Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Protocol Plug-and-play starting point Manufacturing Automation

Protocol: Automation System Operational Qualification (PLC, SCADA, DCS)

A plug-and-play OQ protocol for a process automation system: I/O loop scaling checks, interlock boundary testing, alarm setpoint verification, sequence and abort/hold/resume testing, audit trail and access, and time synchronization, with acceptance criteria, a test-case table, deviation handling, and a filled specimen.

Document type: Protocol

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use operational qualification protocol for a process automation system (PLC, SCADA, or DCS). It proves each GMP-impacting function works against specification, usually with simulated or injected signals, before performance qualification under live process conditions. Replace every <<FILL: ...>> placeholder, set your document numbers, and route it through document control. A worked filled specimen follows. This content is educational and general; adapt it to your own quality system and verify each reference against the current source.

Approval page

RoleNameSignatureDate
Author (CSV / automation)<<FILL>>
Reviewer (process SME)<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality)<<FILL>>

Pre-approval is required before execution. Post-approval is required after execution and deviation closure.

FieldEntry
Protocol number<<FILL: OQ-ID>>
System name / ID<<FILL>>
Version under test<<FILL: program/config version + checksum>>

1. Objective

To verify that <<FILL: SYSTEM NAME>> performs its specified control functions correctly across their operating range, that interlocks, alarms, and sequences behave as designed at their boundaries, and that the data integrity controls (audit trail, access, time synchronization) are effective, so the system is fit to proceed to PQ.

2. Scope

This OQ covers the GMP-impacting functions of the system identified in the risk assessment <<FILL: reference>> and traced in <<FILL: traceability matrix reference>>. It follows a passed and approved IQ (<<FILL: IQ reference>>). It does not cover live-process performance, which is PQ (<<FILL: PQ reference>>).

3. System description

<<FILL: brief description: platform, ISA-95 level, controlled process, interfaces to historian/MES, number of I/O, GAMP category by function>>

4. Prerequisites

#PrerequisiteVerified (Y/N)By
1IQ complete, reviewed, approved
2Program / configuration version locked and checksum recorded
3Instruments providing signals are calibrated and in date
4Test instruments (signal simulators, reference meters) calibrated and traceable
5URS and design specs approved and available
6Executors trained on this protocol

5. Roles

RoleResponsibility
Executor (automation / CSV)Runs the test steps, records actual results and evidence
Process SMEConfirms setpoints, interlock values, and sequence logic are correct
QAReviews execution, approves deviations, approves the protocol

6. Acceptance criteria (summary)

Test areaAcceptance criterion
I/O loop scalingReading at PLC, HMI, and historian agree within the instrument tolerance at low, mid, and high injection points
InterlockTrip occurs at the specified setpoint within the specified response time; no trip just inside the safe boundary
Alarm setpointConfigured value equals the URS value and matches HMI, historian, and batch record
SequenceAbort, hold, and resume each return the system to the defined correct or safe state; no orphaned steps
Audit trailEvery configuration and setpoint change is recorded with user, timestamp, old and new value
Access controlRoles separate operate, configure, and administer; no shared login for attributable actions
Time synchronizationSystem time syncs to the defined source; drift within the defined limit; sync failure raises an alert

7. Test cases

Record actual result, pass/fail, evidence reference, tester, and date for each.

TCFunctionStepExpected resultActualP/FEvidenceTester / date
OQ-01I/O scaling (temp loop)Inject low, mid, high (e.g. 4, 12, 20 mA) at transmitterPLC, HMI, historian all read the mapped value (e.g. 0, 75, 150 C) within tolerance
OQ-02Interlock (jacket heat)Simulate just inside setpoint, then at setpointNo trip inside; trip at setpoint within response time; event alarmed and recorded
OQ-03Alarm setpointCompare each configured alarm to URS and HMI/historian/BRAll match the URS value
OQ-04Sequence abortTrigger abort mid-sequenceSystem reaches the defined safe/correct state; no orphaned step
OQ-05Sequence hold/resumeHold then resumeResumes at the correct step with no data loss
OQ-06Audit trailMake a controlled setpoint changeChange recorded with user, timestamp, old and new value
OQ-07Access controlAttempt a configure action with an operate-only accountAction denied; attempt logged
OQ-08Time syncCheck sync to source; simulate source lossTime syncs; drift within limit; loss raises an alert
OQ-09<<FILL: system-specific function>><<FILL>><<FILL>>

8. Deviation handling

Any actual result that does not meet the expected result is recorded as a protocol deviation with a unique number, assessed for impact on the qualification and on the system’s fitness for use, and resolved before the summary is approved. Reference your deviation procedure <<FILL: SOP-ID>>.

9. Summary and conclusion

FieldEntry
Test cases executed<<FILL>>
Passed<<FILL>>
Deviations raised / closed<<FILL>>
Conclusion<<FILL: system meets OQ acceptance criteria and may proceed to PQ / does not>>
RoleNameSignatureDate
Executor<<FILL>>
QA approval<<FILL>>

10. Attachments

  • Loop check data sheets, alarm setpoint comparison, sequence test records.
  • Audit trail export for the test period.
  • Calibration certificates for reference instruments.
  • Traceability matrix extract.

References

21 CFR 211.68 (automatic, mechanical, and electronic equipment). 21 CFR Part 11 (electronic records and signatures). EU GMP Annex 11 (Computerised systems) and Annex 15 (Qualification and validation). ISPE GAMP 5, A Risk-Based Approach to Compliant GxP Computerized Systems (Second Edition, 2022). FDA Guidance, Computer Software Assurance for Production and Quality Management System Software (issued 3 February 2026, superseding the 24 September 2025 final).


Filled specimen

One executed test case, to show the level of evidence expected.

TCFunctionStepExpectedActualP/FEvidenceTester / date
OQ-01I/O scaling, TT-201Inject 4, 12, 20 mA at transmitterPLC/HMI/historian read 0, 75, 150 C within +/- 0.5 C0.1, 75.2, 150.1 C, all three tags agreePassData sheet DS-OQ01, historian export H-2607-11A. Reyes, 11 Jul 2026
OQ-02Interlock, jacket heatSimulate 64.5 C then 65.0 CNo trip at 64.5; trip at 65.0 within 2 s, alarmedNo trip at 64.5; tripped at 65.1 C in 1.3 s, alarm ALM-118 loggedPassVideo + alarm logA. Reyes, 11 Jul 2026

The interlock row shows the discipline: both the just-inside and the at-setpoint points were tested, the actual trip value was recorded, and the alarm event was captured, so the protocol proves the boundary rather than merely that an interlock exists.

Common inspection findings this protocol prevents

  • Loop checks done at a single point, so a scaling or mapping defect at the extremes is missed.
  • Interlocks “tested” only by confirming they exist, never at the boundary.
  • Alarm setpoints not reconciled to the URS and the batch record.
  • Sequences tested only on the happy path, with abort, hold, and resume untested.
  • No evidence that the audit trail actually captured a change made during the test.

How to adapt this protocol

  1. Build the test-case table from your traceability matrix so every GMP-impacting requirement has at least one case.
  2. Set injection points and tolerances from your instrument ranges and calibration tolerances.
  3. Add Category 5 structural test cases for any custom logic (bespoke sequences or phases).
  4. Reference your real IQ, PQ, deviation, and change-control documents.
  5. Confirm every reference against the current published version before execution.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.