A fixed VHP generator serving multiple rooms or chambers only performs the duty the project defines before specification. Once the equipment is selected and installed, the treatment cycle it delivers is fixed to what the URS described, not to what the room or process might later need. Engineering teams preparing this document are effectively setting the boundary of what any bid can be held to.
Start with the Rooms, Loads and Intended Decontamination Duty
| URS input | What the project must define | 결정 경계 |
|---|---|---|
| Treated enclosure | Each room or other enclosure included in the duty | Keeps the offer tied to the intended treatment boundary |
| Operating state | The operating state for each treated enclosure | Keeps the stated duty tied to the condition in which it will be performed |
| Representative load | The load that represents the intended duty | Gives vendor offers the same load basis |
| Process purpose | The intended decontamination purpose | Keeps the proposed duty aligned with the project purpose |
| Aeration and release | The intended route for aeration and release | Completes the defined path from treatment through release |
A fixed VHP generator does not decontaminate a generic space. It treats a defined enclosure, under a defined operating state, carrying a defined load, for a defined purpose, with a defined route out through aeration and release. Each of these elements changes what a vendor can credibly propose, and changing one without the others creates a specification that cannot be verified later.
The treated enclosure matters because a single generator may serve one room or several interconnected spaces, and the duty differs depending on whether the project is treating an isolator chamber, a transfer space, or a suite of linked rooms. Naming each enclosure individually, rather than describing the installation in general terms, keeps the offered duty tied to what will actually be qualified.
Operating state is a separate variable from the enclosure itself. The same room decontaminated at rest carries a different load and a different penetration challenge than the same room with process equipment installed, doors open to adjoining spaces, or air handling in a particular configuration. Where the URS does not state the operating state for each treated enclosure, two vendors can propose functionally different cycles while appearing to answer the same requirement.
Representative load follows directly from operating state. A cycle validated against an empty enclosure does not establish performance against the load the enclosure will actually carry in production use. If the project changes the representative load after bids are submitted, the vendor’s basis of design changes with it, and comparisons made on the earlier basis no longer hold.
Process purpose should be stated explicitly rather than assumed from context. A decontamination duty intended to support personnel re-entry carries different expectations than one intended to support material transfer or room turnover between campaigns, and the stated purpose should align with how the project will later define acceptance.
Aeration and release complete the duty definition. A treatment cycle without a defined route for residual hydrogen peroxide to clear, and without a defined basis for declaring the space released, leaves the back half of the duty unspecified. Where the release route runs through existing HVAC, through dedicated aeration equipment, or through a different exhaust path, the generator’s required capacity and control sequence change accordingly. Each of these five elements should be captured per treated enclosure before the project moves to utility and distribution interfaces, since every downstream interface decision depends on the duty being fixed first.
Define Utility and Distribution Interfaces Without Hiding Scope Gaps
Once the duty is fixed, the URS must describe how the generator connects to the facility, and this is where scope boundaries are most often left implicit rather than stated. A fixed VHP generator requires power, a supply of hydrogen peroxide and a defined method for its handling, a path for distributing vapor to the treated enclosure, an exhaust route, and the dampers, sensors, and service access needed to operate and maintain the system. None of these should be assumed to fall inside or outside the equipment vendor’s scope by default.
Distribution piping or ductwork connecting the generator to the room, and any shared use of existing HVAC infrastructure for distribution or exhaust, sits at a natural interface boundary. Where the project intends to route vapor through existing ductwork, the URS should state this intent directly rather than leaving the vendor to infer it, because the generator’s distribution design, and the facility’s HVAC design, both depend on which side of that interface each party owns. The same applies to exhaust: whether the generator exhausts to a dedicated path or shares an existing exhaust system changes what the facility team must provide and what the equipment vendor must accept as a boundary condition.
Dampers and sensors sit at this same interface line. Damper control may belong to the generator’s control system, to the building management system, or be split between them depending on how the project structures responsibility, and the URS should state which condition applies rather than leaving damper ownership to be resolved during commissioning. Sensor placement intended to confirm cycle parameters inside the treated enclosure, as distinct from sensors monitoring the generator itself, should be identified by location and function so that the division between equipment-side and facility-side instrumentation is traceable.
Service access is a physical interface as much as a control one. Where the generator, its hydrogen peroxide supply, or its distribution components require access for maintenance, the URS should state the access condition the facility will provide, since equipment placement and facility layout are both constrained by it. Leaving any of these interfaces unstated does not remove the scope question; it defers it to a point in the project where resolving it costs more than defining it would have.
Specify Control States, Interlocks, Alarms and Data Requirements
Controls requirements should be set according to what is actually GMP-relevant to the project, not applied uniformly across every signal the system can generate. A fixed VHP generator’s control system can produce permissives, interlocks, alarms, user access restrictions, retained data, and signals to a building management system, and each of these categories carries a different weight depending on what the project needs to demonstrate.
Permissives and interlocks govern whether a cycle can start or must stop, and the project should state which conditions must be true before treatment begins and which conditions during treatment require the cycle to halt. Where an interlock ties generator operation to a door position, a damper state, or an adjoining room’s status, that relationship should be named in the URS as a defined condition, not left to the control system’s default behavior.
Alarms require a similar distinction between what is informational and what requires a defined response. Not every alarm a generator can produce carries the same consequence, and the project should state which alarms require operator action, which require a documented deviation, and which are advisory only.
User access and data retention become GMP-relevant where the data supports batch release, deviation investigation, or audit trail requirements under Annex 11’s computerized-system framework, which calls for risk-based validation of user requirements and controls over audit trails, stored data, backups, and access. Annex 11’s scope follows documented risk rather than extending automatically to every facility event the control system can log; where a data point does not support a GMP decision, treating it with the same rigor as data that does adds control burden without adding assurance. The project should identify which signals, alarms, and records carry that GMP relevance and which do not, and write the URS accordingly rather than requesting full validation rigor across every available signal.
Building management system signals sit at the boundary between the generator’s own control system and the facility’s broader monitoring. Whether a given signal is advisory to the BMS or forms part of a GMP-relevant record should be stated explicitly, since this determines whether that signal later requires the same qualification evidence as the generator’s core control functions.
Connect Each URS Requirement to FAT, SAT, IQ and OQ Evidence
| Evidence stage | Traceability entry for each applicable URS requirement | 증거의 범위 |
|---|---|---|
| Design review | Identify the documented design review that addresses the requirement | Maintain the link between the URS and design qualification |
| FAT | Identify the justified vendor test evidence planned for the requirement | Use an approved protocol and a predefined, project-owned acceptance criterion |
| SAT | Identify the site test evidence planned for the requirement | Use an approved protocol and a predefined, project-owned acceptance criterion |
| IQ | Identify the installation qualification evidence planned for the requirement | Keep IQ evidence distinct from OQ evidence |
| OQ | Identify the operational qualification evidence planned for the requirement | Keep OQ evidence distinct from IQ evidence |
| Deviation record | Link any deviation arising from the planned verification activity | Document the deviation against the approved protocol and predefined criterion |
A URS requirement that cannot be traced to a verification stage is difficult to enforce later, regardless of how clearly it was written. 부록 15 links the user requirements specification to design qualification, permits justified vendor factory acceptance testing supplemented by site acceptance testing, and distinguishes installation qualification evidence from operational qualification evidence, all under approved protocols with predefined acceptance criteria and documented deviations. Applying that structure to a fixed VHP generator means each applicable requirement from the earlier sections needs an identified home in this evidence chain before the project proceeds to bid comparison.
Design review is the first checkpoint, and it should confirm that the stated duty, interfaces, and control requirements are reflected in the proposed design before any physical test occurs. A requirement that only appears for the first time at FAT has effectively bypassed design review, and any gap discovered at that stage costs more to resolve than one caught earlier.
FAT and SAT divide responsibility between vendor-site and installed-site verification. Where a requirement can be meaningfully tested at the vendor’s facility, using a justified test setup, FAT evidence may satisfy it; where the requirement depends on the actual installed interfaces, such as a distribution path connected to the real enclosure or an interlock tied to the facility’s actual damper, SAT carries the evidence instead. The project should state which requirements belong to which stage rather than assuming FAT alone will carry everything.
IQ and OQ remain distinct kinds of evidence under Annex 15, and conflating them creates ambiguity about what has actually been demonstrated. Installation qualification confirms the system is installed as specified; operational qualification confirms it operates as specified across its intended range. A control permissive or interlock named in the URS should be traceable to one or the other, not to a general qualification statement that does not specify which.
Every verification activity planned against these stages should run under an approved protocol with a predefined, project-owned acceptance criterion, and any deviation arising from that activity should be documented against the same criterion. This traceability work is also where the project information supplied to a generator supplier, including the defined duty, interfaces, and control requirements from earlier sections, enters that supplier’s configuration and quotation review, since the vendor cannot propose justified FAT evidence or a matching control design without first seeing how the project has drawn these boundaries.
Set Bid Assumptions and Project Acceptance Ownership
The sections above establish a chain: a defined duty per enclosure, defined interfaces with scope ownership stated, control requirements set to actual GMP relevance, and each requirement traced to a verification stage. Bid comparison depends on every vendor responding to the same chain rather than filling gaps with differing assumptions.
Where the URS leaves an element undefined, a vendor proposing a fixed VHP generator, such as the Type I unit offered within this equipment category, will typically fill that gap with an assumption suited to their standard configuration rather than the project’s actual condition. This is not a failure of the vendor’s offer; it is a consequence of an incomplete requirement. The project should treat any area where bids differ substantially as a signal that the URS left that element open, rather than treating the lowest or most inclusive bid as automatically correct.
Acceptance criteria ownership should stay with the project throughout, consistent with the predefined-criteria principle running through design review, FAT, SAT, IQ, and OQ. A vendor can propose test methods and can demonstrate that their equipment meets a stated criterion, but the criterion itself, and the decision to accept or reject the evidence against it, belongs to the project. Where this ownership is unclear, a vendor’s internal test criteria can be mistaken for the project’s acceptance standard, which weakens the project’s position if a deviation later requires justification.
Interface ownership, set out earlier for power, hydrogen peroxide supply and handling, distribution, exhaust, dampers, sensors, and service access, should be confirmed in the bid assumptions explicitly, enclosure by enclosure, rather than left as a general scope statement. A general statement that the vendor supplies “the generator and standard interfaces” does not resolve which party owns a specific damper or a specific exhaust connection on a specific room.
Where the project has not yet resolved how a given enclosure’s operating state, load, or release route will be qualified, that gap should be named in the bid request rather than deferred to the responding vendors to interpret independently, since each vendor’s interpretation becomes a different, uncomparable basis for the resulting quotation.
자주 묻는 질문
Q: How can engineering teams compare fixed VHP generator bids when vendors divide interface scope differently?
A: Normalize every bid against the same interface list before comparing it. For power, hydrogen peroxide supply and handling, distribution piping or the HVAC connection, exhaust, dampers, sensors, and service access, record the vendor’s assumption and identify any item whose ownership remains undefined.
Q: What should the URS say if the final room load is not yet confirmed?
A: Define the representative load being used for the RFQ and state that it is the comparison basis rather than a confirmed final condition. The team can then identify which later load decisions would require the proposed treatment duty to be reviewed.
Q: How should the project decide which control and data requirements are GMP-relevant?
A: Classify each control state, alarm, interlock, user-access rule, stored record, and BMS signal according to its actual role in the process and documented risk. Use that classification to define the applicable access, retention, audit-trail, backup, and validation expectations instead of treating every facility event alike.
Q: Can successful FAT evidence replace site testing or qualification evidence?
A: Not as a blanket rule. The project may use justified vendor FAT evidence for applicable requirements, but it should still identify the required SAT, IQ, and OQ evidence separately and apply approved protocols and predefined project-owned acceptance criteria at the relevant stage.
Q: What makes a fixed VHP generator URS requirement testable?
A: A testable requirement links the required condition to a planned evidence stage and a predefined acceptance criterion owned by the project. It should also identify how deviations will be documented so the final evidence remains traceable to the original requirement.





















