[ ENTERPRISE PILLAR 16 ]

EHS, Biosafety, Sustainability & Physical Security

Protect people, communities, controlled materials, facilities, and continuity while managing environmental and physical operating boundaries.

What this pillar does not claim

This pillar covers non-product safety and stewardship that materially affects regulated operation; product safety belongs to the safety-surveillance pillar.

The capability framing below, its failure modes and the boundary with neighbouring pillars are SPEQ’s practitioner reading — not a regulatory requirement, and not an assessment of any organization.

THE CAPABILITY

What this capability is

This is the stewardship that has to hold while regulated production continues: the protection of workers, neighbours, biological and hazardous materials, the site itself and the community around it. It is not product safety, which is a separate obligation with its own reporting duties and its own owner. What distinguishes this capability is where its authority comes from. Its obligations arrive from an entirely separate body of law — occupational, environmental, controlled-materials, security — administered by different agencies, enforced by different inspectors on different cycles, and granting permits and licences that have nothing to do with marketing authorization. And yet that separate legal system is applied to the same building, the same air handling, the same people, the same contractors and the same two-week shutdown window as the regulated operation. So the capability is best understood not as a parallel management system but as the second set of claims on one physical plant: every barrier, gown, airlock, drain, badge reader and permit is doing work for two authorities at once, and the organization has to be able to explain each of them to an inspector who does not accept reasoning from the other as a defence.

Why it is hard

The same physical measure routinely serves two obligations that point in opposite directions, and neither authority is obliged to care about the other. Containment protects the operator by drawing air inward; product protection pushes it outward, and a room can only do one. Garments that shield a person from a potent compound are a particle source aimed at what is being made. A solvent vent that satisfies an emissions limit and a pressure cascade that protects a filling line are two decisions about one column of air, argued in different units by people who report to different directors. That means almost nothing here can be optimised alone: each control is a negotiated position with a control somebody else owns, and both positions are separately auditable. The change machinery does not converge either. A permit amendment and a regulated change record describe the same modification in two vocabularies on two approval clocks, so a project has to satisfy the slower of them without letting the faster one proceed on its own. And the loading is inverted against the calendar. The hours of greatest hazard are the hours when the regulated operation is suspended and its usual defences are down — the shutdown, the construction phase, the breach response, the evacuation — so this capability carries its heaviest demand at exactly the moments when the systems that normally contain risk have been deliberately switched off.

How it fails

Each of these happens with the individual branches below being run competently. That is what makes them capability failures rather than performance problems.

One change, two rulebooks, and whoever is in the room

A modification is assessed thoroughly against the hazard case and never against product impact, or the reverse. Neither function is weak; the defect is that no single assessment asks both questions, and the person raising the change belongs to one of the two communities and reaches instinctively for its form. It surfaces later as a surprise in the other domain, usually during a qualification or an inspection.

Emergency response optimises only for the emergency

During a fire, a spill or an evacuation the correct action for human life can break containment, open a controlled area, abandon in-process material or leave a cold chain unattended. Plans that are rigorous about getting people out are frequently silent about what the operation is holding afterwards, and the reconstruction is then improvised under time pressure by whoever is still on site.

The shutdown is the least controlled fortnight of the year

Contractors arrive in numbers, systems are de-energised, permits stack up, simultaneous activities run in shared space, and handback rests on an assumption that everything returns as it was. A large share of what goes wrong across a whole year is initiated in the short window when the plant is not running and the routine controls are the ones that have been taken out of service.

Resource commitments are set above the level that knows the limits

A target to cut water, solvent or energy use, or to change a refrigerant or a packaging material, is announced as a commitment rather than proposed as a change. It reaches the site as a number to hit, with a date, and the assessment of what it does to validated operating ranges, cleaning cycles or material compatibility happens afterwards if at all.

