VHP 오염 제거 주기가 모든 생산 공정을 통과하더라도, 감사에 필요한 근거를 뒷받침하지 못하는 인증 자료가 남을 수 있습니다. 문제는 성능이 아니라 증거입니다. 어떤 기록이 어느 단계에 속하는지, 그리고 누가 그 기록을 작성하고 승인할 책임이 있는지를 파악하는 것이, 고정형 VHP 시스템이 실제로 인계될 준비가 되었는지, 아니면 단지 사용 준비만 되었는지를 결정합니다.
추적 가능성은 승인된 URS 및 설계 기준에서 시작됩니다
| 추적 가능성 항목 | 승인된 요건 | 설계 기준 | 적용 가능한 FAT, SAT, IQ 또는 OQ 증거 | 최종 조항 |
|---|---|---|---|---|
| 승인된 각 URS 요구사항 (요구사항당 한 행) | 프로젝트별 요구사항 식별자 및 문구 | 관련 설계 문서 또는 기록된 설계 결정 사항 | 해당 단계 또는 단계들에서 요구 사항을 충족하는 기록 | 해당되는 경우, 승인된 편차, 결론, 변경 요건 또는 재검증 요건 |
VHP 시스템 인증 패키지의 신뢰성은 그 출발점, 즉 승인된 사용자 요구사항 명세서(URS)와 이에 부응하는 설계 문서의 신뢰성에 달려 있습니다. URS에 요구사항이 명시되어 있음에도 설계 근거에서 이에 상응하는 내용이 보이지 않는 경우, 해당 요구사항은 FAT가 시작되기도 전에 이미 상실된 것이며, 이후 어떤 시험 단계에서도 이를 되찾을 수 없습니다. 이것이 바로 인증 계획 수립이 다음 단계에서 시작될 수 없는 실질적인 이유입니다. FAT 또는 SAT — 그 시점까지 요구사항 집합이 올바르게 이월되었거나, 그렇지 않았을 것입니다.
이 판단을 바꾸는 요인은 URS 자체가 어떻게 작성되었는지에 달려 있습니다. 기능적 결과를 검증 가능한 용어로 명시한 URS는 설계 기준에 대응할 구체적인 근거를 제공하며, FAT, SAT, IQ 및 OQ에 “요구 사항 충족”이 무엇을 의미하는지에 대한 공통된 기준을 제시합니다. 의도를 모호하게 기술한 URS는 설계 팀과 이후의 자격 검증 팀이 그 의도를 해석하도록 강요하게 되며, 특정 요구 사항이 어디에서 검증되었는지 묻는 감사관의 질문에 그 해석이 타당성을 인정받지 못할 수도 있습니다. EudraLex 부록 15 이 지침은 URS를 설계 적격성 평가와 연계하고, 해당 적격성 평가가 가정이 아닌 승인되고 추적 가능한 근거에 기반해야 한다고 규정함으로써 이 문제를 직접적으로 다루고 있다.
특히 VHP 시스템의 경우 — 사이클 매개변수, 센서 배치, 챔버 또는 인클로저 구성, 재료 호환성 등이 모두 프로젝트별 결정에 따라 결정되는 — 설계 근거는 이러한 결정 사항들이 기록되어, 이후 모든 테스트를 평가하는 기준이 되는 곳입니다. 설계 확정 후 요구 사항이 변경될 경우, 추적성 기록을 통해 해당 변경 사항이 FAT, SAT, IQ 및 OQ 단계까지 반영되거나, 아니면 조용히 사라지게 됩니다.
이 단계에서 구매 담당자의 임무는 추가 문서를 작성하는 것이 아니라, 승인된 모든 요구 사항이 적어도 하나의 자격 심사 단계로 이어지는 명확한 경로를 갖추고 있는지 확인하는 것입니다. 요구 사항에 그러한 경로가 없는 경우, 바로 그 시점에 이를 제기해야 합니다. IQ 단계나 규제 당국의 검사 중에 제기해서는 안 됩니다. 또한 이 시점에서 프로젝트 팀이 제공하는 용도, 유틸리티, 실 내 인터페이스 및 운영 조건에 대한 정보가 공급업체의 구성 또는 견적 검토 과정에 반영됩니다. 공급업체가 제안하는 설계 근거는 해당 정보가 사전에 얼마나 완벽하게 정의되었는지에 달려 있기 때문입니다.
