Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Risk Assessment Plug-and-play starting point Quality Assurance

Risk Assessment: Technology Transfer Scope and Criticality

A plug-and-play risk assessment that scopes a technology transfer before the protocol is written: change-driver identification, CQA/CPP-level severity-probability-detectability scoring per sending-versus-receiving difference, the requalification-depth decision, and the analytical-transfer-option rationale per method, with a filled specimen.

Document type: Risk Assessment

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use risk assessment that scopes a technology transfer before the protocol is written. It identifies what actually changed between the sending and receiving unit, scores the risk of each change against the product’s critical quality attributes and critical process parameters, and produces two defensible outputs the protocol then inherits: how much requalification each part of the transfer needs, and which analytical transfer option applies to each method. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through document control. A worked filled specimen follows the template. This is general guidance to adapt and verify, not legal or regulatory advice; confirm each cited regulation against the current source before you rely on it.

Document control header

FieldEntry
Document titleTechnology Transfer Risk Assessment
Document number<<FILL: ID, e.g. RA-TT-004-01>>
Version<<FILL: version>>
Effective / assessment date<<FILL: date>>
Product / process<<FILL: name, dosage form or modality, strength(s)>>
Sending unit<<FILL: site, function>>
Receiving unit<<FILL: site, function>>
Transfer type<<FILL: R&D-to-GMP / site-to-site / CDMO-to-CDMO / internal line change / other>>
Assessment owner<<FILL: role, e.g. Technical Transfer Lead>>

1. Purpose and methodology

This assessment identifies every material difference between the sending and receiving unit, scores the risk each difference poses to the product’s critical quality attributes (CQAs) and critical process parameters (CPPs), and uses that scoring to scope the transfer protocol: what needs a study, what needs a demo batch, what needs full process performance qualification (PPQ), and what can be managed by verification alone. It also scopes the analytical transfer, method by method. The method follows ICH Q9(R1) quality risk management, applied specifically to the change-drivers a transfer introduces (site, scale, equipment, facility, materials, analysts, methods). Severity is weighted most heavily because it is the patient-facing dimension. This assessment is written and approved before the transfer protocol; it is an input to the protocol, not a retrospective justification of decisions already made.

Assessment team: <<FILL: names and roles, at minimum process SME/MSAT, analytical SME/QC, Quality Assurance from both sending and receiving units>>.

2. Change-driver identification

Mark every dimension where the receiving unit differs from the sending unit. A “No” answer still needs a one-line basis; do not leave a row blank.

Change driverDifferent at receiving unit? (Y/N)Nature of the differenceBasis / evidence
Site / facility<<FILL>><<FILL>><<FILL>>
Scale<<FILL>><<FILL>><<FILL>>
Equipment (make, model, class)<<FILL>><<FILL>><<FILL>>
Raw materials / components / suppliers<<FILL>><<FILL>><<FILL>>
Analysts / operators (training baseline)<<FILL>><<FILL>><<FILL>>
Analytical methods / instrumentation platform<<FILL>><<FILL>><<FILL>>
Reference standards<<FILL>><<FILL>><<FILL>>
Quality system / procedures<<FILL>><<FILL>><<FILL>>
Regulatory filing status at receiving unit<<FILL>><<FILL>><<FILL>>

3. CQA/CPP risk scoring

3.1 Scoring scales

Severity (S), the consequence to the CQA if this difference is not managed:

ScoreMeaning
5Direct risk to a CQA tied to safety or efficacy; a miss could reach a patient
4Significant risk to a CQA, likely caught by in-process or release testing before release
3Moderate risk to a CPP or non-critical quality attribute, contained within the process
2Minor, indirect effect; no direct CQA link
1Negligible; documentation or administrative only

Probability (P), the likelihood the difference actually produces an effect given no additional control:

ScoreMeaning
5Known mechanism by which this difference affects the CQA; prior experience elsewhere confirms it
3Plausible mechanism, not yet demonstrated one way or the other at this scale/site
1No credible mechanism identified; difference is cosmetic or administrative

Detectability (D), how readily an adverse effect would be caught before it reaches a released batch (higher score = harder to detect):

ScoreMeaning
5Would not be detected by existing in-process controls, release testing, or the demo-batch design
3Detectable by routine release testing or in-process control, but not by a dedicated study
1Directly and specifically tested by a planned demo batch, comparative-testing study, or equivalence assessment

Risk priority: High if S is 4 or 5 and either P or D is 3 or higher; Medium if S is 3, or S is 4/5 with both P and D low; Low if S is 1 or 2.

3.2 CQA/CPP risk table

CQA or CPP affectedChange driver(s) involvedSPDRisk priorityRequired control before demo/PPQ
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL: study / demo-batch endpoint / equipment-equivalence closure / analytical comparison>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

4. Requalification-depth decision

Using the risk table above, assign a requalification tier to the overall process transfer. This is a documented judgment, not a default; state the rationale, not just the tier.

TierCriteria to select itSelected?
Full PPQAny High-priority row remains, or the site/scale/equipment change is materially new to the receiving unit<<FILL: Y/N>>
Bridging / reduced qualificationAll rows are Medium or lower after controls, with strong prior knowledge of the equipment class and scale at the receiving unit<<FILL: Y/N>>
Verification onlyAll rows are Low, or Medium rows are fully closed by equipment-equivalence and analytical-comparison evidence with no residual CQA risk<<FILL: Y/N>>

Tier selected: <<FILL>>. Rationale: <<FILL: tie the tier directly to the risk table, not to schedule or cost>>.

