Vendor Protocols in Equipment Qualification
Equipment manufacturers frequently provide Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT), commissioning, Installation Qualification (IQ), Operational Qualification (OQ), or combined IOQ protocols with their systems. These documents can provide valuable qualification evidence and may reduce unnecessary duplication of testing.
However, a protocol does not become acceptable qualification evidence simply because it was prepared or executed by the equipment vendor. Its suitability depends on the protocol’s technical content, alignment with approved requirements, execution controls, documentation quality, and relevance to the equipment as installed at the operating site.
Vendor protocols may be incorporated into the qualification program when they are reviewed, approved, executed, and retained under an appropriate site-controlled strategy. The regulated company remains responsible for determining whether the total body of evidence demonstrates that the equipment is fit for its intended GMP use.
Why Vendor Protocols Are Used
Equipment vendors possess detailed knowledge of their systems, including component design, operating sequences, control logic, alarms, interlocks, and mechanical limitations. Vendor-developed testing can therefore be technically detailed and efficient, particularly for standardized or packaged equipment.
Vendor protocols are commonly used for:
- Manufacturing equipment
- Packaging equipment
- Sterilizers and depyrogenation equipment
- Parts washers
- Lyophilizers
- Refrigerators, freezers, and stability chambers
- Laboratory instruments
- Process skids
- Packaged utility systems
- HVAC and building-control systems
- Automated equipment and integrated control systems
Using suitable vendor protocols can:
- Use the vendor’s specialized equipment knowledge
- Detect design and fabrication problems before delivery
- Reduce duplication between commissioning and qualification
- Improve coordination between the vendor and site personnel
- Provide earlier verification of critical functions
- Reduce the time required for site qualification
- Preserve detailed evidence generated during equipment fabrication and testing
The objective is not simply to reduce testing. Vendor documentation should be leveraged only when it provides reliable evidence that supports the approved qualification strategy.
Common Types of Vendor Protocols
Vendor documentation may support different stages of the equipment lifecycle. The value of each protocol depends on where testing is performed, what configuration is tested, and whether the results remain applicable after delivery and installation.
Factory Acceptance Testing
FAT is performed at the vendor’s facility before equipment shipment. It may verify:
- Equipment fabrication and assembly
- Major components and instruments
- Control-panel construction
- Software and control-system functions
- Operating sequences
- Alarms and interlocks
- Safety functions
- Recipe or parameter controls
- Documentation availability
- Preliminary equipment performance
FAT is particularly valuable for complex or customized equipment because deficiencies can be corrected before shipment.
However, FAT normally evaluates the equipment under factory conditions. Temporary utilities, simulated signals, substitute components, test software, or incomplete interfaces may be used. FAT results therefore do not automatically establish that the equipment is correctly installed or operates properly at the final site.
Site Acceptance Testing
SAT is performed after the equipment arrives at the operating site. It commonly confirms:
- Equipment condition following transportation
- Correct assembly and installation
- Connection to permanent site utilities
- Availability of required documentation
- Communication with supporting systems
- Basic operation in the installed environment
- Resolution of open FAT items
- Site-specific alarms, interlocks, and interfaces
SAT may overlap with commissioning or IQ/OQ activities. The relationship between these activities should be defined in the qualification strategy to prevent undocumented gaps or unnecessary repetition.
Commissioning Protocols
Commissioning verifies that equipment and supporting systems have been installed, adjusted, started, and made ready for operation. Commissioning records may include:
- Installation inspections
- Electrical checks
- Instrument-loop checks
- Motor rotation verification
- Utility connection checks
- Control-loop tuning
- Alarm and interlock challenges
- Equipment startup
- Functional checks
- Balancing and adjustment
- Punch-list resolution
Commissioning data may support qualification when the activities are planned, documented, technically adequate, and performed under appropriate controls. Informal startup records or incomplete checklists should not be treated as qualification evidence without documented evaluation.
Vendor IQ, OQ, and IOQ Protocols
Some vendors provide formal IQ, OQ, or combined IOQ protocols intended for use within the customer’s qualification program.
Vendor IQ protocols normally document equipment identity, components, installation, utilities, drawings, manuals, materials, instruments, and calibration status.
