Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Protocol Plug-and-play starting point Manufacturing Automation

Protocol: Master Recipe Qualification Test Script (ISA-88 / MES)

A plug-and-play OQ/PQ-style test script for qualifying a new or changed ISA-88 master recipe in an MES: approval page, test cases for normal flow, boundary conditions, and failure paths, deviation handling, and summary, with a filled specimen.

Document type: Protocol

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use qualification protocol. Replace every <<FILL: ...>> placeholder, tailor the test cases to your recipe’s actual phases and exception paths, and route through your normal validation approval process. A filled specimen (partial) follows.

Approval page

RoleNameSignatureDate
Author<<FILL>>
Manufacturing reviewer<<FILL>>
Automation/CSV reviewer<<FILL>>
QA approver<<FILL>>

1. Objective

To demonstrate that master recipe <<FILL: recipe name and version>> correctly sequences its procedural elements, enforces its parameters and limits, handles exceptions safely, and produces a batch record that faithfully reflects the executed recipe, satisfying 21 CFR 211.186/211.188, EU GMP Annex 11, and 21 CFR Part 11.

2. Scope

FieldEntry
Recipe under test<<FILL: name, version>>
Equipment class / unit(s) used for testing<<FILL>>
Test environment<<FILL: qualified test/simulation environment, system name>>
Prerequisite qualifications<<FILL: equipment phase library qualification status, MES platform qualification reference>>

3. System description

<<FILL: brief description of the recipe's product, process, unit procedures, and operations in scope, referencing the process flow diagram or tech transfer package>>

4. Roles

RoleResponsibility in this protocol
Test executorRuns each test case, records actual results
WitnessIndependently confirms critical test steps, particularly exception-path tests
Automation/CSV reviewerReviews test evidence for technical accuracy
QAReviews and approves the completed protocol

5. Acceptance criteria

  • Every test case in section 7 executes with the stated expected result, or a deviation is raised and resolved per section 6.
  • The recipe enforces sequencing (no step advances before its predecessor completes and is signed where required).
  • Every exception path tested (phase failure, hold, abort, power recovery) leaves the equipment in a safe, defined state and produces a complete, accurate record of what happened.
  • The completed batch record generated by the control recipe matches the master recipe one for one, with the correct version identified.

6. Deviation handling

Any test case that does not produce its expected result is logged as a protocol deviation: description, immediate containment, root cause, corrective action, and re-test result. Deviations are reviewed and dispositioned by QA before the protocol can reach a final “Pass” conclusion. A deviation does not automatically fail the protocol if root cause is understood, corrected, and successfully re-tested.

7. Test cases

TC #Step / condition testedExpected resultActual resultPass/FailTesterDate
TC-01Normal flow: execute the full procedure end to end with in-range parametersRecipe completes, all phases sequence correctly, batch record generated matches master recipe structure<<FILL>><<FILL>><<FILL>><<FILL>>
TC-02Sequencing enforcement: attempt to start a later phase before an earlier required phase/signature completesSystem blocks the action<<FILL>><<FILL>><<FILL>><<FILL>>
TC-03Parameter boundary: enter a value at the upper acceptable limit of a critical parameterAccepted, recorded, no alarm<<FILL>><<FILL>><<FILL>><<FILL>>
TC-04Parameter out-of-range: enter a value outside the acceptable limitSystem alarms/blocks per design; forces documented operator response<<FILL>><<FILL>><<FILL>><<FILL>>
TC-05Phase failure: force a phase-level failure (e.g. simulated valve fault)Phase goes to a defined failure/held state, equipment left safe, alarm raised, no silent advance<<FILL>><<FILL>><<FILL>><<FILL>>
TC-06Operator hold/restart: press Hold mid-phase, then RestartPhase transitions HOLDING to HELD to RESTARTING correctly, with timestamps and operator ID recorded<<FILL>><<FILL>><<FILL>><<FILL>>
TC-07Abort: abort a phase mid-executionEquipment reaches a safe state per design (e.g. valves close), abort reason captured<<FILL>><<FILL>><<FILL>><<FILL>>
TC-08Power loss and recovery mid-phaseOn recovery, system requires operator confirmation of actual equipment state before resuming; does not silently resume against a stale value<<FILL>><<FILL>><<FILL>><<FILL>>
TC-09Electronic signature: complete a required signing stepSignature captures full name, date/time, meaning; re-authentication enforced per design<<FILL>><<FILL>><<FILL>><<FILL>>
TC-10Audit trail: attempt to alter a recorded value as a non-privileged userSystem prevents the alteration; any privileged correction is captured with old/new value, user, reason<<FILL>><<FILL>><<FILL>><<FILL>>
TC-11Batch record reconciliation: compare the completed batch record against the master recipe structureOne-for-one match of unit procedures, operations, phases, and recorded data fields<<FILL>><<FILL>><<FILL>><<FILL>>
TC-12Version identification: confirm the batch record captures the exact recipe version executedCorrect version number and status recorded on the batch record<<FILL>><<FILL>><<FILL>><<FILL>>

8. Attachments

<<FILL: raw data exports, screenshots, signed printouts, deviation reports, referenced by TC number>>

9. Summary and conclusion

FieldEntry
Total test cases<<FILL>>
Passed<<FILL>>
Failed / deviations raised and resolved<<FILL>>
Overall conclusion<<FILL: recipe qualified for production use / not qualified, pending remediation>>
QA disposition<<FILL: name, date>>

Filled specimen (excerpt)

Recipe under test: DS Production, Bioreactor Production unit procedure, v4.3. Test environment: qualified MES simulation environment, MES-SIM-02.

TC #Step / condition testedExpected resultActual resultPass/FailTesterDate
TC-05Phase failure: simulated flow-meter fault during media chargePhase fails, holds unit, raises alarm, does not advancePhase transitioned to FAILED, alarm raised within 2 seconds, unit remained closed, no advance to next operationPassK. Iwu14 Aug 2026
TC-08Power loss/recovery mid-chargeSystem requires operator confirmation of actual vessel volume before resumingOn restart, system displayed last recorded volume (1120 L) and required operator to enter confirmed actual level (1125 L, verified by level gauge) before Resume was enabledPassK. Iwu14 Aug 2026
TC-12Version identification on batch recordCorrect version recordedBatch record header showed “Recipe v4.3, effective 10 Aug 2026,” matching the version under testPassK. Iwu14 Aug 2026

Summary. 12 of 12 test cases passed on first execution; zero deviations raised. Conclusion: recipe v4.3 qualified for production use. QA disposition: approved, R. Nakamura, 20 August 2026.

Common inspection findings this protocol prevents

  • Recipe testing that only exercises the happy path, leaving failure and boundary behavior unvalidated until a real deviation exposes it in production.
  • No documented evidence that power-recovery behavior was challenged, the exact scenario where a stale recorded state and a different physical reality produce a bad batch.
  • A “qualified” recipe with no test case confirming the batch record actually matches the master recipe structure.

How to adapt this protocol

  1. Add test cases for every phase and exception path specific to your recipe; the twelve cases above are a minimum floor, not a ceiling, for a recipe of meaningful complexity.
  2. If the recipe includes operator prompts or manual data entry, add a test case confirming forced entry and range-checking behave as designed.
  3. Scale rigor to risk: a recipe change to a non-critical prompt may need a reduced version of this script, while a new product’s first master recipe should run the full set.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.