Cleaning Validation × Quality Risk Management
Health-based exposure limits turned cleaning limits from inherited rules into toxicological claims — which makes cleaning validation an exercise in quality risk management, from the limit itself to the decision to share a facility at all.
What this page does not claim
An intersection covers what happens only where two axes overlap. It does not restate what either parent page says, and it is not a substitute for reading them.
WHAT ONLY EXISTS IN THE OVERLAP
- The limit itself became a risk output. A MACO derived from a health-based exposure limit is a toxicological claim about patient exposure, not an inherited convention — and a claim needs qualified derivation, data provenance, and periodic review, which is QRM machinery, not cleaning machinery.
- The biggest risk decision sits upstream of any protocol: whether a product may share a facility at all. Modern expectations route that decision through health-based assessment — the cleaning validation programme exists inside the answer, not the other way around.
- Worst-case selection is a risk argument that must survive challenge. Hardest-to-clean and most-hazardous are different axes, and a grouping justified by habit collapses the moment a new product enters the matrix.
- ICH Q9(R1)'s formality principle lands precisely here: a shared multiproduct facility handling potent compounds warrants the full apparatus, a dedicated single-product line does not — and stating that proportionality explicitly is what makes both positions defensible.
- The risk assessment does not end at the validation report. New products, new equipment, and changed procedures re-open the carryover mathematics — cleaning validation under QRM is a standing calculation, not a completed study.
From inherited numbers to toxicological claims
For decades, cleaning acceptance limits rested on conventions everyone used and no one could defend from first principles: a thousandth of the minimum therapeutic dose, ten parts per million in the next product, visually clean. They were reasonable engineering heuristics with no derivation from patient risk — the same number governed a mild antacid and a potent cytotoxic. The health-based exposure limit approach replaced the convention with a claim: a permitted daily exposure derived from the compound's own toxicological data — the no-effect level, adjusted by uncertainty factors reflecting the quality and relevance of the evidence — from which the maximum allowable carryover follows through batch sizes, shared surface areas, and dosing of the next product. EU GMP Annex 15 anchors this in regulation: carryover limits are to rest on a toxicological evaluation, not on custom.
The consequence is a change in the limit's epistemic status, and that is the intersection. A convention needs no owner; a claim does. Someone qualified derived this PDE from these studies on this date; the derivation has provenance, documented assumptions, and a review trigger when new toxicological data appears. Risk management also governs the seam between old and new practice: where a legacy criterion happens to be tighter than the health-based limit, many sites deliberately retain the tighter number as their operating alert — the HBEL defines the boundary of patient safety, not necessarily the level a capable process should run at, and conflating the two directions wastes either protection or capability.
The facility question comes first
The most consequential risk decision in this overlap is made before any swab is taken: may this product share equipment with the others, or does its hazard demand dedication? The modern architecture answers through health-based assessment — the toxicological evaluation determines whether organisational and technical controls can manage carryover risk in shared equipment, and certain hazard profiles, such as highly sensitising materials, push the answer to dedicated facilities outright. Everything about the cleaning validation programme then lives inside that answer: its rigour, its monitoring intensity, and its margin of safety are calibrated to the residual risk the sharing decision accepted. Reading the cleaning study as the primary control inverts the logic — it is one control inside a risk decision, not the decision itself.
Because the decision is portfolio-dependent, it cannot be static. Every product introduced to a shared train changes the worst-case landscape: a new most-toxic compound resets the carryover mathematics for every product that follows it through the equipment; a new campaign pattern changes dirty-hold assumptions; a new dosage form changes which surfaces matter. ICH Q7 carries the same logic into API manufacture, where campaign production and shared trains are the norm and carryover expectations are framed accordingly. The mature form of the intersection is a shared-facility risk assessment maintained as a living document with the product portfolio as an explicit input — so that "can we make this here?" is answered by re-running an existing assessment, not by convening an improvised one.
Worst case is an argument, not a habit
Grouping and bracketing — validating the hardest case and claiming coverage for the rest — is legitimate exactly to the extent that it is a risk argument. The argument has to hold on multiple axes at once, because they do not coincide: the hardest compound to clean is a matter of solubility, formulation behaviour, and equipment geometry; the most dangerous residue is a matter of the PDE; and the most demanding detection problem is a matter of recovery factors from each surface material. A worst case selected on cleanability alone can leave the most hazardous compound's carryover unexamined, and vice versa. The defensible matrix shows its reasoning per axis — and shows that sampling locations follow the risk, targeting the surfaces and geometries where residue actually persists rather than the ones easiest to swab.
ICH Q9(R1) speaks to this exercise with unusual precision. Its proportionality principle licenses restraint — the depth of the assessment should match the hazard and complexity, so a low-toxicity portfolio on a simple train does not need the apparatus a potent-compound facility does — but the revision's warning about subjectivity cuts the other way. Scoring matrices that launder judgement into arithmetic are nowhere more tempting than in worst-case selection, where a plausible-looking risk-priority number can dress an arbitrary choice in objectivity. The antidote the guideline points toward is data over scores wherever data is obtainable: cleanability studies, historical swab results, and solubility measurements outrank a workshop's consensus integers, and the assessment should record which of the two it is actually standing on.
A standing calculation
Under the lifecycle thinking of ICH Q10, a completed cleaning validation is the beginning of a maintenance obligation, not the end of a project. The validated state is held by ongoing verification proportionate to risk: periodic sampling where the assessment says residue risk concentrates, trending of results against alert levels so that a capable process's drift is seen long before a limit is threatened, and disciplined use of visual inspection — which functions as a documented control only where the site has established what residue quantity is actually visible on each surface under its inspection conditions, tying the visible-clean claim back to the health-based limit rather than to optimism.
Change is what makes the calculation standing rather than archival. A new product on the shared train re-runs the carryover matrix; a new cleaning agent changes both efficacy and its own residue question; a longer campaign changes the dirty-hold basis; a replacement gasket in a different elastomer changes a recovery factor. The mature signature is structural: the MACO matrix lives under change control with its triggers enumerated, so each of these events mechanically re-opens the mathematics — and the re-assessment is documented even when its conclusion is that nothing changes. The immature signature is equally recognisable: a validation report from years ago, a product portfolio it has never met, and a facility relying on the report's age as if it were evidence of robustness.
Derived from the 4 standards SPEQ maps to this intersection, across 2 regulatory bodies: EMA, ICH.
FREQUENTLY ASKED
Are the traditional 10 ppm and 1/1000-dose criteria still acceptable?
Not as the scientific basis of the limit — the basis is now the health-based exposure limit, derived from the compound's toxicological data, and Annex 15 expects carryover limits to rest on exactly that evaluation. The traditional numbers still appear in practice for a defensible reason: where a legacy criterion is tighter than the HBEL-derived limit, sites often retain it as the operating alert level, since a capable cleaning process should not run anywhere near the safety boundary. What is no longer defensible is the old logic in either direction — citing a convention as if it were a safety derivation, or relaxing to the HBEL ceiling simply because the toxicology would technically allow it.
Does every product need a formally derived PDE?
Every product sharing equipment needs a health-based evaluation; the formality of the derivation should be proportionate to the hazard, which is precisely ICH Q9(R1)'s point. Potent, cytotoxic, sensitising, or data-rich compounds warrant a full monograph-quality PDE derived by a qualified toxicologist with documented provenance. Well-characterised low-hazard materials can carry a more streamlined evaluation — provided the proportionality decision is itself recorded, because an undocumented shortcut and a justified one look identical until an inspector asks. The non-negotiable core is ownership and review: someone qualified stands behind each limit, and new toxicological knowledge triggers re-derivation rather than waiting for the next scheduled revalidation.
When does introducing a new product trigger cleaning revalidation?
The honest answer is that the introduction always triggers the assessment, and the assessment decides whether it triggers new validation work. A new product enters the matrix on every axis at once: its PDE may reset the maximum allowable carryover for products that follow it through the train, its formulation may displace the current hardest-to-clean worst case, and its own susceptibility as a "next product" may tighten limits for everything cleaned before it. If the existing worst case still bounds it on every axis, the documented conclusion may be that current validation covers it. What is indefensible is the silent version — a product added to a shared train with the carryover mathematics never re-run, leaving the validation formally intact and factually obsolete.
Is visual inspection an acceptable cleaning control?
As a component of the control strategy, yes; as an unquantified substitute for one, no. Visual inspection earns its place when the site has established visible-residue thresholds for its actual compounds on its actual surfaces under its actual lighting and viewing conditions — demonstrating what quantity per area is reliably seen, and confirming that this detection capability is meaningful against the health-based limit. Where that work exists, visually clean becomes a documented, trainable check with known sensitivity, and in some low-risk situations a substantial part of routine verification. Where it does not, "visually clean" is a hope with a signature — the phrase carries no analytical content until the capability behind it has been measured.