The modern regulatory framework for process validation moved away from the traditional three-batch approach in 2011, when FDA issued its Guidance for Industry: Process Validation, General Principles and Practices. That guidance established a three-stage lifecycle model aligned with the quality by design principles in ICH Q8(R2) Pharmaceutical Development, ICH Q9 Quality Risk Management, and ICH Q10 Pharmaceutical Quality System. EMA adopted equivalent expectations in its 2014 Guideline on Process Validation for Finished Products (and a parallel guideline for biological active substances), and the same logic runs through EudraLex Volume 4, Annex 15 (Qualification and Validation), revised in 2015. The principles apply across modalities: small-molecule oral solids, sterile injectables, biologics, vaccines, and combination products. The tools change, the lifecycle does not.
The shift matters because the old model, run three batches, pass the tests, declare validation complete, treated validation as an event. The lifecycle model treats it as an ongoing program: you design the process to understand it, you qualify it to demonstrate control, and you monitor it continuously to confirm the state of control is maintained. The phrase “state of control” is not decoration. FDA’s guidance defines it as a condition in which the set of controls consistently provides assurance of continued process performance and product quality. Everything in the three stages exists to establish that condition and then prove it has not slipped.
A useful way to read the three stages is by the question each one answers. Stage 1 asks: do we understand this process well enough to control it? Stage 2 asks: can we prove the process performs as designed at commercial scale? Stage 3 asks: is it still performing that way today, this batch, this quarter? A program that cannot answer all three is incomplete, even if a binder labelled “validation” exists.
The Conceptual Framework
Process design (Stage 1) develops the knowledge that defines what the process is and what makes it work. This is where critical quality attributes (CQAs), critical process parameters (CPPs), and, where the company chooses to define one, the design space are established.
Process qualification (Stage 2) confirms that the designed process, implemented in the commercial facility with commercial equipment, produces product meeting specifications consistently. This is the activity most people picture when they hear “validation”: controlled manufacturing runs with enhanced monitoring.
Continued process verification (Stage 3) provides ongoing assurance that the process remains in a state of control during routine commercial manufacturing. Statistical process monitoring detects drift before it causes failures.
All three stages together constitute a validated process. A process with a strong Stage 1 and 2 but no Stage 3 program is technically validated but not under ongoing control. A Stage 3 program without the underlying Stage 1 knowledge base is monitoring without understanding: you can plot a control chart, but you cannot interpret a signal or fix the cause.
| Stage | Lifecycle name | Primary phase | Core output |
|---|---|---|---|
| 1 | Process Design | Development | Process understanding, CQAs, CPPs, control strategy |
| 2 | Process Qualification | Scale-up and launch | PPQ protocol and report, qualified equipment and facility |
| 3 | Continued Process Verification | Commercial life | Trending, control charts, capability, periodic review |
The boundaries are not walls. Knowledge generated in Stage 3, for example a recurring out-of-trend result on a single attribute, often feeds back into Stage 1 thinking and can trigger a process change that itself requires partial requalification. The lifecycle is a loop, not a one-way pipeline.
Where validation sits in the wider quality system
Process validation is not a standalone discipline. It draws on and feeds several other programs, and inspectors will follow those threads:
- Quality risk management (ICH Q9) supplies the risk assessments that justify what gets studied, how many runs are needed, and what the sampling plan looks like. See quality risk management.
- Equipment and utility qualification must be complete before process qualification can start. See equipment qualification lifecycle.
- Change control governs every modification to a validated process. See change control for validated systems.
- The validation master plan sets the site-level strategy, sequencing, and acceptance philosophy that individual protocols inherit. See validation master plan and periodic review.
Stage 1: Process Design
Stage 1 work happens primarily during pharmaceutical development, before commercial manufacturing. Its purpose is to establish a thorough understanding of the process: what it does, what makes it work, and what its failure modes are. The deliverable is not a passing batch. It is knowledge, captured in a form that someone who never ran the development program can read and use.
Critical Quality Attributes (CQAs)
A CQA, as defined in ICH Q8(R2), is any product property of a physical, chemical, biological, or microbiological kind that has to be held inside a suitable limit, range, or distribution for the product to come out with the quality, safety, and efficacy it is meant to have. Examples for a sterile biologic: potency (biological activity), purity (the impurity profile), identity (confirmation of molecular structure), safety (absence of adventitious agents and acceptable endotoxin), and product-related substances such as aggregation, deamidation, and charge variants. For a small-molecule tablet the CQAs look different: assay, content uniformity, dissolution, related substances (degradants), and dose-form attributes such as hardness or disintegration where they affect bioavailability.
CQAs are derived from several inputs working together: knowledge of the mechanism of action (which molecular properties drive efficacy), toxicological assessment (which impurities are safety-relevant and at what level), clinical and nonclinical data (which attributes correlate with patient outcomes), and regulatory precedent for the product class. The exercise is one of justification, not listing. For each candidate attribute you state why it is or is not critical, and that rationale is itself inspectable.
A practical caution for newcomers: criticality is about impact, not about how hard something is to measure. An attribute can be difficult to assay and still not be a CQA, and an easy in-process measurement can be one of the most critical things you track.
Criticality Assessment: A Worked Example
Saying an attribute “is” or “is not” a CQA is a conclusion. The assessment behind it needs to be visible, scored, and repeatable, not a judgment call one scientist made that everyone else accepted. Most programs turn the ICH Q8(R2) idea, that criticality reflects both how bad it would be if the attribute drifted and how likely that drift actually is, into a numeric scoring exercise that produces a defensible, documented answer for every candidate attribute.
A workable scoring approach rates two factors on defined scales and multiplies them into a single risk score:
- Severity: the consequence to patient safety or product efficacy if the attribute falls outside its acceptable range. A 1 to 5 scale might run from 1 (no plausible clinical consequence) to 5 (direct, severe impact on safety or efficacy, for example an impurity tied to immunogenicity).
- Probability of occurrence: how likely the attribute is to move outside its acceptable range under normal process and raw-material variability, informed by development data and how well the relevant unit operations are understood. A 1 to 5 scale might run from 1 (extensive data show the attribute reliably stays in range) to 5 (little data exist, or the attribute is known to be sensitive to routine variability).
A worked example for a monoclonal antibody drug substance, scoring six candidate attributes:
| Attribute | Severity (1-5) | Probability of occurrence (1-5) | Risk score | Rationale | Classification |
|---|---|---|---|---|---|
| Potency (relative bioactivity) | 5 | 3 | 15 | Directly tied to mechanism of action; moderate variability observed across development lots | CQA, high control priority |
| Aggregation (high molecular weight species) | 5 | 4 | 20 | Immunogenicity risk; sensitive to shear, freeze-thaw, and hold time | CQA, high control priority |
| Afucosylation (glycan pattern affecting effector function) | 4 | 3 | 12 | Affects a mechanism-relevant effector function; cell culture conditions shift it measurably | CQA, standard control |
| Charge variants (acidic and basic species) | 3 | 3 | 9 | Some correlation with potency and clearance; still being fully characterized | CQA, standard control |
| Host cell protein | 4 | 2 | 8 | Safety-relevant impurity, but downstream purification clears it with a wide, well-demonstrated margin | CQA, standard control |
| Free thiol (unpaired cysteine) | 2 | 2 | 4 | No demonstrated clinical impact at levels seen; low occurrence across development lots | Non-CQA, monitored only |
The scoring bands behind those calls: 15 to 25 gets high control priority (tight in-process controls, enhanced monitoring in Stage 2 and 3); 6 to 14 is a standard CQA (controlled and tested, without the extra monitoring intensity); 1 to 5 is a non-CQA that is still tracked but does not drive process control decisions. The bands are a company choice, and they belong in the assessment’s methodology section, decided in advance rather than fitted to the answer.
Two things about this table matter more than the specific scores. First, “non-CQA” does not mean “ignore.” Free thiol still gets tested; it just does not carry the control intensity or the specification-tightening logic a CQA does. Second, this is a living assessment, revisited under quality risk management whenever new data, a new impurity found, a clinical signal, a process change, shifts the severity or probability inputs, not filed away once after submission and forgotten.
Critical Process Parameters (CPPs)
CPPs are process parameters whose variability has a real impact on a CQA and which therefore must be monitored or controlled to ensure the process produces the desired quality. Not every process parameter is critical. Temperature during a non-critical mixing step is a process parameter, but it may not be critical if, across a wide range, it has no meaningful effect on any CQA.
CPP identification starts with risk assessment under ICH Q9. Which parameters could plausibly affect which CQAs, and over what ranges? Common tools are failure mode and effects analysis (FMEA) and cause-and-effect (fishbone) mapping. Risk ranking narrows a long list of parameters to a smaller set worth studying experimentally. Then comes confirmation through design of experiments (DoE): studies that systematically vary parameters across their operating ranges and measure the CQA response, so the cause-and-effect relationship is demonstrated rather than assumed. The DoE approach and the QbD vocabulary behind it are covered in quality by design and DoE.
It helps to keep three tiers straight. A critical process parameter has a demonstrated effect on a CQA and a tightly controlled range. A key or well-understood parameter is monitored but has a wider acceptable range. A non-critical parameter is recorded but not a control point. Drawing these lines clearly is what lets a manufacturing team know which alarms matter at 2 a.m.
A worked CPP-to-CQA linkage for one unit operation makes the logic concrete. The example below is a lyophilization (freeze-drying) step:
| Process parameter | Linked CQA | DoE finding | Classification | Control range |
|---|---|---|---|---|
| Shelf temperature, primary drying | Residual moisture; cake appearance | Strong effect on moisture and collapse above a threshold | CPP | -22 to -18 C |
| Chamber pressure | Residual moisture; drying time | Moderate effect within studied range | CPP | 80 to 120 mTorr |
| Freezing ramp rate | Reconstitution time | Weak effect across range studied | Key parameter | 0.5 to 1.5 C/min |
| Loading sequence | None demonstrated | No measurable CQA effect | Non-critical | Recorded only |
The point is not the specific numbers, which depend on the product, but the discipline: each control has a documented reason to exist, and the reason traces back to a CQA and a study.
A Worked DoE Example: From Screening to a Justified Range
The lyophilization table above shows the conclusion a DoE reaches. It is worth seeing the study itself, because “we ran a DoE” and “we ran a DoE that actually supports this range” look identical until someone checks the data.
Take a fluid-bed drying step after high-shear wet granulation for an oral solid dose tablet, where the two candidate CPPs are inlet air temperature and the target granulation moisture (loss on drying, LOD) at the end of drying. A small factorial design, four corner runs plus three center-point replicates, varies both factors and measures two CQAs: tablet content uniformity (relative standard deviation across a sampled set) and dissolution at 30 minutes.
| Run | Inlet air temperature | Target LOD | Content uniformity RSD | Dissolution at 30 min |
|---|---|---|---|---|
| 1 (low, low) | 55 C | 1.0% | 4.8% | 78% |
| 2 (high, low) | 75 C | 1.0% | 3.1% | 82% |
| 3 (low, high) | 55 C | 3.0% | 3.5% | 91% |
| 4 (high, high) | 75 C | 3.0% | 2.6% | 95% |
| 5 (center) | 65 C | 2.0% | 2.9% | 88% |
| 6 (center) | 65 C | 2.0% | 2.8% | 87% |
| 7 (center) | 65 C | 2.0% | 3.0% | 89% |
Reading the pattern, not just the numbers: inlet air temperature has a clear effect on content uniformity (4.8% RSD at 55 C down to roughly 2.6 to 3.1% at 75 C), consistent with faster drying limiting migration of the soluble binder toward the granule surface. Target LOD has the dominant effect on dissolution (78% at the driest target up to 95% at the wettest), consistent with a harder, less porous granule matrix at lower final moisture. Neither factor showed a meaningful effect on the other CQA, and the center points cluster tightly, which supports treating the region between the corners as well behaved rather than needing a more complex response-surface follow-up.
