Root Cause Analysis Tools for GxP CAPA: When to Use Ishikawa, 5-Why and Fault Tree Analysis 

When a deviation occurs, an out-of-specification result is generated, or a pharmacovigilance finding emerges in a regulated pharmaceutical environment, the quality system’s response depends entirely on one thing: whether the organisation can accurately identify why it happened. Not what happened. Not how it was discovered. Why it happened at a level deep enough that fixing the cause prevents recurrence rather than just addressing the symptom.

Root cause analysis is the discipline that makes this possible. In GxP environments spanning GMP, GDP, GvP, and GCP, root cause analysis sits at the heart of every CAPA process and its quality determines whether a corrective action programme genuinely improves the system or simply generates paperwork that closes the finding on a tracker while leaving the underlying cause intact.

The three tools most widely used in pharmaceutical and life sciences root cause analysis are the Ishikawa diagram, the 5-Why technique, and fault tree analysis. Each has a specific logic, a specific type of problem it handles well, and a specific type of problem it handles poorly. Selecting the wrong tool for a given finding is one of the most common reasons CAPA programmes generate shallow root cause conclusions that do not survive regulatory scrutiny.

This guide explains what each tool does, when it should be used, when it should not be used, and how regulators assess the quality of root cause analysis during GMP, GDP, and GvP inspections.

Read More: CE Mark vs National Device Approvals: How Global Medical Device Manufacturers Should Plan Their Compliance Strategy in 2026

Why Root Cause Analysis Quality Is a Regulatory Issue

Root cause analysis is not simply a quality management best practice. It is an expectation embedded in GMP, GvP, and GCP regulatory frameworks across every major authority. The specific requirements include:

  • EU GMP Chapter 8 requires that out-of-specification investigations identify the root cause and that CAPA is implemented to prevent recurrence
  • FDA 21 CFR 211.192 requires a thorough investigation of any unexplained discrepancy in a batch record
  • EU GVP Module I requires that the pharmacovigilance system includes procedures for identifying and correcting quality failures with documented root cause analysis
  • ICH Q10 identifies root cause analysis as a core competency of an effective pharmaceutical quality management system

When FDA investigators or MHRA inspectors examine CAPA records they are trained to assess whether the root cause stated in the investigation is actually supported by the evidence presented and whether the corrective action taken logically addresses that root cause. A root cause conclusion that says “operator error” with a corrective action of “retraining conducted” is one of the most frequently cited examples of shallow root cause analysis in global inspection finding data. It describes a symptom and an activity without demonstrating any understanding of why the operator made the error, what in the system allowed the error to occur, and what has changed to make it less likely in future.

Regulators have become increasingly sophisticated in distinguishing genuine root cause analysis from documentation exercises. The tool used matters less than the depth of thinking it represents, but choosing the right tool for the right type of problem is the first step toward analysis that actually reaches the systemic level regulators expect.

The 5-Why Technique: Powerful for Simple Causal Chains

The 5-Why technique is the most widely used root cause analysis method in pharmaceutical quality systems and also the most widely misused. Its appeal is its simplicity. You start with the problem statement and ask why it occurred. Then you ask why that cause occurred. You continue asking why at each level until you reach a cause that is systemic, actionable, and genuinely explanatory rather than merely descriptive.

The name suggests five iterations but the number is illustrative rather than prescriptive. Some problems reach a meaningful root cause in three iterations. Others require seven or eight. The discipline is to keep asking why until the answer points to something in the system that can be changed, rather than stopping at a level of analysis that still describes the immediate event.

A practical example from a GMP environment illustrates where the technique succeeds and where it stalls. A batch record entry is completed incorrectly by an operator. The immediate cause is that the operator wrote the wrong value. The first why reveals that the operator misread the specification. The second why reveals that the specification document was printed in a font size that makes the relevant value difficult to read in low-light conditions on the production floor. The third why reveals that document formatting requirements in the site’s SOP do not specify minimum font size or legibility requirements for documents used in production areas. That is a systemic cause. It is actionable, it applies beyond this single operator and this single batch, and fixing it genuinely reduces the likelihood of recurrence.

