]> Biopharma Risk Management Ontology The Biopharma Risk Management Ontology provides constructs for representing risk in biopharmaceutical development and manufacturing. It supports modeling how risks are identified, analyzed, evaluated, controlled, communicated, and reviewed, as well as the documented outputs of those activities. The module enables hazards, hazardous situations, possible harm states, risk estimates, residual risks, and method-based assessments to be represented in relation to biopharmaceutical processes, materials, equipment, products, and lifecycle decisions. It is intended to support consistent representation of risk-management knowledge across development, manufacturing, technology transfer, contamination control, process characterization, and ongoing lifecycle management. http://opensource.org/licenses/MIT Copyright (c) 2022, 2023, 2024, 2025, 2026 Open Applications Group failure mode and effects analysis specification https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ An FMEA method specification for a bioreactor operation prescribes that the team enumerate failure modes for each selected function or process step, document causes and effects, and score severity, occurrence, and detectability using a defined rubric. When carried out, the resulting FMEA record includes “pH probe drift” as a failure mode with scores that yield a high risk ranking or RPN, motivating tighter calibration and redundant sensors. FMEA specification https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-quality-risk-management-step-5-first-version_en.pdf and https://www.fda.gov/media/71535/download 1) Failure mode and effects analysis specification prescribes use of a structured, prospective method for evaluating how a process, system, material, or equipment item might fail and what effects those failures may have. 2) FMEA commonly includes identification of failure modes, causes, effects, existing controls, and recommended actions. Many FMEA implementations estimate or rank risk using severity, occurrence, and detectability scores, often combined into a risk priority number or related ranking. 3) In biopharmaceutical manufacturing, FMEA may be used to assess unit operations, equipment, materials, process parameters, and quality attributes, including potential impacts on product quality, process performance, patient safety, or product availability. 4) Recommended actions identified during FMEA may be implemented, followed up, and verified in separate risk control or risk reduction processes. FailureModeAndEffectsAnalysisSpecification(x) → RiskManagementMethodSpecification(x) true risk management method specification that prescribes systematic identification of potential failure modes and evaluation of their causes and effects There are insufficient constructs to create a set of necessary and sufficient conditions if x is a 'failure mode and effects analysis specification' then x is a 'risk management method specification' harm likelihood value expression https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ likelihood score 2 for patient harm from reduced product availability caused by batch rejection; likelihood category 'remote' for hypoxic injury during helium refill after oxygen monitoring controls are implemented https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-quality-risk-management-step-5-first-version_en.pdf HarmLikelihoodValueExpression(x) → ValueExpression(x) ∧ ∃m∃h(HarmSpecification(m) ∧ continuantPartOfAtAllTimes(x,m)) true value expression that represents the assessed likelihood that a specified harm will occur in relation to one or more specified potential sources of harm There are insufficient constructs to create a set of necessary and sufficient conditions if x is a 'harm likelihood value expression' then x is a 'value expression' that is 'continuant part of at all times' some 'harm specification' harm severity value expression https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ minor patient injury; moderate bloodstream infection severity; severe hypoxic injury; severity level 2 for product damage; severity level 4 for coil and cryostat damage; severity score 3 on a 5-point scale for anaphylactic state https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-quality-risk-management-step-5-first-version_en.pdf HarmSeverityValueExpression(x) → ValueExpression(x) ∧ ∃h (HarmSpecification(h) ∧ continuantPartOfAtAllTimes(x, h)) true value expression that represents the magnitude of possible or actual harm There are insufficient constructs to create a set of necessary and sufficient conditions if x is a 'harm severity value expression' then x is a 'value expression' that is 'continuant part of at all times' some 'harm specification' harm specification https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ Harm specification that describes a patient being in a bloodstream infection state after receiving a contaminated injectable biologic; Harm specification that describes a patient being in an anaphylactic state after administration of a product containing an unintended immunogenic contaminant; Harm specification that describes an operator being in a hypoxic injury state after remaining in an oxygen-deficient room following helium discharge; Harm specification that describes loss of batch sterility as a harm to be prevented during aseptic processing; Harm specification that describes unauthorized disclosure of batch genealogy data as a cybersecurity-related harm; https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf and https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-30r1.pdf and ISO 31000 1) In the current model, many harms can be represented through harmed states, especially when the harm involves damage to, degradation of, or loss of required qualities in a material entity, product, process output, equipment item, organism, person, population, or environment. For these cases, an information content entity that describes a harmed state is sufficient for classification as a harm specification. 2) The class is intentionally left open because not all relevant harms are expected to be adequately represented as material harmed states. In cybersecurity, information governance, software, and digital infrastructure contexts, harms may involve loss of confidentiality, loss of data integrity, loss of system availability, unauthorized access, loss of control over an automated process, or compromise of decision-relevant information. Some of these may require future modeling patterns that are not reducible to harmed states in the material domain. 3) A harm specification should not be confused with the harm itself. The harm specification is the information content entity used to represent, communicate, evaluate, or reason about the harm. The harm itself is the adverse condition, consequence, or loss being specified. InformationContentEntity(x) ∧ ∃h (HarmedState(h) ∧ describes(x, h)) → HarmSpecification(x) true information content entity that describes an adverse condition, consequence, or loss There are insufficient constructs to create a set of necessary and sufficient conditions. if x is an 'information content entity' that 'describes' some 'harmed state', then x is a 'harm specification' harmed state https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ a patient has a bloodstream infection after receiving a contaminated injectable biologic; a patient is in an anaphylactic state after administration of a product containing an unintended immunogenic contaminant; a patient has recurrent thrombosis after not receiving a needed anticoagulant because of product shortage; the coil and cryostat are in a severely damaged state after a magnet quench; an operator is in a hypoxic injury state after remaining in an oxygen-deficient room following helium discharge https://www.iso.org/obp/ui/en/#iso:std:iso-iec:guide:51:ed-3:v1:en 1) “Damage to health” includes damage that can occur from loss of product quality (e.g., unsafe or ineffective product) or loss of product availability (e.g., delayed or absent access to a needed product) 2) In this ontology, injury and damage are treated as the particular condition a harm state is focused on, modeled as one or more specifically dependent continuants that depend on a material entity for as long as they exist; in practice this condition is typically a detrimental quality (a quality that inheres in the bearer and corresponds to deterioration relative to an appropriate baseline, e.g., tissue lesion, contamination, corrosion, fracture), and it may also include changes in realizable entities, such as a reduced or lost function/capability (what the bearer is able to do) and altered dispositions (tendencies such as a disposition to leak, fail, corrode further, or propagate contamination). HarmedState(x) → MaterialState(x) ∧ (∃h (HazardousSituation(h) ∧ precededBy(x, h)) ∨ ∃h (HazardousSituation(h) ∧ hasPostMaterialState(h, x))) true material state of one or more persons, property, or an environment in which a person is injured or has damaged health, or property or the environment is damaged There are insufficient constructs to create a set of necessary and sufficient conditions if x is a 'harmed state' then x is a 'material state' that is either 'preceded by' some 'hazardous situation' or is the 'post material state' of some 'hazardous situation' hazard detectability value expression https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ hazard detectability value expression of high assigned to low bioreactor temperature when continuous temperature monitoring and alarm functions are active; Hazard detectability value expression of medium assigned to oxygen presence in a batch polymerization vessel when oxygen presence is inferred from pressure behavior but not directly measured; Hazard detectability value expression of low assigned to trace metal variability in a powdered medium lot when the material is qualified by supplier certificate of analysis but not routinely tested in-house for each lot https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf HazardDetectabilityValueExpression(x) → ValueExpression(x) ∧ ∃h (HazardSpecification(h) ∧ continuantPartOfAtAllTimes(x, h)) true value expression that represents the degree to which a specified hazard can be discovered or determined to exist There are insufficient constructs to create a set of necessary and sufficient conditions if x is a 'hazard detectability value expression' then x is a 'value expression' that is 'continuant part of at all times' some 'hazard specification' hazard identification process https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ Hazard identification process conducted to identify factors that may pose hazards to cell-culture viability, resulting in documentation of temperature, pH, and nutrient feed rate as potential hazards; Hazard identification process conducted to identify potential hazards associated with the anaerobic digestion stage of biogas production, resulting in the documentation of low substrate pH, low temperature (< 38 °C), and high sulfur concentration in the fed substrate as potential hazards to the formation of high levels of hydrogen sulfide; Hazard identification process conducted to identify potential hazards associated with the batch polymerization stage of PVC batch manufacturing, resulting in the documentation of temperature, pressure, and the presence of oxygen as potential hazards to the formation of a flammable/explosive mixture inside the batch reactor ISO 31000:2018 and https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf 1) Hazard identification establishes the foundation for risk assessment by revealing possible events, conditions, or process factors that may influence quality, safety, or performance outcomes. It answers the question “What might go wrong?” by using information such as historical data, theoretical analysis, expert judgment, and stakeholder concerns to build a structured understanding of potential risks. 