[ ENTERPRISE PILLAR 05 ]

Facilities, Engineering & Commissioning

Turn capital intent into safe, operable, maintainable assets whose requirements and turnover evidence support qualification and routine use.

What this pillar does not claim

This is the physical-asset delivery and stewardship pillar. Project lifecycle stages remain canonical and qualification decisions belong to the assurance pillar.

The capability framing below, its failure modes and the boundary with neighbouring pillars are SPEQ’s practitioner reading — not a regulatory requirement, and not an assessment of any organization.

THE CAPABILITY

What this capability is

Everything in this pillar serves one object: the physical plant, considered as a single thing that a product will experience. A batch does not meet a building, a utility system, a vessel and a maintenance history separately — it meets one environment, and the air, the water, the surfaces and the equipment either hold together or they do not. That is why capital argument, design, fabrication, construction, completion, startup, reliability and retirement sit inside one capability rather than in eight departments that meet at milestones. Read across, the pillar is a single custody chain for a physical claim: that this plant can do what the process needs it to do, under the conditions it will actually meet, for as long as the organization intends to run it. Every stage either carries that claim forward intact or silently drops part of it.

Why it is hard

The work is done by a temporary organization and inherited by a permanent one. A capital project assembles designers, vendors, contractors and startup specialists who demobilize the month after handover, and hands the result to people who were not in the room for a single decision they will live with for thirty years. What matters most is exactly what travels worst: why the drain sits where it does, what the transmitter range assumed, which vendor option was deselected and on what grounds. None of that is a deliverable, and the translation across that discontinuity has to happen at completion, when schedule pressure is at its peak and the people holding the reasoning are already costed onto another job. The second half of the difficulty is that the scoreboard is wrong on purpose. A project is judged weekly on a date and a number, both highly visible; the asset is judged for decades on maintainability, cleanability, working room and spare capacity, none of which appear on a schedule and all of which cost money now. And physical decisions are close to irreversible. A method can be revalidated, a procedure rewritten, a recipe re-parameterized; a wall, a floor gradient, a ceiling void and a service route are settled in the weeks when the least is known and then constrain operations until the building is emptied. Branch competence does not touch any of this: excellent design, excellent construction and excellent maintenance can each be delivered while the claim between them fails to transfer.

How it fails

Each of these happens with the individual branches below being run competently. That is what makes them capability failures rather than performance problems.

Custody transfers but understanding does not

The turnover package is delivered by volume — vendor manuals, as-built drawings, test packs, certificates, all present and all indexed. What is missing is the reasoning: the constraint that fixed the layout, the assumption behind a setpoint, the option that was rejected. The first real fault after startup is then diagnosed from first principles by people reconstructing decisions that were obvious to somebody two years ago.

The plant is complete but not operable

Everything was built to specification and the specification never asked whether a person could work there. The filter housing cannot be lifted without a scaffold, the sample point is unreachable in a gown, the valve checked every shift is behind a fixed panel. Operators invent workarounds in the first month, the workarounds become the real method, and nothing in the completion record shows that the plant is being run around rather than run.

Temporary conditions outlive the project that created them

Brownfield work is run as a small project with a large blast radius. Tie-ins into live systems need spools, jumpers, blanks and bypasses, each individually authorized and time-limited on paper. Nobody holds the aggregate. Two years later the temporary spool is a permanent feature, its removal task was closed against a system that has since been retired, and the person who knew it was temporary has moved sites.

The drawing set describes a plant that no longer exists

Field changes are redlined during construction and never fully back-fed; later modifications update the change record but not the master document. The divergence is met one job at a time, by a planner who scopes work against a drawing and a technician who finds a different pipe. Each instance reads as a small documentation error rather than as the systemic loss of an as-built baseline.

