IQ, OQ, and PQ

IQ, OQ, and PQ stand for Installation Qualification,Operational Qualification, and Performance Qualification. They are commonlyused to structure evidence that equipment or a system has been properlyinstalled, functions as specified, and performs effectively for its intendedprocess.

Installation Qualification verifies that required componentshave been installed or provisioned in accordance with approved specifications.For SaaS systems, IQ may be adapted to verify tenant provisioning, environmentand version, enabled components, configuration baselines, integrations,identity and access setup, and relevant supplier documentation.

Operational Qualification verifies selected functions andcontrols against approved requirements or specifications. Testing should beperformed in an appropriately controlled environment, with the selectedfunctions, methods, and evidence based on intended use and risk.

Performance Qualification demonstrates that the system canconsistently support its intended process under defined operating conditions.It may include representative users, realistic workflows, applicableprocedures, configured business processes, and representative data.

Organizations may retain IQ, OQ, and PQ terminology or useanother assurance structure. CSA and GAMP 5 do not require a specific documentnaming convention.

Frequently Asked Questions

Are IQ, OQ, and PQ still required under CSA?

CSA does not require or prohibit the IQ, OQ, and PQstructure. Organizations may use these deliverables or another life-cyclestructure, provided the assurance activities and records are appropriate tointended use and risk.

What is the difference between OQ and PQ for software?

OQ generally verifies selected system functions and controlsagainst approved requirements. PQ generally evaluates whether the configuredsystem supports the intended end-to-end process under representative operatingconditions.

How does IQ work for SaaS platforms?

SaaS IQ commonly verifies the provisioned environment,version, tenant setup, enabled services, configuration baseline, access model,integrations, and relevant supplier information, including customer-controlledelements.

Can IQ, OQ, and PQ overlap?

Controlled overlapmay be appropriate when dependencies, prerequisites, responsibilities, andacceptance criteria are clearly defined. Later activities should not rely onunresolved failures unless the risks and limitations have been formallyassessed and accepted.