Ad Code

Cleaning Validation Protocol: Step-by-Step Guide

WebOfPharma · GMP validation

Cleaning Validation Protocol: Step-by-Step Guide

A practical, inspection-ready framework for writing, approving, executing and reporting a pharmaceutical cleaning validation protocol.

PIC/S aligned MACO & HBEL Swab & rinse sampling Protocol checklist
Cleaning Validation Protocol: Step-by-Step Guide
Quick answer: A cleaning validation protocol is an approved plan that defines how a site will prove an approved cleaning procedure reproducibly removes previous-product residues, cleaning agents and relevant microorganisms from equipment. It sets the scope, responsibilities, worst-case rationale, hold times, cleaning parameters, sampling locations, recovery studies, analytical methods, acceptance limits, number of runs, deviation rules and final-report requirements before the study begins.

A well-written protocol turns cleaning validation from a collection of swabs and laboratory results into a controlled scientific study. It connects product toxicology, equipment design, cleaning chemistry, operator technique, analytical sensitivity and routine monitoring. This guide explains each part of a cleaning validation protocol in plain language, with practical tables, a step-by-step workflow and an inspection-ready checklist.

The approach is intended for shared equipment used in pharmaceutical manufacturing. Adapt the level of detail to the dosage form, equipment train, cleaning technology, product risk and applicable national requirements. The related Cleaning Validation in Pharmaceuticals guide provides broader lifecycle context.

Regulatory note: PIC/S PI 006-4 was published in 2026 and announced an entry-into-force date of 1 October 2026. Check the current PIC/S publication, the version transposed by your competent authority and your approved site procedures before issuing a protocol.

What is a cleaning validation protocol?

A cleaning validation protocol is a controlled document that describes the planned design and execution of a cleaning validation study. It defines what will be cleaned, why it is being challenged, how the cleaning process will be performed, what evidence will be collected, which limits will apply and how results will be evaluated.

The protocol is approved before execution by the appropriate functions, normally Production, Quality, Engineering, Validation and, where needed, Quality Control, Toxicology, Microbiology and Research and Development. It should be detailed enough that a trained person can execute the study without guessing, while avoiding duplicate text that belongs in an approved SOP.

Why the protocol matters in GMP

Cleaning validation protects patients from unintended exposure and protects products from cross-contamination. The protocol is the bridge between the site’s risk assessment and its final validation conclusion. A weak protocol usually creates weak evidence: samples may not represent hard-to-clean locations, limits may be copied from old templates, recovery may not be demonstrated, and deviations may be impossible to interpret.

Within cGMP, the protocol should demonstrate that:

  • the cleaning process is designed and controlled for its intended equipment;
  • residue and microbial risks have been assessed scientifically;
  • the sampling and analytical methods can detect residues below the approved limits;
  • the study conditions represent routine and justified worst-case operation;
  • every failure, deviation and unexpected result is visible in the quality system;
  • the validated state will be maintained after the initial study.

Cleaning validation protocol workflow at a glance

01

Define

Set objective, scope, product family, equipment and responsibilities.

02

Assess

Evaluate risk, toxicology, worst cases, surfaces and process variables.

03

Design

Set limits, parameters, hold times, sampling and analytical strategy.

04

Execute

Run the approved cleaning study and record actual conditions.

05

Conclude

Investigate results, approve the report and define ongoing verification.

Step 1: Define the protocol objective and scope

Start with a precise objective. Avoid statements such as “to validate cleaning.” State the equipment, product family, cleaning procedure and evidence needed. For example:

Example objective statement

“This protocol will demonstrate that Cleaning Procedure CP-014, when applied to the blender, transfer line and tablet press identified in this document, reproducibly reduces residues from Product A and the approved detergent to the predefined chemical, microbial and visual acceptance criteria under the selected dirty-hold, campaign and clean-hold conditions.”

Define whether the protocol covers:

  • one product, a product family or a documented worst-case/bracketing group;
  • one equipment item, a complete process train or a like-for-like equipment family;
  • manual cleaning, clean-in-place (CIP), clean-out-of-place (COP) or a combination;
  • chemical residues, cleaning agents, microbial contamination, endotoxin or all applicable hazards;
  • initial validation, validation after change, revalidation or investigation support.

