|

Analytical Instrument Installation Qualification

Analytical Instrument Installation Qualification

Analytical instrument Installation Qualification (IQ) provides documented evidence that an instrument and the systems supporting it have been received, identified, installed, and configured in accordance with approved requirements, design decisions, manufacturer instructions, and site standards.

IQ establishes the controlled installation and configuration baseline required before functional testing begins. It confirms what was installed, where it was installed, how it was connected, which software and firmware versions were present, and whether the supporting environment is suitable.

IQ does not demonstrate that every instrument function performs correctly across its operating range. That evaluation belongs primarily to Operational Qualification. Installation checks and limited communication checks may be performed during IQ, but they should not be presented as evidence of full functional performance.


1. Purpose of Installation Qualification

The purpose of IQ is to verify that the installed analytical system corresponds to the approved system design and is ready for controlled testing.

A complete IQ should demonstrate that:

  • the delivered instrument matches the approved purchase and design specifications
  • the instrument, modules, accessories, and supporting components are uniquely identified
  • the installation location and supporting utilities are suitable
  • hardware, software, firmware, workstations, network connections, and interfaces are installed as intended
  • the initial configuration is documented and controlled
  • required manuals, certificates, licenses, and technical records are available
  • security-related installation settings have been established
  • critical calibration status is acceptable
  • installation discrepancies have been resolved or formally assessed
  • the system is ready to proceed to OQ

The depth of IQ should follow the approved risk-based analytical instrument qualification strategy. A simple stand-alone instrument may require a concise installation record, while a computerized analytical system may require extensive configuration, network, software, security, and data-path verification.

The following illustration summarizes the progression from receipt through approval of the installed baseline.

Analytical instrument Installation Qualification workflow from receipt and identification through installation, configuration documentation, and readiness for OQ
Installation Qualification establishes a documented baseline before Operational Qualification begins.

2. Relationship to the Qualification Lifecycle

IQ is one part of an integrated qualification lifecycle:

  • User requirements define what the analytical system must support.
  • Design Qualification confirms that the selected design and supplier solution can satisfy those requirements.
  • IQ verifies what was received and how the approved system was installed and configured.
  • Operational Qualification challenges functions, controls, alarms, calculations, security features, and operating ranges.
  • Performance Qualification demonstrates performance under representative routine-use conditions when a separate PQ is justified.

These phases may be combined or scaled when justified by instrument complexity, intended use, risk, and available supplier evidence. The organization should preserve the objective of each activity even when the corresponding records are consolidated.

IQ should trace back to applicable requirements and approved design decisions. It should not become an isolated checklist based only on a generic supplier template.


3. Defining the IQ System Boundary

The IQ scope must follow the approved analytical-system boundary. The boundary may include more than the physical instrument.

Depending on the intended use and architecture, the qualified system may include:

  • instrument chassis and measurement modules
  • autosamplers, detectors, pumps, ovens, injectors, probes, or sensors
  • instrument controller or embedded computer
  • acquisition and processing workstation
  • operating system
  • application software
  • instrument firmware
  • local or network data storage
  • printers, barcode readers, balances, or other peripherals
  • laboratory network connections
  • interfaces with LIMS, chromatography data systems, middleware, or other applications
  • uninterruptible power supplies
  • gases, vacuum, cooling, drainage, exhaust, or other utilities
  • environmental monitoring or control provisions

Components outside the direct system boundary may still be dependencies requiring verification. For example, a laboratory network may be managed as qualified infrastructure, but the instrument’s connection, address, communication path, and applicable network services remain part of IQ.

The following illustration distinguishes the qualified analytical system from its supporting utilities, network, and environment.

Analytical IQ system boundary showing instrument modules, workstation, software, firmware, data storage, interfaces, utilities, network, and environment.
IQ must address the complete installed analytical system and its critical infrastructure dependencies.

4. IQ Planning and Prerequisites

IQ should be performed against an approved protocol or other controlled record with predefined verification steps, evidence requirements, responsibilities, and acceptance criteria.

