Pharma Engineering Insights

Temperature Monitoring in Pharmaceutical Cold Chain: Sensors, Data Loggers, Locations and Data Integrity

Useful monitoring connects the measured location to the product and preserves the context needed to reconstruct every decision.

G GuideGxP 9 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Probes, loggers and a monitoring network for pharmaceutical storage temperature

A sensor records a temperature. Turning it into evidence requires more answers: what does it represent, where is it located, how reliable is it, which load does it belong to, and has the record remained complete? A system with many points can provide little useful information when these links are weak. A continuous graph may be misleading when the software conceals interruptions in measurement.

This article addresses monitoring of pharmaceutical storage areas, equipment and shipments under controlled temperature. Initial mapping and qualification tests help select and justify monitoring, but they are different activities. The intended result is a strategy connecting the quality question to the measurement chain and subsequent data review. The strategy should explain both normal operation and periods of degraded service.

Regulatory scope and classification of decisions

[REQUIREMENT] EU GDP 2013/C 343/01 provides the relevant distribution reference. For systems used in GMP activities, consider operative Annex 11, revision 2011; a subsequent draft is not automatically operative. Applicability within GDP needs separate assessment.

[GUIDANCE] The WHO transport-monitoring supplement, May 2015, and FDA CGMP data-integrity guidance, final December 2018, have different scopes. [GUIDEGXP] The decisions below form an original design method. Frequencies, quantities and criteria follow intended use rather than a general rule copied from another installation.

1. Define what the measurement must demonstrate

Separate three functions: controlling the equipment, monitoring the product condition and collecting diagnostic information. A control probe may be located where the regulator works best. That location does not necessarily represent the most exposed payload. An additional probe used to understand door effects may be valuable even if it is not used for a product decision.

For every point, specify the measured quantity, location, purpose and relationship to the product. Air temperature responds quickly to openings. A probe placed in a thermal buffer responds differently. Neither is automatically superior. The buffer needs a rationale and should not be presented as a direct product measurement unless its demonstrated behaviour supports that interpretation.

Define the decisions to be made from the record. If it must trigger early intervention, response speed matters. If it supports event assessment, history, identity and uncertainty also matter. A single instrument choice may not satisfy both needs without additional points or information. Make any compromise visible in the approved monitoring rationale.

2. Assess the complete measurement chain

[GEP] Do not compare devices only by displayed resolution. Consider stated accuracy, calibration uncertainty, drift, response time, operating range, protection, cable and interface. A display with more digits does not guarantee a more trustworthy measurement. Chain performance may include probe, transmitter, conversion and software, rather than only the sensing element listed in the catalogue.

Check compatibility with the intended environment. Refrigerated, frozen, ultra-low-temperature or relevant cryogenic use needs specific verification. Battery, materials, connections and communication can have different limits from the probe itself. A sensor capable of measuring a temperature does not demonstrate that the complete logger can operate in that same environment throughout the intended period.

For interchangeable probes, define how the link between component and certificate is preserved. An undocumented replacement can make the measured period ambiguous. Clarify which parameters are configurable, who can change them and how the system records the new configuration. A value can be interpreted properly only when the configuration that generated it is known.

3. Choose architecture by its dependencies

ArchitectureOperational advantageDependency to controlUseful challenge
Standalone loggerLocal recording without continuous connectivityStarting, retrieving and downloading recordsComplete assignment and readout cycle
Wired systemStable transmission in a fixed installationPower, wiring and central componentsLine failure and recovery
Wireless systemFlexible installationCoverage, batteries and interferenceCommunication loss and buffer recovery
Cloud serviceDistributed access and central managementNetwork, identity, service and export availabilityDegraded access and record retrieval

Architectures can be combined. A locally recorded value transmitted later is not lost, but its alarm may arrive too late. Separate continuity of records from timeliness of response. The strategy should describe which function remains available when connectivity, power, a server or access to an external service fails. Do not assume one successful recovery test proves every function.

4. Justify locations and coverage

Use temperature-mapping results to connect permanent points to critical zones and conditions. Do not simply choose the easiest position for wiring. Assess loading, airflow, doors, surfaces and relevant seasonal changes. A critical location can depend on configuration, so one snapshot of an empty space may provide insufficient evidence for normal operation.

Document coordinates or physical references, height, support, protection and current photographs. A probe moved during cleaning can continue producing plausible values while no longer representing the authorised zone. Make the correct location recognisable and define how temporary moves, work and maintenance are handled. Include restoration of the location in the return-to-service process.

During transport, associate each logger with shipment and configuration. A location near refrigerant may overrepresent cold exposure or fail to represent the warmest payload. A point outside the container measures another quantity. Placement should follow qualification and measurement purpose. Logger numbers and distribution are not universal and should not be inferred merely from parcel value or vehicle size.

5. Configure sampling and time without losing events

The sampling interval should reveal events relevant to the decision. Sparse recording may not describe a short variation. A high frequency creates more records without correcting a slow or poorly located probe. Assess system dynamics, instrument response, available memory and the review process together. More data are useful only when their meaning remains clear.

Define the time reference, time zone and daylight-saving treatment. Preserve an unambiguous way to reconstruct event order across different systems. Sampling time and receipt time may differ. A delayed transmission should not appear as a measurement just taken. Review displays, exports and reports to ensure they communicate this distinction consistently.

Handle missing, duplicate and invalid values explicitly. A line joining two points across an interruption does not demonstrate continuity. Specify how the gap is shown, who assesses it and what alternative evidence may be considered. Avoid automated reconstruction presented as observed measurements. Any calculated or inferred value should remain distinguishable from the original record.

6. Calibrate to support the decision

The calibration plan should connect operating range, test points, tolerances, uncertainty and risk. Intervals must first meet applicable requirements. [REQUIREMENT] EU GDP section 9.2 sets at least annual maintenance and calibration for transport-temperature monitoring equipment in vehicles or containers. For fixed-storage monitoring, section 3.3 instead bases intervals on a risk and reliability assessment. Stability, use, history and failure consequences may require shorter intervals; risk assessment does not remove the transport-specific minimum. A certificate current in the calendar does not automatically cover every temperature or configuration used. Examine whether the certificate supports the actual measurement decision and any correction applied to the reading.

Define the condition before adjustment, the result afterwards and management of an instrument outside tolerance. The question is not only how to restore it, but which earlier records and products may be affected. Preserve identities, dates and associations so that this assessment is possible. A correction factor should be controlled and understandable to the person reviewing the data.

If a probe is removed for calibration, plan temporary coverage and return to its approved position. Maintenance should not create an unrecognised blind period. Testing after reinstallation should check the complete path through display and relevant alarms. Confirm that replacement identifiers and configuration changes are reflected in the record and the system inventory.

7. Preserve the context of the record

A value without context is insufficient. Connect device identity, configuration, location, shipment assignment, events, changes and decisions. A PDF report may be useful for review but may not contain everything needed for reconstruction. Define what constitutes the original record and which metadata must be retained. Keep the relationship between summaries and their supporting records understandable.

Manage named users, roles and privileges. Operational users should not be able to silently change critical records or configuration. Verify change histories and their review process. An available audit trail that cannot be used, accessed or connected to the underlying data does not solve traceability. The reviewer needs a practical route from an event to the relevant change record.

Test backup, restoration, export and long-term readability. Link retention to applicable requirements and the process rather than inventing one duration. For external services, define access at contract termination and management of updates. Environmental Monitoring Systems architecture provides a useful interface when the platform is shared, while each application still needs its own intended-use assessment.

Hypothetical case: complete records, late alarm

A hypothetical warehouse adopts wireless probes with local memory. During a controlled challenge, the network is interrupted. All records are recovered after restoration, and the supplier considers the continuity test successful. The team nevertheless finds that a simulated critical condition did not reach the on-call person during the outage. Record retention worked; timely response did not.