FAT는 납품 전에 구성된 기능을 확인합니다.
| 스테이지 | 주요 증거의 초점 | 프로젝트 결정 경계 |
|---|---|---|
| FAT | 출하 전에 테스트할 수 있도록 구성된 기능 | 공급업체의 증빙 자료는 정당한 사유가 있고, 사전에 정의된 프로젝트 기준에 따라 평가된 경우에만 사용해야 합니다. |
| SAT | 이동 또는 통합으로 인해 영향을 받는 설치, 현장 유틸리티, 인터페이스 및 기능 | FAT 결과가 해당 사항을 모두 포함한다고 가정하기보다는, 현장별 조건을 직접 확인하십시오. |
공장 인도 전 시험(FAT)이 실시되는 이유는, VHP 시스템이 공급업체의 시설을 떠나기 전에 일부 기능을 검증할 수 있으며, 이를 조기에 검증함으로써 프로젝트 팀이 현장에서 해결해야 할 불확실한 요소를 줄일 수 있기 때문입니다. FAT에서 반드시 검증해야 할 기능은 시스템이 수령 시설 내부에 어떻게 설치될지에 달려 있는 것이 아니라, 장비 자체의 구성(제어 로직, 설정된 매개변수, 내부 센서 반응, 공급업체의 시험 조건 하에서 발전기의 성능 등)에 따라 달라지는 것들입니다.
여기서 중요한 구분은 FAT가 무엇을 나타낼 수 있는지, 그리고 무엇을 나타낼 수 없는지입니다. 공급업체의 테스트 환경에서는 VHP 발생기가 해당 환경에서 이용 가능한 유틸리티와 조건 하에서 구성대로 작동하는지 확인할 수 있습니다. 그러나 동일한 시스템이 프로젝트의 실제 유틸리티에 연결되거나, 수취실의 폭기 또는 모니터링 시스템과 통합되거나, 프로젝트 측이 이를 위해 구축한 물리적 위치에 설치되었을 때 어떻게 작동하는지는 확인할 수 없습니다. 부속서 15는 이러한 점을 인정하여, SAT에서 동일한 테스트를 반복하는 대신 FAT 결과를 사용할 수 있도록 허용하고 있습니다. 단, 이는 그러한 의존이 정당화될 수 있는 경우에 한하며, FAT 결과는 테스트 후가 아닌 테스트 전에 합의된 사전 정의된 기준에 따라 평가되어야 합니다.
이는 프로젝트 팀이 프로토콜을 계획하는 방식에 직접적인 영향을 미칩니다. FAT(공장 수락 테스트) 승인 기준이 모호하게 작성되거나, 테스트가 이미 실행된 후에야 합의된 경우, 감사자나 자격 심사 담당자는 이를 현장 테스트와 동등하게 취급할 수 있는 문서화된 근거가 없기 때문에, 나중에 공급업체가 제시한 FAT 증거를 신뢰하기가 더 어려워집니다. 반면, FAT 기준이 사전에 정의되고 특정 구성 기능과 연계되며 공식적으로 승인된 경우, 해당 증거를 바탕으로 SAT(현장 수락 테스트)에서 반복해야 할 항목을 정당하게 줄일 수 있습니다.
이 단계에서 프로젝트 팀의 임무는 기능별로 어떤 항목이 진정으로 구성에 따라 달라지며 공급업체 현장에서 테스트 가능한지, 그리고 어떤 항목이 FAT 시점에는 아직 존재하지 않는 현장 조건에 좌우되는지를 파악하는 것입니다. 이 두 범주를 혼동하는 것이 나중에 SAT가 중복된 것인지, 아니면 FAT가 불충분했던 것인지에 대한 분쟁을 야기합니다.
SAT는 현장 유틸리티, 인터페이스 및 설치에 미치는 영향을 해결합니다.