WHERE THIS STOPS

Ours or theirs

The dividing line against product safety is the direction of harm: harm to people, communities, materials and the environment sits here, harm reaching a patient through the product belongs to the surveillance capability and carries reporting duties this one does not. The seam is more argumentative than that sounds, because a single event can do both. A containment breach that exposes an operator and jeopardises a batch generates two investigations under two clocks with two acceptance criteria, and the practical resolution is that both records exist and are cross-referenced rather than one being folded into the other — the failure is a single investigation written in whichever language the first responder spoke. Against engineering the split is specification versus asset: this capability defines the hazard and the protection it demands, engineering owns and maintains the equipment that delivers it, and the recurring argument is who holds the testing and maintenance of a safety-critical device that nobody wants to own on a Friday. Against security the argument is the badge. Physical access to a site is stewardship, logical access is a cybersecurity obligation, and an access-control system is undividedly both — the seam runs through a single database, and the only workable answer is one joined view of who can reach what, agreed rather than assumed.

Questions practitioners ask

Is a facility hazard assessment the same exercise as a product risk assessment?

No, though they often examine the same equipment and sometimes credit the same control. They ask different questions with different acceptance criteria and different authorities behind them. Treating one as evidence for the other is how a change gets approved on a hazard rationale that was never tested against product impact, or accepted on a product rationale that never considered the operator.

Where does physical security stop and cybersecurity start?

Nowhere clean, and pretending otherwise is the problem. Doors, cabinets and restricted areas are stewardship; accounts, networks and industrial control systems are cybersecurity. But badge systems, camera estates and door controllers are networked assets holding personal data, and a server room door is simultaneously the last physical barrier and the first logical one, so the two functions need a shared register rather than a boundary.

Does sustainability really belong in a regulated capability at all?

Only where a resource, material or emissions decision touches something that was qualified, validated or claimed. Reducing water or energy in a utility that feeds a process, substituting a solvent, changing a packaging material or altering a cleaning cycle are all regulated changes wearing a sustainability label. The reporting and target setting around them are a corporate obligation and sit outside this frame.

Who owns an incident that is both a safety event and a quality deviation?

Both, deliberately. Each system opens its own record because each has an authority, a timeline and an acceptance criterion the other cannot satisfy, and the two are linked so neither closes on the strength of the other. The practical requirement is a single agreed factual account underneath them, so the two investigations do not diverge on what actually happened.

CAPABILITY BRANCH MAP

What this pillar contains

01

EHS governance & management systems

The management system for environment, health and safety: policy, accountability, legal registers, objectives, risk assessment, permits, assurance, metrics and improvement.

EHS obligations are legal duties enforced by different authorities on different timescales from GxP, and a site can be fully GMP-compliant while operating an unpermitted discharge. The two systems share rooms and people, so they need one view of the site rather than two.

HOW IT FAILS

  • Legal registers are maintained centrally and drift from what the site actually does after a process change.
  • EHS and quality run separate change processes, so a change assessed for product impact is never assessed for exposure or emissions.
  • Leading indicators are absent, so performance is judged by incident count, which only reports failure after it happens.

WHAT CONTAINS IT

  • A legal and permit register reconciled against actual operations, refreshed on process change.
  • A single change assessment that asks the EHS question alongside the GMP one.
  • Leading indicators — observations, near misses, control verification — reported alongside incidents.

EVIDENCE IT OPERATES

  • Legal and permit register with reconciliation records.
  • Change records showing combined EHS and quality assessment.
  • EHS performance reporting including leading indicators.
02

Occupational safety & human health

Protecting the people doing the work: hazard identification, control hierarchy, exposure assessment, ergonomics, protective equipment, permits to work, contractor safety, incidents and medical surveillance.

In regulated manufacturing, personal protection and product protection are the same gowning decision made for two reasons, and they can conflict. Resolving that conflict by procedure rather than by design leaves the operator to choose between two compliance obligations.

HOW IT FAILS

  • Protective equipment is selected for product protection and assumed adequate for operator exposure, or the reverse.
  • Ergonomic risk in aseptic and cleanroom work is unassessed because the environment is clean and therefore assumed safe.
  • Contractors work under permits issued by a function unaware of the GMP status of the area they enter.

WHAT CONTAINS IT

  • Protection assessed against both exposure and contamination requirements, with conflicts resolved in design.
  • Ergonomic assessment of constrained work including gowned and barrier operations.
  • Permit-to-work integrated with area GMP status and release requirements after the work.