The article is guidance for preparing and executing IQ; it is not an executable protocol for every instrument type.

Before IQ begins, the following should be available or formally addressed:

  • approved intended use and system boundary
  • approved user requirements
  • completed design review or Design Qualification, when applicable
  • approved qualification strategy
  • purchase order, approved quotation, or configuration specification
  • supplier installation instructions
  • installation site and required utilities
  • instrument inventory or asset-management process
  • applicable software and infrastructure approvals
  • approved IQ protocol or controlled checklist
  • trained personnel authorized to perform or witness the work
  • defined deviation and change-control processes

Not every prerequisite must be contained in the IQ protocol, but the protocol should identify the governing records and confirm that execution conditions are suitable.


5. Receipt and Delivery Verification

Receipt verification confirms that the delivered system corresponds to the approved order and has not suffered evident shipping damage. Typical checks include:

  • supplier and manufacturer
  • purchase order or procurement reference
  • instrument model
  • ordered modules and options
  • accessories and peripherals
  • computer equipment
  • software licenses or entitlement information
  • cables, connectors, tubing, and installation kits
  • manuals and certificates
  • shipping containers and damage indicators
  • visible condition of the delivered equipment
  • discrepancies between ordered and received items

Shipping damage, missing components, incorrect models, or substituted parts should be documented before installation proceeds. The impact on qualification and the approved design must be evaluated rather than treating receipt discrepancies as administrative issues.


6. Identification and Asset Traceability

Each significant component should be identified sufficiently to establish traceability throughout the instrument lifecycle. Identification may include:

  • site equipment or asset number
  • manufacturer
  • model number
  • serial number
  • module type
  • workstation asset number
  • computer name
  • network hostname
  • software product and version
  • firmware version
  • license identifier where relevant
  • installation location
  • department or system owner

The required level of component identification depends on risk and replaceability. Critical modules, computers, and independently calibrated devices usually require individual identification. Low-risk consumable items generally do not.

Equipment labels should be legible, consistent with site procedures, and applied without obstructing ventilation, safety markings, or supplier labels.


7. Installed Hardware and Physical Configuration

IQ should verify that the installed hardware matches the approved configuration, bill of materials, design record, or procurement specification. Verification should address:

  • instrument base unit
  • measurement and control modules
  • detectors
  • sample-handling devices
  • pumps, valves, injectors, ovens, or temperature-control units
  • computers and monitors
  • data-acquisition hardware
  • interface cards
  • printers and barcode devices
  • uninterruptible power supplies
  • required cables, tubing, fittings, and accessories
  • safety guards, interlocks, shields, and covers
  • component arrangement and module connections

The physical installation should also be checked against manufacturer instructions and site requirements, including:

  • stable and level support
  • adequate bench strength
  • required clearance
  • ventilation
  • service accessibility
  • protection from vibration, direct sunlight, dust, moisture, or corrosive conditions
  • safe routing of electrical cables, gases, tubing, and drains
  • separation from incompatible laboratory activities
  • ergonomic access for routine use and maintenance

IQ confirms that these conditions exist at installation. Where continued environmental control is critical, routine monitoring belongs to the operational lifecycle program.


8. Utilities and Environmental Conditions

Required utilities should be identified in the approved requirements or supplier installation specifications and verified at the point of use. Applicable checks may include:

  • voltage and frequency
  • electrical outlet type
  • grounding
  • power capacity
  • uninterruptible or conditioned power
  • gas identity
  • gas purity
  • gas pressure and flow
  • compressed air
  • vacuum
  • water quality
  • cooling-water conditions
  • exhaust
  • drainage
  • temperature
  • relative humidity
  • vibration
  • electromagnetic interference
  • lighting or protection from direct sunlight

The verification method should be proportionate to the requirement. Recording a utility specification without confirming the installed condition is insufficient.

