Uncategorized

How to Choose a Pharmaceutical Plant Automation Vendor for an Upgrade

Sep 18, 2026 6 min read

Pharmaceutical engineering team reviewing automation plans, process diagrams, and validation documentation in a manufacturing facility
Share

When you upgrade automation on a regulated line, the biggest risk is not the software. It is choosing a pharmaceutical plant automation vendor who can write good code but does not understand what a pharmaceutical plant has to prove to an auditor. A capable general automation firm can deliver a system that runs perfectly and still leave you without the validation trail and documentation an inspection requires, and that gap tends to surface at the worst possible time.

This guide sets out what to look for when you select a vendor, and what to ask before you commit. It is written for the engineers, QA leads, and procurement teams choosing a partner for an automation upgrade or a new regulated system. It focuses on the vendor and their process. For what makes the delivered system itself compliant, see our guide on 21 CFR Part 11 compliant SCADA.

Why a general automation engineer is a risk on a pharma line

A skilled controls engineer can build a working PLC and SCADA system. But automation on a pharmaceutical line is not only a controls problem. It is a compliance and validation problem, and the two need different competencies.

The delivered system has to produce trustworthy electronic records under 21 CFR Part 11, be built and documented to a recognised framework in GAMP 5, and carry a validation trail through DQ, IQ, OQ, and PQ that an auditor will accept. A vendor who has not worked to these will hand over functional software and a compliance gap, and you usually find that gap during an inspection or a requalification, when correcting it is slow and expensive.

The validation lifecycle a competent vendor works to

The validation lifecycle is as much the deliverable as the code. A vendor who cannot produce these documents cannot support your validation, whatever the software does.

  • Design Qualification (DQ): the design is documented and shown to meet the user requirement specification before build. This is where compliance is designed in rather than added later.
  • Installation Qualification (IQ): the system is installed as specified, with documented evidence of versions, components, wiring, and environment.
  • Operational Qualification (OQ): the system operates across its intended range, with functions, alarms, access control, and the audit trail all tested and recorded.
  • Performance Qualification (PQ): the system performs consistently under real production conditions.

Factory Acceptance Test and Site Acceptance Test bracket this work: the FAT verifies the system against specification before it ships, and the SAT verifies it again once installed. A vendor who runs and documents this cycle is one who can stand behind the system at audit.

GAMP 5, and why it matters in a vendor

GAMP 5 is the industry framework for validating computerised systems in regulated manufacturing. It structures how requirements are defined, how a system is categorised and built, how it is tested, and how it is documented, and it scales the validation effort to the risk and the type of system rather than applying the same burden to everything.

A vendor working to GAMP 5 produces the traceability from requirement to test that an auditor expects. Asking a vendor how they apply GAMP 5 to a system like yours is one of the quickest ways to tell whether they understand pharmaceutical validation or only understand controls.

What to check when you select a vendor

These are the checks that separate a vendor who can deliver an auditable system from one who can only deliver working software.

What to checkWhy it mattersQuestion to ask the vendor
Validation lifecycleYou need DQ, IQ, OQ, and PQ, not just working codeCan you show a sample validation package from a comparable project?
GAMP 5 competenceThe framework that makes the system auditableHow do you apply GAMP 5 to a system like ours?
21 CFR Part 11Records must be attributable, secure, and auditableHow do you implement audit trails, access control, and e-signatures?
Platform experienceDepth on your PLC and SCADA platformWhich platforms do you work on, and to what depth?
Documentation and handoverYou need editable drawings and approved programsWhat documentation and source do we receive, and when?
Lifecycle supportUpgrades and audits continue for yearsWhat do ongoing support and maintenance cover?

Documentation and handover, the part that protects you

When the project ends, you need the final approved programs and editable drawings, not a black box you cannot maintain and cannot change without going back to the vendor. Handover is what keeps you in control of your own system, able to maintain it, audit it, and upgrade it later.

Esteril hands over full access to all final approved programmes and editable drawings after OQ completion, and offers an Annual Maintenance Contract, an on-site engineer, and program and drawing handover as part of the engagement. That is what lets a plant own the system it paid for rather than depend on the vendor for every change.

Where Esteril fits

Esteril builds pharmaceutical automation with IPC and SCADA to 21 CFR Part 11, delivered to GAMP 5, with the full validation lifecycle of DQ, IQ, OQ, and PQ and FAT and SAT. Systems run on PLC and SCADA open solutions across Siemens, Schneider, Allen Bradley, and Mitsubishi, with electronic batch records, audit trails, and backup. The automation is delivered as part of the full project lifecycle, from design through commissioning, validation, documentation, training, and support, so the validation trail and handover are built into the engagement rather than bolted on at the end.

Frequently Asked Questions

Can our existing controls contractor handle a pharma upgrade?

They can if they work to GAMP 5, deliver the DQ, IQ, OQ, and PQ validation lifecycle, and implement 21 CFR Part 11 records. If they cannot show that, the risk is a system that runs the process but fails an audit, and the cost of correcting that later usually outweighs any saving up front.

What documentation should we receive at handover?

At minimum, the final approved programs, editable drawings, and the validation package covering DQ, IQ, OQ, and PQ. With those in hand you can maintain, audit, and upgrade the system without being locked to a single vendor.

What is the difference between FAT and SAT?

The Factory Acceptance Test verifies the system against specification before it ships. The Site Acceptance Test verifies it again after installation, in place. Both sit within the validation lifecycle and both should be documented.