Vendor OQ protocols normally challenge operating ranges, controls, alarms, interlocks, sequences, and other functional requirements.
A combined IOQ may be appropriate when installation and operational verification can be efficiently executed within a single controlled protocol. Combining the phases does not eliminate the need to distinguish installation evidence from operational evidence.
Ways Vendor Protocols Can Be Used
Vendor protocols can be incorporated into qualification in several ways.
| Use of vendor document | Qualification treatment |
|---|---|
| Vendor technical testing only | Retained as supporting engineering or commissioning documentation |
| Referenced evidence | Specific vendor results are referenced from a site qualification protocol |
| Leveraged with supplemental testing | Acceptable vendor tests are retained while identified gaps are covered by site testing |
| Adopted as a site protocol | The vendor protocol is reviewed, approved, controlled, and executed as part of the formal qualification package |
| Rewritten as a site protocol | Vendor technical content is transferred into the site’s standard protocol format |
The selected approach should depend on equipment risk, protocol quality, testing location, site procedures, and the extent to which the vendor documentation addresses approved requirements.
Reformatting a technically adequate vendor protocol solely to make it resemble a site template may add work without improving control. Conversely, accepting a poorly structured protocol merely because it carries the vendor’s name creates weak qualification evidence.
The decision must be based on content and control—not document appearance.
The following diagram shows how vendor protocols and test results move through site review, gap assessment, supplemental testing, and final incorporation into the equipment qualification package.

Pre-Execution Review of Vendor Protocols
A vendor protocol intended for formal qualification use should be reviewed before execution. Approval after testing has already been completed cannot establish prospective control over the test methods and acceptance criteria.
The review should determine whether the protocol is suitable for the equipment, qualification phase, and intended use.
Equipment Identification and Scope
The protocol should clearly identify:
- Equipment name and identification number
- Manufacturer and model
- Serial number, where available
- Hardware and software versions
- Equipment boundaries
- Included subsystems
- Excluded systems or activities
- Testing location
- Applicable qualification phase
Generic protocols should be configured for the actual equipment. References to optional features, incorrect component models, or functions that were not purchased should be removed or marked appropriately.
Alignment with User Requirements
The protocol should be compared with the approved User Requirements Specification and applicable design documents.
The review must determine:
- Which requirements are tested
- Which requirements are verified through inspection or document review
- Which requirements are addressed elsewhere
- Which requirements remain untested
- Whether test depth is appropriate to equipment risk
A vendor’s standard functional tests may demonstrate that the equipment works according to the vendor’s design. Qualification must demonstrate that it satisfies the user’s approved requirements and intended GMP use. These are related, but not identical, conclusions.
Test Procedures
Test instructions should be sufficiently detailed to support consistent execution. Each test should define:
- Required preconditions
- Equipment configuration
- Test method
- Required actions
- Expected results
- Data to be recorded
- Applicable acceptance criteria
- Supporting attachments or printouts
Instructions such as “verify correct operation” are inadequate unless correct operation is clearly defined.
Acceptance Criteria
Acceptance criteria should be objective, measurable, and approved before execution. They should be derived from:
- User requirements
- Approved design specifications
- Equipment operating limits
- Process requirements
- Manufacturer specifications
- Applicable standards
- Risk assessments
Vendor protocols sometimes use design tolerances or factory specifications that do not reflect site operating requirements. These differences must be resolved before the protocol is approved.
Test Instruments
The protocol should identify measuring instruments required for execution and provide space to document:
- Instrument identification
- Calibration status
- Calibration due date
- Measurement range
- Required accuracy, where applicable
Test instruments must be suitable for the measurement being performed. A current calibration label alone does not establish that the instrument has the accuracy and range required for the test.
Documentation Controls
The protocol should provide adequate fields for:
- Actual results
- Equipment identification
- Test-instrument information
- Executor initials or signatures
- Execution dates
- Witness or reviewer signatures, when required
- Comments and observations
- Deviation references
- Supporting attachment identification
- Final test disposition
Vendor forms that permit only a pass/fail checkmark may be insufficient when actual values or objective evidence are needed.