Measuring devices used to verify critical utilities or environmental conditions should have suitable calibration status. Recorded results should identify the measuring device when traceability is necessary.

Conditions outside approved limits should be corrected or assessed through the deviation process before the affected installation is accepted.


9. Computer and Network Installation

When a computer or network supports instrument operation, acquisition, processing, review, storage, or transfer of regulated data, IQ should document the installed computing environment. Applicable information may include:

  • computer manufacturer, model, and asset number
  • processor, memory, and storage configuration
  • operating-system edition, version, and patch level
  • computer name and network hostname
  • network address configuration where appropriate
  • domain or workgroup membership
  • required network services
  • time-synchronization source
  • antivirus or endpoint-protection status
  • firewall status and approved communication rules
  • connected printers and peripherals
  • backup agent or data-protection service
  • remote-support components
  • database or application-server connections
  • virtualization details when applicable

IQ should verify the presence and identity of these elements. Detailed challenge testing of access control, backup, audit trails, calculations, and electronic workflows belongs in OQ or the associated analytical instrument software validation activities.

Network verification should establish that approved connections exist. It should not involve uncontrolled changes to qualified infrastructure.


10. Software and Firmware Versions

Installed software and firmware must be identified because version changes can alter instrument operation, calculations, security, data formats, interfaces, and qualification status. IQ should document, as applicable:

  • application name
  • application version
  • build or release number
  • installed modules
  • enabled options
  • license type and status
  • operating-system version
  • database version
  • instrument firmware versions
  • driver versions
  • interface or middleware versions
  • approved patches or hotfixes
  • language or regional settings when relevant
  • installation package or source
  • installation date
  • installer identity

The recorded versions should be compared with the approved design and supplier recommendations. Unplanned version differences require documented assessment. A newer version is not automatically acceptable merely because it was supplied by the vendor.

Installation records, checksums, supplier release documentation, or controlled installation media may be retained where required by the software-assurance strategy.


11. Configuration Baseline

IQ should establish a reproducible baseline describing the system as installed before functional testing. The baseline may include:

  • installed hardware and modules
  • enabled software features
  • firmware versions
  • instrument addresses and module assignments
  • workstation and server identification
  • communication settings
  • regional settings
  • system date, time, and time zone
  • data-storage locations
  • configured interfaces
  • report or file-output locations
  • backup-related configuration
  • security-policy settings
  • initial user roles
  • configurable operating limits
  • default settings reviewed during installation

The baseline should be detailed enough to support change assessment, troubleshooting, restoration, periodic review, and requalification decisions.

IQ should not document passwords, private keys, or other authentication secrets. The record should confirm that required security controls were configured without exposing protected credentials.

After approval, changes to the baseline should be managed through change control or another approved configuration-management process.


12. Interfaces and Data Paths

Interfaces should be verified where they form part of the approved system design. Examples include:

  • instrument-to-workstation communication
  • workstation-to-database communication
  • chromatography data-system connections
  • network storage
  • LIMS interfaces
  • middleware
  • balance or barcode-reader connections
  • printer connections
  • export directories
  • backup destinations
  • time-synchronization services
  • identity-management services

IQ should confirm that the interface is installed, identified, connected, and configured as designed. Testing whether information is transferred completely and accurately under normal and abnormal conditions generally belongs to OQ or separate interface qualification.

For regulated electronic records, the installation should support the controls described in 21 CFR 211.68 and, where applicable, 21 CFR Part 11.


13. Initial Security Setup

IQ should confirm that required security foundations are installed and configured before functional security testing begins. Applicable checks include:

  • unique named accounts can be supported
  • shared or generic administrator access is restricted
  • administrative roles are assigned to authorized personnel
  • routine users are separated from administrators
  • default vendor passwords have been changed or otherwise controlled
  • password settings are configured according to approved requirements
  • account lockout or session controls are configured where supported
  • system date, time, and time zone are correct
  • audit-trail capability is enabled where required
  • users cannot routinely alter the system clock
  • operating-system access is appropriately restricted
  • remote-access mechanisms are approved and controlled
  • service accounts are identified and managed
  • data directories are protected from unauthorized modification or deletion

IQ confirms the installed settings. OQ should challenge the effectiveness of applicable controls, including permissions, prohibited actions, audit-trail generation, electronic signatures, and record protection.

