A Factory Acceptance Test that ends with a passed result does not automatically mean the equipment is ready to ship. Deviations recorded during testing may remain open at the point the FAT report is signed, and how those open items are classified, corrected, and documented determines whether shipment approval is a technical decision or a paperwork formality. For aseptic-processing equipment and containment systems alike, that gap between “FAT passed” and “shipment approved” is where downstream schedule, qualification, and commercial responsibility get defined.
Why a Passed FAT Can Still Contain Shipment-Blocking Exceptions
A FAT result is typically reported as an overall outcome against a test protocol, but that outcome can coexist with individual test steps that did not meet their acceptance criterion. Where a protocol allows conditional acceptance or documented exceptions, the overall pass reflects the majority of verified functions, not the absence of deviations. The reader evaluating a FAT report needs to separate the summary conclusion from the deviation log underneath it, because the summary alone does not indicate whether any open item affects safe shipment, downstream testing, or site qualification.
The distinction matters because a deviation can exist at several different levels of consequence. Some deviations are cosmetic or documentation-related and do not affect the equipment’s function or the validity of other tests already performed. Others affect a function that later tests depend on, so an unresolved deviation in an early test step can invalidate the acceptance basis for a later one, even if that later step was recorded as passed. Where a control sequence, interlock, or monitored parameter feeds into subsequent verification, an open deviation on that item carries forward risk that the summary result does not show.
This is also where the difference between aseptic-processing equipment and containment systems affects how a deviation is read. For isolators or RABS-type barrier systems governed by product protection, a deviation touching air quality, pressure cascade, or transfer integrity speaks directly to the sterility assurance basis the FAT was meant to establish. For containment equipment governed by operator and environmental protection, an equivalent deviation on a barrier, transfer device, or decontamination step speaks to containment integrity instead. The same category of finding, a pressure differential outside its criterion, for example, is not interchangeable in significance between an aseptic context and a containment context, because it is being measured against a different protection objective.
A buyer reviewing a FAT report at this stage should ask what specific test step produced each deviation, whether that step is a precondition for another test in the same protocol, and whether the deviation was closed, accepted, or left open at the time the report was issued. The answer determines whether the reader is looking at a completed verification with minor documentation gaps or a verification sequence with an unresolved link in its chain.
Deviation Records That Preserve Requirement, Criterion, Result, and Impact
A deviation record is only useful to the project if it can be traced back to what was actually being tested and what was expected. Recording that a test “failed” without preserving the tested function, the applicable URS or design reference, the acceptance criterion, and the actual result leaves the project team unable to independently judge severity later, whether at shipment review, at SAT, or during a qualification audit. The record has to stand on its own, separate from the memory of whoever was present during testing.
The requirement basis matters because a deviation is only a deviation relative to a defined criterion. If the URS or design specification that generated the criterion is not identified in the record, a later reviewer cannot confirm whether the criterion itself was correctly derived, whether it was later revised, or whether it still applies unchanged at the point of shipment decision. Where a specification changes between FAT and SAT, for example through a customer-driven configuration adjustment, the deviation record needs to show which version of the requirement was in effect when the test was run.
Impact is the element most often reduced to a general note when it should instead describe what the deviation means for equipment operation, for downstream testing, or for the protection objective the equipment serves. A deviation with no stated impact forces every subsequent reviewer, including QA, validation, and site teams, to re-derive that judgment independently, which increases the chance that different reviewers reach different conclusions about the same finding.
The corrective action field is where accountability enters the record. An owner and due date turn a documented problem into a tracked commitment. Without them, the deviation exists as a description of a gap with no mechanism forcing its resolution before shipment or before the corresponding site activity begins.
| Deviation record element | Required content |
|---|---|
| Tested function | The function tested when the deviation occurred |
| Requirement basis | The applicable URS or design reference |
| Acceptance comparison | The expected acceptance criterion and the actual result |
| Impact | The documented impact of the deviation |
| Corrective action | The proposed corrective action, named owner, and due date |
| Closure evidence | The selected documentary review, targeted retest, or witness-testing evidence after correction |
EudraLex Volume 4 Annex 15 supports this structure at the qualification level: it calls for predefined acceptance criteria, documentation of deviations, investigation of failures, and reporting against those criteria, with FAT-to-SAT evidence use justified rather than assumed. The specific fields a project requires in its own deviation record, and the exact closure criteria that apply, remain matters the project’s own protocols and quality system define.
