Preventive Maintenance and System Reliability Strategy

A reliable GMP maintenance program combines scheduled preventive maintenance, condition-based monitoring, predictive analysis, and corrective maintenance. The appropriate strategy depends on the equipment’s intended function, credible failure modes, detectability of degradation, historical performance, and consequences of failure.

Maintenance supports the qualified state by preserving approved design, operating capability, control functions, cleanliness, and measurement reliability. Completion of a maintenance work order alone does not demonstrate that equipment remains suitable for GMP use. A documented assessment, appropriate post-maintenance testing, and formal return-to-service decision may also be required.

Calibration is closely connected to maintenance but is governed through a separate calibration program.


Purpose and Scope

The purpose of a maintenance and reliability program is to ensure that facilities, utilities, equipment, instruments, and supporting systems remain capable of performing their intended GMP functions throughout their operational lives.

The program may apply to:

  • Manufacturing and packaging equipment
  • Process-support equipment
  • Clean utilities and utility-generation systems
  • HVAC and environmental-control systems
  • Cleaning, sterilization, and sanitization equipment
  • Laboratory instruments
  • Material-handling and storage equipment
  • Automation hardware and control components
  • Safety, alarm, and interlock systems
  • Facility infrastructure affecting GMP operations
  • Components embedded within larger qualified systems
  • Portable or temporary equipment used in GMP operations

Not every asset requires the same maintenance strategy. Program inclusion, task selection, interval, monitoring, documentation, testing, and approval requirements should reflect the actual function and failure consequences of the asset.

Detailed maintenance controls for analytical instruments may be addressed separately within the analytical-instrument program.


Maintenance and System Reliability

Reliability is the ability of an asset or system to perform its intended function under defined conditions for the required operating period.

In a GMP environment, reliability involves more than equipment uptime. A system may continue operating while experiencing unstable control, inaccurate measurement, loss of alarm capability, contamination risk, or degraded performance.

The reliability assessment should consider:

  • Functional availability
  • Operation within approved ranges
  • Resistance to credible failure modes
  • Detectability of deterioration
  • Consistency of process control
  • Alarm and interlock performance
  • Contamination prevention
  • Maintainability and repair capability
  • Availability of critical spare parts
  • Redundancy and backup capacity
  • Recovery following failure
  • Continued support of the qualified state

Maintenance controls should protect the functions that matter to product quality, patient safety, data integrity, process control, and GMP compliance. Maximizing equipment availability cannot override these requirements.


Regulatory and Quality-System Basis

For pharmaceutical manufacturing, 21 CFR 211.67 requires equipment and utensils to be maintained at appropriate intervals to prevent malfunctions or contamination that could affect drug-product quality. It also requires written procedures addressing responsibilities, schedules, methods, materials, disassembly, reassembly, inspection, and records.

21 CFR 211.68(a) requires automatic, mechanical, and electronic equipment to be routinely calibrated, inspected, or checked according to a written program designed to assure proper performance.

21 CFR 211.100 provides supporting requirements for approved written procedures and documented execution. Maintenance affecting production and process controls should be performed consistently with these procedural controls.

21 CFR 211.182 establishes equipment cleaning and use-log requirements, including maintenance where applicable.

For medical-device manufacturing, the FDA’s Quality Management System Regulation became effective on February 2, 2026. The QMSR incorporates ISO 13485:2016 into 21 CFR Part 820, including applicable controls for infrastructure, equipment, monitoring, servicing, and quality-system processes. Former §820.70 and §820.72 should not be presented as the current standalone requirements.

Regulations establish the required control framework but do not prescribe one maintenance strategy or interval for every asset. The manufacturer must define technically justified controls appropriate to intended use and risk.


Governance and Responsibilities

The maintenance program should be governed by approved procedures defining responsibilities, planning, execution, documentation, escalation, testing, and return-to-service controls.

Responsibilities commonly include:

  • Asset owner: Defines intended use, operating requirements, availability needs, and production constraints.
  • Engineering or Maintenance: Manages the maintenance program, technical procedures, schedules, spare parts, and work execution.
  • Maintenance personnel: Perform work according to approved instructions and document the as-found and as-left conditions.
  • Operations: Report abnormal conditions, make equipment available, and verify approved status before use.
  • Metrology or Calibration: Determines whether maintenance affects calibration status and performs required calibration or verification.
  • Automation or IT: Controls software, firmware, configuration, access, backup, and electronic maintenance records.
  • Validation: Evaluates qualification impact and defines required post-maintenance verification or requalification.
  • Quality: Reviews significant failures, deviations, deferrals, impact assessments, qualification decisions, and program effectiveness.
  • Service providers: Perform assigned work according to approved site requirements and provide complete records.

The program should define who may change tasks, frequencies, condition limits, parts, settings, maintenance classifications, and equipment status.


Asset Inventory and GMP Criticality

Maintainable assets should be uniquely identified and included in a controlled inventory when their performance can affect a GMP operation or supported system.

The inventory should contain, as applicable:

  • Asset identification number
  • Description and location
  • Manufacturer, model, and serial number
  • Associated system or equipment train
  • Intended function
  • GMP impact and criticality
  • Critical components
  • Maintenance strategy
  • Maintenance tasks and intervals
  • Condition-monitoring requirements
  • Responsible department
  • Service-provider information
  • Calibration dependencies
  • Qualification status
  • Critical-spare requirements
  • Current operating and maintenance status
  • Last and next scheduled maintenance
  • Change, relocation, replacement, and retirement status

Asset criticality should be based on the use and consequences of failure, not merely on the equipment name, replacement cost, or department ownership.

The assessment should consider whether failure could:

  • Affect product quality or patient safety
  • Cause contamination or loss of containment
  • Affect a critical process parameter
  • Compromise a utility or environmental condition
  • Disable an alarm, interlock, or safeguard
  • Produce unreliable measurements or records
  • Affect batch acceptance or disposition
  • Invalidate qualification or validation evidence
  • Remain undetected before GMP impact
  • Disable required redundancy or backup capability

A risk-based validation approach may support classification and control selection. A numerical score alone should not determine the required maintenance strategy.


Failure Modes and Maintenance Needs

Maintenance should be directed toward defined functions and credible failure modes.

The assessment should identify:

  • What function the asset or component performs
  • How that function could degrade or fail
  • Causes and mechanisms of failure
  • Whether degradation is gradual or sudden
  • Whether the condition can be detected before functional failure
  • Available monitoring parameters
  • Consequences of failure
  • Existing redundancy or backup capacity
  • Time available to respond
  • Appropriate maintenance or replacement action
  • Required post-maintenance testing

Typical failure mechanisms include:

  • Wear
  • Corrosion
  • Fouling
  • Leakage
  • Misalignment
  • Loss of lubrication
  • Seal, gasket, or filter deterioration
  • Electrical or electronic component failure
  • Sensor drift
  • Software or firmware malfunction
  • Loss of configuration
  • Material degradation
  • Fatigue
  • Environmental exposure
  • Improper adjustment
  • Repeated temporary repair

One asset may require different maintenance strategies for different components. For example, a pump may receive scheduled lubrication, condition-based vibration monitoring, predictive bearing analysis, and corrective seal replacement.


Preventive, Condition-Based, Predictive, and Corrective Maintenance

The maintenance program should distinguish the following strategies:

StrategyTriggerTypical applicationImportant limitation
Preventive maintenancePredetermined time, operating hours, cycles, or production quantityLubrication, scheduled inspection, filter replacement, seal replacementA fixed schedule may cause unnecessary intervention or fail to detect degradation developing between tasks
Condition-based maintenanceA measured or observed condition reaches an established criterionDifferential pressure, vibration, temperature, leakage, wear, oil conditionRequires reliable monitoring, justified limits, defined response, and controlled data
Predictive maintenanceTrending, modeling, or diagnostic analysis forecasts degradation or likely failureVibration trending, motor-current analysis, thermal imaging, performance modelingPredictions must be technically supportable and cannot become uncontrolled automatic release decisions
Corrective maintenanceA defect, failure, or unacceptable condition has been detectedRepair, replacement, troubleshooting, restorationRestoring operation does not by itself resolve potential GMP impact before failure detection

Predictive maintenance normally uses condition data but applies analysis to estimate future performance or remaining service life. It is therefore related to, but more analytically advanced than, condition-based maintenance.