WHERE THIS STOPS

Ours or theirs

This pillar delivers and sustains physical capability; it does not decide what evidence about that capability a third party may rely on. The line with the assurance pillar is argued most often and most expensively, because engineering and qualification frequently run the same test twice under two names. What settles it is not the activity but the purpose and the standard of evidence: engineering tests to make the plant work and corrects it as it goes, so its records are working documents that change while the system is tuned; qualification tests to establish a claim that will be relied on later, so its records have to stand unchanged. Executing once and using the result twice is legitimate, and it is a decision to be taken deliberately in the project plan rather than discovered at the point of execution. Downstream, the asset passes to operations at a defined transfer of care, custody and control; after that the plant is maintained by this capability and run by manufacturing, which is why maintenance backlog disputes are usually arguments about who owns availability. The control system is the special case: the project buys it, installs it and proves it works, and the automation capability owns its configured state from the day it starts controlling product.

Questions practitioners ask

When does a project actually hand over the asset?

Handover is not one event, and treating it as one is the source of most startup confusion. Mechanical completion says the system is built; energization says it is safe to make live; care, custody and control says the operating organization now holds it; readiness says it can be used for its intended purpose. Each boundary has a different owner and a different list of open items, and a project that names only one of them leaves the other three to be settled by argument.

Is engineering testing wasted effort if qualification repeats it?

Not necessarily, but the repetition has to be a choice rather than a habit. Engineering testing and qualification testing serve different purposes and hold their records to different standards, so leveraging one for the other requires the test to have been planned, executed, reviewed and retained to the higher standard from the outset. Deciding that after the fact almost never works, which is why the leverage question belongs in the project plan.

Why do the same equipment faults keep recurring after a new plant starts up?

Usually because the failure sits in a design assumption rather than in a component. A pump that keeps cavitating, a seal that keeps failing, a filter that blinds early are all reporting a mismatch between the duty specified and the duty being run. Replacing the part treats the symptom; the fix is to reopen the requirement, which is uncomfortable because the requirement was signed off by a project that no longer exists.

What is worth keeping when a facility is retired?

More than a retention rule usually specifies. Product records carry their own obligations, but the durable value at decommissioning is asset knowledge — as-built information, materials of construction, the history of modifications and the reasons behind them — because equipment frequently moves to another site or is bought secondhand by somebody who inherits its history without knowing it. Retirement is also the last chance to capture what the site learned about running it.

CAPABILITY BRANCH MAP

What this pillar contains

01

Network, capacity & capital strategy

Deciding what capability the organisation needs, where, and whether to build it, buy it or contract it — including capacity, redundancy and how much resilience the network carries against a site being lost.

These decisions set the constraints every other pillar operates inside for decades. Capacity that is technically available but concentrated in one site is a supply risk that no amount of downstream quality work can offset.

HOW IT FAILS

  • Capacity is planned against forecast demand without modelling what a single-site loss would do to supply.
  • Make-versus-buy is decided on unit cost, omitting the oversight burden and the knowledge that leaves with the work.
  • Capital cases assume a regulatory timeline that has never been tested against the authorities involved.

WHAT CONTAINS IT

  • Network modelling that includes loss-of-site and demand-surge scenarios, not only expected demand.
  • Make-versus-buy assessment covering oversight cost, knowledge retention and regulatory consequence.
  • Regulatory feasibility confirmed as an input to the capital case rather than a consequence of it.

EVIDENCE IT OPERATES

  • Capacity and network models with the scenarios evaluated.
  • Make-versus-buy analyses including quality and regulatory factors.
  • Capital approval records with the assumptions stated and later reviewed.
02

Project governance & controls

Running the project itself: scope, schedule, cost, risk, contracts, interface management, change control and the eventual test of whether the promised benefits arrived.

Capital projects fail at the seams — between disciplines, between contractors, and between the project and the operation that inherits it. Governance is what makes those seams somebody’s explicit responsibility.

HOW IT FAILS

  • Schedule pressure converts quality-critical activities into parallel ones, and qualification absorbs the compression.
  • Interface responsibilities between contractors are assumed rather than assigned, so gaps appear at the boundaries.
  • Benefits realisation is never assessed, so the same optimistic assumptions are reused on the next project.

WHAT CONTAINS IT

  • Stage gates with quality and regulatory criteria that cannot be waived by schedule alone.
  • An interface register naming the owner of every boundary between parties and disciplines.
  • Post-implementation review against the benefits and assumptions the case was approved on.