5. Analytical transfer option per method

For each method transferring, select the USP <1224> option and state why, using the risk table as the basis (a method touching a High-priority CQA row should default toward comparative testing or revalidation, not a waiver).

MethodCQA/attribute it measuresRisk priority (from section 3)Option selectedRationale
<<FILL>><<FILL>><<FILL>><<FILL: comparative testing / co-validation / revalidation / transfer waiver>><<FILL>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

6. Residual risk and acceptance

ItemEntry
High-priority rows with no planned control<<FILL: list, or "none">>
Residual risk statement<<FILL: what remains after the controls above, in plain language>>
Conditions attached to acceptance<<FILL: e.g., no PPQ batch release until the demo-batch endpoint study is closed>>
Re-assessment trigger<<FILL: e.g., any demo batch deviation reopens this assessment before PPQ>>

Any High-priority row with no planned control is not acceptable; either add a control (a study, a tighter demo-batch design, an additional analytical comparison) or escalate for a documented risk-acceptance decision by Quality Assurance from both units, recorded here, not implied by silence.

7. References

ICH Q9(R1), Quality Risk Management. ICH Q10, Pharmaceutical Quality System, Section 3.2.3 (technology transfer as a lifecycle stage). ICH Q7, Good Manufacturing Practice Guide for Active Pharmaceutical Ingredients, Section 12.5 (process validation and revalidation). WHO Technical Report Series, No. 961, 2011, Annex 7, WHO guidelines on transfer of technology in pharmaceutical manufacturing. USP General Chapter <1224>, Transfer of Analytical Procedures. FDA Guidance for Industry, Process Validation: General Principles and Practices (2011).

Confirm the current version and clause numbers of each reference before issue.

8. Approval

RoleNameSignatureDate
Assessment owner (Technical Transfer Lead)<<FILL>>
Process SME<<FILL>>
Analytical SME (QC)<<FILL>>
Quality Assurance, sending unit<<FILL>>
Quality Assurance, receiving unit<<FILL>>

Filled specimen

Illustrative, for a lyophilized small-molecule injectable moving from a development pilot plant to a commercial fill-finish site, scale increasing from a 20 L to a 200 L formulation batch.

Change drivers: Site (Y, different building and quality system), Scale (Y, 10x formulation volume), Equipment (Y, different lyophilizer, larger shelf area), Materials (N, same suppliers and grades), Analysts (Y, new site, new training baseline), Analytical methods (Y, HPLC assay moving to a different column lot supplier), Reference standards (N, same lot in use), Quality system (Y, different site procedures), Regulatory filing (Y, site change requires a variation).

CQA/CPP risk table (excerpt):

CQA or CPPChange driver(s)SPDPriorityRequired control
Moisture content (lyo cycle endpoint)Scale, equipment553HighCycle re-development study; moisture data from at least 2 demo batches before PPQ
Reconstitution timeScale, equipment433HighConfirmed by demo-batch testing against the registered limit
Assay (HPLC)Analytical methods431Medium (D lowered by planned comparison)Comparative testing per section 5
Container closure integrityEquipment (stoppering)511Medium (P and D low; established platform)Routine CCIT per existing program, no additional study
Batch record formattingQuality system111LowNone beyond normal document control

Requalification-depth decision: Full PPQ selected. Rationale: moisture content and reconstitution time are High priority off a materially different lyophilizer and a 10x scale change, both directly CQA-linked with no strong prior knowledge at this scale.

Analytical transfer option: Assay (HPLC), Medium priority after the planned comparison, comparative testing selected as the default, three lots, two analysts per lab. Container closure integrity test, Low priority given an established platform method already qualified at the receiving site, transfer waiver selected with reference to the existing CCIT qualification record.

Residual risk: No High-priority row lacks a planned control. Condition attached: PPQ batches cannot start until the lyophilization cycle re-development study and at least two demo batches confirm moisture content within the registered range. Re-assessment trigger: any demo batch moisture or reconstitution result outside the expected range reopens this assessment before a third demo batch or PPQ is scheduled.

Common inspection findings this assessment prevents

  • A transfer protocol whose acceptance criteria and batch counts cannot be traced back to any documented risk judgment, so scope looks arbitrary or schedule-driven.
  • “Full PPQ” or “no revalidation” chosen without a stated basis, so the decision cannot be defended when questioned.
  • An analytical transfer option (especially a waiver) applied to a method tied to a High-risk CQA with no justification connecting the option to the risk.
  • A risk assessment performed after the protocol was already written, so it reads as a retrospective rationalization rather than a scoping input.
  • High-priority rows left with no control and no documented risk acceptance.

How to adapt this assessment

  1. Set your document number and link it explicitly as an input to your transfer protocol, referenced by number in the protocol’s risk assessment section.
  2. Keep the S/P/D scales aligned with your quality system’s existing risk model if you have one; the scales here are a standalone default.
  3. Populate the CQA/CPP list from your product’s actual control strategy (development report, or reconstructed from the master batch record and specifications for a legacy product).
  4. Do not pre-fill the requalification tier or the analytical option before the risk table is complete; the table has to drive the decision, not the other way around.
  5. Confirm every regulation in section 7 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.