State exclusions explicitly. If a non-product-contact component is excluded, explain why migration is not a credible risk or how it is controlled. A scope that cannot be understood from the protocol will be difficult to defend during an inspection.

Step 2: Assign responsibilities and approvals

Cleaning validation is multidisciplinary. The protocol should identify who prepares, executes, reviews and approves each stage. A simple responsibility matrix prevents the common problem of “everyone thought another department owned it.”

FunctionTypical responsibilitiesEvidence in the protocol or report
ProductionExecute the approved cleaning procedure, provide equipment and batch history, record actual parameters.Executed cleaning record, operator and supervisor signatures, equipment status.
Quality/ValidationOwn protocol control, risk assessment, deviation decisions, data review and final conclusion.Approval page, review comments, deviation assessment, report approval.
EngineeringConfirm equipment design, utilities, instruments, drains, spray coverage and maintenance status.Drawings, equipment qualification, calibration and maintenance records.
Quality ControlApprove methods, perform testing, review calculations and report raw data.Chromatograms, worksheets, calculations, method and recovery records.
MicrobiologyDefine microbial sampling, incubation, recovery and organism-specific controls where needed.Microbial method records, recovery evidence and results.
Toxicology/QAReview HBEL/PDE rationale and carryover limits for high-risk products.Approved toxicology assessment, MACO calculation and risk rationale.

External laboratories, equipment suppliers and consultants may support the work, but the manufacturer retains responsibility for study control, data quality and regulatory compliance.

Step 3: Describe the equipment and process train

Identify every item included in the cleaning study using unique equipment IDs. Include the product-contact path and any non-contact parts from which residue could migrate. Attach or reference current drawings and equipment descriptions rather than relying on a generic equipment name.

Equipment information to capture

  • equipment ID, room and manufacturing area;
  • manufacturer, model, capacity and material of construction;
  • surface finish, gaskets, seals, hoses, filters and screens;
  • pipes, valves, dead legs, nozzles, spray balls, drains and difficult-to-access areas;
  • parts that require disassembly and parts cleaned in place;
  • utility inputs such as water quality, pressure, temperature, compressed air and steam;
  • current DQ, IQ, OQ, PQ, calibration, maintenance and change-control status.

For new equipment, link the protocol to the URS, DQ, IQ, OQ and PQ package. Qualification demonstrates fitness for use; the cleaning protocol then demonstrates that the cleaning method performs on that qualified equipment.

Step 4: Perform the risk assessment and select worst cases

The risk assessment is the scientific engine of the protocol. It determines which products, equipment locations, cleaning parameters, sampling methods, number of runs and routine verification frequencies deserve the greatest attention.

Product-risk factors

  • HBEL or PDE, potency, toxicity, sensitising potential and therapeutic dose;
  • solubility in water and the selected cleaning agent;
  • stickiness, viscosity, particle size, colour and tendency to form films;
  • degradation, reaction products or residues that become harder to remove with time;
  • batch size, concentration and maximum product-contact time;
  • historical cleaning alerts, failures, complaints or investigation findings.

Equipment-risk factors

  • complex geometry, dead legs, narrow tubing, gaskets and shadowed surfaces;
  • material compatibility and surface finish;
  • drainability, spray coverage, flow velocity and accessibility;
  • manual disassembly and operator-dependent scrubbing;
  • shared equipment, process-train accumulation and product sequencing.

A single worst-case product may not represent every hazard. A sticky product may challenge cleanability while a low-HBEL product challenges patient risk. Document why the selected product or products represent the relevant extremes. If bracketing is used, identify the products, equipment, strengths, batch sizes and conditions represented by the bracket.

Step 5: Establish acceptance criteria before execution

Acceptance criteria must be approved before the first validation run. They should be practical, achievable, verifiable and linked to the risk assessment. Never wait for results and then adjust a limit to make the study pass.

Criteria normally considered

  • previous-product or active-substance residue;
  • degradation products or other process residues of concern;
  • detergent or cleaning-agent residue;
  • microbial count, objectionable organisms and endotoxin where applicable;
  • visual cleanliness after drying;
  • cumulative carryover through the complete process train;
  • unit-dose impact for compression, filling or primary packaging operations.

