A formulation that performed beautifully across three development batches can fail its first commercial run outright. Blend uniformity drifts, tablet hardness scatters, a drying step that took ninety minutes at pilot scale takes far longer in a production dryer. Pharmaceutical process validation exists precisely because a process that worked once is not the same thing as a process that works every time, on every batch, for years. The financial stakes are severe — failed qualification batches burn API, delay launch, and can push a regulatory submission into a review cycle the company had not budgeted for. This guide works through the three-stage validation lifecycle as regulators now define it, from process design and control strategy through qualification batches to continued verification in commercial production. It also covers the technology transfer step where most scale-up projects actually come apart, and what a defensible validation package needs to contain before an inspector asks for it.
Validation is often treated as a documentation exercise bolted onto the end of development, and that framing is the root of most failures in the discipline. Its actual purpose is to establish documented evidence that a process consistently delivers product meeting its predetermined quality attributes. Testing finished batches cannot substitute for this, because sampling a batch tells you about that batch and nothing about the next one. Regulators codified the principle for exactly this reason.
The stakes explain why regulators rebuilt the framework around a lifecycle rather than a one-time event. Understanding that structure is the starting point for everything that follows.
The modern framework treats validation as continuous rather than as a milestone passed once and filed away. The FDA's 2011 guidance on process validation restructured the discipline into three linked stages that run from early development through the entire commercial life of the product. Each stage answers a different question, and each one depends on the evidence generated by the stage before it. Skipping ahead is the most common structural mistake in validation planning.
| Stage | Name | Question it answers | Primary output |
|---|---|---|---|
| Stage 1 | Process Design | What process will reliably deliver the required quality attributes? | Control strategy defining CQAs, CPPs, and operating ranges |
| Stage 2 | Process Qualification | Does the designed process actually perform at commercial scale? | Qualified facility and equipment plus executed PPQ batches |
| Stage 3 | Continued Process Verification | Does the process remain in control over its commercial life? | Ongoing trending, statistical monitoring, and change management |
This structure is built on the ICH quality framework rather than standing alone. ICH Q8, Q9, and Q10 supply the underlying concepts of pharmaceutical development, quality risk management, and the pharmaceutical quality system. Their alignment is what allows one well-designed programme to satisfy both FDA and EU expectations.
Everything downstream depends on the quality of Stage 1, because a process that was never properly characterised cannot be meaningfully qualified.
Stage 1 is where the process is actually invented, and where the quality of every later stage is determined. The work starts from the quality target product profile, which describes what the finished product must deliver to the patient. From that profile the team derives the critical quality attributes, then identifies which process parameters control them. Done properly, this stage produces a control strategy that explains not just what the settings are but why they are what they are.
The distinction between attributes and parameters trips up more teams than any other concept here. A critical quality attribute belongs to the product; a critical process parameter belongs to the process. Confusing them produces control strategies that diligently monitor variables which do not influence quality.
With the process characterised and the control strategy written, the question shifts from design to proof — which is what Stage 2 exists to deliver.
Stage 2 tests whether the designed process actually performs on the commercial equipment train, in the commercial facility, at the commercial batch size. It has two distinct halves that are frequently conflated: qualifying the facility and equipment, then qualifying the process running on them. Attempting the second before completing the first invalidates the result, because a process cannot be shown to be reproducible on equipment that has not been shown to be reliable. The European framework sets out the qualification sequence particularly explicitly.
Annex 15 of the EudraLex Volume 4 GMP guidelines covers this qualification sequence for EU manufacture. Once the equipment is qualified, process performance qualification batches are executed under an approved protocol with predetermined acceptance criteria and an enhanced sampling plan.
The most persistent myth in this stage concerns batch numbers. The convention of three consecutive successful batches was never a regulatory requirement, and the 2011 FDA guidance deliberately moved away from any fixed count. The number should be justified from process complexity, observed variability, prior knowledge, and the strength of the control strategy — and that justification belongs in the protocol before execution begins.