FDA’s Data Integrity and Compliance With Drug CGMP guidance should be considered when defining controls for computerized analytical systems and regulated laboratory records.


14. Documentation Verification

IQ should verify that documentation necessary for safe operation, qualification, maintenance, calibration, support, and system administration is available and appropriate.

Documentation may include:

  • operating manuals
  • installation manuals
  • maintenance manuals
  • technical specifications
  • wiring, tubing, or connection diagrams
  • spare-parts information
  • software administration guides
  • software release notes
  • firmware information
  • license records
  • calibration certificates
  • material certificates where relevant
  • supplier IQ or OQ documentation
  • factory acceptance test records
  • configuration records
  • backup and recovery instructions
  • service contact information
  • warranty documentation

Supplier records may be leveraged after confirming that they apply to the actual model, configuration, software version, serial number, and intended installation. Receipt of a supplier document does not, by itself, establish its adequacy.

Controlled copies or approved references should be retained according to the site document-management system.


15. Calibration Status

IQ should verify the calibration or certification status of components that require calibration before OQ. Applicable items may include:

  • internal temperature sensors
  • pressure devices
  • flow devices
  • wavelength or detector standards
  • balances supplied with the system
  • external thermometers
  • reference weights
  • vendor test equipment used during installation
  • other measurement devices used to establish installation acceptance

Calibration certificates should be reviewed for:

  • clear identification of the calibrated item
  • calibration date
  • result or conformity statement
  • applicable limits
  • traceability
  • due date or assigned interval
  • authorized approval
  • relevance to the installed instrument or module

IQ should not duplicate the site’s calibration control for analytical instruments. Its purpose is to confirm that the required calibration state exists before qualification testing begins.

Under 21 CFR 211.160(b)(4), laboratory instruments must be calibrated at suitable intervals under an established written program with directions, schedules, limits, and remedial provisions. Associated laboratory calibration records are addressed in 21 CFR 211.194(d).


16. IQ Execution and Evidence

IQ records should show what was checked, how it was checked, the result, the evidence reviewed, and who performed and reviewed the activity.

Good execution practices include:

  • following the approved protocol in sequence
  • recording results when the work is performed
  • using permanent and attributable records
  • identifying supporting documents and attachments
  • recording actual values where acceptance depends on a measured value
  • avoiding unexplained blank fields
  • documenting corrections according to good documentation practices
  • identifying test equipment used for critical measurements
  • retaining relevant screenshots, reports, photographs, or configuration exports
  • documenting every departure from the approved protocol

A simple “pass” may be adequate for an objective presence check. It is usually inadequate when acceptance depends on a model number, serial number, software version, measured condition, or configuration value.


17. Deviations, Discrepancies, and Reverification

Any difference between the approved requirement and the observed installation should be documented and assessed.

Each IQ deviation should address:

  • the affected protocol step or requirement
  • the observed condition
  • the expected condition
  • the affected component or configuration
  • potential impact on intended use, data integrity, safety, and subsequent testing
  • immediate correction, when applicable
  • corrective or preventive action
  • required reverification
  • disposition and approval
  • effect on readiness for OQ

Not every discrepancy prevents OQ. A minor documentation issue may be acceptable with a justified action plan if it does not compromise installation integrity or testing. A missing critical module, incorrect software version, unsuitable utility, uncontrolled administrator account, or unresolved data-path problem may prevent meaningful OQ execution.

The following illustration shows the decision path from completed IQ checks through deviation assessment, baseline approval, and release to OQ.

Installation Qualification deviation assessment and approval process leading to Operational Qualification readiness.
Deviations must be assessed, corrected where necessary, and reverified before the installed baseline is approved.

