Chemical SOP
Microbiology SOP
Warehouse SOP
Manufacturing SOP
Information technology SOP

DESIGN QUALIFICATION PROTOCOL CUM REPORT FOR ENVIRONMENT MONITORING SYSTEM

1. Introduction for Design Qualification for Environment Monitoring System:

The Design Qualification (DQ) for the Environment Monitoring System (EMS) describes the proposed design, configuration, functionality, control philosophy, security features, monitoring parameters, alarms, data recording, and system architecture required for effective environmental monitoring. The EMS is designed to integrate field sensors, Direct Digital Controllers (DDC), communication networks, software, and operator workstations so that environmental information can be continuously monitored from centralized control stations. The system primarily monitors temperature, relative humidity and differential pressure, along with door status and the operating status of associated Air Handling Units. Field devices such as temperature/RH sensors, differential-pressure transmitters and magnetic contacts communicate with DDC controllers and the monitoring software. The modular design also permits future expansion by adding additional sensors, controllers or operator devices. Each DDC controller is capable of independent operation, helping maintain monitoring functions even if network communication is interrupted. During operation, environmental parameters are continuously monitored and recorded in the software. Data can be logged at defined intervals, such as 10 or 15 minutes, and used for report generation, trending, reliability analysis and troubleshooting. When temperature, humidity or other monitored values move outside predefined limits, the system automatically generates alarms. The EMS includes controlled user access with separate Operator, Supervisor and Administrator security levels. User activities are recorded with date and time, unsuccessful login attempts are logged, and password controls are provided to protect system access. The system can generate alarm/event, trend, log-viewer and system-summary reports. UPS protection and power-recovery provisions are also incorporated to support continued operation and data protection during power interruptions. Overall, the DQ establishes documented evidence that the proposed EMS design is suitable for the intended environmental monitoring requirements and agreed user requirements.

Skip to PDF content

2. Flow Diagram for Design Qualification of an Environment Monitoring System (EMS):

The flow diagram explains the step-by-step process for Design Qualification of an Environment Monitoring System (EMS). It begins with reviewing the agreed User Requirement Specification (URS) and applicable standards to establish system requirements. The design objective and scope are then defined, covering HVAC-controlled areas and integrated equipment. The next stage includes system design and integration of sensors, DDC controllers, software, communication networks, and field devices for monitoring temperature, relative humidity, differential pressure, door status, and AHU running status.

Flow Diagram for Design Qualification of an Environment Monitoring System (EMS)

The EMS workstation provides centralized monitoring, while security controls restrict access according to user roles. The system continuously records environmental data, generates alarms for values outside predefined limits, and supports trend and event reporting. UPS backup and recovery features support operation during power interruptions. Finally, the complete design is reviewed against the URS and approved for installation, qualification, and routine operation.

3. Brainstorming Analysis – Design Qualification of Environment Monitoring System (EMS) Not Performed:

The brainstorming analysis identifies possible reasons why Design Qualification (DQ) of the Environment Monitoring System (EMS) was not performed. Major causes include lack of awareness, insufficient resources, unclear URS requirements, inadequate planning, limited technical expertise, and incomplete design documentation. Other contributing factors include excessive dependence on vendors, poor communication between departments, weak management follow-up, changing regulatory expectations, and underestimation of system-related risks. These issues may delay or prevent proper assessment of the EMS design before installation. Brainstorming helps the investigation team identify potential causes systematically for further evaluation and development of suitable corrective and preventive actions.

Brainstorming Analysis – Design Qualification of Environment Monitoring System (EMS) Not Performed

4. 5 Why Analysis for Design Qualification of Environment Monitoring System (EMS) Not Performed:

The 5 Why Analysis identifies the root cause behind the Design Qualification of the Environment Monitoring System (EMS) not being performed. The first reason is that the DQ activity was not initiated and completed on time. This occurred because the qualification plan and project schedule did not adequately include DQ execution. Further analysis shows that the URS, design inputs, and technical documents were incomplete or not finalized. In addition, roles, responsibilities, coordination, and technical expertise were inadequate. The analysis ultimately identifies weak qualification planning and insufficient management oversight as the root cause, supported by poor documentation, vendor dependency, unclear requirements, and limited follow-up.

5 Why Analysis for Design Qualification of Environment Monitoring System (EMS) Not Performed:

5. Heatmap Analysis for Design Qualification of Environment Monitoring System (EMS) Not Performed:

The Heatmap Analysis evaluates risks associated with not performing Design Qualification for the Environment Monitoring System (EMS) by considering severity and likelihood. Risks are categorized into green, yellow, orange, and red zones. Major risks include incomplete URS, missing design documents, poor project planning, vendor dependency, inadequate technical expertise, weak cross-functional coordination, qualification delays, and insufficient management oversight. High-severity risks may affect regulatory compliance, reliable environmental monitoring, product quality, and patient safety. The heatmap helps prioritize risks requiring immediate corrective action, while moderate and low risks can be controlled through monitoring, improved planning, documentation, training, and management review.

