All blueprints

Cleaning validation software.

Limits, execution, samples and equipment state in one control loop.

Illustration of a seal comparing two equipment versions, each linked to its retained evidence.
Cleaning validation / the selected changeover in context
The matrix exposes why a product–equipment pair is worst case, then carries that rationale into execution and release.
Residue risk matrix · score / 100
matrix v07
Product
Mixer M2
Filler F4
Granulator G1
Product A
18
32
41
Product B
25
47
63
Product C
36
72
94
selected
Product D
14
29
52
Potency0.4 µg/day PDE
Solubilitylow / aqueous
Surface18.6 m² shared
Limit basis
MACO 6.4 mg
PDE × next-batch size ÷ daily dose
Swab limit 0.86 µg / 25 cm²
Executed clean · CLN-0441
Hopper
Chute
Shaft
Seal
dirty hold 17h 42m · cycle 4 · visual pass
Train release
All locations ≤ limit
clean until 14:20

Figure 1. Residue risk matrix v07 for four products on mixer M2, filler F4 and granulator G1, where product C on G1 scores highest and is selected. Its MACO of 6.4 mg (PDE × next-batch size ÷ daily dose) over 18.6 m² of shared surface sets a swab limit of 0.86 µg per 25 cm², and executed clean CLN-0441 releases the train clean until 14:20.

Summary

The problem
Limits, worst-case rationale, protocols and routine results sit in workbooks and reports that often disagree. A status of “validated” rarely says whether it covers the next product-equipment transition, or what a changed PDE or surface area invalidates.
Seal’s approach
Seal connects the product-equipment matrix to versioned limit calculations, worst-case rationale, executable cleaning instructions, dirty and clean hold clocks, swab and rinse samples and laboratory results. Each validated state carries an explicit, queryable boundary.
What changes
The production step checks the selected equipment’s clean state before use, and an exceeded hold blocks normal use. A change to a toxicological input, procedure or surface area identifies the calculations, studies and scheduled campaigns in scope.
Where to start
One shared equipment train across a changeover, with at least three products, a justified worst case and a failed result. Book a demo.

Cleaning validation is a control system across products, equipment, toxicological knowledge, cleaning processes, sampling, analytical methods, execution and continued evidence. A calculation workbook or protocol repository captures only fragments of it.

Seal connects the approved product-equipment matrix to residue limits, worst-case rationale, cleaning instructions, equipment use, electronic execution, swab and rinse samples, laboratory results, deviations, change impact and ongoing verification.

1Every validated state has an explicit boundary.

A cleaning process is not valid in the abstract.¹ Its evidence applies to defined residues, equipment trains and surfaces, cleaning agents, parameters, sampling locations, methods, limits and use conditions. Seal records that boundary on each validated state, so an operator, scheduler, validation engineer or reviewer can see whether it covers the next product-equipment transition.

Table 1. The scope a validated cleaning state carries in Seal.
ElementIncludes
ProductsProducts and residues represented, including the approved worst case
EquipmentTrain, shared path, product-contact surfaces and excluded equipment
ProcessCleaning agent, procedure, automation program and parameter ranges
HoldsMaximum dirty hold, clean hold, campaign length and storage conditions
SamplingSwab and rinse locations, recovery assumptions, methods and reporting basis
AcceptanceChemical, microbial, visual and other applicable criteria
EvidenceStudy runs, deviations, repeat work, conclusion and approval
LifecycleRoutine verification, review frequency, change triggers and revalidation state

A status of “validated” without this scope is too broad to control production.

1.1Why teams choose Seal for cleaning validation

A one-off cleaning-validation protocol and report can leave limits calculated in workbooks and routine cleaning recorded on paper, so “validated” is a status that nobody can test against the next changeover. Seal connects the matrix, limits, cleaning execution, holds and results, and the production step checks the equipment’s clean state before use. A new product, PDE or surface area enters as a change that shows the calculations, studies and campaigns it affects, so the validated state keeps up with the product portfolio.

2The matrix defines exposure, and limits keep their inputs.

