A deviation report arrives with a batch you have already paid for. The questions you send back in the first two days decide whether that document protects your process — or only protects the supplier who wrote it.
The email you hope not to receive
It usually arrives on an ordinary morning, from an address you rarely hear from. “We would like to inform you of a deviation identified during batch review of [batch number].” A sentence or two of description.
A closing line — “no impact on product quality is expected” — and a signature from the supplier’s quality department. The material is already in your warehouse under your purchase order number — and now a paper says something about it did not go the way the process says it should.
We sit on the other side of this exchange: we are the ones writing and sending these reports. So let us tell you something most suppliers will not say out loud. The first draft of a deviation report is written to be acceptable, not to be complete.
Nobody sets out to hide anything, but fear of rejection shapes what goes in — the description gets shorter, the impact line gets smoother, the scope stays conveniently narrow.
What the buyer does next determines whether a second, more honest version ever exists. In our experience, the buyers who get the truth are not the ones with the sharpest contract language. They are the ones who reply within a day or two with specific, hard-to-dodge questions.
This guide is what we would tell a customer to look for if one of our reports landed in their inbox — including the questions that make a quality department take the reply seriously.
What a deviation report is — and what it is not
A deviation is a departure from an approved instruction: a process parameter that drifted outside its limit, a holding step that ran long, a cleaning cycle repeated. The key word is unplanned.
Change control covers what you approve before it happens; a deviation is what gets discovered after. ICH Q7, the quality guide for API manufacture, requires deviations to be documented and critical deviations to be investigated with the conclusions recorded, and ICH Q10 places deviation and event management inside the manufacturer’s pharmaceutical quality system.
Most intermediate producers follow the same discipline even where the rules are less explicit, because their API customers audit against it.
What a deviation report is not: an apology, a confession of a failed batch, or — and this is the part buyers sometimes get backwards — bad news. A supplier whose quality system never reports deviations is either running a flawless operation or, far more likely, one that is not looking very hard.
The reports that reach your inbox are evidence that someone downstream of the batch record is awake. Read them that way and the conversation changes: the question is no longer “why did this happen to us” but “what does this document actually tell me about the batch, and about the company that wrote it.”
Reading the report: where the weight sits
Six sections of a deviation report carry almost all the practical weight for an intermediate buyer.
| What you see | What good looks like | What should make you read twice |
|---|
| Batch scope | Every affected lot named, with a stated reason for why the boundary falls where it falls | A single batch named with no word about adjacent lots or shared equipment |
| Description of events | A sequence of facts: what was set, what was found, who acted, when | Conclusions pasted in where facts belong — “a minor issue was resolved” tells you nothing |
| Root cause | A chain of reasoning that ends at something fixable | “Human error” as a full stop, or a cause that conveniently requires no action |
| Impact on product | Test data, or a named reference to test results supporting the assessment | “No impact is expected” with no data behind it — expected by whom, based on what |
| Corrective and preventive action | A specific action plus how its effectiveness will be checked | Retraining as the entire plan, with no verification step anywhere |
| Notification timeline | When the event occurred, when it was detected, when you were told | A long unexplained gap between detection and notification |
The description and the root cause deserve the most patience, because they are where a thin report hides.
A useful habit is to compare the description against what you already hold — the certificate that arrived with the shipment, your own arrival inspection results — and check that the story matches the numbers in your hands.
When the impact assessment cites test data, apply the same instinct you would to any certificate claim: verify rather than trust.
The questions that separate an investigation from paperwork
A one-line reply (“noted, thanks”) signals that no second version is needed. What buys you the real report is a set of specific questions, sent quickly.
Five carry most of the weight. How a supplier answers them — fluently, with data, or defensively, with prose — is the same judgment you make when reading a supplier’s technical answers, and it is just as revealing here.
Which other batches were exposed to the same condition?
The scope section names what was affected. The question names what could have been. Shared equipment, shared solvent recovery, a holding vessel cleaned on the same shift — if the report never mentions adjacent exposure, ask.
A supplier who has genuinely bounded the problem can answer in a sentence; one who has not will answer in a paragraph that says nothing.
What evidence separates the root cause from the best guess?
Root cause analysis is where reports get weakest, because honest uncertainty is uncomfortable to write.
Asking for the evidence — data, records, a logical chain — does not demand perfection. It demands that the words “root cause” appear only when something points there.