Heatmap Analysis for Design Qualification of Environment Monitoring System (EMS) Not Performed

6. Fault Tree Analysis for Design Qualification of Environment Monitoring System (EMS) Not Performed:

The Fault Tree Analysis (FTA) identifies the major causes that can lead to the top event: Design Qualification of the Environment Monitoring System (EMS) not being performed. The analysis groups causes into inadequate planning, unclear requirements, documentation gaps, resource and expertise limitations, vendor or coordination issues, and weak management oversight. These causes may arise from missing qualification plans, incomplete URS, unavailable design documents, limited technical knowledge, delayed vendor inputs, unclear responsibilities, and inadequate review or follow-up. The FTA helps trace how individual failures combine to create the overall problem and supports identification of suitable corrective and preventive actions.

Fault Tree Analysis for Design Qualification of Environment Monitoring System (EMS) Not Performed

7. Pareto Chart Analysis for Design Qualification of the Environment Monitoring System (EMS) not being performed:

The Pareto Chart Analysis identifies the major contributors responsible for the Design Qualification of the Environment Monitoring System (EMS) not being performed. The chart ranks the causes according to their frequency and displays the cumulative percentage of contribution. The leading causes are incomplete URS/requirements, lack of project planning, and delays in vendor inputs, which together account for about 66% of the total identified occurrences. Other contributing factors include insufficient technical expertise, incomplete design documentation, poor cross-functional communication, and inadequate management follow-up. The analysis helps focus corrective and preventive actions on the “vital few” causes so that the greatest improvement can be achieved with targeted actions and stronger qualification planning.

Pareto Chart Analysis for Design Qualification of the Environment Monitoring System (EMS) not being performed:

8. Corrective and Preventive Action (CAPA) – Design Qualification of Environment Monitoring System (EMS) Not Performed:

Based on the DQ document, the EMS design is expected to be verified against the agreed URS, design specifications, system architecture, I/O requirements, field devices, software functionality, security, alarms, reporting, and power-failure management before qualification and routine use.

TypeCAPA ActionExpected Outcome
Corrective ActionRaise a deviation/quality event for failure to perform EMS Design Qualification.Formal documentation and investigation of the failure.
Corrective ActionPerform retrospective review of the approved URS, purchase specification, drawings, I/O list, DDC panels, sensors, software and system architecture.Confirmation that the installed/proposed EMS matches intended requirements.
Corrective ActionPrepare, review and approve the missing DQ protocol/report through Engineering, QA, IT/Automation and User Department.Documented design verification and approval.
Corrective ActionVerify EMS monitoring requirements for temperature, RH, differential pressure, door status and AHU running status.Critical monitoring parameters are correctly incorporated into the design.
Corrective ActionVerify user access, password controls, audit/event logging and defined security levels.Appropriate system security and controlled access are demonstrated.
Corrective ActionVerify alarm configuration, trend reports, event logs, UPS backup and recovery provisions.Critical EMS functions are confirmed before continued qualification/use.
Preventive ActionRevise the qualification SOP/VMP to make approved DQ mandatory before IQ/OQ and installation approval, as applicable.Prevents qualification stages from being skipped.
Preventive ActionIntroduce a DQ readiness checklist covering approved URS, drawings, I/O list, technical datasheets, control philosophy and vendor documents.Ensures required design inputs are available before DQ starts.
Preventive ActionDefine responsibilities and timelines for QA, Engineering, User Department, IT/Automation and vendor.Prevents delays caused by unclear ownership.
Preventive ActionTrain concerned personnel on DQ requirements and EMS qualification lifecycle.Improves technical awareness and compliance.
Preventive ActionAdd DQ status to project/qualification tracking and periodic management review.Provides timely escalation of overdue qualification activities.
Preventive ActionConduct QA effectiveness review after completion of DQ and subsequent IQ/OQ activities.Confirms CAPA effectiveness and prevents recurrence.

Effectiveness check: No EMS installation or qualification project should proceed to the next lifecycle stage without documented evidence that the required DQ review and approval have been completed.