Risk Classification Separates Shipment Holds from Approved Site Punch Items
Not every open deviation should stop equipment from leaving the factory, and not every open deviation is safe to defer. The classification step is where the project team decides which category a given item belongs to, and that decision has to be made deliberately rather than defaulted by omission.
A deviation that blocks safe shipment or invalidates a downstream test cannot be resolved by scheduling it for later attention at site. If a function that protects personnel during transport or installation has not been verified, or if a test result that a later test depends on remains unconfirmed, shipping the equipment does not remove the unresolved risk; it only moves the point at which the gap becomes visible, typically to a site environment with less controlled conditions for retesting than the factory offered.
An approved site punch item is different in kind, not just in degree. It is an item that can be closed at site precisely because its resolution does not depend on factory conditions and does not compromise any test already completed. Cosmetic finish issues, non-critical documentation updates, or components whose function can be verified equally well on site are candidates for this category, provided the project has explicitly approved deferring them and has a plan for closing them during site work.
Where a buyer is reviewing a FAT deviation list before agreeing to shipment, the useful question is not whether deviations exist, since some level of open items is common on a project-configured system, but whether each one has been assigned to one of these categories on a documented basis, and whether that assignment reflects the actual downstream dependency rather than convenience. A deviation deferred to site because it is inconvenient to resolve at the factory is not the same as one deferred because deferring it carries no technical risk.
| Classification | Decision boundary | Handling |
|---|---|---|
| Shipment hold | The deviation blocks safe shipment or invalidates downstream testing | Keep shipment approval on hold under the project’s defined criteria |
| Approved site punch item | The item can be closed at site under an approved plan | Carry the approved plan and any site retest obligation into site work |
| Project-specific boundary | The project team sets the categories and exact closure and shipment criteria | Record the agreed classification; vendor evidence may still require site review or supplemental testing |
The exact boundary between these categories, and the criteria that place a specific item on one side or the other, is set by the project team using its own defined criteria; a supplier’s factory evidence may still require site review or supplemental testing before an item classified as a punch item can be considered genuinely closed.
Corrective Evidence Through Document Review, Retest, or Witness Testing
Once a deviation has been corrected, or a corrective action has been proposed, the project still needs evidence that the correction actually addresses the original finding. Three routes generally exist for generating that evidence, and the choice between them changes what the resulting record can support.
Documentary review is the lightest-weight route: it relies on updated documentation, a corrected calculation, a revised drawing, or a written justification that the original finding was a documentation error rather than an equipment or performance gap. This route is appropriate where the underlying tested function is not in question, only its record. It is not appropriate where the original deviation concerned an actual measured result or an observed function that did not meet its criterion, because a document update cannot substitute for demonstrating that the equipment now performs correctly.
Targeted retest addresses that gap by re-running the specific test step, or a defined subset of it, after the corrective action has been implemented. This is proportionate where the correction is narrow and localized, and where retesting the single affected step does not require re-verifying steps that were unaffected by the original finding. The retest evidence attached to the deviation record then stands as the closure basis for that specific item.
Witness testing raises the evidentiary weight further by having the retest observed and confirmed by a party with standing to accept it, commonly the customer, a quality representative, or another named stakeholder, depending on what the project has defined. This route becomes relevant where the original deviation concerned a function significant enough to the protection objective, aseptic or containment, that the project does not want to rely on the vendor’s own retest record alone.
The choice among these three is a project decision that depends on the nature of the original finding, the significance of the tested function to sterility assurance or containment integrity, and what the project’s own quality system requires for that class of finding. A buyer should confirm which route was used for each closed deviation and whether that route matches the significance of the original gap, rather than assuming all closures carry equal weight.
Open-Item Transfer Into SAT and Site Qualification
Items deferred from FAT do not disappear from the project; they transfer into SAT and, where applicable, into the qualification stages that follow. That transfer needs its own discipline, because an open item that is well documented at FAT but poorly carried forward becomes invisible at exactly the point where it needs to be re-verified.
The mechanism for this transfer is the open-item list itself, carried alongside the FAT deviation records, showing which items remain open, what plan was approved for closing them, and what obligation exists to retest them at site. Where a deviation was classified as an approved site punch item specifically because its resolution required site conditions, SAT is the point at which that resolution is supposed to occur. If SAT proceeds without explicit reference to that open item, the closure may be missed entirely, or closed informally without generating evidence that a later qualification review can rely on.