2) The axiom specifies an objective specification as an input because the hazard identification process must be scoped by some stated objective, question, or problem. The input axiom does not enumerate all informational inputs used during hazard identification, because historical data, theoretical analysis, expert judgment, stakeholder concerns, prior incidents, and tacit experience may all contribute to the process and may not all be explicitly represented in the ontology. HazardIdentificationProcess(x) ↔ PlannedProcess(x) ∧ ∃o (ObjectiveSpecification(o) ∧ hasInput(x, o)) ∧ ∃h (HazardSpecification(h) ∧ hasSpecifiedOutput(x, h)) planned process that systematically uses available information to recognize and record potential hazards relevant to a risk question or problem description every instance of 'hazard identification process' is defined as exactly an instance of 'planned process' that 'has input' some 'objective specification' and 'has specified output' some 'hazard specification' hazard operability analysis method specification https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ A HAZOP method specification for a monoclonal antibody bioreactor operation prescribes that the team analyze deviations for selected process parameters, document their causes, consequences, and existing safeguards, and recommend risk-reduction actions where needed. When carried out, the resulting HAZOP record includes deviations involving temperature, pH, dissolved oxygen, agitation rate, and nutrient feed rate, and identifies issues such as pH probe drift and setpoint-entry error together with recommendations such as more frequent calibration, redundant sensing, and improved entry controls; A HAZOP method specification for an ortho-xylene oxidation reaction in a fixed-bed catalytic reactor prescribes that the team analyze deviations for selected process parameters, document their causes, consequences, and existing safeguards, and recommend risk-reduction actions where needed. When carried out, the resulting HAZOP record includes deviations involving feed and coolant conditions, feed composition, and catalyst activation, and identifies thermal runaway as a critical outcome, with recommendations such as detailed study of safe operating limits and installation of interlocks and relief systems. HAZOP method specification https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-quality-risk-management-step-5-first-version_en.pdf Hazard and Operability Analysis (HAZOP) is a structured, systematic, qualitative technique for identifying potential risks and operability problems in a process, their causes and consequences, evaluating whether the existing safeguards are adequate to prevent hazardous situations and recommending risk reduction actions, where appropriate. It breaks complex processes into manageable elements. “Guide words” (e.g., No/None, High/More, Low/Less, Reverse, Early, Late, etc.) are applied to process parameters of each element to help identify potential deviations from normal values or design intentions. For each deviation, causes, consequences, and existing safeguards are analyzed. If risks are unacceptable or safeguards are insufficient, risk reduction actions are recommended. HazardOperabilityAnalysisMethodSpecification(x) → RiskManagementMethodSpecification(x) true risk management method specification that prescribes the systematic qualitative identification of potential hazards and operability problems in a process, evaluation of their causes, consequences, and existing safeguards, and, where appropriate, identification of recommended risk-reduction action There are insufficient constructs to create a set of necessary and sufficient conditions if x is a 'hazard operability analysis method specification' then x is a 'risk management method specification' hazard specification https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ Hazard record that specifies a cytotoxic cleaning agent present in product contact equipment as a potential source of harm that can lead to product quality failure; Hazard record that specifies trace iron concentration in culture medium above 5 ppm as a potential source of harm that can lead to CQA being out of specification; Hazard record that specifies unintended omission of the required sterile filter integrity test as a potential source of harm that can lead to contamination; Hazard record that specifies misaddition of base during pH adjustment as a potential source of harm that can lead to increased aggregation; Hazard record that specifies dissolved oxygen below the approved operating range as a potential source of harm that can lead to reduced cell viability and titer; Hazard record that specifies that high temperature (> 39 °C), high pH of the substrate, and low Carbon to Nitrogen ratio in the fed substrate are identified as potential hazards to the formation of a high amount of ammonia; Hazard record that specifies temperature, pressure, and presence of oxygen as potential hazards to the formation of a flammable/explosive mixture inside the batch reactor https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf 1) A potential source of harm is commonly referred to as a hazard. 2) A hazard may be a material entity, an information content entity, a process, or an attribute of any of these. 3) A hazard identification result may also include as a part, or may reference, criterion values for a material entity attribute or process parameter that determine when the attribute or parameter is treated as a potential source of harm. These criterion values may be qualitative or quantitative, for example a threshold, a limit, an acceptable range, a variability criterion, or a categorical level such as high, low, or out of tolerance. 4) A process specified as a potential source of harm may be planned or unplanned relative to an applicable plan specification for an execution. This includes omission cases in which a required action does not occur within the time window or at the specified point in the plan. 5) A hazardous situation is distinct from a potential source of harm, because it is a circumstance of exposure in which one or more potential sources of harm can act on a target and is modeled separately HazardSpecification(x) → InformationContentEntity(x) ∧ ∃h (HarmSpecification(h) ∧ isAbout(x, h)) ∧ ∀y (describes(x, y) → Entity(y) ∧ ¬SpatialRegion(y)) true information content entity that describes one or more potential sources of harm There are insufficient constructs to create a set of necessary and sufficient conditions. if x is a 'hazard specification' then x is an 'information content entity' that 'is about' some 'harm specification' and only 'describes' entities that are not 'spatial region' hazardous situation https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ sampling a cell culture bioreactor while the operator and culture are exposed to contamination and pressurized-fluid hazards; performing an aseptic media transfer while the product-contact path is exposed to possible microbial ingress; conducting a viral inactivation hold while personnel, equipment, and product are exposed to hazardous low-pH conditions; transferring bulk drug substance between vessels while product, equipment, and the surrounding area are exposed to leakage or contamination hazards; initiating a clean-in-place cycle while personnel and equipment are exposed to corrosive cleaning chemicals; retrieving cryogenic cell bank vials while operators and storage materials are exposed to liquid nitrogen and extreme cold; refilling an NMR cryostat with liquid helium while operators, equipment, and the room environment are exposed to cryogenic, asphyxiation, and quench-related hazards. https://www.iso.org/obp/ui/en/#iso:std:iso:14971:ed-3:v1:en:term:3.21 Potential source of harm is commonly known as a hazard and is in this case an entity that is described by a hazard specification HazardousSituation(x) → Process(x) ∧ ((∃c ∃s (Continuant(c) ∧ HazardSpecification(s) ∧ hasParticipantAtSomeTime(x, c) ∧ (describedBy(c, s)))) ∨ (∃p ∃s (Process(p) ∧ HazardSpecification(s) ∧ occurrentPartOf(x, p) ∧ (describedBy(p, s))))) true process in which one or more persons, property, or an environment is exposed to one or more potential sources of harm There are insufficient constructs to create a set of necessary and sufficient conditions if x is a 'hazardous situation' then x is a 'process' and either x 'has participant at some time' some 'continuant' that is 'described by' some 'hazard specification', or x is 'occurrent part of' some 'process' that is 'described by' some 'hazard specification' quality risk management process https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ quality risk management process for a monoclonal antibody manufacturing process in which risks to product quality from cell culture pH variability, nutrient feed errors, and harvest timing are assessed, controlled, communicated, and periodically reviewed across development and commercial manufacturing https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf Risks to drug product quality include risks arising from drug substances, raw materials, manufacturing processes, equipment, utilities, supply activities, and product availability issues caused by quality or manufacturing failures. QualityRiskManagementProcess(x) → RiskManagementProcess(x) true risk management process that systematically performs risk assessment, risk control, risk communication, and risk review for risks to drug product quality across the product lifecycle There are insufficient constructs present to create a set of necessary and sufficient conditions if x is a 'quality risk management process' then x is a 'risk management process' residual risk estimate https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ A residual risk estimate of 4 (Medium / Acceptable) has been assigned to the occurrence of microbial contamination in a sterile fill-finish stage of a pharma process, using a 5x5 residual risk matrix evaluation method, after changing both the laminar airflow system over the filling line and the Restricted Access Barrier System (RABS) that minimizes operator access https://www.iso.org/obp/ui/en/#iso:std:iso-iec:guide:51:ed-3:v1:en:term:3.9 1) It is the level of risk that remains after controls, safeguards, or mitigation measures have been applied to address an identified risk. 2) Severity is referred to as ‘impact’ in other domains, such as cybersecurity (ISO/IEC 27001). 3) In many domains the residual risk estimate is calculated iteratively until it reaches an acceptable value. ResidualRiskEstimate(x) → RiskEstimate(x) ∧ ∃a (RiskAnalysisProcess(a) ∧ isSpecifiedOutputOf(x, a) ∧ ∃r (RiskReductionProcess(r) ∧ precededBy(a, r))) true risk estimate that is a combination of the assessed likelihood of harm and the assessed severity of that harm after risk reduction measures have been implemented There are insufficient constructs to create a set of necessary and sufficient conditions if x is a 'residual risk estimate' then x is a 'risk estimate' that 'is specified output of' some 'risk analysis process' that is 'preceded by' some 'risk reduction process' risk acceptance process https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ After implementation of a backup pH probe and enhanced calibration checks, the quality unit accepts the residual risk of pH measurement drift for routine manufacturing. https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf Risk acceptance is the decision to accept risk. It may be a formal decision to accept residual risk or a passive decision in which residual risks are not specified. RiskAcceptanceProcess(x) → PlannedProcess(x) ∧ ∃r∃a∃o(RiskEstimate(r) ∧ Agent(a) ∧ InformationContentEntity(o) ∧ hasInput(x,r) ∧ hasParticipantAtSomeTime(x,a) ∧ hasSpecifiedOutput(x,o) ∧ isAbout(o,r)) true planned process in which an agent makes an informed decision to accept an estimated risk There are insufficient constructs present to create a set of necessary and sufficient conditions if x is a 'risk acceptance process' then x is a 'planned process' that 'has input' some 'risk estimate', 'has participant at some time' some 'agent', and 'has specified output' some 'information content entity' that 'is about' that same 'risk estimate' risk analysis process