The product matrix captures active ingredients, strengths, formulation residues, cleaning difficulty, solubility, toxicity inputs, batch size and contact paths. The equipment matrix captures trains, units, shared surfaces, materials of construction, surface areas, hard-to-clean locations, swab sites and cleanability groups. Mappings show which products contact which equipment under which procedures, so a new product, equipment change or campaign strategy identifies every affected calculation, study, sampling plan and instruction before implementation.

An acceptance limit is a governed calculation, not a number copied into protocols. Seal keeps the toxicological or pharmacological input, dose basis, batch sizes, surface area, safety factors, units, formula version, rounding, rationale, reviewer and effective dates. It can compare applicable criteria and apply the approved selection rule without hiding the alternatives. The manufacturer remains responsible for toxicological conclusions and acceptance strategy; Seal makes the inputs, transformations and downstream use inspectable.

Grouping reduces redundant studies only when the bracket is scientifically justified. Potency, toxicity, solubility, cleanability, dose relationships, equipment exposure and analytical detectability can be scored, and the selected worst case keeps its criteria, data sources, calculation version, expert rationale and approval. When the matrix changes, the system shows whether the representative still holds. A score does not become a scientific conclusion without review.

3Procedures run as instructions, and equipment state gates the next batch.

Approved procedures define equipment state, disassembly, pre-rinse, agent identity and concentration, temperature, flow, time, mechanical action, rinse endpoint, inspection, reassembly and status labelling.² CIP and SIP systems stay authoritative for control and high-frequency data; Seal guides the accountable work and receives the cycle identity, phases, parameters, alarms and completion state. Missing automation evidence stays visible instead of being replaced by a handwritten summary.

The final product-contact event creates the dirty state and starts the dirty-hold clock. Cleaning start, pauses, completion, inspection, sampling, laboratory wait, release, storage and next use update the equipment history, and clean-hold and campaign limits are governed the same way.

Electronic logbook / event time, entry time and equipment state
A log is useful when it controls what may happen next—not when it merely reproduces a ruled page.
Controlled subject
BLD-007
Buffer vessel · suite 2
Current state
Released clean
eligible for BFR-026
Open handoff
Inspect vent filter
Day shift · due 07:00
Event
Entry
Controlled event
State transition
17:54
17:55
Batch 024 disconnected
IN USE → DIRTY
18:12
18:12
Cleaning cycle started
DIRTY → CLEANING
18:42
18:56
Cycle completed / late entry
14-minute contemporaneity exception linked
CLEANING → REVIEW
19:03
19:03
Supervisor verified
REVIEW → CLEAN
Figure 2. An equipment logbook moving a vessel from in use to dirty, cleaning and released clean, with event and entry times recorded

Dirty, cleaning, awaiting sample, awaiting result, clean, expired and under-investigation states stay distinct, and the production step checks the selected equipment before use. Approaching deadlines are visible to scheduling; an exceeded limit blocks normal use and opens the approved assessment or recleaning path. Maintenance, part replacement, surface damage or relocation can invalidate or condition the clean state until the change process has determined the cleaning impact.

4Samples and results keep their physical and analytical context.

The protocol defines swab locations, rinse points, sample areas or volumes, recovery factors, sequence, containers, hold time, method, blanks and limits. Execution identifies the exact equipment, location, surface condition, sampler, time, sample identity and chain of custody; photographs or location maps help repeatability while the structured location stays the controlling identity.

The laboratory record connects each sample to the effective method, acquisition, standards, recovery study, calculation, reporting basis, limit, analyst and reviewer, with raw data linked to the reported result.³ Results below quantitation, invalid runs, dilutions, retests and resamples keep their true state, so a passing summary cannot hide unsuitable system performance or the wrong surface-area conversion.

5Protocol runs and failures stay independent evidence.

The validation protocol resolves its prerequisites: equipment and utility qualification, procedure version, trained personnel, methods, recovery evidence, calibration, soil preparation, sampling plan and acceptance criteria. Each run carries the actual preceding product, train, conditions, holds, interventions, samples, results, deviations and conclusion. Repeated runs remain separate evidence linked to one study, not spreadsheet columns that lose their execution identity.

An adverse residue, missed parameter, wrong agent concentration, late sample, damaged surface or hold excursion opens a deviation with the product, equipment, cleaning execution, sample, method and subsequent use attached. Containment identifies the equipment and potentially affected batches, and the investigation distinguishes execution, sampling, analytical, equipment, procedure and strategy causes. A repeat execution is prospective and justified; it does not erase the failed evidence.

