Cleaning validation in US pharmaceutical manufacturing is governed by 21 CFR 211.67, which requires equipment to be cleaned and maintained at appropriate intervals under written procedures covering schedules, methods, equipment and materials – with records kept. The FDA describes the purpose of cleaning validation as demonstrating that a particular cleaning process will consistently clean equipment to a predetermined standard.

Almost everything written on this subject treats cleaning validation as a documentation and analytical exercise. It is that, but it rests on something decided much earlier: you cannot validate the cleaning of a system that was not designed to be cleaned. Paul Industries builds hygienic process systems to be cleanable and validatable, and this page covers both halves – what the regulations require, and what the construction has to deliver for that requirement to be achievable at all.

The regulatory framework

Source What it requires Scope
21 CFR 211.67 Equipment cleaned and maintained at appropriate intervals; written procedures covering schedules, methods, equipment and materials; records kept under 211.67(c) US finished pharmaceuticals – the core requirement
21 CFR 211.63 Equipment suitably located for cleaning and maintenance Design – cleanability is named in the equipment requirement itself
21 CFR 211.65(a) Product-contact surfaces not reactive, additive or absorptive Surface condition, which governs what can be removed from it
21 CFR 211.100(a) Written procedures for production and process control Where your own cleaning limits become binding on you
ICH Q7 (FDA Q7A) Cleaning expectations for active pharmaceutical ingredients API manufacture
EMA / ICH Health-based exposure limits (HBELs) for all products, from allowable daily exposure values EU, and increasingly expected globally
PIC/S Documented evidence that an approved procedure reproducibly removes previous product or cleaning agents below the scientifically set maximum allowable carryover International inspectorates

The word doing the work in the PIC/S definition is “reproducibly”. A single successful clean is not validation. The claim is that the procedure works every time, which is why the number of runs, the worst-case selection and the sampling plan all have to be argued rather than assumed.

The terms you need before reading a protocol

  • MACO – maximum allowable carryover. The quantity of a previous product that may remain without harming the next.
  • HBEL – health-based exposure limit. The toxicologically derived limit that increasingly replaces older arbitrary criteria.
  • ADE / PDE – acceptable or permitted daily exposure. The toxicological figure HBELs are built from.
  • Worst case – the hardest product, the hardest equipment, the hardest location, used to represent a group.
  • Bracketing and grouping – validating a family of products or equipment using representative worst cases rather than every combination.
  • Dirty and clean hold time – how long equipment may sit soiled before cleaning, and clean before use. Both need data.
  • Swab and rinse sampling – direct sampling of a defined area versus analysis of the final rinse.
  • Recovery study – proving the sampling method actually retrieves residue from the surface in question.

The older arbitrary criteria – 10 ppm, or a thousandth of a therapeutic dose – are being displaced by HBELs, because they were never toxicologically derived. A program still resting on them alone should expect questions.

Sampling and analysis

Method What it measures Strength Limitation
Swab Residue on a defined area of a specific surface Reaches worst-case locations directly; gives a per-area result Only samples where you can physically reach – and a recovery study is required per surface type
Rinse Residue in the final rinse from the whole wetted circuit Covers surfaces a swab cannot reach Dilutes; a clean rinse does not prove a clean surface if flow bypassed a region
TOC Total organic carbon as a non-specific indicator Fast, sensitive, good for routine monitoring Non-specific – it does not tell you which organic
HPLC or specific assay A named residue Specific and quantitative Slower and more costly per sample
Conductivity Ionic residue, typically cleaning agent carryover Immediate, inline, cheap Blind to non-ionic residue – see our note on this below
Visual inspection Visible residue Always required; catches gross failure A visually clean surface can still be chemically contaminated

Swab and rinse answer different questions and neither replaces the other. Rinse samples the whole circuit weakly; swabs sample chosen points strongly. A program relying only on rinse results is vulnerable to exactly the locations flow never reached – which is where a poorly designed system fails.