The project therefore separates two criteria: complete record recovery and an alarm path compatible with the time available for intervention. It assesses a local signal, an alternative communication route or different operational protection. The selected arrangement is tested in the actual context, including unattended operation. No universal probe count or sampling interval can be inferred from this example.

Common mistakes and red flags

Common errors include confusing resolution with accuracy, using the controller probe as the only independent evidence without justification, placing every point near an accessible door and ignoring missing records. Other warning signs are loggers without batch association, inconsistent clocks, shared credentials and certificates that cannot be linked to the installed probe. Plausible numbers do not resolve these gaps.

Monitoring does not make an inadequate thermal system suitable. More sensors can improve visibility but do not correct airflow, capacity or loading practices. If alarms are disabled to avoid disturbance, review the measurement and alarm-management strategy, preserving change history. Investigate the operational reason for the workaround rather than merely asking users to tolerate it.

Checklist for releasing the monitoring system

  • Define data use and the relationship between the measured point and product.
  • Verify complete-chain performance under intended conditions.
  • Justify locations through evidence and preserve their identification.
  • Approve sampling, time reference and gap treatment.
  • Link devices, certificates, payloads and configurations.
  • Challenge relevant losses of connectivity, power and components.
  • Verify rights, changes, review, export and restoration.
  • Assign responsibility for abnormal records, out-of-tolerance findings and modifications.

Organise review so that it produces decisions

Distinguish operational checks from quality assessment. The former identifies conditions requiring prompt action; the latter checks completeness, events, changes and consequences. Define who confirms period coverage, who assesses abnormal records and who authorises the conclusion. A signature on a graph does not clarify these responsibilities unless the review content is defined.

Provide a view showing the requested period, available records, open events, excluded sensors and configuration changes. The reader must understand whether a flat curve represents stability, rounding or failure to update. Displayed thresholds should match the version applicable during that period. A later change should not silently rewrite the historical assessment.

For shipments, define handling of unreturned loggers, unreadable files and data delivered after receipt. Assign a status to the load and an owner to the assessment. Physical delivery should not be assumed to mean complete documentation. Alternative evidence may contribute, but its relevance and limitations must be explicit and recorded with the decision.

Measure review-process quality through unresolved gaps, recovery time, association errors and misunderstood changes. Avoid one score that offsets missing records with many correct readings. When an issue recurs, address its cause in the interface, instruction, system capability or responsibility. Adding a permanent manual check is not always the most effective long-term correction.

Challenge reconstruction of a complete event

Before release, choose a test event and ask a reviewer who did not execute it to reconstruct what happened. Provide the access defined by the procedure without extra informal explanation. The reviewer should identify device, location, period, configuration, alarms, interventions and conclusion. Difficulties reveal process gaps even when every expected file is present and can be opened.

Repeat the exercise through the export intended for archiving or transfer to the recipient. Check that identities, units, timestamps and data status retain their meaning. A readable file without its shipment association may be technically intact but operationally insufficient. Record differences between application view, report and export, defining which source supports each decision. This practical challenge avoids approving isolated functions without showing that the combined process supports a later investigation. Include anomalies selected through risk assessment rather than only a perfectly regular period. The purpose is to prove that another authorised person can reach a defensible understanding from the retained evidence.

Operational conclusions

The system is reliable when the measurement has meaning, the record retains its context and the organisation can act. Approve a point-function-decision matrix, a dependency map and a data-management plan. Together they explain why each point exists and what happens when it stops working, giving maintenance and quality teams the same reference.

Use lifecycle events to revisit assumptions. Relocation, new loads, drift and interruptions can change coverage. Keep monitoring within the Cold Chain & Controlled Temperature Systems programme, connecting measurement quality with the quality of the decisions it supports.

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP