EU GMP Annex 1 (2022) sets pre-use, post-sterilization integrity testing (PUPSIT) as the expectation for the final product sterilizing filter, and requires that any decision not to perform it be supported by a documented risk assessment. This document is that assessment: it identifies the flaw-masking hazard PUPSIT addresses, scores the factors that determine whether a post-use test alone is sufficient, records the decision and its rationale, and states the residual risk. Replace every <<FILL: ...>> placeholder, run the assessment with a cross-functional team, and route it through document control. A filled specimen follows. This is educational reference content, not regulatory advice; confirm the current text of Annex 1 and any cited guidance before you rely on it.
Why this assessment exists (regulatory basis)
PUPSIT addresses a specific mechanism: a filter with a small pre-existing defect after sterilization could, during the filtration run, have that defect plugged by product components or by the bioburden the filter is removing, so the post-use integrity test at the end of the run passes even though the filter let organisms through earlier in the run. Testing the filter’s integrity after sterilization but before use closes that gap directly. EU GMP Annex 1 (2022) addresses filter integrity testing and PUPSIT in its filtration provisions (section 8, commonly referenced around paragraph 8.87 in the published text) and states that PUPSIT should normally be performed, with any decision to omit it justified by risk assessment. PDA Technical Report No. 80 lays out an accepted framework for building that assessment, covering the flaw-masking mechanism, the product and process factors that make it more or less likely, and the contamination risk PUPSIT itself introduces. This document follows that framework in original wording; it does not reproduce the Annex 1 text or the PDA report beyond brief, attributed reference.
Document control header
| Field | Entry |
|---|---|
| Assessment title | PUPSIT Decision, <<FILL: product / filter / line>> |
| Document number | <<FILL: RA-ID>> |
| Version / date | <<FILL>> |
| Feeds | <<FILL: filter validation protocol ID; Contamination Control Strategy ID>> |
| QRM method | Risk-factor scoring adapted for the PUPSIT flaw-masking hazard |
| Team (cross-functional) | <<FILL: Filtration/Validation SME, Manufacturing, Microbiology, QA, Facilities/Engineering>> |
1. Scope
This assessment covers the decision whether to perform PUPSIT on the final sterilizing filter for <<FILL: product / process / line>>. It applies to <<FILL: single-use assembly / fixed housing; filter make and model>>. It does not cover the filter’s bacterial retention or chemical compatibility validation, which are addressed in <<FILL: filter validation protocol ID>>, and it does not cover redundant-filter decision logic beyond how redundancy is used here as a PUPSIT risk mitigation.
2. Scoring scales
State the scales explicitly so scoring is reproducible.
Flaw-masking potential (F), likelihood the product/bioburden combination could plug a small pre-existing defect during the run:
| Score | Meaning |
|---|---|
| 1 | Low: clear, low-viscosity, low-particulate product; well-controlled low bioburden feed |
| 2 | Moderate: some particulate or viscosity, moderate bioburden control |
| 3 | High: particulate-bearing, high-viscosity, or poorly characterized bioburden feed |
Post-use test strength (T), confidence the post-use integrity test alone would detect a defect of concern:
| Score | Meaning |
|---|---|
| 1 | High: validated method, correct wetting-fluid limit, correlation margin well characterized |
| 2 | Moderate: validated but with limited correlation margin or an unusual wetting condition |
| 3 | Low: method validation gaps, uncharacterized wetting-fluid limit, or new filter/product combination |
Bioburden control (B), reliability of low, monitored bioburden ahead of the filter:
| Score | Meaning |
|---|---|
| 1 | Strong: closed system, validated hold times, routine bioburden monitoring within the level the bacterial challenge validated against |
| 2 | Moderate: open steps present but controlled, periodic monitoring |
| 3 | Weak: open manual steps, extended or unvalidated hold, limited monitoring |
PUPSIT manipulation risk (P), contamination risk PUPSIT itself would add to this specific setup:
| Score | Meaning |
|---|---|
| 1 | Low: closed automated test rig, sterilized test gas, redundant downstream filter, or other engineering control in place |
| 2 | Moderate: manual manipulation with partial engineering controls |
| 3 | High: manual manipulation with no redundant protection, in an open or high-risk environment |
3. Risk factor assessment table
| Factor | Score (1 to 3) | Rationale | Evidence source |
|---|---|---|---|
| Flaw-masking potential (F) | <<FILL>> | <<FILL>> | <<FILL: product characterization, filterability data>> |
| Post-use test strength (T) | <<FILL>> | <<FILL>> | <<FILL: integrity correlation study reference>> |
| Bioburden control (B) | <<FILL>> | <<FILL>> | <<FILL: EM/bioburden trend data>> |
| PUPSIT manipulation risk (P) | <<FILL>> | <<FILL>> | <<FILL: engineering control description>> |
Combined interpretation: <<FILL: e.g. "F and T both scoring 1, with B at 1 or 2, supports a case for PUPSIT omission; any factor scoring 3 defaults the assessment toward performing PUPSIT unless the specific concern is separately and fully mitigated.">>. State the decision rule your quality system applies before scoring, not after, so the outcome is not reverse-engineered to match a preference.
