A qualified Environmental Monitoring System does not stay qualified on its own. The state of control is maintained through recurring activities — calibration, maintenance, verification, data review, change management — which must be planned, executed and documented with the same discipline as the initial qualification. The difference is that qualification has a budget, a date and a project owner; operation has only a procedure, and it survives or not depending on how well that procedure was thought through.
The question that sums up this phase is: if an inspector asked tomorrow for evidence that the system is still reliable, which documents would be shown and who signed them? If the answer is “the qualification report from three years ago”, the operational phase has not been governed. If the answer includes a calibration plan executed on schedule, maintenance records, audit trail reviews, a periodic review report and traceable change management, the system is in a state of control.
Why the operational phase determines the value of the investment
The cost of an EMS is not concentrated in the purchase: it is spread across the years in which the system is maintained, calibrated, updated and overseen. It is also across those years that confidence in the data is built or lost. Environmental data supports a GMP decision only if the instrument that generated it was in a valid calibration state, if the system was maintained, and if this can be demonstrated.
There is a second, less obvious reason. Recurring activities are the mechanism by which an organisation notices problems before they become deviations: an instrument drifting gradually, an alarm repeating without ever being closed, a component failing more often than expected, an audit trail showing an unexpected pattern of changes. Those who perform these activities as a formality do not read them; those who use them as a surveillance tool extract information from them.
The regulatory frame
| Level | What it establishes regarding operational management |
|---|---|
| Regulatory requirement (EudraLex Volume 4, Part I and Annex 15) | Require equipment to be maintained and calibrated under a defined programme, activities to be recorded, and the qualified state to be maintained through change control, with requalification assessed on a risk basis. |
| Regulatory requirement (Annex 11, January 2011 revision) | For the computerised component, requires periodic evaluation of the system, incident management, change control, access management, backup and continuity. |
| Regulatory requirement (EudraLex Volume 4, Annex 1) | Requires the monitoring programme to be reviewed periodically and integrated into the contamination control strategy, with trend evaluation. |
| Technical standard requirement (ISO 21501-4; ISO 14644 series) | Define performance and calibration requirements for optical airborne particle counters and methods for classification. Relevant as technical criteria for the calibration programme, where adopted. |
| Manufacturer's specification | The reference for the foreseen maintenance interventions, wear components and recommended checks on the specific instrument. |
| GuideGxP operational recommendation | Define in a single document the operational management plan — calibration, maintenance, checks, reviews, responsibilities and justified frequencies — approved at release, not reconstructed later. |
Technical guidance
Calibration programme
What makes a calibration programme defensible:
- List of instruments subject to calibration, with unique identifiers and criticality assigned according to the use of the data they produce.
- Traceability of calibrations to recognised standards, with certificates available and retained.
- Defined and justified intervals. There is no universal frequency: the interval is set from the manufacturer's guidance, the criticality of use, the stability observed historically and site experience, and the rationale is documented. An interval may be changed, but the change must be justified with data.
- As-found and as-left recording. The condition found before the intervention is the information that makes it possible to assess the impact on data produced since the last valid calibration: without it, that assessment cannot be made.
- Out-of-tolerance handling. This must be defined upstream: who assesses, within what time, which data is potentially affected, how the impact assessment is documented and what decisions follow. It is the procedure that most often is missing, and the one needed at the worst moment.
- Calibration status visible and verifiable before use, with management of expired or out-of-service instruments.
Preventive and corrective maintenance
- Plan derived from the manufacturer's specifications and adapted to site conditions of use, with defined frequencies and assigned responsibilities.
- Wear components and consumables: must be identified, with availability assured and replacement criteria defined. A missing spare is a trivial and frequent cause of prolonged unavailability.
- Accessibility: interventions in classified areas require planning, authorisation and often coordination with production. If the intervention requires entry into a critical area, the contamination impact must be assessed.
- Corrective maintenance: recorded as such, with root cause analysis for recurring events and assessment of the impact on data acquired during the malfunction.
- Supplier interventions: authorised, logged, with verification of the system state at the end of the intervention before return to use.
Periodic checks and functional tests
Beyond calibration, the system requires checks confirming its overall behaviour: alarm and notification testing, verification of time synchronisation, data restore testing from backup, verification of line and connection integrity per the supplier's methods, configuration check against the approved baseline. Each with a defined frequency and a recorded outcome.
Data review and audit trail review
Data review is not the same as audit trail review, and neither replaces the other. The first looks at environmental results and trends; the second looks at who did what in the system. Both must be planned with defined scope, frequency, responsibilities and evidence, on a risk basis. Trend analysis in particular is the tool by which slow drifts are identified — drifts that a single excursion does not reveal.
Periodic review of the system
This is documented verification that the system remains in a state of control and that the assumptions behind qualification still hold. Typical content:
- changes made since the last review and their handling through change control;
- deviations, incidents and malfunctions recorded, with actions and closure status;
- execution of the calibration and maintenance plan against schedule;
- outcomes of data and audit trail reviews;
- account and access management over the period;
- restore tests performed;
- status of support, software versions and obsolescence;
- explicit conclusion on the state of control and resulting actions.
Change management and obsolescence
Every change — adding or relocating points, software updates, component replacement, changes to limits or configuration — goes through change control, with impact assessment on the qualified state and definition of the verifications required. Obsolescence must be managed in advance: when the supplier announces end of support for a version or a component, the useful time to plan replacement is what runs from that moment, not what is left once support has already ceased.