현장 인수 테스트(SAT)는 FAT로는 검증할 수 없는 부분, 즉 VHP 시스템이 실제 설치 위치에 설치되고, 현장의 유틸리티에 연결되며, 수신 시설이 제공하는 인터페이스와 통합되었을 때 어떻게 작동하는지를 검증하기 위해 특별히 마련된 것입니다. 운송, 설치, 그리고 현장별 서비스와의 연결 과정 자체만으로도 장비의 작동 방식에 변화를 줄 수 있으므로, SAT는 단순히 다른 이름으로 불리는 FAT의 반복이 아니라, 전혀 다른 범주의 위험을 대상으로 합니다.
여기서 중요한 유틸리티란 특정 VHP 설비의 작동에 필수적인 모든 요소를 말하며, 중요한 인터페이스란 시스템을 실내, 공정 또는 시설의 모니터링 및 제어 인프라와 연결하는 모든 요소를 의미합니다. 시스템이 실내 환기 시스템, 통과 지점 또는 시설 수준의 모니터링 시스템과 통합되는 경우, 어떤 공급업체의 테스트 환경도 이러한 조합을 재현할 수 없기 때문에 SAT 단계에서 비로소 시스템과 그 인터페이스의 통합된 동작이 처음으로 검증됩니다.
SAT의 범위를 결정하는 요인은 시스템 기능 중 현장별 설치에 의존하는 부분이 어느 정도인지, 그리고 FAT 단계에서 이미 완전히 테스트가 가능했던 부분이 어느 정도인지에 달려 있습니다. 유틸리티 연결이 간단하고 현장 인터페이스 의존도가 최소한인 시스템의 경우, 대부분의 기능이 이미 이전에 확인되었기 때문에 SAT 범위가 더 좁을 수 있습니다. 반면, 복잡한 실내 인프라에 통합되어 있고, 여러 장비 간에 상호 연동이나 모니터링 기능이 공유되는 시스템의 경우, 설치 후에야 관찰할 수 있는 동작이 더 많기 때문에 SAT 범위가 더 넓어집니다.
이 단계가 포착하고자 하는 실질적인 위험은, FAT 단계에서 검증된 기능이 운송 및 설치 후에도 여전히 유효할 것이라는 가정입니다. 부속서 15가 정당화된 FAT 의존을 지지하는 범위는 현장 의존적 기능까지 확대되지 않으며, 오직 기능 자체가 설치의 영향을 받지 않은 경우에만 적용됩니다. 프로젝트 팀의 경우, SAT를 FAT에서 이미 다룬 내용을 재검토하는 형식적인 절차로 여기기보다는, 설치의 영향과 현장 인터페이스를 구체적으로 확인하는 단계로 취급해야 합니다.
IQ는 설치 및 보정된 시스템을 문서화합니다.
설치 적격성 평가란 VHP 시스템의 실제 설치 상태를 사양, 도면 및 주문 내용과 대조하여 확인하는 과정입니다. 이 대조 과정은 도면, 설치된 구성품, 연결된 유틸리티 및 교정 상태를 포괄하며, 그 목적은 설치될 예정이었던 내용이 아닌 실제로 설치된 내용에 대한 문서화된 기준을 확립하는 데 있습니다.
이 조정 단계가 FAT나 SAT와는 별개의 독립된 단계로 중요한 이유는, 설치 과정에서 기능적 결함은 아니지만 문서상의 누락으로 인해 설계 의도와 차이가 발생할 수 있기 때문입니다. 동등한 부품으로 대체된 구성 요소, 도면과 다르게 배선된 유틸리티 연결, 또는 원래 지정된 기준과 다른 기준으로 수행된 교정 등 — 이러한 사항들은 반드시 운영 성능에 영향을 미치는 것은 아니지만, 문서화되지 않은 경우 각각이 승인된 설계 기준까지 거슬러 올라가는 추적성 체인을 끊어 버립니다. IQ 단계는 이러한 편차를 식별하고, 문서화된 근거를 통해 수용하거나, 인증 절차가 진행되기 전에 시정하는 단계입니다.