That reading, not the raw numbers, is what turns into ranges:
| Parameter | Studied range | DoE finding | Classification | Normal operating range | Proven acceptable range |
|---|---|---|---|---|---|
| Inlet air temperature | 55 to 75 C | Strong effect on content uniformity; no meaningful effect on dissolution | CPP | 65 to 75 C | 60 to 75 C |
| Target granulation LOD | 1.0 to 3.0% | Dominant effect on dissolution; minor effect on content uniformity | CPP | 2.0 to 3.0% | 1.5 to 3.0% |
The normal operating range is where routine manufacturing is expected to run; the proven acceptable range is the wider boundary the study actually demonstrated stays acceptable, held in reserve rather than run against routinely. Neither range extends past what the seven runs actually tested. A common Stage 1 weakness is a proven acceptable range that quietly extrapolates past the widest point studied, a decision the data never made. Content uniformity and dissolution acceptance in a real protocol would be tied to the applicable USP general chapters and the product’s own specification, referenced by number and confirmed current before use.
Control Strategy and Design Space
In the ICH Q10 sense, a control strategy is the coordinated set of controls a company puts in place, built from what it has learned about the product and the process, to hold both process performance and product quality where they need to be. It spans input material controls, in-process controls, CPP ranges, and finished-product testing. The control strategy is the practical product of Stage 1: it is what gets implemented on the floor.
In ICH Q8(R2) terms, a design space is the set of input-variable and process-parameter combinations, taken together across more than one dimension, that has been shown to deliver quality. Operating anywhere inside that region counts as staying put rather than making a change, so it does not call for prior regulatory approval. Moving out of the design space is a change and normally requires a regulatory submission. A design space is optional under ICH Q8(R2); many products are licensed with proven acceptable ranges and a sound control strategy and no formal multidimensional design space at all. Define one only where the operating flexibility it buys is worth the development and regulatory effort to characterize it.
Stage 1 Documentation
Typical records include development reports, process characterization study reports, the risk assessments themselves, DoE study reports, and a Process Design Report or development summary that captures the integrated process understanding. This package is the scientific basis for the Process Validation Protocol that governs Stage 2. When an inspector asks “how do you know this parameter range is safe,” the answer lives here, and an answer of “that is what we have always run” is the one finding you most want to avoid.
Stage 1 acceptance criteria: how you know it is done
Stage 1 has no batch to pass, so people sometimes treat it as never finished. It is finished when these are true:
- Every CQA has a documented criticality rationale and an acceptance range tied to clinical, toxicological, or compendial justification.
- Every CPP has an experimentally demonstrated link to a CQA and a defined normal operating range plus a proven acceptable range.
- A risk assessment exists that shows the full parameter list was considered, not just the parameters that turned out to matter.
- The control strategy is written and implementable, with each control traceable to the understanding that justifies it.
- The package is readable by someone outside the development team. If a technical transfer team cannot run the process from the documentation, Stage 1 is not done.
For the wider development-to-commercial picture, see BLA readiness data package and quality in technology transfer.
Stage 2: Process Qualification
Stage 2 occurs during manufacturing scale-up and commercial introduction. It demonstrates that the commercial-scale process consistently produces product meeting CQAs when operated within the defined CPP ranges, in the real facility, with the real equipment, run by the people who will run it.
Process Performance Qualification Protocol
The PPQ protocol must be reviewed and approved by Quality Assurance before any qualification run. Approving acceptance criteria after the data are in hand is not science, and it is a recurring inspection finding. The protocol specifies:
- The manufacturing runs to be included, with the number scientifically justified
- The CPPs to be monitored and their acceptance limits
- The enhanced sampling and testing plan, more intensive than routine release testing
- The CQAs to be evaluated and the methods used
- Statistical acceptance criteria
- Rules for batch inclusion and exclusion, defined in advance
- The deviation handling and pre-defined escalation path for the runs
- The roles and signatures required for protocol approval, execution oversight, and report approval
Number of runs. Three consecutive batches has been industry practice for decades, but FDA’s 2011 guidance deliberately does not prescribe a number. It requires enough runs to demonstrate consistent performance and to provide a statistically meaningful basis for the conclusion. For a well-characterized process backed by extensive development data, three may be appropriate. For a novel modality, a complex biologic, or a process with higher variability, more runs may be needed. The protocol must justify the number chosen rather than reciting “three” by habit. A defensible justification references the variability seen in development, the criticality of the CQAs, and the statistical confidence the chosen number supports.
Consecutive runs. The runs must be consecutive because the point is to show control over time, not that the process can occasionally produce good product. Selecting three good batches out of a larger set, or quietly running batches in between the chosen ones, defeats the purpose and, when discovered, reads as data integrity failure rather than a validation shortfall. See data integrity foundations for why selective reporting is treated so seriously.
Enhanced monitoring. PPQ runs carry heavier instrumentation than routine production: additional in-process samples at key stages, more frequent parameter recording, extra release tests beyond the routine panel, and retention of additional samples for follow-up. The enhanced data set is what supports the statistical conclusions; you cannot generate it retroactively.