EVIDENCE IT OPERATES

  • Exposure assessments and protective equipment selection rationale.
  • Ergonomic assessments for constrained and repetitive tasks.
  • Permits to work with area status and post-work release records.
03

Process safety & hazardous operations

Preventing low-frequency, high-consequence events: hazard studies, safeguards, management of change, mechanical integrity, emergency systems and learning from incidents and near misses.

Process safety failures are rare and catastrophic, and the leading indicators are ordinary — deferred maintenance on safety-critical equipment, bypassed interlocks, changes assessed for product and not for hazard. Occupational safety metrics do not detect them.

HOW IT FAILS

  • Process safety performance is judged by personal injury rates, which are uncorrelated with major-accident risk.
  • Management of change assesses product impact and omits the hazard study assumptions the change invalidates.
  • Safety-critical equipment enters the same maintenance backlog as everything else, with no distinct priority.

WHAT CONTAINS IT

  • Process safety indicators distinct from occupational ones — safeguard availability, overdue inspections, bypass duration.
  • Change assessment that revisits hazard study assumptions, not only product quality impact.
  • Safety-critical equipment identified and protected from routine maintenance deferral.

EVIDENCE IT OPERATES

  • Hazard studies with actions tracked to closure.
  • Change records including hazard-assumption reassessment.
  • Safety-critical equipment register with inspection and deferral status.
04

Biosafety, biosecurity & biological containment

Working safely with biological material: risk-group assignment, containment level, access control, handling practice, decontamination, inventory, transport and incident response.

Containment protects people and environment from the product while cleanroom design protects the product from people, and the two impose opposite pressure regimes. Where a facility must do both, the resolution has to be designed rather than proceduralised.

HOW IT FAILS

  • Containment and cleanliness requirements conflict in the same room and are reconciled by an operating procedure rather than by engineering.
  • Biological inventory is tracked by the laboratory holding it, with no site-level view of what exists and where.
  • Decontamination efficacy is validated once against a surrogate and never re-verified for new agents introduced later.

WHAT CONTAINS IT

  • Combined containment and cleanliness design with the pressure regime resolved and justified.
  • A site-level biological inventory with access control and accountability per holding.
  • Decontamination efficacy re-verified when the agent inventory changes.

EVIDENCE IT OPERATES

  • Containment risk assessments and facility design justification.
  • Biological inventory with access and accountability records.
  • Decontamination validation and re-verification records.
05

Potent compounds, radiation & specialized hazards

Specialised hazards: highly potent compounds, radiation sources, their containment, occupational exposure limits, monitoring, licensing, shielding, contamination control and waste.

Potent-compound handling is where operator protection and cross-contamination control converge on the same containment. The health-based limits that drive cleaning validation come from the same toxicological work that sets the occupational exposure limit — one assessment, two obligations.

HOW IT FAILS

  • Occupational exposure limits and health-based cleaning limits are derived separately, producing inconsistent toxicological positions.
  • Containment performance is verified at commissioning and never re-tested as seals and gaskets age.
  • Radiation source licensing and inventory are held by an individual rather than by a controlled process.

WHAT CONTAINS IT

  • A single toxicological assessment informing both occupational exposure and cleaning limits.
  • Periodic containment performance verification, not one-time qualification.
  • Licensed source inventory under formal control with named accountability and audit.

EVIDENCE IT OPERATES

  • Toxicological assessments underpinning both exposure and residue limits.
  • Containment performance verification records over time.
  • Source licences, inventory and disposal records.
06

Environmental compliance & permits

Environmental compliance: air, water and wastewater, waste, chemical registration, reporting, monitoring, permitted limits and the corrective action when one is exceeded.

Environmental permits are operating licences with numeric limits and reporting duties. A permit breach can stop production as effectively as a quality event, and pharmaceutical effluent carries specific scrutiny for active compounds and antimicrobial resistance.

HOW IT FAILS

  • Permit limits are set on a process configuration that has since changed, and the permit was never varied.
  • Effluent monitoring covers conventional parameters and not the active compounds the site actually handles.
  • Waste is characterised at first generation and never re-characterised when the process changes.