https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ A team performs a risk analysis for contamination scenarios that have already been identified, using an FMEA scoring rubric to assign severity, occurrence, and detectability ratings for “operator error leading to aseptic breach.” The resulting scores and any derived composite value, such as a Risk Priority Number (RPN), provide a comparable risk characterization that supports prioritizing additional controls and operator training; A team performs a risk analysis for the formation of hydrogen sulfide scenarios that have been identified as part of an Anaerobic digestion stage of a hazard identification process. The team uses an RPN +B (Risk Priority Number that also considers biohazardous aspects) indicator to perform a semi-quantitative risk analysis process, which includes severity and frequency of occurrence of the deviations, associated biohazards, and the existence of countermeasures. ISO 31000:2018 and https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf Listing possible contamination causes without estimating likelihood, severity, or any comparable risk characterization Risk analysis transforms identified hazards into measurable or comparable levels of risk. It may be performed qualitatively or quantitatively and can include the likelihood of occurrence, the severity of consequences, and, where appropriate, the ability to detect a failure before harm occurs (detectability). In biopharmaceutical development, it supports Quality-by-Design (QbD) by linking process parameters and material attributes to potential effects on product quality and performance. RiskAnalysisProcess(x) ↔ PlannedProcess(x) ∧ ∃h (HazardIdentificationProcess(h) ∧ precededBy(x, h)) ∧ ∃s (HazardSpecification(s) ∧ hasInput(x, s)) ∧ ∃r (RiskEstimate(r) ∧ hasSpecifiedOutput(x, r)) planned process that estimates the magnitude of risks associated with identified hazards by evaluating the likelihood of harm and the severity of that harm every instance of 'risk analysis process' is defined as exactly an instance of 'planned process' that is 'preceded by' some 'hazard identification process', 'has input' some 'hazard specification', and 'has specified output' some 'risk estimate' risk assessment process https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ During process development, a team conducts a risk assessment process for the objective of meeting a target impurity profile. The team identifies candidate hazards and risk relevant factors such as temperature excursions, pH control drift, and raw material variability, analyzes each risk using an agreed method and scoring rubric, and evaluates the results against predefined criteria to produce a ranked list of factors to investigate in the next DoE study; Before tech transfer, a team conducts a risk assessment process focused on maintaining sterility assurance and product potency. The team identifies failure scenarios across unit operations, analyzes likelihood and impact using platform knowledge and available data, and evaluates which scenarios require additional controls, monitoring, or procedural changes before routine manufacturing. https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf and ISO 31000:2018 A risk-assessment process systematically determines the likelihood and impact of undesirable events or conditions to support informed decision-making. It establishes a basis for prioritising control measures, mitigation strategies, or further study. In pharmaceutical development, it underpins Quality by Design (QbD) activities by identifying process parameters, material attributes, or operational factors that may affect critical quality attributes (CQAs) or key performance indicators (KPIs). RiskAssessmentProcess(x) ↔ PlannedProcess(x) ∧ ∃h∃a∃e∃s∃r∃o(HazardIdentificationProcess(h) ∧ RiskAnalysisProcess(a) ∧ RiskEvaluationProcess(e) ∧ HazardSpecification(s) ∧ RiskEstimate(r) ∧ RiskAssessmentResult(o) ∧ hasOccurrentPart(x,h) ∧ hasOccurrentPart(x,a) ∧ hasOccurrentPart(x,e) ∧ hasSpecifiedOutput(h,s) ∧ hasInput(a,s) ∧ hasSpecifiedOutput(a,r) ∧ hasInput(e,r) ∧ precededBy(a,h) ∧ precededBy(e,a) ∧ hasSpecifiedOutput(x,o) ∧ hasContinuantPartAtAllTimes(o,r)) planned process that consists of the identification of hazards and the analysis and evaluation of the risks associated with those hazards every instance of 'risk assessment process' is defined as exactly an instance of 'planned process' that 'has occurrent part' some 'hazard identification process' producing a 'hazard specification', 'has occurrent part' some subsequent 'risk analysis process' that uses that hazard specification and produces a 'risk estimate', 'has occurrent part' some subsequent 'risk evaluation process' that uses that same risk estimate, and 'has specified output' some 'risk assessment result' containing that same 'risk estimate' risk assessment result https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ risk assessment report a completed quality risk assessment report identifying contamination hazards, recording estimated risk levels for each, and documenting their evaluation against established acceptance categories; a completed equipment risk assessment report identifying magnet quench scenarios, recording estimated damage severity and likelihood, and documenting the resulting risk classification https://csrc.nist.gov/glossary/term/risk_assessment_report A risk assessment result is the overall documented output of the assessment activity. It typically contains more than a single risk estimate, and it often aggregates qualitative descriptors, scores, rankings, and decision criteria across multiple hazards or scenarios. RiskAssessmentResult(x) → InformationContentEntity(x) ∧ ∃p∃a∃e(RiskAssessmentProcess(p) ∧ RiskAnalysisProcess(a) ∧ RiskEstimate(e) ∧ isSpecifiedOutputOf(x,p) ∧ hasOccurrentPart(p,a) ∧ hasSpecifiedOutput(a,e) ∧ hasContinuantPartAtAllTimes(x,e)) true information content entity that is the output of a risk assessment process and that records the characterization of risk for one or more identified hazards There are insufficient constructs to create a set of necessary and sufficient conditions if x is a 'risk assessment result' then x is an 'information content entity' that 'is specified output of' some 'risk assessment process' and 'has continuant part at all times' some 'risk estimate' produced by a 'risk analysis process' that is part of that same 'risk assessment process' risk communication process https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ a quality manager communicates an identified contamination risk to manufacturing staff during a shift handover meeting; a process engineer communicates a high-risk parameter deviation to the production supervisor by email and in the batch review system; a risk management team communicates the outcome of an FMEA to project decision makers through a risk assessment report and a review meeting; a risk management team communicates the additional filtration step that was proposed and accepted to reduce the contamination risk during media preparation https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf RiskCommunicationProcess(x) → PlannedProcess(x) ∧ ∃a (Agent(a) ∧ hasParticipantAtSomeTime(x, a)) ∧ ∃r (RiskManagementProcess(r) ∧ occurrentPartOf(x, r)) true planned process in which information about estimated risk and risk management is shared between the decision makers and other stakeholders There are insufficient constructs present to create a set of necessary and sufficient conditions if x is a 'risk communication process' then x is a 'planned process' that 'has participant at some time' some 'agent' and is 'occurrent part of' some 'risk management process' risk control process https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ a process in which contamination risk during media preparation is reduced by introducing additional filtration and the residual risk is then accepted; a process in which the risk associated with dissolved-oxygen variation is reduced by tightening operating ranges and the remaining risk is then accepted; a process in which a previously analyzed low-level equipment risk is accepted without further reduction; a process in which oxygen-deficiency risk following helium discharge is reduced through ventilation and alarm measures and the remaining risk is then accepted https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf RiskControlProcess(x) → PlannedProcess(x) ∧ ∃p ((RiskAcceptanceProcess(p) ∨ RiskReductionProcess(p)) ∧ hasOccurrentPart(x, p)) ∧ ∃a (RiskAssessmentProcess(a) ∧ precededBy(x, a)) true planned process in which risk is reduced or accepted, or both There are insufficient constructs present to create a set of necessary and sufficient conditions if x is a 'risk control process' then x is a 'planned process' that 'has occurrent part' some 'risk acceptance process' or some 'risk reduction process', and is 'preceded by' some 'risk assessment process' risk estimate https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ The estimated risk that pH variability during the production culture process results in patient harm via reduced product availability, because it can cause harvest titer below the acceptance criterion (leading to batch rejection or reduced supply), is medium (likelihood rating = 2, severity = 3, risk score = 6); The estimated risk that lower temperature (<38 °C) during the anaerobic digestion of a biogas production process leads to H2S accumulation and resulting toxic exposure to personnel has an RPN+B (Risk Priority Number that also considers biohazardous aspects) value of 42 (severity=5, frequency of occurrence = 3, countermeasures existence= 2, associated biohazards= 2). This estimated risk is based on possible failures in the CPH (combined heat and power) system, temperature control loop and sludge stirrer https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf 1) Risk estimate may apply to processes, materials, equipment, or other operational elements and can be expressed as a numerical score, category (e.g., high–medium–low), or risk-priority number (RPN). 2) In regulatory documents such as ICH Q9 (R1), this same concept is typically referred to simply as risk. The term risk estimate is used here to emphasize its informational nature as the assessed level of risk rather than the underlying harmful event or hazard itself. 3) Likelihood is used here instead of 'probability of occurrence' to cover both numerical probabilities (quantitative estimation) and defined ordinal categories/ratings (qualitative range descriptions). 4) In some risk management tools, an assessed detectability value for a specified hazard also factors in the estimation of risk. RiskEstimate(x) → InformationContentEntity(x) ∧ ∃h∃m(HazardSpecification(h) ∧ HarmSpecification(m) ∧ isAbout(x,h) ∧ isAbout(x,m) ∧ isAbout(h,m)) true information content entity that is a combination of the assessed likelihood of harm and the assessed severity of that harm There are insufficient constructs to create a set of necessary and sufficient conditions if x is a 'risk estimate' then x is an 'information content entity' that 'is about' some 'hazard specification' and some 'harm specification' that the same 'hazard specification' 'is about' risk evaluation process https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ comparing FMEA-derived risk-priority numbers (RPNs) for dissolved-oxygen variation against an established risk-ranking scale; comparing the value of the RPN+B indicator for a scenario of high pressure between the gasometer membranes of an anaerobic digester against defined risk acceptability categories ISO 31000:2018 and https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf Risk evaluation is the comparison of estimated risk against predefined risk criteria, using a qualitative or quantitative scale, in order to determine the significance of the risk. It interprets the results of risk analysis in light of criteria such as regulatory thresholds, process capability limits, or business objectives. RiskEvaluationProcess(x) → PlannedProcess(x) ∧ ∃a∃r(RiskAnalysisProcess(a) ∧ RiskEstimate(r) ∧ precededBy(x,a) ∧ hasSpecifiedOutput(a,r) ∧ hasInput(x,r)) true planned process that compares analyzed risks against predefined criteria to determine the significance of the estimated risk There are insufficient constructs present to create a set of necessary and sufficient conditions if x is a 'risk evaluation process' then x is a 'planned process' that is 'preceded by' some 'risk analysis process' and 'has input' the 'risk estimate' produced by that same 'risk analysis process' risk management method specification https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ An FMEA method specification for a bioreactor operation prescribes that the team enumerate failure modes for each selected function or process step, document causes and effects, and score severity, occurrence, and detectability using a defined rubric; A HAZOP method specification for an ortho-xylene oxidation reaction in a fixed-bed catalytic reactor prescribes that the team analyze deviations for selected process parameters, document their causes, consequences, and existing safeguards, and recommend risk-reduction actions where needed. https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf RiskManagementMethodSpecification(x) → PlanSpecification(x) ∧ ∀y (prescribes(x, y) → PlannedProcess(y) ∧ ∃z (RiskManagementProcess(z) ∧ properOccurrentPartOf(y, z))) true plan specification that prescribes a proper part of a risk management process See the general discussion under information content entity if x is a 'risk management method specification' then x is a 'plan specification' that only 'prescribes' a 'planned process' that is 'proper occurrent part of' some 'risk management process' risk management plan specification https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ a plan specifying how contamination risks in media preparation will be assessed, controlled, documented, and reviewed during a development campaign; a plan specifying the responsibilities, decision criteria, and review schedule for managing product quality risks across commercial manufacturing; a plan specifying the resources, procedures, and assigned roles for managing magnet quench risk in an MRI facility; https://www.iso.org/obp/ui/en/#iso:std:iso:31073:ed-1:v1:en 1) A risk management plan specifies the approach, management components, and resources to be applied in managing risk. 2) Management components may include procedures, practices, assignment of responsibilities, and the sequence and timing of activities. 3) A risk management plan may apply to a particular product, process, project, organizational unit, or the organization as a whole. RiskManagementPlanSpecification(x) → PlanSpecification(x) ∧ ∃m(RiskManagementMethodSpecification(m) ∧ hasContinuantPartAtAllTimes(x,m)) ∧ ∀y(prescribes(x,y) → RiskManagementProcess(y)) true plan specification that prescribes a risk management process See the general discussion under information content entity if x is a 'risk management plan specification' then x is a 'plan specification' that 'has continuant part at all times' some 'risk management method specification' and only 'prescribes' 'risk management process' risk management process https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ a process for managing contamination risk during media preparation that includes risk assessment, risk control, communication of the results, and periodic review; a process for managing patient safety risk associated with administration of a biologic product that includes hazard identification, risk analysis, risk evaluation, risk control, and review of new safety information; a process for managing oxygen-deficiency risk associated with helium discharge that includes assessment of injury scenarios, implementation of risk reduction measures, communication of residual risk, and periodic review; a process for managing equipment-related risk in manufacturing that includes identification of failure scenarios, analysis and evaluation of associated risks, implementation of risk controls, and review of their continued suitability https://www.iso.org/obp/ui/en/#iso:std:iso:31073:ed-1:v1:en RiskManagementProcess(x) ↔ PlannedProcess(x) ∧ ∃a ∃r ∃c ∃v ∃p (RiskAssessmentProcess(a) ∧ RiskControlProcess(r) ∧ RiskCommunicationProcess(c) ∧ RiskReviewProcess(v) ∧ RiskManagementPlanSpecification(p) ∧ hasOccurrentPart(x, a) ∧ hasOccurrentPart(x, r) ∧ hasOccurrentPart(x, c) ∧ hasOccurrentPart(x, v) ∧ precededBy(r, a) ∧ prescribedBy(x, p)) planned process that systematically performs risk assessment, risk control, risk communication, and risk review every instance of 'risk management process' is defined as exactly an instance of 'planned process' that 'has occurrent part' some 'risk assessment process', 'has occurrent part' some 'risk communication process', 'has occurrent part' some 'risk review process', 'has occurrent part' some 'risk control process' that is 'preceded by' some 'risk assessment process', and is 'prescribed by' some 'risk management plan specification' risk ranking and filtering specification https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ A team applies a risk ranking and filtering method specification by defining candidate factors such as feed glucose setpoint, osmolality, and pH control, defining weighted criteria for impact on product quality, and scoring each factor using the prescribed rubric. The resulting ranked list places glucose and osmolality highest, so they are selected as candidate critical parameters for the next DoE study. RRF specification https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-quality-risk-management-step-5-first-version_en.pdf 1) Risk Ranking and Filtering (RRF) is a semi-quantitative method used to compare the relative importance of risk-relevant factors when multiple factors differ in nature, scale, or available evidence. It may combine criteria such as severity, likelihood, detectability, uncertainty, process knowledge, or potential impact into scores, categories, or rankings to support prioritization. 