Pharma Engineering Insights

URS for Cleaning, CIP & SIP Systems: Requirements, Structure and Checklist

Define a cleaning-system URS that connects intended use, equipment boundaries, process capability and lifecycle evidence.

G GuideGxP 8 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Pharmaceutical CIP skid and process vessel with engineering requirements documents

A supplier can deliver a CIP skid that meets its quotation while the manufacturing site still cannot demonstrate that its equipment is ready for the next product. The usual gap sits between the machine boundary and the cleaning process: an unlisted transfer hose, an inaccessible valve seat, an undefined dirty hold time or a cycle report that omits the actual recipe version. A useful user requirements specification makes these interfaces visible before procurement.

This article addresses the URS for product contact cleaning, clean in place and steam in place. It covers the equipment and its interfaces with manual cleaning, cleaning out of place, utilities, automation and validation. It does not specify a universal cleaning cycle or replace the site's approved cleaning procedure. The proposed structure and examples are GuideGxP engineering recommendations to adapt through quality risk management.

Start with intended use and a complete boundary

Describe what will be cleaned, what will be removed and what state is needed afterwards. Identify vessels, piping, pumps, instruments, seals, sample connections, removable parts and shared transfer equipment. Draw the boundary on a controlled process diagram and reconcile it with the equipment register. A package supplier's battery limit is a contractual boundary; it does not automatically define the boundary of cleaning validation.

List current products and reasonably foreseeable product families, including soils that become harder to remove through drying, heat exposure or campaign operation. Record available product knowledge and its uncertainties: composition, solubility under relevant cleaning conditions, adhesion, toxicological assessment, degradation products and potential microbiological concerns. Where a product is not yet defined, document the development work needed before the proposed operating envelope can be accepted.

Define changeover, campaign and maintenance cleaning separately. Include the longest proposed interval before cleaning and the conditions for holding equipment after cleaning. Dirty hold time concerns the interval before cleaning; clean hold time concerns the interval after cleaning under specified protection. Neither interval can be taken from another installation without establishing relevance.

Separate the outcomes that the system must support

Cleaning removes residues. Sanitisation and disinfection address microbial contamination through defined processes. Sterilisation has a different objective and requires its own justified process and evidence. A steam phase is not automatically SIP sterilisation, and chemical cleanliness does not establish microbial control. State which outcome applies to each circuit and which evidence will establish it.

CIP cleans assembled equipment through a defined flow path. Cleaning out of place involves removed components processed in another arrangement. Manual cleaning depends on a documented sequence, access, tools and operator execution. A train can contain all three methods. The URS should identify each interface, especially where the automated report finishes before manual parts are reassembled.

Regulatory context and source status

For human medicinal products, EU GMP Annex 15, effective since October 2015, places the URS within the qualification lifecycle; sections 3.2 and 3.3 connect user requirements with design qualification. Chapters 3 and 5 provide the equipment and contamination control context. Annex 11, revision 2011, remains the current published annex for computerised systems at the review date of 21 September 2026. Revision proposals must be assessed separately from current requirements. See the European Commission's current EudraLex register.

Technical standards can support design decisions but their adoption does not replace the manufacturer's GMP responsibilities. Specify the edition, scope and contractual status of each selected standard. Do not convert a supplier's statement of conformity with a technical standard into proof that a particular product residue will be removed. Local occupational safety, pressure equipment and environmental obligations also require a defined interface with the project.

Write requirements that lead to observable evidence

Use a unique identifier for each requirement and avoid bundling unrelated functions into one sentence. Record the requirement, rationale, acceptance criterion, verification method and expected evidence. Assign an owner and identify whether the requirement affects product quality, safety, operation or maintainability. Criticality should follow the consequence of failure, rather than the supplier's willingness to provide a certificate.

Requirement exampleRationale and acceptance basisVerification and evidence
The selected cleaning route is positively identified before chemical addition.Prevent cleaning solution entering an unintended circuit; approved routing and interlock specification.Challenge valid and invalid valve states; retain the route matrix, test records and event history.
The cycle record identifies equipment, recipe version and abnormal interruptions.Enable review of the actual execution; approved data and report specification.Execute normal, aborted and interrupted cycles; compare source data with the generated report.
Product contact locations remain accessible for the approved sampling strategy.Avoid an unverifiable cleaning claim; approved sampling map and access assessment.Design review and physical demonstration using the intended sampling tools.
Return conditions are measured at justified locations.Detect conditions relevant to the cleaned circuit; development and instrumentation strategy.Check installation, calibration, response and challenged operating conditions.

These examples deliberately avoid invented numerical limits. When a limit is known, the URS should contain or reference the actual approved value, unit, tolerance and rationale. When it is not known, assign a development deliverable and decision gate. An unresolved value hidden behind “as required” is a project risk, not a flexible requirement.

Specify process capability before choosing hardware

Describe the intended phases: preparation, pre-rinse, chemical wash, intermediate rinse, final rinse and any subsequent drying, sanitisation or sterilisation. State which phases are mandatory for each equipment family and which can be configured only under change control. Phase transitions need explicit conditions; a timer starting before return conditions are established may record exposure that the equipment never received.

Define the proposed envelopes for flow, pressure, temperature and cleaning-agent concentration through development knowledge, hydraulic assessment and manufacturer data. The design pressure or temperature rating protects the equipment; it is not a validated cleaning parameter. Likewise, a rinse endpoint used by the controller is not automatically a residue acceptance criterion. The analytical and validation strategies must establish the relationship, where such a relationship is claimed.

For SIP interfaces, identify the boundary to be sterilised, steam entry, air removal, condensate discharge, critical measurement locations and the conditions for maintaining the established state during cooling. Allocate responsibility for the steam utility and for the equipment cycle. Refer sterile process interfaces to Aseptic Fill-Finish & Barrier Systems; do not leave them implicit in a generic “SIP ready” option.

Make utilities and hygienic design measurable

For each utility, specify quality attributes at the point of use, available operating ranges, peak demand and the response to supply failure. Distinguish the incoming utility specification from conditions actually delivered to the cleaning circuit. Evaluate the simultaneous loads created by production and cleaning. Final rinse water belongs to the cleaning strategy; broader generation and distribution questions sit within Pharmaceutical Water & WFI Systems.

Require a design review of materials, chemical compatibility, weld documentation, drainability, branches, valve cavities, instrument intrusions and spray-device access. Surface finish and geometric criteria must come from the justified project specification and applicable technical reference. A drawing showing a slope is insufficient when installed supports, thermal movement or flexible connections can create retention points.

Include coverage testing where useful, while keeping its purpose precise. A riboflavin or other visual coverage study can investigate the delivery and removal of a tracer under the defined test conditions. It does not establish product residue removal, toxicological acceptability or cleaning validation. Reserve separate requirements for cleanability development, sampling access and the evidence supporting routine cleaning.

Automation, data and recovery from failure

Specify who may create, edit, approve, select and execute recipes. Define the relationship between the automation recipe and the approved GMP procedure, including controlled instructions for manual actions. A recipe name alone is insufficient if operators can change influential parameters without a retained record. Address permissions, audit trails where applicable, timestamps, retention, backup and restoration according to the system's intended use and risk.

Challenge foreseeable failures at the requirements stage: missing return, wrong connection, failed sensor, loss of heating, power interruption, communication failure and unavailable historian. For each, state the safe equipment condition, cycle status, retained data, restart restrictions and required human review. Automatic restart is a process decision; it should not arise merely because the PLC software supports resuming a sequence.

DecisionEvidence favouring the optionUnresolved question before approval
Shared versus dedicated CIPContamination assessment, campaign schedule and segregation conceptCan shared supply and return paths be cleaned and verified?
Fixed versus mobile connectionEquipment flexibility, access and connection verificationHow are hose identity, storage, status and wrong connections controlled?
Automatic versus manual endpointEstablished sensor response and operator capabilityWhat prevents a normal endpoint masking an unclean location?
Reuse versus dischargeCharacterised soil loading, chemical stability and segregationWhat evidence defines reuse limits and rejection conditions?

Practical example: a shared vessel and transfer line

Consider a development facility buying a skid for two formulation vessels that discharge through different transfer lines. The quotation promises a complete automatic cycle. During the URS workshop, operations identifies a removable hose and a manual sample valve absent from the supplier's circuit diagram. Quality identifies a product family whose dried residue is poorly characterised. Engineering identifies an elevated return section that may retain liquid.

The team does not resolve these issues by adding an arbitrary wash duration. It expands the equipment boundary, assigns the hose to a controlled cleaning and storage method, requires access to the sample valve and opens development work on the dried residue. The return design receives an installation and drainage demonstration. The qualification plan tests route selection and missing return; cleaning validation later challenges the justified product and equipment conditions.

The resulting acceptance decision is traceable. The supplier demonstrates machine functions and provides controlled engineering evidence. The site demonstrates that the chosen procedure works for its products and intended use. Where a development result changes the recipe, the requirement and associated test are updated through change control instead of leaving the original URS disconnected from operation.

Review checklist before issuing the URS

  • Have operations and quality reconciled the equipment boundary with all product contact parts, including temporary connections?
  • Are product families, soils, campaign conditions and hold-time assumptions explicit, with uncertainty assigned to named owners?
  • Does every critical requirement have a rationale, acceptance basis, verification method and retained evidence?
  • Are utility capability, wastewater constraints and simultaneous demand addressed at the actual installation?
  • Are recipes, manual instructions, interruptions, data review and release decisions connected?
  • Are supplier documentation, calibration access, spare parts, training and maintenance deliverables contractually allocated?
  • Is the relationship between FAT, SAT, commissioning, qualification and cleaning validation defined without treating them as interchangeable?

Common mistakes and red flags

“GMP compliant”, “fully drainable” and “validated CIP” are incomplete requirements unless their scope and evidence are defined. Another warning sign is a supplier checklist that closes every requirement with a drawing reference despite the requirement needing a functional challenge. Review also for missing return measurements, unreviewed software options, generic hold times and cleaning claims that exclude the most difficult installed locations.

Maintenance must be possible without undermining the qualified configuration. Define access for inspecting spray devices, replacing seals and calibrating instruments; identify changes that require engineering and quality assessment before return to use. The final URS should remain useful after handover: it supports troubleshooting, new product introduction and evaluation of whether a proposed retrofit changes the established control strategy.

Key takeaways and references

A strong URS connects intended use to evidence. It separates equipment capability from cleaning effectiveness, defines interfaces early and makes unresolved knowledge visible. Keep the requirement chain current throughout the lifecycle and use the Cleaning, CIP & SIP Systems area to connect strategy, design, monitoring and validation decisions.

Related decisions

Explore all decisions in Cleaning, CIP & SIP Systems.

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP