QMS
Tier I, II and III Quality Documentation
By Manoj Kumar Verma7 min read
In short
Pharmaceutical quality documentation is conventionally structured in three tiers: Tier I is the policy layer (Quality Policy, Quality Manual, Site Master File), Tier II is the procedural layer (SOPs that say how the policy is carried out), and Tier III is the execution layer (work instructions, forms, logbooks and batch records that generate the evidence).
Every quality system has a document hierarchy. Most have two: the one drawn in the Quality Manual, and the one people actually use.
The gap between them is where findings live.
The three tiers
| Tier | Contains | Answers | Typical owner |
|---|---|---|---|
| I | Quality Policy, Quality Manual, Site Master File | What we commit to and how quality is organised | Site head / quality head |
| II | Standard Operating Procedures | How each process is carried out, and by whom | Process owners |
| III | Work instructions, forms, logbooks, BMR/BPR, records | Evidence of what was actually done | Operators and their supervisors |
Tier I — the policy layer
Tier I documents state intent and structure. They are short, rarely revised, and approved at the highest level on site.
The Quality Policy is a statement of commitment. The Quality Manual describes the quality management system: its scope, the processes within it, how they interact, and the responsibilities attached to them. The Site Master File describes the site itself in GMP terms.
Tier I is where an inspector calibrates expectations. If the Quality Manual describes a management review cycle the site does not run, everything below is now suspect.
Tier II — the procedural layer
SOPs are the working heart of the system: CAPA, deviations, change control, out-of-specification results, self-inspection, training, document control, supplier qualification, complaints, recalls, data integrity.
Two failure modes dominate.
Procedures written to describe the ideal rather than the actual. Someone documents how the process should run, the floor keeps running it the way it always did, and the divergence stays invisible until an audit traces a record back to the procedure that supposedly governed it.
Procedures that contradict each other. Two SOPs, written by different departments a year apart, specifying different deviation classification timelines. Both current. Both approved.
Neither is a documentation problem. Both are architecture problems — which is why the tier structure is worth taking seriously.
Tier III — the execution layer
Tier III is where the evidence comes from: work instructions, forms, logbooks, batch manufacturing records, batch packaging records, cleaning records, calibration records, training records.
EU GMP Chapter 4 draws the useful distinction here — between documents of the instruction type, which tell you what to do, and documents of the record type, which capture what was done. Tier III contains both, and the pairing matters: an instruction with no corresponding record produces no evidence, and a record with no controlling instruction produces evidence of something nobody specified.
Why the hierarchy actually matters
Not for tidiness. For three concrete reasons:
Traceability. An auditor picks a batch record entry and walks upward: which work instruction governed this step, which SOP governs that instruction, which section of the Quality Manual commits to that process. If the chain holds, the system is coherent. If it breaks, you have found a gap the site did not know it had.
Change impact. When an SOP changes, the hierarchy tells you which forms, instructions and records are affected. Without it, changes propagate by memory.
Orphan prevention. Documents that trace to nothing above them accumulate in every system. They are almost always created under time pressure, by someone who needed a controlled document faster than change control could deliver one.
Four tiers, two tiers, other names
Plenty of organisations use four levels, splitting Tier III into work instructions and records. ISO-influenced systems often use policy / procedure / work instruction / record. Small sites sometimes collapse to two.
All of these are fine. The number is not the point. What matters:
- The structure is defined in a document control procedure.
- Every document type has a stated place in it.
- Every document references its parent.
- The structure is what people actually use, not an aspiration.
How an inspector navigates it
Typically downward then upward. Down first — Quality Manual, then the SOP for the system under examination, then the records it generates — to understand what the site says it does. Then upward from a specific record, to test whether the documented system and the operating reality are the same system.
The second pass is the one that finds things.
Building it in the right order
For a new site or a system being rebuilt, the sequence that works:
- Define the document control procedure first. It is the only SOP that has to exist before the others can be written properly, because it sets numbering, hierarchy, review cycles and approval routes.
- Draft Tier I to establish scope and structure.
- Map the Tier II set — every procedure the regulatory pathway and the operation require — before writing any of them. The map prevents the contradictions.
- Write procedures in dependency order, starting with the ones others reference.
- Build Tier III alongside its parent procedure, never afterwards. Forms designed after the SOP tend to capture what is convenient rather than what the procedure requires.
- Train, then run a trace exercise — pick a record, walk it up the hierarchy, and fix what breaks. Do it before an auditor does.
A quality system is only as strong as the architecture underneath it. Documents written as isolated deliverables produce a library. Documents written into a structure produce a system.
FAQ
Frequently asked questions
Is the three-tier model a regulatory requirement?
No. It is an industry convention, not a regulation. GMP requires that documentation exists, is controlled, is accurate and is retrievable — EU GMP Chapter 4 and 21 CFR Part 211 Subpart J set those expectations — but neither mandates a particular number of tiers or a particular naming scheme. The model is useful because it enforces traceability and prevents orphaned documents, not because an inspector will ask for it by name. Some organisations use four tiers, some use two. What matters is that the structure is defined, documented and actually followed.
What is the difference between an SOP and a work instruction?
An SOP describes a process end to end — what is done, by whom, in what sequence, with what controls — and typically spans roles or departments. A work instruction describes how to perform one specific task, usually at one workstation by one role, in enough detail to be followed without interpretation. "Handle deviations" is an SOP. "Operate the tablet press changeover" is a work instruction. The boundary is a judgement call, and the important thing is that your document control procedure defines where you draw it.
Where does the Site Master File sit?
Tier I. A Site Master File describes the manufacturer's GMP-related activities at a given site — company and site details, personnel, quality system, premises and equipment, documentation, production, quality control, contract activities, distribution, complaints and recalls, and self-inspection. It sits alongside the Quality Manual as an apex document, and it is often read by an inspector before they arrive, which makes it one of the highest-leverage documents on site.
What is an orphaned document?
A document that exists and is used but does not trace to anything above it — a form nobody's SOP references, a work instruction whose parent procedure was superseded, a local spreadsheet doing the job of a controlled record. Orphaned documents are what auditors find when they trace a record upward and the chain breaks. They accumulate quietly, usually because someone needed a document faster than the change control process could produce one.
Further reading
Inspection Readiness · 9 min read
Responding to an FDA Form 483
FDA reviews Form 483 responses received within 15 business days. What to do in each of those days, and the mistakes that trigger a Warning Letter.
GMP Training · 6 min read
How Often Is GMP Training Required?
No regulation sets a fixed interval. What 21 CFR 211.25 and EU GMP Chapter 2 actually require, and how to justify the training frequency you choose.