Part of The GMP Training AcademyAll GMP courses
All guides
Previews Module 4 11 minUpdated 15 Sept 2026

Root cause analysis for deviations: how to get past 'human error'

Why 'human error' is the most cited root cause failure in inspections, what a defensible root cause looks like, and how to use timeline analysis, 5 Whys and Ishikawa without producing a decorative diagram.

Inadequate root cause analysis is consistently one of the top three deficiency categories in published EU inspection data and EudraGMDP non-compliance statements. It is not that sites do not do root cause analysis; it is that they do it badly, and the result is a record that ends with 'human error' or 'procedure not followed' and a CAPA that says 'retrain'.

What a root cause is

A root cause is the underlying condition that, if removed, would prevent the event from recurring. Two tests: if you had fixed it before the event, would the event have happened? And can you fix it? If the answer to the second question is no, you have found a fact, not a root cause.

'The operator made an error' fails the second test. You cannot remove the operator's capacity to err. The question is why the error was possible, why it was likely, and why it was not detected. Those three questions each have answers that can be fixed.

Start with a timeline, not a tool

Before any analysis tool, build a timeline: what happened, in what order, who was there, what the records show, and where the records are silent. Most investigations that go wrong go wrong here, because the investigator started from the conclusion and worked back.

  1. Collect the objective evidence first: batch record, equipment logs, alarm logs, audit trails, training records, environmental data.
  2. Interview the people involved within 24 hours, separately, with open questions. Record what they say, not your summary of it.
  3. Lay out the sequence with timestamps. Mark every point where the record and the interview disagree.
  4. Identify the last point at which the event could have been prevented, and the last point at which it could have been detected. These are usually where the real causes sit.

5 Whys, done properly

5 Whys is criticised because it is often done as a single chain that stops at the first fixable thing. Used well, it branches. At each 'why', ask whether there is more than one answer, and follow each. Stop when you reach a condition you can change and that would have prevented the event.

Ishikawa without the decoration

A fishbone diagram is a prompt list, not evidence. It is useful for making sure you considered method, machine, material, measurement, environment and people. It is useless when every bone is filled in with 'N/A' except 'people'. If you use it, attach the evidence you used to rule each category in or out.

When 'human error' is acceptable

Occasionally, after a proper analysis, the honest conclusion is that a trained, competent person made a one-off slip in a well-designed process. That is acceptable if the record shows the analysis: what was considered, what was ruled out and why. What is not acceptable is human error as the first and only line of the root cause section, with retraining as the CAPA, for the third time this year.

Module 4 of the course works through three full investigations with the actual records, and you practise the timeline and branching 5 Whys on each before seeing the model answer.