Process validation is one of those topics where everyone in pharma knows the basics but surprisingly few people can explain the details clearly. The FDA published its Process Validation Guidance in 2011, introducing the three-stage lifecycle approach that replaced the old "run three batches and call it validated" methodology. Fifteen years later, many companies are still struggling to implement it properly. Not because the guidance is unclear — it is actually one of the better-written FDA guidance documents — but because translating the principles into practical day-to-day activities requires judgement, experience, and a willingness to actually change how you work rather than just relabeling your existing practices.
Stage 1: Process Design — understanding before qualifying
Stage 1 is where you build the scientific understanding of your process. This is not about writing SOPs or batch records — it is about understanding why your process works. What are the critical process parameters? What are the critical quality attributes of your product? How do the process parameters affect the quality attributes? What is the design space within which you can operate and still produce acceptable product?
The tools for Stage 1 include Design of Experiments (DoE), risk assessments (often using FMEA), and extensive process development data. The deliverable is not a validation protocol — it is a process understanding document that defines your control strategy: what you will control, why you will control it, and how tightly you need to control it. Many companies rush through Stage 1 because they are eager to get to Stage 2 and start producing commercial product. This is a mistake. Every dollar you invest in Stage 1 process understanding saves you multiple dollars in Stage 2 deviations and Stage 3 investigations. When a batch fails at commercial scale and you do not have a deep understanding of your process parameters, the root cause investigation becomes a fishing expedition rather then a targeted analysis.
Stage 2: Process Qualification — proving it at scale
Stage 2 is where you demonstrate that the process, as designed in Stage 1, works consistently at commercial manufacturing scale. This is what most people think of when they hear "process validation" — the qualification protocols, the sampling plans, the acceptance criteria, the reports.
Stage 2 has two components: facility and equipment qualification (which maps to your IQ/OQ/PQ activities) and Process Performance Qualification (PPQ). The PPQ is the centrepiece — a protocol that defines enhanced sampling and testing across a defined number of batches to demonstrate that the commercial process consistently produces product meeting its specifications.
The "how many batches" question comes up constantly. The FDA guidance deliberately does not specify a number because the appropriate number depends on your process understanding from Stage 1, the complexity and variability of your process, and your historical experience with similar processes. Three batches is a common starting point, but it should be justified by your risk assessment and process understanding — not by convention or by "that is what we have always done." For a well-understood process with low variability, three batches may be sufficient. For a complex biological process with high inherent variability, you may need significantly more. GxP Copilot helps teams document the rationale for their PPQ batch count and link it directly to the process understanding evidence from Stage 1.
Stage 3: Continued Process Verification — validation never ends
This is the stage that most companies handle poorly. Stage 3 requires ongoing monitoring of process performance to ensure the process remains in a state of control throughout its lifecycle. This is not the same as routine batch release testing — it is a systematic programme that tracks process performance trends, detects drift before it causes out-of-specification results, and triggers investigation and corrective action when performance trends indicate a loss of control. The specific activities include statistical analysis of process parameter data across batches (control charts, capability analysis), monitoring of incoming material variability and its impact on process performance, tracking of non-routine events (deviations, OOS results, complaints) for patterns, and periodic review of the continued adequacy of your control strategy. The challenge is that Stage 3 generates a lot of data that needs to be collected, trended, and reviewed regularly. Many companies set up Stage 3 monitoring when they first validate the process and then let it lapse because the manual effort of maintaining it is not sustainable. This is where electronic tools and automated data collection become essential — not optional — for maintaining a compliant validation lifecycle.
Common mistakes in process validation
- Treating Stage 1 as optional. Rushing to PPQ without adequate process understanding leads to failed batches, unexpected deviations, and validation protocols that test the wrong things.
- Confusing Stage 2 with routine production. PPQ batches require enhanced sampling and monitoring beyond what you do in routine production. If your PPQ protocol looks identical to your routine batch record, you are probably not sampling enough.
- Abandoning Stage 3. Continued process verification is a regulatory requirement, not a nice-to-have. Inspectors will ask to see your trending data and they will notice if it stops after the first year.
- Using arbitrary batch counts. "Three batches because that is what we always do" is not a scientifically justified rationale. Your batch count should be based on your process understanding and risk assessment.
- Not linking stages together. The three stages should build on each other. Your Stage 2 protocol should reference Stage 1 findings. Your Stage 3 monitoring parameters should be derived from Stage 1 critical process parameters. If the stages are disconnected documents, you are missing the point of the lifecycle approach.
Where computerised system validation fits in process validation
Every system that generates, records, or processes data used in process validation needs to be validated itself — the LIMS that reports your in-process results, the MES that records your process parameters, the statistical software you use for Stage 3 trending, and the data historian that captures continuous process data. GxP Copilot handles the CSV services for these systems using a CSA services approach where test depth is proportional to the risk each function poses to your process validation programme. The Live RTM then connects your process validation evidence to the underlying system validation evidence, creating complete traceability from process parameter to validated data source. This is the kind of integrated traceability that FDA inspectors look for — and that is very difficult to maintain manually across separate documents and systems.
Where to go next
Explore GxP Copilot for AI-native validation, TraceDraft for source-traceable clinical documentation, or book a demo to see either on your own data.
