Part 8

The lifecycle position is:
URS → Risk Assessment → DQ → FAT → Shipment → Installation → SAT → Commissioning → IQ → OQ → PQ → GMP Release
The central SAT question is:
Has the equipment/system arrived, been assembled, connected, and configured at the user site without unacceptable change or damage, and is it ready to proceed into formal site qualification?
8.1 What Is Site Acceptance Testing?
A Site Acceptance Test (SAT) is a planned and documented verification performed after equipment or a system has been delivered to and normally assembled/installed at its intended site.
SAT confirms that the system:
- arrived without unacceptable transportation damage;
- has been correctly reassembled;
- is connected to appropriate site utilities;
- retains the required hardware/software configuration;
- communicates with site systems where applicable;
- retains important functionality demonstrated at FAT;
- incorporates approved site-specific modifications;
- has resolved applicable FAT punch-list items;
- is sufficiently ready for commissioning and/or qualification.
SAT is particularly valuable for equipment that was:
- dismantled after FAT;
- transported over significant distances;
- reassembled at site;
- connected to new utilities;
- integrated with site infrastructure;
- connected to upstream/downstream equipment;
- connected to site networks or computerized systems.
8.2 Why SAT Is Required
FAT demonstrates the condition of the system at the supplier’s facility.
Between FAT and site installation, many things can change:
FAT-approved equipment
↓
Disassembly
↓
Packing
↓
Transportation
↓
Unloading
↓
Storage
↓
Positioning
↓
Reassembly
↓
Utility connection
↓
Network/interface connection
↓
Site configuration
Each step can introduce new risks.
Therefore:
A successful FAT does not prove that the equipment remains in the same acceptable state after transportation and installation.
SAT closes this gap.
8.3 FAT vs SAT vs IQ
These activities are related but serve different purposes.
| Activity | Primary Question |
|---|---|
| FAT | Does the factory-built/configured system satisfy applicable requirements before shipment? |
| SAT | Did the system arrive, reassemble, connect and function appropriately at the site? |
| IQ | Is the installed system documented and verified against approved installation/design requirements? |
| OQ | Does the installed system operate as intended throughout applicable operating ranges? |
A practical distinction is:
FAT = Factory State
SAT = Site-Arrival/Installed Functional State
IQ = Qualified Installation State
OQ = Qualified Operational State
8.4 SAT vs Commissioning
SAT may form part of commissioning, but the terms are not necessarily interchangeable.
SAT
Focused on acceptance of the delivered system at site.
Commissioning
Usually broader engineering activities intended to bring the system from installation into an operational state.
Commissioning may include:
- mechanical completion;
- utility startup;
- loop checks;
- flushing;
- rotation checks;
- balancing;
- functional testing;
- tuning;
- troubleshooting.
Where commissioning evidence is sufficiently controlled, relevant evidence may potentially support qualification according to the approved C&Q strategy.
8.5 SAT Strategy
The SAT strategy should be established before execution.
It should define:
- system/equipment scope;
- FAT results being relied upon;
- FAT tests requiring site confirmation;
- transportation-sensitive components;
- site utilities;
- site interfaces;
- site-specific configuration;
- safety checks;
- functional checks;
- punch-list closure;
- acceptance criteria;
- deviation management;
- readiness criteria for IQ/OQ.
8.6 Risk-Based SAT
SAT should not automatically repeat the entire FAT.
Instead ask:
What could have changed, failed, become damaged, become disconnected, or become incorrectly configured between successful FAT and site installation?
Typical risk areas include:
- physical damage;
- loose connections;
- instrument damage;
- wiring errors;
- incorrect motor rotation;
- utility mismatch;
- communication failure;
- software/configuration change;
- interface failure;
- safety-circuit problems.
This produces a focused and scientifically defensible SAT.
8.7 SAT Inputs
Typical inputs include:
- approved URS;
- DQ;
- risk assessment;
- FAT protocol;
- FAT report;
- FAT deviations;
- FAT punch list;
- equipment drawings;
- P&IDs;
- electrical drawings;
- utility specifications;
- instrument list;
- software/configuration records;
- vendor manuals;
- shipping documents;
- installation records.
