MES / EBR
Manufacturing Execution System / Electronic Batch Record
An MES is the system that executes manufacturing. In the ISA-95 / IEC 62264 hierarchy it is Level 3 — the operations layer between the business systems above it (ERP, Level 4) and the control systems below it (SCADA and PLCs, Level 2). It takes the approved master batch record and turns it into an enforced sequence of work: it dispenses the right material against the right lot, presents each instruction in order, refuses to let a step proceed before its predecessor is complete, captures every entry contemporaneously, and binds each action to the identified, qualified individual who performed it.
What this page does not claim
A system class is not a product. SPEQ describes what a CTMS or a LIMS is; the vendor directory at /tools lists the products that implement one, and a GAMP category is a property of an implementation, not of a class.
What a MES / EBR actually is
An MES is the system that executes manufacturing. In the ISA-95 / IEC 62264 hierarchy it is Level 3 — the operations layer between the business systems above it (ERP, Level 4) and the control systems below it (SCADA and PLCs, Level 2). It takes the approved master batch record and turns it into an enforced sequence of work: it dispenses the right material against the right lot, presents each instruction in order, refuses to let a step proceed before its predecessor is complete, captures every entry contemporaneously, and binds each action to the identified, qualified individual who performed it.
The electronic batch record is the output. 21 CFR 211.186 requires a master production and control record; 21 CFR 211.188 requires a batch production and control record that reproduces it and documents the accomplishment of each significant step. An MES holds both: the master recipe is the controlled template, and each execution produces the batch record a release decision rests on. Because the system enforces the sequence, most implementations adopt review by exception — the reviewer examines the deviations the system flagged rather than every page — which makes the exception rules themselves part of the regulated logic.
That record density makes an MES squarely a Part 11 and Annex 11 system. Electronic signatures on weigh-and-dispense checks, in-process verifications, and step completions carry the same regulatory weight as their wet-ink predecessors; the audit trail must capture manual overrides, late entries, and corrections with reason codes; and the time source must be trustworthy, because contemporaneous capture is the property that distinguishes an EBR from a transcribed one. MHRA's GxP data integrity guidance and PIC/S PI 041-1 both treat execution systems as a primary locus of data-integrity risk precisely because the record is created under production pressure.
Implementations are almost always configured commercial platforms — GAMP 5 Category 4 for the platform and recipe configuration, with custom interface code and bespoke calculations landing in Category 5. The recipe is the highest-risk artefact: a phase sequenced wrongly, a tolerance window wider than the master batch record, or an exception rule that suppresses a flag does not fail loudly — it produces a clean-looking batch record that misrepresents what the procedure required. Recipe authoring therefore sits under change control with the same rigour as the paper master it replaced, and the ISA-88 batch model most platforms are built on shapes how recipes, phases, and equipment modules are structured.
WHERE THE BOUNDARY ACTUALLY SITS
Not the quality-event system. The MES flags the exception; the deviation raised from it, the investigation, and the CAPA live in the eQMS.
eQMS owns it →Not the ERP. Inventory valuation, procurement, planning, and the financial view of a batch belong to Level 4; the MES consumes material lots and reports back what was used.
ERP & Warehouse Management owns it →Not the raw process-data archive. Second-by-second process values live in the historian; the EBR carries the values and summaries the batch record requires, not the full time series.
Historians, SCADA & PLC owns it →Not the laboratory system of record. The MES requests an in-process sample and consumes the result status; the analytical record itself belongs to the LIMS.
LIMS owns it →WHAT IT HOLDS, AND WHAT CROSSES ITS BOUNDARY
CORE RECORDS
- Executed electronic batch records, with every step, entry, signature, and timestamp
- Master recipes and their version history, traceable to the approved master batch record
- Weigh-and-dispense records binding material lot, quantity, balance, and verifier
- Exception and review-by-exception records — what was flagged, and how each flag was resolved
- Equipment use and status records supporting the log requirements of 21 CFR 211.182
- In-process check results and the limits they were evaluated against
- Operator identification and the qualification binding that authorised each signature
DATA FLOWS OUT
Execution exceptions that meet the deviation threshold, raised with their batch, step, and equipment context attached
Material consumption, yield, and batch status that release or hold inventory movements
In-process and finished-product sample requests, with the batch and step identity the result must land against
Recipe parameters and phase commands issued down to the control layer for automated steps
Batch, lot, and expiry master data that the packaging lines encode into each unique identifier
HOW THIS CLASS IS USUALLY VALIDATED
- SPEQ synthesis: an MES is approached as GAMP 5 Category 4 for the platform and its configured recipes, with custom interfaces and bespoke calculations treated as Category 5 — and the category is a property of the implementation, not the product, so a single deployment routinely spans both.