What data shows this did not reach the product?
“No impact on product quality” is a conclusion. You are entitled to the basis: which tests, on which samples, against which acceptance criteria.
If the assessment rests on process knowledge alone, say so, and let the buyer decide whether that is enough.
What stops this from happening again — and how will you know it worked?
A corrective action without a verification step is a promise made to nobody. Ask when effectiveness will be checked and by what measure.
The answer tells you whether the supplier’s quality system closes loops or only opens them.
When did it happen, when did you find it, and when did you decide to tell us?
This is the question suppliers like least and buyers should love most. A long gap between detection and notification is not automatically bad faith — investigations take time — but an unexplained one is a signal, and it belongs in your supplier scorecard either way.
Accept, push back, or reject: making the call
Once the answers are in, the decision usually sorts itself into three outcomes.
Accept when the scope is bounded, the impact assessment rests on data, and the corrective action is specific. Record your acceptance in your own system with a short rationale, so the reasoning survives staff changes.
And acceptance does not retire your own checks: the batch still gets its full inspection on arrival, and its retest date still runs on its own clock. A closed deviation does not buy a batch extra life.
Push back when the root cause is thin or the impact statement has no data under it. Ask for the specific evidence, agree a reasonable response window, and put the exchange on record. This is not escalation; it is the conversation the report should have triggered. If the answers improve, proceed. If they do not, the pattern itself is information.
Reject when the impact genuinely reaches the product, or when the scope cannot be bounded no matter how many times you ask. Two principles keep the rejection clean. First, decide it against your specification and your documentation, not against the tone of the report.
Second, if anyone proposes retesting the material into compliance: the FDA’s guidance on out-of-specification results permits retesting only with a justified, documented reason, inside a structured investigation — never as a way to test results away. Resampling needs a rationale, not a hope.
Red flags worth a second opinion
- The report contains conclusions but no events — you cannot reconstruct what happened from what you were sent
- “Human error” is the entire root cause section, with nothing on why the error was possible
- The impact assessment was written before the laboratory results were available
- Affected lots keep growing with each follow-up question
- Corrective action equals retraining, full stop
- You learned about the deviation because you asked, not because they told you
None of these is automatically disqualifying. Two or more together, from a supplier with an otherwise clean record, justify a deeper conversation before the next purchase order — the kind of thing an audit is designed for.
When the deviation touches future batches
A closed report settles the batch in your warehouse. It says nothing about the ones still in production.
If the deviation led to a permanent process change, that change should travel through the supplier’s change control system — and if your quality agreement has a notification clause worth the name, you will hear about it before it reaches you.
If the change touches a parameter tied to your specification, that is a conversation about what the specification should require, held early rather than during a dispute.
What you are watching for is whether the deviation was an event or the start of a pattern. The next few batches answer that.
A distribution that starts drifting across consecutive lots shows up long before a formal report does — which is why buyers who track batch-to-batch consistency tend to see these stories coming. One deviation is a document. A trend is a decision.
Frequently asked questions
What is the difference between a deviation and a change?
A change is planned and approved before it happens, through change control. A deviation is an unplanned departure discovered after the fact. Same process, different direction in time — and different paperwork.
Does a supplier have to report minor deviations to buyers?
Only what your quality agreement obliges them to report. This is exactly why the notification clause needs thresholds and time limits written into it — a supplier will report what the contract requires and, in practice, not much more.
Can we accept a batch that had a deviation?
Yes, and often you should. If the scope is bounded, the impact assessment is supported by data, and the corrective action is specific, the batch is what it is: tested material with a documented history. Record your rationale and keep testing it on arrival like any other batch.
What if the report only arrives after the shipment?
It happens more often than suppliers like to admit, because deviation investigations finish after release decisions get made. Ask the timeline question — event, detection, notification — and weigh the gap. A supplier who tells you late but tells you thoroughly is a different proposition from one who tells you late because you asked.
Working the other side of the report
Most deviation reports are written by people who would rather send you good news, and read by buyers who have ten minutes. That combination produces the smooth, thin document this guide started with. The way out is not a sharper contract or a colder email. It is a short list of specific questions, sent early, that make the second draft — the honest one — worth writing. If a deviation report is sitting in your inbox right now and the answers do not add up, tell us what does not add up. Hard questions are the ones we answer best.