The Misdiagnosis That Sinks Most Backlog Programs

A quality head inherits a number. Four hundred open change controls. Eleven hundred. Whatever it is, it is on a slide, it has been on that slide for three quarters, and a regulator or a corporate audit has now asked about it. The response is predictable: a task force, a target, a weekly stand-up, and a burndown chart. Six months later the count is lower. Eighteen months later it is back.

What went wrong is not effort or discipline. It is that the program treated the count as the problem. The count is an output. It is produced by a system with an intake side, a work side, and a closure side, and a high count can be generated by a failure in any of the three. Two sites can report an identical number of open changes and have almost nothing in common. One is drowning because its procedure routes trivial work into a formal path. The other is stalled because a single validation engineer is the only person who can sign a particular assessment. Giving both of them the same instruction, which is usually some version of “close more,” helps neither.

Regulators do not look at the count either. They look at what the open records mean. The FDA’s warning letter to Glenmark Pharmaceuticals in July 2025 makes the point cleanly. The agency was not counting change records. It asked the firm to produce “a list of all process changes for the potassium chloride ER capsule product since product launch” together with an evaluation of whether each change, alone or in combination, could have affected dissolution.8 The finding was not that changes were open. It was that changes had been made and the firm could not demonstrate it understood their effect. A backlog is dangerous because of what sits inside it, not because of how long the list is.

The same emphasis runs through the inspection data. In the MHRA’s published GMP deficiency dataset for 2019, Chapter 1 of EU GMP, the pharmaceutical quality system chapter that covers change control, deviations, and CAPA, accounted for roughly 1,300 citations, more than any other category, and for 34 percent of all critical deficiencies.11 Analysis of FDA drug GMP warning letters issued during 2025 found 21 CFR 211.22(a) and (d), the sections defining the authority and responsibility of the quality unit, cited 54 times across the set reviewed.12 Neither of those figures is about volume. Both are about whether the quality system does what it says it does.

~1,300 EU GMP Chapter 1 (pharmaceutical quality system) citations in the MHRA 2019 GMP deficiency dataset, the highest of any category11
34% Share of all MHRA critical GMP deficiencies in 2019 falling under Chapter 111
54 Citations of 21 CFR 211.22(a) and (d), quality unit authority and responsibility, across FDA drug GMP warning letters reviewed for 202512

Why the diagnosis step gets skipped

Diagnosis gets skipped because it looks like delay. When a backlog has become visible to senior management or to an inspector, the pressure is to show movement immediately, and spending the first two weeks pulling data feels like the opposite of movement. It also gets skipped because the data is unpleasant to assemble. Most electronic quality management systems will give you a count and a list on demand. Getting a clean aging distribution, or the elapsed time each record spent in each state, usually means exporting the audit trail and working with it outside the tool.

That work is worth two weeks of a quarter. A diagnosis takes roughly ten working days and tells you which of four responses will work. Skipping it wastes the other eleven weeks.

Four Causes That Look Identical From the Queue Length

Four distinct mechanisms produce a change control backlog. From the count alone they are indistinguishable. From the shape of the data they are easy to tell apart. Their responses are not just different, they are close to opposite, so guessing wrong does real damage.

CAUSE 1

Genuine capacity shortfall

More changes arrive each month than the organization can assess, approve, implement, and close. The work is legitimate, the process is proportionate, and there are simply not enough people or enough approval slots. The queue grows steadily and evenly.

CAUSE 2

Over-scoped intake

The procedure requires a formal change control for work that does not need one. Like-for-like component replacements, editorial corrections, changes to systems with no GxP impact. Each record is small, but each consumes an assessment, an approval, and a closure.

CAUSE 3

Abandoned changes

Records opened in good faith, then overtaken. The project was defunded, the equipment was retired, the supplier moved, the originator left. Nobody cancelled them because cancellation is harder than ignoring them, so they sit.

CAUSE 4

A bottleneck or external dependency

Work is stalled at one point. One approver, one committee that meets monthly, one validation resource, one supplier document that has not arrived, one regulatory outcome that has not landed. Everything upstream and downstream is fine.

