In our last post, we wrote about the gap between tracking and oversight: how a spreadsheet can hold a due date but can’t tell you, in time to act, whether that commitment is actually at risk. Nowhere does that gap create more exposure than in the implementation of additional risk minimization measures (aRMM), where the obligations are specific, the deadlines are regulatory, and the consequences for missing either are not hypothetical.
If your team manages aRMM and broader risk mitigation measure implementation primarily through spreadsheets and shared drives, you already know the discipline it takes to keep that system accurate. What’s harder to see, until an inspection or a near-miss forces the issue, is where that discipline quietly breaks down.
The compliance gaps hiding inside “we track this manually”
Ownership drift. aRMM implementation is rarely owned by one person for its full lifecycle. A given measure, say an educational program or a controlled access program, might start with regulatory affairs, move to a medical safety reviewer, and end with someone in quality confirming rollout and effectiveness checks. In a spreadsheet, ownership is whatever the “Owner” column says, which is only accurate if every handoff is logged the moment it happens. In practice, handoffs happen in meetings and emails first, and the spreadsheet catches up later, if it catches up at all.
Status that isn’t actually current. A cell that says “on track” is a claim, not a fact. It reflects whatever the last person to touch it believed at the time. There’s no built-in mechanism forcing that status to be reverified against what’s actually happening with the measure itself: whether materials have actually reached the intended audience, whether an effectiveness check is due, whether a distribution restriction is being followed in practice. The result is a tracker that looks orderly right up until someone checks the underlying reality and finds it’s drifted from what the spreadsheet says.
Fragmented tracking across measures. A single RMP can carry multiple aRMM and other risk mitigation measures running in parallel, each with its own timeline, audience, and reporting obligation. Tracking all of that inside one spreadsheet (or worse, several, one per measure) means cross-referencing dependencies by hand. Miss a dependency, an updated educational material that should trigger a corresponding update to a related measure, and you have a compliance gap that won’t surface until someone goes looking for it specifically.
No defensible trail, by default. When a regulatory assessment or internal audit asks for the history of an aRMM commitment, who changed the status, when, and why, “check the version history and cross-reference the email thread” is not a defensible answer. It’s a scramble dressed up as a process. Spreadsheets don’t build an audit trail as a byproduct of use. Someone has to build and maintain that discipline on top of the tool, and it’s the first thing to slip when the team is busy.
Scale exposes all of it at once. A handful of risk mitigation measures, closely watched by a small team, can survive on manual discipline for a while. Add a growing portfolio, more products, more aRMM programs, more regulatory touchpoints across geographies, and the same manual process that used to be merely inefficient becomes actively risky. The gaps above don’t grow linearly with portfolio size. They compound.
Why “add more process” doesn’t close the gap
The typical response to a near-miss is procedural: a stricter update cadence, a second reviewer, a monthly reconciliation meeting. These aren’t bad ideas, and PV and regulatory teams are generally disciplined about applying them. But they’re patches on a tool that was never designed to enforce aRMM or risk mitigation measure logic; it was designed to hold data and calculate on it. Every patch adds manual overhead without addressing the underlying issue: the system itself doesn’t know what a “measure” is, doesn’t know when one is at risk, and doesn’t preserve history unless a person remembers to make it do so, every time, without exception.
What closing the gap actually looks like
Closing these gaps doesn’t mean adding more oversight meetings. It means moving aRMM and risk mitigation measure tracking into a system where ownership, status, dependencies between measures, and audit history are structural, not something a person has to reconstruct or reconcile by hand. That’s the difference between a tracker you have to trust and a system you can verify.
This is the specific problem Orbit’s risk mitigation measure tracking is built to solve: a single place to see which measures are on track, which are drifting, who owns each one right now, and a defensible history of every change, without a parallel manual process running underneath it to keep that view honest.
You’re passionate about patient safety, not spreadsheets. aRMM and risk mitigation measure implementation shouldn’t be the thing standing between those two.