This has a direct bearing on IQ/OQ/PQ planning. Qualification protocols are typically built on the assumption that the equipment they are testing has a known, documented configuration and a known set of prior test results. An open item carried forward without clear status can create ambiguity about whether a qualification test result reflects the equipment’s final configuration or an interim state still awaiting a FAT-originated correction. Where the open item touches a function that IQ or OQ would otherwise re-verify, coordinating the closure timing with the qualification schedule avoids duplicating effort or, conversely, missing a gap that qualification testing was not designed to catch.
The project team’s SAT planning should therefore treat the FAT open-item list as an input, not a separate record to be reconciled informally. Confirming, before SAT execution begins, which FAT deviations remain open and what each one requires at site keeps the qualification sequence built on a documented and current equipment status rather than an assumed one.
Shipment Release With Named Owners, Dates, Residual Risk, and Commercial Effects
The decision to release equipment for shipment is a project decision, not a byproduct of the FAT report being signed. Treating equipment dispatch as automatic technical closure removes the visibility that the open-item and risk-classification work was meant to create. A shipment release record should make explicit what is still open, what risk is being accepted by shipping with those items unresolved, what obligations exist at site as a result, who owns each of those obligations, and what happens commercially if resolving them affects cost or schedule.
Naming owners and dates against each open item is what converts a list of exceptions into something the project can actually track after the equipment leaves the factory floor. An open item with no owner tends to remain open past its relevance window, because no single party is accountable for closing it before it affects a later stage, such as SAT or qualification.
Accepted residual risk deserves explicit statement because shipping with open items is, by definition, a decision to accept some level of risk that a punch-list item may not close cleanly, or that a retest at site may surface a result different from what was expected at FAT. Recording that acceptance, rather than leaving it implicit, gives the project a documented basis for the decision that can be reviewed later if an item does not close as planned.
Commercial responsibility is the element most easily left out of a technical release record, but it has direct bearing on how the project proceeds if a site retest fails or an open item takes longer to close than planned. Whether the cost and schedule effect of that outcome sits with the supplier or the buyer is a matter the shipment release documentation should state, not something inferred after the fact.
| Release record check | What the approval record should show |
|---|---|
| Open items | Each item still open at shipment |
| Accepted residual risk | Any risk acceptance supporting release |
| Site follow-up | Site retest obligations for open items |
| Accountability | Named owners and dates |
| Commercial effect | Responsibility for cost or schedule effects |
| Release boundary | Equipment dispatch does not by itself establish technical closure |
Where a project is coordinating this release process with a supplier such as QUALIA, the deviation records, risk classifications, and open-item list the project has already prepared become the basis for that shipment review, since the supplier’s own configuration and quotation review depends on having that documented status rather than an informal summary of what remains outstanding.
Frequently Asked Questions
Q: Can equipment ship while a FAT deviation remains open?
A: Only when the project team classifies it as an approved site punch item rather than an issue that blocks safe shipment or invalidates downstream testing. Before release, record the accepted residual risk, the site closure plan, the required retest, a named owner and date, and responsibility for any cost or schedule effect.
Q: Is a closed status enough to accept a FAT deviation?
A: No. Check that the record links the tested function to the URS or design reference, expected criterion, actual result, impact, corrective action, and closure evidence. The status should follow that evidence rather than replace it.
Q: How should the closure evidence route be chosen?
A: Match documentary review, targeted retest, or witness testing to what the correction must prove against the original acceptance criterion. Record that choice in the project protocol and attach the resulting evidence to the deviation, with supplemental site testing identified when required.
Q: What should travel with an open item from FAT into SAT?
A: Carry the deviation record, approved site plan, specific site retest obligation, owner, due date, and accepted residual risk. Keep commercial responsibility visible as well, so shipment does not obscure who bears any cost or schedule effects.
Q: Who should approve whether a deviation is a shipment hold or a site punch item?
A: The project team should set and document the exact classification, closure, and shipment criteria. Supplier evidence can inform that decision, while site review or supplemental testing may still be required; equipment dispatch alone does not establish technical closure.





