Corrective maintenance is not automatically unacceptable. Run-to-failure may be appropriate for noncritical components where failure is readily detected and cannot reasonably affect product quality, system control, or the qualified state.

Maintenance strategy selection diagram distinguishing preventive, condition-based, predictive, and corrective maintenance based on failure mode, detectability, and GMP consequences.
Maintenance strategy is selected for the specific function and failure mode; one asset may require a combination of preventive, condition-based, predictive, and corrective controls.

Selecting the Appropriate Maintenance Strategy

Strategy selection should begin with the failure mode rather than a default calendar interval.

Available approaches include:

  • Calendar-based preventive maintenance
  • Usage-based preventive maintenance
  • Condition-based intervention
  • Predictive analysis
  • Planned corrective maintenance
  • Run-to-failure with corrective response
  • Combination strategies

The selection should consider:

  • GMP criticality
  • Failure consequence
  • Failure mechanism
  • Detectability of deterioration
  • Rate and predictability of degradation
  • Availability and reliability of condition data
  • Equipment duty and operating environment
  • Historical failure performance
  • Redundancy
  • Repair time and spare-part availability
  • Manufacturer recommendations
  • Regulatory or technical requirements
  • Risk introduced by maintenance intervention itself

Run-to-failure should not be selected where failure could affect product quality, cause contamination, disable a critical control, or remain undetected until after GMP impact.

The selected strategy and rationale should be documented at the asset, component, or task level.


Developing Maintenance Tasks and Procedures

Each maintenance task should have a defined technical purpose. A task that does not prevent, detect, predict, or correct a relevant failure mode has no demonstrated maintenance value.

Maintenance procedures should define, as applicable:

  • Asset, component, and function addressed
  • Failure mechanism controlled
  • Work trigger or interval
  • Required personnel and qualifications
  • Tools and test equipment
  • Approved replacement parts and materials
  • Safety and isolation requirements
  • Disassembly and reassembly instructions
  • Cleanliness and contamination controls
  • Lubrication, torque, alignment, or adjustment requirements
  • Critical settings and configuration
  • Inspection and acceptance criteria
  • Required calibration
  • Required functional or qualification testing
  • Conditions requiring escalation
  • Documentation and review requirements
  • Return-to-service requirements

Instructions should be sufficiently detailed to ensure consistent execution without preventing qualified personnel from documenting legitimate abnormal findings or additional necessary work.


Establishing Maintenance Intervals and Triggers

Maintenance intervals and intervention triggers should be established before routine operation and periodically reassessed.

Intervals may be based on:

  • Calendar time
  • Operating hours
  • Cycle count
  • Production quantity
  • Environmental exposure
  • Component life
  • Condition-monitoring results
  • Historical degradation
  • Failure data
  • Regulatory or technical requirements

The assessment should consider:

  • Asset criticality
  • Failure consequences
  • Equipment design and stability
  • Manufacturer recommendations
  • Frequency and severity of use
  • Operating environment
  • Maintenance history
  • Failure between scheduled tasks
  • Condition-monitoring effectiveness
  • Spare-part availability
  • Risk created by excessive disassembly or intervention

Manufacturer recommendations may provide an initial interval, but they should not automatically become the permanent GMP interval.

Intervals may be shortened when there is adverse degradation, repeated failure, early component wear, or inadequate detection. They may be extended when sufficient performance history demonstrates sustained control and the change is approved through the applicable quality-system process.


Condition Monitoring and Predictive Analysis

Condition-based and predictive strategies depend on controlled, reliable information.

