Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
SOP Plug-and-play starting point Manufacturing Automation

SOP: Recipe Management and Change Control (ISA-88 / MES)

A plug-and-play SOP for master recipe lifecycle and change control in a validated MES: authoring, risk-proportionate testing, versioning, segregation of duties, and reconstruction, with a filled specimen and the GMP basis it satisfies.

Document type: SOP

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use SOP for managing master recipes and their changes in a validated Manufacturing Execution System. Replace every <<FILL: ...>> placeholder and route it through document control. A filled specimen follows. Verify each cited regulation against the current source. This is general guidance to adapt, not legal or regulatory advice.

Document control header

FieldEntry
Document titleRecipe Management and Change Control
Document number<<FILL: e.g. SOP-MFG-055>>
Version<<FILL: e.g. 1.0>>
Effective date<<FILL: date>>
Supersedes<<FILL: prior version or "New">>
Document owner<<FILL: role, e.g. Head of Automation>>
Applies to<<FILL: systems / lines in scope>>

1. Purpose

This procedure governs the lifecycle of master recipes in <<FILL: MES/DCS name>>, from authoring through approval, change, and retirement. The master recipe is the electronic master production and control record required by 21 CFR 211.186; the executed control recipe plus its captured data is the batch production record required by 211.188. The objective is that every recipe parameter is traceable, every change is controlled, and any historical batch can be reconstructed to the exact recipe version that produced it.

2. Scope

Applies to all GMP master recipes built on the ISA-88 procedural model in the systems listed in the header. It covers master and control recipes; it does not define equipment-phase logic, which is controlled under <<FILL: automation qualification SOP-ID>>.

3. Responsibilities

RoleResponsibility
Manufacturing (recipe owner)Owns master recipe content; raises and justifies changes; owns operator instructions and prompts.
Automation / control engineerAuthors procedural structure in the MES; configures exception handling; supports testing. Does not approve own work.
Validation / CSVDefines test strategy; ensures coverage of boundary and failure paths.
Quality AssuranceApproves master recipes and changes; enforces change control; releases recipes to effective state.
QCOwns IPC/sampling specs the recipe enforces.
MES administratorManages recipe states, versioning, access, and audit-trail integrity; does not author or approve recipe content (segregation of duties).

The person who edits recipe content must not be the person who approves it, and the administrator who manages states must not author parameters.

4. Definitions

  • Master recipe: the approved, equipment-class-bound template under change control (the master production record).
  • Control recipe: one execution generated by the batch engine, bound to specific units; its completed form is the batch record.
  • Critical process parameter (CPP): a parameter whose variability affects a critical quality attribute and which therefore must be controlled.
  • Equipment phase: the controller-level logic the recipe references by name and passes parameters to.

5. Procedure: building a master recipe

  1. Confirm the process definition (site recipe / tech transfer package) is approved and locked.
  2. Confirm the equipment phases the recipe needs exist and are qualified.
  3. Author the procedural structure (unit procedures, operations, phases), reusing qualified library phases.
  4. Enter the formula and parameters; source every limit to a controlled document and record the link.
  5. Add IPC, sampling, prompts, forced data entries, and electronic-signature points; decide which steps need second-person verification.
  6. Configure exception handling for every failure mode: out-of-range entry, phase failure, hold, abort, power loss and recovery.
  7. Simulate and dry-run against simulated I/O.
  8. Test under an approved protocol that challenges normal flow, boundaries, and failure paths.
  9. Review and approve (manufacturing, automation, QA) with electronic signatures.
  10. Release with an effective date; move the prior version to superseded, retained not deleted.

6. Procedure: changing a master recipe

  1. Raise the change with what is changing, why, and the requested scope; reference the trigger (CAPA, tech transfer, improvement).
  2. Assess impact and criticality. Determine whether the parameter is a CPP, touches an IPC acceptance range, or affects a registered/established condition.
  3. Determine regulatory impact using ICH Q12 tools (established conditions, post-approval change management); decide reporting category and whether a variation is needed.
  4. Author the new version in a draft state so the current effective recipe keeps running production.
  5. Test proportionate to risk: a CPP or IPC-range change gets challenge testing and a process-validation impact assessment (possible PPQ); a functional non-CPP change gets functional and failure-path testing; a cosmetic change gets documented verification. Do not over-test the trivial or under-test the critical.
  6. Review and approve with the same approvers and electronic signatures.
  7. Release with an effective date and supersede the prior version, retained for reconstruction.
  8. Verify the first batch on the new version with heightened review, especially for critical changes.

7. Versioning and reconstruction

  • Every batch record identifies the exact recipe version that produced it.
  • Superseded versions are retained, never deleted, for the records-retention period.
  • The recipe object audit trail records who changed what, when, old and new value, and why; it is reviewed in periodic review and at change verification, not just generated.

8. Acceptance criteria

  • Every parameter and limit traces to a controlled source document.
  • The recipe reuses qualified library phases; bespoke recipe-layer logic is the justified exception.
  • Exception handling is defined and tested for every failure mode.
  • The recipe is in an approved, version-controlled state with effective date and superseded predecessor.
  • A control recipe generated from it produces a batch record matching the master one for one.
  • Any historical lot can be tied to its exact recipe version.

9. Records generated

  • Recipe change record (see the companion form).
  • Test/validation evidence; first-batch verification record.
  • Recipe audit-trail review record.

10. References

21 CFR 211.186 (master production and control records); 211.188 (batch production records); 211.100 (procedures, review of deviations). 21 CFR Part 11; EU GMP Annex 11 (computerised systems). ANSI/ISA-88 (IEC 61512) batch control models and terminology. ICH Q12 (lifecycle management, established conditions); ICH Q9 (quality risk management).

Confirm the current version and clause numbers of each reference before issue.

11. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

12. Approvals

RoleNameSignatureDate
Author<<FILL>>
Reviewer (Automation)<<FILL>>
Approver (QA)<<FILL>>

Filled specimen

The following shows a change being routed under this SOP. Details are illustrative; replace with your own.

FieldEntry
ChangeWiden harvest VCD IPC range from 18-22 to 16-24 x10^6/mL
CriticalityVCD is a critical in-process attribute; acceptance-range change
Testing pathCPP/IPC-range branch: challenge test of IPC logic plus statistical justification of the new range; no PPQ re-run needed per impact assessment
RegulatoryAssessed against established conditions (ICH Q12); within reported flexibility, annual-report category, documented
Versions4.2 effective to 4.3 draft, approved
First batchLot 2026-117 reviewed with heightened scrutiny, no issues

In this example a “just a range tweak” was correctly recognised as a critical-attribute change, so it took the challenge-testing branch with statistical justification rather than the cosmetic path, and the prior version was retained for reconstruction.

Common inspection findings this SOP prevents

  • Recipe edits made directly in the system with no change record.
  • Parameters with no traceable controlled source.
  • Inability to reconstruct which recipe version made a given lot.
  • Deleted superseded versions.
  • No segregation of duties between authoring and approval, or shared logins.
  • Undefined exception handling.

How to adapt this SOP

  1. Set your document number, owner, and effective date.
  2. Name your actual MES/DCS and automation qualification SOP.
  3. Align the testing branches in section 6.5 with your validation and ICH Q12 framework.
  4. Confirm every regulation in section 10 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.