6Routine verification and change keep the matrix current.

After validation, the approved strategy defines routine checks by product, equipment, campaign, risk or frequency: visual inspection, conductivity, TOC, specific assays, microbial monitoring, cycle parameters and periodic swabs. Seal trends results with procedure, product, equipment, location, preceding use, operator, hold and method context, so drift can prompt investigation or revalidation before a limit fails. Routine monitoring does not silently broaden the scope of a validated claim.

A change to product, formulation, dose, toxicological input, batch size, equipment, surface area, material, agent, procedure, automation, hold time, sampling site, method, recovery or limit is traced through the matrix to the calculations, groupings, protocols, instructions, training, open equipment, scheduled campaigns and prior conclusions it affects. Reviewers see why each item is in scope rather than receiving a flat checklist. Study reports render from the governed runs, samples, results and deviations, with source references intact.

7Reconcile master data, then prove one shared train.

Cleaning programmes often find that equipment lists, surface areas, product matrices, procedure applicability, sampling locations and current limits disagree across spreadsheets and reports. Software cannot resolve those scientific and engineering conflicts automatically, so implementation starts with governed identities: a stable hierarchy from line and unit to surface or sampling point, current product assumptions and contact paths, and each method’s relationship to residue and surface. Seal exposes missing mappings and conflicting versions early, and the migration record documents source, transformation, verification and owner.

Then model one real shared train with at least three products, a justified worst case, a versioned limit calculation, manual and automated cleaning evidence, swab and rinse samples, a failed result, hold controls and next-batch gating. Change a toxicological input, a surface area, a procedure and the product matrix. The system is credible when each change identifies the correct validation scope and production cannot use equipment whose cleaning state is incomplete or expired.

References

  1. 1EudraLex Volume 4, Annex 15, Qualification and Validation (2015), sections 5 (process validation), 10 (cleaning validation) and 11 (change control). European Commission
  2. 221 CFR 211.67, Equipment cleaning and maintenance: equipment and utensils must be cleaned, maintained and, as appropriate, sanitised or sterilised at appropriate intervals under written procedures. eCFR
  3. 321 CFR 211.194, Laboratory records: laboratory records must include complete data derived from all tests necessary to assure compliance with established specifications and standards. eCFR

ACapabilities

CapabilityWhat it covers
Product-equipment matrixKeep products, residues, equipment trains, surfaces, procedures and validated coverage in one controlled model.
Controlled limit calculationsEach acceptance limit keeps its toxicological input, dose basis, batch sizes, surface area, safety factors, units and version, and can be traced to where it is used.
Worst-case rationaleGrouping criteria, source data, the representative selected and the expert rationale remain inspectable and are reassessed when the matrix changes.
Electronic cleaning executionManual cleaning steps and automated cycle evidence share the equipment, preceding use, hold clocks, parameters, alarms and status.
Sampling and laboratorySwab and rinse samples keep their location, custody, method, recovery, calculation, limit and review.
Equipment clean stateDirty, cleaning, awaiting sample, awaiting result, clean, expired and under-investigation states stay distinct, and the production step checks the selected equipment before use.
Validation lifecycleLink protocols, prerequisites, study runs, deviations, reports, routine monitoring, change impact and revalidation for each validated state.
Deviation and impactA failure opens with the equipment, product, cleaning execution, sample, method and result attached, and identifies the equipment’s subsequent use.
Continued verificationTrend routine results by product, train, procedure, sampling location, campaign and hold time.
Change impactTrace a change to product, equipment, toxicology, procedure, method, surface or limit to the validated claims it affects before it takes effect.

