GxP Insights

Risk-Based VMP and Lifecycle: Integrating ICH Q9/Q10 and Change Control to Maintain the Validated State

Learn how to make the Validation Master Plan truly risk-based and lifecycle-oriented: risk policy, change control, KPIs, master list and audit-proof strategies.

A Aldo Xhango 10 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
VMP Risk-Based e Lifecycle: integrare ICH Q9/Q10 e Change Control per mantenere lo stato validato

Risk-Based VMP and Lifecycle: Integrating ICH Q9/Q10 and Change Control to Maintain the Validated State

Risk-Based VMP and Lifecycle: how to make validation sustainable and defensible

An effective Validation Master Plan (VMP) should not only describe what has been validated. It must explain how the company decides what needs to be validated, to what depth and how the validated state is maintained over time.

The central point is this: the risk-based approach is not a trend. It is the only sustainable and defensible way to govern validation.

Two opposite errors often lead to difficult inspections:

  • under-validation, meaning gaps in critical assets, processes or systems;
  • over-validation, meaning validating everything in the same way, with excessive documentation and testing, until the plan can no longer be maintained.

The modern approach, consistent with Annex 15 and the logic of ICH Q9/Q10, pushes companies to use Quality Risk Management to define scope, extent of activities and maintenance of the validated state throughout the lifecycle.

Table of Contents

  • Why risk-based is the only sustainable and defensible way
  • Step 1 — Put the Risk Policy clearly in the VMP
  • Step 2 — Translate risk into validation strategy
  • Step 3 — Lifecycle: validated once does not mean validated forever
  • Step 4 — Change Control: the point where you win or lose
  • Step 5 — Computerised systems: from documentary CSV to risk-based assurance
  • Step 6 — Validation KPIs for mature sites
  • 30–60–90 day implementation roadmap
  • FAQ on the risk-based VMP
  • Do you want to truly apply risk-based and lifecycle principles to your VMP?

1. Why risk-based is the only sustainable and defensible way

A validation system cannot treat everything in the same way.

A critical autoclave, a sterile utility, a GxP computerised system and low-impact equipment cannot require the same level of testing, evidence and review.

The risk-based approach helps avoid two dangerous extremes:

  • doing too little where the risk is high;
  • doing too much where the risk is low.

1.1 Under-validation

Under-validation occurs when critical assets, systems or processes are not qualified or validated with sufficient depth.

Typical examples:

  • a GxP system not included in scope;
  • a critical utility qualified superficially;
  • an impacting change closed without validation impact assessment;
  • equipment used in production without adequate evidence;
  • cleaning validation not proportionate to the real risk.

During an audit, this immediately raises questions about the company’s ability to control product quality, patient safety and data integrity.

1.2 Over-validation

Over-validation is the opposite error: validating everything with the same level of detail, even when the risk is low.

The result is a heavy, slow system that is difficult to maintain.

Typical signals:

  • too many protocols that are not truly necessary;
  • repetitive testing without rationale;
  • time-based requalification on everything, without considering trends or criticality;
  • backlog of overdue activities;
  • huge documentation with limited practical value;
  • loss of credibility because the plan is not maintained.

A well-written risk-based approach in the VMP allows the company to demonstrate that it is not doing “less validation”, but the right validation where it is truly needed.

2. Step 1 — Put the Risk Policy clearly in the VMP

The first step is to clearly state in the VMP how the company applies Quality Risk Management to validation.

It is not enough to write “risk-based approach”. You must explain how it works.

2.1 What the Risk Policy must declare

In the VMP, you should indicate:

  • which risk assessment method you use;
  • how you define high, medium and low risk;
  • which criteria you use for severity, probability and detectability;
  • how risk is linked to the level of testing;
  • how risk is linked to the level of evidence;
  • when an independent QA review is required;
  • when requalification or revalidation is required;
  • how risk is reassessed in case of changes, deviations or trends.