WHAT CONTAINS IT

  • Permit conditions reconciled against current operations, with variation applied for before change.
  • Monitoring scope covering the compounds actually processed, including actives.
  • Waste re-characterisation triggered by process or material change.

EVIDENCE IT OPERATES

  • Permits with conditions mapped to current operations.
  • Monitoring data against permitted limits, including active compounds.
  • Waste characterisation and disposal records with change triggers.
07

Sustainability, energy, water & resources

Resource intensity and stewardship: energy, water, emissions, the waste hierarchy, design choices, resilience to resource constraint, and the accuracy of any public claim made about it.

Sustainability changes regulated operations directly — single-use versus stainless, solvent recovery, HVAC reduction — and each change is a GMP change. Public claims are also increasingly regulated in their own right, so an unsupported one is a compliance exposure rather than a marketing one.

HOW IT FAILS

  • Energy reduction is applied to HVAC without assessing the pressure cascade and recovery time the cleanroom classification depends on.
  • Single-use versus stainless decisions are made on carbon footprint alone, omitting extractables, supply resilience and validation burden.
  • Public claims outrun the evidence, creating a claim the organisation cannot substantiate on request.

WHAT CONTAINS IT

  • Efficiency changes to classified areas assessed as GMP changes with qualification impact.
  • Material and technology decisions assessed across quality, supply and environmental dimensions together.
  • Public claims held to the same evidence standard as regulatory statements, with substantiation retained.

EVIDENCE IT OPERATES

  • Change records for efficiency measures affecting classified areas.
  • Technology assessments covering quality, supply and environmental factors.
  • Substantiation files for published environmental claims.
08

Physical security & site protection

Protecting the site physically: perimeters, access control, visitor management, critical-area restriction, material security, insider risk, surveillance and response.

Physical access is the ultimate control over product and records — someone in the room can defeat most logical controls. It also carries specific legal obligations for controlled substances, where security and recordkeeping are federally prescribed rather than risk-based.

HOW IT FAILS

  • Access is granted by area rather than by need, so a badge that opens one classified area opens all of them.
  • Visitor escort is procedural with no verification, and contractors move unescorted once familiar.
  • Controlled-substance security is treated as a site security matter rather than as the specific regulatory requirement it is.

WHAT CONTAINS IT

  • Access granted by demonstrated need per area, with periodic review and prompt revocation.
  • Visitor and contractor escort verified rather than assumed, with access logged and reviewed.
  • Controlled-substance storage, access and recordkeeping to the prescribed requirement, audited separately.

EVIDENCE IT OPERATES

  • Access control matrices with periodic review and revocation records.
  • Visitor and contractor access logs with escort verification.
  • Controlled-substance security, inventory and recordkeeping records.
09

Emergency management & crisis response

Responding when something goes badly wrong: scenario planning, command structure, communications, evacuation, mutual aid, continuity of critical operations, exercises and recovery.

Emergency response protects people first, and in regulated operations it also determines what happens to product and records in the process. An evacuation that abandons a batch mid-process creates a quality decision that is far easier to make if it was anticipated.

HOW IT FAILS

  • Plans cover evacuation and omit the product, sample and record consequences of an abrupt stop.
  • Exercises test the alarm and assembly and never test decision-making under partial information.
  • Recovery restores operations without a quality assessment of what the interruption did to in-process material.

WHAT CONTAINS IT

  • Response plans including product, sample and record actions for an abrupt stop.
  • Exercises that test decisions and communication, not only evacuation mechanics.
  • A defined quality assessment and release decision before resuming after an emergency stop.

EVIDENCE IT OPERATES

  • Emergency plans covering product and record consequences.
  • Exercise records including decision-making scenarios and findings.
  • Post-incident quality assessments and return-to-operation decisions.
10

Construction, shutdown & contractor safety

Safety when building inside an operating site: site controls, permits, simultaneous operations, isolations, hazards introduced by commissioning, contractor management and handover.

Construction next to production is where EHS and GMP risk are most tightly coupled. The same activity that endangers a worker — a breached wall, an isolation, hot work — is also the one that threatens the contamination-control strategy of the area beside it.

HOW IT FAILS

  • Simultaneous operations are managed for worker safety with no assessment of contamination risk to adjacent production.
  • Isolations are applied to utilities shared with operating areas without confirming the downstream effect.
  • Handover transfers the asset without transferring the temporary controls still in place around it.

