1. Introduction for URS for Environmental Monitoring System Software:
The URS for Environmental Monitoring System (EMS) Software explains what the environmental monitoring system is expected to do in a pharmaceutical facility. In simple terms, this system continuously watches important environmental conditions in manufacturing and processing areas so that the required conditions can be maintained. The software is intended for online monitoring, data recording, alarm generation, and logging of different AHU and room parameters. It is also expected to include features suitable for 21 CFR Part 11 compliance. The EMS collects information from sensors and instruments connected to different Air Handling Units through DDC panels. Important parameters include temperature, relative humidity, AHU fan status, pre-filter status, fine-filter status, and airflow measured in CFM. For example, the document specifies a temperature range of 20–27°C and relative humidity range of 35–60% for return air monitoring. If any monitored value goes outside its set limit, the EMS generates an alarm so responsible personnel can take timely action. Differential pressure, however, is stated to be monitored manually. The system stores monitoring information in the form of trends and audit trails, making it easier to review past conditions and investigate any abnormal event. The software also provides graphical displays, alarm handling, reports, online and offline trends, log viewing, data backup, and different security access levels such as Administrator, Supervisor, and Operator. Safety is also considered. During power failure or system malfunction, the system should remain in a safe condition, should not restart automatically, and should require human intervention before operation resumes. The vendor is expected to provide manuals, system specifications, qualification documents such as DQ, IQ, OQ and PQ, warranty information, and other required technical documentation. Overall, this URS provides a clear guide for purchasing, installing, qualifying, operating, and maintaining a reliable EMS for pharmaceutical environmental control.
Skip to PDF content2. Flow Diagram for URS for Environmental Monitoring System Software:
The flow diagram explains how the Environmental Monitoring System (EMS) Software works in a pharmaceutical facility. The process starts with field instruments installed in AHUs and processing areas. These instruments monitor important parameters such as temperature, relative humidity, fan status, pre-filter status, fine-filter status, and airflow in CFM. The collected signals are sent to the DDC panel, which transfers the information to the EMS software.

The EMS software continuously displays and records the environmental data. It also stores information in the system database, including trends, alarms, events, and audit trails. Authorized users such as administrators, supervisors, and operators can access the system according to their assigned security levels. If any monitored parameter goes outside its defined limit, the system generates an alarm. Users can review alarms, trends, and reports, take necessary corrective action, and maintain proper environmental control and regulatory compliance.
3. Brainstorming for URS for Environmental Monitoring System Software not prepared:
The brainstorming diagram explains the possible reasons, risks, operational effects, and immediate actions related to the situation where the User Requirement Specification (URS) for the Environmental Monitoring System (EMS) has not been prepared. The main possible causes include undefined user requirements, poor planning, lack of cross-functional input, no responsible owner, incomplete process understanding, delayed vendor discussion, and documentation backlog.

The diagram also highlights compliance risks such as gaps in 21 CFR Part 11 requirements, delayed validation, missing audit-trail requirements, weak data-integrity controls, and inadequate definition of alarms and security. Operationally, the absence of an approved URS may cause procurement delays, installation delays, improper monitoring setup, unclear system scope, training gaps, and difficulty during qualification. Immediate actions include assigning a responsible team, collecting user needs, defining monitoring parameters, alarms, reports, and security levels, reviewing requirements with QA, Engineering, and IT, and finally approving the URS before system implementation.
4. 5 Why Analysis for URS for Environmental Monitoring System Software not prepared:
The 5 Why Analysis explains the root cause behind the issue that the User Requirement Specification (URS) for the Environmental Monitoring System (EMS) was not prepared. The first reason identified is that user requirements were not properly collected and documented before starting the project. This happened because no formal requirement-gathering meeting was conducted with departments such as QA, Engineering, Production, and IT. The next reason is that responsibility and ownership for preparing the URS were not clearly assigned. This shows a weakness in project planning and cross-functional coordination. Further analysis indicates that there was no defined procedure or management system to ensure timely preparation, review, and approval of the URS.

The root cause is therefore a lack of a defined system, clear ownership, and proper cross-functional planning. Corrective actions include assigning a URS owner, collecting user requirements, reviewing them with relevant departments, and approving the URS before system implementation.
5. Heat Map for URS for Environmental Monitoring System Software not prepared:
The heat map analysis shows the level of risk associated with the User Requirement Specification (URS) for the Environmental Monitoring System not being prepared. The diagram connects different root causes such as unclear ownership, lack of training, poor project planning, incomplete requirement collection, documentation backlog, delayed vendor discussion, and weak coordination between QA, Engineering, IT, and other users. These causes can lead to several operational and compliance risks. The heat map evaluates each risk using Likelihood and Impact, generally on a scale from very low to very high. Lower-risk issues appear in the green zone, while increasing risk moves through yellow and orange toward the red zone.

The highest-risk areas include compliance gaps and data integrity risks, because they can directly affect regulatory expectations and reliability of the monitoring system. Other important risks include validation delays, unclear system scope, alarm-setting errors, qualification difficulties, training gaps, and procurement delays. The analysis supports prioritizing corrective actions based on risk severity.
6. Fault Tree Analysis for URS for Environmental Monitoring System Software not prepared:
The Fault Tree Analysis explains why the User Requirement Specification (URS) for the Environmental Monitoring System (EMS) was not prepared. The top event is divided into four major failure areas: planning failure, ownership or people failure, requirement collection failure, and documentation or compliance failure. Planning issues include absence of structured project planning, missing schedules, and implementation starting before requirements were defined. People-related causes include unclear responsibility, no assigned URS owner, limited cross-functional involvement, and inadequate training. Requirement collection failures arise when user needs, monitoring parameters, alarms, and departmental inputs are not properly gathered. Documentation and compliance failures include missing templates, documentation backlog, and undefined requirements for audit trails, reports, security, and 21 CFR Part 11. The analysis identifies the root cause as inadequate ownership, weak requirement-gathering, and poor project planning. Corrective actions include assigning ownership, collecting requirements, defining system functions, conducting cross-functional review, and approving the URS before implementation.

7. Pareto Chart Analysis for URS for Environmental Monitoring System Software not prepared:
The Pareto Chart Analysis identifies the main reasons why the User Requirement Specification (URS) for the Environmental Monitoring System (EMS) was not prepared. The chart ranks causes from highest to lowest contribution and also shows the cumulative percentage. The major cause is unclear ownership or responsibility, followed by lack of project planning and insufficient cross-functional input. Together, these three causes account for about 75% of the overall problem, indicating that they should receive the highest priority. Other contributing factors include inadequate understanding of user needs, documentation backlog, lack of training or awareness, and delayed vendor discussions. The cumulative line helps show how a small number of major causes contribute to most of the problem.

