FREE WEBINAR & DOWNLOAD:  How does your SCTA performance measure up?  Get your SCTA Health Check here.

Matching Rigour to Risk: From Learning Teams to SCTA in GMP

If you work in pharmaceutical quality, you already live by a distinction this blog depends on: the difference between a useful discussion and a documented risk assessment. Both have their place. They are not the same thing, and you would never offer one where a regulator expects the other.

Why a Learning Team is not a risk assessment, and how the LT+ gradient closes the gap for GMP-critical tasks

If you work in pharmaceutical quality, you already live by a distinction this blog depends on: the difference between a useful discussion and a documented risk assessment. Both have their place. They are not the same thing, and you would never offer one where a regulator expects the other.

Learning Teams have, rightly, become popular in our industry. They are one of the best ways to understand how work is really done on the floor, and to do it with the people who do it. However, a Learning Team is a structured conversation, and a conversation, however skilled, is not a risk assessment. For your most critical, highest-consequence tasks, that gap matters. This blog is about how to close it without giving up anything you value about Learning Teams, by treating them as the first rung of a gradient that runs all the way up to a full Systems Critical Task Analysis (SCTA)[1].

What Learning Teams do well

A Learning Team, drawn from the Human and Organisational Performance (HOP) tradition, is a facilitated group session with frontline staff and subject matter experts about how a task is actually performed. In practice it usually runs in two phases: a learning phase that gathers the real story of the work without rushing to fixes, and an improvement phase that turns that understanding into action.

Its strengths are genuine. It creates the psychological safety that gets operators to tell you what really happens, including the adaptations needed (workarounds) that are needed given production pressures that never reach a deviation report. It exposes the gap between the procedure as written and the work as done. It moves a quality culture away from blame and towards curiosity. For an organisation early in its human factors journey, that shift alone is valuable, and nothing here is meant to diminish it.

Why that is not yet risk control

The limitation is not about facilitation skill. It is structural, and it is exactly the limitation a quality professional would expect of any method built on discussion. As a way of controlling risk on a critical task, a Learning Team on its own falls short in three specific ways.

It is not systematic. A conversation covers what participants raise and remember on the day. A different shift, a different facilitator, or a different mood in the room produces a different list. There is no guarantee that every step of the task has been examined, which is precisely the guarantee a risk assessment is meant to provide.

It is not predictive. A Learning Team learns from what has happened, or is happening now. It is strong on lived experience and weak on the failure that has not occurred yet. On a long-established process, where training leans on accumulated personal experience, the rare, high-consequence failure mode is the one least likely to come up, because no one in the room has lived it.

It is not anchored to the critical risks. Discussion tends to surface issues in the order they come to mind, not in the order they threaten the product. Without a systematic pass, you rarely end up with a ranked, defensible statement of the few things most likely to cause real harm.

We saw all three on a real task. We ran a study on a manual, repetitive operation: preparing a trolley of equipment for an autoclave, a process that suffered frequent and sometimes costly deviations. When we asked staff across shifts what the top risks were, we got energetic discussion but no shared, ranked answer. In an ideal world the principal risks would headline the training and the procedure, and any operator could name the top few. They could not, and that is no reflection on them. It is what discussion alone tends to produce.

A good Learning Team on this task would have surfaced real issues, and some of what we found could have come up in conversation. What the structured analysis added was completeness and order. Working through the task step by step, we examined every step rather than only the ones that came to mind, and then ranked what we found by risk. That approach pinned down detail like this: of around twenty items, only three needed triple rather than double bagging, an easily missed distinction; a stopper transfer arm could be assembled wrongly with no visual cue and no easy check afterwards; bags tied too tightly were causing problems on the sterile side, traced to inconsistent training; and stopper tubes were sometimes inverted, partly because the reference photo in the procedure was itself printed upside down. The point is not that a conversation could never reach any one of these. It is that a systematic, ranked approach reaches all of them, in order of importance, every time, and leaves you with something you can defend. You can read the full case study here: Systems Critical Task Analysis: A Case Study for Quality Improvement.

Matching Rigour to Risk: a worker loads an autoclave.

What SCTA adds

SCTA is, at its core, a risk assessment methodology, and it closes those three gaps directly. It is built on a detailed task model and works through four linked elements.

  • Hierarchical Task Analysis (HTA) decomposes the task with the people who do it. It forces tacit knowledge into the open and tests what the procedure assumes against work-as-done. A forty-step procedure can expand past a hundred and twenty steps once properly broken down, exposing detail experienced operators no longer realise is important. This is what makes the analysis systematic: every step is on the table for the risk assessment (importantly they don’t all need to make it back into the procedure).
  • Failure mode analysis (from a human point of view) is then applied to every step in turn, in effect a human HAZOP. It considers not only the error traps that have caught people before, but the ones that have not yet caused a problem. This is what makes it predictive.
  • Performance Influencing Factors (PIFs) are tied to specific failure modes at specific steps: which step, under what condition, fails in what way, and why. “Staffing is a problem” becomes “at this step, under this condition of limited resource, this is the likely error, for this reason.”
  • Risk reduction and control then follows. With the failure modes and their PIFs understood, controls are chosen against a hierarchy: eliminate or substitute the hazard first, engineer it out next, and only then rely on the weaker administrative controls of procedure, training and supervision. Optimising the PIFs, the conditions that make error more or less likely, sits alongside this, so the task is made more reliable by design not by asking people to try harder. Ranking by risk is what anchors the output to the critical few.

In a high-hazard industry, a good conversation is not a risk assessment.

Beneath this sits a difference in what each method draws on. A Learning Team is rooted in people’s experience: it surfaces what operators have noticed and can put into words. SCTA starts from that same experience but does not stop there. It also looks analytically at the things that shape behaviour whether or not they came up in the room – the psychology of how people slip and lapse, the contextual and design features of the workplace, and the engineering and structure of the task itself.

The difference shows in the depth of a single finding. A Learning Team might note that operators find tying the bags too tightly annoying. That is true, and worth fixing. SCTA notices it too, but also sees that the three items needing triple bagging are dispersed among twenty that need only double bagging, and recognises that this arrangement makes a lapse more likely, with the predictable result being an item left double-bagged when it should have been triple. One is a report of an irritation. The other is an analysis of how the task is set up to fail, and what to change so that it is not.


One is a report of an irritation. The other is an analysis of how the task is set up to fail, and what to change so that it is not.

The LT+ gradient

None of this means abandoning Learning Teams. On the contrary, it means recognising that they sit at one end of a continuum and SCTA at the other, and that you can move along it one structural layer at a time. We call the steps in between LT+, simply a Learning Team plus an added layer of structure. Each layer closes a little more of the gap between a good conversation and a full risk assessment.

Matching Rigour to Risk: the ladder of levels for the LT+ gradient

These grades are not a ladder you must climb to the top of every time. They are a way of matching the depth of analysis to the task in front of you and the significance of the impact of the issue you are investigating.

How much rigour, and when?

That raises the question a quality professional will already be asking: how far up the ladder should we go, and when is the extra effort justified? This is familiar ground, because it is the logic of ICH Q9(R1). Rigour should be proportionate to risk. More rigour is warranted as four things increase: the importance of the task to product quality and patient safety; the complexity of the work; the uncertainty in your current understanding of how it is done; and the consequence of failure. A routine, well-understood, low-consequence task may need no more than a Level 1 or 2 conversation. A complex, high-consequence sterile operation carrying real uncertainty is where Level 4 or 5 earns its place. The gradient is simply how you make that call deliberately, and document why you made it.

Outputs you can act on, and defend

Because SCTA works at the level of steps, failure modes and PIFs, its outputs are specific enough to act on. From a single analysis you can produce a risk-based procedure, a training or competency standard, and a full risk assessment, all prioritised by risk and all traceable to the same task model.

Two careful points, both from colleagues who reviewed this work. First, SCTA does not, by itself, deliver compliance or reduce risk. What it does is support a documented rationale for risk reduction, and improve the likelihood that procedures, training and controls are genuinely aligned with work-as-done. The reduction comes from acting on the analysis. Second, the loop has to close: revised procedures and training should be verified through effectiveness checks, not assumed to have worked because the analysis was thorough. Working in a single platform such as SHERPA helps here, because when the analysis changes, the linked procedure, training standard and risk assessment can change with it, rather than drifting apart the moment they are filed.

There is a related check worth making explicit. It is easy to assume a control is doing its job when it is not. Sometimes a control cannot work as intended by design, sometimes it quietly changes, sometimes it is simply not operational, and sometimes it can be defeated so easily that it offers far less protection than people believe. Working through a task step by step tends to expose this. In one analysis, two bags were treated as impossible to confuse because they came in different sizes; on inspection, they were exactly the same size. In other analyses an emergency shutdown button was inaccessible, and a unique coupling could be defeated. Part of the value of SCTA, and of recording controls against specific failure modes in SHERPA, is that assumed controls have to be named and then checked as present and effective, rather than taken on trust.

Different flavours of LT+

We have presented the LT+ gradient as layers building towards a full SCTA, but the layering is flexible. It is perfectly possible to miss out the task analysis and failure analysis and run a PIF analysis off the back of a Gemba-style walkthrough and talkthrough, though importantly that would not constitute a full SCTA.

The plus idea also travels well beyond SCTA. The same move – take a structured conversation with the people who do the work, then add a method that shapes what you look for – can be aimed at very different questions. Learning Team plus usability testing, Learning Team plus contextual design, Learning Team plus a cybersecurity audit: each adds different prompts, inputs and affordances, and so yields different data, depending on the research and learning objective. They are different recipes producing different results. 

Where you stand

For GMP-critical tasks, the question is not whether to run Learning Teams. It is whether, for your highest-consequence work, a conversation is quietly doing a job that calls for more in-depth risk assessment.

If you would like to find out, we have a one-page self-assessment that lets you place your most critical tasks on the gradient in about five minutes. And if you would like us to look at a specific task with you, book a 30-minute gradient review: we will tell you which rung your highest-risk task sits on today, and what the next rung would add. No obligation, and you will come away with a clearer view of where a conversation ends and a risk assessment needs to begin.


Acknowledgements


The author is grateful to Julie Avery, Valerie Mulholland and Neil Hunter, whose comments on earlier versions helped to sharpen both these ideas and the way they are presented. This article was drafted with the assistance of Claude, an AI assistant developed by Anthropic; the ideas, expertise and final editorial decisions are the author’s own


[1] SCTA is also known as Human Factors Safety Critical Task Analysis in the high hazard industry, however we have adopted ‘Systems’ for a wider scope beyond safety. These are rooted on a family of Human Reliability Assessment methods that have their foundation based on SHERPA (Embrey, 1986) that link Hierarchical Task

Analysis, Failure Modes and PIF (Performance Influencing Factors) assessments.

Professionals like you subscribe to our Human factors thinking.

Want specialist HRA insights direct to your inbox? Get the handbook, email series, and monthly insights from our industry-leading thinkers.