Qualification assumes the process arrived at the commercial site intact, and that assumption is exactly where most scale-up projects run into trouble.
Moving a process from development to commercial manufacture is a formal lifecycle activity under ICH Q10, not an administrative handover. It fails for two distinct reasons: incomplete knowledge transfer between organisations, and physical phenomena that simply do not scale with batch size. The second category is the more dangerous, because it produces failures that look like execution errors when they are actually design gaps. Understanding which unit operations are scale-sensitive is what allows a team to predict problems instead of discovering them during PPQ.
| Unit operation | Why it does not scale linearly | Typical consequence if unaddressed |
|---|---|---|
| Blending | Shear distribution and fill level depend on vessel geometry, not volume alone | Blend uniformity failures or over-blending and segregation |
| Wet granulation | Impeller tip speed and liquid addition rate change with equipment size | Granule size distribution shifts, altering flow and compressibility |
| Drying | Surface-area-to-volume ratio falls as vessel size increases | Longer cycles, moisture gradients, and inconsistent endpoint |
| Tablet compression | Dwell time at a given speed differs between research and high-speed presses | Hardness and dissolution variability at production speed |
| Heat transfer in liquids | Jacket surface area does not keep pace with vessel volume | Slower heating and cooling, with thermal exposure risk to the API |
The knowledge side of transfer is more tractable but no less consequential. A complete package carries the master formula and process description, plus the control strategy with its CQAs and CPPs. It also carries analytical methods with their transfer and verification plan, and the development history explaining the design. Hold-time data and material specifications belong in it too, because both routinely differ between a development lab and a commercial warehouse.
Analytical method transfer deserves separate attention, since a method that performs well in a development laboratory may behave differently on the receiving site's instruments and with its analysts. Stability data generated during transfer also needs to align with the programme described in our guide to ICH stability testing and shelf-life determination. A transfer protocol with acceptance criteria agreed by both sites, signed before any batch is made, is what converts the handover into something verifiable.
Once the process is transferred and qualified, the work shifts from proving capability to sustaining it.
Stage 3 is the longest phase of validation and the one most often under-resourced. Its purpose is to confirm that the process stays in a state of control across its entire commercial life, using data from routine production rather than a special campaign. Done well, it detects drift while it is still a trend rather than a deviation. Done poorly, it becomes a filing exercise that generates data nobody analyses until an inspector asks about it.
This replaces the older practice of calendar-driven revalidation, where batches were re-run periodically whether or not anything had changed. ICH Q12 extends the approach further, providing a framework of established conditions and post-approval change management protocols that lets a well-characterised process absorb change without a full revalidation each time. The regulatory strategy behind those filings is covered in our guide to FDA, ICH and USP regulatory pathways.
The decision framework, condensed: invest in Stage 1 characterisation before anything else, qualify equipment before qualifying the process, and justify PPQ batch numbers from risk rather than convention. Treat technology transfer as a knowledge problem and a physics problem at the same time. For companies without an internal validation function, our guide to selecting a pharmaceutical formulation consultant covers how to evaluate that capability. Our pharmaceuticals and health care practice page sets out how Global Formulation supports scale-up and commercial transfer projects.
There is no fixed number, and this is one of the most persistent misconceptions in the industry. The old expectation of three consecutive successful batches was an industry convention rather than a regulatory requirement, and the FDA's 2011 process validation guidance explicitly moved away from it.
The number of process performance qualification batches should instead be justified on scientific and risk-based grounds. Process complexity, variability observed during development, control strategy strength, and prior knowledge of the equipment train all feed into that justification. A well-understood process supported by extensive Stage 1 data may justify fewer batches than a complex or highly variable one. That justification has to be documented in the protocol before execution begins.
A critical quality attribute, or CQA, is a property of the product itself that must stay within a defined limit. Assay, dissolution, content uniformity, degradation products, and microbial limits are typical examples. A critical process parameter, or CPP, is a setting on the manufacturing process whose variation directly affects one or more CQAs. Blending time, compression force, granulation endpoint, and drying temperature are common examples.
The relationship runs one way: CQAs come from the quality target product profile and patient requirements, and CPPs are then identified as the process levers that control them. Confusing the two produces control strategies that monitor the wrong things, which is a common finding in validation reviews.
Because several of the physical phenomena that govern a pharmaceutical process do not scale linearly with batch size. Mixing and blending depend on shear distribution and vessel geometry rather than volume alone. Blend uniformity achieved in a small blender may not be reproduced in a larger one at the same time setting.
Heat and mass transfer behave the same way — the surface-area-to-volume ratio falls as vessels get larger, which changes drying and cooling profiles significantly. Tablet compression adds another layer, because dwell time at a given press speed differs between a research press and a high-speed commercial machine, and that changes compaction behaviour. These are the failures that Stage 1 process design exists to predict rather than discover during qualification.
Continued process verification, Stage 3 of the validation lifecycle, is the ongoing collection and statistical analysis of process and product data throughout commercial production. Its purpose is to confirm that the process remains in a state of control after qualification, and to detect drift or emerging variability before it becomes a deviation.
Traditional revalidation, by contrast, was a periodic re-execution of validation batches on a calendar schedule regardless of whether anything had changed. The lifecycle approach replaces that calendar-driven exercise with continuous monitoring, and triggers targeted requalification only when a change or an adverse trend genuinely warrants it. Regulators now expect the ongoing data programme, not a batch of paperwork repeated every few years.
The underlying principles are closely aligned, but the documents and terminology differ, and manufacturers supplying both markets need to satisfy each. In the United States, process validation expectations sit within the drug GMP regulations of 21 CFR Parts 210 and 211, interpreted through the FDA's 2011 lifecycle guidance.
In the European Union, Annex 15 of the EudraLex Volume 4 GMP guidelines covers qualification and validation, and it sets out the design, installation, operational, and performance qualification sequence explicitly. Both frameworks are built on ICH Q8, Q9, and Q10. That shared foundation is what makes a single well-designed validation programme workable across both regions when it is planned that way.
Technology transfer is the structured handover of product and process knowledge from the development organisation to the receiving manufacturing site. ICH Q10 treats it as a formal lifecycle stage rather than an administrative step. It covers the master formula and process description, plus the control strategy with its CQAs and CPPs. Analytical methods, their transfer and verification at the receiving site, and the development history all belong in it too.
Gaps in that package are the single most common cause of validation failure at the receiving site, because the new team inherits settings without the reasoning behind them. A transfer protocol with defined acceptance criteria, agreed by both sites before any batch is made, is what turns the handover into a verifiable exercise.
The trigger is impact on the control strategy, not the size of the change on paper. A formal change control assessment should evaluate whether the change could affect any critical quality attribute or alter a critical process parameter. It should also check whether the change moves the process outside the qualified range.
Changes to equipment, batch size, a critical raw material supplier, the manufacturing site, or a validated process step normally warrant at least a risk assessment. Targeted requalification of the affected steps is often required as well. ICH Q12 provides a framework for managing these post-approval changes through established conditions and change management protocols. That framework lets a well-characterised process accommodate change without a full revalidation each time.
Stage 1 process design work can and should run in parallel with late-stage formulation development, because the two inform each other and early process knowledge often improves the formulation. Stage 2 process qualification, however, requires a locked formulation, a defined control strategy, and qualified equipment. Attempting it against a moving formulation wastes batches and generates data that cannot be used.
The practical sequence is to finalise the formulation and its analytical methods, then complete the risk assessment and control strategy. Qualify the facility and equipment, and only then execute PPQ batches under an approved protocol. Compressing that sequence to save time is the most expensive shortcut available in pharmaceutical development.
Global Formulation provides pharmaceutical process validation and scale-up consultancy — control strategy development, technology transfer packages, validation protocol design, and GMP manufacturing handoff support.
Talk to Our Formulation Team