EVIDENCE IT OPERATES

  • Stage-gate decisions with the criteria applied and any exceptions justified.
  • Interface and project risk registers maintained through execution.
  • Post-implementation review comparing outcome to business case.
03

Facility & process design

Designing the physical environment: material and personnel flows, segregation, cleanliness zoning, utilities, containment, and whether the result can actually be maintained and cleaned once it is running.

Flow and segregation decisions determine the contamination-control strategy for the life of the facility. A cross-flow designed in is a permanent procedural burden, mitigated forever by people rather than by geometry.

HOW IT FAILS

  • Flows are designed for construction efficiency, leaving crossovers that operations must control procedurally.
  • Maintainability is not a design criterion, so routine maintenance requires entering classified areas or shutting production.
  • User requirements are written by engineering rather than by the people who will operate and clean the space.

WHAT CONTAINS IT

  • User requirements authored with operations, quality and maintenance, and traced through design.
  • Flow and segregation reviewed against the contamination-control strategy, not only against area classification.
  • Maintainability and cleanability assessed as explicit design criteria with sign-off.

EVIDENCE IT OPERATES

  • User requirement specifications with cross-functional approval.
  • Flow, zoning and segregation drawings with the design rationale.
  • Design review records covering maintainability, cleanability and containment.
04

Engineering disciplines & design integration

The coordination of process, mechanical, electrical, civil, structural, architectural and instrumentation design into one buildable, consistent set of documents.

Each discipline can be individually correct while the combination is not. Clashes discovered on site are resolved under time pressure by whoever is present, and the as-built result rarely matches anyone’s intent.

HOW IT FAILS

  • Discipline models are coordinated for physical clash but not for functional consequence, so a compliant routing defeats a cleaning requirement.
  • Late design changes propagate to construction without returning to the disciplines that depended on the original.
  • Instrumentation and control design lags process design, so critical parameters have no means of measurement.

WHAT CONTAINS IT

  • Formal multi-discipline design review at defined maturity points, including quality where GMP impact exists.
  • Change management that re-checks dependent disciplines rather than only the one changed.
  • Instrumentation design driven by the control strategy, with critical parameters traced to a measurement.

EVIDENCE IT OPERATES

  • Coordinated design deliverables with review and approval records.
  • Design change records showing dependency re-assessment.
  • Traceability from critical process parameters to instruments and their qualification.
05

Procurement, fabrication & vendor management

Buying the equipment and services: specifications, bid evaluation, vendor documentation, factory acceptance testing, expediting, inspection, logistics and acceptance on site.

Most of the quality of a capital asset is determined by the specification it was bought against and the testing done before it shipped. A deficiency found at site acceptance is orders of magnitude more expensive than the same deficiency found at the factory.

HOW IT FAILS

  • Factory acceptance testing is witnessed as a formality, so equipment ships with known deficiencies recorded as punch items.
  • Vendor documentation arrives incomplete and is chased after installation, delaying qualification.
  • Specifications describe the equipment but not the GMP-critical aspects it must satisfy.

WHAT CONTAINS IT

  • Specifications that state the regulated requirements, not only the engineering ones.
  • Factory acceptance testing against pre-approved protocols, with leverage retained until deficiencies close.
  • Vendor documentation defined as a deliverable with acceptance criteria and payment linkage.

EVIDENCE IT OPERATES

  • Specifications and bid evaluations including quality criteria.
  • Factory and site acceptance test protocols and results.
  • Vendor documentation packages assessed for completeness before qualification.
06

Construction, installation & field quality

Physical execution and the quality control around it: installation to specification, field inspection, welding and materials verification, field change handling, and the as-built record of what was actually built.

Qualification verifies what exists, not what was drawn. Where the as-built record is unreliable, every subsequent change and investigation starts from a drawing that does not describe the plant.

HOW IT FAILS

  • Field changes are made to solve an installation problem and captured only as redlines that are never incorporated.
  • Material traceability for product-contact components is incomplete, and cannot be reconstructed later.
  • Construction quality records are held by the contractor and not transferred in a usable form.

