case studies
This arc answers the questions this course was built around. Arc E closes with the three enforcement case studies previewed throughout this arc, each mapped to a different way this framework breaks down in practice.
What makes a root cause "conclusive"
A CAPA is only as good as the cause it targets. This module draws the line between a cause that is merely probable and one that is actually conclusive enough to build a corrective action on.
D1.1 A higher bar than Phase II's own floor
Requirement Arc A and Arc C both covered FDA's Phase II documentation requirement: an assignment of actual or probable cause. That word "probable" is doing real work — it is FDA's stated floor for closing a Phase II investigation's documentation. A CAPA is a different commitment: resources, process changes, and a firm's own confidence that the problem is actually fixed. A conclusive root cause — corroborated, reproducible, and defensible against the alternative explanations that were actually considered and ruled out — is the bar this course treats as necessary before a CAPA can be called valid, even where "probable" would have been enough to close the investigation file itself.
D1.2 What actually elevates "probable" to "conclusive"
Practice Three things generally distinguish a conclusive cause from a merely probable one: the failure can be reproduced under controlled conditions consistent with the proposed cause — exactly the work Arc C's R&D-escalation practice is built to do; the plausible alternative explanations were actually considered and ruled out, not simply left unexamined because the first explanation was convenient; and the reasoning is documented well enough that an independent reviewer, including a regulator, could follow it and reach the same conclusion.
Requirement ICH Q10 states this as a matter of principle: a structured approach to the investigation process should be used with the objective of determining the root cause. Structure is what makes a cause reproducible and independently reviewable in the first place — an unstructured, ad hoc search for an explanation rarely survives that kind of scrutiny.
FDA's 2026 warning letter to Medline Inc. describes nine separate documented investigations into Bacillus cereus contamination between June 2023 and August 2025 that, in FDA's words, "failed to adequately identify the root causes of contamination." FDA drew the connection directly: "Inadequate investigations can lead to unidentified root causes, ineffective CAPA, and recurring problems that may pose a patient safety hazard." Nine investigations, and the same contamination kept recurring — which is precisely what an unconfirmed, merely probable cause puts at risk. Arc E covers this letter in full.
Module D1 — conclusive root cause
Five questions.
CAPA impact assessment: how far it has to reach
A conclusive root cause answers what happened. Impact assessment answers what else it might have touched — and that question turns out to be just as easy to get wrong.
D2.1 211.192's scope requirement, worked out in practice
Requirement Arc A introduced 211.192's requirement that an investigation extend to other batches of the same product and other products that may share the same failure or discrepancy. A CAPA's impact assessment is where that requirement is actually carried out: identifying every batch, product, distributed lot, ongoing stability program, and validated process that could plausibly share the confirmed cause, and documenting the basis for each conclusion reached about them.
D2.2 "No product impact" is a conclusion, not a default
Practice It is tempting to treat "no other products are affected" as the assumed answer unless proven otherwise. It is not. A conclusion that nothing else was affected requires the same kind of documented evidence as any other finding in the investigation — it is a substantive claim, and it has to be earned.
FDA's 2026 warning letter to Genzyme Ireland Limited found that the firm "cancelled numerous deviations without investigating the root cause or assessing product impact." For one specific deviation (QE-1679805), FDA found the firm's "no product impact" conclusion "not adequately supported due to discrepancies," requiring a revised investigation addressing root causes. The conclusion itself wasn't necessarily wrong — the problem was that it wasn't actually supported by evidence, which is exactly the gap this module is warning against. Arc E covers this letter in full.
D2.3 Beyond the batches already on the shelf
Requirement A properly scoped impact assessment also looks at ongoing stability programs and validated processes that may rely on data affected by the same confirmed cause — the same ground MHRA's Phase III, covered in Arc C, is built to review. A cause confirmed today can call into question conclusions a firm already reached and relied on before the investigation even began.
Module D2 — impact assessment
Six questions.
Does every CAPA need an effectiveness check?
Root cause and impact assessment both look backward, at what happened and what it touched. This module is about the one piece of a CAPA that looks forward: did the fix actually work?
D3.1 ICH Q10's answer, directly
Requirement ICH Q10, Section 3.2.2, states the expectation plainly. The pharmaceutical company should have a system for implementing corrective actions and preventive actions resulting from the investigation of complaints, product rejections, non-conformances, recalls, deviations, audits, regulatory inspections and findings, and trends from process performance and product quality monitoring. And, critically:
“CAPA should be used and the effectiveness of the actions should be evaluated.”ICH Q10, Pharmaceutical Quality System, Section 3.2.2, Table 2.
Requirement That is a direct answer to the question this module is named after: yes, evaluating whether a CAPA's actions actually worked is part of the same expectation as implementing them in the first place. Implementation without evaluation is only half of what ICH Q10 describes.
D3.2 What an effectiveness check actually looks like
Practice In practice, an effectiveness check is a planned, documented follow-up review conducted after the corrective or preventive action has been implemented — typically continued monitoring of the relevant parameter or trend over a defined period, specifically to confirm the action resolved the issue and did not introduce a new one. It is not a review of the plan on paper before anything has been done; it is evidence gathered afterward.
D3.3 Scaled to risk, not skipped for it
Requirement ICH Q10 is equally clear that the level of effort, formality, and documentation of the investigation — and, by extension, its CAPA — should be commensurate with the level of risk, in line with ICH Q9. A low-risk finding can reasonably carry a lighter-weight effectiveness check than a finding tied to patient safety. Scaled is not the same as skipped: risk determines how much evaluation is appropriate, not whether any evaluation happens at all.
Requirement ICH Q10 frames the payoff of doing this well directly: CAPA methodology should result in product and process improvements and enhanced product and process understanding — not simply a closed file.
Module D3 — effectiveness check
Six questions.
Putting it together: what a valid CAPA requires
Three modules, three questions, three ways a CAPA can quietly fail even when it looks complete on paper.
D4.1 Three pillars, three separate ways to fail
Requirement A valid CAPA rests on all three of the pillars this arc has covered. Each answers a different question, and each can fail independently of the other two — a strong root cause does not compensate for a missing impact assessment, and a well-scoped impact assessment does not compensate for a skipped effectiveness check.
| Pillar | Question it answers | What failure looks like | Covered in |
|---|---|---|---|
| Conclusive root cause | What actually caused this, with real confidence? | A "probable" cause treated as sufficient; the first plausible story, unexamined against alternatives | Module D1; Medline Inc. (Arc E) |
| Impact assessment | What else could this same cause affect? | "No product impact" asserted without supporting evidence | Module D2; Genzyme Ireland (Arc E) |
| Effectiveness check | Did the corrective action actually work? | Implementation treated as the finish line, with no planned follow-up | Module D3; ICH Q10 §3.2.2 |
D4.2 Where each failure has already happened
Practice Arc E closes this course with three real, current FDA warning letters, each mapped to a different failure this course has now covered in full: Medical Products Laboratories, Inc. for invalidating OOS results without documented assignable cause (Arc B); Medline Inc. for root cause investigations that never actually identified why contamination kept recurring (Module D1); and Genzyme Ireland Limited for CAPA decisions, including impact assessments, that FDA found unsupported by the underlying evidence (Module D2).
Every idea in this arc has, by now, appeared somewhere else in this course first — assignable cause from Arc B, 211.192's scope requirement from Arc A and Arc C, MHRA's Phase III from Arc C. That repetition is deliberate. A CAPA is not a separate system bolted onto the end of an OOS investigation; it is the same discipline this entire course has been building, applied to the last and most consequential decision the investigation produces. Arc E closes the course with the enforcement record behind all of it.
Module D4 — putting it together
Five questions.