This guide describes the step-by-step process for logging and managing deviations. Deviations, per ISO 17025 §7.10, occur when a procedure is not followed as documented — the record captures what happened, analyses the root cause, and determines whether a CAPA link is needed.
Before you begin, make sure that:
| # | Prerequisite | Why | Page |
|---|---|---|---|
| 1 | Users | Responsible person assignment | Users |
Go to the Deviations page from the main menu. A table of existing deviation records is displayed.
The visible table columns are:
| Column | Description |
|---|---|
| Deviation No. | Unique code (for example DEV-YYYY-0001) |
| Title | Short title of the event |
| Classification | Major or Minor |
| Detection Date | When the deviation was detected |
| Responsible | Person responsible for handling |
| Status | Open, Under Investigation, Resolved or Closed |
| Source | Where the deviation originated |
There are also hidden columns (Deadline, Resolution Date, Detected By, Description, Root Cause, Immediate Action, CAPA Reference, Notes). You can show them from the column settings.
A deviation is identified when a documented procedure was not followed correctly. Typical examples:
| Situation | Example |
|---|---|
| SOP deviation | Wrong reagent used in an analysis |
| Method deviation | Calibration step skipped |
| Specification deviation | Sample stored outside temperature limits |
| Unauthorised change | Parameter modified without approval |
Click the "+" button on the toolbar to open the creation form.
Fill in the fields:
| Field | Description | Required |
|---|---|---|
| Deviation No. | Leave blank for auto-numbering (for example DEV-YYYY-0001) | No |
| Title | Short title of the event | Yes |
| Classification | Major or Minor | Yes |
| Source | Internal Audit, Proficiency Testing, Daily Operation, Management Review or Other | No |
| Detection Date | When the deviation was detected | Yes |
| Deadline | Deadline for resolution | No |
| Detected By | The user who detected the deviation | Yes |
| Responsible | Person responsible for handling | Yes |
| Status | Starts as "Open" | Yes |
| Resolution Date | When the deviation was resolved | No |
| CAPA Reference | Pick an existing CAPA record from a list (see Step 6) | No |
| Description | What exactly happened | Yes |
| Root Cause | Analysis of the underlying cause | No |
| Immediate Action | The measures taken to contain the impact | No |
| Notes | Additional remarks | No |
If a competency requirement is configured for the "Deviation Handling" function in the staff competency matrix, the user assigned as Responsible must hold authorized competence — otherwise saving is rejected (ISO 17025 §6.2.3).
There is no separate "Impact Assessment" field. Open the record and document your assessment in the Root Cause field, considering:
This analysis determines whether a link to a Corrective Action (CAPA) is needed or whether the immediate action is sufficient.
Fill in the Immediate Action field with the measures taken to contain the impact.
Example: "Stopped use of the reagent. Re-ran the analyses with the correct reagent. Notified the laboratory supervisor."
The immediate action addresses the current problem — if a systemic fix is needed, create a CAPA record.
If the root cause analysis shows that a systemic correction is needed:
Closing is not done by simply changing the Status field in the edit form; it is a separate, gated action:
The following restrictions apply:
The record permanently retains who closed the deviation, when, and the closure reason.
During ISO 17025 audits, assessors check whether each deviation was analysed, addressed, and fully documented.
Type in the search field for quick text filtering.
Click the filter icon to open the filter panel:
| Filter | Type | Description |
|---|---|---|
| Classification | Select | Show only Major or Minor deviations |
| Status | Select | Show only one status |
| Source | Select | Show only deviations from a specific source |
| Responsible | Select | Show only deviations for a specific responsible person |
| Max Records | Number | Record limit for print/export (default: 200) |
When should I record a deviation instead of a CAPA?
A deviation documents what happened — it is the factual record of the event. A CAPA is the fix — the systemic response. First record the deviation, then create a CAPA if needed to prevent recurrence.
Is a CAPA link always required?
By default the application blocks closing a deviation without a linked CAPA Reference. If the impact is genuinely minor and no systemic correction is needed, only the Lab Director or Reviewer can override this restriction, by recording a mandatory override reason.
How does auto-numbering work?
If you leave the "Deviation No." field blank during creation, the application assigns the next available code (format DEV-YYYY-NNNN). You can also enter your own code.