WHAT CONTAINS IT

  • Field change control with the same rigour as design change, including quality assessment where GMP-relevant.
  • Material traceability maintained for product-contact and critical components at installation.
  • As-built documentation defined as a contractual deliverable, verified before turnover.

EVIDENCE IT OPERATES

  • Installation and field inspection records, including weld and material certification.
  • Field change records with assessment and incorporation into drawings.
  • Verified as-built documentation handed over with the asset.
07

Systems completion & turnover

Bringing the asset to a defined, verified completion state: system boundaries, mechanical completion, punch listing, documentation dossiers, safe energisation and the controlled handover to the next party.

Turnover is the moment accountability moves. Where completion is declared with open items and an incomplete dossier, qualification begins on an asset nobody can fully describe, and the gaps surface as deviations later.

HOW IT FAILS

  • Mechanical completion is declared against schedule pressure with significant punch items open and no closure plan.
  • System boundaries are drawn differently by the project and by the qualification team, so scope falls between them.
  • Turnover dossiers are assembled from what exists rather than against a defined required content list.

WHAT CONTAINS IT

  • Defined, agreed completion criteria per system, with categorised punch items and closure before handover.
  • A single system boundary definition used by construction, commissioning and qualification alike.
  • A required turnover dossier content list agreed before completion, verified at handover.

EVIDENCE IT OPERATES

  • Mechanical completion certificates with punch-list status.
  • System boundary definitions shared across project and qualification.
  • Turnover dossiers verified against the agreed content list.
08

Commissioning & technical startup

Making the installed asset work: functional testing, loop checks, balancing, control sequence verification, alarm testing, utility startup and the reliability run that shows it holds.

Commissioning is where engineering verification and regulated qualification meet, and the science- and risk-based approach expects the two to be leveraged rather than duplicated. Done well it removes rework from qualification; done as a formality it guarantees it.

HOW IT FAILS

  • Commissioning and qualification testing duplicate each other because commissioning was not executed under conditions that allow leverage.
  • Alarm and interlock testing covers the expected path and not the failure conditions the alarm exists for.
  • Startup proceeds with temporary configurations that are never formally removed or documented.

WHAT CONTAINS IT

  • Commissioning executed under documented, reviewable conditions so verified results can be leveraged into qualification.
  • Functional testing that includes failure modes, interlocks and recovery, not only normal operation.
  • A register of temporary configurations with mandatory closure before qualification.

EVIDENCE IT OPERATES

  • Commissioning protocols and results, with the leverage decision documented.
  • Loop check, alarm and interlock test records including failure-condition testing.
  • Temporary configuration register closed out before handover.
09

Asset management, maintenance & reliability

Keeping the asset fit for use across its life: criticality assessment, preventive and predictive maintenance, spares, the calibration interface, and managing equipment as it becomes obsolete.

Qualification proves an asset was fit at a point in time; maintenance is what keeps that true. A validated state is not preserved by documentation — it is preserved by the work that keeps the equipment behaving as qualified.

HOW IT FAILS

  • Maintenance intervals are inherited from the vendor manual without reference to criticality or observed failure behaviour.
  • Deferred maintenance accumulates on equipment that is running, and the backlog is invisible to quality.
  • Obsolescence is discovered when a part cannot be sourced during a breakdown.

WHAT CONTAINS IT

  • Criticality-based maintenance strategy, with GMP-critical equipment identified and treated accordingly.
  • Deferral of maintenance on critical equipment visible to and assessed by quality.
  • Obsolescence monitoring with planned replacement ahead of end-of-support.

EVIDENCE IT OPERATES

  • Asset register with criticality and maintenance strategy per item.
  • Maintenance completion and deferral records with quality assessment where critical.
  • Calibration records and obsolescence plans for critical instruments and systems.
10

Brownfield change, shutdowns & decommissioning

Changing a facility that is already operating: tie-ins to live systems, temporary controls, shutdown planning, dealing with legacy conditions, and the safe retirement of equipment, areas and records.