The analysis suggests focusing corrective actions on assigning clear URS ownership, including URS activities in project planning, ensuring involvement of QA, Engineering, IT and users, improving training, and managing documentation within defined timelines.
8. Corrective Action and Preventive Action (CAPA):
URS for Environmental Monitoring System (EMS) Was Not Prepared
The source document shows that the EMS URS is intended to define online monitoring, data/alarm logging, technical requirements, security, audit trail, reporting, backup, and 21 CFR Part 11-related expectations. It also identifies the need for qualification documents and vendor documentation.
The CAPA below is a recommended quality-system response based on the identified failure.
| Type | Action |
|---|---|
| Corrective Action 1 | Immediately assign a responsible URS owner from QA/Engineering for EMS documentation. |
| Corrective Action 2 | Conduct a cross-functional meeting involving QA, Engineering, IT, Production/User Department, Validation, and Vendor. |
| Corrective Action 3 | Collect and document complete EMS user requirements, including temperature, RH, fan status, filter status, CFM, alarms, reports, trends, audit trail, security, backup, and user access levels. |
| Corrective Action 4 | Prepare the EMS URS using the approved company format and assign a document number, revision status, and effective date. |
| Corrective Action 5 | Review the URS against system functionality, data-integrity requirements, applicable 21 CFR Part 11 controls, and validation requirements. |
| Corrective Action 6 | Obtain documented review and approval from all responsible departments before procurement, configuration, qualification, or routine use. |
| Corrective Action 7 | Perform a retrospective impact assessment to determine whether any system procurement, installation, configuration, or validation was performed without an approved URS. |
| Corrective Action 8 | Update or repeat qualification activities where necessary to demonstrate traceability between approved requirements and tested system functions. |
Preventive Actions
- Revise the SOP for URS preparation and project initiation to require an approved URS before purchase, configuration, installation, or validation of computerized systems.
- Make URS approval a mandatory milestone in the project and validation lifecycle.
- Introduce a URS preparation checklist covering functional requirements, alarms, reports, user access, audit trail, backup, security, data retention, interfaces, and compliance requirements.
- Define clear responsibility using a RACI matrix for QA, Engineering, IT, Validation, User Department, and Vendor.
- Train concerned personnel on URS preparation, review, approval, and traceability.
- Maintain a centralized tracker for pending URS documents with target dates and responsible persons.
- Require QA approval before issuing purchase orders for GMP-critical computerized systems.
- Link each URS requirement to DQ/IQ/OQ/PQ or computerized-system validation testing through a traceability matrix.
- Include periodic QA review of URS compliance in internal audits.
- Verify CAPA effectiveness after implementation by confirming that future EMS or computerized-system projects begin only after an approved URS is available.
9. Questions and Answers:
Q1. What is the purpose of the Environmental Monitoring System (EMS)?
The EMS is used for online monitoring, data recording, and alarm logging of environmental parameters related to AHUs and processing areas.
Q2. Why is a User Requirement Specification (URS) required for EMS?
The URS defines what the user expects from the EMS and forms part of the procurement agreement with the selected vendor.
Q3. Which parameters are monitored by the EMS?
The EMS monitors temperature, relative humidity, AHU fan status, pre-filter status, fine-filter status, and airflow in CFM.
Q4. What happens when a monitored parameter goes outside its set limit?
The EMS generates an alarm for the affected parameter so that the condition can be identified and reviewed.
Q5. How does the EMS receive data from field instruments?
Field instruments send data through the DDC panel to the Environmental Monitoring System software.
Q6. How is EMS data recorded?
The EMS records data in the form of trends and audit trails.
Q7. What software functions are expected in the EMS?
Expected functions include graphics viewing, alarm handling, reports, online and offline trends, log viewing, audit trail, database backup, and user security.
Q8. What user access levels are defined in the system?
The document defines Administrator, Supervisor, and Operator access levels.
Q9. What compliance requirement is mentioned for the EMS software?
The document states that the EMS software should be suitable for 21 CFR Part 11 compliance.
Q10. What is the main risk if the EMS URS is not prepared?
Without a prepared URS, system requirements may not be clearly defined before procurement, configuration, qualification, and use, creating gaps in traceability and system expectations.
Q11. What should be done if the EMS URS has not been prepared?
A responsible owner should be assigned, user requirements should be collected, the URS should be prepared, reviewed by relevant departments, and formally approved before implementation.
Q12. Which departments should participate in URS preparation?
The preparation should involve the user department and relevant functions such as QA, Engineering, IT, and Validation so that functional and compliance requirements are properly captured.
Q13. What vendor documents are expected for the EMS?
The vendor is expected to provide system requirement specifications, software user manuals, computer system validation documents, warranty certificates, and qualification documents.
Q14. How should power failure be handled by the system?
The system should remain safe during power failure, should not restart automatically, and should require human intervention before restart.
Q15. How can recurrence of missing URS preparation be prevented?
Recurrence can be prevented by defining URS preparation in the project procedure, assigning clear ownership, using a URS checklist, completing cross-functional review, training personnel, and making approved URS availability mandatory before system implementation.
10. Reference Guidelines – URS for Environmental Monitoring System (EMS):
The following guidelines and regulations are relevant when preparing, reviewing, approving, and validating the User Requirement Specification (URS) for a pharmaceutical Environmental Monitoring System:
- EU GMP Annex 11 – Computerised Systems
Section 4.4 specifically states that User Requirement Specifications should describe the required functions of the computerized system, be based on documented risk assessment and GMP impact, and remain traceable throughout the system life cycle.
EU GMP Annex 11 – Computerised Systems - EU GMP Annex 15 – Qualification and Validation
Annex 15 states that equipment, facilities, utilities, or systems should be defined through a URS and/or functional specification, with quality requirements incorporated and GMP risks controlled. The URS should remain a reference throughout the validation life cycle.
EudraLex Volume 4 – EU GMP Guidelines - 21 CFR Part 11 – Electronic Records and Electronic Signatures
Applicable where regulated electronic records or electronic signatures are maintained. Relevant controls include system validation, authorized access, audit trails, record protection, operational checks, authority checks, and controls over system documentation.
FDA Part 11 Scope and Application Guidance - 21 CFR Part 211.68 – Automatic, Mechanical and Electronic Equipment
Requires suitable controls over computerized systems used in pharmaceutical manufacturing, including appropriate control of changes, accuracy of data, and maintenance/checking of computerized equipment. - PIC/S PI 011 – Good Practices for Computerised Systems in Regulated GXP Environments
Provides guidance for lifecycle management, validation, documentation, security, data integrity, and control of GxP computerized systems. PIC/S notes that PI 011 is currently under revision.
PIC/S Publications - ISPE GAMP 5 – A Risk-Based Approach to Compliant GxP Computerized Systems, Second Edition
Provides industry good-practice guidance for defining user requirements, system lifecycle activities, risk-based validation, supplier involvement, roles and responsibilities, and demonstrating that computerized systems are fit for intended use. GAMP is industry guidance rather than a regulation. - WHO Guidelines on Validation and Data Integrity
WHO guidance states that GxP computerized systems should be suitable for their intended use, appropriately validated, maintained in a validated state, and controlled to protect data integrity throughout the data lifecycle.