- The recipe is validated as an instance, not just the engine: each master recipe is verified against its approved master batch record — sequence, limits, calculations, and hold points — before first GMP use, and re-verified on every revision.
- Review-by-exception logic is scripted-test territory even under a CSA-leaned approach: a rule that under-flags produces batch records that pass review while hiding the very entries a reviewer exists to see.
- Interfaces to ERP, LIMS, and the control layer are verified for failure behaviour, not just the happy path — a silently dropped material-consumption message or sample result corrupts two systems of record at once.
SPEQ synthesis, not a rating. This is SPEQ’s reading of how this system class is commonly approached, offered to help you scope your own work. A GAMP category is a property of a specific implementation, not of a product class, and one deployment routinely spans several. It is not a classification service and does not replace your own documented risk assessment.
- Stage 1 · Reactive
Batches run on paper, or on an MES used as paper-on-glass — free-text entries, no enforced sequence, and full manual review of every record. Transcription errors and missing entries are discovered at batch review, weeks after the step that produced them.
- Stage 2 · Defined
Master recipes are modelled in the system with enforced sequence, dispensing verification, and electronic signatures. Batch review is still page-by-page because exception rules are not yet trusted, and interfaces to ERP and LIMS are partly manual.
- Stage 3 · Controlled
Review by exception is qualified and operating: the reviewer sees flagged entries with context, recipe changes flow through change control, and material, sample, and control-layer interfaces are verified including failure modes. Right-first-time is measured per recipe.
- Stage 4 · Predictive
Execution data drives improvement: exception clustering identifies the steps and recipes that generate review load, recipe tolerances are refined from process capability evidence, and release cycle time is managed as a controlled output of the system rather than an aspiration.
- Stage 5 · Adaptive
The EBR is the live spine of the batch: control-layer data, in-process results, and exceptions converge into a release-ready record at batch end, and recipe design anticipates variability rather than flagging it — the review effort concentrates where the risk actually is.
SPEQ’s shared five-stage progression, labelled synthesis. It is not the FDA QMM rating scale and not the scored maturity-assessment domains — assess your quality system for those.
WHAT AN INSPECTION PROBES, AND WHERE IT GOES WRONG
INSPECTION SIGNALS
- Whether entries are contemporaneous — late entries, back-dating patterns, and clustered timestamps at shift end are the first thing a data-integrity-focused inspector trends.
- Whether the review-by-exception rules are documented, justified, and periodically challenged, or were configured once and never revisited.
- Whether manual overrides and corrections carry a reason, a second signature where required, and appear in the audit trail an ordinary user cannot alter.
- Whether the executing recipe matches the currently approved master batch record — a recipe revised outside change control is a §211.186 finding wearing a software costume.
- Whether the person who signed was qualified for the task at the time of signing, demonstrable from the system, not reconstructed from a training binder.
COMMON RISKS
- Paper-on-glass implementations that digitise the form but not the enforcement, keeping every transcription risk while adding validation cost.
- Exception rules tuned to reduce review workload until they suppress the signals review exists to catch.
- Recipe changes made as "configuration" without the impact assessment the equivalent master-batch-record change would have required.
- Interface failures handled by re-keying data manually, creating a second, unofficial record path that the validation never covered.
- Shared terminal sessions on the shop floor, leaving signatures attributable to a workstation rather than a person.
WHO WORKS IN IT, AND WHERE IT IS SHAPED
ROLES
- Production operator and line supervisor
- MES recipe author / master data owner
- MES system administrator / business owner
- QA batch-record reviewer and release designee
- CSV analyst
- Manufacturing systems engineer
DELIVERY-LIFECYCLE PHASES
[ POSITION IN THE FRAMEWORK ]
6 OF 7 DIMENSIONS · 25 LINKSExecutes the master batch record on the shop floor and produces the electronic batch record a batch-release decision rests on — ISA-95 Level 3 between ERP and the control layer, and a primary locus of data-integrity risk.
