Cleaning validation in US pharmaceutical manufacturing is governed by 21 CFR 211.67, which requires equipment to be cleaned and maintained at appropriate intervals under written procedures covering schedules, methods, equipment and materials – with records kept. The FDA describes the purpose of cleaning validation as demonstrating that a particular cleaning process will consistently clean equipment to a predetermined standard.
Almost everything written on this subject treats cleaning validation as a documentation and analytical exercise. It is that, but it rests on something decided much earlier: you cannot validate the cleaning of a system that was not designed to be cleaned. Paul Industries builds hygienic process systems to be cleanable and validatable, and this page covers both halves – what the regulations require, and what the construction has to deliver for that requirement to be achievable at all.
The regulatory framework
| Source | What it requires | Scope |
|---|---|---|
| 21 CFR 211.67 | Equipment cleaned and maintained at appropriate intervals; written procedures covering schedules, methods, equipment and materials; records kept under 211.67(c) | US finished pharmaceuticals – the core requirement |
| 21 CFR 211.63 | Equipment suitably located for cleaning and maintenance | Design – cleanability is named in the equipment requirement itself |
| 21 CFR 211.65(a) | Product-contact surfaces not reactive, additive or absorptive | Surface condition, which governs what can be removed from it |
| 21 CFR 211.100(a) | Written procedures for production and process control | Where your own cleaning limits become binding on you |
| ICH Q7 (FDA Q7A) | Cleaning expectations for active pharmaceutical ingredients | API manufacture |
| EMA / ICH | Health-based exposure limits (HBELs) for all products, from allowable daily exposure values | EU, and increasingly expected globally |
| PIC/S | Documented evidence that an approved procedure reproducibly removes previous product or cleaning agents below the scientifically set maximum allowable carryover | International inspectorates |
The word doing the work in the PIC/S definition is “reproducibly”. A single successful clean is not validation. The claim is that the procedure works every time, which is why the number of runs, the worst-case selection and the sampling plan all have to be argued rather than assumed.
The terms you need before reading a protocol
- MACO – maximum allowable carryover. The quantity of a previous product that may remain without harming the next.
- HBEL – health-based exposure limit. The toxicologically derived limit that increasingly replaces older arbitrary criteria.
- ADE / PDE – acceptable or permitted daily exposure. The toxicological figure HBELs are built from.
- Worst case – the hardest product, the hardest equipment, the hardest location, used to represent a group.
- Bracketing and grouping – validating a family of products or equipment using representative worst cases rather than every combination.
- Dirty and clean hold time – how long equipment may sit soiled before cleaning, and clean before use. Both need data.
- Swab and rinse sampling – direct sampling of a defined area versus analysis of the final rinse.
- Recovery study – proving the sampling method actually retrieves residue from the surface in question.
The older arbitrary criteria – 10 ppm, or a thousandth of a therapeutic dose – are being displaced by HBELs, because they were never toxicologically derived. A program still resting on them alone should expect questions.
Sampling and analysis
| Method | What it measures | Strength | Limitation |
|---|---|---|---|
| Swab | Residue on a defined area of a specific surface | Reaches worst-case locations directly; gives a per-area result | Only samples where you can physically reach – and a recovery study is required per surface type |
| Rinse | Residue in the final rinse from the whole wetted circuit | Covers surfaces a swab cannot reach | Dilutes; a clean rinse does not prove a clean surface if flow bypassed a region |
| TOC | Total organic carbon as a non-specific indicator | Fast, sensitive, good for routine monitoring | Non-specific – it does not tell you which organic |
| HPLC or specific assay | A named residue | Specific and quantitative | Slower and more costly per sample |
| Conductivity | Ionic residue, typically cleaning agent carryover | Immediate, inline, cheap | Blind to non-ionic residue – see our note on this below |
| Visual inspection | Visible residue | Always required; catches gross failure | A visually clean surface can still be chemically contaminated |
Swab and rinse answer different questions and neither replaces the other. Rinse samples the whole circuit weakly; swabs sample chosen points strongly. A program relying only on rinse results is vulnerable to exactly the locations flow never reached – which is where a poorly designed system fails.