Setting PPQ acceptance criteria
Acceptance criteria in a PPQ protocol come in layers, and confusing them is a common protocol weakness:
- Registered specification limits. Each CQA must meet the limits filed in the marketing application. There is no discretion to waive or soften this layer at the protocol-writing stage; a result outside specification is an out-of-specification event, not a validation observation.
- In-process and CPP limits. Each monitored parameter must stay within its proven acceptable range during the run.
- Statistical or consistency criteria across runs. Beyond passing per batch, the protocol should state how consistency across runs is judged, for example that the mean and spread of a CQA across the PPQ runs sit comfortably inside the specification, or an early estimate of capability where the data support it. Some processes set a target such as observed results falling within a defined fraction of the specification width.
A worked acceptance-criteria table for one CQA on a three-run PPQ:
| CQA | Spec | Run 1 | Run 2 | Run 3 | Per-run criterion | Cross-run judgment |
|---|---|---|---|---|---|---|
| Assay (% label) | 95.0-105.0 | 99.4 | 100.1 | 98.9 | Each within spec | Mean 99.5, range 1.2; centered, low spread, acceptable |
| Dissolution (% at 30 min) | not less than 80 | 94 | 96 | 92 | Each meets limit | Consistent margin above limit |
| Water content (% w/w) | not more than 3.0 | 1.8 | 2.1 | 2.4 | Each within limit | Upward pattern across runs; flag for Stage 3 watch |
Notice the last row. All three runs pass, but a reviewer who only checks pass/fail misses the upward movement. The validation conclusion can still be “qualified,” but the report should explicitly carry that observation into the continued verification plan. This is the difference between a tick-box validation and one that actually understands its process.
Concurrent Release During Stage 2
FDA’s 2011 guidance explicitly allows concurrent release during process qualification: product made during PPQ runs can be released to market while the PPQ protocol is still being completed, provided Quality makes a documented, risk-based decision that the data available at release time support that release. The full PPQ report must still be finalized and reviewed afterward. EMA Annex 15 and the EMA process validation guideline treat concurrent validation as a route reserved for justified cases, for example a product addressing a genuine medical need with limited batches. Under the lifecycle approach this is a defined, risk-managed practice with a documented rationale, not an after-the-fact exception used to rescue a batch.
Process Qualification Report
The PPQ report summarizes the runs conducted, the data generated, the comparison against pre-approved acceptance criteria, any deviations and their investigations, the statistical analysis, and the conclusion that the process is qualified. QA approval is required. The report then becomes a reference point: later changes to the process are assessed against this qualified state through change control for validated systems. A deviation during PPQ is not automatically fatal, but it must be investigated to root cause and its impact on the validity of the run assessed honestly. Quietly carrying a serious deviation forward is worse than failing the run.
The deeper protocol-and-report mechanics, including the criteria for declaring a run successful, are covered in process performance qualification (PPQ) and the general writing validation protocols and reports. Biologic-specific considerations, where scale-down models and comparability complicate the picture, are in process validation for biologics.
Stage 2: Equipment and Facility Qualification
Stage 2 also covers qualification of the manufacturing equipment, utilities, and facility used for commercial production. This is the IQ/OQ/PQ work performed at the equipment and system level, and it must be complete before process performance qualification, because you cannot qualify a process on equipment that has not been qualified itself.
Installation Qualification (IQ) verifies that equipment was installed correctly, that the physical installation matches design and purchase specifications, that connected utilities meet specification, and that documentation such as manuals, materials certificates, and calibration records is in place.
Operational Qualification (OQ) verifies that equipment operates as intended across its full operating range, including the edges and any alarms and interlocks. For a bioreactor, OQ challenges temperature control accuracy, agitation speed, pH control response, dissolved oxygen control, and data acquisition across the range it will actually be used in, not just at a comfortable midpoint. For a tablet press, OQ challenges compression force control, turret speed, and reject-station function.
Performance Qualification (PQ) verifies that the equipment performs consistently within specification under conditions representative of production. It often includes consecutive runs under production-like conditions.
Process Performance Qualification (PPQ) is the combined Stage 2 activity in which qualified equipment, utilities, and facility are run with the actual product and process to show the whole system produces consistent, specification-meeting output. A frequent terminology trap: equipment-level “PQ” and process-level “PPQ” are different activities. Keep the acronyms straight in protocols so reviewers and inspectors are not left guessing which one a document means.
Many sites now run a science- and risk-based commissioning and qualification approach under ASTM E2500, where verification effort is focused on the aspects that affect product quality and patient safety rather than testing everything equally. That approach is covered in commissioning and qualification (ASTM E2500). The deeper mechanics of qualifying equipment are in equipment qualification lifecycle and the supporting validation deliverables guide. Utility qualification (water, clean steam, compressed gases) is in clean utilities qualification and water system validation (USP 1231).
Stage 3: Continued Process Verification
Stage 3 is the ongoing program that maintains and confirms the state of control established in Stage 2. It runs for the commercial life of the product, and for most products it generates far more data over time than Stages 1 and 2 combined. The full operational design of a Stage 3 program is covered in continued process verification (CPV); this section gives the working core.
Statistical Process Monitoring
Stage 3 uses statistical tools to monitor process performance over time and, critically, to distinguish two kinds of variation:
Common cause variation is the random variation inherent in a stable process. A process can be in statistical control even though variation is present. Common cause variation is reduced only by changing the process design, not by chasing individual points.
Special cause variation comes from an identifiable, correctable source: equipment malfunction, operator error, a raw material lot shift, an environmental change. A signal that points to special cause is what triggers an investigation. Confusing the two is the classic mistake. Reacting to common cause as if it were special cause, called tampering, usually makes a process worse, not better.
