From concept to commercial release — with quality built in at every gate.
How regulated projects actually get delivered — the lifecycle from concept through design, construction, commissioning & qualification, and validation to commercial release, with quality built in at every gate rather than inspected in at the end.
Project-management bodies teach delivery without regulatory context; regulators publish requirements without delivery methodology. SPEQ bridges the two — this page is the operating view of the framework’s Execution Methodology layer.
7 phases. One thread of quality.
The regulated-project arc from first concept to commercial supply — what happens in each phase, what quality owns there, and the deliverables that become the inspection record. A SPEQ synthesis of the delivery methods and GxP guidance on the shelf below.
Concept & feasibility
The business case, product and capacity requirements, and the regulatory strategy are framed. Decisions made here — technology selection, site, contracting model — set the compliance burden for everything downstream.
A seat at the table from day one: regulatory-strategy input, early user requirements, and the quality criteria the project will be judged against.
- ›Business case & project charter
- ›Initial user requirements (URS) outline
- ›Regulatory strategy memo
- ›Quality project plan (first issue)
Design & engineering
Requirements become specifications. Under ASTM E2500 thinking, design review and design qualification happen here — quality risk management decides which design elements are critical to product quality and patient safety.
Quality-by-design input: URS approval, critical aspects & critical design elements identification, and risk assessments that will drive verification scope.
- ›User requirements specification (URS)
- ›Functional & design specifications
- ›System-level impact / criticality assessments
- ›Design review & design qualification records
Construction & build
Facilities, utilities, equipment, and systems are built or configured. Good Engineering Practice governs the work; vendor documentation, FATs, and installation records become the evidence base later verification will leverage.
Oversight of GEP execution: vendor and supplier quality, FAT/SAT witness points, and the document trail that lets C&Q leverage vendor testing instead of repeating it.
- ›Construction turnover packages
- ›Factory / site acceptance test (FAT/SAT) records
- ›Installation records & red-lines
- ›Vendor documentation packages
Commissioning & qualification
Systems are verified fit for intended use. Risk-based C&Q per ASTM E2500 and ISPE Baseline Guide Vol. 5 scales the verification effort to product-quality impact — direct-impact systems get qualification rigor, the rest get good commissioning.
The acceptance and release decision: approving C&Q strategy, reviewing verification against pre-defined acceptance criteria, and releasing systems for GMP use.
- ›C&Q plan / verification strategy
- ›Commissioning & qualification protocols and reports (IQ/OQ or verification equivalents)
- ›Discrepancy & punch-list resolution
- ›System release / handover certificates
Process validation & PPQ
The process itself is proven. Stage 1 process design carries into Stage 2 process performance qualification on the new asset, with computerised systems validated under GAMP 5 alongside.
Protocol approval, batch disposition during PPQ, and the judgement that the process is in a state of control before commercial supply.
- ›Process validation master plan
- ›PPQ protocols & reports
- ›Computerised system validation packages (GAMP 5)
- ›Cleaning validation & environmental monitoring baselines
Regulatory & inspection readiness
The evidence is assembled for the market: submission sections drawn from project deliverables, and the site prepared for pre-approval or pre-license inspection where one applies.
Inspection readiness end-to-end: the story of the project told through its documentation, mock inspections, and the data-integrity of every record the inspector will pull.
- ›Submission-supporting documentation
- ›Inspection-readiness assessments & mock audits
- ›Quality system integration (deviations, CAPA, change control live on the new asset)
Commercial release & handover
The project dissolves into operations. Ongoing monitoring, periodic review, and continued process verification take over — and the lessons learned feed the next project’s concept phase.
The handover gate: confirming operational readiness, closing project quality actions, and standing up continued process verification and periodic review.
- ›Project closure & lessons-learned report
- ›Continued process verification (Stage 3) plan
- ›Operational SOPs & training completion
- ›Asset lifecycle & maintenance plans
The lifecycle framing and phase narratives are a SPEQ synthesis — a practitioner on-ramp, not any single body’s method.
18deliverables. Who owns each, and why it’s a record.
The regulated deliverables across all 7 phases, with a RACI-style ownership call and the regulatory reason each one is an inspectable record — not disposable project paperwork. Ownership is a SPEQ synthesis.
Two control systems, one project.
Every regulated project runs a project-management control system and a quality control system side by side. The failures live in the seams — these four are where they meet.
Stage gates ↔ quality gates
PM methods govern progression with stage gates: a project may not proceed until scope, cost, and schedule criteria are met and sponsors sign off.
GxP governs progression with quality gates: a system may not be used, and a process may not supply the market, until pre-defined acceptance criteria are met and quality approves.
Project risk ↔ quality risk (ICH Q9)
PM risk management protects the project: schedule, cost, resource, and delivery risks, logged in a register and owned by the PM.
ICH Q9(R1) risk management protects the patient: risk to product quality drives the scope of design review, verification, and validation.
Change management ↔ change control
PM change management protects the baseline: scope changes are assessed for cost and schedule impact and approved by the sponsor.
GxP change control protects the validated state: changes to specifications, systems, and processes are assessed for quality impact and approved by quality.
Project documentation ↔ GxP documentation
PM documentation exists to manage the work: plans, schedules, registers, minutes — disposable once the project closes.
GxP documentation IS the deliverable: URS, protocols, reports, and records are the evidence of fitness for use, retained for the asset’s life and inspectable at any time.
The references worth owning.
Layer them: a general delivery method, the pharma-specific integration guide, the risk-based C&Q pair, the computerised-system method, and the quality-risk backbone.
External references maintained by their respective bodies; identifiers verified before publish. SPEQ curates the shelf and does not publish or certify against them.
A tool and templates for the seams.
Score a project against its quality gates, then document how quality is built in — a Project Quality Plan for the whole project and a Stage-Gate Quality Review record for each phase boundary.
Templates are documented in full; downloads are in preparation. The readiness tool is a planning aid, not a release decision.
Regulated delivery, in plain terms.
How is project management different on a regulated project?
The mechanics are the same — scope, schedule, cost, risk — but a second acceptance authority sits alongside the sponsor: the quality unit. Systems and processes are not “done” when they are built and handed over; they are done when verification against pre-defined acceptance criteria shows them fit for intended use, and the documentation proving it is itself a regulated deliverable. Delivery methods like PMBOK or PRINCE2 still apply, but their gates, risk registers, and change processes must be fused with quality gates, ICH Q9 risk management, and GxP change control.
Which frameworks actually apply to regulated project delivery?
Layer them: a general delivery method (PMI’s PMBOK Guide or PRINCE2) for how the project runs; ISPE’s Good Practice Guide on Project Management for how GxP integrates with the project life cycle; ASTM E2500 and ISPE Baseline Guide Vol. 5 for risk-based commissioning & qualification; GAMP 5 for the computerised-system slice; and ICH Q9(R1) for the quality-risk thread that runs through all of it.
When should quality get involved in a project?
At concept — before the URS exists. The most expensive quality problems are decisions made without quality in the room: technology selections that cannot be cleaned or validated, layouts that fight contamination control, and contracts that leave vendor documentation unusable for verification. Quality involvement from day one is cheaper than qualification heroics at the end.
What is the single most common failure mode in regulated projects?
Treating quality as a phase instead of a thread — deferring “the validation part” to the end. It surfaces as design decisions that verification cannot rescue, field changes that bypassed change control, and a documentation retrofit under schedule pressure. The fix is structural: quality criteria inside every stage gate, and GxP deliverables tracked on the same plan as engineering ones.
Put the methodology to work.
Scope your next system’s verification with the C&Q planner, or see how the delivery layer fits the full SPEQ operating model.