18. IQ Acceptance and Readiness for OQ

IQ is acceptable when the approved acceptance criteria have been met and the evidence supports a controlled installed baseline.

The final review should confirm that:

  • the correct instrument and components were received
  • equipment and software are uniquely identified
  • the installed configuration matches the approved design or accepted changes
  • utilities and environmental conditions are suitable
  • computer and network installation is documented
  • software, firmware, drivers, and interfaces are identified
  • security foundations are configured
  • required documentation is available
  • calibration status is acceptable
  • critical installation evidence is complete
  • deviations have been resolved or appropriately justified
  • the baseline is approved and placed under change control
  • the system is ready for OQ

Approval should be performed by authorized functions defined in the qualification plan or site procedures. Quality-unit involvement should be proportionate to the instrument’s GMP impact and the organization’s quality system.

The IQ conclusion should state what system and configuration were accepted. It should not merely state that “IQ passed.”


19. Supplier IQ Documentation

Supplier-generated IQ documentation can reduce duplication when it is technically sound and applicable to the installed system. It should not be accepted without review. Before relying on supplier documentation, confirm that:

  • the protocol applies to the correct model and configuration
  • the executed record identifies the actual system
  • acceptance criteria are predefined and appropriate
  • results and evidence are complete
  • deviations are documented
  • test equipment is appropriately controlled
  • software and firmware versions are recorded
  • the scope aligns with the approved system boundary
  • site-specific utilities, infrastructure, security, and interfaces are addressed
  • supplier approvals and execution records are complete

Site-specific supplements are commonly required for equipment identification, location, network configuration, user administration, data storage, backup, interfaces, calibration-program enrollment, and document control.

Supplier evidence should be leveraged according to the approved qualification strategy, not copied into the validation package without evaluation.


20. Changes After IQ Approval

IQ establishes a baseline, but it does not freeze the system permanently. Subsequent changes should be assessed for their effect on the approved installation and qualification state. Examples include:

  • instrument relocation
  • module addition or replacement
  • workstation replacement
  • operating-system change
  • software upgrade
  • firmware update
  • network or domain change
  • data-storage change
  • interface modification
  • security-configuration change
  • utility modification
  • major repair
  • restoration from backup or system image

The impact assessment should determine whether documentation updates, installation checks, calibration, regression testing, OQ testing, or broader requalification are required.

A complete original IQ record should not be overwritten to represent the new state. The approved baseline should be maintained through controlled change records and supplemental qualification evidence.


21. Common Installation Qualification Weaknesses

Common weaknesses include:

  • using a generic protocol that does not match the installed configuration
  • limiting IQ to the physical instrument while omitting the computer, software, network, storage, and interfaces
  • failing to record serial numbers or version information
  • recording expected values instead of observed values
  • accepting supplier documents without assessing applicability
  • performing extensive functional testing in IQ without clear phase rationale
  • treating successful software launch as evidence of software validation
  • failing to document default accounts or passwords
  • omitting time, time-zone, and synchronization settings
  • accepting calibration certificates without confirming instrument identity
  • leaving configuration differences unexplained
  • proceeding to OQ with unresolved installation conditions
  • changing the system after IQ without change control
  • using IQ approval language that does not identify the accepted baseline

These weaknesses reduce traceability and make later changes, investigations, repairs, and requalification more difficult.


22. Conclusion

Analytical instrument Installation Qualification establishes the verified installation and configuration baseline on which subsequent functional and performance testing depend.

Effective IQ confirms the identity, location, components, utilities, environment, computing platform, software and firmware versions, interfaces, security setup, documentation, and calibration status of the complete analytical system. It also ensures that discrepancies are assessed and that the approved baseline is controlled before OQ begins.

IQ should be detailed enough to make the installed state reproducible and reviewable, but it should not duplicate OQ. Its central question is straightforward: Has the approved analytical system been correctly installed and documented so that meaningful operational testing can begin?