The program should define:

  • Parameter being monitored
  • Measurement method
  • Data-collection frequency
  • Baseline condition
  • Alert and action criteria
  • Trend period
  • Data-review responsibility
  • Required response time
  • Work-order or escalation trigger
  • Sensor calibration requirements
  • Data-quality controls
  • Prediction limitations
  • Required confirmation before intervention

Possible monitoring techniques include:

  • Vibration analysis
  • Thermal imaging
  • Oil or lubricant analysis
  • Motor-current analysis
  • Differential-pressure trending
  • Temperature trending
  • Acoustic or ultrasonic inspection
  • Leak detection
  • Performance or efficiency trending
  • Visual wear measurements

Predictive software should support qualified technical judgment. Its output should not automatically extend maintenance, release equipment, or override an established action limit unless the decision logic has been appropriately assessed and controlled.


Planning, Scheduling, and Work Control

Maintenance work should be planned and controlled according to its technical scope and GMP impact.

Work control should address:

  • Work request and priority
  • Equipment identification
  • Current equipment status
  • Required shutdown and isolation
  • Production and Quality coordination
  • Applicable procedure
  • Required permits
  • Tools, parts, and materials
  • Contamination and foreign-material controls
  • Calibration and test requirements
  • Qualification-impact review
  • Change-control or deviation requirements
  • Required approvals
  • Release responsibility

The system should distinguish routine scheduled work from urgent corrective, emergency, deferred, or overdue maintenance.

Maintenance should not begin under an incomplete or inaccurate work order when the missing information could affect execution, testing, or GMP assessment.


Spare Parts, Materials, and Technical Equivalence

Maintenance reliability depends on appropriate control of replacement parts and materials.

Controls should address:

  • Approved specifications
  • Critical-spare identification
  • Manufacturer and part number
  • Original and equivalent components
  • Materials of construction
  • Dimensions and capacity
  • Software or firmware compatibility
  • Storage conditions
  • Shelf life
  • Obsolescence
  • Part traceability where required
  • Lubricants, sealants, filters, and gaskets
  • Product-contact or process-contact suitability
  • Cleaning and sterilization compatibility
  • Inspection or testing before use

A replacement described as equivalent still requires technical evaluation when its material, dimensions, performance, capacity, firmware, signal behavior, or operating characteristics could affect qualified operation.

Substitution of a component may require change control, calibration, functional testing, or requalification.


Maintenance Execution and Documentation

Maintenance should be performed by trained and qualified personnel using approved instructions.

Execution records should document:

  • As-found condition
  • Reported symptom or work trigger
  • Inspection and diagnostic findings
  • Work actually performed
  • Parts and materials used
  • Settings or adjustments changed
  • Unexpected conditions
  • Deviations from the approved instruction
  • As-left condition
  • Test and inspection results
  • Calibration performed
  • Equipment status
  • Technician and reviewer
  • Date and time of work
  • Associated change, deviation, or investigation

Pre-entered statements should not be accepted without confirmation that the described activity was actually completed.

If the work scope changes after execution begins, the additional work and its impact should be assessed and documented rather than concealed under the original task description.


Corrective, Breakdown, and Emergency Maintenance

Corrective maintenance should distinguish among:

  • Planned correction of a detected nonurgent defect
  • Deferred corrective work under approved controls
  • Unplanned breakdown maintenance
  • Emergency maintenance
  • Temporary repair
  • Permanent repair
  • Repetitive repair indicating an unresolved cause

The response to a failure should include:

  • Control of the affected equipment
  • Description of the failure
  • Determination of the affected function
  • Assessment of materials, batches, records, and operations
  • Identification of the failure period where possible
  • Repair or replacement
  • Calibration or testing
  • Qualification-impact determination
  • Investigation or CAPA when warranted
  • Documented return to service

Emergency circumstances may require immediate action to protect personnel, product, facilities, or equipment. The work must still be documented retrospectively, assessed for GMP impact, and subjected to required testing before routine GMP use resumes.

A temporary repair should have a defined limitation, monitoring requirement, approval, and expiration or replacement date.


Deferred and Overdue Maintenance

Deferred maintenance is work intentionally postponed through an approved assessment. Overdue maintenance is work not completed by its established due date.

Neither condition proves that equipment has failed, but the scheduled control has not been performed as planned.

