Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Protocol Plug-and-play starting point Equipment Qualification

Instrument Installation Qualification (IQ) Protocol

A plug-and-play installation qualification protocol for a laboratory instrument: delivery and component verification, utilities and environment, software and firmware versions, calibration certificates, documentation, test cases with expected and actual results, deviations, and summary, with a worked HPLC specimen and the regulations it satisfies.

Document type: Protocol

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use installation qualification protocol for a laboratory instrument. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, attach the vendor documents and calibration certificates the protocol calls for, and route it through your normal document control, review, and approval. A worked filled specimen for an HPLC system follows the template so you can see how a completed version reads. Verify each cited regulation against the current source before you rely on it.

IQ proves one thing: that the instrument arrived complete, undamaged, and to specification, and was installed correctly in the right environment with the right utilities, software, and documentation, before anyone tries to make it perform. It is the second stage of the qualification lifecycle after design qualification (DQ) and before operational qualification (OQ) and performance qualification (PQ). Everything OQ later relies on (a stable power supply, the correct firmware, a calibrated detector lamp) is established and recorded here.

Document control header

FieldEntry
Document titleInstallation Qualification Protocol for <<FILL: instrument type / model>>
Document number<<FILL: PRT-ID, e.g. IQ-LAB-031>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Supersedes<<FILL: prior version or "New">>
Document owner<<FILL: role, e.g. Head of Metrology / Laboratory>>
Site / room<<FILL: site, building, laboratory room>>
Linked DQ / OQ / PQ<<FILL: DQ ref; OQ ref to follow; PQ ref to follow>>
Linked report<<FILL: IQ summary report number to be issued>>

1. Purpose

This protocol defines the checks and acceptance criteria to confirm that instrument <<FILL: instrument ID / asset number>> was delivered complete and undamaged, installed correctly at <<FILL: room / bench>>, supplied with the correct utilities and environment, loaded with the specified software and firmware, supported by valid calibration and documentation, and is ready to enter operational qualification. The objective is a documented, inspection-ready record that installation matches the approved specification and vendor requirements.

2. Scope

This protocol applies to the single instrument identified in the header and section 5, including its modules, the controlling workstation and data system where fitted, and the immediate utilities and environment serving it. It covers verification at installation only. It does not establish operating performance, which is covered by the OQ referenced in the header, and it does not cover routine use, calibration intervals, or change control after qualification, which are governed by <<FILL: cross-reference SOP-IDs>>. Where the instrument includes a computerized system holding GxP data, the software-related checks here are coordinated with the computerized system validation under <<FILL: CSV SOP-ID>> and do not replace it.

3. Responsibilities

RoleResponsibility
Validation engineer / metrologistAuthors and executes this protocol, records results, raises deviations, and writes the summary report.
Instrument / laboratory ownerConfirms the instrument and configuration match the approved DQ and user requirements, and supports execution.
Vendor field service engineerPerforms the physical installation and the vendor IQ/commissioning, and supplies installation records, certificates, and version evidence. Vendor records are reviewed and attached, not blindly accepted.
IT / system administratorConfirms network, workstation, time synchronization, and access configuration where a data system is fitted.
QC analytical (where applicable)Confirms the instrument and configuration meet the intended analytical use.
Quality AssuranceReviews and approves the protocol, deviations, and report, and authorizes progression to OQ.

4. Definitions

  • Installation qualification (IQ): documented verification that an instrument and its components are received as specified and correctly installed in the selected environment.
  • Design qualification (DQ): documented verification, before purchase, that the proposed instrument is fit for its intended use; the input to this IQ.
  • Operational qualification (OQ): documented verification that the installed instrument operates as intended across its operating ranges; the next stage after this IQ.
  • Instrument category (USP <1058>): a risk-tiered way to sort instruments by complexity so the qualification effort matches the risk. Simpler measuring devices that need little or no separate qualification sit in the lowest tier; routine bench instruments with adjustable parameters sit in the middle tier and need installation and function checks; software-driven analytical systems with a data system sit in the highest tier and need the deepest qualification. The category an instrument falls into sets how much of this protocol applies.
  • Critical component: a part whose identity, model, or version affects data quality or instrument performance and so must be recorded at installation (for example a detector lamp, a column heater, a firmware version).
  • As-found / as-installed configuration: the recorded state of hardware, modules, software, and firmware at the time of installation, used as the baseline for later change control.

5. Instrument and configuration under qualification

State the instrument category per USP <1058> in section 5.1; the category drives how much of this protocol applies. Group C instruments (the usual case for a chromatograph with a data system) need the full hardware, software, firmware, and environment checks. Group B instruments need installation and module verification but lighter software checks.