06 · QUALITY MATURITY — MES / EBR, REACTIVE TO ADAPTIVE
Batches run on paper, or on an MES used as paper-on-glass — free-text entries, no enforced sequence, and full manual review of every record. Transcription errors and missing entries are discovered at batch review, weeks after the step that produced them.
Master recipes are modelled in the system with enforced sequence, dispensing verification, and electronic signatures. Batch review is still page-by-page because exception rules are not yet trusted, and interfaces to ERP and LIMS are partly manual.
Review by exception is qualified and operating: the reviewer sees flagged entries with context, recipe changes flow through change control, and material, sample, and control-layer interfaces are verified including failure modes. Right-first-time is measured per recipe.
Execution data drives improvement: exception clustering identifies the steps and recipes that generate review load, recipe tolerances are refined from process capability evidence, and release cycle time is managed as a controlled output of the system rather than an aspiration.
The EBR is the live spine of the batch: control-layer data, in-process results, and exceptions converge into a release-ready record at batch end, and recipe design anticipates variability rather than flagging it — the review effort concentrates where the risk actually is.
SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →
07 · REGULATORY & EVIDENCE
GOVERNING STANDARDS · 8
Derived from the 8 standards SPEQ maps to this subject, across 6 regulatory bodies: FDA, EMA, ICH, ISPE, PIC/S, MHRA.
RECORDS & OBJECTIVE EVIDENCE
- Executed electronic batch records, with every step, entry, signature, and timestamp
- Master recipes and their version history, traceable to the approved master batch record
- Weigh-and-dispense records binding material lot, quantity, balance, and verifier
- Exception and review-by-exception records — what was flagged, and how each flag was resolved
- Operator identification and the qualification binding that authorised each signature
COMMON INSPECTION FINDINGS
- Non-contemporaneous entries — back-dating and timestamps clustered at shift end
- Review-by-exception rules never justified or challenged, tuned until they suppress signals
- The executing recipe not matching the currently approved master batch record
- Manual overrides and corrections without a reason code or the required second signature
- Shared terminal sessions leaving signatures attributable to a workstation, not a person
Choosing, validating, and living with MES / EBR
FREQUENTLY ASKED
What is the difference between an MES and an ERP?
The ERP plans and accounts; the MES executes. In ISA-95 terms the ERP is Level 4 — orders, inventory, planning, cost — and the MES is Level 3, where the approved master batch record becomes enforced work on the floor. The ERP knows a batch was scheduled and what it consumed in aggregate; the MES knows which operator dispensed which material lot at which balance at which minute, and holds the signed record of it. The two exchange orders and consumption data, but only the MES record can support a batch-release decision.
Is review by exception acceptable to regulators?
Yes, when it is earned. Review by exception rests on the validated claim that the system enforces the recipe and flags every departure, so the reviewer can concentrate on the flags rather than re-reading compliant entries. That makes the exception rules themselves regulated logic: they must be specified, tested, and revisited when recipes change. An inspector probing the practice will ask what the system does not flag and why that is justified — an organisation that cannot answer has automated its review without qualifying it.
Where does a deviation live — in the MES or the eQMS?
Both, but they hold different things. The MES holds the execution-level exception: the entry outside its limit, the override, the skipped verification, in the context of the batch and step where it happened. The eQMS holds the quality event built from it — the deviation record, the investigation, the impact assessment, and the CAPA. A well-integrated pair raises the eQMS record from the MES exception automatically and keeps the two linked, so the batch record and the investigation reference each other rather than drifting apart.
What GAMP 5 category is an MES?
Most deployments are configured commercial platforms — GAMP 5 Category 4 — because the organisation models recipes, workflows, and exception rules without altering the product code. Custom interface adapters, bespoke calculations, and site-specific extensions are Category 5 elements inside the same system. GAMP 5 Second Edition (2022) is explicit that the category describes the implementation rather than the product, and that a single system commonly spans several; the retired Category 2 no longer exists as a bucket for any of it. This framing is SPEQ synthesis to aid scoping, not a classification service.