How to build a validation master plan (VMP)
What is a validation master plan? And what should it entail? Learn how to build a plan that aligns with GMP Annex 15 and PIC/S – get a free template to build your own.
Get an overview of the different sections your VMP should entail.
Note
This article is for educational purposes only and should not be seen as regulatory advice since the requirements vary. You should always work from the current version of your relevant guidance and quality management system.
What is a validation master plan?
A validation master plan (also know as an VMP) is the top-level document that defines how validation is planned, executed, and maintained across a facility. Validation is the documented evidence that a process, system, or piece of equipment consistently performs as intended, and the plan is where that evidence program is designed; it sets scope, assigns responsibility, states the approach, and records the rationale for what is validated and what is not.
The difference between VMP, validation plan, validation protocols, and quality manuals
Three documents get confused with the VMP often enough to be worth separating.
- A validation plan: Covers one project, system, or product. It sits below the VMP and inherits its approach.
- A validation protocol: Defines the tests for one system, with acceptance criteria. It sits below the validation plan.
- A quality manual: Describes the quality management system as a whole. The VMP is one input into it, governed by it rather than replacing it.
In other words, the validation master plan sits above protocols and reports. Where a protocol proves one system performs as intended, the validation master plan explains why that system was in scope, the depth of testing it needed, and how its qualified state will be maintained.
Therefore, it is an important tool that should be created before your protocols. If a plan is written after the protocols are complete it becomes a description of what happened and not a statement of intent – and inspectors can usually tell the difference from the way the risk rationale is written.
Is a validation master plan legally required?
A VMP is not mentioned by name in most regulations. However, that does not make irrelevant. On the contrary, it is often a practical, structured way to meet the requirements there are.
- EU GMP Annex 15 requires that qualification and validation activities are planned and documented, and that the key elements of the program are clearly defined, and a validation master plan or a similar document is a common way to meet these requirements.
- PIC/S PI 006 goes further and sets out recommended VMP contents directly, which is why many European sites treat it as the de facto structure.
- 21 CFR Part 211 does not name a validation master plan. FDA expectations derive from the general requirement that processes and equipment are validated, from the 2011 process validation guidance, and from inspection practice. An inspector will often ask for the plan even though no clause names it.
This means that while the document is not required, large parts of the validation master plan is. As such, designing one is a practical way to document, unify, communicate and being able to easily explain your validation logic at inspections.
Also read: What is ISPE Validation 4.0? A practical guide for pharma quality teams
What goes in a validation master plan?
The content of your validation master plan vary by site, but the same thirteen areas make our the core part of most plans.
- Purpose and scope: Which sites, product types, and validation disciplines the plan governs.
- Regulatory basis: The standards the plan is written against, matched to the markets you supply.
- Organization and responsibilities: Roles rather than named individuals, with quality authority for approval separated from execution.
- Scope table: Every facility, utility, equipment item, and computerized system, with in-scope status, validation approach, risk rationale, and ongoing verification method.
- Validation approach: The lifecycle model, and how each qualification stage maps onto each system type.
- Risk management: The methodology, who applies it, and how risk outcomes change validation depth.
- Acceptance criteria: How criteria are set and approved, and how deviations are handled.
- Documentation and data integrity: Record types, storage, retention, and how electronic records meet ALCOA+ and Annex 11 or 21 CFR Part 11 expectations.
- Requalification and periodic review: The triggers, and the review cycle for the plan itself.
- Change control: How changes to validated systems are assessed and revalidated.
- Training: Competence requirements and where records are held.
- Schedule and status: A reference to the validation schedule, held as a separate dynamic document rather than embedded here.
- Glossary and references: Short, and only terms actually used in the plan.
Notes
- Order matters since the scope and risk should form the basis of the rest of the plan.
- The length of your plan depends on the content for each section,but if your plan becomes very long, check if it entails detalis that should be part of your protocols instead.
How to build the scope table
The scope table of a validation master plan often carries the most weight for the least page space, and it is where many findings originate. Every row makes four claims: That a system is in or out of scope, that a particular validation approach fits it, that a risk rationale supports both, and that a defined method will keep it in a qualified state. It is often a good idea to work through it in that order rather than filling columns left to right.
Start from the system inventory
Build the scope table from a system inventory rather than the equipment list. The equipment list is the obvious starting point but it will leave out the utilities, environments, and computerized systems your units depend on. Build the inventory from asset registers, calibration schedules, drawings, and the monitoring system itself.
Write the exclusion rationale first
Deciding what is out of scope forces the risk logic into the open, and, at the same time, a blank justification column against an excluded system is one of the first things an auditor questions. As such exclusions are a good place to start. Make sure your acceptable rationales are specific, for instance, no product contact, no impact on a critical quality attribute, no data used for release decisions.
Make the ongoing verification column produce evidence
This is the column that commits you to something after the plan is approved, and your entries should name a method, a frequency, and a data source. Compare these two entries for the same cold room:
Version | Ongoing verification entry for Cold room 1 |
Weak | Monitored routinely, reviewed periodically |
Strong | Continuous mapping and monitoring across risk-assessed positions, alarm escalation on excursion, quarterly trend review, annual data-supported requalification decision |
The first commits to nothing an inspector can check, whereas the second describes a method that generates records, which is what the plan is for.
Also read: Complete guide to thermal validation
Verification and validation: What is the difference?
Verification confirms that something meets its specification. Validation confirms that it meets its intended use. A cold room can be verified as built to drawing and still fail validation if the drawing never accounted for how it performs when fully loaded on a warm afternoon with the door cycling.
In a validation master plan the distinction shows up in the qualification stages. Installation and operational qualification largely verify against specification. Performance qualification validates against real use under representative load, which is why it is the stage that produces most of the surprises and most of the schedule slippage.
The distinction also matters for computerized systems, where supplier documentation often covers verification thoroughly and intended use barely at all. A vendor certificate confirming a monitoring platform meets its own specification does not establish that it meets yours.
How the qualification stages map onto the plan
The validation approach section explains which lifecycle stages apply to which system types. Keep this at the level of principle – the detail belongs in protocols – but be specific enough that someone can predict what a protocol will contain.
Design qualification documents that the design meets user and regulatory requirements. It is where a user requirement specification earns its place, and skipping it tends to surface later as scope disputes with suppliers.
Installation qualification verifies the system is installed as specified: correct components, correct location, utilities connected, documentation and calibration certificates present.
Operational qualification challenges the system across its operating range, including alarms, interlocks, and failure modes. For temperature-controlled units this is where door-open recovery, power failure recovery, and alarm setpoints are tested.
Performance qualification demonstrates consistent performance under actual use conditions, over a period long enough to capture real variation. For storage units, mapping under representative load sits here.
The plan should state which stages apply to which risk categories. A low-risk ambient storage area may warrant installation and operational qualification with an abbreviated performance stage; a cell therapy freezer bank at –80 °C / –112 °F will not.
Also read: IQ, OQ, PQ in pharmaceuticals
Who writes and approves the validation master plan?
Validation or engineering usually drafts the plan, and quality approves it. In smaller organizations a validation manager may do both, which weakens the plan – an approver who also wrote the scope rationale has no independent view of it.
Name roles, not people. A plan listing individuals goes out of date on the next resignation, and an inspector reading an obsolete responsibility matrix will ask what else has not been maintained.
Where a site uses contractors for commissioning or qualification, the plan should state which activities may be delegated and who retains approval authority. Delegated execution is normal. Delegated approval is not.
How often should a validation master plan be reviewed?
Annual review is common practice, though no regulation fixes the interval. What matters more is that the plan has defined triggers for revision outside the cycle.
Typical triggers include facility or layout changes, new equipment or product introductions, HVAC modifications, repeated deviations on a system, adverse trend data, changes to applicable regulations, and any change to the ongoing verification method named in the scope table.
A plan reviewed only on a calendar, with no record of a change ever prompting an update, invites the question of whether the review was real. Conversely, a revision history showing three updates in two years, each tied to a documented change, is one of the easier things to defend in an inspection.
Validation master plan template
Download a section-by-section template for creating a validation master plan.
Should the plan use IQ/OQ/PQ for software, or computer software assurance?
The qualification stages above were designed for physical equipment, and applying them unchanged to computerized systems produces documentation volume without much added confidence. This is the gap the FDA computer software assurance framework addresses.
Computer software assurance replaces uniform scripted testing with a risk-based approach: establish intended use, assess risk to product quality and patient safety, then choose assurance activities proportionate to that risk. Those activities can include unscripted and exploratory testing, and leveraging supplier evidence rather than repeating a vendor test script in your own environment.
One scope point matters before you write this into a plan. The FDA guidance, Computer Software Assurance for Production and Quality Management System Software, was finalized in February 2026 and applies to medical device production and quality management system software under 21 CFR Part 820. It does not extend to drug manufacturing under Part 211. Industry bodies including ISPE and PDA support applying the same principles in pharmaceutical GMP environments, and it is a defensible position, but it is not a regulatory requirement there.
What that means for your plan: State which approach you apply to computerized systems and why. A pharmaceutical site adopting computer software assurance principles should say so explicitly and justify it, rather than leaving an inspector to work out why a monitoring platform received unscripted testing while an autoclave received a full IQ/OQ/PQ package. A device manufacturer can cite the guidance directly.
The framework does not require re-validating systems already in a validated state. It applies going forward, to new implementations, changes, and ongoing assurance.
Also read: EU GMP Annex 11: What it requires for computerized systems
Writing a validation master plan across multiple sites
Mature global organizations rarely run a single document. The common structure is three tiers, and knowing which tier you are writing saves most of the argument about what belongs in it.
Corporate validation policy
Sits above every site. Holds the risk methodology, the definition of a critical system, the ongoing verification standard, and the approval hierarchy. This is the layer that stops three sites reaching three different conclusions about the same freezer model.
Site validation master plan
Governs one site: its infrastructure, its equipment inventory, and its routine requalification. This is the document an inspector asks for during a site inspection, and the one this page is mostly about.