Control Charts
Shewhart control charts are the foundational tool: individuals and moving-range charts for batch data, and X-bar and R or X-bar and S charts where rational subgroups exist. Each result is plotted as a point. Control limits are calculated from the process data, typically anchored in the Stage 2 and early Stage 3 history, and are distinct from specification limits, which come from the registered acceptance criteria. The chart is read for:
- Points outside the control limits, a possible special cause
- A run of eight or more consecutive points on one side of the center line, suggesting a shift
- Six consecutive increasing or decreasing points, a trend
- The wider Western Electric and Nelson pattern rules (for example, two of three points beyond two sigma on the same side)
A chart showing a process drifting toward an upper specification limit while every batch still passes is more useful than a pass/fail table. It says the process center has moved and that action should be taken before a failure occurs. That early warning is the whole reason Stage 3 exists.
A practical distinction worth internalizing: specification limits protect the patient and come from the registered application; control limits protect the process and come from its own demonstrated behavior. Control limits are usually tighter than specification limits, which is the point. A result inside specification but outside the control limit is an out-of-trend event, not an out-of-specification event, and it gets investigated as a process signal. See out-of-trend investigations.
Process Capability
Process capability indices quantify how well a stable process fits inside its specification limits. Cpk relates the distance from the process mean to the nearer specification limit. A Cpk of 1.33 corresponds to the process mean sitting at least four standard deviations from the closest specification limit. A minimum Cpk around 1.33 is a common expectation for commercial processes, with a higher target such as 1.67 sometimes set for the most safety-relevant CQAs. Capability is only meaningful once the process is demonstrably stable; computing Cpk on an out-of-control process produces a number with no valid interpretation. A capability index that erodes over time, even while still nominally acceptable, is a drift signal worth acting on. The mechanics of these calculations are worked through in statistics in quality: Cpk and control charts.
A small numeric illustration. Suppose assay has a specification of 95.0 to 105.0 (so the specification mean is 100.0), and the routine commercial data show a mean of 99.0 with a standard deviation of 1.0. The distance to the nearer limit (95.0) is 4.0, so Cpk is 4.0 divided by (3 times 1.0), which is 1.33. If the mean drifts to 98.0 with the same spread, the distance to 95.0 falls to 3.0 and Cpk drops to 1.00, even though no individual batch has failed yet. That falling number is the action signal.
Stage 3 for Small-Batch and Patient-Specific Products
Classical Stage 3 monitoring assumes enough batches, made similarly enough to each other, that a control chart means something. Autologous cell and gene therapies break that assumption directly. Many of these products are manufactured one patient’s material at a time, batch size is inherently one, and the starting biological material, that patient’s own cells, carries variability the manufacturing process did not create and cannot remove. Applying a standard individuals chart with an eight-consecutive-point run rule to a product line making a handful of batches a month, each from a different patient’s starting material, produces a chart with too few points to say anything statistically sound, and it mixes patient-to-patient biological variability into what looks like a process signal.
Programs working in this space typically adapt Stage 3 rather than abandon it:
- Trend process parameters and in-process attributes, which are more comparable run to run than final product potency, since potency is itself heavily shaped by the input material.
- Lean more on tightened in-process controls and release-time acceptance criteria than on long-run process trending, since there may not be enough same-process data points to trend meaningfully for months at a time.
- Track manufacturing success rate, the proportion of batches meeting release criteria, as a primary ongoing signal, because that metric accumulates across patients even when individual product results cannot be pooled into one chart.
- Reach for a comparability assessment, the same logic that governs a manufacturing change, when it is the starting-material variability itself that needs to be characterized rather than assumed away.
None of this loosens the expectation that a state of control exists and is monitored. It changes what monitoring can mean when the population a chart would normally trend does not exist in the usual sense. The release-strategy consequences of n equals one batches are covered in ATMP and cell and gene therapy manufacturing, and the purification-train and comparability mechanics that also apply to biologics generally are in process validation for biologics.
Periodic Product Review
21 CFR 211.180(e) requires a review of records for each drug product at least annually to determine the need for changes in specifications or manufacturing or control procedures. EudraLex Volume 4, Chapter 1, sets the equivalent Product Quality Review (PQR) expectation in the EU. The review compiles:
- Batch manufacturing data for the period
- Out-of-specification, out-of-trend, and deviation summaries
- CAPA status for product-related issues
- Stability data
- Complaint and return data
- Changes implemented during the period
- Statistical analysis of key quality attributes and CPPs
- An overall assessment of continued process control
The annual review is a Stage 3 output, not a filing exercise. A review that compiles tables without trend analysis or comparison to control limits is not doing the job the lifecycle assigns it. The structure and common failure modes are covered in annual product review and PQR.
Stage 3 acceptance criteria: what “in control” looks like
- A defined set of CQAs and CPPs are trended on the appropriate charts every batch or at the defined frequency.
- Control limits are established, documented, and periodically re-evaluated as data accumulate.
- A written procedure defines what constitutes a signal and what response each signal triggers, so reaction is consistent and not left to whoever is on shift.
- Out-of-trend results are investigated and linked to deviation and CAPA records where appropriate.
- Process capability is tracked over time, not computed once and forgotten.
- The annual or periodic review closes the loop with a documented conclusion on the state of control.
Validating a Legacy or Already-Marketed Process
Most of this article assumes a process moving from development into its first commercial launch: Stage 1 happens before approval, Stage 2 happens at launch. A large share of real validation work looks nothing like that. It is a product already on the market, sometimes for decades, sometimes acquired from another company, sometimes transferred in from a contract manufacturer, where the original Stage 1 characterization package is thin, missing, or was never built to the standard the 2011 guidance now expects.
