Written and maintained by CASRAI Editorial Board
Last updated
Cleaning validation is the documented proof that a defined cleaning procedure, applied to a defined piece of equipment, consistently removes residues of a previous product, cleaning agent, and microbial load to a scientifically justified acceptance limit. It differs from cleaning verification — a one-off check of a single cleaning event, used where full validation is not required (e.g. some non-shared, dedicated, or low-risk equipment) — in that validation demonstrates the procedure works reproducibly, across at least three consecutive successful runs, before it is relied on routinely.
The obligation traces to a specific, narrow requirement in 21 CFR 211.67 (“Equipment cleaning and maintenance”) and is elaborated in ICH Q7 section 12.7 for API manufacturing and in EU GMP Annex 15‘s cleaning-validation section for finished-dose and API sites alike. FDA’s original 1993 “Guide to Inspections of Validation of Cleaning Processes” introduced the acceptance-limit heuristics still in use today (the 1/1000-dose and 10 ppm criteria below); the 2014 EMA guideline on health-based exposure limits changed which of those heuristics regulators now expect to see leading the calculation. This page walks the decision process end to end: how to group products and equipment into a worst case, how to calculate an acceptance limit under each accepted method, how to convert that limit into a number a lab can actually test against, and how to choose between swab and rinse sampling to get there.
Where cleaning validation sits in the quality system
Cleaning validation is one line item inside a facility’s broader validation master plan — it doesn’t stand alone. It depends on equipment already having completed IQ/OQ (so the equipment train and its surface areas are actually known and fixed), on the analytical method used to test recovered residue having its own ICH Q2(R2) method validation (limit of detection and quantitation below the acceptance limit, plus a demonstrated swab or rinse recovery rate), and on a documented, ICH Q9-style risk assessment to justify which products and equipment actually represent the worst case. A cleaning validation exercise that skips straight to swabbing without that upstream work in place is the single most common inspection finding in this area — the calculation can be arithmetically correct and still be indefensible if the risk assessment behind the worst-case selection isn’t documented.
Step 1 — Group products and equipment into a worst case
Validating every product/equipment combination separately doesn’t scale, and regulators don’t expect it. The standard approach is bracketing (also called matrixing): identify the single worst-case combination on a shared line, validate that one, and use a written rationale to extend coverage to every less-stringent combination cleaned with the same procedure.
Ranking products
A product-ranking matrix typically scores each product manufactured on a shared line against four factors:
- Toxicity/potency — a lower permitted daily exposure (PDE) or occupational exposure limit means less residue is tolerable, which drives the worst case.
- Solubility in the cleaning agent — poorly soluble actives and excipients are harder to remove and push a product toward worst case.
- Formulation difficulty to clean — ointments, suspensions, and sticky granulations are generally harder to clean than simple aqueous solutions.
- Dose — the product contributing the residue (its minimum daily dose) and the product receiving it (its largest daily dose, which dilutes the carryover) both feed directly into the acceptance-limit formulas below.
The product that produces the lowest calculated acceptance limit for a given shared equipment train — not necessarily the most toxic product in isolation — is the actual worst case, because it’s the hardest combination to demonstrate compliance against. This is why the ranking matrix is a starting hypothesis, not the final answer; the acceptance-limit math in Step 2 confirms or overturns it.
Grouping equipment
Equipment is grouped into families by construction material, geometry, and cleaning procedure/parameters — not just by equipment type. Within a family, the unit with the least accessible internal surfaces (dead-legs, gaskets, valve seats, welds, the largest ratio of hard-to-reach area to total surface area) is validated as the representative worst case for the whole family, with the equivalence rationale (same material of construction, same cleaning SOP, same or lesser surface complexity) documented in the validation protocol, not assumed.
