IQ (Installation Qualification) proves a system was installed correctly, OQ (Operational Qualification) proves it operates across its range, and PQ (Performance Qualification) proves it performs consistently in real use – each with its own documented protocol. Together they form the validation chain FDA/cGMP expects for a process system.
IQ vs OQ vs PQ
| Stage | What it verifies | Example |
|---|---|---|
| IQ | Installed per design and specs | Correct components, materials, calibration, utilities connected |
| OQ | Operates across its full range | Alarms, controls, and setpoints work at limits |
| PQ | Performs consistently in real use | Repeatable results over multiple runs under production conditions |
Documentation requirements
Each stage requires an approved protocol, executed results, deviations and their resolution, and a final report. The system also needs supporting records – material certs, weld logs, calibration, and P&IDs – that IQ references. Missing documentation is the most common reason qualification stalls.
Related: Validation & commissioning · IQ OQ PQ explained · What is process validation · Request a quote
Frequently asked questions
What are the requirements for IQ OQ PQ documentation?
A compliant IQ/OQ/PQ package requires approved protocols with pre-defined acceptance criteria, executed and signed test records, calibration certificates, material and weld documentation, as-built drawings, deviation handling, and a final summary report. Every result must be traceable, contemporaneous, and reviewed by quality before approval.
What must an IQ protocol include to be compliant?
An Installation Qualification protocol must document equipment identification, utilities and connections, materials of construction, instrument calibration status, required manufacturer documentation, drawings, and installation verification against design. Each item needs a defined acceptance criterion and a place to record the verified result and reviewer signature.
What are the documentation requirements for good documentation practice?
cGMP documentation must be attributable, legible, contemporaneous, original, and accurate, the ALCOA principles. That means signed and dated entries made at the time of the activity, no back-dating, corrections struck through rather than erased, and a clear audit trail. These practices apply to every executed qualification record.
Do we need user requirement specifications before qualification?
Yes. A User Requirement Specification (URS) defines what the system must do and becomes the reference qualification tests trace back to. Without a URS and design specifications, acceptance criteria have no documented basis, which is a common audit gap. The URS is typically the first controlled document in the package.
What calibration records are required for OQ?
Operational Qualification requires that every instrument used to make a pass/fail decision, and every critical instrument on the system, has a current calibration traceable to a recognized standard. Calibration certificates are attached to the package, and out-of-tolerance instruments must be addressed before the affected tests are considered valid.
How many PQ runs are required?
There is no universal fixed number; the requirement is enough consecutive successful runs to demonstrate consistency, justified by risk. Water-system PQ commonly uses a multi-phase sampling program spanning weeks. The count must be pre-defined in the protocol and scientifically justified rather than chosen arbitrarily.
What acceptance criteria are required in a protocol?
Criteria that are measurable, pre-approved and tied to a rationale, rather than written after the data arrives. Each test needs a stated expected result with a tolerance, the instrument and its calibration status, the sampling locations with a justification for why those are worst case, and a defined handling route for deviations. The failure that surfaces at inspection is an acceptance criterion adjusted retrospectively to match an observed result, which invalidates the exercise regardless of how good the system is.
What signatures and approvals does a qualification package need?
At minimum the author, a technical reviewer, and your quality unit, with quality approval required before execution begins rather than after. Executed protocols then need the executor and date on each step, review of the raw data rather than only the summary, formal disposition of every deviation, and a final approval that explicitly states the system is fit for its intended use. Where a contractor executes, your quality unit still approves and releases; that cannot be delegated.
What material and weld documentation is required for high-purity systems?
High-purity piping qualification requires material test reports for tubing and components, weld logs, weld maps, coupon or borescope inspection records, and passivation certificates. This traceability proves the wetted path meets ASME BPE surface-finish and material requirements and supports the IQ record.
How are deviations required to be handled during qualification?
Any result outside acceptance criteria must be recorded as a deviation, investigated for root cause, assessed for impact, and formally resolved before qualification is completed. The deviation, its resolution, and any re-testing become part of the permanent package so an auditor sees the full history.
What is required to close out a qualification project?
Closeout requires all protocols executed, all deviations resolved, calibration and material documentation attached, and a final summary report that references every protocol, states the conclusion, and is approved by quality. Only then is the system considered qualified and released for its intended cGMP use.
Are electronic qualification records required to meet 21 CFR Part 11?
If qualification data is captured or stored electronically, those records and any electronic signatures must meet 21 CFR Part 11 expectations: access controls, audit trails, and secure, attributable records. Paper-based execution must still meet ALCOA data-integrity principles. Paul Industries structures documentation to withstand audit scrutiny. Call 201-450-8280.
What documentation is required when requalifying after a change?
Requalification requires a documented change assessment identifying which IQ, OQ, or PQ elements are affected, protocols covering those elements, and a rationale for anything leveraged from the original package. The change control record ties the requalification back to the modification that triggered it.
Who is required to approve qualification protocols before execution?
Protocols must be reviewed and approved prior to execution by the appropriate functions, generally engineering or the system owner and the quality unit. Executing a protocol that was not pre-approved invalidates the results, because acceptance criteria could otherwise be altered after seeing the data.
What are the traceability requirements between design and qualification?
There must be a documented trace from user requirements and design specifications through to the qualification tests that verify them, often shown in a requirements traceability matrix. This proves every requirement was tested and every test maps to a requirement, closing gaps auditors look for.
Can Paul Industries deliver a turnkey IQ OQ PQ package?
