Deviation vs Change Control in Pharma: The Real Difference
2026-08-31
Deviation = an unplanned departure that already happened; change control = a planned change before it happens. The difference, the 'planned deviation' trap, and how they connect.

Deviation and change control are two of the most-used systems in a pharma quality unit — and two of the most-confused. Both raise a record, both need risk assessment and QA approval, both can spawn a CAPA. But they answer opposite questions. Mix them up and you either bury a real change inside a deviation (where it dodges proper evaluation) or you slow every small correction to a crawl. Here's the clean distinction, and how the two are supposed to work together.
The one-line difference
- A deviation is an unplanned departure from an approved instruction, specification or standard that has already happened (or is happening). It is reactive — you're documenting and investigating something that went differently than the procedure says.
- Change control is the formal, proactive evaluation of a planned change to a GMP system before it is implemented — a new supplier, a revised SOP, a different piece of equipment, a process tweak.
The axis is simple: unplanned + after the fact = deviation; planned + before the fact = change control.
What is a deviation?
A deviation is any measurable difference between what actually happened and what the approved documents required — a mixing time overrun, a temperature excursion, a wrong sequence of steps, a missing signature. It's raised after the fact, investigated for root cause, classified by impact (minor / major / critical), and closed with corrective and preventive actions. Nobody plans for a deviation; you detect one and respond. See the step-by-step deviation workflow and how to run the root-cause analysis.
What is change control?
Change control is the gatekeeper for intentional changes to anything validated or GMP-relevant: master formula, SOPs, specifications, equipment, utilities, suppliers, computerised systems, facility layout. A change request is raised, risk-assessed, reviewed by the affected functions (QA, production, QC, engineering, regulatory), approved, implemented in a controlled way, and verified for effectiveness. Changes are usually classed minor / major, and temporary / permanent (with emergency change as a fast-track path that still gets documented). The point is to decide before you change, not to explain after. See how to implement change control in pharma manufacturing.
Deviation vs change control: side by side
| Deviation | Change control | |
|---|---|---|
| Trigger | Something happened unplanned | Someone wants to change something |
| Timing | After (or during) the event | Before implementation |
| Nature | Reactive / corrective | Proactive / preventive |
| Core question | "Why did this happen and what's the impact?" | "Should we make this change, and how do we do it safely?" |
| Key outputs | Root cause, impact assessment, CAPA | Risk assessment, approval, implementation & verification plan |
| Classification | Minor / major / critical | Minor / major; temporary / permanent; emergency |
| Owner | QA, with the department involved | QA, with the change initiator & affected functions |
Where people get it wrong
The "planned deviation" trap. If you know in advance that you're going to depart from a procedure, that is not a deviation — it's a change (usually a temporary one), and it belongs in change control. Modern GMP expectations, including India's revised Schedule M and EU GMP, actively discourage the term "planned deviation" precisely because it's used to skip proper evaluation. Rule of thumb: if you can plan it, change-control it; a deviation is only ever unplanned.
Using a deviation to sneak a change. The reverse mistake — quietly making a change on the floor, then writing it up as a deviation "because it already happened." That defeats the entire control system. A change that recurs is a signal that change control was skipped.
How the two connect
They're not rivals — they hand off to each other:
- A deviation investigation often concludes that the real fix is a permanent change (revise the SOP, re-qualify the equipment, change the vendor). That CAPA is then routed into change control for controlled implementation. Deviation → CAPA → change control.
- A change that isn't managed well is a leading cause of deviations — an unvalidated tweak, a supplier swap nobody assessed. Good change control prevents future deviations.
- Both feed the same higher-level records: trends of deviations and changes are reviewed in the APQR / Annual Product Quality Review and sit inside the same pharmaceutical QMS.
The data/workflow view
On paper the two look similar — a numbered record, a risk assessment, approvals, a CAPA link — which is exactly why they get blurred. In a workflow system the difference lives in the trigger and the state model, not the form:
DEVIATION Open → Under Investigation → Root Cause → CAPA → Closed
CHANGE CONTROL Requested → Risk Assessed → Approved → Implemented → Verified → Closed
Same building blocks (records, statuses, role-gated transitions, a CAPA link), different entry point and different sequence. Run them as two distinct digital workflows — each with its own fields, statuses and who-can-move-it rules — and the system enforces the difference for you, so a change can never masquerade as a deviation. That field-and-status model is covered in detail in the batch-release, deviation & OOS data-model guide. Platforms like Flobri let you build both as controlled, auditable workflows without writing code — the deviation form, the change-control form, the CAPA that bridges them, all with their own state machines.
The bottom line
Ask one question: did this already happen unplanned, or am I proposing to change something? Unplanned-and-past is a deviation; planned-and-future is change control. Keep them as separate systems, let the CAPA connect them, and never let "planned deviation" creep into your vocabulary.
FAQ
Is a planned deviation the same as a temporary change?
Effectively yes — and that's the point. What people call a "planned deviation" should be handled as a temporary change through change control, not the deviation system. Many regulators discourage the term entirely.
Can a deviation lead to a change control?
Very often. If a deviation's CAPA requires altering an SOP, spec, equipment or supplier, that corrective action is implemented through change control.
Do both need a CAPA?
A deviation almost always drives a CAPA. A change control may generate CAPAs too (e.g. to close verification gaps), but its primary output is the controlled change itself.
Which one covers an OOS result?
Neither, directly — an OOS is its own investigation. But an OOS may raise a deviation, and its CAPA may trigger a change control.