IQ (Installation Qualification) proves a system was installed correctly, OQ (Operational Qualification) proves it operates across its range, and PQ (Performance Qualification) proves it performs consistently in real use – each with its own documented protocol. Together they form the validation chain FDA/cGMP expects for a process system.

IQ vs OQ vs PQ

StageWhat it verifiesExample
IQInstalled per design and specsCorrect components, materials, calibration, utilities connected
OQOperates across its full rangeAlarms, controls, and setpoints work at limits
PQPerforms consistently in real useRepeatable results over multiple runs under production conditions

Documentation requirements

Each stage requires an approved protocol, executed results, deviations and their resolution, and a final report. The system also needs supporting records – material certs, weld logs, calibration, and P&IDs – that IQ references. Missing documentation is the most common reason qualification stalls.

Related: Validation & commissioning · IQ OQ PQ explained · What is process validation · Request a quote

Frequently asked questions

What are the requirements for IQ OQ PQ documentation?

A compliant IQ/OQ/PQ package requires approved protocols with pre-defined acceptance criteria, executed and signed test records, calibration certificates, material and weld documentation, as-built drawings, deviation handling, and a final summary report. Every result must be traceable, contemporaneous, and reviewed by quality before approval.

What must an IQ protocol include to be compliant?

An Installation Qualification protocol must document equipment identification, utilities and connections, materials of construction, instrument calibration status, required manufacturer documentation, drawings, and installation verification against design. Each item needs a defined acceptance criterion and a place to record the verified result and reviewer signature.

What are the documentation requirements for good documentation practice?

cGMP documentation must be attributable, legible, contemporaneous, original, and accurate, the ALCOA principles. That means signed and dated entries made at the time of the activity, no back-dating, corrections struck through rather than erased, and a clear audit trail. These practices apply to every executed qualification record.

Do we need user requirement specifications before qualification?

Yes. A User Requirement Specification (URS) defines what the system must do and becomes the reference qualification tests trace back to. Without a URS and design specifications, acceptance criteria have no documented basis, which is a common audit gap. The URS is typically the first controlled document in the package.

What calibration records are required for OQ?

Operational Qualification requires that every instrument used to make a pass/fail decision, and every critical instrument on the system, has a current calibration traceable to a recognized standard. Calibration certificates are attached to the package, and out-of-tolerance instruments must be addressed before the affected tests are considered valid.

How many PQ runs are required?

There is no universal fixed number; the requirement is enough consecutive successful runs to demonstrate consistency, justified by risk. Water-system PQ commonly uses a multi-phase sampling program spanning weeks. The count must be pre-defined in the protocol and scientifically justified rather than chosen arbitrarily.

What acceptance criteria are required in a protocol?

Protocols must state measurable, pre-approved pass/fail criteria tied to specifications, established before execution. Vague or after-the-fact criteria are an audit risk. Each test needs an expected result, the method of measurement, and the tolerance that determines pass or fail.

What signatures and approvals does a qualification package need?

Protocols require pre-execution approval, typically by the author, engineering, and quality. Executed records require the tester’s signature and date, reviewer verification, and final quality approval on the summary report. Electronic records must meet data-integrity controls equivalent to those signatures.

What material and weld documentation is required for high-purity systems?

High-purity piping qualification requires material test reports for tubing and components, weld logs, weld maps, coupon or borescope inspection records, and passivation certificates. This traceability proves the wetted path meets ASME BPE surface-finish and material requirements and supports the IQ record.

How are deviations required to be handled during qualification?

Any result outside acceptance criteria must be recorded as a deviation, investigated for root cause, assessed for impact, and formally resolved before qualification is completed. The deviation, its resolution, and any re-testing become part of the permanent package so an auditor sees the full history.

What is required to close out a qualification project?

Closeout requires all protocols executed, all deviations resolved, calibration and material documentation attached, and a final summary report that references every protocol, states the conclusion, and is approved by quality. Only then is the system considered qualified and released for its intended cGMP use.

Are electronic qualification records required to meet 21 CFR Part 11?

If qualification data is captured or stored electronically, those records and any electronic signatures must meet 21 CFR Part 11 expectations: access controls, audit trails, and secure, attributable records. Paper-based execution must still meet ALCOA data-integrity principles. Paul Industries structures documentation to withstand audit scrutiny. Call 201-450-8280.

What documentation is required when requalifying after a change?

Requalification requires a documented change assessment identifying which IQ, OQ, or PQ elements are affected, protocols covering those elements, and a rationale for anything leveraged from the original package. The change control record ties the requalification back to the modification that triggered it.

Who is required to approve qualification protocols before execution?

Protocols must be reviewed and approved prior to execution by the appropriate functions, generally engineering or the system owner and the quality unit. Executing a protocol that was not pre-approved invalidates the results, because acceptance criteria could otherwise be altered after seeing the data.

What are the traceability requirements between design and qualification?

There must be a documented trace from user requirements and design specifications through to the qualification tests that verify them, often shown in a requirements traceability matrix. This proves every requirement was tested and every test maps to a requirement, closing gaps auditors look for.

Can Paul Industries deliver a turnkey IQ OQ PQ package?

Yes. Because Paul Industries designs, fabricates, installs, and validates as one accountable party, it can deliver a complete qualification package, protocols, executed records, supporting certifications, and summary reports, for the systems it builds. Single-source delivery keeps documentation consistent and audit-ready. Call 201-450-8280.

What is the difference between IQ, OQ, and PQ?

IQ verifies correct installation, OQ verifies operation across the full range, and PQ verifies consistent performance in real production use.

What are the requirements for IQ OQ PQ?

An approved protocol, executed results, documented deviations, and a report for each stage, plus supporting records (material certs, weld logs, calibration, P&IDs).

Which comes first, IQ or OQ?

IQ first (installed correctly), then OQ (operates correctly), then PQ (performs consistently).

Do you provide IQ/OQ/PQ support?

Yes – Paul Industries installs and supports qualification with turnover documentation for the systems we build.

Get IQ/OQ/PQ support

Paul Industries is a single-source supplier, installer, and validator – one accountable partner from design through documented startup. Tell us about your project and we will scope it.

Request a Quote

Service needed *

The regulatory basis for each qualification document

IQ, OQ and PQ are industry terminology. None of the three appears by name in 21 CFR Part 211. What the regulation does require is that equipment be suitable, that it be controlled, and that all of it be evidenced in records – and each qualification document exists to satisfy a specific one of those requirements. Knowing which section a document answers to is what turns a protocol from a formality into something an investigator can follow.

CitationWhat the regulation requiresWhich document evidences it
21 CFR 211.63Equipment used in manufacture, processing, packing or holding shall be of appropriate design, adequate size and suitably located for its intended use, cleaning and maintenanceIQ – confirms the installed item matches the specified design, size and location
21 CFR 211.65(a)Equipment surfaces contacting components or product shall not be reactive, additive or absorptive so as to alter safety, identity, strength, quality or purityIQ – material certificates, surface finish records and the passivation record
21 CFR 211.67(a) and (b)Equipment shall be cleaned and maintained at appropriate intervals under written proceduresOQ for the cleaning cycle, plus the maintenance and cleaning procedures referenced by the protocol
21 CFR 211.67(c)Records shall be kept of maintenance, cleaning, sanitising and inspectionThe qualification package itself, and the cleaning and use log it hands over to
21 CFR 211.68(a)Automatic, mechanical and electronic equipment shall be routinely calibrated, inspected or checked to a written programmeIQ for instrument identification and calibration status; OQ for the control functions
21 CFR 211.68(b)Controls shall be exercised over computer or related systems to assure that changes are instituted only by authorised personnel, with input and output accuracy verifiedOQ for access control, alarm and interlock testing, and data integrity checks
21 CFR Part 11Requirements for electronic records and electronic signatures where records are kept electronicallyOQ for audit trail, time stamps, record retention and signature controls
21 CFR 211.100(a)Written procedures for production and process control, designed to assure that products have the identity, strength, quality and purity they purport to possessPQ – demonstrates the equipment reproducibly supports those procedures
21 CFR 211.182A written record of cleaning, maintenance and use shall be kept for each major item of equipmentThe turnover deliverable the qualification package establishes
21 CFR 211.188Batch production and control records shall document the performance of each significant stepPQ, where qualification runs are executed against the actual batch record

Two consequences follow from reading the table in that direction. First, a protocol that cites no regulation is testing whatever its author thought of – which is why acceptance criteria drift between vendors and why two IQ packages for the same skid can look nothing alike. Second, several of these obligations are continuing rather than one-off: 211.67(c), 211.68(a) and 211.182 describe records that must go on being kept after qualification closes, so the qualification package should hand over the mechanism, not just the evidence.

What the regulation does not say

Just as useful, and more often got wrong. The three-consecutive-successful-runs convention for PQ is not in 21 CFR 211. It is an industry practice that hardened into an assumption. The FDA’s 2011 process validation guidance is explicit that the number of runs should be justified by an understanding of process variability rather than fixed by convention, which means three runs may be too few for a variable process and unnecessary for a well-characterised one – but either position has to be argued in the protocol rather than asserted.

Likewise, the regulation does not name IQ, OQ or PQ, does not mandate a particular protocol format, and does not require a specific number of sampling points. What it requires is that the approach be written down in advance, followed, and evidenced. ASTM E2500 offers a risk-based verification alternative to the traditional three-document structure, and it is accepted precisely because the regulation specifies outcomes rather than a document set.