2.2 Examples of usable methods

You may use different methods, provided they are defined and consistent.

Examples:

  • Severity / Probability / Detectability matrix;
  • FMEA;
  • impact assessment;
  • criticality assessment;
  • Low / Medium / High risk ranking;
  • risk-based testing strategy.

The choice of tool is less important than consistent application.

2.3 Example of a simple 3×3 matrix

A simple matrix may be sufficient if well documented.

Severity

Assesses the potential impact on:

  • product quality;
  • patient safety;
  • data integrity;
  • GMP compliance;
  • ability to control the process.

Probability

Assesses how plausible the failure mode is, considering:

  • system complexity;
  • deviation history;
  • frequency of use;
  • operational criticality;
  • previous experience;
  • level of automation or manual intervention.

Detectability

Assesses how easily the error can be detected before it impacts the product or release.

Examples of factors:

  • alarms;
  • interlocks;
  • in-process controls;
  • QA review;
  • audit trail;
  • double check;
  • routine monitoring.

The output may be classified as:

  • low risk;
  • medium risk;
  • high risk.

You do not need to be sophisticated. You need to be consistent, documented and defensible.

Validation Master Plan (VMP) GMP: How to Govern Validation and Defend It in EMA, AIFA, FDA and PIC/S Audits

3. Step 2 — Translate risk into validation strategy

The true value of a risk-based VMP is translating risk into an operational strategy.

Many VMPs declare Quality Risk Management, but do not explain what changes in practice.

3.1 High risk

For high-risk systems, processes or assets, the strategy should include:

  • full qualification or validation;
  • worst-case testing;
  • robust evidence;
  • independent QA review;
  • strict acceptance criteria;
  • deviations managed with a high level of attention;
  • structured periodic review;
  • possible event-based requalification or revalidation;
  • strong link with change control.

Examples:

  • critical utilities;
  • GxP computerised systems with impact on release or data integrity;
  • sterile processes;
  • cleaning validation for high-risk products;
  • critical equipment for CPP/CQA.

3.2 Medium risk

For medium-risk assets or processes, the strategy can be more targeted.

Examples of approach:

  • tests focused on critical parameters;
  • rationalisation of tests;
  • verification of main controls;
  • proportionate QA review;
  • complete but not excessive documentation;
  • attention to sensitive points;
  • periodic review based on data and trends.

The objective is to maintain control without creating unnecessary documentation.

3.3 Low risk

For low-risk elements, a leaner verification may be sufficient.

Examples:

  • basic verification;
  • procedural controls;
  • documentary confirmation;
  • documented commissioning, if appropriate;
  • justified exclusion from GMP scope, if applicable;
  • review only in case of relevant change.

Attention: low risk does not mean “no control”. It means proportionate control.

3.4 The bridge between QRM and the operational plan

The most important part is linking each risk level to a practical decision.

Example logic:

  • high risk → full testing and robust review;
  • medium risk → targeted testing on critical parameters;
  • low risk → basic verification and procedural control.

This is the bridge between Quality Risk Management and the validation plan. And it is exactly the bridge that many VMPs fail to build.

4. Step 3 — Lifecycle: validated once does not mean validated forever

A common mistake is considering validation as a one-time event.

In reality, a system validated today may no longer be under control tomorrow if the process changes, the software changes, components change or trends worsen.

Validation must be managed throughout the lifecycle.

4.1 What the VMP must explain

The VMP must describe how the company:

  • maintains the validated state;
  • monitors performance;
  • assesses trends and deviations;
  • decides whether to requalify;
  • decides whether to revalidate;
  • integrates CPV, PQR/APR and periodic review;
  • links change control and validation impact assessment;
  • manages obsolescence, upgrades and decommissioning.

4.2 Critical equipment

For critical equipment, a sustainable policy may be based on:

  • periodic review;
  • event-based triggers;
  • performance trends;
  • relevant deviations;
  • extraordinary maintenance;
  • out-of-tolerance calibrations;
  • impacting changes;
  • system use.