Use the toxicological assessment to establish an HBEL/PDE-based carryover strategy. A PDE is a health-based exposure value, not automatically the final equipment surface limit. The calculation must consider the receiving product, minimum batch size, maximum daily dose, shared surface area, process-train effect, sampling plan and unit conversions.

Illustrative MACO calculation logic

MACO (mg) = PDE of previous product × minimum batch size of next product ÷ maximum daily dose of next product

Use the exact equation, units, safety factors and surface-area conversion approved in your site procedure. Toxicology and Quality must approve the final calculation.

Do not rely on a copied “10 ppm” or fixed-dose rule by default. Where compound-specific toxicology is available, the limit should be scientifically justified. The final limit must also be measurable with the selected sampling and analytical method.

Step 6: Define the cleaning procedure and challenge conditions

The protocol should reference the current approved cleaning SOP and identify the parameters that will be challenged. Do not reproduce an uncontrolled or obsolete procedure inside the protocol. If the study requires a temporary or enhanced condition, describe it, justify it and control it through change control.

Manual-cleaning parameters

  • equipment preparation and disassembly sequence;
  • detergent identity, concentration, volume, temperature and contact time;
  • brushes, wipes, spray devices and mechanical action;
  • rinse quality, pressure, temperature, duration and endpoint;
  • drying, reassembly, storage and protection from recontamination;
  • operator training, qualification and visual-inspection conditions.

Automated or CIP parameters

  • recipe version and cleaning sequence;
  • temperature, flow, pressure, spray rate, volume and valve position;
  • number and duration of wash, rinse and sanitisation steps;
  • detergent concentration and conductivity or other endpoint;
  • alarms, interlocks, sensor calibration and response actions;
  • electronic recipe access, audit trail, backup and protection from alteration.

Automated recipes and electronic cleaning data should be reviewed against ALCOA+ data-integrity principles. Where electronic records or signatures are in scope, map the controls to applicable 21 CFR and local requirements. The protocol should specify which electronic records are part of the validation package and how they will be retained.

Step 7: Define dirty hold, clean hold and campaign length

Cleaning performance changes with time. The protocol should state the interval between the end of manufacturing and the start of cleaning (dirty hold) and the interval between completion of cleaning and equipment use (clean hold). Choose conditions that represent the maximum approved operating range or a justified worst case.

Campaign length should normally be defined by both elapsed time and number of batches. Assess product build-up, microbial control, processability and the effect of extended production on cleanability. For wet equipment, prevent stagnant water and define storage orientation, drainage and drying requirements.

ConditionProtocol questionEvidence expected
Dirty holdHow long can residue remain before cleaning begins?Challenge at the maximum approved time, with residue condition recorded.
Campaign lengthHow many batches or hours can be manufactured before full cleaning?Maximum batches/time, product build-up observation and chemical/microbial results.
Clean holdHow long can equipment remain clean before reuse?Storage conditions, protection, microbial/chemical results and visual inspection.
Seasonal or utility variationCould temperature, humidity, water pressure or operator availability change performance?Risk rationale, monitoring data or additional challenge studies.

Step 8: Design the sampling plan

A sample plan should show where, how, when and why each sample will be taken. Sampling must challenge the locations most likely to hold residue rather than simply collect convenient points.

Swab or wipe sampling

  • define the sampling template area, solvent, swab material and extraction volume;
  • specify the movement pattern, pressure and number of passes;
  • include hard-to-clean and representative locations identified from drawings and practical inspection;
  • demonstrate recovery on stainless steel, elastomer, plastic, silicone and every other relevant surface;
  • apply a justified recovery correction factor when recovery is incomplete.

Rinse sampling

  • define rinse medium, volume, contact time, agitation and collection point;
  • demonstrate recovery using a method representative of the production rinse;
  • evaluate solubility and the possibility that a large rinse will dilute a localised residue;
  • use rinse sampling for inaccessible areas, supported by targeted swabs where feasible.

PIC/S generally prefers direct swab sampling where feasible because it can target defined surfaces. Rinse sampling is valuable for large or inaccessible areas, but a rinse from a large train may average results and hide a high residue at one location.

Step 9: Validate recovery and analytical methods

Recovery studies demonstrate that the sampling and extraction process can remove and measure residues from the equipment surface. The study should use the same materials, surface finishes, swabs, solvents, templates and extraction conditions that will be used during validation and routine verification.

