Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Template Plug-and-play starting point Sterility & Microbiology

Worksheet: MALL Derivation and CCIT Method Sensitivity Requirement

A structured calculation worksheet that walks from a product's critical quality attribute (sterility, headspace oxygen, moisture) to a defined maximum allowable leakage limit (MALL) and the resulting CCIT method sensitivity requirement, with a worked numeric example.

Document type: Template

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use worksheet for deriving a maximum allowable leakage limit (MALL) and the CCIT method sensitivity requirement it implies. Replace every <<FILL: ...>> placeholder with your own numbers and references, work through the steps in order, and attach the completed worksheet to your container closure system qualification file or your CCIT method validation protocol. A worked filled specimen follows the template. Verify each cited reference against the current source before you rely on it. This worksheet organizes the derivation; it does not itself replace a validated shelf-life ingress model or a microbial correlation study, both of which are cited as external inputs.

Document control header

FieldEntry
Document titleMALL Derivation and Method Sensitivity Requirement for <<FILL: product / package>>
Document number<<FILL: WS-ID, e.g. CCIT-WS-004>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Feeds<<FILL: CCIT method validation protocol ID; container closure system qualification ID>>
Prepared by<<FILL: role, e.g. Container Closure SME>>

1. Purpose

This worksheet derives the maximum allowable leakage limit (MALL) for <<FILL: product / package>> from its critical quality attributes, and converts the MALL into the detection limit a CCIT method must demonstrably meet. The output feeds method selection and method validation; it is the documented answer to “why this method, and why this acceptance threshold.”

2. Scope

This worksheet covers derivation of the MALL for one product presented in one primary container closure system. It does not derive a shelf-life ingress model or a microbial ingress correlation from first principles; those come from external, validated sources referenced in sections 5 and 6. It does not select the method itself, which is documented in <<FILL: CCIT method selection risk assessment ID>>, nor does it constitute the method validation, which is <<FILL: validation protocol ID>>.

3. Responsibilities

RoleResponsibility
Container closure / packaging SMEOwns this worksheet, identifies the critical quality attributes, and drives the derivation to a governing MALL.
MicrobiologyProvides or confirms the microbial ingress correlation basis for the sterility-driven MALL.
Formulation / stability scienceProvides the shelf-life ingress model or study data for gas- or moisture-driven attributes.
Validation / engineeringCarries the resulting sensitivity requirement into method selection and method validation.
Quality AssuranceReviews and approves the completed worksheet and the governing MALL.

4. Definitions and conventions

  • MALL (maximum allowable leakage limit): the largest leak, expressed as an orifice size (microns) or a leak rate (commonly std cc/s or mbar L/s), that the package can carry without compromising a named critical quality attribute over the labeled shelf life.
  • Governing MALL: where more than one attribute produces a MALL, the tightest (smallest leak size, lowest leak rate) of the attribute-specific limits, unless a documented dual-limit strategy is used (see section 7).
  • Detection margin factor (M): the multiple by which a method’s demonstrated detection limit must sit below the MALL before the method is considered fit for purpose. State your program’s policy value; do not leave it undefined.
  • Helium-equivalent leak rate: the leak rate in standard cc/s (or mbar L/s) that a physical orifice size corresponds to, established through a helium tracer correlation study. Record the conversion basis used, do not assume a universal constant across container geometries.

Unit discipline: keep leak-size units in microns and leak-rate units in std cc/s (or your program’s fixed unit) throughout. State the conversion basis explicitly wherever a size is translated to a rate.

5. Step A: Identify the critical quality attributes integrity protects

List every attribute this package’s integrity protects. Not every product has all three.

AttributeApplicable (Y/N)Why it matters for this product
Sterility<<FILL>><<FILL>>
Headspace oxygen / oxidative stability<<FILL>><<FILL>>
Moisture ingress (lyophilized product, hygroscopic actives)<<FILL>><<FILL>>
Headspace vacuum (lyophilized product stoppered under vacuum)<<FILL>><<FILL>>
Other: <<FILL>><<FILL>><<FILL>>

6. Step B: Sterility-driven MALL

Complete this step whenever sterility is an applicable attribute (nearly always, for a sterile product).