부속서 11의 요건 VHP 시스템에 전산화 제어 기능이 포함된 경우, GMP와 관련된 모든 전산화 요소의 설치 및 교정 상태는 물리적 구성 요소와 동일한 대조 절차가 필요하므로, 추적 가능한 사용자 요구 사항 및 문서화된 시스템 기록이 여기에 적용됩니다. 제어 로직, 데이터 처리 또는 감사 추적 구성이 설치된 시스템의 일부인 경우, IQ 단계는 해당 구성이 지정 및 승인된 내용과 일치하는지 여부를 확인하는 단계이며, OQ 단계는 설치 상태가 이미 올바른 것으로 가정하고 시스템의 동작 방식을 테스트하는 단계입니다.
이 조정 작업의 난이도를 결정하는 요인은 설치된 시스템 자체의 복잡성입니다. 단순한 독립형 장치의 경우, 조정해야 할 구성 요소와 설비가 적습니다. 반면, 건물 공용 설비, 네트워크 제어 시스템 또는 여러 교정된 계측기와 통합된 시스템은 조정해야 할 항목이 더 많으며, 인터페이스가 하나 추가될 때마다 실측 상태가 설계 기준과 달라질 수 있는 또 다른 지점이 생깁니다. 프로젝트 팀의 임무는 IQ 기록에 설계 기준에 명시된 모든 설비, 구성 요소 및 교정된 계측기가 반영되었는지 확인하는 것이며, 단순히 확인하기 쉬운 항목들만 포함하는 데 그쳐서는 안 됩니다.
OQ: 작동 한계, 경보 및 고장 대응에 대한 검증
| OQ 챌린지 구역 | 프로토콜에서는 다음을 미리 정의해야 합니다. | 결론을 내리기 위해 필요한 증거 |
|---|---|---|
| 작동 범위 | 과제별 범위 및 검증·수용 기준 | 검증 대상 범위 전반에 걸친 원시 결과 및 승인된 결론 |
| 알람 | 테스트 조건, 예상 결과 및 수용 기준 | 경보 발생 내역, 편차 및 승인된 결론 |
| Interlocks | 테스트 조건, 예상 결과 및 수용 기준 | Interlock challenge records, deviations and the approved conclusion |
| Abort and recovery scenarios | Scenario, expected abort and recovery responses, and acceptance criteria | Scenario records, deviations and the approved conclusion |
Operational qualification is where the VHP system is challenged against its approved operating ranges, its alarm responses, its interlocks, and its behavior under abort and recovery scenarios. Where IQ confirms that the system was installed and calibrated as specified, OQ confirms that the installed system actually behaves as intended when operated, including when it is deliberately pushed toward its limits or into fault conditions.
Each of these challenge categories carries a different kind of evidence requirement. Operating range challenges need a protocol that defines, in advance, the specific range being tested and the criteria for an acceptable result — a VHP cycle’s parameters are project-specific, so the acceptance basis has to be established for that system rather than assumed from general practice. Alarm and interlock challenges need defined trigger conditions and an expected response, confirmed through records that show the system responded as specified when that condition was deliberately created. Abort and recovery scenarios need the same discipline extended further: a defined scenario, an expected abort behavior, an expected recovery behavior, and a predefined basis for judging whether both were acceptable.
What ties these categories together is that none of them can be verified informally. An operator confirming that “the alarm worked” during commissioning is not equivalent to a challenge record showing the specific condition created, the response observed, and the conclusion reached against a criterion agreed before the test. This is the distinction Annex 15 reinforces in requiring predefined acceptance criteria and documented deviations — a deviation encountered during OQ is not a failure of the qualification exercise, but it does require an approved disposition before the result can be relied upon.
The condition that changes the depth of OQ needed is how much of the system’s safety or product-protection function depends on dynamic response versus static configuration. A system whose protective function activates only under fault conditions needs those fault conditions actually created and observed, because a static review of the control logic cannot confirm dynamic behavior. Where VHP cycles interact with other equipment — pass-throughs, BIBO transfer points, or room-level monitoring — the OQ scope has to decide whether those interactions are challenged as part of this system’s qualification or addressed separately, and that boundary needs to be explicit in the protocol rather than assumed.