The half nobody writes about: what makes a system validatable
Cleaning validation is normally discussed as a quality exercise. But the ceiling on what any cleaning procedure can achieve was fixed when the system was built, and no protocol, detergent or analytical method raises it. These are the construction decisions that decide whether validation is straightforward or perpetually marginal:
| Design factor | Why it limits cleaning | What good looks like |
|---|---|---|
| Dead legs | Flow does not sweep them, so cleaning depends on diffusion and time | L/D below 2 with the measurement basis stated; zero-static valves at sample and additive points |
| Drainability | A heel that will not drain cannot be cleaned, dried or sterilized | Continuous slope, low-point outlets, verified by a witnessed drain test |
| Velocity | Cleaning depends on wall shear, which depends on velocity | 5 ft/s minimum in a full line; 10-14 ft/s in upward branches for air removal |
| Spray coverage | A vessel surface the spray never reaches is cleaned by nothing | Coverage verified by riboflavin under UV at 365 nm, not assumed from a datasheet |
| Surface finish | Rougher surfaces hold soil and are harder to rinse | A stated Ra with measurement records – including welds, not only the shell |
| Weld quality | Internal heat tint, crevices and mismatch are soil traps | Orbital welding, purge verified by analyzer, borescoped at a stated percentage |
| Passivation | A free-iron-contaminated or rouged surface is reactive and holds residue | ASTM A967 designation named, with an acceptance test |
| Gasket fit | An oversized or misaligned gasket intruding into the bore creates a crevice | Correct gasket sizing and controlled assembly |
Two consequences follow. First, a cleaning validation that keeps failing at one sample point is usually reporting a construction problem, not a chemistry problem – and changing detergent will not fix it. Second, the cheapest time to solve any of this is at design, when routing can still move. After installation, every item above becomes a modification.
Why conductivity alone is not enough
Final rinse conductivity is the most common inline endpoint and it is genuinely useful – but it measures ions. It is blind to non-ionic organic residue and to microbial contamination, in the same way resistivity is blind to bioburden in a deionization loop. A rinse that reaches feed-water conductivity has demonstrated that ionic cleaning agent has been removed. It has not demonstrated that product residue has. That is why TOC sits alongside it, and why microbial monitoring sits alongside both.
Where the responsibility sits
Paul Industries delivers this as a single turnkey scope – we design and build for cleanability, deliver the CIP circuit, verify spray coverage, produce the surface finish, weld and passivation records, and author and execute the qualification and cleaning validation protocols. Having the firm that built the system also validate it removes the handoff where a failed result becomes a question of whose problem it is.
One input stays with you and cannot sensibly move: the product-specific toxicological limits. Health-based exposure limits and acceptable daily exposure values derive from your molecule and your toxicological assessment. Give us those, and the protocol, the sampling plan, the recovery studies, the execution and the report are ours to deliver.
Related: CIP system design covers the full TACT parameter set · CIP chemical charge calculator · dead legs and the L/D rule · validation and commissioning.
Get a single-source quote
Standards referenced: 21 CFR 211 · ASTM A967 · ASME BPE · ICH Q7
Related: What Is an FDA 483? Observations and Response Explained · Pharmaceutical CIP and SIP Systems (Validated) · Validation Cost: What IQ, OQ and PQ Actually Cost to Execute
Dedicated equipment vs shared trains: what changes in the validation
Whether a piece of equipment makes one product or many is the decision that sets the size of a cleaning validation program, and it is made years before the first protocol is written.
Dedicated equipment narrows the question to one carryover: the product onto itself, batch to batch, plus cleaning agent residue and bioburden. There is no cross contamination calculation to defend, no worst case product to select, and adding a batch of the same product does not reopen anything. The cost is capital and floor space, and a line that sits idle between campaigns.
A shared train buys utilization and pays for it in analytical work. Every product in the train has to be assessed against every other, a worst case is selected on solubility, toxicity and cleanability, and limits are calculated from the health based exposure figure for the compound being carried over. The train has to be revalidated in some part whenever a product is added, and the matrix that justified the worst case has to be revisited each time.
The two also fail differently. On dedicated equipment, a failure is a cleaning problem. On a shared train, a failure raises a question about every batch made since the last successful verification, across products. That difference is why potent compounds, sensitizers and biologics are so often given dedicated equipment even where the throughput does not obviously justify it. Decide the train structure first, then write the validation strategy to match it.