8.8 SAT Prerequisites
Before SAT execution, verify as applicable:
- □ Equipment received
- □ Equipment positioned at intended location
- □ Major assembly completed
- □ Shipping inspection performed
- □ Required utilities available
- □ Electrical supply available
- □ Safety conditions established
- □ Relevant site permits complete
- □ FAT report available
- □ FAT punch list available
- □ SAT protocol approved
- □ Test instruments available
- □ Calibration status acceptable
- □ Drawings available
- □ Vendor/engineering personnel available
- □ Software/configuration information available
8.9 Recommended SAT Protocol Structure
A practical SAT protocol may contain:
1. Document Control
- title;
- SAT number;
- revision;
- equipment/system ID;
- project number.
2. Approval
- prepared by;
- reviewed by;
- approved by.
3. Objective
4. Scope
5. References
6. Definitions
7. Responsibilities
8. System Description
9. Prerequisites
10. FAT Status Review
11. Shipment/Receipt Inspection
12. Equipment Identification
13. Installation Verification
14. Utility Verification
15. Electrical Verification
16. Instrument Verification
17. Safety-System Verification
18. PLC/HMI/SCADA Verification
19. Communication/Interface Verification
20. Alarm Verification
21. Basic Functional Testing
22. Site-Specific Configuration
23. FAT Punch-List Closure
24. Deviations
25. SAT Punch List
26. Summary
27. Readiness for Qualification
28. Approval
8.10 Receipt and Shipment Inspection
One of the first SAT activities should be confirmation that transportation has not adversely affected the equipment.
Inspect for:
- damaged panels;
- dents;
- broken components;
- damaged product-contact parts;
- broken glass/screens;
- damaged cables;
- loose instruments;
- broken piping;
- damaged seals;
- corrosion;
- missing parts;
- water ingress;
- packaging damage.
8.11 Shipment Damage Assessment
If damage is found:
Observation
↓
Photograph/Document
↓
Identify Component
↓
Assess GMP/Safety/Functional Impact
↓
Notify Supplier/Project Team
↓
Repair/Replace
↓
Verify
↓
Close
Significant damage should not simply be repaired informally without assessing whether qualification impact exists.
8.12 Equipment Identification
Confirm that the delivered equipment is the equipment that underwent FAT.
Verify:
- manufacturer;
- model;
- serial number;
- equipment tag;
- major assemblies;
- applicable component identification.
This is especially important when vendors manufacture multiple similar machines.
8.13 Example Identification Table
| Parameter | FAT Record | Site Observation | Status |
|---|---|---|---|
| Manufacturer | _____ | _____ | |
| Model | _____ | _____ | |
| Serial Number | _____ | _____ | |
| Equipment Tag | _____ | _____ | |
| PLC Version | _____ | _____ | |
| HMI Version | _____ | _____ |
Any unexplained difference should be assessed.
8.14 Installation Verification
SAT may perform an initial installation verification before formal IQ.
Check:
- location;
- orientation;
- leveling;
- anchoring;
- access;
- clearance;
- assembly;
- guards;
- covers;
- piping connections;
- cable connections;
- ancillary equipment.
SAT does not necessarily replace the formal IQ installation verification.
8.15 Equipment Location
Verify that the equipment is installed in the intended room/location.
Consider:
- approved layout;
- material flow;
- personnel flow;
- cleaning access;
- maintenance access;
- operator access;
- interfaces with adjacent equipment.
A technically functioning machine may still be unacceptable if installation creates poor GMP accessibility.
8.16 Reassembly Verification
Equipment may be partially dismantled for shipment.
Verify correct reassembly of:
- guards;
- motors;
- hoppers;
- feeders;
- product chutes;
- sensors;
- cables;
- piping;
- instruments;
- safety devices.
Critical components removed after FAT should receive particular attention.
8.17 Leveling and Alignment
Where equipment performance depends on physical alignment, verify:
- leveling;
- alignment;
- interface alignment;
- vibration;
- foundation/anchoring.
For a tablet compression line, alignment may be important between:
Compression Machine → Deduster → Metal Detector → Collection System
8.18 Utility Connections
SAT should confirm correct connection of required utilities.
Examples:
- electrical power;
- compressed air;
- vacuum;
- dust extraction;
- nitrogen;
- chilled water;
- Purified Water;
- clean steam;
- process gases.
The exact scope depends on equipment.
8.19 Utility Verification Table
| Utility | Requirement | Site Supply | Connection | Result |
|---|---|---|---|---|
| Electrical | As approved | _____ | Correct | |
| Compressed Air | _____ | _____ | Correct | |
| Vacuum | _____ | _____ | Correct | |
| Dust Extraction | _____ | _____ | Correct | |
| Nitrogen | _____ | _____ | Correct |
Actual acceptance criteria should come from approved requirements/design specifications.