The analytical method should be suitable for its intended decision. Assess specificity or selectivity, accuracy, precision, linearity, range, solution stability, sample hold time, interference, limit of detection and limit of quantification. The LOQ should be below the residue acceptance limit with appropriate margin.

Specific product assays are preferred. TOC, conductivity or other non-specific methods may be appropriate when scientifically justified, but interference and conservative interpretation must be addressed. Microbial recovery should consider neutralisation or inhibition from residual detergent and should represent relevant pharmacopoeial or local isolates.

Method reminder: A sensitive HPLC method cannot compensate for poor recovery or an unrepresentative sampling location. Sampling recovery and analytical capability must be assessed together.

Step 10: Specify the number of validation runs

Do not insert “three runs” automatically. PIC/S PI 006-4 expects the protocol to define a predetermined number of consecutive cleaning assessments, with a documented rationale based on risk, equipment, product knowledge, manual variability, historical data and confidence in the sampling method.

More runs or expanded routine verification may be appropriate for manual cleaning, low-HBEL products, difficult equipment, new detergents, new operators, weak historical data or a failure history. A well-understood automated system may support a focused study, but only when the risk assessment, recipe controls, recovery evidence and ongoing monitoring are strong.

State the minimum successful run sequence, whether all locations must pass in each run, how invalid samples will be handled and which deviations require a repeat or a new study. Never plan to repeat a run merely because the result was unexpected.

Step 11: Write the execution instructions

The execution section should be written as a controlled sequence. It must be possible for a trained operator and sampler to follow it without relying on informal knowledge.

  1. Confirm protocol approval, equipment status, current cleaning SOP, calibration and training.
  2. Identify the previous product, batch, campaign length and dirty-hold start time.
  3. Record actual cleaning parameters, not only target values.
  4. Perform the cleaning procedure exactly as approved, including disassembly and drying.
  5. Conduct and document visual inspection after the equipment is dry.
  6. Collect swab, rinse and microbial samples at the defined locations.
  7. Label, secure and transfer samples under controlled conditions.
  8. Perform testing using approved methods and record complete raw data.
  9. Review results against the pre-approved criteria and document any deviation.
  10. Repeat the planned sequence for each consecutive validation assessment.

Include fields for date, time, operator, supervisor, sampler, equipment ID, product, batch, cleaning SOP number, detergent lot, water quality, actual temperatures, actual contact times and sample IDs.

Step 12: Manage deviations, failures and invalid data

Every failed visual inspection, out-of-limit result, missed sample, incorrect parameter, instrument issue or protocol departure should be recorded. The investigation should determine whether the event is a laboratory error, sampling failure, procedural deviation, equipment problem or true cleaning failure.

Assess product impact, equipment status, previous validation runs and routine verification data. Root-cause tools such as 5 Whys, fishbone analysis or fault-tree analysis can help, but the conclusion must be supported by evidence. Use CAPA when systemic action is required and link the action to change control or revalidation.

Never “clean and test until passing.” Repeated cleaning or retesting can conceal a process failure and makes the validation conclusion unreliable. A failed result remains part of the study record and must be scientifically explained.

If a sample is invalid for a documented, proven laboratory reason, follow the approved invalid-result procedure. Do not discard an inconvenient result or repeat a sample without a traceable justification.

Step 13: Prepare the cleaning validation report

The final report should allow an independent reviewer to reconstruct the study from protocol approval through conclusion. It should not simply list passing results.

  • approved protocol and revision history;
  • equipment and product identifiers;
  • executed cleaning records and actual parameters;
  • operator and sampler training evidence;
  • sampling map, sample IDs and chain of custody;
  • recovery data and analytical method references;
  • raw data, chromatograms and instrument printouts;
  • calculations, units and recovery corrections;
  • deviations, investigations and product-impact decisions;
  • run-by-run and location-by-location results;
  • limitations, trends and lessons learned;
  • final conclusion and ongoing verification plan.

The conclusion should state whether the cleaning procedure met every pre-approved criterion, identify any limitations and define the continued verification, change-control and revalidation requirements. Production, Quality and other appropriate functions should approve the report.