What a cleaning validation program costs per product
Our published facility figures put cleaning validation at $20,000 to $92,000 per product, and note that the cost recurs with every product added to a shared train. That recurrence is the part worth planning around. A dedicated line pays once. A shared train pays again each time the product list grows, and the later additions are not cheaper because the matrix has to be reworked from the new worst case.
What moves a program within that band is sample point count, the number of distinct equipment trains, the analytical method required for the residue in question, and how many recovery studies the surface materials demand. The wider qualification picture, including the lines that sit next to cleaning validation on a project budget, is on our turnkey GMP facility cost guide.
What to require in a protocol before execution starts
Most failed cleaning validations fail on a protocol gap rather than on a dirty surface. Close these before anyone swabs anything.
- Sample locations fixed on a drawing with a unique identifier per point, so the same point is sampled every run and a trend means something.
- A documented rationale for each location, naming why it is a worst case: geometry, flow shadow, material, or accessibility.
- Recovery studies run on the actual surface material and finish, per residue and per sampling method, with the recovery factor applied to the limit rather than mentioned in passing.
- The residue limit derivation shown in full, from the health based exposure figure through shared surface area to the per swab value.
- Analytical method validated for the specific residue and matrix, with the limit of quantitation confirmed below the acceptance limit by a stated margin.
- Swab material and solvent qualified against the method, since a swab that interferes with the assay invalidates every result taken with it.
- Dirty hold time and clean hold time both defined with supporting data, because both are routinely assumed and rarely studied.
- The cleaning procedure written to the level of detail an operator actually follows, with volumes, temperatures, times and a defined end point rather than until clean.
- Operator training records current and attached, since procedure variability between operators is what turns three successful runs into an unreproducible result.
- A pre-agreed route for an out of specification result, naming who investigates, what gets quarantined and what triggers a return to the design of the equipment rather than the procedure.
Frequently asked questions
What are the regulatory requirements for cleaning validation in pharmaceutical manufacturing?
In the US, 21 CFR 211.67 requires equipment to be cleaned and maintained at appropriate intervals under written procedures covering schedules, methods, equipment and materials, with records kept under 211.67(c). The FDA describes cleaning validation as demonstrating that a cleaning process will consistently clean equipment to a predetermined standard. Internationally, EMA and ICH expect health-based exposure limits, and PIC/S defines it as documented evidence that an approved procedure reproducibly removes residues below a scientifically set maximum allowable carryover.
What is MACO in cleaning validation?
Maximum allowable carryover – the quantity of a previous product that may remain on equipment without presenting a risk in the next product. It is calculated from toxicological data, increasingly via health-based exposure limits derived from acceptable or permitted daily exposure. Older arbitrary criteria such as 10 ppm or a thousandth of a therapeutic dose are being displaced because they were never toxicologically derived.
Is swab or rinse sampling better?
Neither replaces the other and a robust program uses both. Swab sampling reaches chosen worst-case locations directly and gives a result per unit area, but only where you can physically reach, and it needs a recovery study per surface type. Rinse sampling covers the whole wetted circuit including places a swab cannot reach, but dilutes the result – and a clean rinse does not prove a clean surface if flow bypassed a region entirely.
Is final rinse conductivity enough to show equipment is clean?
No. Conductivity measures ions, so it demonstrates that ionic cleaning agent has been removed. It is blind to non-ionic organic residue and to microbial contamination. That is why total organic carbon is used alongside it as a non-specific organic indicator, why specific assays are used where a named residue matters, and why microbial monitoring runs separately. Conductivity is a useful inline endpoint, not a complete answer.
Why does a cleaning validation keep failing at the same sample point?
Because it is usually reporting a construction problem rather than a chemistry problem. A persistent failure at one location typically indicates a dead leg that flow does not sweep, a region the spray device never reaches, a low point that does not drain, or a weld or gasket crevice holding residue. Changing detergent or extending contact time rarely fixes it – the ceiling on what cleaning can achieve was set when the system was built.
Who is responsible for cleaning validation – the contractor or the manufacturer?
The manufacturer. Cleaning validation depends on your products, your limits, your toxicological data and your quality system, none of which a contractor owns. The contractor is responsible for whether the equipment can meet a cleaning requirement at all – cleanability by design, CIP circuit capability, spray coverage verification, and the surface finish, weld and passivation records that support your protocol.
What design factors most affect cleanability?
Dead legs, drainability, velocity, spray coverage, surface finish, weld quality, passivation and gasket fit. Each is fixed at construction and each caps what any cleaning procedure can achieve. The practical rule is that L/D below 2 with a stated measurement basis, continuous slope verified by drain test, at least 5 ft/s in full lines, and riboflavin-verified spray coverage are the four that most often decide whether validation is straightforward.
What is a clean hold time and does it need data?
It is how long equipment may remain clean before it is used, and yes – it needs supporting data rather than a convention. The same applies to dirty hold time, the period equipment may sit soiled before cleaning begins. Both are commonly assigned by assumption and both are commonly examined, because a hold time asserted without study is an unsupported claim in a validated system.
More questions we are asked
What are the common causes of failed cleaning validation in pharmaceutical manufacturing?
Five causes account for most failures, and only one is chemistry. Inadequate spray coverage, where solution never reached part of the vessel, which is why riboflavin coverage testing must precede residue testing. Dead legs and non-drainable sections holding soil or detergent that no cycle time removes. Insufficient return velocity, since a return line not running full and turbulent leaves soil in place regardless of what happened in the vessel. Sampling technique, where swab recovery was never validated so low recovery is read as clean. And an acceptance limit set too tight by a worst-case calculation that used an unrealistically small subsequent batch size. Lengthening the cycle addresses none of these and is the usual first response.
Immediate actions after a cleaning validation failure
Quarantine any product made on the equipment since the last successful cleaning verification, and do not clean the equipment again before it is examined, because re-cleaning destroys the evidence needed to find the cause. Record the actual cycle parameters achieved rather than the setpoints, since a cycle that did not reach temperature or flow is a different problem from one that did. Inspect the equipment internally, ideally by borescope, looking for residue location, which tells you whether this is a coverage problem or a chemistry problem. Open a deviation immediately and assess whether other equipment cleaned by the same circuit or recipe is affected. Only then plan the corrective action.
How to identify root causes of inadequate equipment cleaning results
Work in a fixed order because the intuitive response, adding time or chemical strength, is almost always wrong. First confirm the cycle actually ran to parameters, checking recorded flow, temperature, concentration and time against the recipe. Second, run a riboflavin coverage test, because measuring residue removal on a surface the solution never wetted proves nothing. Third, check valve sequencing to confirm every branch saw flow. Fourth, verify return velocity and that the line runs full. Fifth, examine sampling: was swab recovery validated on this surface and this residue, and were the locations worst-case. If conductivity falls normally but total organic carbon does not, the residue is product or biofilm rather than retained detergent, which is a different fix.
Which companies offer consulting services for failed cleaning validation issues?
The distinction that matters is whether the provider can correct what they find, because cleaning validation failures are usually mechanical. A consultancy can analyze data, rewrite protocols and recalculate limits, which resolves the subset of failures caused by an unrealistic acceptance limit or a flawed sampling plan. It cannot replace a spray device, reroute a circuit to raise return velocity, eliminate a dead leg or modify a vessel that does not drain, and those are the majority. Ask any candidate directly what happens when the finding is physical, and how long procurement of a contractor would then add. Paul Industries delivers the investigation, coverage testing, the physical correction and the revalidation under one contract nationwide.
Services for cleaning validation in multi-product pharmaceutical facilities
Multi-product validation is a matrix problem rather than a single exercise, and the work divides into four parts. Worst-case selection, identifying the hardest-to-clean product and the one with the lowest health-based exposure limit, which together with the smallest subsequent batch size set the acceptance limit everything else is designed to meet. Grouping and bracketing, so that validating the worst case covers the family rather than validating every pairing. Analytical method development and swab recovery validation for each residue on each surface material. And a change control process, because every new product introduced to a shared train reopens the matrix. That last part is a recurring cost the initial validation budget frequently omits.
What is a health-based exposure limit and how does it change acceptance criteria?
It is a toxicologically derived limit, commonly expressed as a permitted daily exposure, used to calculate how much residue may carry over into the next product. It replaced the older dose-fraction and parts-per-million conventions in much of the industry because it is based on the actual toxicology rather than on a general rule.
How is a worst-case product selected for cleaning validation?
By combining solubility, cleanability difficulty, toxicity and batch size into a rationale that identifies which product represents the hardest case. Validating the worst case then supports the others, which is what makes a bracketing approach defensible.
What is equipment grouping and when is it acceptable?