Step 2 — Choose and calculate the acceptance limit
Three calculation methods are in active use. Regulatory expectation has shifted materially since the EMA’s 2014 guideline (EMA/CHMP/CVMP/SWP/169430/2012, adopted 24 November 2014) formalized health-based exposure limits as the scientifically preferred basis — but all three are worth knowing because inspectors still ask facilities to show the dose-based and 10 ppm figures as a sanity cross-check, and older validation packages were built on them.
Method A — Dose-based (the “1/1000” criterion)
The legacy approach, from FDA’s 1993 guidance: no more than 1/1000th of the minimum therapeutic dose of the previous product may appear in the maximum daily dose of the next product.
MACO = (MDDprev × SF × MBSnext) / LDDnext
where MDDprev is the previous product’s minimum daily dose, SF is the safety factor (0.001 for 1/1000; some facilities use 1/10,000 for higher-risk actives), MBSnext is the minimum batch size of the next product, and LDDnext is the next product’s largest daily dose, all in consistent mass units.
Method B — The 10 ppm criterion
A simpler, arbitrary limit also from the 1993 FDA guidance: no more than 10 mg of the previous product’s residue per kilogram of the next product.
MACO = 10 mg/kg × MBSnext
It requires no toxicological data and is trivial to calculate, which is why it’s still used as a floor value — but it has no scientific relationship to actual patient risk, which is precisely what the health-based method below was introduced to fix.
Method C — Health-based exposure limits (PDE/ADE)
The current regulatory default. A toxicologist derives a permitted daily exposure (PDE) — sometimes called acceptable daily exposure (ADE) in older or US-context documents — for the previous product’s active ingredient, following the EMA 2014 methodology (no-observed-adverse-effect level, adjusted by uncertainty factors for interspecies/intraspecies variability, exposure duration, and severity of effect).
MACO = (PDEprev × MBSnext) / LDDnext
The formula’s shape matches Method A — PDE simply replaces the dose-based safety-factor term with a substance-specific, toxicologically derived value, which is exactly why it’s considered more defensible: the limit reflects the actual pharmacological/toxicological profile of the compound rather than an arbitrary fraction of its therapeutic dose.
Which one governs
Calculate all applicable methods and take the lowest resulting MACO as the true acceptance limit — the most conservative figure always wins. In practice, once PDE data exists for a compound, current guidance (and most inspectors) expect the health-based limit to be the primary basis, with the dose-based and 10 ppm figures retained in the validation report as a documented cross-check, not as the governing value.
Step 3 — Convert MACO into a number a lab can test against
MACO as calculated above is a total mass limit across the whole shared equipment train — not directly testable. Two more conversions turn it into an actual pass/fail criterion:
Surface concentration limit: Limit (µg/cm²) = MACO (µg) / SSA, where SSA is the total shared surface area of the equipment train in cm², established during equipment qualification.
Swab result acceptance limit: Swab limit (µg/swab) = (Surface limit × swabbed area) / recovery, where recovery is the fraction recovered in a validated recovery study for that specific residue/surface/swab-material combination — recovery is very rarely 100%, and using an unvalidated assumed recovery rate is a common inspection finding.
Rinse limit: Rinse limit (µg/mL) = MACO (µg) / rinse volume (mL), using the actual final-rinse volume for the equipment train, also adjusted for recovery if the rinse recovery study shows it isn’t complete.
Step 4 — Choose the sampling method: swab vs. rinse
| Swab sampling | Rinse sampling | |
|---|---|---|
| What it measures | Direct residue on a defined, physically accessible surface area | Indirect — residue dissolved into the final rinse solvent across the whole train or circuit |
| Best for | A risk-assessed set of worst-case locations: welds, gaskets, valve seats, other hard-to-clean geometry the swab can physically reach | Large, complex, or inaccessible surfaces (long pipe runs, internal tank walls, CIP loops) that cannot practically be swabbed |
| Recovery | Typically well below 100%; must be established by a validated recovery study per surface/residue combination | Often closer to 100% for a soluble analyte, but still requires demonstration, not assumption |
| Blind spots | Only covers the specific area swabbed — cannot detect residue elsewhere on the train | Cannot detect residue insoluble in the rinse solvent, and can dilute a localized “hot spot” below detection |
| Operational cost | Labor- and technique-intensive; each swab covers a small area | Faster, easier to automate as part of a CIP cycle, supports routine/ongoing monitoring |
Most validation protocols use both: rinse sampling for overall train coverage and inaccessible internals, and swab sampling at a documented, risk-assessed set of worst-case points the rinse alone can’t confirm. Relying on rinse data alone to justify not swabbing a genuinely hard-to-clean location is a defensible position only when the risk assessment says that location isn’t actually a worst case — not as a default cost-saving shortcut.
