The factory acceptance test is the last point at which a problem is cheap to fix. After the skid ships, every correction carries transport, site access, cleanroom entry, revalidation and lost production time behind it.
Despite that, FAT is often run as a demonstration rather than a test. The supplier shows that the equipment works. The client signs. Nobody tries to make it fail. Six weeks later the same system behaves differently at site, and the argument about who owns the gap starts.
This guide sets out what a FAT and a SAT should actually cover for a pharmaceutical process skid, and where the responsibility line between the two should sit.
What FAT is for, and what it is not
FAT verifies that the equipment meets the user requirement specification and the approved design, under controlled conditions in the supplier facility, before it is released for dispatch.
It is not a substitute for installation qualification, and it does not prove performance with your product. What it does prove is that the build matches the design, that the control system behaves as specified including under fault conditions, and that the documentation set is complete.
The FAT protocol should be issued and approved before the test date. If a protocol arrives on the morning of the test, the test is a demonstration.
| Quick checkA useful test of a FAT protocol: can a person who was not involved in the project read it and know what would count as a failure? If the acceptance criteria are written as descriptions rather than as measurable values, the protocol needs rework before the visit is booked. |
What a FAT should cover
Construction and materials
- Material test certificates traced to the actual product contact parts, not a general grade statement.
- Surface finish records for product contact surfaces against the Ra value stated in the URS.
- Weld records and inspection reports. Orbital welding on product contact piping should have documented parameters and coupons.
- Dimensional check against the general arrangement drawing, including skid footprint and connection points.
- Slope and drainability check. Verify that the skid drains as specified rather than accepting it as a design statement.
Mechanical and process function
- Hydro test or pressure test records for vessels and piping.
- Water run at minimum and maximum working volume. Minimum volume is where mixing problems appear and it is often skipped.
- Agitator operation across the full speed range, with power draw noted.
- Load cell verification with calibrated weights, checked against the tolerance in the URS.
- Where the skid is CIP and SIP capable, spray coverage verification by riboflavin test, with photographic records.
- Sterilisation cycle run with the temperature profile recorded and held against the specified conditions.
Automation, alarms and data integrity
This is the part of FAT that is most often compressed and most expensive to correct later.
- Input and output check on every instrument and valve, one by one.
- Sequence testing for each automatic cycle, including abort and recovery behaviour.
- Alarm and interlock testing by forcing the fault condition, not by simulating the alarm in software.
- Power failure and recovery test. Verify what the system does on restart and whether the batch record survives.
- User access levels, electronic signature behaviour and audit trail review, in line with 21 CFR Part 11.
- Software documentation review against GAMP 5, including the design specification and the test records.
- Backup and restore demonstrated, not described.
Documentation
Review the documentation set during FAT while there is still commercial leverage. A complete package normally includes design qualification, the FAT protocol and executed report, IQ, OQ and PQ protocols, material and calibration certificates, spare parts list, and operating and maintenance manuals.
Where the FAT and SAT responsibility line sits
Disputes at site almost always trace back to a boundary that was never written down. The table below is a workable split for a process skid.
| Item | FAT, at supplier works | SAT, at your site |
|---|---|---|
| Purpose | Verify build against URS and approved design | Verify the installed system works under site conditions |
| Utilities | Supplier facility utilities, conditions recorded | Your plant utilities at the stated conditions |
| Materials and welds | Certificates and inspection reviewed and accepted | Reviewed only if damage occurred in transit |
| Mechanical checks | Full dimensional and pressure testing | Check for transit damage, levelling, anchoring |
| Water run | Full run at minimum and maximum volume | Repeat run with site utilities |
| CIP and SIP | Spray coverage and cycle demonstrated | Cycle repeated against site steam and water conditions |
| Automation | Full sequence, alarm and interlock testing | Retest after any interface or network change |
| Integration | Standalone or simulated interfaces | Live integration with plant SCADA, BMS or EBR |
| Documentation | Complete set reviewed and accepted | Site specific records, IQ execution, as built updates |
| Outcome | Release for dispatch | Release for qualification and use |
Why site conditions change the result
A cycle that passes at the supplier works can fail at site for reasons that have nothing to do with build quality.
Clean steam pressure, WFI temperature at the point of use, compressed air quality and chilled water flow all vary between facilities. If those conditions were not stated in the URS, the supplier tested against their own utilities and both parties are technically correct.
Record the utility conditions used at FAT in the FAT report. It converts a later argument into a documented comparison.
Red flags in a FAT protocol
- Acceptance criteria written as descriptions instead of values. Satisfactory operation is not a criterion.
- Alarms tested by simulation only, with no forced fault conditions.
- No test at minimum working volume.
- Documentation review deferred to dispatch.
- Punch list items closed by verbal agreement rather than a written closure record with dates and owners.
- No power failure and recovery test.
Every one of these is straightforward to correct in the protocol. None of them is straightforward to correct after the skid is in a cleanroom.
What to agree before the FAT date is booked
- Protocol issued and approved by both sides, with acceptance criteria as measurable values.
- Attendee list confirmed, covering engineering, production and QA or validation.
- Punch list format agreed, including who closes each item and by when.
- What constitutes a conditional pass, and what triggers a repeat test.
- Whether the documentation set travels with the skid or is handed over separately.
- When editable drawings and the final approved control programme are handed over.
Frequently asked questions
How long should a FAT take for a process skid?
It depends on the number of automated sequences rather than on the size of the vessel. A single vessel skid with basic automation can be tested in a day. A multi vessel skid with CIP and SIP, several product paths and plant integration usually needs two to four days if alarms and interlocks are tested individually.
Can FAT be done remotely?
Parts of it can. Documentation review, sequence testing and audit trail review work reasonably well over video with a witnessed protocol. Dimensional checks, weld inspection, drainability and riboflavin coverage should be witnessed in person. If a remote FAT is unavoidable, agree in writing which items are deferred to SAT and who carries the cost if they fail there.
Does a successful FAT replace IQ and OQ?
No. FAT can reduce duplication if the protocols are written to reference it, and some OQ tests can be leveraged from executed FAT records where the system has not changed. The qualification itself still has to be executed at site under your quality system.
What should be handed over after OQ?
The final approved control programme and the editable drawing set, in addition to the qualification records. Esteril provides both after OQ completion, so that later modifications and requalification do not depend on returning to the original supplier for the source files.
