# "We cannot touch that. It's GMP."

That sentence freezes entire quality systems. It is nonetheless false, and the guide says the exact opposite: it asks for an **effective** pharmaceutical quality system, subject to review and continual improvement. What remains is to know where the line runs between simplifying and deviating.

Q9 and Q10

Quality risk management and the pharmaceutical quality system are part of the European GMP guide. Both ask that the control effort be proportionate to risk, and that the system improve.

ICH Q9 asks for effort commensurate with risk, where many systems apply uniform effort.Uniform effortCommensurate effort (ICH Q9)Level of riskEffort

ICH guidelines Q9 and Q10, taken up in part III of the European Union GMP guide.

This is the point a defensive reading of GMP systematically misses. **The guide does not ask for a frozen system, it asks for a controlled one.** A control kept without justification, a procedure never challenged, a record nobody uses: none of that is required — and all of it consumes the resource you will lack elsewhere.

"What was once validated is not up for discussion."

Behind that caution lies a confusion between two very different things: **the regulatory requirement**, which binds you, and **the solution your site chose in order to meet it**, which does not. Ten years later the process has changed, so has the equipment, but the solution has stayed — and nobody remembers which requirement it served. That is the heart of the matter: it is not the regulation that thickened your system, it is your successive answers to forgotten questions.

## The line, in three points.

### Document with care

The documentation chapter asks for documents **designed, prepared, reviewed and distributed with care**, written in a clear and unambiguous style. An unreadable document is not a compliant document you could improve later: it is already outside the requirement.

### Scale to risk

ICH Q9 sets two principles: risk evaluation is based on scientific knowledge and links to protection of the patient; and the level of effort and formality **should be commensurate with the level of risk**. That second principle is an explicit permission to cut back where risk is low.

### Control the change

Here is where the line runs. Simplifying through change control, with impact assessment and justification, is an ordinary operation of the quality system. Simplifying silently is an undeclared deviation. **The difference is not in what you do, but in the trail you leave.**

## QA that slows the business down is not rigorous QA. It is badly designed QA.

Slowness is not proof of seriousness, and the guide never asked for it. It asks for control. **A three-week release loop does not protect the patient better than a three-day one** if the three days rest on the same verifications, performed in the right places. It merely costs more, in working capital and in attention.

## The same level of control, for less.

Release

The delay between end of production and availability can nearly always be reduced without touching a single critical verification. What goes is the waiting between verifications.

Attention

Removing redundant controls makes the remaining ones more reliable. An operator ticking twenty boxes does not look twenty times; they tick. That is a known result, and it is a quality risk.

Inspection

A simplification file argued by risk and traced through change control is an excellent interview topic. It demonstrates a system that is steered, which is what an inspector looks for first.

So the right question to put in review is not "are we allowed?" but **"which requirement does this control serve, and how do we know?"**. When nobody can answer, you are not holding a requirement: you are holding a habit.

## Go further.

[

### The GMP guide

The framework, chapter by chapter.

Read →](/en/resources/gmp/)[

### Shorten batch release

Where the days actually go.

Read →](/en/blog/reduce-batch-release-time-batch-record/)[

### Reduce QC controls

Through risk analysis.

Read →](/en/blog/reduce-qc-controls-risk-analysis/)

## Simplifying under GMP, plainly.

Does GMP forbid removing a control? +

No. It requires the change to be controlled: assess the impact, justify, decide at the right level, trace, and verify afterwards. A control removed that way is a normal evolution of the system. A control that disappears without a file is a deviation — the trail makes the difference, not the decision.

What do you answer to "the inspector won't understand"? +

That an inspector understands an argued risk analysis very well, because it is the language of the guide. What they do not understand is a system nobody can explain. Transparency about what was reduced, and why, is sturdier than a pile you will defend badly.

Where do you start on a system that has thickened a lot? +

By mapping the controls and the requirement each one serves. The exercise is short and revealing: over a given scope, a notable share of controls attaches to no identifiable requirement, or duplicates a control performed upstream. Those are the candidates, not the critical ones.

Is simplifying a risk for the patient? +

That is the right question, and it is settled by risk analysis, not by blanket precaution. Keeping useless controls is not neutral: it consumes attention that will be missing at the genuinely critical points. Patient risk is managed by concentrating effort, not by spreading it thin.

## Which requirement do your controls serve?

Two days is enough to map what is required, what was added out of caution, and what nobody can justify any more.