Illustrative worked example
The figures below are hypothetical, for illustration only — not a real product, company, or validated result.
- Product A (previous, worst case): PDE = 0.1 mg/day
- Product B (next, shares the equipment train): minimum batch size = 100 kg (100,000,000 mg); largest daily dose = 10,000 mg/day
- Shared surface area of the equipment train = 40,000 cm²
- Swabbed area per sample = 25 cm²; validated swab recovery = 80%
MACO = (0.1 mg/day × 100,000,000 mg) / 10,000 mg/day = 1,000 mg across the whole train.
Surface limit = 1,000 mg / 40,000 cm² = 0.025 mg/cm² = 25 µg/cm²
Swab acceptance limit = (25 µg/cm² × 25 cm²) / 0.80 = 781.25 µg per swab
Any swab result below ~781 µg (per this hypothetical swab area and recovery rate) would pass; the facility would run this same logic in parallel using Method A and Method B above and confirm the health-based figure is still the lowest — and therefore governing — value before finalizing the protocol.
Documentation and revalidation
A cleaning validation package should include the product/equipment risk assessment and bracketing rationale, the acceptance-limit calculation under whichever method(s) apply, the analytical method validation summary, at least three consecutive successful validation runs, and the ongoing monitoring plan. Changes that can trigger revalidation — a new product added to the shared train, a cleaning agent or parameter change, equipment modification, or a repeat cleaning failure — should route through the facility’s CAPA and change-control process, the same governance already covering the rest of the GMP quality system, rather than being decided ad hoc by the validation team alone. Underlying computerized systems (LIMS, chromatography data systems used to analyze swab/rinse samples) still need their own CSV and ALCOA+-compliant data handling — a cleaning validation result is only as defensible as the system that generated it.
Frequently asked questions
What’s the difference between cleaning validation and cleaning verification?
Validation demonstrates a cleaning procedure works reproducibly across multiple runs (typically three consecutive successes) before it’s relied on routinely. Verification is a single, one-off check of a single cleaning event’s result — used where full validation isn’t warranted, such as some dedicated, single-product, or lower-risk equipment.
Do I need PDE data for every product, or can I keep using the 1/1000 or 10 ppm criteria?
Where toxicological data exists to derive a PDE, current guidance expects the health-based limit to govern. The dose-based and 10 ppm figures haven’t disappeared — they’re still calculated as a cross-check and remain the basis for some older, still-valid validation packages — but a facility that can obtain PDE data and isn’t using it as the primary limit should expect that gap to be questioned in an inspection.
How many consecutive successful runs does cleaning validation require?
Three consecutive successful cleaning cycles against the acceptance criteria is the widely used industry convention, reflecting the general validation principle that a single pass doesn’t demonstrate reproducibility. It’s a convention rather than a fixed number written into 21 CFR 211.67 or ICH Q7 itself, so a facility’s own validation master plan should state and justify the number it uses.
Why not just always use rinse sampling — it’s faster and less labor-intensive?
Rinse sampling can’t detect residue that isn’t soluble in the rinse solvent, and can dilute a genuinely localized hot spot below the detection threshold. Worst-case, hard-to-clean locations identified in the risk assessment generally still need direct swab confirmation; rinse alone is defensible only where the risk assessment supports it, not as a default substitute.