Brownfield work happens next to product, and the risk is to the operation continuing around it. Decommissioning carries a quieter risk: records and materials disposed of before their retention obligations were checked.

HOW IT FAILS

  • Temporary controls put in place for a tie-in are never formally removed, becoming permanent undocumented configuration.
  • Impact on adjacent operating areas — pressure cascades, utilities, traffic — is assessed for safety but not for product quality.
  • Decommissioning disposes of equipment, samples or records still subject to retention or a pending investigation.

WHAT CONTAINS IT

  • Temporary change control with mandatory expiry and verified restoration.
  • Impact assessment covering adjacent operating areas and their contamination-control assumptions.
  • Decommissioning checklists covering record retention, sample retention and open investigations before disposal.

EVIDENCE IT OPERATES

  • Shutdown and tie-in plans with quality impact assessment.
  • Temporary change records with expiry and closure verification.
  • Decommissioning records including retention and disposal decisions.

Why it matters in regulated work

  • Carries user and process needs into design, construction, commissioning, and handover.
  • Creates the physical and documentary foundation for qualification and operational readiness.
  • Keeps brownfield change, reliability, and decommissioning inside controlled boundaries.

Principal failure modes

  • Requirements are lost between design and turnover
  • Systems are complete but not operable or maintainable
  • Construction or brownfield change compromises controlled operations

Control objectives

  • Trace critical requirements through design and acceptance
  • Control interfaces, completion, turnover, and readiness
  • Maintain asset knowledge and safe configuration

Evidence families

  • User requirements, design reviews, and risk assessments
  • Construction, commissioning, turnover, and acceptance records
  • Asset registers, maintenance strategies, and as-built information

CONNECTED OPERATING MODEL

Where this capability connects

Lifecycle reach

  • Technology Transfer
  • Process Development & Characterisation
  • Commissioning & Qualification
  • Validation
  • Commercial Manufacturing
  • Laboratory Control
  • Discontinuation & Record Retention

Quality capabilities

  • Change Control
  • Quality Risk Management
  • Supplier Quality
  • Validation & Qualification
  • Document & Record Control
  • Training & Qualification

System classes

  • Digital Twins
  • ERP & Warehouse Management
  • Historians, SCADA & PLC

Roles to start with

  • CQV Engineer
  • Process Engineer
  • Technology-Transfer Engineer

MATURITY ORIENTATION · SPEQ SYNTHESIS

What stronger operation looks like

  1. 01ReactiveOwnership and evidence are reconstructed after events; controls depend on individuals.
  2. 02DefinedScope, roles, methods, records, and escalation are documented for routine use.
  3. 03ControlledCritical controls are risk-based, verified, monitored, and governed through change.
  4. 04PredictiveLeading signals connect performance, drift, capacity, risk, and intervention.
  5. 05AdaptiveLearning improves the operating model without weakening accountability or evidence.

HIGH-VALUE INTERSECTIONS

SOURCE BASIS

REGULATORY BASIS

What governs this capability

The 11 standards SPEQ maps to this pillar, and the 7 regulatory bodies behind them. Which standards belong to a pillar is a SPEQ judgement; the bodies, disciplines and industries below are read from the standards themselves.

DISCIPLINES

BODIES

ASME · ASTM · EMA · FDA · ISO · ISPE · USP

Also reached through the systems this pillar runs on

These 13 standards govern the system classes this pillar depends on rather than the pillar itself. The distinction matters: a standard that governs a system is not thereby a standard of every capability that uses it.

ISPE GAMP 5 (2022)EU GMP Annex 11ICH Q8(R2)ICH Q9(R1)ICH Q10FDA Process Validation Guidance (2011)2013/C 343/01WHO TRS 957, Annex 5MHRA GDPDSCSA (FD&C Act §§581–585)21 CFR Part 11MHRA GxP DI (2018)PIC/S PI 041-1

PROFESSIONAL · READINESS ORIENTATION

Turn the pillar into a bounded operating conversation.

Rate observable operation from 0 (not established) to 4 (adaptive). The protected output prioritizes operating dimensions and evidence—not a compliance score.