Working tool: operational management plan
Table to be completed at system release and kept current. Frequencies and owners must be defined and justified by the site.
| Activity | Frequency (to be set) | Owner | Evidence produced |
|---|---|---|---|
| Instrument calibration | Certificates with as-found and as-left | ||
| Preventive maintenance | Intervention records | ||
| Alarm and notification testing | Test report | ||
| Time synchronisation check | Check record | ||
| Restore test from backup | Test report | ||
| Sampling line integrity check | Record per supplier method | ||
| Configuration check against baseline | Documented comparison | ||
| Data and trend review | Review report | ||
| Audit trail review | Review record | ||
| Account and permission review | Verified and approved list | ||
| System periodic review | Report with conclusion | ||
| Spares availability and support check | Updated status |
A practical scenario
At a site we will call Site Delta — realistic but fictional — the periodic calibration of a particle counter returns an out-of-tolerance result. The instrument is adjusted, returned to service, and the event is closed as a maintenance activity.
The problem surfaces during an audit: nobody assessed what that result means for the data produced by the instrument between the last valid calibration and the current one. The question is legitimate and direct: did that data support decisions? If so, with what margin of reliability?
The cause is not technical but procedural. What is missing is a procedure establishing, before the case arises, that an out-of-tolerance result triggers a formal impact assessment: identification of the period concerned, list of decisions that rested on it, evaluation of the magnitude of the deviation against applicable criteria, documented and approved conclusion. With that procedure, the event would have been handled in a few hours. Without it, it requires a retrospective reconstruction under pressure, with an uncertain outcome.
At the same site, the following periodic review highlights a second element: the as-found record had not been requested from the calibration service provider, and was therefore unavailable. The correction — adding the requirement to the service contract — is simple, but only if someone notices before it is needed.
Common mistakes and red flags
- Not requiring as-found recording. Without it, impact assessment of an out-of-tolerance result is not possible.
- Treating an out-of-tolerance result as routine maintenance. It must be handled as an event with potential impact on data, under a procedure defined in advance.
- Setting calibration intervals by convention. They must be defined and justified; if changed, the change must be supported by data.
- Confusing data review with audit trail review. They are distinct and complementary activities.
- Deferring the restore test. A backup never restored is not a guarantee.
- Not checking configuration against the baseline. Configuration drift is silent and is typically discovered during an investigation.
- Managing supplier interventions without logging. Every intervention on a qualified system must be authorised, recorded and verified on completion.
- Ignoring end-of-support announcements. Obsolescence is planned when it is announced, not when it becomes a problem.
- Treating periodic review as a formality. It is the instrument through which the state of control is demonstrated, and the occasion to spot problems before they become deviations.
How to document
- Operational management plan approved at release, with activities, justified frequencies, responsibilities and expected evidence.
- Calibration programme with instrument list, traceability, intervals and rationale.
- Out-of-tolerance handling procedure with impact assessment criteria.
- Maintenance records, preventive and corrective, with outcomes and parts used.
- Records of periodic checks and functional tests.
- Data and audit trail review reports.
- Periodic review report with explicit conclusion and actions.
- Change register with impact assessment and verifications performed.
- Obsolescence management plan kept up to date.
Key takeaways
- The qualified state is maintained through planned recurring activities; it does not preserve itself.
- The as-found record is the precondition for assessing the impact of an out-of-tolerance result.
- Calibration intervals are justified, not inherited.
- Data review and audit trail review are distinct and complementary activities.
- A backup is worth exactly as much as its verified restore.
- Periodic review is how the state of control is demonstrated — and maintained.
Frequently asked questions
How often should a monitoring instrument be calibrated?
There is no universal frequency. The interval is set from the manufacturer's guidance, the criticality of data use, the stability observed and site experience, and must be documented with its rationale. Changing it is possible, provided the change is justified by data.
What should be done if a calibration is out of tolerance?
Trigger the impact assessment procedure: identify the period since the last valid calibration, identify the data and decisions potentially affected, evaluate the magnitude of the deviation against applicable criteria and document the conclusion with approval. The procedure must be written before the case arises.
How often should periodic review be performed?
At a frequency defined by the company according to system criticality and its own computerised systems policy, and in any case when significant changes occur. The choice must be justified and documented.
Does environmental trend review replace audit trail review?
No. The first concerns monitoring results, the second concerns operations performed on the system and on records. They are complementary activities, both necessary and with different purposes.
How are supplier interventions on the system managed?
With prior authorisation, logged and time-limited access, recording of the work performed and verification of the system state at the end, before return to use. Responsibilities must be defined in the service contract.
When does a maintenance activity require requalification?
When it may affect the qualified state: replacement of components influencing measurement, configuration changes, software updates, infrastructure work. The assessment is performed within change control on a risk basis, and is linked to the criteria defined during system qualification.
Regulatory and technical references
- EudraLex Volume 4 — EU Guidelines for Good Manufacturing Practice (European Commission): Part I, Annex 1 (applicable from 25 August 2024), Annex 11 (January 2011 revision), Annex 15 (in operation from 1 October 2015).
- ISO 21501-4 — Determination of particle size distribution: light scattering airborne particle counter for clean spaces.
- ISO 14644-1 — Cleanrooms and associated controlled environments: classification of air cleanliness by particle concentration.
- ICH Quality Guidelines — ICH Q9(R1) Quality Risk Management.
- PIC/S — Guides and Guidance Documents.
Continue the project journey
This article is part of the GuideGxP Environmental Monitoring Systems pathway, which follows the life cycle of an EMS project from requirements definition through to operational management.
- Upstream: FAT, SAT, IQ, OQ and PQ of the system and software, Annex 11 and data integrity.
- As the system ages: retrofit and gap assessment of an existing system and total cost of ownership.
- GuideGxP regulatory foundations: the audit-ready environmental monitoring plan.
Want analysis like this straight to your inbox? Subscribe to The Pragmatic GMP, the GuideGxP newsletter for professionals working daily with GMP, qualification and data integrity.