Most pharmaceutical root cause investigations stall at the first or second why, producing conclusions like “operator did not follow the procedure” without asking why the procedure was not followed, why the system did not prevent the deviation from occurring, and why the training programme did not produce the level of competence required to prevent it.

The 5-Why technique is best suited to:

  • Single-event deviations with a relatively linear causal chain
  • Process failures where human actions are involved and the sequence of events is reasonably clear
  • Documentation failures, data entry errors, and procedural non-compliance events where the cause can be traced through a chain of contributing factors
  • Situations where speed of analysis is important and the problem is not sufficiently complex to justify more resource-intensive methods

The 5-Why technique is not well suited to:

  • Complex technical failures involving multiple interacting variables where the causal chain is not linear
  • Events with multiple simultaneous contributing causes that cannot be reduced to a single chain
  • Critical findings involving patient safety risk where the completeness of causal analysis is paramount
  • Situations where the same deviation has recurred repeatedly despite previous CAPA actions, suggesting the root cause has not yet been correctly identified

The Ishikawa Diagram: Built for Multifactorial Problems

The Ishikawa diagram, also called the fishbone diagram or cause-and-effect diagram, is the tool of choice when a problem is likely to have multiple contributing causes across different domains of the quality system rather than a single linear causal chain. In manufacturing environments the standard categories are people, process, equipment, materials, measurement, and environment, often referred to as the 6M framework. In pharmacovigilance and quality system contexts the categories may be adapted to reflect the nature of PV or quality operations.

The value of the Ishikawa approach is that it forces the investigation team to consider all relevant causal domains simultaneously rather than following the most obvious causal thread and stopping when a plausible explanation is found. In a GxP environment this matters because quality failures are frequently the product of multiple weaknesses across different parts of the system that individually might not have caused the event but in combination created the conditions for it.

A pharmacovigilance example illustrates this well. An ICSR submission is made late, missing the regulatory reporting deadline. A 5-Why analysis might trace the immediate cause to the case processor not completing the assessment in time and conclude that the root cause is insufficient training. An Ishikawa analysis of the same event might reveal contributing causes across multiple categories simultaneously:

  • People: the case processor was managing an unusually high case volume due to a colleague’s absence
  • Process: the triage SOP did not specify a required action when case workload exceeded a defined threshold
  • Technology: the safety database did not generate an automated escalation alert when a case approached its reporting deadline
  • Measurement: the PV department’s KPI system measured overall compliance rate rather than tracking individual cases at risk of missing their deadline
  • Management: the responsible person was not informed of the increased case volume in time to reassign resources

Each of these is a genuine contributing cause. Addressing only one of them would leave the system vulnerable to recurrence whenever a different combination of circumstances creates similar conditions. The corrective and preventive actions emerging from an Ishikawa analysis are therefore typically broader and more systemic than those produced by a 5-Why investigation of the same event.

The Ishikawa diagram is best suited to:

  • Complex GMP deviations involving multiple departments, process steps, or contributing variables
  • Pharmacovigilance system failures where technology, process, people, and management factors may all have contributed
  • Sterility failures, contamination events, and out-of-specification results where both technical and human factors are potentially involved
  • Recurring deviations where previous CAPA has not prevented recurrence, suggesting the full causal picture has not been captured
  • Quality system failures affecting multiple product lines or multiple sites simultaneously

The Ishikawa diagram is less well suited to:

  • Simple single-cause deviations where the causal chain is already clear
  • Situations where rapid analysis is required and resource constraints limit a full multidisciplinary cause mapping exercise
  • Events where the immediate cause is well established and the investigation only needs to trace that single cause to its systemic origin

Fault Tree Analysis: When Patient Safety Is at Stake

Fault tree analysis is the most technically demanding of the three methods and the one least frequently used in routine pharmaceutical quality investigations. It is a top-down deductive approach that starts with an undesired event at the top of the tree and systematically maps all the pathways through which that event could occur, using logical AND and OR gates to represent the relationships between contributing failures.

An AND gate means that multiple events must all occur simultaneously for the branch to contribute to the top event. An OR gate means that any one of several events is sufficient to cause the branch outcome. This structure makes fault tree analysis uniquely capable of identifying which combinations of failures represent the highest risk pathways to the undesired outcome.

