Validation & Qualification
Documented evidence the process consistently makes conforming product — and the systems behind it.
What a domain score is not
A domain is one of the axes SPEQ’s assessment scores, on SPEQ’s own five-stage progression. It is a labelled synthesis, not the FDA’s Quality Management Maturity rating, and a score here is a self-assessment — nobody but you has rated your organization.
Validation is documented evidence that a process, operated in a defined range, consistently produces conforming product; qualification proves the facility, equipment, and computerised systems support it. Gaps here are patient-safety gaps, so they draw intense inspection scrutiny — and the modern expectation is a lifecycle, not a one-time three-batch event.
Maturity here is the move from validation as an event to validation as a state that has to be maintained. A low-maturity operation validates to get into production and then defends the package; a mature one treats the validated state as a live condition, assesses every change against it, and runs continued process verification that could actually detect drift. The second shift is scope: testing derived from the risk the system carries to product and patient, with the reasoning recorded, rather than everything tested to the same depth.
- Write acceptance criteria that can fail, each with a stated basis. A criterion derived from the observed result is a record of what happened, not a test.
- Define the revalidation triggers explicitly, and wire them into change control so a qualifying change cannot close without the assessment.
- Make continued process verification look at trends rather than at conformance. A process that is inside specification and moving is the case CPV exists to catch.
- Use supplier documentation where it is adequate and record why — repeating a vendor test under your own cover page consumes the effort that scoping was supposed to release.
The most informative signal is how many qualification protocols recorded a deviation. A package with none has either tested nothing capable of failing or been tidied, and both are legible to an inspector reading the acceptance criteria. Beyond that: the number of systems whose last requalification date has passed, and whether CPV output has ever triggered an action.
The observable behaviours that place a site at each level — what a practitioner or inspector would actually see — and the concrete move that carries it to the next.
- ·Processes run without documented qualification
- ·No control strategy links parameters to quality attributes
- ·Problems are discovered in product, not predicted
TO ADVANCE →Establish qualification protocols and a documented control strategy for the critical processes.
- ·Validation packages exist but are box-ticking, not understanding
- ·The control strategy is fixed at launch and never revisited
- ·Every system is validated to the same depth regardless of risk
TO ADVANCE →Adopt a risk- and science-based lifecycle (ICH Q8/Q9, ASTM E2500) so effort follows impact.
- ·Verification effort is visibly proportionate to risk
- ·A living control strategy links CQAs → CPPs → controls
- ·Qualification leverages vendor evidence where justified
TO ADVANCE →Instrument the process — trend Cpk and CPV so drift is seen before a batch fails.
- ·Cpk and CPV trends are reviewed and drift is acted on proactively
- ·Deviations feed back into the control strategy under change control
- ·Statistical control, not spec-passing, is the language used
TO ADVANCE →Move toward continuous verification and real-time control where the economics and risk justify it.
- ·Continuous/real-time verification replaces periodic re-validation where fitting
- ·Process knowledge is deep enough to predict and prevent drift
- ·The control strategy evolves continuously with accrued knowledge
- A control strategy tracing critical quality attributes to critical process parameters and their controls
- Continued process verification (Stage 3) data with capability trending, not just batch pass/fail
- A risk-based validation rationale showing where rigour was applied and why (ASTM E2500 / CSA)
Want the specific artifacts that move your score up? The Comprehensive assessment turns your domain scores into a prioritised, personalised remediation plan.
The observable evidence a practitioner — or an inspector — would expect at each maturity level. Drawn from the assessment questions themselves.
How is your equipment and process validation program structured?
Validation performed on an ad hoc basis when required
Validation Master Plan exists; coverage is incomplete
Comprehensive VMP with defined scope, risk-based approach, and revalidation triggers
Lifecycle validation model per ICH Q8/Q9/Q10; continued process verification in place
Continuous process verification with PAT / real-time release; the validation lifecycle self-optimises against live process data
How are computer systems validated (CSV/CSA)?
No formal CSV program; systems used without validation
Critical systems validated; program lacks consistency and inventory
Risk-based CSV program with system inventory, validation plans, and periodic reviews
CSA approach aligned with ISPE GAMP5 (2022); data integrity controls documented and audited
Continuous assurance: automated risk-based testing, live data-integrity monitoring, and audit-by-exception across the system landscape
- ›Processes in routine commercial use without current, completed validation; no Continued Process Verification.
- ›Validation Master Plan absent or incomplete; revalidation triggers undefined.
- ›Computerised systems used without validation, or with audit trails disabled or never reviewed.
- ›Acceptance criteria set after the fact, or not justified by process understanding (ICH Q8).
Recent FDA recalls whose reason SPEQ maps to this domain — a SPEQ editorial interpretation of the recall reason, not an official FDA classification.