5.1 Instrument identification

FieldEntry
Instrument type<<FILL: e.g. HPLC, GC, dissolution apparatus, balance, plate reader>>
Manufacturer / model<<FILL>>
Serial number<<FILL>>
Asset / equipment ID<<FILL>>
USP <1058> category<<FILL: A / B / C with one-line rationale>>
Intended use<<FILL: e.g. release and stability assay of small-molecule drug product>>
Location (room / bench)<<FILL>>
DQ reference<<FILL: DQ document number>>

5.2 Components and modules (delivery check)

List every module and major accessory expected per the purchase order and packing list. Confirm each is present, the model and serial match, and there is no shipping damage. Anything missing or damaged is a deviation, not a quiet substitution.

Item / moduleModelSerial numberOn PO / packing listPresentDamage (Y/N)
<<FILL: e.g. quaternary pump>><<FILL>><<FILL>>Yes / NoYes / No<<FILL>>
<<FILL: e.g. autosampler>><<FILL>><<FILL>>Yes / NoYes / No<<FILL>>
<<FILL: e.g. column compartment>><<FILL>><<FILL>>Yes / NoYes / No<<FILL>>
<<FILL: e.g. detector>><<FILL>><<FILL>>Yes / NoYes / No<<FILL>>
<<FILL: e.g. controlling workstation>><<FILL>><<FILL>>Yes / NoYes / No<<FILL>>

6. Test cases

Each test case below states what to verify, the expected result, where the actual result and evidence are recorded, and the pass/fail call. Record the actual result, attach the evidence (certificate, screenshot, photo, vendor record), initial and date each line, and reference any deviation. A test case passes only when the actual result meets the expected result and the evidence is attached.

6.1 Delivery and component verification

No.CheckExpected resultActual resultEvidence refPass / FailInit / date
6.1.1Packaging intact, no shipping damageOuter and inner packaging undamaged; shock/tilt indicators (if any) not tripped<<FILL>><<FILL>><<FILL>><<FILL>>
6.1.2All modules and accessories presentEvery line on the PO and packing list present and accounted for<<FILL>><<FILL>><<FILL>><<FILL>>
6.1.3Model and serial numbers matchEach module model/serial matches PO and section 5.2<<FILL>><<FILL>><<FILL>><<FILL>>
6.1.4No physical damage on inspectionNo dents, leaks, cracked displays, bent fittings<<FILL>><<FILL>><<FILL>><<FILL>>

6.2 Utilities and environment

Verify the supplied utilities and the room environment against the manufacturer site preparation requirements. Record the actual measured values, not just “OK”.

No.CheckExpected resultActual resultEvidence refPass / FailInit / date
6.2.1Electrical supplyVoltage, frequency, phases, and dedicated/grounded outlet per manufacturer spec<<FILL: e.g. 230 V, 50 Hz>><<FILL>><<FILL>><<FILL>>
6.2.2Room temperatureWithin manufacturer operating range<<FILL: measured value>><<FILL>><<FILL>><<FILL>>
6.2.3Relative humidityWithin manufacturer operating range<<FILL: measured value>><<FILL>><<FILL>><<FILL>>
6.2.4Bench / vibration / levelStable, level bench; vibration within tolerance for sensitive instruments<<FILL>><<FILL>><<FILL>><<FILL>>
6.2.5Gases / solvents / waste (if applicable)Correct grade gas at correct pressure; solvent and waste lines fitted and labeled<<FILL>><<FILL>><<FILL>><<FILL>>
6.2.6Network connection (if data system)Connected to the qualified network segment per IT<<FILL>><<FILL>><<FILL>><<FILL>>

6.3 Software, firmware, and configuration

Capture the as-installed versions exactly. These versions become the baseline that change control protects, and an OQ run later means nothing if the firmware silently changed afterwards. For a Group C instrument, confirm the data system, time synchronization, and access controls support the records the instrument will generate.

No.CheckExpected resultActual resultEvidence refPass / FailInit / date
6.3.1Instrument firmware versionMatches the version specified in DQ / vendor spec<<FILL: version recorded>><<FILL: screenshot>><<FILL>><<FILL>>
6.3.2Module firmware versionsEach module firmware recorded and within compatible range<<FILL>><<FILL>><<FILL>><<FILL>>
6.3.3Data system / control software versionMatches specified version and license<<FILL: version recorded>><<FILL: screenshot>><<FILL>><<FILL>>
6.3.4Operating system / workstationSpecified OS and patch level, supported configuration<<FILL>><<FILL>><<FILL>><<FILL>>
6.3.5Time and date / time zoneSynchronized to the controlled time source; correct time zone<<FILL>><<FILL>><<FILL>><<FILL>>
6.3.6Audit trail enabled (data system)Audit trail on and cannot be disabled by ordinary users<<FILL>><<FILL>><<FILL>><<FILL>>
6.3.7User accounts / access rolesConfigured per access matrix; no shared accounts for GxP actions<<FILL>><<FILL>><<FILL>><<FILL>>

6.4 Calibration certificates and standards traceability

Confirm that components needing calibration at installation carry a current certificate traceable to a recognized standard, and that the certificate sits within the instrument operating range. Calibration done by the vendor at installation is acceptable if the certificate is reviewed and attached.

