This is a ready-to-use OQ protocol for the data-integrity behaviors of a process historian. Generic CSV testing does not prove a historian’s time-series behavior is correct; these challenge tests do. Replace every <<FILL: ...>> placeholder, execute contemporaneously with attributable entries, and route through your validation lifecycle. A filled specimen test case follows. Verify each cited regulation against the current source before you rely on it. This protocol supports the SOP: Process Historian Data Integrity Governance and the Log: Process Historian GxP Tag Register.
Approval page
| Role | Name | Signature | Date |
|---|---|---|---|
| Author (Validation / CSV) | <<FILL>> | ||
| Reviewer (Automation / System Owner) | <<FILL>> | ||
| Reviewer (QA) | <<FILL>> | ||
| Approver (Quality Head) | <<FILL>> |
Pre-approval (before execution) and post-approval (after execution and review) both required. Protocol number <<FILL: VAL-ID>>, version <<FILL>>.
1. Objective
To verify that the process historian captures, stores, retrieves, protects, retains, and exports GxP time-series data with integrity, specifically challenging compression, interpolation, quality-flag handling, audit trail, time control, and archive/restore.
2. Scope
The historian <<FILL: system name, version>> and its GxP-classified tags per the tag register <<FILL: register ID>>. Interfaces in scope: <<FILL: source PLC/DCS/SCADA>>. Out of scope: control-layer logic, covered by <<FILL: reference>>.
3. System description
<<FILL: brief description: architecture, source devices, storage, retrieval clients, time source, archive strategy>>
4. Prerequisites
- Approved URS and configuration specification with the data-integrity requirements stated.
- Tag register current and GxP-critical list QA-approved.
- IQ complete and approved; system in a controlled state.
- Test tools calibrated (signal source / reference), test accounts provisioned with unique IDs.
5. Roles
| Role | Responsibility |
|---|---|
| Tester | Executes test cases, records actual results and evidence contemporaneously. |
| Reviewer (System owner) | Confirms configuration and technical correctness. |
| QA | Reviews execution, approves acceptance, dispositions deviations. |
6. Acceptance criteria (protocol level)
All test cases pass, or any failure has an approved deviation with justified resolution and, where needed, retest. No GxP-critical excursion can be hidden by compression; no interpolated value is presented as measured without a label; audit trail reconstructs configuration and data changes; archived data restores complete and unchanged.
7. Test cases
Record for each: actual result, pass/fail, tester initials, date, evidence reference.
| ID | Test step | Expected result | Actual | P/F | Tester / date |
|---|---|---|---|---|---|
| TC-01 Capture accuracy | Inject a known calibrated signal at the source; compare stored values to the source over a defined window | Stored values match the source within <<FILL: tolerance>> | <<FILL>> | ||
| TC-02 Compression (critical) | On a GxP-critical tag with compression disabled, feed a transient excursion of <<FILL: magnitude, duration>> | The excursion is stored, not smoothed away | <<FILL>> | ||
| TC-03 Compression (deadband) | On a compressed tag, feed signals just inside and just outside the configured deadband | Behavior matches the documented deadband; nothing of regulatory concern is lost | <<FILL>> | ||
| TC-04 Interpolation / retrieval | Query the same window in raw and interpolated modes | Raw returns stored points; interpolated values are labeled; the GxP report uses the specified mode | <<FILL>> | ||
| TC-05 Aggregation consistency | Generate the standard GxP report twice with the defined settings | Identical results; aggregation method and interval boundaries are fixed | <<FILL>> | ||
| TC-06 Quality flags | Simulate a sensor fault / communication loss | Bad-quality samples and the resulting gap appear in trends and reports, not silently filled | <<FILL>> | ||
| TC-07 Audit trail (config) | Change a tag’s compression / scan rate / retention under a test change | Audit trail records who, what, old value, new value, when | <<FILL>> | ||
| TC-08 Audit trail (data) | Attempt a manual edit of a stored value (if possible) | Edit is restricted or fully audit-trailed with reason; ordinary users cannot disable the trail | <<FILL>> | ||
| TC-09 Time synchronization | Compare source-device and historian time; introduce and observe a controlled time change | Times agree within <<FILL: tolerance>>; time change is logged and restricted | <<FILL>> | ||
| TC-10 Retention / archive | Move data through the archive cycle | Data retrievable and unchanged; no unauthorized down-sampling of GxP-critical tags | <<FILL>> | ||
| TC-11 Restore | Restore an archived window and compare to original | Restored data complete, accurate, with metadata and audit trail | <<FILL>> | ||
| TC-12 True-copy export | Export a defined window for GxP use | Export is complete, accurate, human-readable, includes metadata and quality flags | <<FILL>> | ||
| TC-13 Access control | Attempt privileged actions with a routine account | Denied; roles enforce least privilege; no shared accounts on GxP functions | <<FILL>> |
8. Deviation handling
Any failure or unexpected result is recorded as a protocol deviation with description, impact, root cause, resolution, and retest where applicable, reviewed and approved by QA before the protocol is closed. Reference <<FILL: deviation SOP>>.
9. Summary and conclusion
On completion, summarize results versus acceptance criteria, list deviations and their resolution, and state the qualification conclusion. Attach evidence (screenshots, exports, audit trail extracts).
| Field | Entry |
|---|---|
| Test cases executed / passed | <<FILL>> |
| Deviations raised / closed | <<FILL>> |
| Conclusion | <<FILL: qualified for intended use / not qualified>> |
| QA disposition (name, signature, date) | <<FILL>> |
References
21 CFR 211.68 (I/O accuracy checks), Part 11 (electronic records, audit trail, access). EU GMP Annex 11 (validation, data accuracy, storage, audit trail, security). Pending draft Annex 11 revision (consultation closed 7 October 2025, draft as of mid-2026); confirm final clause numbers before citing. GAMP 5 (2nd ed., 2022) for the risk-based approach; ASTM E2500-13 where a commissioning-and-qualification approach is used.
Confirm each reference against the current source before issue.
Filled specimen (one executed test case)
| Field | Entry |
|---|---|
| ID | TC-02 Compression (critical), tag BR101.TEMP.PV |
| Test step | Fed a 30-second +2.5 degC transient via calibrated source, compression disabled on this tag |
| Expected | The transient is stored, visible at 1-second resolution |
| Actual | Transient stored; 30 one-second points show the excursion and recovery; retrieved in raw mode with no smoothing |
| Pass/Fail | Pass |
| Tester / date | A. Reyes, 03 July 2026 |
| Evidence | Export EXP-TC02-BR101 attached; source log attached |
Contrast: the same test on a tag with a 3 degC deadband would have smoothed the 2.5 degC transient out of the record entirely, which is exactly why compression is disabled on GxP-critical batch tags and why this test exists.
How to adapt this protocol
- Populate the tag references, tolerances, and excursion magnitudes from your process control limits and your tag register.
- Drop TC-08 to a “restricted, not possible” verification if manual editing of stored values is fully disabled for GxP tags, and record that as the expected result.
- For a legacy historian, run this as retrospective/periodic-review qualification and route any bad historical settings through deviation and impact assessment on already-released batches.
- Confirm each regulation against the current source, including the pending Annex 11 revision, before execution.