Requirement Traceability and Gap Assessment
A documented gap assessment should compare the vendor protocol against the approved qualification requirements.
The assessment may be incorporated into a requirements traceability matrix or maintained as a separate protocol-review record.
Common vendor-protocol gaps include:
- Site-specific equipment identification
- Permanent utility connections
- Facility interfaces
- Process operating ranges
- GMP-critical alarms
- Electronic records and audit trails
- User-access restrictions
- Site recipe configurations
- Data transfer and system interfaces
- Emergency recovery
- SOP availability
- Preventive-maintenance requirements
- Calibration-program enrollment
- Training requirements
- Performance under actual loads or products
- Verification under routine environmental conditions
Each gap should be assigned a disposition. It may be addressed through:
- A revised vendor protocol
- A site protocol addendum
- Supplemental IQ or OQ testing
- Commissioning documentation
- A separate computerized-system test
- PQ or process-specific studies
- Document review
- A documented technical justification
A gap assessment does not require every vendor test to be repeated. It ensures that every applicable requirement is addressed by adequate evidence.
Leveraging FAT Results
FAT results can sometimes be used to reduce site OQ testing, but only when the FAT conditions and evidence remain applicable.
Factors supporting FAT leverage include:
- Testing was performed on the actual equipment
- The tested hardware and software versions are documented
- The protocol was approved before execution
- Acceptance criteria were technically appropriate
- Test instruments were controlled and calibrated
- Actual results were recorded
- Deviations were investigated and resolved
- Test records are complete and available
- Shipment and installation could not invalidate the tested function
- No relevant design or configuration changes occurred afterward
Testing should generally be repeated at the site when the function could be affected by:
- Disassembly or shipment
- Reassembly or installation
- Permanent utility connections
- Site wiring or field devices
- Network configuration
- Software or configuration changes
- Integration with other equipment
- Environmental conditions
- Site-specific recipes or operating parameters
For example, an alarm generated entirely within unchanged control software may be suitable for FAT leverage. An alarm dependent on a field instrument installed and wired at the site generally requires site verification.
The leverage decision should be based on what could have changed or been affected—not on a blanket rule that all FAT testing must or must not be repeated.
Protocol Ownership and Site Control
A vendor may prepare and execute the protocol, but the regulated company retains ownership of the qualification decision.
When a vendor protocol is adopted as part of formal qualification, site controls should address:
- Document identification or cross-reference
- Vendor document number and revision
- Site approval before execution
- Authorized protocol changes
- Execution responsibilities
- Good documentation practices
- Deviation management
- Review of completed records
- Retention of original data and attachments
- Final approval and disposition
The protocol does not necessarily need to be converted into the site’s document format. A controlled cover sheet or approval page may be used to identify the vendor protocol, establish its status, define site requirements, and document approval.
Handwritten corrections, test changes, repeated steps, and added acceptance criteria should be handled according to approved procedures. Changes that alter the test objective or acceptance criteria should receive documented approval before the affected testing is performed.
Execution Responsibilities
Vendor personnel may execute specialized tests because they understand the equipment and possess the necessary technical expertise. Site personnel should nevertheless provide appropriate oversight.
Responsibilities should be established before execution for:
- Test execution
- Witnessing
- Recording results
- Reviewing test evidence
- Identifying deviations
- Approving protocol changes
- Resolving technical issues
- Determining test acceptance
- Approving the completed protocol
A vendor representative should not be the sole authority deciding whether a GMP-significant failure is acceptable. Vendor technical input may support the assessment, but the final qualification disposition must follow the site’s quality and validation procedures.
Deviations and Open Items
Failures and unexpected results identified during vendor testing should be documented and evaluated. Renaming failures as “observations,” “comments,” or “punch-list items” does not eliminate the need for assessment.
The classification and management process should distinguish between:
- Minor documentation corrections
- Construction or installation punch-list items
- Test deviations
- Failed acceptance criteria
- Design deficiencies
- Configuration errors
- Requirements gaps
- Conditions preventing test completion
Each significant item should include:
- Description of the issue
- Affected requirement or function
- Investigation or technical assessment
- Corrective action
- Retesting requirements
- Impact on previously completed testing
- Final resolution and approval
Conditional acceptance may be appropriate for limited open items that do not affect safe operation, product quality, data integrity, or the validity of completed tests. The justification, responsible person, and completion requirement should be documented.