Step 14: Define ongoing verification and revalidation

Validation is the initial demonstration; verification maintains confidence during routine manufacture. Define the sampling frequency, products or locations covered, alert limits, trend-review method and escalation criteria. Increased monitoring may be justified for low-HBEL products, manual cleaning, limits below visual detection, limited data or variable equipment performance.

Use change control before changing a product, equipment item, detergent, water pressure, cleaning recipe, sampling method, analytical method, hold time, campaign length or acceptance limit. Consider revalidation after repeated failures, adverse trends, significant equipment changes, procedure changes or a new product that challenges the original worst-case rationale.

Link the validated process to the site’s CAPA, deviation and change-control systems. A protocol is not complete until the validated state can be monitored and protected after the study closes.

Cleaning validation protocol template

Protocol sectionWhat to writeReviewer question
Document controlTitle, number, version, effective date and approval page.Is the executed version clearly identified?
Objective and scopePurpose, equipment, products, cleaning procedure and exclusions.Can a reader understand exactly what is being validated?
ResponsibilitiesPreparation, execution, sampling, testing, review and approval.Is every critical activity assigned to a qualified role?
Risk assessmentHazards, worst-case selection, equipment locations and control strategy.Does the evidence support the chosen scope and sampling?
LimitsProduct, detergent, microbial, visual and cumulative train criteria.Were limits justified before execution?
Cleaning procedureSOP reference, parameters, disassembly and drying requirements.Can the procedure be repeated consistently?
Hold and campaign conditionsDirty hold, clean hold, maximum campaign and storage conditions.Do conditions represent the approved operating range?
Sampling planLocations, method, solvent, area, recovery, sample handling.Are the hardest-to-clean areas represented?
Analytical methodsMethod number, specificity, LOQ, stability and microbial controls.Can the method reliably support the decision?
Execution and deviationsRun sequence, recording rules, failure and invalid-result handling.Are failures visible and investigated?
Report requirementsData package, calculations, conclusion and ongoing controls.Will the report demonstrate a maintained state of control?

Worked example: protocol for a shared tablet press

A tablet press is shared by Product A, which has a low PDE and a sticky formulation, and Product B, which has a higher PDE but is easy to remove. The protocol should not select Product B solely because it is manufactured in the largest batch.

  1. Define the press, hopper, feed frame, punches, dies, deduster and vacuum line included in the train.
  2. Map powder traps, seals, feeder corners, punch guides and vacuum filters as hard-to-clean locations.
  3. Use the toxicological assessment to calculate Product A and Product B carryover limits for the next product.
  4. Challenge the maximum approved campaign and dirty-hold time.
  5. Specify disassembly, vacuuming, dry cleaning, wet cleaning, rinsing and drying steps.
  6. Demonstrate swab recovery on stainless steel, polymer seals and coated tooling surfaces.
  7. Use targeted swabs for feeder corners and punch guides; use a justified rinse or extraction for inaccessible vacuum components.
  8. Set criteria for previous-product residue, detergent, microbial risk and visual cleanliness.
  9. Define the predetermined consecutive assessments and investigate every failure without “clean until pass.”
  10. Trend routine verification by location and operator, and reassess the protocol after tooling or formulation changes.

The example shows why a protocol must connect product risk, equipment design, sampling recovery and routine control. A single passing bulk rinse cannot prove that powder trapped in a punch guide is below the approved limit.

Common protocol mistakes to avoid

MistakeWhy it creates riskBetter practice
Copying an old protocolProducts, PDEs, equipment and limits may have changed.Reconfirm scope, risk assessment, limits and references before each study.
Using “three runs” without rationaleIt does not show that variability or process risk was considered.Use a predetermined, risk-based run strategy.
Sampling only convenient surfacesHard-to-clean areas remain untested.Use drawings, practical inspection and risk analysis to select locations.
Relying on visual inspection aloneResidue below visual detection can remain.Pair visual inspection with validated analytical sampling when risk requires it.
Ignoring recoveryA low result may reflect poor sampling rather than a clean surface.Demonstrate recovery on every relevant material and finish.
Changing limits after testingIt creates a biased conclusion.Approve limits before execution and manage changes formally.
Hiding failures through retestingIt masks process weakness and compromises data integrity.Record, investigate and correct each failure.
No ongoing planInitial validation does not prove long-term control.Define verification, trending, change control and revalidation triggers.