Grouping equipment of the same design, material and cleaning method so that validating one represents the group. It is acceptable where the equipment is genuinely equivalent and the rationale is documented, and it fails when a nominally identical unit has a different internal geometry.
How is a swab recovery study performed?
A known quantity of residue is applied to a coupon of the same material and finish as the equipment, swabbed using the production method, and the recovered amount measured. The recovery factor corrects the field results, and a study with poor recovery invalidates otherwise clean-looking data.
What is total organic carbon used for in cleaning validation?
As a non-specific measure of organic residue in rinse samples, useful where the residues are organic and a specific assay is not needed. It is fast and sensitive, but it cannot distinguish one compound from another, so it is used alongside specific methods where identification matters.
How are cleaning agents themselves validated as removed?
The detergent is treated as a residue in its own right, with its own acceptance limit and analytical method. A cleaning validation that proves product removal but ignores detergent carryover is incomplete.
What is a dirty hold time?
The maximum time equipment may sit soiled before cleaning starts, established by demonstrating that cleaning is still effective after that delay. It matters because dried residue behaves differently from fresh, and most cleaning failures involving hold time are dirty hold rather than clean hold.
How does visual inspection fit into cleaning validation?
It is a necessary condition, not a sufficient one, and its detection limit can be established by spiking studies so the visual criterion carries a quantitative meaning. Visually clean plus a residue limit below the acceptance criterion together form the standard.
How do dedicated equipment decisions get made?
When the calculated carryover limit is so low that no validated cleaning process can reliably meet it, or when the analytical method cannot detect at the required level, dedication becomes the control instead of cleaning. That is a facility design decision with capital consequences.
What triggers cleaning revalidation?
A change to the product, the cleaning agent, the procedure, the equipment or the campaign length, assessed under change control. Continued verification through routine monitoring also feeds it, because trends can reveal drift without any formal change.
How does equipment design affect cleaning validation outcomes?
Drainability, dead legs, spray coverage, surface finish and the absence of crevices determine whether a cleaning process can succeed at all. A validation that keeps failing at the same sample point is usually reporting a design problem rather than a chemistry problem.
Who owns cleaning validation between the contractor and the manufacturer?
The manufacturer owns the validation, because it depends on their products, limits and procedures. The contractor owns whether the equipment can be cleaned, by delivering coverage, drainability and finish, and by providing the evidence those were achieved.
What is the FDA cleaning validation guidance, and where does 21 CFR require it?
The FDA cleaning validation guidance is the 1993 Guide to Inspections: Validation of Cleaning Processes, still the reference inspectors cite, supplemented by the 2011 process validation guidance and, for limits, the health-based approach in EMA and ISPE guidance. The 21 CFR cleaning validation requirement itself comes from 21 CFR 211.67, which requires equipment to be cleaned and maintained to prevent contamination that would alter the drug product, with written procedures and records, and from 211.113 on microbiological contamination. Cleaning validation guidelines from PDA (Technical Reports 29 and 49) and ISPE fill in the methodology.
How does pharmaceutical cleaning validation differ from medical device cleaning validation?
Cleaning validation in pharmaceutical industry practice proves that residues of the previous product, cleaning agent and microorganisms are below a limit before the next product is made in shared equipment; the limit is based on the toxicology of the carried-over drug. Medical device cleaning validation, under ISO 13485 and ASTM F3127 for manufacturing residues and AAMI TIR30 for reusable devices, proves that manufacturing residues (lubricants, polishing compounds, cutting fluids, endotoxin, particulate) are removed from the device itself before packaging and sterilization. Pharmaceutical cleaning validation is about the equipment; device cleaning validation is about the product.
What are swab, coupon and riboflavin tests in cleaning validation?
Swab cleaning validation samples a defined area (typically 25 cm2) of a hard-to-clean location with a solvent-wetted swab, which is then extracted and analyzed by HPLC, TOC or a specific assay to give residue per area. Cleaning validation coupons are small test pieces of the same material and finish as the equipment, deliberately soiled with product, cleaned under the proposed cycle and tested, which lets a laboratory establish the cleaning parameters before running them on production equipment. The riboflavin test cleaning validation uses for spray coverage is different: riboflavin fluoresces under UV, so a vessel interior coated with dilute riboflavin and then run through the CIP spray cycle shows any surface the spray did not reach as a bright patch.