BConnected records

Entity
What it records
Kind
Product or Residue
Product, active, formulation residue, potency, toxicity, cleanability and batch context.
type
Equipment Train
Shared product-contact equipment, surfaces, paths, locations and cleanability grouping.
type
Cleaning Matrix
Approved product-equipment-procedure coverage and validated-state boundary.
type
OSD Shared Equipment Matrix
Reusable matrix structure for products, trains, procedures and validated coverage.
template
OSD Matrix v07
Effective matrix governing the representative changeover.
instance
Residue Limit
Versioned scientific inputs, formula, units, result, selection rule and approval.
type
Health-Based Carryover Limit
Approved input, calculation, unit, selection and review structure.
template
Limit AB12 → CD40
Effective residue limit for the product changeover on Train 4.
instance
Worst-Case Rationale
Grouping criteria, scores, representative, evidence, rationale and review.
type
Cleaning Procedure
Approved manual or automated phases, materials, parameters, checks and exception paths.
type
Granulation Train Cleaning
Approved disassembly, wash, rinse, inspection, assembly and release pattern.
template
CLN-GRAN-04 v11
Effective procedure used after batch AB12-2608.
instance
Cleaning Execution
Actual equipment, preceding use, cycle, values, alarms, holds, inspection and status.
type
Product Changeover Clean
Reusable electronic execution with holds, evidence, samples and state transitions.
template
CLN-0441
Executed cleaning of Granulation Train 4.
instance
Sampling Location
Controlled physical swab or rinse point with surface, area, accessibility and risk.
type
Hard-to-Clean Swab Site
Defined location identity, area, material, map, technique and risk.
template
FBD Discharge Chute S07
Worst-case swab location sampled after CLN-0441.
instance
Cleaning Sample
Swab, rinse, blank or microbial sample with collection and custody context.
type
Residue Swab
Approved collection, container, hold, custody, test and calculation pattern.
template

CQuestions and answers

What is pharmaceutical cleaning validation software?

It manages the evidence that a defined cleaning process controls residues and other applicable risks for specified products and equipment. That covers matrices, limits, worst-case rationale, procedures, execution, holds, sampling, results, deviations and change impact.

Can Seal calculate cleaning residue limits?

Seal can run configured and verified calculations using approved inputs, units, formulas and rounding, keeping versions and review. The manufacturer remains responsible for the toxicological inputs, scientific rationale and acceptance strategy.

How are PDE or health-based inputs controlled?

Each input keeps its source, value, units, applicability, version and approval. A change triggers an impact assessment across the affected products, calculations, equipment, studies and validated state.

Can the system select a worst-case product?

It can calculate approved scores or groupings and present candidates, but the expert rationale and approval remain explicit. The selected representative keeps its criteria and source evidence, and matrix changes prompt reassessment.

Does Seal integrate with CIP systems?

Yes. The control system can remain the source for cycle execution and high-frequency data. Seal receives the cycle identity, phases, critical parameters, alarms and completion state, and manages the instructions, exceptions, samples, review and equipment release.

How are dirty and clean hold times controlled?

Defined equipment-use and cleaning events start the applicable clocks, and approaching deadlines are visible for scheduling. Exceeding a limit takes the equipment out of the normal path and into the approved recleaning or assessment route. Actual pauses and storage conditions stay in the history.

Can cleaning samples be managed in LIMS?

Yes. Execution creates samples with the equipment, location, area or volume, time, method and limit attached. Results return with their acquisition, recovery, calculation, reporting basis and review, including any invalid or OOS state.

How are failed cleaning results handled?

The failure opens with the equipment, preceding product, execution, location, sample, method and result attached. Containment identifies the equipment and any batches potentially affected. Investigation, repeat work and disposition remain separate controlled events.

Does routine cleaning verification replace validation?

No. Routine verification supplies continued evidence within the approved strategy, but it does not expand validated coverage. Drift or change can trigger investigation, further study or revalidation.

How does cleaning status block production?

The manufacturing step checks the selected equipment’s clean state, hold limits and investigation status before use. Equipment that is incomplete, expired or under investigation does not follow the normal execution path.

What changes should trigger a cleaning validation assessment?

Examples include changes to product, formulation, dose, toxicological input, batch size, equipment, surface area, cleaning agent, procedure, automation, hold time, sampling, method, recovery or acceptance limit.

What should the first cleaning-validation implementation prove?

Model one shared train with several products, a justified worst case and a versioned limit calculation. Run manual and automated cleaning, swab and rinse samples, a failed result and a hold excursion through to equipment release. Then change a key input and check that its impact is traced correctly.

See your process in Seal.

Bring a procedure or a recurring problem. See how your team can use Neil to configure the workflow, investigate the results and improve the next version.

Book a demo