Project validation master plan
Written for a major capital project or system implementation, and retired or folded back into the site plan when the project closes. A new facility, a warehouse expansion, or a monitoring system rollout across forty units belongs here.
Forcing a major expansion into the routine site plan is the mistake worth avoiding. It clutters a document that quality has to review annually with project detail that is obsolete within a year, and it makes the site plan harder to defend because the routine content is buried.
Smaller single-site organizations can compress this. One plan carrying corporate-level methodology and site-level scope is defensible, provided the methodology is stated rather than assumed. What does not work is a plan that reads as site-level but is applied to several sites, because the scope section then cannot describe any of them accurately.
If you are consolidating from several site plans into one, the scope tables are the place to start. Merging them exposes exactly where sites have classified comparable systems differently.
Also read: Temperature-controlled units in pharma: Qualification and monitoring
Data integrity requirements in the validation master plan
Validation generates records that later support release decisions, so the plan has to state how those records stay trustworthy.
Cover four things. First, which systems generate GxP-relevant data and where that data lives. Second, how ALCOA+ principles apply to it – attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring, and available. Third, how electronic records and signatures meet Annex 11 or 21 CFR Part 11 expectations, including audit trails, access control, and periodic audit trail review. Fourth, retention periods and the plan for retrieving data after a system is retired.
That last point is routinely missed. A monitoring system decommissioned after five years still holds data supporting batches that remain within shelf life, and the plan should say how it will be read.
For temperature data specifically, the chain runs from sensor to record to report. Manual transcription anywhere along that chain is a data integrity weakness before it is an efficiency problem, because a transcribed value is no longer original.
Where validation master plans commonly fall short
Five patterns come up repeatedly when validation master plans are reviewed.
Exclusions without rationale
Systems marked out of scope with a blank justification column. Every exclusion needs a reason an inspector can follow, tied to product impact or data criticality.
Ongoing verification stated as intent
"Periodic review" or "monitored routinely" with no defined method, frequency, or data source behind it. The plan commits you to producing evidence; if the method cannot produce it, the commitment is the finding.
A schedule that has drifted
Overdue requalifications sitting in the status table with no deviation record. This is one of the fastest ways to turn a document review into a deeper look at the whole program.
Risk assessments that never change an outcome
If every assessment concludes full validation, the methodology is decorative and an experienced inspector will say so. Risk-based validation means some systems get less, and the plan should show where.
A plan that no longer matches the facility
New equipment installed, a room repurposed, a monitoring system replaced – none of it reflected in the scope table. This is a change control failure that surfaces as a VMP finding, and it is why the change control section should explicitly require the scope table to be checked.
How continuous data changes what the plan can commit to
The scope table in any validation master plan asks how a qualified state will be maintained between studies. For temperature-controlled storage, that answer has traditionally been a periodic re-mapping interval plus routine monitoring, with the two treated as separate activities producing separate records.
Continuous mapping and monitoring changes what the plan can honestly commit to. With enough loggers placed against a documented risk assessment, one installation produces a data foundation that serves both monitoring and mapping requirements, which may reduce or remove the need for periodic re-mapping. The concept is not new – continuous process verification appears in ICH Q8 and in the FDA 2011 process validation guidance – but the economics only recently made it practical at scale.
This matters at the plan stage rather than afterwards. A validation master plan that commits to a two-year re-mapping cycle locks that cycle in until the plan is revised, and revising it mid-cycle means justifying the change to an inspector who has already seen the original. Writing the ongoing verification column around continuous data instead gives you a plan that keeps producing evidence rather than snapshots.
Three qualifications are worth stating plainly, because this argument is often overstated.
First, mapping and routine monitoring are distinct functions, and regulators treat them that way. Mapping establishes spatial variation across the whole volume under seasonal and operational worst-case conditions. Monitoring tracks conditions at selected control points. Monitoring at a handful of fixed points confirms conditions at those points, does not qualify the space, and does not replace a mapping study. This is why the distinction between ordinary monitoring and continuous mapping matters: the benefit comes from logger density and placement, not from the fact that data is collected continuously.
Second, the reduction is not automatic. It depends on logger placement justified by risk assessment under ICH Q9, on coverage sufficient to characterize the space rather than sample it, and on the data being retained and reviewable in the form an inspector expects.
Third, expect to defend it. Substituting continuous data for periodic requalification is a risk-based argument, not a settled expectation, and some auditors will challenge it. Write the justification into the plan at the outset rather than assembling it during an inspection.
Where it does apply, the effect on the plan is concrete. Requalification triggers become data-driven rather than calendar-driven, the schedule section shortens, and the periodic review has something to review.
Also read: Key guidelines for temperature qualification
Download a validation master plan template
The template gives you every section of a VMP, the scope table format, and a note on what an auditor looks for in each one.
Frequently asked questions about validation master plans
One vendor for mapping, monitoring, and calibration
Eupry brings mapping, monitoring, and calibration into one GxP-compliant solution, so the ongoing verification column in your plan is backed by data that is already being collected.