The assessment should consider:

  • Asset criticality
  • Purpose of the task
  • Failure mode being controlled
  • Current equipment condition
  • Operating exposure since the due date
  • Available monitoring information
  • Failure and maintenance history
  • Redundancy
  • Length of the proposed extension
  • Interim controls
  • Latest permissible completion date
  • Required approval authority

Continued operation should be limited to the conditions supported by the assessment. Production demand alone is not technical justification for postponement.

Repeated extensions or recurring overdue maintenance should be evaluated through Periodic Review and Continued Verification as a program deficiency rather than normalized through repeated individual approvals.


Maintenance Impact Assessment

Maintenance impact should be determined from the affected function, not the name assigned to the work order.

The assessment should determine whether the work affects:

  • Approved design
  • Materials of construction
  • Product-contact surfaces
  • Equipment capacity or operating range
  • Critical parameters
  • Sensors and measurement functions
  • Alarms or interlocks
  • Automated controls
  • Software, firmware, or configuration
  • Utility connections
  • Cleanability or sterility
  • Environmental-control performance
  • Data generation or retention
  • Previously qualified functions

For example, filter replacement in a noncritical enclosure fan may require only inspection. HEPA-filter replacement in a classified area may require installation verification, integrity testing, and environmental assessment.

Replacement of a pump with an identical approved spare may require targeted functional testing. A replacement that changes capacity, materials, control behavior, or process performance may require change control and requalification.

A documented change-impact assessment should be initiated when the work changes an approved characteristic or creates a potential effect beyond routine restoration.

Maintenance and qualified-state lifecycle connecting work planning, controlled maintenance, affected-function assessment, calibration and testing, formal return to GMP service, operation, reliability monitoring, and program review.
Maintenance supports the qualified state through controlled execution, assessment of affected functions, appropriate testing, formal release, and feedback from operating experience.

Calibration and Post-Maintenance Testing

Maintenance can affect calibration, alignment, installation, control behavior, alarms, utilities, cleanliness, and system performance.

Post-maintenance activities may include:

  1. Documentation review
  2. Visual or installation verification
  3. Calibration
  4. Functional check
  5. Alarm or interlock challenge
  6. Leak, pressure, flow, integrity, or performance testing
  7. Cleaning or environmental verification
  8. Targeted Operational Qualification testing
  9. Targeted Performance Qualification testing
  10. Comprehensive requalification
  11. Product, batch, utility, environmental, or data-impact assessment

The required testing should be linked directly to the affected functions and credible failure conditions.

Testing should confirm the relevant as-left condition. A simple startup check is not sufficient when maintenance could affect critical operating ranges, controls, alarms, interlocks, cleanliness, or performance.


Requalification and the Qualified State

The qualified state is maintained when equipment continues to conform to approved design and performs its intended functions within established limits.

Maintenance preserves the qualified state only when:

  • Approved design and function are retained or restored
  • Required parts and materials are acceptable
  • Critical settings and configuration remain controlled
  • Instrument calibration is acceptable
  • Functional checks confirm correct operation
  • Alarms, interlocks, controls, and safeguards remain effective
  • Cleaning and contamination controls are satisfied
  • Qualification impact is assessed
  • Required testing is completed and reviewed
  • Equipment is formally released before GMP use

Completion of the work order alone is not evidence that the qualified state was maintained.

The scope of risk-based requalification should correspond to the affected functions, uncertainty introduced by the work, available evidence, and potential GMP consequences.

Post-maintenance verification decision connecting affected equipment functions to inspection, calibration, functional testing, targeted qualification, comprehensive requalification, results review, and formal return to GMP service.
Post-maintenance verification is based on the functions affected and the uncertainty introduced, rather than the maintenance work-order category alone.

Change-Control Interface

Maintenance restores equipment to its approved condition. Change control governs intentional changes to approved design, configuration, use, or control strategy.

Change control may be required for:

  • Non-equivalent component replacement
  • Material changes
  • Capacity changes
  • New or altered operating ranges
  • Software or firmware updates
  • Configuration changes
  • Control-loop changes
  • Alarm or interlock modifications
  • Relocation
  • Utility changes
  • Maintenance-strategy changes
  • Interval extensions
  • New lubricants, sealants, filters, or gaskets
  • Permanent replacement of a temporary repair
  • Changes affecting qualification documentation

The organization should avoid classifying a design or configuration change as routine maintenance solely to bypass change-control requirements.