Inspection-ready checklist

  • Protocol objective and scope are unambiguous
  • Current cleaning SOP and equipment IDs are referenced
  • Roles, training and approvals are defined
  • Risk assessment and worst-case rationale are approved
  • HBEL/PDE, MACO and cumulative train limits are traceable
  • Dirty hold, clean hold and campaign conditions are defined
  • Manual and automated parameters are controlled
  • Hard-to-clean and non-contact migration locations are evaluated
  • Swab/rinse recovery is demonstrated for each surface material
  • Analytical specificity and LOQ support the acceptance limit
  • Microbial and detergent controls are justified
  • Number of runs is risk-based and predetermined
  • Deviation and failure rules prevent “clean until pass”
  • Report, ongoing verification and revalidation requirements are defined

Frequently asked questions

What is a cleaning validation protocol?

It is an approved, prospective plan defining the equipment, products, cleaning procedure, sampling, analytical methods, acceptance criteria, execution steps and report requirements used to demonstrate reproducible cleaning performance.

What should a cleaning validation protocol include?

Include objective, scope, responsibilities, equipment description, product and worst-case rationale, cleaning procedure, hold times, number of runs, sampling locations, recovery data, analytical methods, limits, deviations and report requirements.

Does PIC/S require three cleaning validation runs?

No. PIC/S expects a predetermined number of consecutive cleaning assessments justified by documented quality risk management, process knowledge and method variability.

Is visual inspection enough for cleaning validation?

Visual inspection is an important minimum check, but it is not sufficient when residues may be below visual detection or when the risk assessment requires analytical evidence.

What is the difference between validation and verification?

Validation demonstrates that the approved cleaning process is reproducible under defined conditions. Verification provides routine or interim evidence that a specific cleaning event met established limits.

How are MACO limits established?

MACO limits come from a documented toxicological and risk assessment considering HBEL/PDE, potency, therapeutic dose, next-product dose, batch size, surface area, process-train carryover and analytical capability.

Which is better, swab or rinse sampling?

Swabbing is generally preferred when feasible because it targets defined and hard-to-clean areas. Rinse sampling is useful for large or inaccessible areas, and a justified combination may provide the strongest coverage.

What are dirty-hold and clean-hold times?

Dirty hold is the maximum time equipment may remain soiled before cleaning. Clean hold is the maximum time cleaned equipment may wait before reuse. Both should be supported by representative evidence.

What happens if a validation run fails?

Document and investigate the failure through the quality system, assess equipment and product impact, address root causes and initiate CAPA or revalidation when justified. Do not repeatedly clean and test until passing.

When should a protocol be revised?

Revise it before execution when scope, equipment, product, method, limits or sampling changes. Reassess the validated state after significant equipment, detergent, procedure, hold-time, campaign or repeated-failure changes.

Key takeaways

  • A protocol is a prospective scientific plan, not a blank form completed after testing.
  • Risk assessment must drive scope, worst-case selection, locations, limits, run count and monitoring.
  • HBEL/PDE values support carryover limits but require a documented calculation and unit-dose assessment.
  • Swab recovery, rinse recovery and analytical LOQ must support the decisions made from sample results.
  • Manual cleaning needs detailed instructions, trained operators and risk-based verification.
  • Every failure remains part of the study record; “clean and test until pass” is unacceptable.
  • The final report must define ongoing verification, change control and revalidation triggers.

Conclusion

A strong cleaning validation protocol makes the study predictable, reproducible and defensible. It begins with a clear scope and risk assessment, translates toxicology into practical limits, challenges the right equipment locations and hold times, validates sampling recovery and analytical sensitivity, and defines how results and failures will be handled. When linked to CAPA, data integrity, change control and routine verification, the protocol supports a lasting state of GMP control rather than a one-time pass.

Before approval, compare the protocol with current PIC/S and national requirements, the site’s contamination-control strategy and the full Cleaning Validation in Pharmaceuticals lifecycle.

References and further reading

This article is an educational GMP overview and does not replace an approved site SOP, toxicological assessment, regulatory advice or Quality Unit approval. Verify current requirements before using the content in a controlled protocol.