GxP Insights

Process Validation Protocol: Template and Structure

How to build a process validation protocol template compliant with EU GMP Annex 15: the mandatory sections of point 5.22, the number of batches and the acceptance criteria. With an operational table of typical errors and audit-ready recommendations.

G GuideGxP 5 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Illustrazione editoriale GuideGxP a colori sul tema GMP: protocollo di convalida di processo farmaceutico.

The process validation protocol is the document that turns your validation strategy into inspection evidence: it defines, before execution, what will be demonstrated, on which batches, with which sampling plans and against which acceptance criteria. A well-built process validation protocol template is the difference between a defensible validation and a pile of data an inspector can dismantle with two questions. In this guide we go through the structure required by EU GMP Annex 15, section by section, the most frequent mistakes and how to set up a reusable template for your site's processes.

What a process validation protocol template must contain according to Annex 15

The primary regulatory reference in Europe is Annex 15 of EudraLex Volume 4 (Qualification and Validation, in force since October 2015). Point 5.22 explicitly lists the elements the protocol must include: a short description of the process with reference to the Master Batch Record, functions and responsibilities, a summary of the Critical Quality Attributes (CQAs) to be investigated, the Critical Process Parameters (CPPs) with their limits, non-critical attributes and parameters with the justification for their inclusion, the list of equipment and facilities with calibration status, analytical methods and their validation status, in-process controls with acceptance criteria and rationale, any additional testing, the sampling plan with its rationale, the methods for recording and evaluating results and, where applicable, the batch release and certification process.

The regulatory message is clear: nothing that will be measured during validation can be decided after the fact. CPPs, CQAs and acceptance criteria must derive from development data or documented process knowledge, not from the outcome of the validation batches.

Before the protocol: validation approach and lifecycle

The protocol does not appear out of nowhere: it flows from the Validation Master Plan (Annex 15, point 2.5) and from the chosen validation approach. Annex 15 allows three: the traditional approach (points 5.18–5.22), where a defined number of batches is manufactured under routine conditions to confirm reproducibility; Continuous Process Verification (points 5.23–5.25), applicable when a Quality by Design approach ensures a high degree of quality assurance through the control strategy; and the hybrid approach (points 5.26–5.27), which combines the two when robust historical product and process knowledge exists.

The FDA, in its 2011 guidance Process Validation: General Principles and Practices, frames the same logic in three lifecycle stages: Stage 1 Process Design, Stage 2 Process Qualification (which includes the Process Performance Qualification, PPQ) and Stage 3 Continued Process Verification. The protocol we discuss in this article is, in FDA terminology, the PPQ protocol: the moment you demonstrate that the designed process is capable of reproducible commercial manufacturing. For European regulatory submissions, the data to be provided are defined by the EMA guideline on process validation for finished products (Rev 1, applicable since August 2016).

Topics like this one — protocols, qualification, inspections — are the daily bread of The Pragmatic GMP, GuideGxP's free weekly newsletter: once a week, one GMP topic broken down into ready-to-use operational decisions. Subscribe here.

The structure of the protocol, section by section

The table below turns the requirements of point 5.22 into an operational template, with the errors inspectors find most often in each section.

Protocol sectionExpected contentTypical error
Purpose and process descriptionConcise process flow, reference to the Master Batch Record and its versionReferences to superseded or not-yet-approved MBR versions
Functions and responsibilitiesWho drafts, executes, reviews and approves; role of QA and ProductionResponsibility for deviation assessment left unassigned
CQAs and CPPsSummary of CQAs to investigate and CPPs with limits, linked to development dataLimits copied from release specifications without a process rationale
Non-critical parametersNon-critical attributes/parameters included, with justificationInclusion "just in case" without criteria: everything becomes critical
Equipment and facilitiesList with qualification and calibration statusMeasuring instruments with calibration expired during execution
Analytical methods and IPCsValidation status of methods, in-process controls with criteria and rationaleMethods not yet validated at the time of execution
Sampling planPoints, sample sizes and statistical rationale of the additional samplingSampling identical to routine: the validation demonstrates nothing extra
Recording and evaluationHow results are recorded, how deviations and OOS are handledNo predefined rules for deviations occurring during validation
Batch releaseFate of the validation batches and conditions for certificationRelease taken for granted before the report is approved

How many batches do you really need?

Point 5.20 of Annex 15 states that, as a general principle, a minimum of three consecutive batches manufactured under routine conditions could constitute a validation, but it requires the number to be justified: process complexity, the use of standard methods and the site's experience with similar products all count. "Three" is therefore not a magic number to quote in a protocol without a rationale — and Annex 15 itself foresees that the initial data may need to be supplemented with subsequent batches as part of ongoing process verification. The FDA, since 2011, has abandoned any fixed number altogether: the number of PPQ batches must be determined based on risk and on the expected variability of the process.

After execution: report, deviations and ongoing verification

The approved protocol is binding: any change during execution must be handled as a documented deviation and assessed in the final report, which must answer the predefined acceptance criteria point by point. Initial validation does not close the lifecycle: points 5.28–5.32 of Annex 15 require Ongoing Process Verification demonstrating that a state of control is maintained throughout the product's commercial life, with scope and frequency reviewed periodically.

Finally, watch the regulatory calendar: PIC/S has published its revised Recommendations on Qualification and Validation (PI 006-4), entering into force on 1 October 2026, superseding the four previous recommendations on the Validation Master Plan, IQ/OQ, non-sterile process validation and cleaning validation. Anyone updating their protocol template today should already align it with the inspection expectations of this document.

GuideGxP recommendation

Build a single site-wide protocol template, approved by QA, and ban local copies: every validation must start from the same skeleton, with the sections of point 5.22 already in place. Before drafting the protocol, always verify three prerequisites: equipment qualification closed, analytical methods validated, MBR approved. Define in the protocol — not downstream — how deviations and OOS results will be managed during execution. And link every protocol to the VMP: it is the first thing the inspector does, in the opposite direction.

To set up the full governance — validation inventory, templates, management of validation deviations and the transition to PI 006-4 — the GuideGxP guide Validation Master Plan (VMP) in GMP includes ready-to-use Word and Excel templates and an audit-ready roadmap.

Official sources

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP →