This is a ready-to-use operational qualification protocol for a process automation system (PLC, SCADA, or DCS). It proves each GMP-impacting function works against specification, usually with simulated or injected signals, before performance qualification under live process conditions. Replace every <<FILL: ...>> placeholder, set your document numbers, and route it through document control. A worked filled specimen follows. This content is educational and general; adapt it to your own quality system and verify each reference against the current source.
Approval page
| Role | Name | Signature | Date |
|---|---|---|---|
| Author (CSV / automation) | <<FILL>> | ||
| Reviewer (process SME) | <<FILL>> | ||
| Reviewer (QA) | <<FILL>> | ||
| Approver (Quality) | <<FILL>> |
Pre-approval is required before execution. Post-approval is required after execution and deviation closure.
| Field | Entry |
|---|---|
| Protocol number | <<FILL: OQ-ID>> |
| System name / ID | <<FILL>> |
| Version under test | <<FILL: program/config version + checksum>> |
1. Objective
To verify that <<FILL: SYSTEM NAME>> performs its specified control functions correctly across their operating range, that interlocks, alarms, and sequences behave as designed at their boundaries, and that the data integrity controls (audit trail, access, time synchronization) are effective, so the system is fit to proceed to PQ.
2. Scope
This OQ covers the GMP-impacting functions of the system identified in the risk assessment <<FILL: reference>> and traced in <<FILL: traceability matrix reference>>. It follows a passed and approved IQ (<<FILL: IQ reference>>). It does not cover live-process performance, which is PQ (<<FILL: PQ reference>>).
3. System description
<<FILL: brief description: platform, ISA-95 level, controlled process, interfaces to historian/MES, number of I/O, GAMP category by function>>
4. Prerequisites
| # | Prerequisite | Verified (Y/N) | By |
|---|---|---|---|
| 1 | IQ complete, reviewed, approved | ||
| 2 | Program / configuration version locked and checksum recorded | ||
| 3 | Instruments providing signals are calibrated and in date | ||
| 4 | Test instruments (signal simulators, reference meters) calibrated and traceable | ||
| 5 | URS and design specs approved and available | ||
| 6 | Executors trained on this protocol |
5. Roles
| Role | Responsibility |
|---|---|
| Executor (automation / CSV) | Runs the test steps, records actual results and evidence |
| Process SME | Confirms setpoints, interlock values, and sequence logic are correct |
| QA | Reviews execution, approves deviations, approves the protocol |
6. Acceptance criteria (summary)
| Test area | Acceptance criterion |
|---|---|
| I/O loop scaling | Reading at PLC, HMI, and historian agree within the instrument tolerance at low, mid, and high injection points |
| Interlock | Trip occurs at the specified setpoint within the specified response time; no trip just inside the safe boundary |
| Alarm setpoint | Configured value equals the URS value and matches HMI, historian, and batch record |
| Sequence | Abort, hold, and resume each return the system to the defined correct or safe state; no orphaned steps |
| Audit trail | Every configuration and setpoint change is recorded with user, timestamp, old and new value |
| Access control | Roles separate operate, configure, and administer; no shared login for attributable actions |
| Time synchronization | System time syncs to the defined source; drift within the defined limit; sync failure raises an alert |
7. Test cases
Record actual result, pass/fail, evidence reference, tester, and date for each.
| TC | Function | Step | Expected result | Actual | P/F | Evidence | Tester / date |
|---|---|---|---|---|---|---|---|
| OQ-01 | I/O scaling (temp loop) | Inject low, mid, high (e.g. 4, 12, 20 mA) at transmitter | PLC, HMI, historian all read the mapped value (e.g. 0, 75, 150 C) within tolerance | ||||
| OQ-02 | Interlock (jacket heat) | Simulate just inside setpoint, then at setpoint | No trip inside; trip at setpoint within response time; event alarmed and recorded | ||||
| OQ-03 | Alarm setpoint | Compare each configured alarm to URS and HMI/historian/BR | All match the URS value | ||||
| OQ-04 | Sequence abort | Trigger abort mid-sequence | System reaches the defined safe/correct state; no orphaned step | ||||
| OQ-05 | Sequence hold/resume | Hold then resume | Resumes at the correct step with no data loss | ||||
| OQ-06 | Audit trail | Make a controlled setpoint change | Change recorded with user, timestamp, old and new value | ||||
| OQ-07 | Access control | Attempt a configure action with an operate-only account | Action denied; attempt logged | ||||
| OQ-08 | Time sync | Check sync to source; simulate source loss | Time syncs; drift within limit; loss raises an alert | ||||
| OQ-09 | <<FILL: system-specific function>> | <<FILL>> | <<FILL>> |
8. Deviation handling
Any actual result that does not meet the expected result is recorded as a protocol deviation with a unique number, assessed for impact on the qualification and on the system’s fitness for use, and resolved before the summary is approved. Reference your deviation procedure <<FILL: SOP-ID>>.
9. Summary and conclusion
| Field | Entry |
|---|---|
| Test cases executed | <<FILL>> |
| Passed | <<FILL>> |
| Deviations raised / closed | <<FILL>> |
| Conclusion | <<FILL: system meets OQ acceptance criteria and may proceed to PQ / does not>> |
| Role | Name | Signature | Date |
|---|---|---|---|
| Executor | <<FILL>> | ||
| QA approval | <<FILL>> |
10. Attachments
- Loop check data sheets, alarm setpoint comparison, sequence test records.
- Audit trail export for the test period.
- Calibration certificates for reference instruments.
- Traceability matrix extract.
References
21 CFR 211.68 (automatic, mechanical, and electronic equipment). 21 CFR Part 11 (electronic records and signatures). EU GMP Annex 11 (Computerised systems) and Annex 15 (Qualification and validation). ISPE GAMP 5, A Risk-Based Approach to Compliant GxP Computerized Systems (Second Edition, 2022). FDA Guidance, Computer Software Assurance for Production and Quality Management System Software (issued 3 February 2026, superseding the 24 September 2025 final).
Filled specimen
One executed test case, to show the level of evidence expected.
| TC | Function | Step | Expected | Actual | P/F | Evidence | Tester / date |
|---|---|---|---|---|---|---|---|
| OQ-01 | I/O scaling, TT-201 | Inject 4, 12, 20 mA at transmitter | PLC/HMI/historian read 0, 75, 150 C within +/- 0.5 C | 0.1, 75.2, 150.1 C, all three tags agree | Pass | Data sheet DS-OQ01, historian export H-2607-11 | A. Reyes, 11 Jul 2026 |
| OQ-02 | Interlock, jacket heat | Simulate 64.5 C then 65.0 C | No trip at 64.5; trip at 65.0 within 2 s, alarmed | No trip at 64.5; tripped at 65.1 C in 1.3 s, alarm ALM-118 logged | Pass | Video + alarm log | A. Reyes, 11 Jul 2026 |
The interlock row shows the discipline: both the just-inside and the at-setpoint points were tested, the actual trip value was recorded, and the alarm event was captured, so the protocol proves the boundary rather than merely that an interlock exists.
Common inspection findings this protocol prevents
- Loop checks done at a single point, so a scaling or mapping defect at the extremes is missed.
- Interlocks “tested” only by confirming they exist, never at the boundary.
- Alarm setpoints not reconciled to the URS and the batch record.
- Sequences tested only on the happy path, with abort, hold, and resume untested.
- No evidence that the audit trail actually captured a change made during the test.
How to adapt this protocol
- Build the test-case table from your traceability matrix so every GMP-impacting requirement has at least one case.
- Set injection points and tolerances from your instrument ranges and calibration tolerances.
- Add Category 5 structural test cases for any custom logic (bespoke sequences or phases).
- Reference your real IQ, PQ, deviation, and change-control documents.
- Confirm every reference against the current published version before execution.