2) RRF may support risk analysis, risk evaluation, or selection of factors for further study, but it does not necessarily constitute the entirety of risk assessment. 3) In biopharmaceutical process characterization, RRF may be used to identify and prioritize potential critical process parameters (pCPPs), potential critical material attributes (pCMAs), or other factors based on platform knowledge, prior knowledge, and product-specific data. The resulting prioritization can guide experimental design, control strategy development, and resource allocation. RiskRankingAndFilteringSpecification(x) → RiskManagementMethodSpecification(x) true risk management method specification that prescribes criteria and procedures for prioritizing identified risk-relevant factors according to their relative risk level There are insufficient constructs to create a set of necessary and sufficient conditions if x is a 'risk ranking and filtering specification' then x is a 'risk management method specification' risk reduction process https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ To prevent human exposure to VCM (Vinyl Chloride Monomer) in the polymerization facility, a new detection system was installed that doubled the number of valves automatically sampling the air in the polymerization room, tripled the sampling frequency, and added a gas chromatography system with an electron capture detector capable of processing the full sample load, reporting results within two minutes of sampling, and detecting increases in VCM concentration at designated sampling points.; To reduce the risk of microbial contamination during aseptic filling, an automated isolator with integrated VHP (Vaporized Hydrogen Peroxide) decontamination was installed for the filling line, and the transfer of sterile components was changed from open handling to closed, decontaminated rapid-transfer port; To reduce the risk of cell-culture viability loss due to pH control failures, redundant pH probes were installed on the production bioreactor, a validated probe calibration and drift-check procedure was implemented, and an automated control logic change was deployed to hold base addition and trigger operator intervention when probe disagreement exceeded the defined threshold https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf Risk reduction may be realized through many different kinds of actions and subprocesses, including actions that eliminate a particular hazard, measures that mitigate the severity and/or probability of harm, and measures that improve the detectability of hazards and quality risks. In practice, these measures are typically made explicit in recorded outputs such as risk control plans, control strategy specifications, CAPA (Corrective Action and Preventive Action) plans, change controls, and associated implementation records. However, because the concrete form of risk reduction varies widely across organizations and contexts, the ontology treats these measures primarily as occurrent parts of the risk reduction process, rather than axiomatically constraining a fixed set of required action types or outputs. RiskReductionProcess(x) → PlannedProcess(x) ∧ ∃r (RiskEstimate(r) ∧ hasInput(x, r)) true planned process that consists of actions taken to lessen an estimated risk There are insufficient constructs present to create a set of necessary and sufficient conditions if x is a 'risk reduction process' then x is a 'planned process' that 'has input' some 'risk estimate' risk mitigation process risk review process https://spec.industrialontologies.org/ontology/biopharma/BiopharmaRiskManagement/ A biopharmaceutical manufacturer evaluates prior risk management outcomes concerning raw material variability after a supplier change; An organization evaluates prior risk management outcomes after an audit identifies that an existing approval step is not being performed consistently; A team evaluates prior risk management outcomes in light of findings from a failure investigation; During a periodic review, monitoring data and change records are considered to determine whether an existing inspection frequency remains appropriate https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-use-ich-guideline-q9-r1-quality-risk-management-step-5-revision-2_en.pdf 1) This process is used to determine whether the outcomes of risk management activities remain appropriate typically in light of new knowledge, experience, or events relevant to the risk. 2) Risk management activities are planned processes that are parts of a risk management process. 3) This process may occur periodically or in response to planned or unplanned events that could affect a risk-related decision, its basis, or the adequacy of associated risk controls. 4) Planned events may include product review, inspections, audits, change control activities, or scheduled trend evaluation. 5) Unplanned events may include deviations, failure investigation findings, complaints, recalls, or newly identified sources of risk. 6) Information considered in this process may include monitoring data, trend data, investigation outcomes, change records, audit observations, and other records relevant to the risk. 7) This process may lead to confirmation of current or prior outcomes or to their revision, including updates to risk acceptance decisions, risk controls, or associated records RiskReviewProcess(x) → PlannedProcess(x) ∧ ∃r(RiskManagementProcess(r) ∧ occurrentPartOf(x,r) ∧ (∃p(PlannedProcess(p) ∧ occurrentPartOf(p,r) ∧ precededBy(x,p)) ∨ ∃p(PlannedProcess(p) ∧ occurrentPartOf(p,r) ∧ isTemporallyOverlappedBy(x,p)))) true planned process in which the outcomes of risk management activities are monitored or evaluated There are insufficient constructs present to create a set of necessary and sufficient conditions if x is a 'risk review process' then x is a 'planned process' that is 'occurrent part of' some 'risk management process' and either is 'preceded by' some 'planned process' that is 'occurrent part of' that same 'risk management process', or is 'temporally overlapped by' some 'planned process' that is 'occurrent part of' that same 'risk management process'