No.CheckExpected resultActual resultEvidence refPass / FailInit / date
6.4.1Calibrated components identifiedAll components requiring installation calibration listed<<FILL>><<FILL>><<FILL>><<FILL>>
6.4.2Calibration certificate present and currentCertificate dated, in date, signed<<FILL>><<FILL: cert no.>><<FILL>><<FILL>>
6.4.3Traceability to a recognized standardTraceable to a national/international standard (e.g. NIST or equivalent)<<FILL>><<FILL>><<FILL>><<FILL>>
6.4.4Calibration range covers intended useCalibrated range brackets the working range<<FILL>><<FILL>><<FILL>><<FILL>>

6.5 Documentation

Confirm the documentation that must exist before the instrument can be operated and maintained is on hand and controlled.

No.CheckExpected resultActual resultEvidence refPass / FailInit / date
6.5.1Operating manuals receivedUser and service manuals on hand and current revision<<FILL>><<FILL>><<FILL>><<FILL>>
6.5.2Vendor IQ / installation recordVendor installation/commissioning report reviewed and attached<<FILL>><<FILL>><<FILL>><<FILL>>
6.5.3Maintenance / PM schedule definedPreventive maintenance plan documented<<FILL>><<FILL>><<FILL>><<FILL>>
6.5.4Spare parts / consumables listCritical spares and consumables identified<<FILL>><<FILL>><<FILL>><<FILL>>
6.5.5Instrument logbook / asset record openedLogbook and asset/calibration record created<<FILL>><<FILL>><<FILL>><<FILL>>

7. Acceptance criteria

The IQ is acceptable when all of the following are true:

  • Every applicable test case in section 6 has a recorded actual result that meets the expected result, with evidence attached, and is marked Pass.
  • All delivered components match the PO and section 5.2 with no unresolved damage or shortage.
  • Utilities and environment are within manufacturer specification, recorded as measured values.
  • Software, firmware, and configuration versions are recorded exactly and match the specified versions.
  • Every component requiring calibration carries a current, traceable certificate covering the working range.
  • The required documentation exists, is current, and is under control.
  • Any deviation raised under section 8 is resolved and assessed as not affecting the qualified installation state.

A single failed test case prevents progression to OQ until it is resolved or justified through deviation handling.

8. Deviations

Any check that does not meet its expected result, any missing or damaged component, any version mismatch, or any departure from this protocol is documented as a deviation per <<FILL: deviation SOP-ID>>, assessed for impact, and resolved before the IQ is approved and the instrument progresses to OQ. Record each deviation below and reference the full deviation record.

Deviation no.Test case refDescriptionImpact assessmentResolutionReference
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

9. Summary and conclusion

On completion, the executor summarizes the outcome and states whether the instrument passed IQ and may progress to OQ.

FieldEntry
Test cases executed<<FILL: count>>
Test cases passed<<FILL: count>>
Test cases failed / deviations<<FILL: count and references>>
As-installed firmware / software baseline<<FILL: versions recorded>>
Conclusion<<FILL: IQ PASS, progress to OQ ref ___ / IQ on hold pending deviation ___>>

10. Attachments

No.Attachment
1Purchase order and packing list
2Vendor installation / commissioning report
3Calibration certificates with traceability
4Software, firmware, and configuration screenshots
5Utilities and environment readings
6Manufacturer site preparation / requirements document

11. References

21 CFR 211.63 (equipment design, size, and location) and 211.68 (automatic, mechanical, and electronic equipment). 21 CFR 211.160(b) and 211.194 (laboratory controls and records). EU GMP Annex 15 (Qualification and Validation), 2015 revision. USP <1058> Analytical Instrument Qualification. USP <1058> instrument categories A, B, and C (depth of qualification by risk). ICH Q9, Quality Risk Management (for the risk-based category and test depth). Where the instrument holds GxP data: 21 CFR Part 11 and EU GMP Annex 11. ISO/IEC 17025 (for the calibration laboratory and traceability of certificates).

Confirm the current version and clause numbers of each reference before issue.

12. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

13. Approvals

RoleNameSignatureDate
Author / executor (Validation)<<FILL>>
Instrument owner<<FILL>>
Reviewer (QC / IT as applicable)<<FILL>>
Approver (QA)<<FILL>>

Filled specimen

The following shows the protocol executed for an example HPLC system, so you can see the level of detail an inspector expects. The company, instrument, versions, and numbers are illustrative; replace them with your own.

Instrument identification

FieldEntry
Instrument typeHPLC with diode array detector (DAD)
Manufacturer / modelExample Instruments, quaternary HPLC model XL-200 series
Serial numberDEAB-2026-00471
Asset / equipment IDLAB-HPLC-12
USP <1058> categoryC (computerized analytical instrument with data system)
Intended useRelease and stability assay of a small-molecule drug product
LocationQC Laboratory, Room 214, Bench B3

Selected test case results

No.CheckExpected resultActual resultPass / Fail
6.1.2All modules presentQuaternary pump, autosampler, column compartment, DAD, workstation per POAll five present, models and serials match PO and packing listPass
6.2.1Electrical supply230 V, 50 Hz, dedicated grounded outlet231 V, 50 Hz, dedicated grounded outlet verifiedPass
6.2.2Room temperature15 to 30 C per manufacturer spec21.4 C measuredPass
6.2.3Relative humidity20 to 80 percent RH, non-condensing44 percent RH measuredPass
6.3.1Instrument firmwarePer DQ: pump firmware A.10.18A.10.18 recorded, screenshot attachedPass
6.3.3Data system software versionValidated chromatography data system, version 7.3 SR2Version 7.3 SR2 confirmed, screenshot attachedPass
6.3.5Time synchronizationSynced to controlled NTP source, time zone correctSynced, time zone correct, drift under 1 secondPass
6.3.6Audit trail enabledOn, not disable-able by analystsEnabled and locked at admin level, verified by ITPass
6.4.2DAD wavelength calibration certificateCurrent certificate, traceable, in dateCertificate CAL-2026-0883 attached, in date, holmium oxide referencePass
6.4.4Calibration range covers useWorking range 210 to 360 nm coveredCertified across 200 to 400 nm, brackets working rangePass
6.5.2Vendor IQ recordVendor installation report reviewed and attachedVendor report FSE-0471 reviewed, one note on a loose waste line corrected and re-checkedPass

Deviation raised

Deviation no.Test case refDescriptionResolution
DEV-2026-02076.2.5Solvent waste line delivered the wrong length, did not reach the waste container safelyCorrect line sourced and fitted by FSE, re-checked, photo attached; no impact on installed state

Summary

FieldEntry
Test cases executed27
Test cases passed27 (after deviation resolution)
Deviations1 (DEV-2026-0207, resolved, no impact)
As-installed baselinePump firmware A.10.18, data system 7.3 SR2
ConclusionIQ PASS, progress to OQ protocol OQ-LAB-031

The count of 27 reflects the 26 numbered checks in section 6 with the per-module firmware check (6.3.2) recorded as two module lines (pump and detector firmware), so it executes as two results.

In this example the executor recorded measured values rather than ticking “OK”, captured the exact firmware and software versions as the change-control baseline, confirmed the DAD calibration certificate was traceable and bracketed the working range, raised the one real shortfall (a waste line that did not reach the container) as a deviation rather than fixing it silently, and only declared IQ PASS after that deviation was resolved with attached evidence. That sequence, verify against spec to record actual values to deviation to resolution to documented conclusion, is exactly what a reviewer is expected to demonstrate.

Common inspection findings this protocol prevents

  • IQ executed with “OK” or “Pass” ticked but no recorded actual values, so there is no evidence anyone checked anything.
  • Firmware and software versions not captured at installation, so a later version change cannot be detected and OQ has no baseline.
  • A missing or damaged module quietly substituted with no deviation and no model/serial record.
  • Calibration certificates accepted without checking traceability, in-date status, or that the calibrated range covers the working range.
  • Vendor installation records filed unread and treated as the qualification, with no independent review or acceptance criteria.
  • Utilities and environment assumed adequate rather than measured against the manufacturer site preparation requirements.
  • Audit trail, time synchronization, and access controls not verified at installation for a data-generating instrument, surfacing only later as data integrity gaps.
  • IQ approved with an open deviation, so the instrument progressed to OQ before installation was actually confirmed.

How to adapt this protocol

  1. Set your document number, owner, room, linked DQ/OQ/PQ references, and effective date in the header.
  2. State the USP <1058> instrument category in section 5.1 and scale the test cases to it: a Group B balance does not need the full data-system checks in 6.3.6 and 6.3.7, while a Group C chromatograph does.
  3. Replace the example modules in section 5.2 and the test cases in section 6 with your actual instrument modules, manufacturer site preparation values, and the versions specified in your DQ.
  4. Point the cross-references in sections 2 and 8 to your real CSV, deviation, change control, and calibration procedures.
  5. Where the vendor performs IQ, keep the test-case structure and use it to review and accept the vendor records against your own acceptance criteria, rather than substituting the vendor report for this protocol.
  6. Confirm every regulation in section 11 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.