The distinct value of fault tree analysis is that it does not just identify what caused the event that actually occurred. It maps all the ways the event could have occurred, identifying vulnerabilities in the system that did not contribute to the current event but could contribute to a future one. A fault tree analysis of a sterility failure might reveal that while the immediate event was caused by a specific gowning failure, there are three other pathways in the system through which a sterility breach could occur that have not yet been addressed by any existing control.

In pharmaceutical manufacturing fault tree analysis is most appropriately applied to:

  • Critical GMP failures involving potential patient safety impact such as sterility failures, cross-contamination events, or dosing errors in high-risk products
  • Computerised system failures where multiple system components interact and failure modes need to be mapped comprehensively
  • Process safety analysis for highly potent active pharmaceutical ingredients or biologics where the consequences of containment failure are severe
  • Validation failures for critical processes where understanding all conditions that could produce an out-of-specification outcome is essential
  • Investigations required by regulatory agencies following a serious adverse event or product recall where comprehensive causal analysis is expected

Fault tree analysis should be reserved for situations where:

  • The consequences of incomplete causal analysis are severe from a patient safety perspective
  • Complex technical systems create failure pathways that are not intuitively obvious
  • The event has significant regulatory visibility and the quality of the investigation will be subject to close scrutiny
  • The probability and severity of a recurrent event justify investment in the most comprehensive analytical approach available

Combining Tools: The Approach Regulators Expect for Complex Investigations

One of the insights that distinguishes experienced GxP investigators is the understanding that these three tools are not mutually exclusive. Complex GMP and GvP investigations often benefit from using more than one method in sequence or in parallel, with each tool contributing a different dimension of understanding.

A common and effective approach for complex deviations is to:

  • Begin with an Ishikawa diagram to identify all potential contributing causes across the relevant domains
  • Apply 5-Why analysis to each significant contributing cause identified on the fishbone to trace it back to its systemic origin
  • Apply fault tree analysis to the most significant causal pathways for critical events involving patient safety risk, to ensure all latent vulnerabilities have been mapped

When presenting root cause analysis findings in a regulatory context, whether in a CAPA record, a deficiency letter response, or an inspection, the quality of the documentation matters as much as the conclusions reached. Regulators should be able to follow the logic of the investigation, see the evidence that supported each causal conclusion, and understand why the corrective actions proposed address the root causes identified.

Common Root Cause Analysis Failures That Regulators Identify

Across FDA warning letters, MHRA inspection reports, and EMA inspection findings, certain patterns of inadequate root cause analysis appear repeatedly. The most common failures cited by global regulators include:

  • Concluding that the root cause is operator error without investigating why the operator made the error and what in the system permitted it
  • Using the root cause conclusion to justify a corrective action that was already planned rather than the action most directly addressing the identified cause
  • Failing to extend the investigation beyond the specific product or batch affected to assess whether the same root cause exists elsewhere in the operation
  • Closing the investigation before CAPA effectiveness has been verified, meaning the root cause conclusion cannot be confirmed as correct
  • Producing root cause analysis documentation that restates the deviation description rather than explaining the causal pathway
  • Applying the same root cause conclusion to multiple different deviation types as a default response rather than conducting event-specific analysis
  • Treating root cause analysis as a documentation exercise rather than a genuine investigative process, producing conclusions that are logically inconsistent with the evidence presented

How Quality and Vigilance Supports Root Cause Analysis and CAPA Excellence

At Quality and Vigilance we support pharmaceutical manufacturers, MAHs, and medical device companies across GMP, GDP, and GvP environments to build root cause analysis capabilities that produce genuinely systemic insights. Our team brings direct regulatory inspection experience across FDA, MHRA, EMA, TGA, and PIC/S frameworks and understands what distinguishes a CAPA programme that inspectors trust from one that generates ongoing scrutiny.

We offer individual investigation reviews, CAPA programme gap assessments, root cause analysis training for quality and PV teams, and independent review of causal conclusions before they are presented to regulatory authorities.

Contact Quality and Vigilance today to strengthen your root cause analysis capability and build a CAPA programme that satisfies global regulatory expectations.

Newsletter Signup

Subscribe to our newsletter for the latest insights