Handover Closes Deviations, Records and Requalification Triggers
| Record group | Handover evidence to retain | 결정 경계 |
|---|---|---|
| Approved protocols | Predefined acceptance criteria and the approved test basis | Exact tests and criteria remain project-specific |
| 편차 | Approved deviation records and their effect on the relevant result or conclusion | A deviation requires an approved disposition rather than an undocumented exception |
| Responsibility split | Supplier-provided records and the corresponding site qualification decisions | Supplier evidence does not make the site decision unless that responsibility is explicitly assigned |
| Final cycle evidence | Representative-load definition, sensor and indicator placement, raw records and conclusions | Indicator results do not replace physical measurements or define a universal cycle |
| Change and requalification | Defined change or requalification triggers | Trigger conditions remain specific to the approved project basis |
A qualification package is complete only when every deviation raised during FAT, SAT, IQ or OQ has an approved disposition, every protocol’s predefined criteria and approved test basis are retained in the final record, and the boundary between supplier-provided evidence and site qualification decisions is explicit rather than assumed. An undocumented exception — a result that was accepted informally without a recorded justification — is the single most common way a qualification package fails to support an inspection, because the absence of a documented disposition leaves no basis for an auditor to understand why an anomalous result was considered acceptable.
The responsibility split matters because a VHP system supplied and qualified through a vendor relationship generates two categories of record: what the supplier tested and documented, and what the site qualification team concluded and approved. Supplier records can inform a site decision, but they do not substitute for it unless that responsibility has been explicitly assigned in the project’s qualification plan. Where that assignment is unclear, the handover package risks containing records that look complete but do not actually establish who approved what.
For the final cycle evidence specifically, EU GMP 부속서 1 is explicit that sterilization or decontamination validation relies on physical measurements, with biological or chemical indicators used where appropriate and placed at suitable locations — indicator results do not replace the physical measurements, and neither replaces a defined, representative load. A handover package for a VHP system needs to retain the representative-load definition used during qualification, the placement of sensors and indicators, the raw records from the qualification runs, and the conclusions drawn from them, because a future review of cycle performance depends on being able to reconstruct what was actually tested, not only what the summary report states.
The final element is the set of conditions that would trigger a change evaluation or a requalification — a modification to the load configuration, a change to room interfaces, a change to the control system, or any other condition the project’s qualification basis identifies as relevant. These triggers are specific to the approved project basis rather than generic, which is why they need to be stated explicitly in the handover package rather than left for a future reviewer to infer. Equipment such as a VHP 과산화수소 발생기 configured for a specific project enters service against this exact record set, and the completeness of that record set is what determines whether the system can be maintained, modified, or requalified later without reconstructing the qualification basis from memory.
자주 묻는 질문
Q: What should be agreed before FAT, SAT, IQ and OQ protocols are drafted?
A: Start with the approved URS, recorded design decisions, project-specific acceptance criteria and a clear split between supplier records and site qualification decisions. For final cycle evidence, also define the representative load and planned sensor and indicator locations so the protocol can produce evidence that matches the intended conclusion.
Q: When can FAT evidence be carried into the site qualification package?
A: It can support a requirement when the tested configured function remains applicable and its use is justified against predefined project criteria. Installation, utilities, interfaces and functions affected by transport or integration still need site-specific verification rather than an assumption that the FAT result remains sufficient.
Q: How should a requirement change after FAT be handled in the traceability record?
A: Update the requirement-to-evidence mapping and identify which design documents, tests, conclusions or requalification triggers are affected. The handover package should preserve the change and its approved disposition so the original FAT record is not treated as evidence for a condition it did not test.
Q: Who should decide whether a deviation is acceptable at handover?
A: The protocol should assign that responsibility explicitly and require an approved disposition tied to the affected result or conclusion. A supplier deviation record can document what occurred, but it should not be treated as the site’s qualification decision unless that authority was clearly assigned.
Q: Do indicator results alone demonstrate that a VHP cycle is acceptable?
A: No. Indicator results do not replace physical measurements or establish a universal cycle. The conclusion should follow the approved project criteria and retain the representative-load definition, sensor and indicator placement, raw records, deviations and final approved conclusion.





