8.20 Utility Quality
Do not verify only that a pipe is connected.
Where relevant, consider:
- pressure;
- flow;
- temperature;
- quality;
- capacity;
- connection material;
- connection size;
- identification.
Example:
A machine requiring compressed air at a specified operating pressure should not be accepted merely because a compressed-air hose is physically connected.
8.21 Electrical Supply
Verify:
- supply voltage;
- frequency;
- phase;
- protective earthing;
- isolator;
- panel supply;
- circuit protection;
- electrical identification.
Site supply should correspond to the approved equipment requirement.
8.22 Motor Rotation
Transportation/reconnection may result in incorrect motor rotation.
Where applicable verify direction for:
- main motor;
- pumps;
- blowers;
- fans;
- feeders;
- auxiliary motors.
Incorrect rotation can cause equipment damage or process failure.
8.23 Instrument Verification
Instrumentation should be checked after shipment.
Verify as appropriate:
- tag;
- physical condition;
- location;
- range;
- wiring;
- tubing;
- connection;
- display;
- signal;
- calibration status.
8.24 Instrument Damage
Transportation may affect:
- load cells;
- pressure transmitters;
- temperature sensors;
- proximity sensors;
- speed sensors;
- balances;
- force transducers.
Sensitive instruments may require calibration or functional verification after installation depending on risk and manufacturer recommendations.
8.25 Calibration Status
SAT should verify that instruments used for acceptance testing are appropriately calibrated.
For installed GMP-relevant instruments, establish whether:
- vendor calibration remains valid;
- transportation affects calibration;
- site calibration is required before IQ/OQ;
- calibration range matches intended use.
8.26 Electrical Checks
SAT electrical checks may include:
- panel condition;
- wiring;
- loose terminals;
- cable connections;
- earthing;
- power supply;
- motor connections;
- field devices;
- emergency circuits;
- safety relays.
These checks are especially important after equipment has been dismantled and reconnected.
8.27 Safety Systems
Safety functions should be confirmed after installation.
Examples:
- emergency stops;
- guard switches;
- door interlocks;
- safety relays;
- overload protection;
- pressure protection;
- safety sensors.
A safety function that passed FAT may still require site confirmation because wiring or mechanical installation may have changed.
8.28 Emergency-Stop Verification
Example test:
- Establish safe operating condition.
- Start the equipment.
- Activate designated emergency stop.
- Observe equipment response.
- Confirm required equipment shutdown.
- Reset emergency stop.
- Verify restart behavior.
Acceptance criteria should derive from the approved design.
8.29 Guard Interlock Verification
Example:
Guard Closed
↓
Machine permitted to operate.
Guard Opened
↓
Machine responds according to design.
Attempt Restart with Guard Open
↓
Restart prevented where specified.
Guard Closed + Reset
↓
Controlled restart becomes possible.
Critical interlocks should be challenged, not merely visually inspected.
8.30 PLC Verification
After installation verify:
- PLC hardware;
- CPU/module identification;
- program version;
- firmware where relevant;
- communication;
- configuration;
- backup status.
The key question is:
Is the site-installed PLC configuration the same approved configuration tested at FAT, or have changes occurred?
8.31 Software Version Comparison
A useful SAT record is:
| Item | FAT Version | Delivered Version | Site Version | Difference? |
|---|---|---|---|---|
| PLC | _____ | _____ | _____ | |
| HMI | _____ | _____ | _____ | |
| SCADA | _____ | _____ | _____ | |
| Firmware | _____ | _____ | _____ | |
| Recipe DB | _____ | _____ | _____ |
Any difference should be assessed.
8.32 HMI Verification
Verify basic HMI functionality:
- startup;
- login;
- screen navigation;
- equipment status;
- parameter display;
- alarm display;
- recipe access;
- user access;
- date/time;
- communication with PLC.
Detailed OQ testing can follow later.
8.33 SCADA Verification
Where SCADA is used, SAT may verify:
- server/client connectivity;
- PLC communication;
- tag communication;
- alarms;
- trends;
- historian connection;
- user login;
- time synchronization;
- interface connectivity.
Site infrastructure is often unavailable during factory testing, making SAT particularly important.
8.34 Network Connections
Verify applicable:
- Ethernet connections;
- switches;
- network ports;
- IP configuration;
- VLAN/network configuration where applicable;
- server connectivity;
- domain connection;
- firewall arrangements;
- time synchronization.
Detailed cybersecurity/CSV verification may occur later according to the approved validation strategy.
8.35 Communication Checks
Communication should be verified between relevant systems.
Examples:
PLC ↔ HMI
PLC ↔ SCADA
Equipment ↔ MES
Equipment ↔ Historian
Compression Machine ↔ Metal Detector
Machine ↔ Checkweigher
Equipment ↔ BMS/EMS
8.36 Communication Failure
Where risk significant, test or plan later challenge of communication loss.
Verify:
- alarm generation;
- equipment response;
- data behavior;
- recovery;
- resynchronization.
A system should not silently lose critical communication without an appropriate response where the approved design requires one.
8.37 Peripheral Equipment Interfaces
For integrated lines, SAT should verify physical and signal interfaces.
Example:
Tablet Compression Machine
↓
Deduster
↓
Metal Detector
↓
Checkweigher
↓
Product Collection
Check:
- physical alignment;
- start/stop signals;
- permissives;
- fault signals;
- reject interfaces;
- downstream-full signals where applicable.
8.38 Alarm Checks
SAT should confirm important alarms remain functional after installation.
Potential examples:
- compressed-air low;
- lubrication failure;
- motor overload;
- guard open;
- communication failure;
- emergency stop;
- downstream equipment fault.
Detailed alarm challenge testing may be performed during OQ.
8.39 FAT Alarm vs SAT Alarm
Suppose an alarm was comprehensively challenged during FAT.
At SAT, the team might confirm:
- relevant field device connected;
- signal reaches PLC;
- correct alarm appears;
- correct site-connected function responds.
Whether the full FAT test needs repetition depends on risk and the approved leveraging strategy.
8.40 Basic Functional Testing
SAT should generally demonstrate basic operation before formal qualification progresses.
Potential checks:
- power ON/OFF;
- startup;
- shutdown;
- motor operation;
- equipment movement;
- manual mode;
- automatic mode;
- basic sequence;
- alarms;
- interlocks;
- HMI;
- communications.
The goal is not necessarily to execute full OQ.
8.41 Dry Run
A dry run may be useful.
A dry run operates equipment without commercial product to verify:
- mechanical movement;
- sequence;
- sensors;
- motors;
- controls;
- alarms;
- interfaces.
Dry-run results may identify installation problems before qualification execution.
8.42 Water/Placebo/Simulation Runs
Depending on equipment type, commissioning/SAT may use:
- water;
- placebo;
- dummy material;
- simulated signals;
- test pieces.
Use should be appropriate to the system and controlled according to site procedures.
8.43 FAT Punch-List Review
Every FAT punch-list item should be reviewed at SAT.
Possible statuses:
- closed before shipment;
- closed during installation;
- requires SAT verification;
- remains open;
- transferred to qualification action list.
No item should disappear merely because the equipment has moved to site.
8.44 FAT Punch-List Closure Table
| FAT Item | Description | Required Site Action | Evidence | Status |
|---|---|---|---|---|
| FAT-PL-01 | Panel label missing | Verify installed | Photo/inspection | Closed |
| FAT-PL-02 | HMI text correction | Verify software | Screenshot | Closed |
| FAT-PL-03 | Drawing update | Verify final drawing | Drawing review | Open |
8.45 Site-Specific Differences
SAT is particularly important for identifying differences between the factory and site configurations.
Examples:
- utility pressure;
- electrical supply;
- network;
- server;
- room environment;
- dust extraction;
- upstream equipment;
- downstream equipment;
- software interfaces;
- user accounts;
- site recipes.
These differences should feed into IQ/OQ scope.
8.46 Site-Specific Configuration
Examples include:
- equipment tag;
- user accounts;
- network address;
- printer;
- time zone;
- server connection;
- recipe database;
- alarm routing;
- site naming conventions.
Configuration changes made after FAT should be controlled and verified.
8.47 Site User Accounts
Factory systems may contain vendor test accounts.
Before GMP use, review:
- vendor accounts;
- default passwords;
- temporary accounts;
- administrator accounts;
- site user roles.
SAT may identify these items, while final access-control qualification may occur during OQ/CSV.
8.48 Vendor Remote Access
Where remote access exists, SAT should identify:
- whether remote access is enabled;
- method of connection;
- authorization process;
- account control;
- logging;
- disabling mechanism.
The final control should align with approved site security/GMP procedures.
8.49 Date and Time
For systems generating GMP-relevant electronic records, verify appropriate site date/time configuration.
Consider:
- local time;
- time synchronization;
- time zone;
- daylight-saving handling where relevant;
- unauthorized time modification.
Detailed testing may occur in OQ/CSV.
8.50 Data Storage
Where site installation changes the data architecture, SAT should confirm connectivity.
Example:
Machine PLC
↓
Machine HMI
↓
Site SCADA
↓
Historian
↓
Server / Archive
The factory test may have used a temporary vendor server.
The actual site path therefore requires verification.
8.51 Backup After Installation
After final site configuration, create or verify an appropriate baseline backup where required.
Potential items:
- PLC program;
- HMI application;
- SCADA configuration;
- recipes;
- configuration database.
The site baseline should be clearly identifiable.
8.52 Configuration Baseline
A useful SAT deliverable is:
Site-Installed Configuration Baseline
It may identify:
- hardware;
- firmware;
- software;
- PLC program;
- HMI application;
- SCADA version;
- critical configuration;
- network configuration.
This provides a reference for OQ and future change control.
8.53 SAT Deviations
A SAT discrepancy may arise when:
- equipment is damaged;
- wrong component is installed;
- utility requirement is not met;
- wiring is incorrect;
- software version differs;
- alarm fails;
- interface fails;
- FAT punch-list item remains unresolved.
These should be documented and assessed.
8.54 SAT Deviation Lifecycle
Observation
↓
Document
↓
Initial Impact Assessment
↓
Can SAT Safely Continue?
┌──────┴──────┐
Yes No
│ │
Continue Stop Affected Testing
│ │
└──────┬───────┘
↓
Investigation
↓
Correction
↓
Qualification Impact?
┌───┴───┐
Yes No
│ │
Update Document
Strategy │
↓ ↓
Retest / Verify
↓
Closure
8.55 When Should SAT Stop?
Execution of the affected test/system should normally be stopped pending assessment where continuing could:
- create safety risk;
- damage equipment;
- compromise GMP-relevant evidence;
- invalidate subsequent testing;
- mask the root cause;
- cause further failures.
Not every minor discrepancy requires complete SAT shutdown.
The response should be proportionate to risk.
8.56 Retesting
Retesting should occur after:
- issue documentation;
- appropriate assessment/investigation;
- correction;
- authorization according to procedure.
The original failed result should remain part of the record.
Never:
Fail → Fix → Delete → Repeat → Pass
Instead:
Fail → Record → Assess → Correct → Retest → Retain Complete History
8.57 SAT Punch List
SAT may generate its own punch list.
Example:
| Item | Observation | Criticality | Owner | Required Before | Status |
|---|---|---|---|---|---|
| 01 | Network interface unavailable | High | IT | OQ | Open |
| 02 | Drawing requires update | Medium | Vendor | IQ closure | Open |
| 03 | Cosmetic panel scratch | Low | Vendor | Project closeout | Open |
The significance should determine whether progression is permitted.
8.58 SAT Acceptance Criteria
Overall SAT acceptance criteria may include:
- equipment received without unresolved critical damage;
- equipment identity confirmed;
- installation sufficiently complete;
- utilities appropriately connected;
- critical electrical checks acceptable;
- critical instruments functional;
- safety systems functional;
- PLC/HMI operational;
- required communications established;
- critical FAT punch-list items closed;
- site-specific configuration documented;
- deviations appropriately dispositioned.
8.59 SAT Completion Does Not Equal GMP Release
Successful SAT means:
The equipment is sufficiently accepted at site to progress according to the approved project/qualification strategy.
It does not automatically mean:
The equipment may be used for routine GMP production.
Normally the system must still complete applicable:
IQ → OQ → PQ → SOP/Training Readiness → Qualification Summary → GMP Release
8.60 Leveraging SAT Evidence
Just as FAT evidence may potentially support qualification, suitable SAT/commissioning evidence may also be leveraged.
Potential examples:
- equipment identification;
- utility connection;
- component verification;
- instrument verification;
- electrical verification;
- loop checks;
- software-version verification;
- interface testing.
But leverage should be planned and justified.
8.61 Conditions for Leveraging SAT Evidence
Ask:
- Was the test predefined?
- Was it executed under controlled conditions?
- Were acceptance criteria predefined?
- Were actual results recorded?
- Is raw evidence retained?
- Were appropriate calibrated test instruments used?
- Are executors identifiable?
- Were deviations controlled?
- Is the configuration unchanged?
- Does the evidence directly satisfy a qualification requirement?
If yes, unnecessary duplicate testing may potentially be avoided under the approved qualification strategy.
8.62 Example — Leveraging Utility Verification
Suppose SAT verifies:
Compressed-air connection
- correct connection;
- pressure measured;
- instrument ID recorded;
- calibrated test gauge used;
- acceptance criteria met;
- evidence retained.
If the approved C&Q strategy permits leveraging, IQ may reference this controlled evidence rather than repeating an identical measurement without scientific value.
8.63 Example — When Reverification Is Needed
Suppose SAT verifies a pressure transmitter.
After SAT, the transmitter is removed for maintenance.
Then:
The earlier SAT evidence may no longer fully represent the final installed state.
The impact should be assessed and appropriate re-verification performed.
8.64 SAT Report
A SAT report should summarize:
- Objective
- Scope
- Equipment/system
- SAT dates
- Participants
- FAT status
- Tests performed
- Test results
- Deviations
- Retests
- FAT punch-list closure
- SAT punch-list items
- Site-specific changes
- Software/configuration status
- Outstanding actions
- Qualification impact
- Overall conclusion
- Readiness recommendation
- Approval
8.65 Example SAT Summary
| Section | Status | Comments |
|---|---|---|
| Shipment Inspection | Pass | No critical damage |
| Installation | Pass | Installation complete |
| Utilities | Pass | Required services available |
| Electrical | Pass | Site supply verified |
| Instruments | Pass | Critical instruments checked |
| Safety | Pass | Critical safety functions verified |
| PLC/HMI | Pass | FAT version confirmed |
| Communication | Open | MES interface pending |
| FAT Punch List | Pass | Critical items closed |
| Documentation | Conditional | Two as-built drawings pending |
Overall conclusion might be:
SAT acceptable for progression to IQ, subject to documented closure of identified non-blocking open items according to the approved qualification plan.
8.66 Worked Example — Tablet Compression Machine SAT
For the compression machine example used throughout the handbook, SAT could include:
Receipt
- machine identity;
- shipping damage;
- major components;
- product-contact components.
Installation
- location;
- leveling;
- feeder assembly;
- guards;
- discharge;
- deduster interface.
Utilities
- electrical;
- compressed air;
- dust extraction;
- vacuum where applicable.
Electrical
- panel;
- power;
- earthing;
- motors;
- rotation.
Instruments
- compression-force system;
- speed feedback;
- sensors;
- pressure switches.
Automation
- PLC version;
- HMI version;
- communication;
- user access;
- site configuration.
Safety
- emergency stops;
- guards;
- interlocks.
Interfaces
- deduster;
- metal detector;
- downstream equipment.
8.67 Compression Machine SAT Matrix
| Function | FAT Status | SAT Verification | Reason |
|---|---|---|---|
| Machine identity | Pass | Verify | Confirm delivered machine |
| Product-contact parts | Pass | Inspect | Shipment/reassembly |
| Main motor | Pass | Rotation check | Electrical reconnection |
| Turret drive | Pass | Basic function | Transportation/reassembly |
| Compression force | Pass | Basic signal check | Sensor integrity |
| Feeder | Pass | Functional check | Reassembly |
| Reject system | Pass | Basic check | Mechanical/site connection |
| Guards | Pass | Challenge | Reassembly |
| Emergency stop | Pass | Challenge | Safety wiring |
| PLC software | Pass | Version check | Configuration integrity |
| HMI | Pass | Functional check | Site installation |
| SCADA | Simulated | Site test | Actual infrastructure |
| Metal detector interface | Partial | Site test | Actual equipment interface |
| MES interface | Not tested | Site test | Site-specific system |
8.68 Risk-to-SAT Example
URS
Machine shall prevent operation when the designated safety guard is open.
↓
FAT
Guard interlock challenged successfully.
↓
Transportation
Guard removed for shipment.
↓
Site Installation
Guard and safety switch reinstalled.
↓
SAT Risk
Incorrect alignment/wiring could invalidate FAT result.
↓
SAT Test
Challenge guard interlock again.
↓
Result
Pass.
↓
OQ Strategy
Final qualification verification performed/referenced according to the approved risk-based strategy.
This demonstrates why some FAT tests should be repeated at site.
8.69 Site Interface Example
Consider:
Compression Machine → Deduster → Metal Detector
At FAT, the vendor may simulate the metal-detector signal.
At SAT, actual equipment is available.
Test:
- Confirm physical interface.
- Confirm communication/signal wiring.
- Generate defined metal-detector fault/reject signal where safe.
- Verify compression-line response.
