
Who Feels Calm When the Inspector Walks In?
Inspection readiness is often described as a state.
In reality, it is a moment.
The notification arrives. Diaries shift. Senior leaders send reassuring messages. QA begins coordinating. Someone suggests a refresher session. Someone else says, “We were fine last time.”
In that moment, pause and ask a harder question:
Who genuinely feels calm?
Not who says they are calm.
Who actually is.
Because calm is rarely about documents. It is about clarity. Ownership. And whether your confidence is grounded in evidence or in assumption.
Across this month’s edition, Gill and I examined whether mock inspections create reassurance rather than readiness. Thomas and I explored how vendor oversight often becomes the weak link in GLP environments. John and I highlighted the gap between validated systems and governed systems.
What sits beneath all three is something more structural.
Inspection readiness is not a QA condition.
It is an organisational capability.
And many organisations are operating under a set of comforting myths.
Myth 1: “QA Will Handle It”
This is rarely said explicitly. It does not need to be.
You see it in meetings. When a complex deviation is discussed, all eyes turn to QA. When a regulator’s question is replayed, QA answers on behalf of operations. When a study director hesitates in an interview scenario, someone says, “We’ll get QA to explain.”
On paper, this can look like strong oversight. In practice, it can indicate over-functioning.
Regulators are not assessing whether QA understands the system. They are assessing whether the organisation does.
Under ICH E6(R3), senior management retains accountability for the quality management system. Under OECD GLP, QA provides independent oversight, not operational substitution. If operational leaders cannot articulate risk decisions without QA in the room, the system is not embedded. It is propped up.
This becomes visible very quickly in inspection interviews. When answers are routed through QA, inspectors notice. When operational staff cannot explain why a decision was made, confidence erodes.
A useful internal test is simple. In your next risk review or deviation discussion, ask operations to present the rationale. QA observes.
If that feels uncomfortable, that discomfort is data.
Myth 2: “It’s Documented, Therefore It’s Controlled”
Most organisations can evidence activity:
SOPs are current.
CAPAs are closed.
Training matrices are complete.
Audit findings are trending downwards.
But documentation proves existence. It does not prove effectiveness.
Repeated minor findings often tell a story. CAPAs that address symptoms but not system drivers tell a story. Management review minutes that record discussion but no decision tell a story.
Inspectors increasingly probe beyond compliance artefacts. They ask:
What trends are you seeing?
How have those trends influenced resourcing?
Where is your highest residual risk?
What evidence do you have that this CAPA prevented recurrence?
If quality data does not influence leadership decisions, then quality governance is superficial.
A practical reflection point for senior leaders:
When was the last time a quality trend led to a change in resource allocation, process design, or vendor strategy?
If the answer is “rarely”, your documentation may be compliant, but your control is weak.
Myth 3: “The Regulators Are Happy With It”
This one is common. It is often said with relief.
“We’ve always done it this way.”
“The regulator has seen it before.”
“They didn’t raise it last time.”
“They’re happy with it.”
When we explore that statement more closely, something interesting emerges.
Very often, the regulator did not look at it.
Inspections are time-bound. They are risk-based. They are snapshots. Inspectors sample. They do not validate every control or interrogate every process.
Absence of challenge is not endorsement.
If a particular area was not selected for deep review, that tells you nothing about its compliance or effectiveness. It tells you it was not sampled.
This becomes more acute as regulatory focus evolves. Data integrity expectations have sharpened significantly over the last decade. Vendor oversight scrutiny has increased with greater outsourcing. Governance and senior management accountability are under more explicit examination, particularly under ICH E6(R3).
Relying on historical non-objection is a fragile strategy.
A stronger internal question is:
If this process were challenged tomorrow, could we defend not just what we do, but why we do it that way?
If the honest answer is “we think so”, you are operating on reassurance.
What Real Readiness Looks Like
Real readiness is rarely dramatic.
It looks like:
Senior management able to articulate the organisation’s top three quality risks without consulting a slide deck.
Study directors explaining deviation rationale in plain language.
Vendor oversight evidenced through active performance review, not archived audit reports.
Digital system owners able to describe change control impact and residual risk.
CAPA discussions that include prevention, not just closure.
It also looks like measured responses. Not defensive ones.
Calm in the inspection room does not come from rehearsal scripts. It comes from clarity of ownership and shared understanding.
Where readiness is embedded, interviews feel like conversations about a living system. Where readiness is superficial, interviews feel like performance.
Three Practical Moves This Month
If you are reading this as a QA leader or operational executive, here are three actions that will generate meaningful data about your current state.
1. Remove QA From One Critical Conversation
Choose a deviation review or risk assessment meeting. Ask operations to present the narrative and defend the rationale. QA remains silent unless invited.
Observe:
Are decisions explained clearly?
Is risk language understood?
Does ownership sit naturally with the right role?
If answers default to “QA would know”, you have a capability gap.
2. Stress-Test the “Regulator Is Happy” Assumption
Identify one long-standing practice that has never been challenged in inspection.
Ask:
Why do we do it this way?
What risk does it control?
Is that risk still valid?
How would we defend this if scrutinised today?
If the answer relies on historical precedent rather than current risk rationale, revisit it.
3. Test Leadership Alignment
At your next management review, ask three unscripted questions:
What is our most significant inspection vulnerability?
Where is vendor oversight most exposed?
What data integrity risk keeps you awake at night?
If answers vary widely, alignment is weak. And misalignment is visible under inspection pressure.
Bringing It Together
Across clinical, preclinical and digital domains, the technical manifestations differ.
In clinical environments, readiness fractures when narratives diverge.
In GLP environments, it fractures when vendor oversight is assumed.
In CSV environments, it fractures when validation masks governance weakness.
But the underlying pattern is consistent.
Inspection readiness fails when capability is concentrated in one function and not distributed across the organisation.
It fails when documentation substitutes for decision-making.
It fails when historical survival is mistaken for ongoing resilience.
So return to the original question.
If the inspector walked in tomorrow, who would feel calm?
And who would look to QA for reassurance?
Your answer tells you whether you are genuinely ready, or simply reassured.
If you would value an independent perspective on that question, we are always open to a candid conversation.