This approach is often more defensible than requalification every 12 months “regardless”, if the rationale is well documented.

4.3 Manufacturing processes

For manufacturing processes, the lifecycle should include:

  • PPQ;
  • Continued Process Verification;
  • trends of critical parameters;
  • deviation trends;
  • PQR/APR;
  • CAPA assessment;
  • process capability monitoring;
  • assessment of potential drift signals.

PQR/APR and CPV must become real inputs to decide whether the process remains in the validated state.

4.4 Critical utilities

For critical utilities, the strategy may include:

  • initial qualification;
  • routine monitoring;
  • microbiological/chemical/physical trends;
  • periodic review;
  • deviation management;
  • preventive maintenance;
  • change assessment;
  • possible targeted requalification.

Here too, the principle is always the same: data and risk must drive decisions.

5. Step 4 — Change Control: the point where you win or lose

Change control is often the point where the validated state is maintained or lost.

An apparently small change may impact critical parameters, software, data flow, recipes, materials, cleaning or process controls.

5.1 Validation Impact Assessment

A robust change control must always include a Validation Impact Assessment section.

This section must answer questions such as:

  • Is the system validated?
  • Does the change affect critical parameters?
  • Does the change affect set-points or recipes?
  • Does the change modify data flow or data integrity?
  • Does the change modify materials, components or configuration?
  • Does the change impact cleaning, process or controls?
  • Are tests required?
  • Is requalification required?
  • Is revalidation required?
  • Which documents must be updated?
  • Must the VMP or master list be updated?

5.2 Good example: proportionate decision

Case: replacement of a temperature probe on validated equipment.

Risk assessment:

  • equivalent specifications;
  • no change to the operating principle;
  • no impact on recipe or control logic;
  • critical component but replaced like-for-like.

Proportionate action:

  • calibration;
  • functional verification;
  • record update;
  • documented assessment;
  • no full OQ if the rationale demonstrates that it is not required.

This is an example of a proportionate and defensible decision.

5.3 Bad example: almost certain finding

Case: GxP software upgrade performed by IT without QA/Validation involvement.

Problems:

  • no validation impact assessment;
  • no data integrity assessment;
  • no documented testing of critical functions;
  • no audit trail review;
  • no documentation update;
  • no evidence of the validated state post-change.

During an audit, this is an almost certain finding, because you cannot demonstrate that the system remained under control after the change.

6. Step 5 — Computerised systems: from documentary CSV to risk-based assurance

For GxP computerised systems, the VMP must avoid two errors:

  • treating CSV as a documentation file separated from the PQS;
  • testing everything in the same way, without distinguishing critical and non-critical functions.

The more mature approach is based on assurance, risk and data integrity.

6.1 Identify critical functions

The VMP or CSV plan must clearly define how critical functions are identified.

Examples:

  • product release;
  • GMP calculations;
  • recipe management;
  • audit trail;
  • access management;
  • electronic signatures;
  • data flow;
  • data acquisition;
  • backup and restore;
  • interfaces with other systems;
  • reports used for GMP decisions.

6.2 Perform robust testing where needed

The most robust testing must focus on functions that can impact:

  • product quality;
  • patient safety;
  • data integrity;
  • regulatory compliance;
  • GMP decisions.

For low-impact functions, documentation can be leaner, provided the rationale is clear.

6.3 Streamline without losing control

A modern approach does not mean reducing control.

It means:

  • eliminating redundant tests;
  • using supplier evidence where applicable;
  • focusing internal testing on critical functions;
  • documenting the rationale;
  • keeping data integrity, audit trail, access and backup under control.

The VMP must show this logic clearly and defensibly.

7. Step 6 — Validation KPIs for mature sites

Validation KPIs are not always mandatory, but they are a sign of site maturity.

