Site Acceptance Test (SAT) in Pharmaceutical Industry.

Part 8

The lifecycle position is:

URS → Risk Assessment → DQ → FAT → Shipment → Installation → SAT → Commissioning → IQ → OQ → PQ → GMP Release

The central SAT question is:

Has the equipment/system arrived, been assembled, connected, and configured at the user site without unacceptable change or damage, and is it ready to proceed into formal site qualification?


8.1 What Is Site Acceptance Testing?

A Site Acceptance Test (SAT) is a planned and documented verification performed after equipment or a system has been delivered to and normally assembled/installed at its intended site.

SAT confirms that the system:

  • arrived without unacceptable transportation damage;
  • has been correctly reassembled;
  • is connected to appropriate site utilities;
  • retains the required hardware/software configuration;
  • communicates with site systems where applicable;
  • retains important functionality demonstrated at FAT;
  • incorporates approved site-specific modifications;
  • has resolved applicable FAT punch-list items;
  • is sufficiently ready for commissioning and/or qualification.

SAT is particularly valuable for equipment that was:

  • dismantled after FAT;
  • transported over significant distances;
  • reassembled at site;
  • connected to new utilities;
  • integrated with site infrastructure;
  • connected to upstream/downstream equipment;
  • connected to site networks or computerized systems.

8.2 Why SAT Is Required

FAT demonstrates the condition of the system at the supplier’s facility.

Between FAT and site installation, many things can change:

FAT-approved equipment

Disassembly

Packing

Transportation

Unloading

Storage

Positioning

Reassembly

Utility connection

Network/interface connection

Site configuration

Each step can introduce new risks.

Therefore:

A successful FAT does not prove that the equipment remains in the same acceptable state after transportation and installation.

SAT closes this gap.


8.3 FAT vs SAT vs IQ

These activities are related but serve different purposes.

ActivityPrimary Question
FATDoes the factory-built/configured system satisfy applicable requirements before shipment?
SATDid the system arrive, reassemble, connect and function appropriately at the site?
IQIs the installed system documented and verified against approved installation/design requirements?
OQDoes the installed system operate as intended throughout applicable operating ranges?

A practical distinction is:

FAT = Factory State

SAT = Site-Arrival/Installed Functional State

IQ = Qualified Installation State

OQ = Qualified Operational State


8.4 SAT vs Commissioning

SAT may form part of commissioning, but the terms are not necessarily interchangeable.

SAT

Focused on acceptance of the delivered system at site.

Commissioning

Usually broader engineering activities intended to bring the system from installation into an operational state.

Commissioning may include:

  • mechanical completion;
  • utility startup;
  • loop checks;
  • flushing;
  • rotation checks;
  • balancing;
  • functional testing;
  • tuning;
  • troubleshooting.

Where commissioning evidence is sufficiently controlled, relevant evidence may potentially support qualification according to the approved C&Q strategy.


8.5 SAT Strategy

The SAT strategy should be established before execution.

It should define:

  • system/equipment scope;
  • FAT results being relied upon;
  • FAT tests requiring site confirmation;
  • transportation-sensitive components;
  • site utilities;
  • site interfaces;
  • site-specific configuration;
  • safety checks;
  • functional checks;
  • punch-list closure;
  • acceptance criteria;
  • deviation management;
  • readiness criteria for IQ/OQ.

8.6 Risk-Based SAT

SAT should not automatically repeat the entire FAT.

Instead ask:

What could have changed, failed, become damaged, become disconnected, or become incorrectly configured between successful FAT and site installation?

Typical risk areas include:

  • physical damage;
  • loose connections;
  • instrument damage;
  • wiring errors;
  • incorrect motor rotation;
  • utility mismatch;
  • communication failure;
  • software/configuration change;
  • interface failure;
  • safety-circuit problems.

This produces a focused and scientifically defensible SAT.


8.7 SAT Inputs

Typical inputs include:

  • approved URS;
  • DQ;
  • risk assessment;
  • FAT protocol;
  • FAT report;
  • FAT deviations;
  • FAT punch list;
  • equipment drawings;
  • P&IDs;
  • electrical drawings;
  • utility specifications;
  • instrument list;
  • software/configuration records;
  • vendor manuals;
  • shipping documents;
  • installation records.

8.8 SAT Prerequisites

Before SAT execution, verify as applicable:

  • □ Equipment received
  • □ Equipment positioned at intended location
  • □ Major assembly completed
  • □ Shipping inspection performed
  • □ Required utilities available
  • □ Electrical supply available
  • □ Safety conditions established
  • □ Relevant site permits complete
  • □ FAT report available
  • □ FAT punch list available
  • □ SAT protocol approved
  • □ Test instruments available
  • □ Calibration status acceptable
  • □ Drawings available
  • □ Vendor/engineering personnel available
  • □ Software/configuration information available

8.9 Recommended SAT Protocol Structure

A practical SAT protocol may contain:

1. Document Control

  • title;
  • SAT number;
  • revision;
  • equipment/system ID;
  • project number.

2. Approval

  • prepared by;
  • reviewed by;
  • approved by.

3. Objective

4. Scope

5. References

6. Definitions

7. Responsibilities

8. System Description

9. Prerequisites

10. FAT Status Review

11. Shipment/Receipt Inspection

12. Equipment Identification

13. Installation Verification

14. Utility Verification

15. Electrical Verification

16. Instrument Verification

17. Safety-System Verification

18. PLC/HMI/SCADA Verification

19. Communication/Interface Verification

20. Alarm Verification

21. Basic Functional Testing

22. Site-Specific Configuration

23. FAT Punch-List Closure

24. Deviations

25. SAT Punch List

26. Summary

27. Readiness for Qualification

28. Approval


8.10 Receipt and Shipment Inspection

One of the first SAT activities should be confirmation that transportation has not adversely affected the equipment.

Inspect for:

  • damaged panels;
  • dents;
  • broken components;
  • damaged product-contact parts;
  • broken glass/screens;
  • damaged cables;
  • loose instruments;
  • broken piping;
  • damaged seals;
  • corrosion;
  • missing parts;
  • water ingress;
  • packaging damage.

8.11 Shipment Damage Assessment

If damage is found:

Observation

Photograph/Document

Identify Component

Assess GMP/Safety/Functional Impact

Notify Supplier/Project Team

Repair/Replace

Verify

Close

Significant damage should not simply be repaired informally without assessing whether qualification impact exists.


8.12 Equipment Identification

Confirm that the delivered equipment is the equipment that underwent FAT.

Verify:

  • manufacturer;
  • model;
  • serial number;
  • equipment tag;
  • major assemblies;
  • applicable component identification.

This is especially important when vendors manufacture multiple similar machines.


8.13 Example Identification Table

ParameterFAT RecordSite ObservationStatus
Manufacturer__________
Model__________
Serial Number__________
Equipment Tag__________
PLC Version__________
HMI Version__________

Any unexplained difference should be assessed.


8.14 Installation Verification

SAT may perform an initial installation verification before formal IQ.

Check:

  • location;
  • orientation;
  • leveling;
  • anchoring;
  • access;
  • clearance;
  • assembly;
  • guards;
  • covers;
  • piping connections;
  • cable connections;
  • ancillary equipment.

SAT does not necessarily replace the formal IQ installation verification.


8.15 Equipment Location

Verify that the equipment is installed in the intended room/location.

Consider:

  • approved layout;
  • material flow;
  • personnel flow;
  • cleaning access;
  • maintenance access;
  • operator access;
  • interfaces with adjacent equipment.

A technically functioning machine may still be unacceptable if installation creates poor GMP accessibility.


8.16 Reassembly Verification

Equipment may be partially dismantled for shipment.

Verify correct reassembly of:

  • guards;
  • motors;
  • hoppers;
  • feeders;
  • product chutes;
  • sensors;
  • cables;
  • piping;
  • instruments;
  • safety devices.

Critical components removed after FAT should receive particular attention.


8.17 Leveling and Alignment

Where equipment performance depends on physical alignment, verify:

  • leveling;
  • alignment;
  • interface alignment;
  • vibration;
  • foundation/anchoring.

For a tablet compression line, alignment may be important between:

Compression Machine → Deduster → Metal Detector → Collection System


8.18 Utility Connections

SAT should confirm correct connection of required utilities.

Examples:

  • electrical power;
  • compressed air;
  • vacuum;
  • dust extraction;
  • nitrogen;
  • chilled water;
  • Purified Water;
  • clean steam;
  • process gases.

The exact scope depends on equipment.


8.19 Utility Verification Table

UtilityRequirementSite SupplyConnectionResult
ElectricalAs approved_____Correct
Compressed Air__________Correct
Vacuum__________Correct
Dust Extraction__________Correct
Nitrogen__________Correct

Actual acceptance criteria should come from approved requirements/design specifications.


8.20 Utility Quality

Do not verify only that a pipe is connected.

Where relevant, consider:

  • pressure;
  • flow;
  • temperature;
  • quality;
  • capacity;
  • connection material;
  • connection size;
  • identification.

Example:

A machine requiring compressed air at a specified operating pressure should not be accepted merely because a compressed-air hose is physically connected.


8.21 Electrical Supply

Verify:

  • supply voltage;
  • frequency;
  • phase;
  • protective earthing;
  • isolator;
  • panel supply;
  • circuit protection;
  • electrical identification.

Site supply should correspond to the approved equipment requirement.


8.22 Motor Rotation

Transportation/reconnection may result in incorrect motor rotation.

Where applicable verify direction for:

  • main motor;
  • pumps;
  • blowers;
  • fans;
  • feeders;
  • auxiliary motors.

Incorrect rotation can cause equipment damage or process failure.


8.23 Instrument Verification

Instrumentation should be checked after shipment.

Verify as appropriate:

  • tag;
  • physical condition;
  • location;
  • range;
  • wiring;
  • tubing;
  • connection;
  • display;
  • signal;
  • calibration status.

8.24 Instrument Damage

Transportation may affect:

  • load cells;
  • pressure transmitters;
  • temperature sensors;
  • proximity sensors;
  • speed sensors;
  • balances;
  • force transducers.

Sensitive instruments may require calibration or functional verification after installation depending on risk and manufacturer recommendations.


8.25 Calibration Status

SAT should verify that instruments used for acceptance testing are appropriately calibrated.

For installed GMP-relevant instruments, establish whether:

  • vendor calibration remains valid;
  • transportation affects calibration;
  • site calibration is required before IQ/OQ;
  • calibration range matches intended use.

8.26 Electrical Checks

SAT electrical checks may include:

  • panel condition;
  • wiring;
  • loose terminals;
  • cable connections;
  • earthing;
  • power supply;
  • motor connections;
  • field devices;
  • emergency circuits;
  • safety relays.

These checks are especially important after equipment has been dismantled and reconnected.


8.27 Safety Systems

Safety functions should be confirmed after installation.

Examples:

  • emergency stops;
  • guard switches;
  • door interlocks;
  • safety relays;
  • overload protection;
  • pressure protection;
  • safety sensors.

A safety function that passed FAT may still require site confirmation because wiring or mechanical installation may have changed.


8.28 Emergency-Stop Verification

Example test:

  1. Establish safe operating condition.
  2. Start the equipment.
  3. Activate designated emergency stop.
  4. Observe equipment response.
  5. Confirm required equipment shutdown.
  6. Reset emergency stop.
  7. Verify restart behavior.

Acceptance criteria should derive from the approved design.


8.29 Guard Interlock Verification

Example:

Guard Closed

Machine permitted to operate.

Guard Opened

Machine responds according to design.

Attempt Restart with Guard Open

Restart prevented where specified.

Guard Closed + Reset

Controlled restart becomes possible.

Critical interlocks should be challenged, not merely visually inspected.


8.30 PLC Verification

After installation verify:

  • PLC hardware;
  • CPU/module identification;
  • program version;
  • firmware where relevant;
  • communication;
  • configuration;
  • backup status.

The key question is:

Is the site-installed PLC configuration the same approved configuration tested at FAT, or have changes occurred?


8.31 Software Version Comparison

A useful SAT record is:

ItemFAT VersionDelivered VersionSite VersionDifference?
PLC_______________
HMI_______________
SCADA_______________
Firmware_______________
Recipe DB_______________

Any difference should be assessed.


8.32 HMI Verification

Verify basic HMI functionality:

  • startup;
  • login;
  • screen navigation;
  • equipment status;
  • parameter display;
  • alarm display;
  • recipe access;
  • user access;
  • date/time;
  • communication with PLC.

Detailed OQ testing can follow later.


8.33 SCADA Verification

Where SCADA is used, SAT may verify:

  • server/client connectivity;
  • PLC communication;
  • tag communication;
  • alarms;
  • trends;
  • historian connection;
  • user login;
  • time synchronization;
  • interface connectivity.

Site infrastructure is often unavailable during factory testing, making SAT particularly important.


8.34 Network Connections

Verify applicable:

  • Ethernet connections;
  • switches;
  • network ports;
  • IP configuration;
  • VLAN/network configuration where applicable;
  • server connectivity;
  • domain connection;
  • firewall arrangements;
  • time synchronization.

Detailed cybersecurity/CSV verification may occur later according to the approved validation strategy.


8.35 Communication Checks

Communication should be verified between relevant systems.

Examples:

PLC ↔ HMI

PLC ↔ SCADA

Equipment ↔ MES

Equipment ↔ Historian

Compression Machine ↔ Metal Detector

Machine ↔ Checkweigher

Equipment ↔ BMS/EMS


8.36 Communication Failure

Where risk significant, test or plan later challenge of communication loss.

Verify:

  • alarm generation;
  • equipment response;
  • data behavior;
  • recovery;
  • resynchronization.

A system should not silently lose critical communication without an appropriate response where the approved design requires one.


8.37 Peripheral Equipment Interfaces

For integrated lines, SAT should verify physical and signal interfaces.

Example:

Tablet Compression Machine
          ↓
       Deduster
          ↓
     Metal Detector
          ↓
      Checkweigher
          ↓
 Product Collection

Check:

  • physical alignment;
  • start/stop signals;
  • permissives;
  • fault signals;
  • reject interfaces;
  • downstream-full signals where applicable.

8.38 Alarm Checks

SAT should confirm important alarms remain functional after installation.

Potential examples:

  • compressed-air low;
  • lubrication failure;
  • motor overload;
  • guard open;
  • communication failure;
  • emergency stop;
  • downstream equipment fault.

Detailed alarm challenge testing may be performed during OQ.


8.39 FAT Alarm vs SAT Alarm

Suppose an alarm was comprehensively challenged during FAT.

At SAT, the team might confirm:

  • relevant field device connected;
  • signal reaches PLC;
  • correct alarm appears;
  • correct site-connected function responds.

Whether the full FAT test needs repetition depends on risk and the approved leveraging strategy.


8.40 Basic Functional Testing

SAT should generally demonstrate basic operation before formal qualification progresses.

Potential checks:

  • power ON/OFF;
  • startup;
  • shutdown;
  • motor operation;
  • equipment movement;
  • manual mode;
  • automatic mode;
  • basic sequence;
  • alarms;
  • interlocks;
  • HMI;
  • communications.

The goal is not necessarily to execute full OQ.


8.41 Dry Run

A dry run may be useful.

A dry run operates equipment without commercial product to verify:

  • mechanical movement;
  • sequence;
  • sensors;
  • motors;
  • controls;
  • alarms;
  • interfaces.

Dry-run results may identify installation problems before qualification execution.


8.42 Water/Placebo/Simulation Runs

Depending on equipment type, commissioning/SAT may use:

  • water;
  • placebo;
  • dummy material;
  • simulated signals;
  • test pieces.

Use should be appropriate to the system and controlled according to site procedures.


8.43 FAT Punch-List Review

Every FAT punch-list item should be reviewed at SAT.

Possible statuses:

  • closed before shipment;
  • closed during installation;
  • requires SAT verification;
  • remains open;
  • transferred to qualification action list.

No item should disappear merely because the equipment has moved to site.


8.44 FAT Punch-List Closure Table

FAT ItemDescriptionRequired Site ActionEvidenceStatus
FAT-PL-01Panel label missingVerify installedPhoto/inspectionClosed
FAT-PL-02HMI text correctionVerify softwareScreenshotClosed
FAT-PL-03Drawing updateVerify final drawingDrawing reviewOpen

8.45 Site-Specific Differences

SAT is particularly important for identifying differences between the factory and site configurations.

Examples:

  • utility pressure;
  • electrical supply;
  • network;
  • server;
  • room environment;
  • dust extraction;
  • upstream equipment;
  • downstream equipment;
  • software interfaces;
  • user accounts;
  • site recipes.

These differences should feed into IQ/OQ scope.


8.46 Site-Specific Configuration

Examples include:

  • equipment tag;
  • user accounts;
  • network address;
  • printer;
  • time zone;
  • server connection;
  • recipe database;
  • alarm routing;
  • site naming conventions.

Configuration changes made after FAT should be controlled and verified.


8.47 Site User Accounts

Factory systems may contain vendor test accounts.

Before GMP use, review:

  • vendor accounts;
  • default passwords;
  • temporary accounts;
  • administrator accounts;
  • site user roles.

SAT may identify these items, while final access-control qualification may occur during OQ/CSV.


8.48 Vendor Remote Access

Where remote access exists, SAT should identify:

  • whether remote access is enabled;
  • method of connection;
  • authorization process;
  • account control;
  • logging;
  • disabling mechanism.

The final control should align with approved site security/GMP procedures.


8.49 Date and Time

For systems generating GMP-relevant electronic records, verify appropriate site date/time configuration.

Consider:

  • local time;
  • time synchronization;
  • time zone;
  • daylight-saving handling where relevant;
  • unauthorized time modification.

Detailed testing may occur in OQ/CSV.


8.50 Data Storage

Where site installation changes the data architecture, SAT should confirm connectivity.

Example:

Machine PLC
    ↓
Machine HMI
    ↓
Site SCADA
    ↓
Historian
    ↓
Server / Archive

The factory test may have used a temporary vendor server.

The actual site path therefore requires verification.


8.51 Backup After Installation

After final site configuration, create or verify an appropriate baseline backup where required.

Potential items:

  • PLC program;
  • HMI application;
  • SCADA configuration;
  • recipes;
  • configuration database.

The site baseline should be clearly identifiable.


8.52 Configuration Baseline

A useful SAT deliverable is:

Site-Installed Configuration Baseline

It may identify:

  • hardware;
  • firmware;
  • software;
  • PLC program;
  • HMI application;
  • SCADA version;
  • critical configuration;
  • network configuration.

This provides a reference for OQ and future change control.


8.53 SAT Deviations

A SAT discrepancy may arise when:

  • equipment is damaged;
  • wrong component is installed;
  • utility requirement is not met;
  • wiring is incorrect;
  • software version differs;
  • alarm fails;
  • interface fails;
  • FAT punch-list item remains unresolved.

These should be documented and assessed.


8.54 SAT Deviation Lifecycle

Observation
    ↓
Document
    ↓
Initial Impact Assessment
    ↓
Can SAT Safely Continue?
  ┌──────┴──────┐
 Yes            No
  │              │
Continue       Stop Affected Testing
  │              │
  └──────┬───────┘
         ↓
     Investigation
         ↓
     Correction
         ↓
 Qualification Impact?
      ┌───┴───┐
     Yes      No
      │        │
 Update     Document
 Strategy      │
      ↓        ↓
    Retest / Verify
         ↓
       Closure

8.55 When Should SAT Stop?

Execution of the affected test/system should normally be stopped pending assessment where continuing could:

  • create safety risk;
  • damage equipment;
  • compromise GMP-relevant evidence;
  • invalidate subsequent testing;
  • mask the root cause;
  • cause further failures.

Not every minor discrepancy requires complete SAT shutdown.

The response should be proportionate to risk.


8.56 Retesting

Retesting should occur after:

  • issue documentation;
  • appropriate assessment/investigation;
  • correction;
  • authorization according to procedure.

The original failed result should remain part of the record.

Never:

Fail → Fix → Delete → Repeat → Pass

Instead:

Fail → Record → Assess → Correct → Retest → Retain Complete History


8.57 SAT Punch List

SAT may generate its own punch list.

Example:

ItemObservationCriticalityOwnerRequired BeforeStatus
01Network interface unavailableHighITOQOpen
02Drawing requires updateMediumVendorIQ closureOpen
03Cosmetic panel scratchLowVendorProject closeoutOpen

The significance should determine whether progression is permitted.


8.58 SAT Acceptance Criteria

Overall SAT acceptance criteria may include:

  • equipment received without unresolved critical damage;
  • equipment identity confirmed;
  • installation sufficiently complete;
  • utilities appropriately connected;
  • critical electrical checks acceptable;
  • critical instruments functional;
  • safety systems functional;
  • PLC/HMI operational;
  • required communications established;
  • critical FAT punch-list items closed;
  • site-specific configuration documented;
  • deviations appropriately dispositioned.

8.59 SAT Completion Does Not Equal GMP Release

Successful SAT means:

The equipment is sufficiently accepted at site to progress according to the approved project/qualification strategy.

It does not automatically mean:

The equipment may be used for routine GMP production.

Normally the system must still complete applicable:

IQ → OQ → PQ → SOP/Training Readiness → Qualification Summary → GMP Release


8.60 Leveraging SAT Evidence

Just as FAT evidence may potentially support qualification, suitable SAT/commissioning evidence may also be leveraged.

Potential examples:

  • equipment identification;
  • utility connection;
  • component verification;
  • instrument verification;
  • electrical verification;
  • loop checks;
  • software-version verification;
  • interface testing.

But leverage should be planned and justified.


8.61 Conditions for Leveraging SAT Evidence

Ask:

  1. Was the test predefined?
  2. Was it executed under controlled conditions?
  3. Were acceptance criteria predefined?
  4. Were actual results recorded?
  5. Is raw evidence retained?
  6. Were appropriate calibrated test instruments used?
  7. Are executors identifiable?
  8. Were deviations controlled?
  9. Is the configuration unchanged?
  10. Does the evidence directly satisfy a qualification requirement?

If yes, unnecessary duplicate testing may potentially be avoided under the approved qualification strategy.


8.62 Example — Leveraging Utility Verification

Suppose SAT verifies:

Compressed-air connection

  • correct connection;
  • pressure measured;
  • instrument ID recorded;
  • calibrated test gauge used;
  • acceptance criteria met;
  • evidence retained.

If the approved C&Q strategy permits leveraging, IQ may reference this controlled evidence rather than repeating an identical measurement without scientific value.


8.63 Example — When Reverification Is Needed

Suppose SAT verifies a pressure transmitter.

After SAT, the transmitter is removed for maintenance.

Then:

The earlier SAT evidence may no longer fully represent the final installed state.

The impact should be assessed and appropriate re-verification performed.


8.64 SAT Report

A SAT report should summarize:

  1. Objective
  2. Scope
  3. Equipment/system
  4. SAT dates
  5. Participants
  6. FAT status
  7. Tests performed
  8. Test results
  9. Deviations
  10. Retests
  11. FAT punch-list closure
  12. SAT punch-list items
  13. Site-specific changes
  14. Software/configuration status
  15. Outstanding actions
  16. Qualification impact
  17. Overall conclusion
  18. Readiness recommendation
  19. Approval

8.65 Example SAT Summary

SectionStatusComments
Shipment InspectionPassNo critical damage
InstallationPassInstallation complete
UtilitiesPassRequired services available
ElectricalPassSite supply verified
InstrumentsPassCritical instruments checked
SafetyPassCritical safety functions verified
PLC/HMIPassFAT version confirmed
CommunicationOpenMES interface pending
FAT Punch ListPassCritical items closed
DocumentationConditionalTwo as-built drawings pending

Overall conclusion might be:

SAT acceptable for progression to IQ, subject to documented closure of identified non-blocking open items according to the approved qualification plan.


8.66 Worked Example — Tablet Compression Machine SAT

For the compression machine example used throughout the handbook, SAT could include:

Receipt

  • machine identity;
  • shipping damage;
  • major components;
  • product-contact components.

Installation

  • location;
  • leveling;
  • feeder assembly;
  • guards;
  • discharge;
  • deduster interface.

Utilities

  • electrical;
  • compressed air;
  • dust extraction;
  • vacuum where applicable.

Electrical

  • panel;
  • power;
  • earthing;
  • motors;
  • rotation.

Instruments

  • compression-force system;
  • speed feedback;
  • sensors;
  • pressure switches.

Automation

  • PLC version;
  • HMI version;
  • communication;
  • user access;
  • site configuration.

Safety

  • emergency stops;
  • guards;
  • interlocks.

Interfaces

  • deduster;
  • metal detector;
  • downstream equipment.

8.67 Compression Machine SAT Matrix

FunctionFAT StatusSAT VerificationReason
Machine identityPassVerifyConfirm delivered machine
Product-contact partsPassInspectShipment/reassembly
Main motorPassRotation checkElectrical reconnection
Turret drivePassBasic functionTransportation/reassembly
Compression forcePassBasic signal checkSensor integrity
FeederPassFunctional checkReassembly
Reject systemPassBasic checkMechanical/site connection
GuardsPassChallengeReassembly
Emergency stopPassChallengeSafety wiring
PLC softwarePassVersion checkConfiguration integrity
HMIPassFunctional checkSite installation
SCADASimulatedSite testActual infrastructure
Metal detector interfacePartialSite testActual equipment interface
MES interfaceNot testedSite testSite-specific system

8.68 Risk-to-SAT Example

URS

Machine shall prevent operation when the designated safety guard is open.

FAT

Guard interlock challenged successfully.

Transportation

Guard removed for shipment.

Site Installation

Guard and safety switch reinstalled.

SAT Risk

Incorrect alignment/wiring could invalidate FAT result.

SAT Test

Challenge guard interlock again.

Result

Pass.

OQ Strategy

Final qualification verification performed/referenced according to the approved risk-based strategy.

This demonstrates why some FAT tests should be repeated at site.


8.69 Site Interface Example

Consider:

Compression Machine → Deduster → Metal Detector

At FAT, the vendor may simulate the metal-detector signal.

At SAT, actual equipment is available.

Test:

  1. Confirm physical interface.
  2. Confirm communication/signal wiring.
  3. Generate defined metal-detector fault/reject signal where safe.
  4. Verify compression-line response.
  5. Verify alarm/indication.
  6. Verify recovery.

The site test provides evidence that factory simulation could not provide.


8.70 Site Network Example

Factory configuration:

PLC → Vendor Laptop

Site configuration:

PLC → HMI → SCADA → Site Network → Historian

Therefore, factory communication testing cannot fully establish site operation.

SAT should verify actual connections before detailed OQ/CSV testing.


8.71 Site Configuration Change Example

During installation, the site requests:

Change alarm text from “Air Low” to “Compressed Air Pressure Low.”

Even a seemingly minor software change should be controlled.

Assess:

  • version impact;
  • affected screens;
  • alarm logic;
  • documentation;
  • regression-test requirement.

Do not allow uncontrolled vendor modifications simply because the vendor engineer is on site.


8.72 SAT RACI Example

ActivityProductionEngineeringValidationQAIT/AutomationVendor
Receipt inspectionCRCIIC
Installation checksCRCCCR
UtilitiesCRCIIC
ElectricalIRCICR
Instrument checksCRCCCR
SafetyCRCCCR
PLC/HMICCCCRR
NetworkICCIRC
DeviationsCR/CRACC
SAT reportCRR/CA/CCC

R = Responsible, A = Accountable, C = Consulted, I = Informed.

Actual assignments depend on the company’s PQS.


8.73 Common SAT Deficiencies

DeficiencyGMP/Project Concern
SAT skipped because FAT passedTransportation/site risks missed
Shipment damage not documentedEquipment integrity uncertain
Wrong equipment/version deliveredTraceability failure
Utilities only visually checkedActual suitability unknown
Critical instruments not checkedTransport damage may remain
Safety functions not reverifiedReassembly risk
Software changed without controlFAT baseline invalid
Site interfaces not testedIntegration failure discovered during OQ
FAT punch list ignoredKnown problems remain unresolved
SAT results only recorded as “OK”Weak evidence
Uncontrolled vendor changesConfiguration integrity compromised
Failed tests repeated without documentationData-integrity concern
SAT automatically treated as IQ/OQQualification purpose unclear

8.74 Inspector Perspective

An inspector may ask:

How did you ensure the equipment received at site was the same equipment tested during FAT?

Expected evidence:

  • equipment identification;
  • serial number;
  • FAT report;
  • SAT identification record;
  • software version comparison.

Another question:

What changed between FAT and OQ?

The organization should be able to show:

FAT Baseline

Shipment

Site Installation

Site Changes

SAT

Final Configuration

IQ/OQ


8.75 Inspector Question — Vendor Site Changes

An inspector may ask:

Did the vendor make any software changes during installation?

Strong evidence should include:

  • change record;
  • reason;
  • affected software;
  • version;
  • impact assessment;
  • regression testing;
  • updated backup;
  • updated documentation.

A response such as:

“The vendor made a few small changes; we do not know exactly what”

would be a serious control weakness.


8.76 Inspector Question — FAT Leverage

An inspector may ask:

Why did you not repeat this test at site?

A defensible response should show:

  • approved qualification strategy;
  • risk assessment;
  • FAT evidence;
  • configuration verification;
  • change assessment;
  • site-dependency assessment;
  • SAT confirmation where appropriate.

The key is not whether the test was repeated.

The key is whether sufficient evidence exists for the final installed state.


8.77 SAT Best Practices

A mature SAT program should:

  • use FAT as an input;
  • focus on what can change during shipment/installation;
  • inspect equipment systematically;
  • verify site utilities;
  • confirm sensitive instrumentation;
  • verify safety systems after reassembly;
  • compare software versions;
  • control vendor modifications;
  • verify actual site interfaces;
  • close FAT punch items;
  • retain raw evidence;
  • document failures transparently;
  • establish the site configuration baseline;
  • formally determine readiness for qualification.

8.78 SAT Inspection-Readiness Checklist

Documentation

  • □ Approved SAT protocol
  • □ URS available
  • □ DQ available
  • □ Risk assessment available
  • □ FAT protocol/report available
  • □ FAT deviations available
  • □ FAT punch list available
  • □ Drawings available
  • □ Vendor manuals available

Receipt

  • □ Equipment identity verified
  • □ Serial number verified
  • □ Shipping condition inspected
  • □ Damage documented
  • □ Missing parts assessed
  • □ Product-contact parts inspected

Installation

  • □ Location verified
  • □ Orientation verified
  • □ Leveling checked where relevant
  • □ Reassembly checked
  • □ Guards installed
  • □ Access acceptable
  • □ Interfaces aligned

Utilities

  • □ Electrical supply
  • □ Compressed air
  • □ Vacuum
  • □ Dust extraction
  • □ Water where applicable
  • □ Steam where applicable
  • □ Nitrogen/process gas where applicable
  • □ Utility parameters verified as required

Electrical

  • □ Panel inspected
  • □ Connections checked
  • □ Earthing verified
  • □ Motors checked
  • □ Rotation checked
  • □ Safety circuits checked

Instruments

  • □ Instruments identified
  • □ Damage checked
  • □ Ranges confirmed as needed
  • □ Calibration status reviewed
  • □ Signals verified
  • □ HMI indications checked

Automation

  • □ PLC identified
  • □ PLC version compared with FAT
  • □ HMI version compared
  • □ SCADA verified where applicable
  • □ Communication established
  • □ Site configuration documented
  • □ Network configuration controlled
  • □ Date/time checked
  • □ Backup baseline available

Functional/Safety

  • □ Startup
  • □ Shutdown
  • □ Basic sequence
  • □ Critical alarms
  • □ Critical interlocks
  • □ Emergency stops
  • □ Guards
  • □ Interfaces
  • □ Communication failure response where required

Closure

  • □ FAT punch-list items reviewed
  • □ SAT deviations documented
  • □ Retests controlled
  • □ SAT punch list established
  • □ Critical issues closed
  • □ Open items assessed
  • □ Qualification impact assessed
  • □ Configuration baseline documented
  • □ SAT report approved
  • □ IQ/OQ readiness established

8.79 SAT Readiness Gate

The final SAT decision should answer:

Is the site-installed equipment/system sufficiently complete, intact, connected, configured, functional, documented, and controlled to proceed to the next qualification stage?

Possible dispositions include:

Accepted

SAT successfully completed.

Conditionally Accepted

Noncritical open items remain with approved actions and closure requirements.

Not Accepted

Critical deficiencies prevent progression.


8.80 Golden Rule of SAT

The strongest SAT philosophy is:

Do not simply repeat FAT. Verify what transportation, installation, reassembly, site utilities, site infrastructure, interfaces, and site configuration could have changed or invalidated.

This makes SAT a risk-based lifecycle activity rather than another duplicate protocol.


Part 8 — Key Takeaway

SAT provides the bridge between supplier acceptance and formal site qualification.

The evidence chain becomes:

URS → Risk Assessment → DQ → FAT → FAT Baseline → Shipment → Receipt Inspection → Installation → Site Utilities → Site Configuration → SAT → Final Installed Baseline → IQ/OQ

A robust SAT should establish five things:

1. Equipment Integrity
The correct equipment arrived without unacceptable transportation damage.

2. Installation Readiness
The system has been appropriately positioned, reassembled and connected.

3. Site Integration
Utilities, electrical systems, networks and equipment interfaces function appropriately.

4. Configuration Integrity
Hardware/software/configuration remain controlled from FAT through site installation.

5. Qualification Readiness
Critical FAT/SAT deficiencies are resolved or appropriately dispositioned so formal qualification can proceed.

SAT therefore should not be treated as a duplicate FAT or a substitute for IQ/OQ. Its purpose is to provide documented assurance that the factory-tested system has successfully transitioned into its intended site-installed state.

The next stage is Part 9 — Installation Qualification (IQ).The IQ chapter to provide a detailed protocol structure covering equipment identity and installation, components and product-contact parts, materials and surface finish, utilities, piping/P&IDs, electrical systems, instruments and calibration, software/firmware and PLC/HMI/SCADA, network connections, safety devices, manuals, drawings, spares, lubricants, PM, SOP/training requirements and as-built documentation, with every IQ test structured as Objective → Prerequisite → Test Method → Expected Result → Actual Result → Acceptance Criteria → Evidence → Pass/Fail → Executed By → Reviewed By.

About the Author

Ramesh Palav is a pharmaceutical professional with 20+ years of industry experience in manufacturing, GMP, quality systems, validation, compliance, and operational excellence. Through Pharma Manufacturing Hub, he shares practical insights on pharmaceutical careers, manufacturing, quality, validation, Pharma 4.0, AI, and professional development.

His goal is to help students, freshers, experienced professionals, and career-break professionals build the knowledge and skills needed to succeed in the pharmaceutical industry.

Leave a Comment

Scroll to Top