- Verify alarm/indication.
- Verify recovery.
The site test provides evidence that factory simulation could not provide.
8.70 Site Network Example
Factory configuration:
PLC → Vendor Laptop
Site configuration:
PLC → HMI → SCADA → Site Network → Historian
Therefore, factory communication testing cannot fully establish site operation.
SAT should verify actual connections before detailed OQ/CSV testing.
8.71 Site Configuration Change Example
During installation, the site requests:
Change alarm text from “Air Low” to “Compressed Air Pressure Low.”
Even a seemingly minor software change should be controlled.
Assess:
- version impact;
- affected screens;
- alarm logic;
- documentation;
- regression-test requirement.
Do not allow uncontrolled vendor modifications simply because the vendor engineer is on site.
8.72 SAT RACI Example
| Activity | Production | Engineering | Validation | QA | IT/Automation | Vendor |
|---|---|---|---|---|---|---|
| Receipt inspection | C | R | C | I | I | C |
| Installation checks | C | R | C | C | C | R |
| Utilities | C | R | C | I | I | C |
| Electrical | I | R | C | I | C | R |
| Instrument checks | C | R | C | C | C | R |
| Safety | C | R | C | C | C | R |
| PLC/HMI | C | C | C | C | R | R |
| Network | I | C | C | I | R | C |
| Deviations | C | R/C | R | A | C | C |
| SAT report | C | R | R/C | A/C | C | C |
R = Responsible, A = Accountable, C = Consulted, I = Informed.
Actual assignments depend on the company’s PQS.
8.73 Common SAT Deficiencies
| Deficiency | GMP/Project Concern |
|---|---|
| SAT skipped because FAT passed | Transportation/site risks missed |
| Shipment damage not documented | Equipment integrity uncertain |
| Wrong equipment/version delivered | Traceability failure |
| Utilities only visually checked | Actual suitability unknown |
| Critical instruments not checked | Transport damage may remain |
| Safety functions not reverified | Reassembly risk |
| Software changed without control | FAT baseline invalid |
| Site interfaces not tested | Integration failure discovered during OQ |
| FAT punch list ignored | Known problems remain unresolved |
| SAT results only recorded as “OK” | Weak evidence |
| Uncontrolled vendor changes | Configuration integrity compromised |
| Failed tests repeated without documentation | Data-integrity concern |
| SAT automatically treated as IQ/OQ | Qualification purpose unclear |
8.74 Inspector Perspective
An inspector may ask:
How did you ensure the equipment received at site was the same equipment tested during FAT?
Expected evidence:
- equipment identification;
- serial number;
- FAT report;
- SAT identification record;
- software version comparison.
Another question:
What changed between FAT and OQ?
The organization should be able to show:
FAT Baseline
↓
Shipment
↓
Site Installation
↓
Site Changes
↓
SAT
↓
Final Configuration
↓
IQ/OQ
8.75 Inspector Question — Vendor Site Changes
An inspector may ask:
Did the vendor make any software changes during installation?
Strong evidence should include:
- change record;
- reason;
- affected software;
- version;
- impact assessment;
- regression testing;
- updated backup;
- updated documentation.
A response such as:
“The vendor made a few small changes; we do not know exactly what”
would be a serious control weakness.
8.76 Inspector Question — FAT Leverage
An inspector may ask:
Why did you not repeat this test at site?
A defensible response should show:
- approved qualification strategy;
- risk assessment;
- FAT evidence;
- configuration verification;
- change assessment;
- site-dependency assessment;
- SAT confirmation where appropriate.
The key is not whether the test was repeated.
The key is whether sufficient evidence exists for the final installed state.
8.77 SAT Best Practices
A mature SAT program should:
- use FAT as an input;
- focus on what can change during shipment/installation;
- inspect equipment systematically;
- verify site utilities;
- confirm sensitive instrumentation;
- verify safety systems after reassembly;
- compare software versions;
- control vendor modifications;
- verify actual site interfaces;
- close FAT punch items;
- retain raw evidence;
- document failures transparently;
- establish the site configuration baseline;
- formally determine readiness for qualification.
8.78 SAT Inspection-Readiness Checklist
Documentation
- □ Approved SAT protocol
- □ URS available
- □ DQ available
- □ Risk assessment available
- □ FAT protocol/report available
- □ FAT deviations available
- □ FAT punch list available
- □ Drawings available
- □ Vendor manuals available
Receipt
- □ Equipment identity verified
- □ Serial number verified
- □ Shipping condition inspected
- □ Damage documented
- □ Missing parts assessed
- □ Product-contact parts inspected
Installation
- □ Location verified
- □ Orientation verified
- □ Leveling checked where relevant
- □ Reassembly checked
- □ Guards installed
- □ Access acceptable
- □ Interfaces aligned
Utilities
- □ Electrical supply
- □ Compressed air
- □ Vacuum
- □ Dust extraction
- □ Water where applicable
- □ Steam where applicable
- □ Nitrogen/process gas where applicable
- □ Utility parameters verified as required
Electrical
- □ Panel inspected
- □ Connections checked
- □ Earthing verified
- □ Motors checked
- □ Rotation checked
- □ Safety circuits checked
Instruments
- □ Instruments identified
- □ Damage checked
- □ Ranges confirmed as needed
- □ Calibration status reviewed
- □ Signals verified
- □ HMI indications checked
Automation
- □ PLC identified
- □ PLC version compared with FAT
- □ HMI version compared
- □ SCADA verified where applicable
- □ Communication established
- □ Site configuration documented
- □ Network configuration controlled
- □ Date/time checked
- □ Backup baseline available
Functional/Safety
- □ Startup
- □ Shutdown
- □ Basic sequence
- □ Critical alarms
- □ Critical interlocks
- □ Emergency stops
- □ Guards
- □ Interfaces
- □ Communication failure response where required
Closure
- □ FAT punch-list items reviewed
- □ SAT deviations documented
- □ Retests controlled
- □ SAT punch list established
- □ Critical issues closed
- □ Open items assessed
- □ Qualification impact assessed
- □ Configuration baseline documented
- □ SAT report approved
- □ IQ/OQ readiness established
8.79 SAT Readiness Gate
The final SAT decision should answer:
Is the site-installed equipment/system sufficiently complete, intact, connected, configured, functional, documented, and controlled to proceed to the next qualification stage?
Possible dispositions include:
Accepted
SAT successfully completed.
Conditionally Accepted
Noncritical open items remain with approved actions and closure requirements.
Not Accepted
Critical deficiencies prevent progression.
8.80 Golden Rule of SAT
The strongest SAT philosophy is:
Do not simply repeat FAT. Verify what transportation, installation, reassembly, site utilities, site infrastructure, interfaces, and site configuration could have changed or invalidated.
This makes SAT a risk-based lifecycle activity rather than another duplicate protocol.
Part 8 — Key Takeaway
SAT provides the bridge between supplier acceptance and formal site qualification.
The evidence chain becomes:
URS → Risk Assessment → DQ → FAT → FAT Baseline → Shipment → Receipt Inspection → Installation → Site Utilities → Site Configuration → SAT → Final Installed Baseline → IQ/OQ
A robust SAT should establish five things:
1. Equipment Integrity
The correct equipment arrived without unacceptable transportation damage.
2. Installation Readiness
The system has been appropriately positioned, reassembled and connected.
3. Site Integration
Utilities, electrical systems, networks and equipment interfaces function appropriately.
4. Configuration Integrity
Hardware/software/configuration remain controlled from FAT through site installation.
5. Qualification Readiness
Critical FAT/SAT deficiencies are resolved or appropriately dispositioned so formal qualification can proceed.
SAT therefore should not be treated as a duplicate FAT or a substitute for IQ/OQ. Its purpose is to provide documented assurance that the factory-tested system has successfully transitioned into its intended site-installed state.
The next stage is Part 9 — Installation Qualification (IQ).The IQ chapter to provide a detailed protocol structure covering equipment identity and installation, components and product-contact parts, materials and surface finish, utilities, piping/P&IDs, electrical systems, instruments and calibration, software/firmware and PLC/HMI/SCADA, network connections, safety devices, manuals, drawings, spares, lubricants, PM, SOP/training requirements and as-built documentation, with every IQ test structured as Objective → Prerequisite → Test Method → Expected Result → Actual Result → Acceptance Criteria → Evidence → Pass/Fail → Executed By → Reviewed By.
About the Author
Ramesh Palav is a pharmaceutical professional with 20+ years of industry experience in manufacturing, GMP, quality systems, validation, compliance, and operational excellence. Through Pharma Manufacturing Hub, he shares practical insights on pharmaceutical careers, manufacturing, quality, validation, Pharma 4.0, AI, and professional development.
His goal is to help students, freshers, experienced professionals, and career-break professionals build the knowledge and skills needed to succeed in the pharmaceutical industry.