Supplemental Site Qualification
Vendor protocols rarely address every site-specific requirement. Supplemental qualification should be developed when the vendor package does not provide complete coverage.
Supplemental testing may address:
- Permanent utility connections
- Site installation
- Facility interfaces
- Site-specific operating ranges
- Critical alarms and interlocks
- Local control-system configuration
- Electronic data controls
- User access
- System interfaces
- Actual operating loads
- Cleaning or sterilization cycles
- Product-contact requirements
- Performance under routine conditions
Supplemental testing should target identified gaps. It should not automatically repeat acceptable vendor testing without a technical reason.
Review and Final Acceptance
Completed vendor protocols should undergo the same level of technical and quality review expected for site-generated qualification records.
Final review should confirm that:
- The approved protocol revision was executed
- All required tests were completed
- Actual results meet acceptance criteria
- Supporting data are present and identifiable
- Test instruments were suitable and calibrated
- Corrections comply with documentation requirements
- Deviations were evaluated and resolved
- Open items have an approved disposition
- Supplemental testing was completed where required
- Requirements traceability is complete
- Changes after testing were assessed
- The results remain applicable to the installed equipment
The qualification report should explain how vendor protocols were used and identify any supplemental testing. It should provide a clear conclusion regarding whether the combined evidence supports the equipment’s qualified status.
Common Inadequate Practices
Vendor-protocol leverage becomes difficult to defend when an organization:
- Executes the protocol before site review and approval
- Accepts a generic protocol that does not identify the actual equipment
- Relies on pass/fail checkmarks without objective evidence
- Uses acceptance criteria that are undefined or subjective
- Fails to compare the protocol with the URS
- Treats FAT as proof of correct site installation
- Repeats all vendor testing without assessing its value
- Accepts unresolved vendor deviations
- Cannot identify the hardware or software version tested
- Fails to retain raw data, printouts, or test attachments
- Allows the vendor alone to determine final acceptability
- Assumes that purchasing a vendor IQ/OQ package guarantees qualification
The purchase of a protocol is not the purchase of a qualified system. Qualification depends on the adequacy and control of the complete lifecycle evidence.
Risk-Based Decision Framework
The extent to which vendor protocols may be leveraged should be based on risk and documented evidence.
| Consideration | Greater potential for leverage | Greater need for site testing |
|---|---|---|
| Equipment design | Standardized and well understood | Customized or novel |
| GMP impact | Indirect or limited | Direct effect on product quality |
| Protocol quality | Detailed, objective, and traceable | Generic, incomplete, or subjective |
| Test configuration | Actual final configuration | Temporary or simulated configuration |
| Installation effect | Function unaffected by shipment | Function dependent on site installation |
| Changes after testing | None or fully assessed | Hardware, software, or configuration changed |
| Documentation | Complete and controlled | Missing records or weak data integrity |
| Supplier capability | Demonstrated and reliable | Uncertain or inadequately assessed |
Risk determines the necessary depth of verification. It does not justify accepting incomplete evidence.
Qualification Principle
Vendor protocols can form an effective part of a risk-based equipment qualification program. They may provide detailed technical testing, support earlier defect detection, and prevent unnecessary repetition of activities already performed under adequate controls.
Their use must be governed by four conditions:
- The protocol is technically adequate.
- The testing is traceable to approved requirements.
- Execution and documentation are properly controlled.
- Gaps and site-specific conditions are covered by supplemental qualification.
Vendor testing supports qualification, but it does not transfer qualification responsibility to the vendor. The regulated company must evaluate the complete evidence and formally determine that the installed equipment is suitable for its intended GMP use.
Vendor protocols and FAT results may support equipment qualification when they are technically adequate, applicable to the installed configuration, and properly reviewed and controlled by the site. The regulated company remains responsible for demonstrating that the equipment is suitable for its intended GMP use.