The 2011 guidance moved the industry away from retrospective validation, the older practice of declaring a long-running process validated purely by mining historical batch records after the fact, with no prospective protocol and no pre-set acceptance criteria. That does not make a legacy process unvalidatable. It means the path runs through the same three stages, built from where the product actually sits rather than from a blank page:
- Reconstruct Stage 1 knowledge from what exists. Development reports, technology transfer packages, historical deviation and OOS trends, and years of accumulated commercial batch data stand in for a formal characterization program. A documented risk assessment decides which CQAs and CPPs can be justified from that existing evidence and which ones need a targeted confirmatory study before anyone relies on them.
- Treat commercial history as evidence, not as the validation itself. A long batch history has genuine statistical value for demonstrating process capability, and it is legitimate Stage 3 evidence. It is not a substitute for a prospective PPQ against pre-approved acceptance criteria if that PPQ was never actually done.
- Scope a bridging or confirmatory PPQ to the actual gaps. Rather than repeating the entire Stage 1 to Stage 2 sequence, a risk assessment that names the specific gaps, followed by a small, justified number of confirmatory runs against acceptance criteria drawn from the accumulated commercial data, is usually the proportionate answer. The scope decision belongs in writing, held to the same justification standard as any PPQ protocol.
- Where the product changes hands, transfer and validation are one activity. An acquired product or a new contract manufacturing site is validated through technology transfer; see quality in technology transfer. The receiving site inherits the obligation to have this knowledge, not an excuse for lacking it. “It came to us this way” answers nothing in an inspection.
New products and legacy products converge on the same Stage 3 destination regardless of route. Once the current process is judged qualified, whichever path got you there, statistical process monitoring runs the same way going forward. The difference is entirely in how much of Stage 1 and Stage 2 has to be reconstructed from history rather than planned in advance.
Traditional Batch Validation vs Continuous Manufacturing Under ICH Q13
Everything above assumes a batch process: discrete, defined-size batches move through unit operations in sequence, and each batch earns its own PPQ run and its own point on the Stage 3 chart. Continuous manufacturing (CM) links multiple unit operations into one ongoing process, and several lifecycle concepts have to be rethought rather than simply reused.
ICH Q13, Continuous Manufacturing of Drug Substances and Drug Products, is a finalized ICH guideline that FDA adopted as final guidance in 2023, and it carries equivalent standing across the other ICH regions. It covers both small-molecule and biologic products, both new products developed for CM from the start and existing batch processes converted to CM, and it sets out the scientific and regulatory considerations specific to running a process this way. It does not replace the three-stage lifecycle; it adapts what each stage means when material never stops moving.
| Concept | Traditional batch process | Continuous manufacturing under ICH Q13 |
|---|---|---|
| Batch definition | A discrete quantity from one manufacturing cycle, bounded by the equipment charge | Defined by a specified quantity of input material, output material, or run time; the definition itself is part of the control strategy and has to be justified |
| Process dynamics | Each unit operation is largely independent; material sits between steps | Material moves continuously between connected unit operations; residence time and material traceability through the system become control points in their own right |
| Release testing | End-product testing is the default release path; real-time release testing is possible but not universal | Real-time release testing, testing and monitoring performed during processing rather than solely on the finished product, is a central design feature |
| Qualification runs | A justified number of full-scale batches run consecutively | Runs demonstrate the process across its intended state of control, including startup, steady state, and shutdown, and how material is diverted during those transitions |
| Stage 3 monitoring | Batch-by-batch control charts and periodic capability review | Continuous, often in-line data streams monitored close to real time; the control strategy has to define how a detected excursion triggers diversion or a stop |
| Control strategy emphasis | CQA and CPP ranges plus finished-product testing | Adds material traceability, residence time behavior, and a defined response to process disturbances without stopping the whole line |
The underlying Stage 1, 2, and 3 logic does not disappear under CM. CQAs are still CQAs, CPPs are still CPPs, and a control strategy still ties them together. What changes is the unit of qualification, a system demonstrated to hold a state of control rather than a fixed-size batch, and the intensity of in-line monitoring that Stage 3 leans on. For a site converting an existing batch process to CM, ICH Q13 anticipates that path directly and expects a comparability assessment between the batch and CM versions rather than a from-scratch revalidation, provided equivalence is actually demonstrated. Where a digital process model sits behind that in-line monitoring, see digital twins across the process lifecycle for how such a model itself gets verified and governed.
How the Stages Connect to Change and Lifecycle Management
A validated process is not frozen. Raw material sources change, equipment is replaced, sites are added, yields are optimized. Each of these is handled through change control, and each must be assessed against the qualified state from Stage 2 and the understanding from Stage 1. The question is always: does this change affect a CQA, a CPP, or the control strategy, and if so, what level of revalidation does it require?
ICH Q12 (Technical and Regulatory Considerations for Pharmaceutical Product Lifecycle Management, finalized in 2019) gives tools for managing post-approval changes with less regulatory friction, including Established Conditions and the Post-Approval Change Management Protocol. A mature Stage 1 knowledge base and a defined design space are what make those tools usable, because they let a company show in advance which parameters can move without affecting quality. The connection is covered in ICH Q12 lifecycle management. Revalidation triggers, the criteria for when Stage 2 must be repeated in whole or in part, should be written down before they are needed, not improvised when a change lands.
A simple revalidation decision aid, which belongs in a site procedure rather than in someone’s head:
| Change | Likely impact | Typical validation response |
|---|---|---|
| New supplier for a critical raw material | Possible CQA or CPP effect | Risk assessment plus at-scale confirmation runs, often a partial PPQ |
| Like-for-like replacement of a qualified unit operation skid | Equipment only | Requalification (IQ/OQ/PQ) of the skid; process impact assessed |
| Scale increase (larger batch) | Mixing, heat, mass transfer change | Full or partial PPQ at the new scale |
| Tightening an in-process control limit | Reduces risk | Usually assessment only, documented, no new runs |
| New manufacturing site | Everything | Full technical transfer plus full PPQ at the new site |
That table gives the general pattern. Reduced to a decision gate, the logic a validation lead applies to an actual change request looks like this:
There is no branch marked "run it and see." A change that has not been through this gate has not been assessed, whatever the change control record says.