WHAT CONTAINS IT

  • Simultaneous-operations assessment covering both worker safety and adjacent-area contamination control.
  • Isolation planning verified against the full downstream dependency of shared utilities.
  • Handover including an explicit register of temporary controls and their removal.

EVIDENCE IT OPERATES

  • Simultaneous-operations risk assessments with quality input.
  • Isolation certificates with downstream dependency verification.
  • Handover records including temporary control closure.

Why it matters in regulated work

  • Worker, process, biological, radiation, environmental, and physical hazards intersect with product and facility controls.
  • Construction, emergency response, and restricted access can affect contamination, continuity, and evidence.
  • Sustainability decisions must preserve product quality and validated operating limits.

Principal failure modes

  • Hazards are assessed in isolation from process and product risk
  • Emergency action protects one objective while compromising another
  • Physical access, waste, utilities, or environmental change escapes control

Control objectives

  • Identify and control occupational, process, biological, environmental, and physical hazards
  • Coordinate emergency command, continuity, containment, and communication
  • Govern resource and sustainability change through regulated impact assessment

Evidence families

  • Hazard analyses, permits, exposure, biosafety, and security assessments
  • Access, inspection, monitoring, incident, emergency, and drill records
  • Waste, utilities, emissions, resource, change, and continuity evidence

CONNECTED OPERATING MODEL

Where this capability connects

Lifecycle reach

  • Research & Discovery
  • Nonclinical Development
  • Clinical Development
  • Technology Transfer
  • Process Development & Characterisation
  • Commissioning & Qualification
  • Validation
  • Commercial Manufacturing
  • Laboratory Control
  • Packaging & Serialisation
  • Storage & Distribution
  • Post-Market Surveillance
  • Discontinuation & Record Retention

Quality capabilities

  • Quality Risk Management
  • Change Control
  • Deviation & Investigation Management
  • CAPA
  • Supplier Quality
  • Training & Qualification
  • Audit & Inspection Management

System classes

  • ERP & Warehouse Management
  • Historians, SCADA & PLC
  • eQMS

Roles to start with

  • CQV Engineer
  • Manufacturing Operator
  • Sterility Assurance Specialist

MATURITY ORIENTATION · SPEQ SYNTHESIS

What stronger operation looks like

  1. 01ReactiveOwnership and evidence are reconstructed after events; controls depend on individuals.
  2. 02DefinedScope, roles, methods, records, and escalation are documented for routine use.
  3. 03ControlledCritical controls are risk-based, verified, monitored, and governed through change.
  4. 04PredictiveLeading signals connect performance, drift, capacity, risk, and intervention.
  5. 05AdaptiveLearning improves the operating model without weakening accountability or evidence.

HIGH-VALUE INTERSECTIONS

SOURCE BASIS

REGULATORY BASIS

What governs this capability

The 8 standards SPEQ maps to this pillar, and the 6 regulatory bodies behind them. Which standards belong to a pillar is a SPEQ judgement; the bodies, disciplines and industries below are read from the standards themselves.

DISCIPLINES

BODIES

DEA · EMA · EPA · FDA · ISO · USP

Also reached through the systems this pillar runs on

These 18 standards govern the system classes this pillar depends on rather than the pillar itself. The distinction matters: a standard that governs a system is not thereby a standard of every capability that uses it.

21 CFR Part 2112013/C 343/01WHO TRS 957, Annex 5MHRA GDPDSCSA (FD&C Act §§581–585)21 CFR Part 11EU GMP Annex 11ISPE GAMP 5 (2022)ASTM E2500ISPE Baseline Guide Vol. 5 (2019)EU GMP Annex 15MHRA GxP DI (2018)PIC/S PI 041-1ICH Q10ICH Q9(R1)21 CFR Part 820ISO 13485:2016ISO 9001:2015

PROFESSIONAL · READINESS ORIENTATION

Turn the pillar into a bounded operating conversation.

Rate observable operation from 0 (not established) to 4 (adaptive). The protected output prioritizes operating dimensions and evidence—not a compliance score.