Yes. Because Paul Industries designs, fabricates, installs, and validates as one accountable party, it can deliver a complete qualification package, protocols, executed records, supporting certifications, and summary reports, for the systems it builds. Single-source delivery keeps documentation consistent and audit-ready. Call 201-450-8280.
What is the difference between IQ, OQ, and PQ?
Installation qualification documents that what was built matches what was specified: materials and heat numbers against certificates, weld records, slope and drainability, instrument calibration, as-built drawings. Operational qualification demonstrates performance across the full operating range, not just at the design point, for example that sanitization reaches temperature at the furthest point in a loop. Performance qualification proves consistent performance in routine use with actual materials, which for water means the three phase sampling program.
What are the requirements for IQ OQ PQ?
Approved protocols before execution, calibrated instruments traceable to a standard, defined acceptance criteria with a documented rationale, raw data retained rather than only summaries, deviations recorded and dispositioned, and a change control process so that modifications after qualification are assessed rather than absorbed. The requirement most often missed is the last one: unassessed modifications to a qualified system are a recurring inspection finding, and they quietly invalidate the qualification that preceded them.
Which comes first, IQ or OQ?
Installation qualification first, and the sequence matters because the cost of discovery rises sharply at each stage. Gaps found at installation, a wrong heat number, an uncalibrated instrument, a section that does not drain, are cheap to correct while access is still open and crews are on site. The same gaps found during operational or performance qualification mean re-opening a closed system, re-passivating, re-sanitizing and re-sampling, with the qualification program restarted from the affected point.
Do you provide IQ/OQ/PQ support?
Yes, for systems we build and for systems we did not. That includes writing protocols against your templates or ours, executing them, investigating deviations found during execution, and producing the objective evidence, which for a water system means the three phase sampling campaign and for a cleaning system means recovery studies from coupons of your actual contact surfaces. Your quality unit retains protocol approval and release. We state in the quotation which of installation, operational and performance qualification are in scope.
Get IQ/OQ/PQ support
Paul Industries is a single-source supplier, installer, and validator – one accountable partner from design through documented startup. Tell us about your project and we will scope it.
The regulatory basis for each qualification document
IQ, OQ and PQ are industry terminology. None of the three appears by name in 21 CFR Part 211. What the regulation does require is that equipment be suitable, that it be controlled, and that all of it be evidenced in records – and each qualification document exists to satisfy a specific one of those requirements. Knowing which section a document answers to is what turns a protocol from a formality into something an investigator can follow.
| Citation | What the regulation requires | Which document evidences it |
|---|---|---|
| 21 CFR 211.63 | Equipment used in manufacture, processing, packing or holding shall be of appropriate design, adequate size and suitably located for its intended use, cleaning and maintenance | IQ – confirms the installed item matches the specified design, size and location |
| 21 CFR 211.65(a) | Equipment surfaces contacting components or product shall not be reactive, additive or absorptive so as to alter safety, identity, strength, quality or purity | IQ – material certificates, surface finish records and the passivation record |
| 21 CFR 211.67(a) and (b) | Equipment shall be cleaned and maintained at appropriate intervals under written procedures | OQ for the cleaning cycle, plus the maintenance and cleaning procedures referenced by the protocol |
| 21 CFR 211.67(c) | Records shall be kept of maintenance, cleaning, sanitizing and inspection | The qualification package itself, and the cleaning and use log it hands over to |
| 21 CFR 211.68(a) | Automatic, mechanical and electronic equipment shall be routinely calibrated, inspected or checked to a written program | IQ for instrument identification and calibration status; OQ for the control functions |
| 21 CFR 211.68(b) | Controls shall be exercised over computer or related systems to assure that changes are instituted only by authorized personnel, with input and output accuracy verified | OQ for access control, alarm and interlock testing, and data integrity checks |
| 21 CFR Part 11 | Requirements for electronic records and electronic signatures where records are kept electronically | OQ for audit trail, time stamps, record retention and signature controls |
| 21 CFR 211.100(a) | Written procedures for production and process control, designed to assure that products have the identity, strength, quality and purity they purport to possess | PQ – demonstrates the equipment reproducibly supports those procedures |
| 21 CFR 211.182 | A written record of cleaning, maintenance and use shall be kept for each major item of equipment | The turnover deliverable the qualification package establishes |
| 21 CFR 211.188 | Batch production and control records shall document the performance of each significant step | PQ, where qualification runs are executed against the actual batch record |
Two consequences follow from reading the table in that direction. First, a protocol that cites no regulation is testing whatever its author thought of – which is why acceptance criteria drift between vendors and why two IQ packages for the same skid can look nothing alike. Second, several of these obligations are continuing rather than one-off: 211.67(c), 211.68(a) and 211.182 describe records that must go on being kept after qualification closes, so the qualification package should hand over the mechanism, not just the evidence.
What the regulation does not say
Just as useful, and more often got wrong. The three-consecutive-successful-runs convention for PQ is not in 21 CFR 211. It is an industry practice that hardened into an assumption. The FDA’s 2011 process validation guidance is explicit that the number of runs should be justified by an understanding of process variability rather than fixed by convention, which means three runs may be too few for a variable process and unnecessary for a well-characterized one – but either position has to be argued in the protocol rather than asserted.
Likewise, the regulation does not name IQ, OQ or PQ, does not mandate a particular protocol format, and does not require a specific number of sampling points. What it requires is that the approach be written down in advance, followed, and evidenced. ASTM E2500 offers a risk-based verification alternative to the traditional three-document structure, and it is accepted precisely because the regulation specifies outcomes rather than a document set.