Roles and Responsibilities
Validation is a team activity, and inspectors expect clear ownership. A workable split:
| Role | Primary responsibility in the lifecycle |
|---|---|
| Process development / MSAT | Owns Stage 1 understanding, CQA/CPP definition, DoE, and the control strategy; leads scale-up and the technical content of PPQ |
| Manufacturing / Operations | Executes qualification and routine production exactly as the protocol and batch record specify; raises deviations |
| Quality Assurance | Approves protocols and reports before and after execution; owns acceptance criteria, deviation disposition, and the validated-state decision |
| Quality Control / Analytical | Runs the enhanced testing, owns the methods, ensures methods are validated and instruments qualified |
| Validation / Engineering | Owns equipment and utility qualification (IQ/OQ/PQ) and the validation master plan |
| Statistics / data science | Designs the DoE, sets control limits and capability targets, builds and interprets the Stage 3 monitoring |
| Regulatory Affairs | Owns the submission content (Module 3), commitments, and the design-space and Established-Conditions strategy |
The one boundary that is never negotiable: QA approves acceptance criteria before execution and makes the final call on whether the process is validated. Manufacturing and development can recommend; QA decides. Roles across the quality system are mapped in GxP roles and responsibilities.
Common Process Validation Failures
These are the patterns that recur in inspection findings and warning letters across the industry, grouped by the stage where they usually originate. None are exotic; most come from treating validation as paperwork rather than evidence.
Stage 1 findings
Knowledge gaps carried into qualification. Qualification runs attempted on a poorly characterized process, leading to Stage 2 failures nobody could anticipate because the cause-and-effect relationships were never established. The fix is upstream, in development, not in re-running batches.
Criticality reverse-engineered after the fact. A CQA or CPP list assembled to match whatever the Stage 2 data happened to show, rather than documented from a development-stage risk assessment and DoE before qualification began. An inspector who asks for the dated risk assessment and finds none, or finds one written after the PPQ report, reads this as bordering on a data integrity concern, not just a documentation gap.
A claimed range that outruns the data. A proven acceptable range or design space stated in the marketing application wider than what the characterization studies actually tested. The boundary a company can defend is the boundary it studied, not the boundary it hopes is safe.
Stage 2 findings
Protocol not approved before execution. A frequent inspection finding. The protocol defines the acceptance criteria, and criteria written after the data are seen are not acceptance criteria.
Batches not truly consecutive. Cherry-picking passing batches from a larger set, or running undisclosed batches between the chosen ones. This crosses from a validation weakness into a data integrity problem.
Number of runs unjustified. A protocol that says “three batches” with no rationale tied to process variability or risk. Inspectors increasingly ask why three, and “industry standard” is not an answer the 2011 guidance supports.
OOS results handled poorly during validation. An out-of-specification result during PPQ that is invalidated without a proper investigation undermines the whole conclusion. Handle these through a sound OOS investigation process, the same way you would in routine production.
Concurrent release used as a default, not an exception. Releasing every PPQ batch concurrently as a matter of course, with no per-batch documented risk-based rationale, turns a narrow, justified allowance into an unexamined habit.
Stage 3 findings
No Stage 3 program. PPQ completed and then no statistical process monitoring at all. The process is “validated” on paper but has no ongoing assurance of control. Lack of continued process monitoring has been cited as a GMP deficiency.
Control limits equated with specification limits. Stage 3 charts drawn with specification limits as the action lines, so the early-warning function is lost and the program only reacts to outright failures.
Limits set once and never revisited. Control limits calculated from three PPQ batches, still in use years into commercial production with no re-evaluation as real data accumulate, so the chart stops reflecting the process it is supposed to be watching.
Annual review disconnected from monitoring. A review that aggregates data without statistics, trend identification, or comparison to control limits is not fulfilling its Stage 3 purpose.
Cross-stage findings
Revalidation triggers undefined. No documented decision point for when requalification is needed, so significant changes accumulate and validation data quietly goes stale.
A legacy process running on inherited assumptions. A product operated for years with no documented Stage 1 rationale and no plan to build one, discovered only when a change or an inspection forces the question. The legacy-process approach described above is the answer, built before the moment forces it, not after.
Interview-Ready: Questions and How to Answer
These are the questions an interviewer or an inspector tends to ask on this topic. Short, correct, confident answers matter more than long ones.
“Walk me through the three stages of process validation.” Stage 1 process design builds process understanding (CQAs, CPPs, control strategy) during development. Stage 2 process qualification proves the commercial-scale process performs consistently, including equipment qualification and PPQ. Stage 3 continued process verification monitors the process statistically for the life of the product to confirm it stays in control. Name the FDA 2011 guidance and ICH Q8/Q9/Q10 as the framework.
“How many PPQ batches do you need?” Enough to demonstrate consistent performance and give a statistically meaningful conclusion. The 2011 guidance deliberately does not set a number. Three is common for a well-characterized process; a novel or variable process may need more. The protocol must justify the number, not recite habit.
“What is the difference between a specification limit and a control limit?” Specification limits come from the registered application and protect the patient; a breach is an OOS. Control limits are calculated from the process’s own data and protect the process; they are usually tighter, and a breach is an out-of-trend signal that triggers investigation before a failure occurs.
“What is the difference between a CQA and a CPP?” A CQA is a property of the product that must be controlled for quality, safety, or efficacy. A CPP is a process input whose variation affects a CQA and therefore must be controlled. CPPs are identified by risk assessment and confirmed by DoE; they exist to keep CQAs in range.