The half nobody writes about: what makes a system validatable

Cleaning validation is normally discussed as a quality exercise. But the ceiling on what any cleaning procedure can achieve was fixed when the system was built, and no protocol, detergent or analytical method raises it. These are the construction decisions that decide whether validation is straightforward or perpetually marginal:

Design factor Why it limits cleaning What good looks like
Dead legs Flow does not sweep them, so cleaning depends on diffusion and time L/D below 2 with the measurement basis stated; zero-static valves at sample and additive points
Drainability A heel that will not drain cannot be cleaned, dried or sterilized Continuous slope, low-point outlets, verified by a witnessed drain test
Velocity Cleaning depends on wall shear, which depends on velocity 5 ft/s minimum in a full line; 10-14 ft/s in upward branches for air removal
Spray coverage A vessel surface the spray never reaches is cleaned by nothing Coverage verified by riboflavin under UV at 365 nm, not assumed from a datasheet
Surface finish Rougher surfaces hold soil and are harder to rinse A stated Ra with measurement records – including welds, not only the shell
Weld quality Internal heat tint, crevices and mismatch are soil traps Orbital welding, purge verified by analyzer, borescoped at a stated percentage
Passivation A free-iron-contaminated or rouged surface is reactive and holds residue ASTM A967 designation named, with an acceptance test
Gasket fit An oversized or misaligned gasket intruding into the bore creates a crevice Correct gasket sizing and controlled assembly

Two consequences follow. First, a cleaning validation that keeps failing at one sample point is usually reporting a construction problem, not a chemistry problem – and changing detergent will not fix it. Second, the cheapest time to solve any of this is at design, when routing can still move. After installation, every item above becomes a modification.

Why conductivity alone is not enough

Final rinse conductivity is the most common inline endpoint and it is genuinely useful – but it measures ions. It is blind to non-ionic organic residue and to microbial contamination, in the same way resistivity is blind to bioburden in a deionization loop. A rinse that reaches feed-water conductivity has demonstrated that ionic cleaning agent has been removed. It has not demonstrated that product residue has. That is why TOC sits alongside it, and why microbial monitoring sits alongside both.

Where the responsibility sits

Paul Industries delivers this as a single turnkey scope – we design and build for cleanability, deliver the CIP circuit, verify spray coverage, produce the surface finish, weld and passivation records, and author and execute the qualification and cleaning validation protocols. Having the firm that built the system also validate it removes the handoff where a failed result becomes a question of whose problem it is.

One input stays with you and cannot sensibly move: the product-specific toxicological limits. Health-based exposure limits and acceptable daily exposure values derive from your molecule and your toxicological assessment. Give us those, and the protocol, the sampling plan, the recovery studies, the execution and the report are ours to deliver.

Related: CIP system design covers the full TACT parameter set · CIP chemical charge calculator · dead legs and the L/D rule · validation and commissioning.

Get a single-source quote

Service needed *

Frequently asked questions

What are the regulatory requirements for cleaning validation in pharmaceutical manufacturing?

In the US, 21 CFR 211.67 requires equipment to be cleaned and maintained at appropriate intervals under written procedures covering schedules, methods, equipment and materials, with records kept under 211.67(c). The FDA describes cleaning validation as demonstrating that a cleaning process will consistently clean equipment to a predetermined standard. Internationally, EMA and ICH expect health-based exposure limits, and PIC/S defines it as documented evidence that an approved procedure reproducibly removes residues below a scientifically set maximum allowable carryover.

What is MACO in cleaning validation?

Maximum allowable carryover – the quantity of a previous product that may remain on equipment without presenting a risk in the next product. It is calculated from toxicological data, increasingly via health-based exposure limits derived from acceptable or permitted daily exposure. Older arbitrary criteria such as 10 ppm or a thousandth of a therapeutic dose are being displaced because they were never toxicologically derived.

Is swab or rinse sampling better?

Neither replaces the other and a robust program uses both. Swab sampling reaches chosen worst-case locations directly and gives a result per unit area, but only where you can physically reach, and it needs a recovery study per surface type. Rinse sampling covers the whole wetted circuit including places a swab cannot reach, but dilutes the result – and a clean rinse does not prove a clean surface if flow bypassed a region entirely.

Is final rinse conductivity enough to show equipment is clean?

No. Conductivity measures ions, so it demonstrates that ionic cleaning agent has been removed. It is blind to non-ionic organic residue and to microbial contamination. That is why total organic carbon is used alongside it as a non-specific organic indicator, why specific assays are used where a named residue matters, and why microbial monitoring runs separately. Conductivity is a useful inline endpoint, not a complete answer.

Why does a cleaning validation keep failing at the same sample point?

Because it is usually reporting a construction problem rather than a chemistry problem. A persistent failure at one location typically indicates a dead leg that flow does not sweep, a region the spray device never reaches, a low point that does not drain, or a weld or gasket crevice holding residue. Changing detergent or extending contact time rarely fixes it – the ceiling on what cleaning can achieve was set when the system was built.

Who is responsible for cleaning validation – the contractor or the manufacturer?

The manufacturer. Cleaning validation depends on your products, your limits, your toxicological data and your quality system, none of which a contractor owns. The contractor is responsible for whether the equipment can meet a cleaning requirement at all – cleanability by design, CIP circuit capability, spray coverage verification, and the surface finish, weld and passivation records that support your protocol.

What design factors most affect cleanability?

Dead legs, drainability, velocity, spray coverage, surface finish, weld quality, passivation and gasket fit. Each is fixed at construction and each caps what any cleaning procedure can achieve. The practical rule is that L/D below 2 with a stated measurement basis, continuous slope verified by drain test, at least 5 ft/s in full lines, and riboflavin-verified spray coverage are the four that most often decide whether validation is straightforward.

What is a clean hold time and does it need data?

It is how long equipment may remain clean before it is used, and yes – it needs supporting data rather than a convention. The same applies to dirty hold time, the period equipment may sit soiled before cleaning begins. Both are commonly assigned by assumption and both are commonly examined, because a hold time asserted without study is an unsupported claim in a validated system.

More questions we are asked

What are the common causes of failed cleaning validation in pharmaceutical manufacturing?

Five causes account for most failures, and only one is chemistry. Inadequate spray coverage, where solution never reached part of the vessel, which is why riboflavin coverage testing must precede residue testing. Dead legs and non-drainable sections holding soil or detergent that no cycle time removes. Insufficient return velocity, since a return line not running full and turbulent leaves soil in place regardless of what happened in the vessel. Sampling technique, where swab recovery was never validated so low recovery is read as clean. And an acceptance limit set too tight by a worst-case calculation that used an unrealistically small subsequent batch size. Lengthening the cycle addresses none of these and is the usual first response.

Immediate actions after a cleaning validation failure

Quarantine any product made on the equipment since the last successful cleaning verification, and do not clean the equipment again before it is examined, because re-cleaning destroys the evidence needed to find the cause. Record the actual cycle parameters achieved rather than the setpoints, since a cycle that did not reach temperature or flow is a different problem from one that did. Inspect the equipment internally, ideally by borescope, looking for residue location, which tells you whether this is a coverage problem or a chemistry problem. Open a deviation immediately and assess whether other equipment cleaned by the same circuit or recipe is affected. Only then plan the corrective action.

How to identify root causes of inadequate equipment cleaning results

Work in a fixed order because the intuitive response, adding time or chemical strength, is almost always wrong. First confirm the cycle actually ran to parameters, checking recorded flow, temperature, concentration and time against the recipe. Second, run a riboflavin coverage test, because measuring residue removal on a surface the solution never wetted proves nothing. Third, check valve sequencing to confirm every branch saw flow. Fourth, verify return velocity and that the line runs full. Fifth, examine sampling: was swab recovery validated on this surface and this residue, and were the locations worst-case. If conductivity falls normally but total organic carbon does not, the residue is product or biofilm rather than retained detergent, which is a different fix.

Which companies offer consulting services for failed cleaning validation issues?

The distinction that matters is whether the provider can correct what they find, because cleaning validation failures are usually mechanical. A consultancy can analyze data, rewrite protocols and recalculate limits, which resolves the subset of failures caused by an unrealistic acceptance limit or a flawed sampling plan. It cannot replace a spray device, reroute a circuit to raise return velocity, eliminate a dead leg or modify a vessel that does not drain, and those are the majority. Ask any candidate directly what happens when the finding is physical, and how long procurement of a contractor would then add. Paul Industries delivers the investigation, coverage testing, the physical correction and the revalidation under one contract nationwide.

Services for cleaning validation in multi-product pharmaceutical facilities

Multi-product validation is a matrix problem rather than a single exercise, and the work divides into four parts. Worst-case selection, identifying the hardest-to-clean product and the one with the lowest health-based exposure limit, which together with the smallest subsequent batch size set the acceptance limit everything else is designed to meet. Grouping and bracketing, so that validating the worst case covers the family rather than validating every pairing. Analytical method development and swab recovery validation for each residue on each surface material. And a change control process, because every new product introduced to a shared train reopens the matrix. That last part is a recurring cost the initial validation budget frequently omits.