Return to GMP Service

Return to service should be a documented status decision rather than an assumption following completion of physical work.

Before release, responsible personnel should confirm, as applicable:

  • Work was completed against an approved instruction
  • As-found and as-left conditions were documented
  • Parts and materials were recorded
  • Temporary controls were removed or formally retained
  • Tools and foreign materials were accounted for
  • Equipment was cleaned and inspected
  • Critical settings and configuration were verified
  • Calibration was completed
  • Functional testing was accepted
  • Qualification testing was completed
  • Deviations were assessed
  • Impact assessments were approved
  • Records and attachments were complete
  • Equipment status was updated
  • Required Quality approval was obtained

Equipment should remain unavailable for unrestricted GMP use until all release prerequisites have been satisfied.


Maintenance Records and Data Integrity

Maintenance records should provide a complete and traceable history of the condition of the asset and the work performed.

Records should include:

  • Asset identification
  • Work trigger or reported condition
  • Date and time
  • Task or procedure
  • As-found condition
  • Diagnosis
  • Parts and materials used
  • Adjustments and settings
  • Work performed
  • As-left condition
  • Inspection and test results
  • Calibration performed
  • Deviations or unexpected conditions
  • Technicians and reviewers
  • Downtime
  • Impact assessment
  • Qualification determination
  • Release decision
  • Related change control, investigation, or CAPA

Electronic maintenance-management systems should provide appropriate access control, status control, record protection, attachment retention, backup, and audit trails where applicable.

Electronic records used to support regulated decisions should be evaluated within the broader 21 CFR Part 11 compliance and data-integrity framework.


Reliability Trending and Program Review

The maintenance program should be periodically reviewed to determine whether its strategies, tasks, intervals, resources, and controls remain effective.

The review may consider:

  • Scheduled-maintenance completion
  • Deferred and overdue work
  • Repeat failures
  • Emergency maintenance
  • Failure between scheduled tasks
  • Equipment downtime
  • Mean time between failures where useful
  • Condition-monitoring alerts
  • Adverse performance trends
  • Spare-part consumption
  • Maintenance-induced deviations
  • Post-maintenance test failures
  • Out-of-tolerance calibration following maintenance
  • Recurring temporary repairs
  • Service-provider performance
  • CAPA effectiveness
  • Task and interval suitability
  • Asset obsolescence

Absence of reported failures does not independently demonstrate program effectiveness. Failures may remain undetected or be inadequately reported.

Detailed evaluation of maintenance and calibration performance is addressed in Periodic Review and Continued Verification.

Review outcomes may support:

  • Revising maintenance strategies
  • Adding or removing tasks
  • Shortening or extending intervals
  • Improving condition monitoring
  • Replacing unreliable equipment
  • Increasing critical-spare availability
  • Revising procedures
  • Strengthening service-provider controls
  • Initiating CAPA
  • Performing requalification

Asset Replacement and Retirement

Asset replacement and retirement should be controlled and documented.

The process should address:

  • Removal from active maintenance schedules
  • Equipment-status updates
  • Change-control requirements
  • Replacement-equipment suitability
  • Spare-part disposition
  • Qualification and calibration impact
  • Historical-record retention
  • Electronic-data retention
  • Decontamination
  • Disposal or transfer
  • Prevention of unintended reuse
  • Update of drawings, inventories, and system documentation

An asset removed from the maintenance program should not remain available for unrestricted GMP use.


Conclusion

A compliant maintenance and system-reliability program does more than schedule recurring work. It identifies critical assets and failure modes, selects an appropriate combination of preventive, condition-based, predictive, and corrective maintenance, and controls the work from planning through documented return to service.

Maintenance outcomes must be connected to the qualified state. When work can affect measurement, installation, control, cleanliness, alarms, configuration, or performance, appropriate calibration, functional testing, impact assessment, and requalification must be completed before GMP use resumes.

Reliability is demonstrated through controlled performance and accumulated evidence—not simply through equipment uptime or closure of maintenance work orders.