“Common cause versus special cause variation?” Common cause is the inherent random variation of a stable process, reduced only by redesigning the process. Special cause comes from an identifiable, correctable source and produces a signal on the chart. Reacting to common cause as if it were special cause (tampering) makes the process worse.
“What does a Cpk of 1.33 mean, and why does it matter?” It means the process mean sits at least four standard deviations from the nearer specification limit, a common minimum expectation for a commercial process. It only has meaning on a stable process; computing it on an out-of-control process is meaningless. A falling Cpk is a drift signal even before any batch fails.
“What triggers revalidation?” A change that affects a CQA, a CPP, or the control strategy, assessed through change control. The triggers should be written down in advance. Examples: new critical material supplier, scale change, new site, equipment change affecting process performance.
“How do you handle a deviation during a PPQ run?” Investigate to root cause, assess the impact on the validity of that run honestly, and document the disposition. A deviation does not automatically void the run, but carrying a serious unexplained deviation forward is worse than declaring the run invalid and repeating it.
“Where does process validation live in a marketing application?” CTD Module 3, mainly 3.2.P.3.3 (manufacturing process and controls) and 3.2.P.3.5 (process validation and evaluation), with development content in 3.2.P.2.
“How would you validate a process for a product that has been on the market for years with a thin Stage 1 package?” Reconstruct what you can from development reports, tech transfer records, and accumulated commercial batch history, then run a documented risk assessment naming the actual gaps. Commercial history is legitimate Stage 3 grade evidence but not a substitute for a prospective PPQ that was never done. Close real gaps with a scoped, justified confirmatory PPQ rather than repeating the whole lifecycle from scratch.
“What is ICH Q13 and how does it change process validation?” Q13 is the finalized ICH guideline for continuous manufacturing, adopted by FDA as final guidance in 2023. It keeps the CQA, CPP, and control strategy logic of the three-stage lifecycle but redefines the unit of qualification: a continuously connected process demonstrated to hold a state of control, including startup, steady state, and shutdown, rather than a fixed-size batch. Real-time release testing and material traceability through the system become central control elements.
“How do you score whether an attribute is a CQA?” Rate severity, the consequence if the attribute drifts out of range, and probability of occurrence, how likely that drift is given current process knowledge, each on a defined scale, and multiply them into a risk score against a pre-set threshold. Document the rationale for every attribute, including the ones that land below the CQA threshold, because the assessment itself gets inspected, not just its conclusion.
“How is Stage 3 different for a cell therapy than for a small-molecule tablet?” Classical control charting assumes enough comparable batches to say something statistically. Autologous cell therapy batches are inherently n equals one, made from a different patient’s starting material each time, so a standard control chart mixes patient variability into what looks like a process signal. Programs adapt by trending process parameters more than final potency, leaning on tightened in-process and release controls, and tracking success rate across patients as the ongoing signal.
“What decides whether a change gets a full or a partial revalidation?” How much of the control strategy it touches. A change inside the proven acceptable range with no new CQA at risk is usually assessment-only. A change confined to one or a few CPPs in a single unit operation is usually a partial revalidation scoped to what changed. A change to the design space, the site, the scale, or a new unit operation is a full revalidation, treated as a new PPQ.
Regulatory Submission Requirements
For a BLA, NDA, or MAA, process validation information sits in CTD Module 3, principally section 3.2.P.3.3 (Description of Manufacturing Process and Process Controls) and section 3.2.P.3.5 (Process Validation and/or Evaluation), with supporting development content in 3.2.P.2. A typical package includes:
- A summary of process development work (Stage 1)
- The PPQ protocol and report, or a justified commitment for post-approval PPQ
- A description of the Stage 3 continued process verification program
- Statistical analysis of the PPQ batch data
For expedited development pathways such as Breakthrough Therapy and Accelerated Approval, FDA’s 2011 guidance acknowledges that full PPQ may not be complete at the time of initial licensure. A reliable process monitoring program plus a commitment to provide additional validation data after approval can be agreed with the agency, but the bar for justification is high and the post-approval commitments are tracked and enforced.
One expectation is worth stating plainly for readers moving from clinical to commercial work. The standard for commercial-scale process validation is higher than for clinical manufacturing. Product for early clinical trials is made under appropriate GMP, but the process characterization, statistical rigor, and continued verification expected for a commercial license are substantially more extensive. Treating a Phase 1 process record as if it were a commercial validation package is a predictable way to draw findings. For the surrounding inspection expectations, see FDA inspection readiness and the submission structure in eCTD submission architecture.
Practical Tips
- Write the revalidation triggers into a procedure before you need them. The worst time to decide whether a change needs a new PPQ is while the change is already on the floor.
- Carry forward the soft signals. If a CQA drifts inside specification during PPQ, name it in the report and hand it to the Stage 3 plan. Do not let a “pass” hide a pattern.
- Keep the acronyms clean. PQ (equipment) and PPQ (process) are different activities; CQA, CPP, and key parameter are different tiers. Sloppy terminology in a protocol invites reviewer questions.
- Make Stage 1 transferable. The test of a development package is whether a technical transfer team can run the process from it without phoning the original scientists.
- Let the statistics drive the conversation. A control chart that shows a centered, stable process is a stronger validation story than a table of passing results, and it is the kind of evidence inspectors find persuasive.
- Tie every control back to a reason. For each in-process control and CPP range, be able to point to the study or rationale that justifies it. “That is what we have always run” is the answer that draws a finding.
- Score criticality with a documented method, not a conversation. A severity-times-probability table with a stated threshold survives an inspector’s question about why an attribute is or is not a CQA; a remembered discussion does not.
- Treat a legacy product’s batch history as an asset to mine, not a validation to declare. It tells you where the process actually sits; it does not replace the prospective protocol that was never run.