If an inspector asks:

“How do you measure the effectiveness of the validation system?”

having well-selected KPIs can make the difference.

7.1 Useful KPIs

Examples of useful KPIs:

  • percentage of change controls with completed validation impact assessment;
  • average closure time of validation deviations;
  • backlog of overdue requalifications;
  • percentage of periodic reviews completed on time;
  • trend of deviations by category: equipment, IT, utilities, cleaning;
  • percentage of validation-related CAPA closed on time;
  • number of requalifications triggered by changes or deviations;
  • number of gaps identified during periodic review.

7.2 How to use KPIs

KPIs must lead to decisions.

They should be used to:

  • identify backlog;
  • assign priorities;
  • trigger escalation;
  • justify resources;
  • improve the maintenance strategy;
  • feed Management Review or Quality Council.

A KPI without a decision is just a number. A KPI that drives actions demonstrates governance.

8. 30–60–90 day implementation roadmap

If you want to make the VMP more risk-based and lifecycle-oriented, you can follow a progressive roadmap.

8.1 From 0 to 30 days

Objective: align the documentation basis.

Actions:

  • align asset list, VMP, maintenance and calibrations;
  • verify consistency between VMP and master list;
  • identify missing assets or systems;
  • formalise risk matrix and criteria;
  • define High / Medium / Low categories;
  • identify any critical gaps;
  • assign owners for each action.

8.2 From 31 to 60 days

Objective: integrate risk into operational processes.

Actions:

  • integrate validation impact assessment into change control;
  • update qualification and validation SOPs;
  • build or update the Validation Master List;
  • assign status and dates to assets;
  • define escalation for high-impact changes;
  • link change control, deviations and CAPA to the validation strategy.

8.3 From 61 to 90 days

Objective: make the system sustainable throughout the lifecycle.

Actions:

  • define the policy for maintaining the validated state;
  • establish criteria for CPV, review, requalification and revalidation;
  • create an audit evidence package by category;
  • define essential KPIs;
  • set up periodic review;
  • prepare real examples of risk-based decisions;
  • integrate the VMP with Management Review or Quality Council, if applicable.

9. FAQ on the risk-based VMP

9.1 When should I revalidate after a change?

You should revalidate when the change impacts critical parameters, process control, cleaning, data integrity or control strategies.

The decision must be risk-based and documented in the change control through validation impact assessment.

9.2 Does risk-based mean doing fewer tests?

No.

Risk-based means performing the right tests where the risk is real, avoiding both gaps and unnecessary paperwork.

The objective is not to reduce work, but to make it proportionate, defensible and sustainable.

9.3 Can I use supplier documentation to reduce internal testing?

Yes, but only if the supplier documentation is applicable, assessed and linked to your specific use.

You must verify:

  • scope of the document;
  • version of the system or component;
  • conditions tested;
  • functions covered;
  • GxP criticality;
  • any gaps compared with your process.

9.4 How do I demonstrate that lifecycle is under control?

You can demonstrate it through:

  • change control with validation impact assessment;
  • periodic review;
  • CPV;
  • PQR/APR;
  • trending;
  • deviations/CAPA;
  • documented requalification or revalidation;
  • updated master list;
  • KPIs, if implemented.

9.5 How do I avoid over-validation?

To avoid over-validation, you must:

  • define clear risk criteria;
  • link risk and level of testing;
  • distinguish critical and non-critical functions;
  • use supplier evidence where applicable;
  • avoid redundant tests;
  • periodically review backlog and unnecessary activities.

10. Do you want to truly apply risk-based and lifecycle principles to your VMP?

If you want to truly apply a risk-based and lifecycle-oriented approach with ready-to-use models, such as risk matrix, impact assessment, master list, lifecycle tracker and real audit cases, you will find everything in the GuideGxP premium guide:

Validation Master Plan (VMP): Govern Validation and Defend It During Audits

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP