Pharma Engineering Insights

URS for Pharmaceutical Water and WFI Systems: Requirements, Structure and Checklist

A badly written specification produces bids that cannot be compared, qualification that cannot be defended and costs that only surface years later. Structure, method and criteria for building verifiable requirements across intended use, boundary, sanitisation, CQV and lifecycle.

G GuideGxP 24 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Sistema di generazione e distribuzione di acqua farmaceutica in un'area tecnica di uno stabilimento GMP

Three bids for the same WFI system. Three different architectures, three prices that cannot be compared, and no objective criterion for saying which one is best. The problem did not start at tender stage: it started in the URS, which described a plant instead of describing what the plant has to do.

The User Requirements Specification of a pharmaceutical water system settles three things at once: how comparable the bid evaluation will be, how defensible the qualification will be, and how much the system will cost over the next fifteen or twenty years. It is also the document written in the greatest hurry, usually recycled from the previous project, and the one nobody re-reads until it has to justify something to an inspector.

What follows is not a ready-made URS. It is the structure of the document, the method for building each section, and the criteria for telling whether a requirement is well written. Where a number is needed, it explains how the justification for that number is built, because it is the justification — not the number — that holds up in qualification and in inspection. The full picture of the subject sits in the Pharmaceutical Water & WFI Systems hub.

Why the URS drives the tender, the qualification and the lifecycle cost

On bid evaluation: without measurable requirements, offers can only be compared on price and on whatever each supplier chose to describe. The URS is the common denominator that makes performance, scope of supply, documentation package and acceptance conditions commensurable. Every requirement that is not written down becomes, after contract signature, a variation order at an open price.

On qualification: Annex 15 of EudraLex Volume 4, 2015 revision in operation since 1 October 2015, structures the qualification and validation cycle; the design is verified against the user's requirements and the performance against the intended use. A requirement that cannot be verified does not generate a test, it generates a protocol built after the fact. Note that the concept paper on the EU-PIC/S revision of Annex 15, published on 9 February 2026 with a corrigendum on 16 July 2026 and consultation closed on 9 April 2026, has not changed Annex 15: the applicable text remains the 2015 one.

On lifecycle cost: sanitisation strategy, materials, redundancy, instrument accessibility, sampling points, openness of the automation system and spare parts availability cost very little when they are written and a great deal when they are changed. How they turn into tender criteria and TCO items is developed in the article on selecting a pharmaceutical water system supplier.

Regulatory framework: what is a constraint and what is a choice

No regulatory text prescribes the format of a URS. The texts prescribe the outcomes the system has to deliver and the fact that those outcomes are specified, verified and documented. A URS that blurs regulatory requirement, good engineering practice and design choice makes deviations impossible to discuss, because nobody can tell any more what is negotiable.

SourceStatusWhat it constrains in the URS
EudraLex Vol. 4, Annex 15 (rev. 2015)In operation since 1 October 2015; concept paper of 9 February 2026 that has not changed the textQualification and validation framework against which the URS becomes the verifiable reference
EudraLex Vol. 4, Annex 1In operation since 25 August 20236.1-6.5 risk-based controls on utilities; 6.7 design, slopes, dead legs; 6.8 qualification taking seasonal variation into account; 6.9 turbulent flow; 6.10 WFI, storage and distribution; 6.11 vent filters; 6.12 sanitisation on a predetermined schedule; 6.13 alert levels from qualification data; 6.15 continuous monitoring
EMA/CHMP/CVMP/QWP/496873/2018In force since 1 February 2021Minimum grade as a function of intended use (s.5.1 water as an excipient; s.5.2 active substances and dosage forms); prior notification to the supervisory GMP authority before introducing RO
ICH Q9(R1)Step 4 on 18 January 2023Effort proportionate to risk: which requirements are critical and how deep the verification has to go
ASTM E2500-25Approved on 1 April 2025Specification - design - verification logic: the URS is the specification node from which the verification plan follows
ISPE Baseline Guide Vol. 4, 3rd ed. (2019)Industry guide, not a regulationGood practice reference, never a binding requirement

Two readings bear immediately on the structure of the document. Annex 1 clause 6.8 requires water systems to be qualified and validated for physical, chemical and microbiological control taking seasonal variation into account: that is satisfied upstream, in the source water data. The EMA guideline 496873/2018 ties water grade to intended use: the intended use section is not a preamble, it is the section from which almost everything else follows.

Intended use and system boundary

The grade is derived, not chosen

A sound URS starts from a list of uses, not from a plant. For each use: product or process served, stage of use, direct or indirect contact, sterile or non-sterile nature of the finished product, route of administration, flow and temperature at the point of use, continuity of draw-off, and whether the water enters the formulation or serves for cleaning.

From that list the grade is derived. The EMA guideline 496873/2018 deals separately with water as an excipient, with a minimum grade depending on the sterile or non-sterile nature of the product and on the route of administration (s.5.1), and with water used in the manufacture of active substances and dosage forms, where lower grades are acceptable in the early steps of synthesis (s.5.2). A site with several lines can therefore legitimately have several water grades: the comparison is developed in the article on choosing between Purified Water and WFI.

The recurring mistake is specifying WFI for the whole site because "it is safer". It is not: it is more expensive in capex and energy, more demanding in sanitisation and qualification, and it loads operations with monitoring that was never necessary. Over-specification is a design choice, to be justified like any other.

System boundary

This is the section that prevents the most expensive sentence in utility projects: "that was not in my scope". Four boundaries have to be fixed, ideally with a block diagram.

  • Upstream: delivery point of the feed water, who guarantees it, with what characteristics and with what continuity of pressure. The minimum reference is 21 CFR 211.48(a), which requires potable water supplied under continuous positive pressure in a plumbing system free of defects that could contribute contamination to any drug product; 211.48(b) deals with drains and back-siphonage.
  • Scope of supply: what falls within the supplier's scope and what stays with the site (civil works, electrical connections, steam, compressed air, cooling water, drains, data network).
  • Downstream: where the system ends and the user equipment begins, typically the last valve of the point of use. Responsibility for sampling, sanitisability of the terminal section and management of flexible hoses all depend on that line.
  • Information boundary: which data leave the system and towards which destinations (SCADA, historian, LIMS, building management), over which protocol and with what responsibility for record retention.

Source water: the constraint the project cannot ignore

Feed water quality determines the acceptable technology, the chemical consumption, the sanitisation frequency and the microbiological risk of the whole system. The USP Purified Water monograph is explicit: the water is prepared from water complying with the U.S. EPA National Primary Drinking Water Regulations or with the drinking water regulations of the European Union or of Japan, or with the WHO Guidelines for Drinking Water Quality, and it contains no added substance. Drinking water compliance is the floor, not the design input.

The design input is variability. The URS has to contain, or call up as a controlled annex, an analytical dataset covering seasonal variation, with the source stated (mains, borehole, blend and proportion), the chlorination or chloramination regime, the guaranteed pressure and availability, and contractual responsibility in the event of an excursion. The link to Annex 1 clause 6.8 is direct: a URS built on a single analysis pushes that risk into the phase where correcting it is most expensive.

The point becomes critical where membrane-based WFI is under consideration. The Q&A EMA/INS/GMP/443117/2017, in force since 1 August 2017, notes that reverse osmosis plants typically operate at ambient temperature and therefore provide an ideal environment for biofilm formation, and expects extended testing, daily testing of all critical points in the initial phase and data gathered over about one year to capture seasonal variation. That is a schedule requirement, not only a specification one. The dataset and the pretreatment logic are developed in the article on source water and pretreatment.

Capacity and consumption profiles

Capacity is the requirement most often got wrong, because it is the easiest one to copy from the previous project. But it is not a property of the plant: it is a property of the production plan. It has to be built user by user and aggregated into a time profile, and that construction has to be documented in the URS as a design premise. As a minimum it needs:

  • a complete list of points of use with grade, instantaneous flow, temperature and pressure, laboratory and occasional users included;
  • duration and frequency of each draw-off, distinguishing consumption per batch from consumption per hour;
  • an explicit simultaneity assumption with a named owner: assuming full or zero simultaneity without stating it is the most common error;
  • peak volumes and flows of CIP, SIP and washing steps, which must not be treated as average consumption;
  • the worst hour, the worst day and the worst campaign, obtained by aggregation;
  • a growth reserve, with margin and time horizon justified by the business plan.

Oversizing is not prudence: a system much larger than the demand runs at low velocity in the loop, turns the tank volume over slowly and consumes more energy during sanitisation. Annex 1 clause 6.9 requires flow to remain turbulent in order to limit microbial adhesion and biofilm formation, and requires the flow rate to be established at qualification and monitored routinely: fixing only the peak capacity without stating the minimum recirculation regime sets up a conflict that will surface in OQ. The growth margin must be written as a separate item rather than buried in the capacity figure; otherwise it becomes a requirement at tender stage and, at qualification, nobody knows what has to be demonstrated.

Pretreatment, generation, storage, distribution

Pretreatment is expressed as the performance required on the water delivered to the generation stage, plus a list of constraints. The URS states what has to be removed or controlled as a function of the source water dataset, not which technology to use, unless there is a genuine site constraint, which is then written as a constraint with its rationale. What does belong in the URS: sanitisability of every unit, full drainability, absence of permanent stagnation, compatibility of chemicals with downstream stages, dechlorination strategy, and management of filter beds as a potential microbiological source.

For generation the URS states the quality attributes and the pharmacopoeias applicable to the markets served, the capacity derived from the consumption profile, the required availability and how it is calculated, the behaviour on start-up, shutdown and turndown, and compatibility with the chosen sanitisation strategy. On WFI the regulatory position is settled: monograph Ph. Eur. 0169, revised by adoption at the 154th session of the European Pharmacopoeia Commission (March 2016) and effective from 1 April 2017, allows production by a purification process equivalent to distillation, and the EMA guideline 496873/2018 at s.4.2 refers to single or double pass reverse osmosis coupled with EDI, ultrafiltration or nanofiltration; the USP Water for Injection monograph defines WFI as water purified by distillation or by a purification process that is equivalent or superior to distillation in the removal of chemicals and microorganisms; Annex 1 clause 6.10 adds that WFI must be produced from water meeting specifications defined at qualification. The point that belongs in the URS is a different one: allowing the membrane route triggers the prior notification to the supervisory GMP authority required by the EMA guideline before introducing reverse osmosis. A technology choice becomes a project milestone involving an external party.

For storage, tank volume is the difference between the draw-off profile and the generation capacity, plus a reserve justified by a stated scenario: generator outage, campaign peak, recovery time. The URS has to require the supplier to show the calculation, because it is the calculation, not the volume, that will be discussed at qualification. Also to be fixed: temperature control strategy and its rationale, full coverage of internal surfaces by the spray device, drainability, level instrumentation that can be maintained without opening the system, and materials and surface finish defined by reference to the ASME BPE edition fixed contractually. On the vent filter, Annex 1 clause 6.11 requires hydrophobic bacteria-retentive vent filters that are not themselves a source of contamination, with integrity testing before installation and after use, and with prevention of condensate, for example by heating: three distinct requirements, to be written as three distinct requirements.

Distribution is where the URS has to be most rigorous in separating requirement from solution. What belongs to it: the required topology and the points of use with their performance, full drainability, absence of dead legs, turbulent regime under all foreseen operating conditions, sanitisability of every branch up to the last valve, the ability to sample without compromising loop integrity, and the ability to isolate a branch without shutting down the loop. Annex 1 clause 6.7 explicitly requires sloping of pipework for drainage and avoidance of dead legs; clause 6.10 cites constant circulation above 70 °C as an example of a condition that minimises microbial growth. What does not belong to it are the numerical design criteria — L/D ratios, slopes, surface roughness, minimum velocities — which sit in the design specification and in the applicable technical standard, typically ASME BPE in the edition fixed contractually. Reproducing them breaches the copyright of the standard and freezes into the URS a value which, when the edition changes, forces a change control on the wrong document.

Sanitisation: a capability requirement, not a cycle recipe

Annex 1 clause 6.12 requires sterilisation, disinfection or regeneration to be carried out according to a predetermined schedule and also as a remedial action following out-of-limit or out-of-specification results. From that wording follow requirements about the capability of the system, not about the cycle.

  • The system must be sanitisable in its entirety, including every branch up to the last valve, without dismantling.
  • Sanitisation must be executable as an unplanned action too: within timescales compatible with operations, with a repeatable procedure and recorded evidence.
  • The site must state whether it can be performed with the system in service or requires a shutdown: this is one of the heaviest operating cost items and has to be assessed at bid stage.
  • Materials, seals and instrumentation must be compatible with the chosen method for the whole expected life of the system.
  • The system must provide evidence that sanitisation reached every point: instrumentation, recording and cycle completion criteria are URS requirements.

What the URS must not do is write the cycle. WHO TRS 1025 Annex 3 requires validated thermal and/or chemical sanitisation at specified intervals, leaving the intervals to the manufacturer and setting no numerical limits; the Q&A EMA 443117/2017 mentions thermal treatment above 75 °C, leaving contact times to the manufacturer's validation. The URS asks for a cycle that can be validated and for a system that makes it executable; the parameters are justified in validation, on data.

Instrumentation, automation and data

Annex 1 clause 6.15 requires WFI systems to include continuous monitoring such as TOC and conductivity. The URS turns that into verifiable requirements: which parameters online and which offline, in which positions (supply, return, point of use), with what continuity of recording, with what behaviour on excursion, and with what accessibility for calibration and maintenance without compromising loop integrity. These measurements are governed by USP chapters <643> and <645>; no ISO, ASME, ASTM or CEN standard has been identified for the qualification of this instrumentation. Chapter <643> explicitly says nothing about how often the system suitability test should be run: the frequency is left to the user's risk assessment, and is therefore a decision the site has to be able to justify. The same principle governs sampling points: number, position and accessibility follow from a documented risk assessment, not from a reused template. If sampling is awkward it will not be done well, and that is a defect that originates in the URS.

On automation the URS fixes the control philosophy before the architecture: operating modes, alarm and interlock logic, alarm hierarchy, behaviour on power failure and on restoration, manual override policy and its traceability, access management, management of sanitisation recipes, remote access and its conditions. The version in force is the one to use: the applicable Annex 11 is the January 2011 version, operational since 30 June 2011. The draft revision, out for consultation from 7 July to 7 October 2025 together with the revision of Chapter 4 and the proposal for a new Annex 22, has not been adopted and has no published date of application: it belongs, at most, in a regulatory watch section, never among the requirements.

On data, the URS lists the records the system generates and, for each of them, the owner, the location, the retention period, how it is exported and how it is shown to be unaltered. Explicit requirements are needed on audit trail, time synchronisation, user and profile management, verified backup and restore, archiving with guaranteed readability over time, and interfaces to historian and LIMS. In the United States 21 CFR Part 11 is in force, with the FDA guidance Part 11 – Scope and Application of September 2003 narrowing its interpretation and exercising enforcement discretion, while stating that part 11 remains in effect. The detail is covered in the article on automation, SCADA and data integrity in water systems.

CQV requirements and supplier documentation

ASTM E2500-25, approved on 1 April 2025, formalises the science- and risk-based specification, design and verification logic. The URS is the specification node: if the specification cannot be verified, the verification cannot be planned. A CQV section is therefore needed, stating before the tender what the supplier will have to demonstrate and with what evidence.

  • FAT: scope of testing, who witnesses, what constitutes acceptance, which results can be leveraged in support of qualification, how deviations are handled and which must be closed before shipment.
  • SAT: tests that only make sense after installation, site access conditions, utility prerequisites.
  • Support to IQ, OQ and PQ: what the supplier provides as documentation, what as attendance, what as data.
  • Traceability matrix: every requirement traced to the design document that satisfies it and to the test that verifies it. It is the single requirement that does most to make a URS useful rather than decorative.
  • Documentation package: P&IDs, datasheets, material certificates, surface finish and passivation records (with contractual reference to standards such as ASTM A967/A967M-25 and ASTM A380/A380M-25), welding documentation and welder qualification, calibration certificates, software documentation, spare parts list, operation and maintenance manuals, training plan, with format and language stated.

Everything not listed in the URS will be negotiated after contract signature, and at that point it will have a price. The full sequence of tests and responsibilities is developed in the article on FAT, SAT, IQ, OQ and PQ of water systems.

Lifecycle requirements

A URS that stops at handover has covered the least expensive part of the system's life. Lifecycle requirements have to be written while there is still contractual leverage: physical access to components and isolation of a branch without shutting down the system; commitments on the availability of critical components and policy in case of discontinuation; software update policy, platform end of support and the impact of updates on validated status; the ability to add points of use without requalifying the whole system; service coverage and required competencies, bearing in mind that service levels are a contractual matter and that the URS defines the requirement and how it will be measured, not the number.

One requirement is regularly forgotten: data availability. Annex 1 clause 6.13 establishes that alert levels are based on initial qualification data and are periodically reviewed on the basis of requalification, routine monitoring and investigations; clause 6.14 requires excursions to be documented, reviewed and investigated, distinguishing an isolated event from an adverse trend. For that to be possible, the system has to export usable historical series: a URS requirement, not an expectation.

How to write a verifiable requirement

A requirement is verifiable if, on reading it, you can name the test that demonstrates it, the evidence it produces and the acceptance condition. Otherwise it is a statement of intent. The traits are few: atomic, unambiguous, attributable to a need, testable, free of solution unless the solution is a declared constraint, prioritised, and uniquely identified with a code usable in the traceability matrix.

Poor wordingWhy it is a problemVerifiable rewording
"The system shall deliver high quality water."No attribute, no criterion, no possible test."Water delivered to each point of use shall comply with the pharmacopoeial monograph applicable to the required grade for the markets served [list]; attributes and methods are defined in analytical specification [ref.]."
"The loop shall be stainless steel with roughness no greater than [value] and a slope of [value]."It prescribes the solution and freezes numbers that belong to the design specification and to the technical standard."Product contact surfaces shall be compatible with the fluid and with all foreseen sanitisation cycles; materials, finish and passivation shall comply with the ASME BPE edition fixed contractually and shall be documented by the supplier."
"The system shall be sanitised periodically."It says nothing about the capability required or how it is verified at design stage, and it confuses a system requirement with an operating procedure."The system shall be sanitisable in its entirety, including every branch up to the last valve, without dismantling, according to a predetermined schedule and as a remedial action; the supplier shall demonstrate coverage of the method over all contact surfaces."
"The system shall have high availability."The term is undefined, the calculation basis is not stated and there is no reference period."Required availability is [value], calculated as [definition] over a reference period of [period] and derived from consumption profile [ref.]; the supplier shall state the calculation method and its assumptions."
"The system shall comply with current GMP regulations."It transfers to the supplier an interpretative responsibility that belongs to the site, and produces no acceptance criterion."The system shall meet the requirements of the texts listed in [annex], in the version in force at the URS issue date; every derived requirement is identified and traced in the traceability matrix."
"TOC shall be monitored continuously."Position, recording, behaviour on excursion and destination of the data are all missing."The system shall measure TOC and conductivity continuously at positions [list], record values at [x] resolution, raise a configurable alarm on excursion and make the data exportable for trending; alert levels will be set on initial qualification data."
"The supplier shall provide technical documentation."It does not list, does not define format and language, and does not tie delivery to an acceptance condition."The supplier shall deliver the documentation package listed in [annex], in [x] language, indexed and traced to the matrix; complete delivery is a condition of SAT acceptance."

Acceptance criteria: where a number legitimately comes from

  1. Compendial or regulatory. The value comes from a monograph or a binding text and is cited with source and edition, after checking that it actually applies to the markets served: pharmacopoeias are not aligned on everything and editions change. The Ph. Eur. in force in August 2026 is the 12th edition, Issue 12.3, applicable since 1 July 2026, with Issue 13.1 already published and implementation from 1 January 2027.
  2. Derived from the product or the process. The value follows from the formulation, the batch size, the cleaning cycle or cleaning validation, and in the URS it is traced to the document it derives from.
  3. Established by the site on data. The value does not exist yet, because it depends on how the system behaves. The URS must not fix it: it must require the system to generate the data needed to set it and keep it under control.

The third category is where most mistakes are made, and it concerns microbiological alert and action levels in particular. Annex 1 clause 6.13 ties alert levels to initial qualification data, with periodic review; WHO TRS 1033 Annex 3 derives alert and action levels from reported historical data and from system knowledge with data trending. USP chapter <1231>, official since 1 December 2021, is informational and sets no mandatory microbiological limits: the action levels it reports, 100 cfu/mL for Purified Water and 10 cfu/100 mL for Water for Injection, are stated as non-binding, as levels above which the water is unfit for use, and USP asks users to establish in-house specifications. Transcribing them into a URS as a contractual requirement on the supplier inverts the logic: the supplier is being asked to guarantee a level that depends on data the system will produce after installation.

There is also a directional constraint: the Q&A EMA 443117/2017 states that increasing such limits is not good practice and may mask a failing system. A practical rule follows: every number written into the URS carries four fields — source, rationale, owner, review date. If even one of them cannot be filled in, that number is not a requirement yet. The methodology behind these choices, consistent with ICH Q9(R1), is developed in the article on quality risk management applied to water systems.

Worked example: Site Delta

Site Delta is a fictitious example, built to show the reasoning rather than to supply values. The site manufactures non-sterile dosage forms in an existing area and is adding a sterile filling line. The question that reaches engineering is phrased as a plant question: "one WFI system or two separate systems?". It is the wrong question.

The correct sequence starts from the uses: for every user, new and existing, the team records the product served, the contact, the sterile or non-sterile nature of the finished form, the route of administration and the stage of use. Applying the logic of the EMA guideline 496873/2018, it emerges that some existing users do not require WFI while the whole sterile line does: the plant decision becomes a consequence of the analysis. The boundary work then reveals that the feed water delivery point is shared with a non-GMP technical user, with nobody formally responsible for continuity of pressure: 21 CFR 211.48(a) becomes an action on the site side, not a request to the supplier. Finally generation: if the membrane route is under consideration, the URS has to carry the prior notification to the supervisory GMP authority and a qualification strategy that captures seasonal variation, consistent with Annex 1 clause 6.8 and with the expectations of the Q&A EMA 443117/2017. That is not a specification detail: it is a line in the project schedule.

Downstream, the requirements become bid evaluation criteria. The matrix is issued with the weighting column empty: weights are assigned by the team according to its own context, and the assignment is documented before the bids are opened, not after.

Criterion derived from the URSWhat is assessedEvidence requiredWeight
Coverage of the consumption profileDeclared capacity against peak and daily profile, behaviour at turndownSizing calculation with explicit assumptions
Full sanitisability and turbulent regimeCoverage of the method over all contact surfaces; hydraulic behaviour at limit conditionsCoverage diagram and hydraulic calculation of the loop
Monitoring and data availabilityOnline parameters, positions, recording, exportability for trendingMeasurement architecture and specification of the records generated
Automation and electronic recordsCompliance with Annex 11 in force and with 21 CFR Part 11 where applicableSoftware documentation and verification plan
CQV package, traceability and long-term supportCompleteness of FAT, SAT and qualification support; commitments on spares, software and maintainabilityDocumentation index, draft matrix, critical spares list

URS completeness checklist

The checklist does not certify that a URS is good: it catches the omissions, which are the most frequent and most expensive defect.

  • Purpose, system covered, exclusions; list of intended uses with derived grade and rationale.
  • System boundary upstream, scope of supply, downstream and information, with interfaces and responsibilities.
  • Source water dataset covering seasonal variation, with contractual responsibility for excursions.
  • Consumption profile built user by user, with a stated simultaneity assumption and a separate growth reserve.
  • Quality attributes and applicable pharmacopoeias; pretreatment expressed as performance.
  • Generation, storage and distribution with drainability, absence of dead legs, turbulent regime, testable vent filter, branch isolation and sampling capability.
  • Sanitisation expressed as system capability, not as cycle parameters.
  • Technical standards called up with a contractually fixed edition, without reproducing their numerical criteria.
  • Instrumentation and sampling points derived from risk assessment; control philosophy and electronic record requirements referred to texts in force.
  • FAT and SAT scope, support to IQ, OQ and PQ, traceability matrix as a deliverable, documentation package with format, language and acceptance condition.
  • Maintainability, spares, obsolescence, software, extensibility, data export for periodic review.
  • Unique identifier and mandatory/desirable classification for every requirement; source, rationale, owner and review date for every number.
  • Explicit distinction between regulatory requirement, good practice and design choice; approval by engineering, quality and users; document under change control.

Common mistakes and red flags

  • Recycled URS: it carries constraints that no longer exist and omits the new ones.
  • URS written by the supplier: the supplier contributes to the design specification, not to the user's requirements. If the supplier writes them, the bid evaluation is already decided.
  • URS that describes a skid: if it contains a P&ID it is describing a solution and has given up comparing alternatives.
  • Requirements without identifiers: without codes there is no traceability matrix, and qualification cannot be demonstrated requirement by requirement.
  • Alert levels written before qualification: this contradicts the logic of Annex 1 clause 6.13.
  • A single source water analysis: it makes it impossible to demonstrate that seasonal variation was considered, as required by Annex 1 clause 6.8.
  • Generic regulatory references: "GMP compliant" is not a requirement; an itemised list of the applicable texts is.
  • Texts not in force cited as requirements: the Annex 15 concept paper and the Annex 11 draft revision are changes to monitor, never requirements.
  • No priority classification: if everything is mandatory nothing is negotiable, and the supplier decides on its own what to ignore.
  • URS not under change control: a document that changes without traceability cannot be the reference for qualification.

If you want analysis like this as it is published, the The Pragmatic GMP newsletter collects GuideGxP's technical content with the same approach: method, verified sources, no shortcuts.

Key takeaways

  • The URS does not describe a plant: it describes what the plant has to do. That is what makes bids comparable and qualification verifiable.
  • Intended use is the generative section: the water grade is derived from it following the logic of the EMA guideline 496873/2018, and capacity, boundary and monitoring strategy follow from it too.
  • Annex 15 rev. 2015 remains the applicable text: the concept paper of 9 February 2026 has not changed it.
  • Seasonal variation of source water is an upstream data requirement (Annex 1 clause 6.8), not a problem to discover during PQ.
  • Sanitisation is written as a system capability, not as a cycle recipe.
  • Every number needs a source, a rationale, an owner and a review date; alert levels are built on qualification data, not copied from an informational chapter.

References

  • EudraLex Volume 4: Annex 15 rev. 2015 (EU-PIC/S concept paper of 9 February 2026, Annex 15 not revised); Annex 1, C(2022) 5938 final, clauses 2.5(v) and 6.1-6.15; Annex 11, January 2011 version, with a draft revision consulted in 2025 and not adopted. EudraLex Volume 4
  • EMA/CHMP/CVMP/QWP/496873/2018 and Q&A EMA/INS/GMP/443117/2017. EMA — ICH Q9(R1). ICH — WHO TRS 1033 Annex 3 and TRS 1025 Annex 3. WHO — PIC/S PE 009-17 and PI 009-4 rev. 4. PIC/S
  • Ph. Eur. monographs 0169 and 0008, chapters 2.2.38 and 2.2.44; USP Purified Water, Water for Injection and chapters <643>, <645>, <1231>; 21 CFR 210.3(b)(3), 211.48 and Part 11 with the related FDA guidance of 2003. 21 CFR Part 211 — Part 11 — FDA
  • ASTM E2500-25, A967/A967M-25, A380/A380M-25; ASME BPE, edition to be fixed contractually; ISO 22519:2023 and ISO/DIS 25413 (draft). ISO — ISPE Baseline Guide Vol. 4, 3rd ed. (2019) and ISPE GPG Approaches to C&Q of Pharmaceutical Water and Steam Systems, industry guides, not regulations.

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP →