This is a ready-to-use form for deriving bioburden alert and action limits from your own process data, and for reviewing them on a defined cycle. Replace every <<FILL: ...>> placeholder, attach the baseline data set, and route it through your normal review and approval. A worked filled specimen with a real derivation follows. This is educational reference content, not regulatory advice; confirm the applicable regulatory and specification limits for your own product and process before setting anything.
1. Field table
| Field | Entry |
|---|---|
| Form number | <<FILL: FORM-ID>> |
| Version | <<FILL>> |
| Supersedes | <<FILL: prior version or "New">> |
| Control point | <<FILL: e.g. bulk immediately before final sterilising filtration>> |
| Product / material | <<FILL>> |
| Test parameter | <<FILL: TAMC / TYMC>> |
| Unit of measure | <<FILL: e.g. CFU per 100 mL>> |
| Recovery method | <<FILL: membrane filtration / plate count / MPN>> |
| Sample volume or mass | <<FILL: e.g. 100 mL>> |
| Method suitability reference | <<FILL>> |
| Applicable regulatory or specification limit | <<FILL: e.g. not more than 10 CFU per 100 mL>> |
| Source of that limit | <<FILL: filing section / specification document / guideline>> |
| Baseline period start and end | <<FILL>> |
| Number of results in baseline (n) | <<FILL>> |
| Basis for calling the baseline period “in control” | <<FILL>> |
| Derivation method used | <<FILL: non-parametric percentile / other, with justification>> |
| Alert limit derived | <<FILL>> |
| Action limit derived | <<FILL>> |
| Cap check performed (neither limit exceeds the applicable limit) | Yes / No |
| Effective date of these limits | <<FILL>> |
| Next scheduled review date | <<FILL>> |
| Reason for this issue | <<FILL: initial derivation / scheduled review / process change / method change>> |
2. Baseline data set
The limits describe what this process does when it is behaving. That means the baseline has to come from a period when it actually was.
| Requirement | Entry |
|---|---|
| Period covered | <<FILL>> |
| Number of results | <<FILL>> |
| Same recovery method throughout? | Yes / No (if No, the data is not poolable) |
| Same sample volume or mass throughout? | Yes / No (if No, the data is not poolable) |
| Same control point throughout? | Yes / No |
| Results excluded, and why | <<FILL: none, or list each with the documented assignable cause>> |
| Evidence the period was in control | <<FILL: no unexplained excursions, no open investigations at this control point, no unresolved process changes>> |
Rules for the baseline:
- Same method, same sample size, same control point. A result from a 1 mL plate count and a result from a 100 mL membrane filtration are not the same measurement and cannot sit in one data set.
- Do not exclude results because they are high. A result may be excluded only where an assignable cause was documented at the time, in an approved investigation. Removing inconvenient points before the derivation is the same error as re-deriving a limit to make an excursion disappear, performed earlier.
- State the minimum n.
<<FILL: e.g. not fewer than 30 results, and not fewer than 100 before a high percentile is used>>. A high percentile calculated from a small data set is simply the largest observation wearing a statistical label. - Attach the raw data set to this form. The derivation must be reproducible from the attachment without going back to source systems.
3. Derivation method
Microbial count data is not normally distributed. It is bounded at zero, right-skewed, and typically contains a large proportion of zeros, especially at a well controlled in-process control point. Applying a mean plus two or three standard deviations calculation to that distribution assumes a shape the data does not have; it can produce a negative lower bound, and it is sensitive to the single largest value in a way that a percentile is not.
Non-parametric percentile approaches generally behave better on this kind of data. They make no distributional assumption and they are reproducible from the data set alone.
3.1 Percentile derivation (default)
| Step | Working |
|---|---|
| Sort the n baseline results in ascending order | <<FILL: attach>> |
| Alert limit percentile selected | <<FILL: e.g. 95th>> |
| Rank for the alert percentile (nearest rank, round up) | <<FILL: ceil(percentile x n)>> |
| Value at that rank | <<FILL>> |
| Alert limit (rounded to a whole count, upward only if justified) | <<FILL>> |
| Action limit percentile or rule selected | <<FILL: e.g. 99th percentile, or the applicable limit where n is too small>> |
| Rank for the action percentile | <<FILL>> |
| Value at that rank | <<FILL>> |
| Action limit | <<FILL>> |
3.2 Comparison calculation (record it, do not necessarily use it)
Record the mean plus two and three standard deviations for comparison, and state whether the distribution supports that model. Where the numbers happen to agree with the percentile result, that agreement is a coincidence of this data set, not a validation of the normal model.
| Statistic | Value |
|---|---|
| Mean | <<FILL>> |
| Standard deviation | <<FILL>> |
| Proportion of zero results | <<FILL: percent>> |
| Mean + 2 SD | <<FILL>> |
| Mean + 3 SD | <<FILL>> |
| Is a normal model defensible for this data? | Yes / No, with reasoning |
3.3 Cap against the applicable limit
Neither the alert limit nor the action limit may exceed the applicable regulatory or specification limit at that control point.
| Check | Entry |
|---|---|
| Applicable limit | <<FILL>> |
| Derived alert limit | <<FILL>> |
| Derived action limit | <<FILL>> |
| Alert limit at or below the applicable limit? | Yes / No |
| Action limit at or below the applicable limit? | Yes / No |
| If either exceeded it, capped value applied | <<FILL>> |
Where the derivation produces a limit above the applicable limit, the process capability is the problem, not the limit. Capping the number is the immediate action; understanding why the process runs that close to its limit is the real one.
4. Defined response to each level
Write the response before you need it. A limit with no defined response is a number, not a control.
| Level | Definition | Response | Owner | Timing |
|---|---|---|---|---|
| At or below alert | Normal operation | Record and trend | <<FILL>> | Routine |
| Above alert, at or below action | Early warning that the process is drifting | <<FILL: notify supervisor and process owner; review recent results for trend; identify isolates; record the review>> | <<FILL>> | <<FILL: e.g. same working day>> |
| Above action, below specification | Defined response required; material still within specification | <<FILL: raise an investigation; identify and assess isolates; assess batch impact; decide on the affected material; assess upstream systems>> | <<FILL>> | <<FILL>> |
| At or above specification or regulatory limit | Out of specification | <<FILL: report same working day; quarantine; route per the OOS procedure; no repeat testing before the investigation is opened>> | <<FILL>> | <<FILL: same working day>> |
Note that an organism identification can escalate a result that the numbers alone would have passed. An objectionable organism recovered below the alert limit is still a deviation.
5. Periodic review and re-derivation
| Field | Entry |
|---|---|
| Review frequency | <<FILL: e.g. annually, and after any process or method change>> |
| Review triggers outside the cycle | <<FILL: process change, method change, sample volume change, control point change, sustained trend, facility change>> |
| Data period covered by this review | <<FILL>> |
| Number of results since last derivation | <<FILL>> |
| Trend observed | <<FILL>> |
| Re-derivation performed? | Yes / No |
| New limits (if changed) | <<FILL>> |
| Direction of change | <<FILL: tightened / widened / unchanged>> |
| Recorded rationale for the change | <<FILL>> |
| Integrity check completed (section 6) | Yes / No |
Re-derive against accumulated data on the defined cycle. Tightening limits as a process improves is the expected outcome of a working programme; limits that never move as a process matures suggest nobody is looking.
6. Integrity control on limit changes
This is the section an inspector will read most carefully, and it exists because the failure mode is easy and quiet.
Recalculating a limit so that a signal disappears converts monitoring into a mechanism for not noticing things. The excursions stop being reported, the trend flattens, and the record shows a controlled process.
The test to apply, and to record, before any limit is widened:
The recorded reason for changing a limit must be one that would have applied whether or not a signal was sitting in the data.
| Integrity check | Entry |
|---|---|
| Is there an open excursion, investigation, or adverse trend at this control point? | Yes / No |
| If yes, describe it | <<FILL>> |
| Stated reason for the limit change | <<FILL>> |
| Would that reason have applied if the excursion or trend did not exist? | Yes / No |
| If No, the change is not approved on this basis | <<FILL: record the decision>> |
| Independent reviewer confirming the above | <<FILL>> |
Reasons that pass the test: a validated change of recovery method or sample volume that changes what the number measures; a documented process or facility change; the accumulation of enough additional data to support a better estimate; a change to the applicable regulatory or specification limit.
Reasons that fail the test: recent excursions at this control point; the investigation workload the current limit generates; the limit being described as “too tight” with no supporting change; a batch currently under investigation.
A widening that fails this test is not automatically forbidden forever. It is forbidden on that basis. Close the excursion on its own merits first, then review the limit on the cycle with the excursion in the data set rather than removed from it.
7. Approval
| Role | Name | Signature | Date |
|---|---|---|---|
| Derived by | <<FILL>> | ||
| Verified by (independent recalculation from the attached data) | <<FILL>> | ||
| Process owner | <<FILL>> | ||
| QA approval | <<FILL>> |
8. Attachments
Baseline data set; sorted data and percentile calculation; comparison statistics; trend chart; prior version of this form; records of any excluded result and its documented assignable cause.
Filled specimen
The following shows an initial derivation and a subsequent periodic review for an example bulk bioburden control point. Company, product, and numbers are illustrative; replace them with your own.
Control point: Compounding vessel outlet, immediately before final sterilising filtration. Product MAB-2210 bulk drug product. Parameter TAMC, unit CFU per 100 mL, membrane filtration of a 100 mL sample throughout. Applicable limit: not more than 10 CFU per 100 mL, per the product specification.
Baseline: 30 commercial batches, 14 August 2024 to 20 June 2026. Same method, same volume, same control point throughout. No results excluded. No open investigations at this control point during the period and no unexplained excursions, so the period is accepted as demonstrating control.
Data set (frequency form):
| Result (CFU per 100 mL) | Number of batches | Cumulative count | Cumulative percent |
|---|---|---|---|
| 0 | 14 | 14 | 46.7 |
| 1 | 7 | 21 | 70.0 |
| 2 | 4 | 25 | 83.3 |
| 3 | 2 | 27 | 90.0 |
| 4 | 1 | 28 | 93.3 |
| 5 | 1 | 29 | 96.7 |
| 7 | 1 | 30 | 100.0 |
Percentile derivation (nearest rank, round up):
- Alert, 95th percentile: rank = 0.95 x 30 = 28.5, rounded up to rank 29. The value at rank 29 is 5. Alert limit = 5 CFU per 100 mL.
- Action, 99th percentile: rank = 0.99 x 30 = 29.7, rounded up to rank 30. The value at rank 30 is 7, which is simply the maximum observed value. With n = 30, a 99th percentile carries almost no information. The action limit was therefore set at 7 CFU per 100 mL on the stated basis that it is the highest count observed under demonstrated control, with a recorded commitment to re-derive the action limit as a true 99th percentile once n reaches 100. Action limit = 7 CFU per 100 mL.
Comparison calculation: mean 1.23, standard deviation 1.72, zeros 46.7 percent of results. Mean + 2 SD = 4.7, mean + 3 SD = 6.4. These land close to the percentile values, but a distribution that is 47 percent zeros and bounded below is not normal, so the normal model is not defensible here and was not used. The closeness of the numbers is a property of this data set, not evidence that the model fits.
Cap check: alert 5 and action 7 both sit below the applicable limit of 10 CFU per 100 mL. No capping required. Effective 01 July 2026, next review 01 July 2027.
Periodic review, 12 months later. 96 results now available, including the original 30. Following a purified water loop sanitisation and a change to loop sampling frequency in July 2026, the distribution shifted: 61 percent zeros, maximum 5, 95th percentile value 3, 99th percentile value 5. The limits were re-derived and tightened to alert 3 and action 5. The recorded rationale was the accumulation of 66 additional results and a documented process change, both of which would have applied regardless of any signal in the data. Integrity check passed.
A change that was rejected. During the same review, a proposal was raised to widen the alert limit from 5 to 8 on the grounds that the existing alert limit had generated four alert excursions in the previous quarter and the associated reviews were consuming laboratory time. Applying the section 6 test, the reviewer asked whether that reason would have applied if the four excursions did not exist. It would not; the excursions were the entire reason. The proposal was rejected on that basis and recorded as rejected, with the four excursions investigated on their own merits. Three were traced to a single raw material lot and one had no assignable cause. The limit review then proceeded on the cycle with all four results included in the data set, and the outcome was a tightening rather than a widening.
That rejected proposal is the most useful thing in this record. It is the point at which the programme either stays a monitoring system or quietly becomes a way of producing quiet data.
Common inspection findings this form prevents
- Alert and action limits set at round numbers with no link to process capability and no derivation on file.
- A limit widened shortly after a run of excursions, with a rationale that only makes sense because the excursions happened.
- Baseline data pooled across different sample volumes or recovery methods, so the derivation describes no single measurement.
- High results dropped from the baseline with no documented assignable cause, producing limits the process cannot actually meet.
- An alert or action limit set above the applicable regulatory or specification limit, so the “action” trigger fires only after the material has already failed.
- Limits with no defined response, so an excursion produces a note in a log and nothing else.
- Limits never reviewed as the process matured, or reviewed with no record of the data considered.
- Mean plus three standard deviations applied to a data set that is mostly zeros, with no assessment of whether the model fits.
- A derivation that cannot be reproduced from the attached data.
How to adapt this form
- Complete one form per control point and per parameter. TAMC and TYMC at the same control point are separate derivations.
- Fix the applicable regulatory or specification limit first and record where it came from, because it is the cap on everything below it.
- Set your minimum n and your percentile choices as standing rules in the parent procedure, so they are not selected after seeing the data.
- Attach the raw data set and make the derivation reproducible from the attachment alone.
- Record the comparison statistics even when you do not use them, so a reviewer can see the choice was made rather than defaulted to.
- Fill the response table in section 4 with real owners and real timings before the limits go into effect.
- Run the section 6 integrity check on every proposed change, record the answer either way, and keep rejected proposals on file. A rejected widening is evidence the control is working.
- Read this alongside the bioburden testing SOP and bioburden and bacterial endotoxin testing.