---
title: "ICH Q9(R1) — Quality Risk Management — KYE Protocol™ coverage"
description: "ICH Q9(R1) — Quality Risk Management coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it."
url: https://kyeprotocol.com/compliance/ich-q9/
lang: en
source: "KYE Protocol"
---

> ICH Q9(R1) — Quality Risk Management coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it.

ICH Q9(R1) — Quality Risk Management

# ICH Q9(R1) — Quality Risk Management — 100% of in-scope requirements covered.

4 requirements · 3 in scope (3 enforced) · 1 out-of-scope (outside KYE™’s authority layer). The 100% is weighted over the in-scope base.

**Source:** ICH Q9(R1) Quality Risk Management provides principles and tools for a systematic process for the assessment, control, communication and review of risks to the quality of a medicinal product across its lifecycle. It anchors risk-based decision-making (formality of the risk assessment, subjectivity of risk decisions, and the role of risk in supply chain and product availability). KYE Protocol™ governs whether an AI-generated QRM output (a risk assessment, a risk-based decision, an FMEA record) may PROCEED to a consequential action — Quality-Unit approval, reliance in a dossier, or use to release a lot — under a named Quality Unit / QP authority, with the risk-decision justification recorded before the action and replay-provable provenance. KYE™ does not perform the risk science, set the risk thresholds, or judge whether the risk decision is correct. · **License:** ICH guidelines are published by the International Council for Harmonisation; KYE™ registry paraphrases each requirement's intent and cites the official identifier for mapping purposes only.

## By category

| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
| --- | --- | --- | --- | --- | --- | --- |
| Risk-based decision authority at the action boundary | 1 | 1 | 0 | 0 | 0 | **100%** |
| Risk-decision justification recorded before the action | 1 | 1 | 0 | 0 | 0 | **100%** |
| Replay-provable QRM provenance | 1 | 1 | 0 | 0 | 0 | **100%** |
| Risk-assessment science & control-strategy selection | 1 | 0 | 0 | 0 | 0 | **0%** |

## Every requirement → the KYE™ artefact that enforces it

| ID | Title | Status | KYE™ enforcement |
| --- | --- | --- | --- |
| `ich-q9.qrm-decision-authority` | Risk-based decision by an AI QRM output proceeds only under a recorded named-authority decision | enforced | **audit\_events**: `kye.purpose.request.v1`, `kye.purpose.admissibility.v1`, `kye.evidence.decision_map.v1` **engines**: `internal`, `internal` **rule\_packs**: `kye:rule-pack:ich-authority` **dictionaries**: `internal` **constitution\_refs**: `constitution/12-PURPOSE-PERMISSION.md` |
| `ich-q9.risk-decision-justification` | An AI risk-based decision proceeds only with its risk-decision justification recorded before the action | enforced | **audit\_events**: `kye.evidence.decision_map.v1`, `kye.evidence.pack.v1` **engines**: `internal` **rule\_packs**: `kye:rule-pack:ich-authority` **constitution\_refs**: `constitution/13-RESILIENCE-LOOP.md` |
| `ich-q9.qrm-provenance` | Replay-provable provenance pin for an AI QRM output relied on in a consequential action | enforced | **audit\_events**: `kye.evidence.tool_call.v1`, `kye.replay.context_seal.v1` **engines**: `internal` **rule\_packs**: `kye:rule-pack:ich-authority` **constitution\_refs**: `constitution/13-RESILIENCE-LOOP.md` |
| `ich-q9.risk-assessment-science` | Hazard identification, probability / severity scoring and control-strategy selection | out-of-scope | _(no enforcement cited)_ |

Canonical KYE™ surfaces referenced on this page: [KYE Protocol™](https://kyeprotocol.com/).