The responses are not interchangeable

Add contract resources to a capacity shortfall and the queue falls. Add contract resources to an intake problem and you have paid people to process work that should never have entered the system, and the queue refills as soon as they leave. Add contract resources to a bottleneck and they sit in the same line as everyone else.

Rewrite the procedure to tier changes by risk and an intake problem improves permanently. Rewrite the procedure when the real cause is a single overloaded approver and you have spent three months producing a document while the line stayed exactly where it was.

Run a cancellation sweep against a population of abandoned records and the count drops legitimately. Run the same sweep against a capacity shortfall and you have cancelled real work, which is a far more serious finding than a backlog.

The four causes rarely appear alone

In practice most sites have two or three of them at once, in different proportions. The point of the diagnosis is not to pick one label. It is to know which mechanism accounts for the majority of the aged population, so the largest part of the effort goes where it will actually move the system. A site that is 60 percent intake problem and 40 percent bottleneck should fix the intake rules first and unblock the bottleneck second, and should not hire anyone.

How to Measure Which One You Actually Have

Six measurements, all of which can be produced from a standard electronic quality management system export, will separate the four causes. None of them is the total count.

1. Aging distribution, not median age

Bucket every open record by age: 0 to 30 days, 31 to 90, 91 to 180, 181 to 365, and over 365. Then look at the shape rather than the average. A single number, whether that is the count or the median age, hides everything that matters.

A capacity shortfall produces a distribution that is populated across every bucket and shifts to the right month over month. Nothing is qualitatively different about the oldest records; they are simply the ones that have been waiting longest. An abandoned population produces something different: a normal-looking distribution in the newer buckets plus a distinct, disconnected cluster in the over-365 bucket that does not shrink no matter how much work gets done. That second shape is the clearest single signal in the whole diagnosis, and you cannot see it in a median.

2. Time in state

For each record, calculate the elapsed days spent in each workflow state: drafting, impact assessment, approval, implementation, verification, closure. Then sum across the population by state. The question is not how old the records are. It is where the time is sitting.

If 70 percent of the accumulated time sits in one state, you have a bottleneck and you know exactly which one. If time is distributed roughly evenly across states, you have a capacity problem. If most of the time sits in the earliest states, before any real work started, you are probably looking at abandoned records rather than stalled ones. This measurement alone separates cause 4 from causes 1 and 3.

3. Arrival rate against closure rate

Plot monthly opened and monthly closed for the trailing eighteen months on the same axis. This is the only measurement that tells you whether the system is in balance, and it is the one most often missing from backlog reporting, which tends to show only the open count.

If arrivals have consistently exceeded closures for more than a few months, the queue will keep growing whatever you do to the existing population, and the intervention has to touch either intake or capacity. If the two lines are roughly equal and the queue is still large, the backlog is a historical accumulation rather than an ongoing failure, and clearing it may genuinely be a one-time exercise. Those are entirely different situations and the count cannot distinguish them.

4. Concentration

Take the records older than 180 days and ask what share is assigned to the five most-loaded owners or approvers, and what share is waiting on the same external dependency. Bottlenecks concentrate. Capacity shortfalls do not. If 40 percent of the aged population sits with three people, you do not have a resourcing problem across the quality unit, you have a specific approval design problem.

5. Classification mix

What proportion of the open population is classified minor or low risk? PIC/S recommendation PI 054-1 is explicit that the level of formality, effort, and documentation applied to a change should be commensurate with the level of risk, and that for simple and minor changes an impact assessment alone can be sufficient without a more formal risk assessment tool.1 If 80 percent of your open records are minor and every one of them carried a full assessment, a cross-functional review, and a formal closure package, the process is doing work the guidance does not ask for.

6. Implementation status

This is the measurement that matters most for the next section, and it is often absent from the workflow entirely. For every open record, has the change already been made in the plant, in the system, or in the document? Split the population in two. Records where the change is live but the record is open are a fundamentally different problem from records where nothing has happened yet.

What the data showsMost likely causeResponse that failsResponse that works
Even distribution across age buckets, shifting right; time spread across all states; arrivals above closures Capacity shortfall Rewriting the procedure Added assessment and approval capacity, plus a hard look at whether arrivals can be reduced
High share of minor classifications; short work content per record but long elapsed time; arrivals high and rising Over-scoped intake Contract resources to work the queue Risk tiering and a documented list of what does not enter formal change control
Distinct cluster over 365 days that does not move; time concentrated in the earliest states; owners departed or unassigned Abandoned changes Trying to complete them Structured cancellation with a documented rationale for each record
Time concentrated in one or two states; aged records concentrated among few owners or one dependency Bottleneck or external dependency Site-wide overtime and burndown targets Redesign the specific approval step, delegate it, or resolve the single dependency

Rank the Backlog by Exposure, Not by Age

Once the diagnosis is done, the instinct is to work the list oldest first. That is the wrong order, and it is wrong for a reason worth stating plainly.

An open change control is not administrative debt. Depending on what is behind it, an open record can mean one of two genuinely serious things. It can mean a change that has already been implemented, in production or in a validated system, with no closure evidence and no verification that it worked. Or it can mean a validated system, process, or facility running in a state that no longer matches its documentation. Neither of those is housekeeping. Both are the substance of a GMP finding.

EU GMP Annex 15 is direct on the point: the control of change is part of knowledge management and belongs inside the pharmaceutical quality system, quality risk management should be used to evaluate planned changes and to plan any process validation, verification, or requalification the change requires, and an evaluation of the effectiveness of the change should be carried out.3 A record that stops before that last step has not completed the requirement. It has parked it.

PI 054-1 adds a second exposure that a long queue creates directly. It expects that the potential impact of a proposed change on other change proposals running at the same time is assessed, and that the risks arising from the collective effect of multiple concurrent changes are managed.1 With four hundred records open, nobody is performing that assessment. The backlog is not just a set of individually unfinished items. It is a state in which the interaction between changes has stopped being evaluated at all.

The question an inspector will ask. Not “why do you have 400 open change controls.” The question is “show me a change that has been implemented and tell me how you know it worked.” If the answer for a meaningful number of records is that the effectiveness evaluation was never defined and never performed, the backlog stops being a metrics discussion and becomes a control discussion. Rank the queue so that those records are the first ones you can answer for.

An exposure ranking that holds up

TierWhat it meansWhy it ranks here
A Change implemented, record open, no closure evidence and no completed effectiveness evaluation The validated or documented state and the actual state may differ, and there is no evidence the change performed as intended. Highest exposure regardless of age.
B Change partially implemented, with some actions complete and others outstanding PI 054-1 expects risks arising during the change period to be assessed and interim controls put in place in a timely manner.1 Partial implementation without interim controls is an uncontrolled state.
C Approved but not started, where the change was raised to mitigate a quality, safety, efficacy, or compliance hazard The hazard the change was meant to reduce is still live, and the record is evidence that the organization knew about it.
D Change touches a registered detail, an established condition, or a regulatory commitment Under ICH Q12, changes to established conditions require a regulatory submission.5 A filing that lags an implemented change is a distinct and serious exposure.
E Open, not started, improvement or convenience only, no hazard behind it Lowest exposure. This tier is where most cancellation candidates live, and where most of the count usually is.

The useful property of this ranking is that it frequently inverts the age order. A ninety-day-old Tier A record, where a process parameter was changed last quarter and nobody has verified the effect, matters far more than a three-year-old Tier E record proposing a nicer label format that was never started. Working oldest first would take you to the label first. That is how organizations spend a quarter reducing a count while leaving every real exposure exactly where it was.

The 90-Day Operating Plan

Ninety days is enough time to change the state of a backlog. It is usually not enough time to close every record, and a plan that promises otherwise will either fail or produce closures that do not survive review. Be explicit about that at the start with whoever set the target. The goal of the ninety days is to move the whole population into a state you can defend and keep, which means every record either closed with evidence, cancelled with a rationale, or carried forward with an owner, a tier, and a date.

1

Days 1 to 10: Diagnose

Export the full open population with audit trail history. Build the six measurements: aging distribution, time in state, arrival against closure, concentration, classification mix, implementation status. Sample twenty to thirty records by hand to confirm what the data implies, because system status fields are frequently wrong about whether a change was actually implemented. Done looks like: a one-page diagnosis naming the dominant cause with the numbers behind it, signed off by the quality head and the change management process owner. No remediation work starts before this exists.