InputValueSource
Microbial ingress onset leak size (orifice diameter range at which liquid-borne microbial ingress becomes a real risk)<<FILL: e.g. 0.2 to 0.3 micron, from published correlation work or your own correlation study>><<FILL: literature reference or internal correlation study ID>>
Safety margin applied to the onset range<<FILL: e.g. lower bound of the onset range, or a stated fraction of it>><<FILL: rationale>>
MALL_sterility (micron)<<FILL: computed value>>Onset leak size, margin applied
Helium-equivalent leak rate for MALL_sterility<<FILL: std cc/s>><<FILL: helium correlation study ID that established the conversion>>

7. Step C: Attribute-driven MALL (oxygen, moisture, vacuum)

Complete one row of this table per applicable non-sterility attribute. The ingress model itself (how a leak size converts into an oxygen, moisture, or vacuum change over shelf life) is an external, validated input; this worksheet records its output, it does not derive the model.

InputAttribute: <<FILL>>Attribute: <<FILL>>
Shelf life (months)<<FILL>><<FILL>>
Headspace volume<<FILL: mL>><<FILL: mL>>
Attribute threshold not to exceed by end of shelf life<<FILL: e.g. max % O2, max % moisture, min residual vacuum>><<FILL>>
Baseline (initial) attribute value<<FILL>><<FILL>>
Ingress model / study reference used to convert allowable ingress into a leak size or leak rate<<FILL: validated shelf-life ingress model ID, or accelerated ingress study ID>><<FILL>>
MALL_attribute (micron or leak rate, from the model output)<<FILL>><<FILL>>

A smaller headspace volume produces a tighter MALL for the same absolute ingress tolerance, because the same quantity of gas or moisture represents a larger fractional change in a small headspace. A prefilled syringe or cartridge, with a much smaller headspace than a vial, will typically compute to a tighter oxygen- or moisture-driven MALL than a vial of the same formulation. Confirm the headspace volume entered above matches the actual primary container, not a generic assumption carried over from a different format.

8. Step D: Select the governing MALL

AttributeMALL (micron / leak rate)Governing?
Sterility<<FILL from section 6>><<FILL: Y/N>>
<<FILL: attribute>><<FILL from section 7>><<FILL: Y/N>>
<<FILL: attribute>><<FILL from section 7>><<FILL: Y/N>>

Two acceptable outcomes:

  1. Single governing MALL. The tightest limit above governs, and the CCIT method must be validated to detect below that single number with margin.
  2. Dual-limit strategy. Where the sterility-driven MALL is sub-micron and far tighter than the routine method’s practical detection range, document that the sub-micron limit is anchored through a helium leak-rate correlation performed during method development (not through the routine method’s pass/fail curve), while the routine deterministic method is validated to detect reliably below the looser, attribute-driven MALL. State explicitly which strategy applies here and why: <<FILL>>.

9. Step E: Convert the governing MALL into a method sensitivity requirement

ItemValue
Governing MALL (from section 8)<<FILL>>
Detection margin factor (M), per program policy<<FILL: e.g. 2x to 5x>>
Required method detection limit = governing MALL / M<<FILL: computed>>
Statement to carry forward into method selectionThe candidate CCIT method must demonstrate, in validation, reliable detection at or below <<FILL: computed value>>, with the detection curve confirming margin below the governing MALL of <<FILL>>.

10. Step F: Candidate method screen

Use this table to shortlist candidate methods before handing off to a full method selection risk assessment (<<FILL: risk assessment ID>>).