9. Questions & Answers – Design Qualification of Environment Monitoring System (EMS):

  1. What is the purpose of Design Qualification for the EMS?
    The purpose is to verify that the proposed EMS design, specifications, major components, and engineering details meet the agreed User Requirement Specification and project requirements.
  2. What parameters are monitored by the EMS?
    The EMS monitors temperature, relative humidity, differential pressure, door status, and AHU running status.
  3. What is the role of DDC controllers in the EMS?
    DDC controllers receive field inputs, execute monitoring and control functions, collect historical data, and operate independently according to configured programs.
  4. How are environmental data recorded?
    Environmental parameters are monitored continuously and logged in the software at user-defined intervals, such as 10 or 15 minutes, for reporting and trending.
  5. What happens when temperature or humidity exceeds the defined limits?
    The EMS automatically generates an alarm when monitored values exceed the predefined acceptable limits.
  6. What security levels are available in the EMS?
    The system provides Operator, Supervisor, and Administrator security levels with different access rights.
  7. How does the EMS control unauthorized access?
    Users must log in with individual credentials, passwords are encrypted, unsuccessful login attempts are recorded, and accounts can be locked after repeated failed attempts.
  8. What reports can be generated by the EMS?
    The EMS can generate alarm and event reports, trend reports, log-viewer reports, and system summary reports.
  9. How does the EMS handle power failure?
    UPS support is provided for the server and field controllers so that the system can continue operating for a defined period and allow orderly shutdown or recovery.
  10. Why is Design Qualification important before EMS installation?
    DQ confirms that the proposed system design is suitable for the intended purpose and complies with the agreed URS before further qualification activities proceed.
  11. What documents are important during EMS Design Qualification?
    Important documents include the URS, system architecture diagram, input/output list, DDC panel list, DDC panel GA drawing, floor drawings, and technical datasheets.
  12. What should be done if a field device is found faulty?
    The device and its connecting cables should be physically checked. If replacement is required, the respective panel power supply should be switched off and the change should be handled through the applicable change-control procedure.
  13. What is the benefit of performing EMS DQ correctly?
    Proper DQ provides documented confirmation that the EMS design, monitoring functions, security, alarms, reporting, and supporting components are suitable for the intended environmental monitoring application.
  14. What is the risk if EMS DQ is not performed?
    The system may proceed without documented verification that its design meets the agreed requirements, potentially resulting in design gaps, incomplete monitoring functions, or qualification delays.

10. Reference Guidelines – Design Qualification of Environment Monitoring System (EMS):

The following guidelines and standards are relevant for the Design Qualification, computerized functions, environmental monitoring, data integrity, alarm management, and qualification of an EMS:

  1. EU GMP Annex 15 – Qualification and Validation
    Provides requirements for qualification of facilities, utilities, equipment, and systems, including Design Qualification (DQ) and verification against the approved URS. The current EU GMP Volume 4 lists Annex 15 as the qualification and validation reference.
    EU GMP Volume 4 – Annex 15
  2. EU GMP Annex 11 – Computerised Systems
    Applicable where the EMS uses computerized software for monitoring, alarms, electronic data, user access, audit trails, backup, archiving, and reporting. It requires a lifecycle and risk-based approach to computerized-system validation.
    EU GMP Annex 11 – Computerised Systems
  3. EU GMP Annex 1 – Manufacture of Sterile Medicinal Products
    Relevant for EMS used in sterile/aseptic manufacturing areas. Annex 1 addresses facility and system design, qualification, environmental monitoring, contamination control, alarms, and ongoing monitoring of critical environments.
    EU GMP Annex 1 – Sterile Medicinal Products
  4. WHO TRS No. 1019, Annex 3 – Good Manufacturing Practices: Guidelines on Validation
    Includes specific appendices covering qualification and validation of computerized systems, making it directly relevant to DQ and EMS validation activities.
    WHO Guidelines on Validation
  5. PIC/S GMP Guide PE 009 – Annex 15, Qualification and Validation
    Requires qualification and validation activities to be planned, documented, risk-based, and defined within the VMP or equivalent system.
    PIC/S GMP Guide – Qualification and Validation
  6. US FDA – 21 CFR Part 11, Electronic Records and Electronic Signatures
    Relevant when the EMS creates or maintains GMP electronic records. Key considerations include authorized access, electronic records, system controls, security, validation, and data integrity.
    FDA Part 11 Guidance
  7. ISPE GAMP® 5 – A Risk-Based Approach to Compliant GxP Computerized Systems, Second Edition
    Provides industry good-practice guidance for computerized-system lifecycle management, risk assessment, supplier involvement, specification, verification, and maintaining systems fit for intended use. It is guidance rather than a regulatory requirement.
    ISPE GAMP 5 Guide
  8. ISO 14644-1:2015 and ISO 14644-2:2015 – Cleanrooms and Associated Controlled Environments
    ISO 14644-1 addresses cleanroom classification by airborne particle concentration, while ISO 14644-2 provides requirements for monitoring plans demonstrating continued cleanroom performance. These are particularly relevant where the EMS supports cleanroom environmental monitoring.

error: Content is protected !!

This is the Premium Content

You can access this page after paying the subscription fees of 21 ₹ /month only.