2

Days 8 to 25: Triage by exposure and assign owners

Every open record gets an exposure tier (A through E) and a named individual owner, not a department. For every Tier A and Tier B record, make and document an immediate decision on interim controls: either the current state is acceptable and here is why, or here is the control that goes in place now. Done looks like: zero records without a tier and a named owner, a ranked worklist, and a documented interim-control position on every A and B record.

3

Days 15 to 45: Fix intake before clearing the queue

This phase overlaps the previous one deliberately. If intake is unchanged while you clear, the queue refills behind you and the ninety days ends roughly where it started. Publish the risk tiering, the list of what does not enter formal change control, the mandatory closure criterion at approval, and the cancellation path. Done looks like: the revised procedure approved and in force, staff trained, and new records demonstrably entering under the new rules.

4

Days 25 to 70: Work Tiers A and B to closure

Build the closure evidence packages. Where the effectiveness criterion was never defined, define it now and either run it prospectively or justify against data that already exists. Where the change cannot be verified at all, say so in the record and raise a remediation action rather than closing on a statement that the change was implemented. Done looks like: every Tier A record either closed with real evidence or converted into a documented remediation item with an owner and a date.

5

Days 45 to 80: Cancel deliberately

Work the abandoned population one record at a time. Each cancellation requires confirmation that the change was never implemented, verified against the physical or system state rather than the record, a rationale for why the need no longer exists, a statement on any residual risk, and quality unit approval. Done looks like: individually justified cancellations approved by the quality unit, with no two rationales identical because no two situations were.

6

Days 70 to 90: Verify and hand over to routine

Re-run all six measurements against the new population and compare them to day 10. Set the standing review cadence, the aging thresholds that trigger escalation, and the reporting line into management review. Done looks like: trailing 90-day closure rate above arrival rate, no record above the new age threshold without a documented reason, and the change management metrics permanently on the management review agenda.

A note on sequencing. The single most common structural error in these programs is running phase 4 before phase 3. Clearing the queue while intake stays the same produces a visible improvement that reverses within two or three quarters, and it makes it harder to get support for changing the procedure afterward. Fix the front of the process while you are working the back of it, even though that means doing two hard things at once.

Cancelling Changes: The Part Nobody Wants to Own

Some open change controls should not be completed. They should be cancelled. This is the part of the plan that generates the most internal resistance, partly because cancellation feels like an admission that the original decision was wrong, and partly because nobody is certain what a defensible cancellation looks like.

The guidance is clearer than most people expect. PI 054-1 states that for rejected or voided change proposals, particularly those relating to mitigation of a quality, safety, efficacy, or compliance hazard, the system should ensure the rationales for those decisions are documented and well justified, and that any continued risk is adequately managed.1 That is an explicit acknowledgment that not implementing a proposed change is a legitimate outcome, together with an explicit statement of what makes it legitimate.

What a defensible cancellation record contains

  • Confirmation the change was never implemented, verified against the physical asset, the system configuration, or the effective document, not against the status field in the record. This is the step people skip, and it is the one that matters most. Cancelling a record for a change that was quietly made anyway converts a backlog problem into an undocumented change.
  • The reason the need no longer exists, stated specifically. The equipment was decommissioned in March. The supplier was replaced. The product was withdrawn from the market. “No longer required” is not a rationale.
  • The nature of the original trigger. If the change was raised to reduce a hazard, the record has to say how that hazard is being managed now. This is the requirement PI 054-1 names directly, and it is the difference between a cancellation and an unmanaged risk.
  • Quality unit approval, not approval by the originator alone. Under 21 CFR 211.22 the quality unit carries responsibility and authority over these decisions, and the FDA cites those sections routinely.12
  • A dependency check. Does another open record, a CAPA, a deviation, or a validation activity assume this change will happen? Cancelling into a dependency creates a gap nobody notices for a year.
The bulk cancellation trap. The fastest way to turn a backlog finding into a much worse finding is to cancel a few hundred records in one action with an identical rationale. An inspector who finds three hundred cancellations sharing one sentence will ask about all three hundred, and the organization will not be able to answer for most of them. Individual justification is slow, and it is the whole point. If you cannot justify a cancellation individually, you have not established that it should be cancelled.

The opposite failure is just as common and less discussed. Some organizations, having been told that cancellation looks bad, refuse to cancel anything. They then spend a quarter completing changes that nobody wants, to equipment that is being retired, in systems being replaced, producing closure documentation for work with no remaining value. That is not conservatism. It is a different way of wasting the same quarter, and it also leaves the real exposures untouched.

The Closure Evidence Problem

Work through any aged backlog and a pattern appears quickly. A large share of the oldest records are not stuck at assessment or at implementation. They are stuck at closure. The change was made. It appears to have worked. And nobody can close the record because nobody knows what evidence would be sufficient.

The mechanism is straightforward once you see it. The effectiveness criterion was never defined at approval. At the time the change was approved, the discussion was about whether to make the change, what the impact would be, and what validation was needed. Nobody wrote down what would be measured afterward, against what threshold, over what period. Six or twelve months later, the person trying to close the record is negotiating with the quality unit about what “effective” means for a change they did not design, using data that may not have been collected.

PI 054-1 places the fix squarely at the front of the process. In change planning, it expects that the data needed to demonstrate effective implementation, the acceptance criteria, and the change effectiveness criteria are all pre-defined, and it notes that these may include provisions such as intensified sampling, continuous process verification, and statistical assessment.1 At the review and closure step, it expects that changes meet those pre-defined acceptance and effectiveness criteria, that deviations from them are assessed and justified, and that quantitative data are used wherever possible.1 The criterion is meant to exist before approval, not to be invented at closure.

Four fields at the approval gate

A closure criterion that actually works needs four things recorded before approval, and a gate that will not pass without them:

  • What will be measured. A named parameter, output, record, or observation.
  • Against what threshold. A number, a specification, a defined pass condition.
  • Over what period or sample size. Three commercial batches. Sixty days of routine operation. All lots through the end of the quarter.
  • Who will look at it and when. A named role and a date, so the review is scheduled rather than remembered.

Scaling the check to the change

The reason this requirement is often resisted is that people imagine it applied uniformly, which would mean a statistical study for a document formatting correction. That is not what proportionality means. A minor documentation change may need nothing more than confirmation that the revised document is in effect and the affected personnel have been trained, and that is a legitimate, complete effectiveness check for that change. A change to a critical process parameter needs data, and PI 054-1 explicitly contemplates process capability and performance indices as part of quantitative assessment.1 Setting the check by tier is what makes the requirement workable across a few thousand changes a year.

What to do with aged records where nothing was defined

For the records already in the backlog, retrofitting is not optional but it does have honest limits. There are three defensible paths and one that is not.

  1. Define the criterion now and run it prospectively. This works when the change is still monitorable: a process parameter with ongoing batch data, a system function still in daily use, a supplier still delivering. Set the measure, the threshold, and the period, then close on the result. The record stays open a little longer and closes on real evidence.
  2. Use data that already exists and document why it answers the question. Continuous process verification output, batch record trends, deviation history, complaint data, and stability results may already contain the answer. The requirement is that the record states what question was asked, what data answered it, and why that data is sufficient. This is not a shortcut; it is a written argument that has to hold.
  3. Determine that no effectiveness evaluation is warranted for this change class and record the justification. Legitimate for genuinely low-risk changes, and the justification should reference the tiering rules rather than the individual record, so the same reasoning applies consistently.
  4. Close the record on “change implemented” as the evidence. This is the path that is not available. Implementation is not effectiveness. Annex 15 asks for an evaluation of the effectiveness of the change, and a statement that the change was made does not perform that evaluation.3
The front-of-process fix is what makes this section worth acting on. Retrofitting closure criteria onto a few hundred aged records is slow and partly unsatisfying work. Requiring the criterion before approval takes about four fields and thirty seconds per change, and it removes the single largest cause of records stalling at closure. Every organization that does the retrofit and not the gate will do the retrofit again.

Preventing the Rebuild

A backlog cleared without changing intake will rebuild. This is the least comfortable statement in the article and the most reliable one. If the same volume of work enters the same process with the same approval design and the same closure ambiguity, the same queue reappears, and the second time it is harder to get attention for because leadership believes the problem was already solved.

Tier by risk, and say what does not enter at all

Risk-based tiering is where prevention starts, and it has clear regulatory grounding. Annex 15 requires quality risk management to be used to evaluate planned changes and to plan the validation, verification, or requalification effort each one needs.3 PI 054-1 expects the level of formality, effort, and documentation to be commensurate with risk, and notes that for simple and minor changes an impact assessment can be sufficient without a more formal risk assessment tool.1 Three tiers is usually enough. Each tier gets its own assessment depth, approval roster, validation expectation, and closure evidence standard, written out so nobody has to negotiate it per change.

The more valuable half of this work is defining what does not enter formal change control at all, with a documented boundary for each exclusion. Like-for-like replacement of a qualified component with identical specification. Correction of a typographic error that does not alter meaning or instruction. Changes to systems with no GxP impact and no interface to a GxP system. Each exclusion needs a written boundary and a mechanism for catching the case that turns out not to qualify, and the whole exclusion list needs a periodic review. Sites that never write this list end up with the largest queues, because in the absence of a rule the safe individual choice is always to raise a change control.

One named owner per change

Assign a person, not a department. Departmental ownership means nobody is late, because nobody in particular is responsible. Then connect reassignment to the leaver process, because a meaningful share of every abandoned population belongs to people who left the organization two years ago and whose records simply stopped moving. This is a small administrative change with a large effect on the over-365 bucket.

Aging thresholds with escalation, not just due dates

Due dates slip quietly. Aging thresholds with a named escalation do not. A record crossing 90 days goes to the quality head with a stated reason. A record crossing 180 days goes to management review individually, by name and by reason. EU GMP Chapter 1 requires periodic management review of the operation of the pharmaceutical quality system with senior management involvement, and change control performance belongs in that review.4 The threshold matters less than the fact that crossing it produces a conversation with someone senior rather than a red cell on a report.

A standing cadence, and the metric that tells the truth

CadenceWhat gets reviewedWho
WeeklyTier A and B exposure records: implemented but unclosed, partially implemented, interim controls in placeChange management process owner and quality unit
MonthlyAging distribution, time in state, records crossing thresholds, new exclusions appliedSite quality leadership
QuarterlyArrival rate against closure rate over the trailing four quarters, classification mix, cancellation volume and rationale qualityManagement review4

The metric that tells you whether prevention worked is not the open count. It is whether closure rate has held above arrival rate for two consecutive quarters. A count can fall for reasons that have nothing to do with system health, including a temporary contract team, a quiet quarter, or a round of cancellations. Closure rate holding above arrival rate over six months means the system is genuinely processing what enters it. That is the number to put on the management review slide, and it is the one to defend when someone asks why the open count is no longer the headline.

There is a wider reason to get this right. ICH Q12 ties regulatory flexibility on post-approval changes to the maturity of a company’s pharmaceutical quality system, and PI 054-1 notes that maturity in change management may support the fullest benefit from those flexibilities.15 The FDA’s Quality Management Maturity program at CDER runs on the same logic, assessing how effectively manufacturers monitor and manage quality beyond the baseline CGMP requirement.1617 A visible change control backlog is not only an inspection exposure. It is a direct argument against the maturity claim that these programs are designed to reward.

Conclusion

The reason change control backlogs are so persistent is that the number on the slide invites the wrong response. It suggests the problem is volume and the answer is speed, when in most cases the problem is a specific mechanism and the answer is a specific correction. Ten working days spent on aging distribution, time in state, and arrival against closure rate will tell you which of four situations you are in, and the four need different things. That diagnosis step is the part most programs skip and the part that determines whether the rest of the ninety days is useful or merely busy.

The second half of the discipline is refusing to treat open records as paperwork. Some of them mean a change is live in a validated environment with nothing to show that it worked, and those should be worked first regardless of age. Some of them should be cancelled, individually and with a written rationale that survives being read out loud. And most of the ones stuck at closure are stuck because nobody defined what closure meant at approval, which is a problem you fix at the front of the process rather than at the back. Do the clearing without doing the intake work and the queue returns, quietly, over about four quarters.

Sakara Digital works with pharma and biotech organizations on quality system remediation of exactly this kind, where the visible number is a symptom and the useful work is upstream of it. If you are looking at a change control backlog and want an independent read on which of these four situations you are actually in before committing a quarter to it, we are happy to have that conversation.

For Further Reading