Workflow Template
Deviation Management Workflow
Manages the lifecycle of a quality deviation: intake and containment by the reporter, severity classification by quality, root cause investigation and corrective actions for major deviations, disposition approval by a quality reviewer, and closure notification to the reporter.
Designed for quality, manufacturing, and compliance teams managing GxP or ISO-regulated processes, this workflow structures the full lifecycle of a deviation from initial report to closure. It automates intake and containment, severity classification, root cause investigation for major deviations, disposition approval, and closure notification, so nothing stalls between handoffs. The result is a consistent, auditable deviation record with clear accountability at every decision point.
Business Outcomes
- Helps reduce time-to-disposition by removing manual handoffs between reporters, quality reviewers, and investigators
- Supports more consistent severity classification and disposition decisions across sites or shifts
- Improves audit readiness with a structured, timestamped record of each deviation stage
- Reduces risk of stalled or lost deviations through automated status tracking and routing
- Makes it easier to scale deviation handling as quality event volume grows
Workflow Steps
Steps
- 1Create Deviation Recordcreate record
Registers the reported deviation as a record.
- 2Set Status to Openupdate record
Marks the deviation as newly opened.
- 3Assign Quality Reviewerassign user
Assigns the deviation to a quality team member for severity assessment.
- 4Assess Severitycreate task
Quality assesses the deviation and classifies it as minor or major.
- 5Update Status: Under Severity Assessmentupdate record
Persists severity classification and updates status.
- 6Route on Severity Classification
Minor deviations go straight to disposition; major deviations require investigation first.
severity_classification: "Minor"→Disposition Minor Deviationseverity_classification: "Major"→Root Cause InvestigationDefault→Disposition Minor Deviation - 7Disposition Minor Deviationcreate task
Quality reviewer records the disposition for a minor deviation.
- 8Persist Minor Dispositionupdate record
Saves the minor disposition to the record.
- 9Root Cause Investigationcreate task
Investigator determines the root cause and defines corrective actions with owners.
- 10Update Status: Under Investigationupdate record
Persists investigation findings and updates status.
- 11Check if Root Cause Established
Only send for disposition approval if the root cause has been established.
cause_established: "Yes"→Update Status: Pending Disposition Approvalcause_established: "No"→Return for Further InvestigationDefault→Return for Further Investigation - 12Return for Further Investigationrestart from step
Root cause not established; restarts the investigation task for rework.
- 13Request Disposition Approvalrequest approval
Quality reviewer approves the disposition, or returns it for more investigation if the cause is not established.
- 14Route on Disposition Approval
Approved dispositions proceed to closure; rejected ones return for further investigation or revision.
approval_status: "approved"→Close Deviationapproval_status: "rejected"→Route Rejection Based on SeverityDefault→End - 15Route Rejection Based on Severity
Sends minor deviations back to re-disposition and major deviations back to further investigation.
severity_classification: "Minor"→Return Minor Disposition for Reworkseverity_classification: "Major"→Return Major Investigation for ReworkDefault→Return Minor Disposition for Rework - 16Return Minor Disposition for Reworkrestart from step
Restarts the minor disposition task for revision.
- 17Return Major Investigation for Reworkrestart from step
Restarts the root cause investigation task for further work.
- 18Close Deviationupdate record
Marks the deviation as closed following disposition approval.
- 19Notify Reporter of Closuresend email
Sends the reporter an email confirming the deviation has been closed.
- 20Update Status: Pending Disposition Approvalupdate record
Marks the deviation as pending disposition approval before the approval request is sent.
Fields
- Reporter Name*
- Reporter Email*
- Affected Item Type*
- Process / Product / Batch Reference*
- Description of Deviation*
- Immediate Containment Taken
- +10 more fields
Forms
Deviation Report
7 fields
Data Views
Deviation Register
deviation_ref, affected_item_type, affected_item_reference, severity_classification +2 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Workflows
Similar Categories
FAQs
Why should we automate deviation management instead of using spreadsheets or email?
Spreadsheets and email threads make it hard to track where a deviation sits in its lifecycle, who owns the next action, and whether root cause investigation was actually completed before disposition. This workflow assigns ownership at each step, updates status automatically, and routes based on severity, which helps reduce the risk of deviations sitting unresolved or being closed without proper review. It also creates a consistent record structure that supports internal audits and regulatory inspections.
What is the ROI of implementing this workflow on assess.one?
The main return comes from reduced administrative overhead in chasing approvals, fewer delays caused by unclear ownership, and lower risk of compliance findings from incomplete deviation records. Because the template publishes and runs immediately inside assess.one, there is no lengthy implementation project consuming budget before value is realised. Teams typically see the benefit in faster disposition cycles and a clearer audit trail almost as soon as the workflow goes live.
How does this compare to a paper-based or generic ticketing system approach?
Generic ticketing tools can log a deviation but don't natively enforce severity-based routing, investigation gating, or disposition approval logic specific to quality processes. This workflow builds those decision points directly into the process, including a step to check if root cause has been established before allowing progression. Paper-based systems, by comparison, offer no automated status tracking, notifications, or structured escalation for major deviations.
How long does it take to get this workflow live?
Publishing the template takes minutes, not weeks, because it runs natively inside assess.one with no external software installation required. Once published, your team can begin logging and processing deviations immediately using the built-in steps for intake, severity assessment, investigation, and disposition. Any adjustments to steps or roles can be made directly in the platform without a separate development project.
Can we customise the severity classification or disposition approval logic?
Yes, the severity assessment, routing rules, and disposition approval steps can be adjusted directly in assess.one to match your organisation's classification criteria and approval hierarchy. You can modify what happens on each severity outcome, including how minor versus major deviations are routed, and configure who is required to approve disposition. Notification triggers and rework loops, such as returning an investigation for further work, can also be tailored to your process.
Who typically needs access to this workflow?
Access is generally needed by the reporter who logs the initial deviation and containment details, a quality reviewer who assesses severity and reviews disposition, and an investigator responsible for root cause analysis on major deviations. Depending on your process, additional approvers may be added to the disposition approval step. Roles and permissions are configured within assess.one, so access can be scoped to match your existing quality organisation.
What happens if root cause cannot be established during investigation?
The workflow includes a dedicated check for whether root cause has been established, and if not, it routes the deviation back for further investigation rather than allowing it to proceed prematurely. This helps prevent incomplete investigations from moving to disposition approval. The investigation status remains visible throughout, so stakeholders can see when a deviation is cycling back for additional work.
How are disposition approvals and rejections handled?
Once a disposition is proposed, whether for a minor deviation or following major deviation investigation, it is routed for approval by a quality reviewer. If the disposition is rejected, the workflow routes based on the original severity classification, sending minor dispositions back for rework or major investigations back for further work. This ensures rejected dispositions are returned to the correct stage rather than requiring the process to restart from intake.
Are there compliance or audit trail considerations built into this workflow?
The workflow tracks status changes such as Open, Under Severity Assessment, and Under Investigation, creating a timestamped record of how the deviation progressed through each stage. This structure is designed to support audit and inspection readiness by making it easier to demonstrate that severity was assessed, root cause was established, and disposition was properly approved before closure. Organisations subject to GxP, ISO, or similar quality standards can use this record as supporting evidence during audits, though final compliance determinations remain the responsibility of the quality organisation.
How is the reporter kept informed throughout the process?
The reporter creates the initial deviation record and receives a closure notification once the deviation has been dispositioned and formally closed. This keeps the originator informed of the outcome without requiring them to manually track the deviation's progress through severity assessment, investigation, and approval. Notification triggers can be adjusted within assess.one if additional updates are needed at intermediate stages.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
