Week 2 — Sep 21: Analytical Methods Development, the Modality Landscape, and Risk

Three things that have to be understood together before anything else in the course makes sense: how an analytical method actually gets developed and regulated, what is actually being made (the modality landscape), and how much evidence is enough (quality risk management).
A banner titled 'Week 2 – Sep 21: Risk Management, How much evidence is enough — and how do you decide?' with the tagline 'Focus the effort on what matters most. Protect the patient. Make scientifically justified decisions,' alongside a photo of a hiker overlooking mountains and a list — Identify, Assess, Control, Communicate, Review, A Safer Tomorrow. Below, five panels: (1) The Big Idea — quality risk management is how we decide how much evidence is enough, focusing time, money, and attention on the failures that would actually harm a patient without gold-plating the rest, with the ICH Q9(R1) quote that risk evaluation is grounded in scientific knowledge and linked to patient protection, and that effort, formality, and documentation should be proportionate to risk; (2) The ICH Q9 Framework, shown as a continuous four-step cycle around 'Quality Risk Management' — 1. Risk Assessment (identify, analyze, evaluate), 2. Risk Control (reduce, accept), 3. Risk Communication (share with stakeholders), 4. Risk Review (revisit when something changes); (3) Risk Assessment in Practice, a table walking Identify → Analyze → Evaluate → Control → Communicate → Review, each row pairing what happens with an analytical example (e.g., identify: a co-eluting degradant not resolved from the API; control: use an orthogonal column and add a peak-purity check); (4) From Risk to Control Strategy, a chevron flow — identify and assess risks (FMEA, FTA, etc.) → prioritize (highest impact on patient) → implement controls (method design, process controls) → accept residual risk (document and justify) → monitor and review (lifecycle, new information) — beside four callouts: right level of effort, right data, right decisions, greater patient protection. A second row of panels: (5) The Risk Management Toolbox, a table of tools and best uses — FMEA/FMECA (failures of a process or method, workhorse in analytical development), fault tree analysis/FTA (work backward from a defined failure, good for OOS investigations), HACCP (identify and control critical points, origin in food safety, maps well to manufacturing), HAZOP (deviations from design intent, common in process/engineering), risk ranking and filtering (compare many risks, portfolio- and site-level decisions), Ishikawa/fishbone/PHA (first-pass hazard identification, often the front end of an FMEA); (6) FMEA: How It Works, break the process down, find the weaknesses, act on them — a table of steps (failure mode, effect, cause, detection, score, action) each with its question and an HPLC-assay example, ending in RPN = severity × occurrence × detection prioritizing where to act; (7) Two Key Reminders from Q9(R1) — first, hazard is not risk (a hazard is the potential to cause harm; risk combines the probability of that harm with its severity; 'this solvent is toxic' is a hazard statement, 'at the residual level this method can detect, the exposure is X% of the PDE' is a risk statement); second, formality is a dial, not a switch — match the formality to what is at stake, and say why. A closing photo strip: understand the risks (a gloved hand holding a vial), generate the evidence (a chromatogram on a monitor), make the decision (an analyst at a workstation), protect the patient (tablets on a line), enable a healthier tomorrow (a globe).

(Lecture 2.) Week 1 argued that a method is a hypothesis about a molecule and that the discipline is built to revise it when the evidence says so. This week asks three questions that sit underneath everything else in the course: how does an analytical method actually get developed and regulated, what is actually being made, and how much evidence is enough? The third question is risk — assessed explicitly, not by reflex — and it’s the one this week is named for; the first two are the ground it stands on.

The one idea

A control strategy cannot be designed in the abstract — it is designed against a specific molecule, made by a specific process, measured by a method developed and validated for that purpose, with its own population of things that can go wrong. Before the course can teach how you measure something and how you control it, it has to teach what you are holding and how the method that measures it came to exist — then it can teach how much evidence is enough.

Analytical methods development and regulation

Every technique week for the rest of the term assumes a method already exists. This section is the one-page version of how it got there, so that assumption is never invisible:

StageWhat happensTies to
Analytical target profile (ATP)State the requirement — analyte, matrix, range, accuracy/precision — before any column, wavelength, or probe is chosenQ14
DevelopmentScout and optimise against the ATP, not against “does it separate”Taught in full at Separation Methods, the pattern generalises to every technique
ValidationSpecificity, linearity, range, accuracy, precision, LOD/LOQQ2(R2)
TransferThe same answer in every receiving labWeek 1 · QC
LifecycleMonitored and revised over its life; what counts as a reportable change is itself a risk decisionQ12, Q14

The regulatory expectation — captured in ICH Q14 — is that a method is designed against its validation targets and its analytical target profile from the start, not developed first and validated as an afterthought. Every worked method later in the course (chromatography, mass spec, spectroscopy) follows this same lifecycle; this is the only week that names it explicitly end to end.

What’s actually being made, and how much evidence is enough

Two more questions sit underneath every technique week: what is actually being made, and how much evidence is enough? Both get their own full treatment this week, in their own sections:

  • The modality landscape — a small molecule, a large molecule / biologic, and an advanced therapy compared side by side (size, manufacture, what “the molecule” even is, what purity means), plus why small molecule dominates entry-level hiring.
  • Quality risk management — the ICH Q9(R1) framework, the risk-management toolbox (FMEA, FTA, HACCP, HAZOP, risk ranking and filtering, Ishikawa/PHA, each with its own full walkthrough), and how a risk assessment becomes a control strategy.

The risk-homework thread

Three of the technique weeks later in the term — atomic spectroscopy, molecular spectroscopy, mass spectrometry — carry a risk-assessment assignment: take the method taught that week and build a method FMEA against a stated analytical target profile. The point is repetition: by the third checkpoint, scoring detectability should be a habit.

Where the analyst sits

Nobody hands you the modality landscape or the method-development lifecycle on day one — you infer them from the job posting, the SOPs on the shelf, and the first specification you’re asked to read. And in almost every method FMEA, the analyst is the only person in the room who knows the true detection score. A project manager can estimate severity; a process chemist can estimate occurrence; but whether the current controls would actually catch a failed extraction, a mis-integrated peak, a drifting calibration, or a co-eluting impurity before it reached a release decision is analytical knowledge, and if the analyst rounds it toward “we’d probably catch it,” the whole assessment is quietly wrong.

This is the STEAM “A” again: judgment about what the evidence can and cannot rule out. The refrain for the term — science → evidence → reduced uncertainty → control → regulatory confidence → patient trust — runs through method development above, and through the modality landscape and risk management in the sections that follow.

On the job

  • Read a job posting for an “Analytical Chemist I” or “QC Analyst” role and identify which column of the modality table it’s written against — the instrument list in the posting almost always gives it away.
  • Small molecule dominates entry-level hiring for a structural reason: there are simply more marketed small-molecule products, more generic and CDMO manufacturing sites, and more routine QC testing volume than for biologics or advanced therapies, which remain comparatively low-volume, specialised, and concentrated at fewer sites.
  • You will fill out, or be asked to sign off on, an FMEA far more often than you will build one from scratch — learn to read one critically before you learn to write one.
  • “Detection” is the column you’ll be asked about most, because you’re usually the only person in the room who actually knows what the running method would or wouldn’t catch. Don’t round it up to be agreeable.
  • A risk assessment that predates you (written by someone who’s since left) is still binding until it’s formally revisited — know how to find it, read it, and flag when it no longer matches reality.

For discussion

  • A job posting lists “HPLC, dissolution, ICP-MS” as required instruments. Which column of the landscape table is this role almost certainly in?
  • Why does “purity” require a panel of methods for a biologic but one method for a small molecule? Push past “it’s bigger” to the actual mechanism.
  • An advanced-therapy company is hiring far fewer analysts than a generic small-molecule manufacturer down the road, for a product that’s scientifically more sophisticated. Reconcile that with “the industry needs analytical skill.”
  • A method FMEA gives a mis-integration failure mode an RPN of 90 (S=9, O=2, D=5) and a wrong-diluent failure mode an RPN of 90 (S=5, O=3, D=6). Should they get the same attention? What does RPN hide here?
  • Your detection score for “co-eluting unknown degradant” depends on data you don’t have yet (forced degradation isn’t finished). How do you score it now, and what do you commit to?
  • The nitrosamine risk assessments concluded “no risk” for many products on the strength of a purge argument, with no confirmatory testing. When is a scientific argument enough, and when do you need the number?

Source note. Method-development framing follows ICH Q14 and ICH Q2(R2). See the modality landscape and risk management for their own sourcing. (Instructor: this session now absorbs what were two separate lecture weeks — confirm the pacing works in a single 3-hour slot.)


What's Actually Being Made — the Modality Landscape

Before any technique week makes sense, the course needs to answer what is actually being made: a small molecule, a large molecule / biologic, and an advanced therapy compared side by side — size, manufacture, what “the molecule” even is, what purity means, and why small molecule dominates entry-level hiring.

Quality Risk Management — How Much Evidence Is Enough

ICH Q9(R1) as a loop, not a form: the risk-management toolbox (FMEA, FTA, HACCP, HAZOP, risk ranking and filtering, Ishikawa/PHA), FMEA in action, and how a risk assessment becomes a control strategy — worked through the nitrosamine risk assessments.