4. Decision
| Field | Entry |
|---|---|
| Decision | <<FILL: Perform PUPSIT / Omit PUPSIT with documented rationale>> |
| Rationale summary | <<FILL: two to four sentences tying the decision to the scores above>> |
| Engineering controls relied upon (if PUPSIT performed) | <<FILL: redundant downstream filter, sterilized test gas, closed rig>> |
| Compensating controls relied upon (if PUPSIT omitted) | <<FILL: enhanced bioburden monitoring, tightened integrity correlation margin, redundant filtration>> |
5. Mitigations and actions
| Action ID | Factor addressed | Action | Owner | Due | Status |
|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
6. Residual risk statement and acceptance
State the residual flaw-masking risk remaining after the decision and any mitigations, and record who accepted it and on what basis. An omission decision with no residual risk statement is incomplete.
Residual risk summary: <<FILL>>. Accepted by: <<FILL: risk authority / Quality Head>>.
7. Acceptance criteria
- The flaw-masking mechanism is described in the assessment’s own terms, not asserted away.
- All four factors are scored with a recorded rationale and a named evidence source, not just a number.
- The decision rule was stated before scoring and applied consistently to the result.
- If PUPSIT is omitted, the assessment explicitly addresses probability of an undetected post-sterilization defect, filterability/particle characteristics, upstream bioburden control, post-use test strength, and whether redundant filtration is in place.
- The decision, its rationale, and the residual risk are approved by Quality Assurance and filed with the filter validation package, referenced from the batch record.
- The assessment carries a review trigger (product, process, filter, or bioburden-control change) and is not treated as permanent.
8. References
EU GMP Annex 1, Manufacture of Sterile Medicinal Products (2022), section 8, filtration and integrity testing (PUPSIT). PDA Technical Report No. 80, Application of Pre-Use Post-Sterilization Integrity Testing (PUPSIT). ICH Q9(R1), Quality Risk Management. FDA Guidance for Industry, Sterile Drug Products Produced by Aseptic Processing, Current Good Manufacturing Practice (2004).
Confirm the current version and clause numbers of each reference before issue.
Filled specimen
An illustrative assessment for a 200 L monoclonal antibody drug product, 0.2 micron PES final filter, closed single-use assembly.
| Factor | Score | Rationale |
|---|---|---|
| Flaw-masking potential (F) | 1 | Clear, low-particulate mAb bulk after depth filtration; bioburden feed well characterized and consistently low based on 24 months of trend data |
| Post-use test strength (T) | 1 | Diffusive flow method validated against a three-lot bacterial retention correlation with a defined margin; product-wetted limit established after a validated water flush |
| Bioburden control (B) | 1 | Closed single-use path from depth filtration through the final filter, validated 6-hour maximum hold, routine bioburden monitoring within the qualified challenge level |
| PUPSIT manipulation risk (P) | 1 | Redundant downstream sterilizing filter present in the assembly, protecting the line during a pre-use manipulation |
Decision: Perform PUPSIT. Although the F, T, and B scores would support a case for omission on their own, the site elected to perform PUPSIT because the redundant downstream filter already present in the assembly makes the PUPSIT manipulation risk low (P = 1), removing the main argument against testing. The pre-use test on the upstream filter is protected by the downstream filter; both filters are integrity tested post-use per the validated decision logic.
Residual risk: Low. Both pre-use and post-use testing close the flaw-masking gap directly; the residual risk is limited to a false-negative integrity test result, which is addressed by the correlation margin built into the production limit (see the filter validation protocol). Accepted by the Head of Quality Assurance.
Common inspection findings this assessment prevents
- No PUPSIT and no risk assessment, with the omission simply asserted in the batch record.
- A risk assessment that concludes omission without addressing flaw-masking, bioburden control, post-use test strength, and redundant filtration by name.
- Scoring performed with no evidence source cited, so the conclusion cannot be traced to data.
- A decision rule applied inconsistently, or defined only after the scores were already known.
- No residual risk statement, or a residual risk statement with no named acceptor.
- An assessment never revisited after a product, process, filter, or bioburden-control change.
How to adapt this assessment
- Set the scales to match your quality risk management procedure so a “3” means the same to every scorer.
- Score all four factors with a named evidence source; do not let the desired outcome drive the score.
- Fix the decision rule before scoring, and apply it the same way every time.
- If you omit PUPSIT, name the compensating controls explicitly and carry them into routine monitoring, not just this document.
- Put the assessment under change control with a defined review trigger, and confirm the Annex 1 and PDA references against the current published text before issue.