A cleaning cycle can finish with a green status while the wrong route was selected, a critical parameter was changed without review or part of the electronic record was lost. Automation is useful only when its decisions correspond to the approved process and its records allow someone to reconstruct what actually happened. For CIP and SIP, the central challenge is connecting recipes, physical equipment states and quality decisions.
This article covers PLC, HMI and supervisory functions supporting cleaning and steam-in-place treatment. It addresses recipe governance, interlocks, abnormal situations and electronic evidence. It does not prescribe a particular control architecture or assume that buying a software package establishes GMP compliance. The recommendations require adaptation to the system’s intended use and the applicable regulatory record obligations.
A recipe implements a procedure; it does not replace one
The approved cleaning or SIP procedure defines the intended outcome, equipment scope, prerequisites, operating conditions and response to deviations. The automation recipe implements selected parts of that procedure. Manual assembly, connection checks, chemical identity, sampling and equipment disposition may remain outside the PLC. Identify those interfaces explicitly so an automated completion signal does not imply that every GMP task has been performed.
Separate the approved master recipe from the instance executed for a particular cycle. The cycle record should identify the equipment, selected route, recipe version, relevant parameter values and execution context. If an authorised operator can adjust parameters within an approved range, record the actual values used. A report containing only the recipe name cannot demonstrate which version or settings governed the cycle.
Distinguish operational setpoints, permitted adjustment ranges, alarm thresholds and acceptance criteria. They may interact, but they serve different purposes. Equipment design pressure is a mechanical constraint; a SIP exposure parameter belongs to the validated process. A conductivity endpoint controls a rinse phase; it is not automatically a residue acceptance criterion. Clear terminology prevents software limits from acquiring unsupported scientific meaning.
Regulatory basis and status of guidance
EU GMP Annex 11, January 2011, remains the current annex listed by the European Commission for computerised systems. The 2025 consultation text is a draft and must not be presented as a current requirement. Use the applicable Annex 11 and the site’s quality system to define validation, access, records, changes and continuity controls.
For US operations, assess 21 CFR 211.68 and the applicability of 21 CFR Part 11 to the records and signatures actually used. Part 11 does not automatically apply identically to every PLC signal. Predicate-rule obligations and the business use of electronic records matter. GAMP 5, Second Edition, published in 2022, is industry guidance for a risk-based lifecycle; it is neither legislation nor a certification that a supplier can confer on an installation.
Model the sequence as states and transitions
Describe each phase through its entry conditions, actions, monitored conditions, completion criteria and exit state. A CIP phase may require an established route, confirmed return and suitable process conditions before timing begins. A SIP exposure phase needs the approved conditions for its defined boundary. A timer should accumulate qualifying process time according to the approved logic, not merely elapsed time since a start command.
State transitions deserve the same scrutiny as steady operation. Examine the change from water to chemical circulation, from cleaning to rinse, from steam admission to exposure, and from steam isolation to protected cooling. Specify which valves move first, which feedback is required and what prevents incompatible routes. Unclear transition logic can produce short, significant failures that are difficult to see in a compressed trend.
Create a cause-and-effect description that engineering, operations and quality can understand. It should explain whether a condition generates an advisory message, blocks start, pauses a phase, aborts the cycle or prevents release. Avoid using one generic alarm response for unrelated risks. A temporary low-flow condition and an unconfirmed valve route may require different actions because their process consequences differ.
Routing and interlocks must reflect the physical plant
Map every approved route to the actual valves, pumps, instruments and connections. Define exclusivity where shared equipment could connect cleaning solution to a product path or interfere with another user. Consider both commanded position and available feedback. A valve’s open signal does not necessarily prove the intended internal path is unobstructed; the verification strategy should address the relevant failure mechanisms.
Interlocks should cover prerequisites such as chemical availability and identity, return-path readiness, utility suitability and equipment status where needed. Define what happens when an instrument becomes unavailable or a communications link stops updating. A last-known good value can be misleading if the software continues treating it as a current measurement. Signal quality and freshness belong in the logic, not only in a maintenance screen.
Assess manual modes, overrides and maintenance functions as part of the intended use. Define authorisation, time limits, recording, visibility and restoration of normal control. A bypass must not disappear from the cycle report merely because it was removed before completion. Some interventions should invalidate the cycle or require documented assessment. Their consequences must be specified before an operator faces the situation during production.
Recipe governance across the lifecycle
Assign responsibility for creating, technically assessing, approving, deploying and retiring recipes. The system should prevent an unapproved revision from being selected for routine use according to the approved access model. A parameter download should be traceable to the authorised change and target equipment. Where recipes exist in both a central database and local controllers, define which copy is authoritative and how versions are reconciled.
Recipe changes require assessment of process impact as well as software functionality. Shortening a rinse, changing a valve pulse or extending SIP exposure can affect cleaning effectiveness, sterility assurance or component life. Determine whether development, qualification, cleaning validation or sterilisation validation evidence must be updated. Software testing alone cannot establish that the changed process remains scientifically suitable.
Retain the ability to reconstruct historical executions after a master recipe changes. Editing a master should not silently alter the reported parameters of completed cycles. Define how obsolete versions remain identifiable and how rollback is controlled. A rollback is itself a governed deployment with an impact assessment, especially if records or controller structures have changed since the earlier version was used.
Failure and recovery decision matrix
| Event | Process question | Required design response |
|---|---|---|
| Loss of return flow | Was the intended equipment exposed under qualifying conditions? | Stop or manage timing as justified; retain the excursion and disposition |
| Valve feedback disagreement | Is the route known and safe? | Prevent unsupported continuation and identify the affected equipment boundary |
| Network loss during execution | Can local control continue, and can evidence be recovered? | Define autonomous behaviour, buffering, reconciliation and review |
| Power interruption | What is the physical and data state after restart? | Recover to a defined state without an automatic unsupported pass |
| Operator abort | Is the equipment clean, treated, incomplete or unknown? | Preserve the partial record and require the approved recovery procedure |
“Resume” needs a precise definition. Continuing from the interrupted phase may be acceptable only under specified conditions. Restarting the whole recipe may also be inappropriate if residual chemical, temperature or pressure makes the initial steps unsafe. The decision should account for the actual equipment state and the approved process, rather than relying on a convenient software button.
Records that support an informed review
Define the record needed to demonstrate execution before choosing report graphics. Relevant content may include cycle identifier, equipment and route, recipe version, actual parameters, phase times, critical trends, alarms, interventions and outcome. Identify data needed to interpret exceptions. A polished PDF summary cannot compensate for missing raw values or an unexplained gap during a critical phase.
Assess sampling rate, historian compression and event recording against the process dynamics. Excessive compression can hide a short excursion or obscure the order of valve events. Conversely, collecting every signal at the fastest possible rate can create large records without improving decisions. Demonstrate that the configured data capture preserves the events and variability relevant to the approved acceptance strategy.
Synchronise relevant clocks and define how time changes are controlled. Distinguish event time, acquisition time and report-generation time where they can differ. Reconcile locally buffered data after communications recovery without overwriting or duplicating events silently. The reviewer should be able to understand an interrupted cycle from retained evidence, including what the system knew at the time it made a decision.
Access, audit trails and review
Assign roles according to actual responsibilities and maintain individual accountability for relevant actions. Control privileged access to the operating system, database, engineering tools and controllers as well as the HMI. A well-designed operator login offers limited protection if a shared engineering account can modify the underlying recipe or erase records without traceability.
Determine audit-trail needs from GMP relevance and risk. Capture meaningful changes with sufficient context to understand who changed what, when and, where required, why. The audit trail should be available for review in a useful form. Define review responsibilities and triggers rather than accumulating records that nobody examines. Separate routine cycle review from deeper investigation of privileged changes or unexplained anomalies.
Electronic signatures, where used, need a defined meaning and association with the intended record. An operator acknowledging an alarm is not necessarily approving the equipment for use. Similarly, an automated “pass” is a calculation or status output, not a human quality decision unless the approved process explicitly establishes that role. Make the disposition workflow visible to the people who rely on it.
Practical example: a network interruption during rinsing
An illustrative CIP system controls the sequence locally while a supervisory server stores records. During final rinse, the network connection fails. The PLC continues, the endpoint is reached and the HMI later shows completion. The quality question is not simply whether the network returned; it is whether the process and its evidence remained under the approved control strategy.
The investigation examines local data buffering, endpoint inputs, signal validity, phase transitions and event reconciliation. If the required evidence is preserved and the behaviour was validated, the interruption can be assessed through the predefined procedure. If critical data are absent, a favourable summary cannot establish what happened. The equipment’s disposition must reflect that uncertainty rather than converting missing data into an assumed acceptable state.
A targeted improvement may add monitored buffer capacity, a record-completeness check and a release block when required evidence is incomplete. Testing then challenges interruption, recovery, duplicate events and a full buffer. The revised procedure explains responsibilities for reviewing the exception. This closes both the technical failure path and the operational decision path.
Validation and handover checklist
- Trace critical process requirements to configuration, code or manual controls and to the evidence that verifies each function.
- Challenge phase entry, timing, routing, signal failure, alarms, abort, restart and loss of utilities or communications.
- Verify recipe approval, version deployment, permitted adjustments, historical reconstruction and controlled rollback.
- Confirm relevant records, audit trails, time behaviour, access restrictions, backup and successful restoration.
- Test meaningful boundaries and failure mechanisms rather than repeating screenshots of normal operation.
- Review supplier evidence for applicability to the installed configuration and close site-specific gaps.
- Train operators and reviewers using abnormal situations, then define support, change control and periodic review ownership.
Backup is valuable only if the required configuration and records can be restored and used. Include recipes, controller logic, database dependencies and necessary configuration information within the assessed recovery scope. Define acceptable recovery arrangements from the process need and test them. A successful file-copy operation alone does not demonstrate that a restored system can produce trustworthy records.
Common mistakes and key takeaways
Warning signs include editable completed reports, shared privileged accounts, undocumented overrides, recipe changes without process assessment and unexplained differences between PLC and server versions. Another warning is a validation package that tests normal sequence execution extensively but never challenges a failed sensor or interrupted record transfer. These gaps affect the credibility of the final cycle status.
Good automation makes the approved process executable and its exceptions understandable. Establish the physical route, govern the recipe, specify recovery and retain evidence that supports the disposition decision. Coordinate sterile boundary transitions with Aseptic Fill-Finish & Barrier Systems and wider interfaces through Pharma Engineering. Keep the automation recipe aligned with the approved cleaning or SIP procedure throughout its lifecycle.
References and document status
The regulatory references are EU GMP Annex 11, January 2011, 21 CFR 211.68 and 21 CFR Part 11. The ISPE GAMP 5 Second Edition is a technical guidance reference; only publisher metadata is used here, without reproducing protected material. The decision matrix and example are original engineering recommendations.
Related decisions
- Monitoring CIP Cleaning Cycles: Conductivity, TOC, Temperature, Flow and Rinse Endpoint
- Troubleshooting and Retrofit of CIP & SIP Systems: Recurring Failures, Changes and Requalification
Explore all decisions in Cleaning, CIP & SIP Systems.