MethodMeets sensitivity requirement (Y/N/needs dev.)Fits package format (Y/N)Fits product conductivity/optical properties (Y/N)Carry forward?
<<FILL: e.g. Vacuum decay>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. HVLD>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. Headspace gas analysis>><<FILL>><<FILL>><<FILL>><<FILL>>

11. Conclusion

State the governing MALL, the strategy used (single limit or dual limit), and the resulting method sensitivity requirement in one paragraph, then route this worksheet for approval before it feeds method selection.

<<FILL: conclusion statement>>

12. References

USP General Chapter <1207> Package Integrity Evaluation, Sterile Products (and <1207.1>, <1207.2>, <1207.3>). EU GMP Annex 1, Manufacture of Sterile Medicinal Products (2022). FDA Guidance, Container and Closure System Integrity Testing in Lieu of Sterility Testing as a Component of the Stability Protocol for Sterile Products (2008).

Confirm the current version and clause numbers of each reference before issue. USP is copyrighted; cite by number and title and describe it in your own words rather than pasting its text.

13. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

14. Approvals

RoleNameSignatureDate
Author<<FILL>>
Microbiology<<FILL>>
Quality Assurance<<FILL>>

Filled specimen

The following shows the worksheet completed for an example 10 mL liquid-filled vial of a conductive, oxygen-sensitive sterile biologic with a nitrogen overlay, the same product used as the worked example in the parent article, so you can see how the numbers connect back to the narrative discussion. The numbers are illustrative; replace them with your own.

Step A, applicable attributes: sterility (Y), headspace oxygen (Y), moisture (N, liquid-filled, not lyophilized), vacuum (N).

Step B, sterility-driven MALL: microbial ingress onset leak size 0.2 to 0.3 micron (published correlation work); margin applied at the lower bound; MALL_sterility approximately 0.2 micron, equivalent to a helium leak rate near 6x10^-6 std cc/s per the method-development helium correlation study.

Step C, oxygen-driven MALL: shelf life 24 months; headspace volume approximately 2 mL; attribute threshold set from the shelf-life oxidative stability model; ingress model reference <<the product's internal shelf-life oxygen model, illustrative>>; MALL_oxygen computed near a 5 micron equivalent leak.

Step D, governing MALL: dual-limit strategy used. Sterility MALL (approximately 0.2 micron) is anchored via helium correlation during method development; the routine method is validated against the oxygen-driven MALL (approximately 5 micron), which is within practical HVLD detection range.

Step E, sensitivity requirement: governing MALL for the routine method is 5 microns; margin factor M = 1 (validation curve shows detection at and above 5 microns is reliable, providing margin against the smaller 2 micron result); required statement: HVLD must demonstrate reliable detection at 5 microns and above, with the 2 micron result characterizing the lower edge of capability, consistent with the validation protocol’s detection curve.

Step F, candidate screen: HVLD carried forward (meets sensitivity requirement, fits liquid-filled vial, fits conductive product); vacuum decay listed as a fallback if conductivity were later found insufficient; headspace oxygen analysis added as a complementary stability-time-point method rather than the primary release method.

Common inspection findings this worksheet prevents

  • A MALL asserted with no traceable derivation from a critical quality attribute.
  • A single MALL number used across formats (vial and syringe) without recomputing for a different headspace volume.
  • A sub-micron sterility limit implicitly expected of a routine method that was only ever validated to a looser, attribute-driven number, with no documented dual-limit rationale.
  • No stated detection margin factor, so “detection at the MALL” and “detection below the MALL with margin” are used interchangeably without evidence.

How to adapt this worksheet

  1. Set your document number, product, and package in the header.
  2. Complete section 5 for your actual attribute set before doing any arithmetic.
  3. Route the sterility-driven derivation (section 6) through microbiology and the attribute-driven derivation (section 7) through formulation or stability science; do not derive either from memory.
  4. Decide and record your program’s detection margin factor (section 9) once, and apply it consistently across products rather than choosing it after seeing validation data.
  5. Hand the completed worksheet to your method selection risk assessment and method validation protocol as a formal input.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.