A multi-product facility does not become safe because every room is classified, every hose is labeled, and every changeover has a completed checklist. It becomes safe when the organization can make, and defend, a scientifically coherent claim that material from Product A cannot reach a patient receiving Product B at a level capable of causing harm.
That claim is harder to sustain in a contract development and manufacturing organization than in a conventional single-product facility. A CDMO must accommodate changing client portfolios, incomplete early-phase knowledge, different cell substrates and processes, short campaigns, accelerated technology transfers, and commercial pressure to use the same suites efficiently. Each new product changes the contamination problem. Each new process train changes the pathways. Each new piece of toxicological or clinical information may change what “acceptable” means.
The central task is therefore not simply cleaning validation. It is cross-contamination risk management across the product, process, facility, equipment, and patient-safety lifecycles.
For a multi-product CDMO, that system must distinguish clearly between two manufacturing architectures:
- Reusable equipment, where previous-product carryover is controlled principally through equipment design, validated cleaning, sampling, analytical capability, maintenance, and changeover discipline.
- Single-use systems (SUS), where direct carryover through the discarded product-contact path may be greatly reduced, but risk shifts toward assembly integrity, incorrect connections, retained reusable interfaces, extractables and leachables, particulates, supplier controls, sterilization assurance, and human manipulation.
Neither architecture is inherently safe. Both can be made safe. Both can fail in characteristic ways.
The Regulatory Question
The regulatory question is not, “Was the equipment cleaned?” It is, “Was the risk of cross-contamination identified, scientifically evaluated, controlled, and kept under review?”
ICH Q9(R1) defines quality risk management as a systematic process for assessing, controlling, communicating, and reviewing risks to product quality across the lifecycle. It also makes two points that matter directly to a CDMO: risk evaluation should be grounded in scientific knowledge and linked ultimately to patient protection, and the level of effort, formality, and documentation should be commensurate with risk. Resource limitations are not a valid reason to lower the formality of the assessment.
EU GMP Chapter 5 is more explicit about shared manufacture. It requires cross-contamination risk to be assessed, including contamination arising from product residues, aerosols, organisms, genetic material, and operators’ clothing. It further requires a quality risk management process that includes potency and toxicological evaluation and considers facility and equipment design, personnel and material flows, microbiological controls, physicochemical characteristics, cleaning processes, analytical capability, and the intended use of the product.
The EMA health-based exposure limit guideline replaces arbitrary carryover conventions with a structured scientific evaluation of pharmacological and toxicological data. A permitted daily exposure, or equivalent health-based exposure limit, represents a substance-specific daily exposure that is unlikely to cause an adverse effect over a lifetime; its derivation includes hazard identification, selection of the critical effect and point of departure, and application of adjustment factors for uncertainty.
FDA requirements approach the problem through enforceable expectations for buildings, flow, defined areas, equipment, procedures, and controls that prevent contamination and mix-ups. Under 21 CFR 211.42, material and product flow must be designed to prevent contamination, and operations must occur in defined areas or under other adequate control systems. FDA’s inspection program for protein drug substances also expects validated cleaning of nondisposable product-contact equipment, predetermined carryover limits for shared equipment, continued verification, and toxicologically derived acceptable daily exposures for highly potent or toxic residues; where limits cannot be achieved, dedicated or disposable equipment may be necessary.
For CDMOs, regulatory responsibility cannot be outsourced through the commercial contract. FDA’s quality-agreement guidance expects the owner and contract facility to define and document their respective CGMP responsibilities, but the agreement is a governance mechanism and not a transfer of accountability away from either party.
Begin With the Patient
The most common weakness in shared-facility risk assessments is that they begin with the room or equipment rather than the patient. The team draws process maps, scores hose connections, reviews cleaning cycles, and concludes that controls are strong. Only later, sometimes after the manufacturing decision has already been made, does anyone ask how much of the previous product could safely reach the next patient.
That sequence is backward.
The assessment should begin with a human product-safety evaluation for each molecule proposed for the facility. In EU terminology this is generally expressed through an HBEL, commonly a PDE or ADE. The evaluation is not merely a calculation and should not be reduced to a spreadsheet populated from the lowest clinical dose. It is an expert interpretation of all relevant pharmacological, toxicological, nonclinical, and clinical evidence.
EMA states that HBELs should be established for medicinal products and periodically reassessed as knowledge develops. It also specifies that the person deriving the HBEL should have adequate expertise and experience in toxicology or pharmacology, familiarity with pharmaceuticals, and experience establishing health-based limits. When the work is outsourced, the manufacturer must qualify the provider and the specific expert; simply purchasing an HBEL report without assessing the contractor’s suitability is not acceptable.
A defensible assessment should address, as applicable:
- Molecular target and mechanism of action.
- Intended and reasonably foreseeable off-target pharmacology.
- Potency and dose-response relationships.
- Route of administration and systemic bioavailability.
- Patient population, including vulnerable or immunocompromised groups.
- Acute, repeated-dose, reproductive, developmental, genotoxic, carcinogenic, immunotoxic, and local-tolerance information, where relevant.
- Cytokine-release, immune agonism, immune suppression, complement activation, or unintended tissue cross-reactivity.
- Clinical adverse-event data and the lowest exposure associated with the critical effect.
- Pharmacokinetics, persistence, accumulation, and half-life.
- Uncertainty arising from limited data, especially for early clinical programs.
- The biological activity of fragments, aggregates, conjugated species, degradants, or process-transformed residues.
- Whether route-to-route extrapolation is scientifically justified.
For biologics, the assessment may require judgment different from that used for a conventional small molecule. A protein may denature during alkaline cleaning, but “denatured” is not automatically synonymous with “non-hazardous.” Loss of the primary mechanism of action does not by itself establish the absence of immunogenic, inflammatory, allergenic, or other biological effects. Conversely, a large protein’s poor oral bioavailability may materially reduce risk for an orally administered next product, while offering little reassurance when the next product is parenteral. The conclusion must follow the exposure scenario and evidence, not a generic statement that proteins are readily degraded.
The resulting HBEL is an input to risk management, not the risk assessment’s conclusion. EMA explicitly states that once the health-based assessment is complete, the data should be used through QRM to determine whether existing technical and organizational controls are adequate or require supplementation.
The CDMO Information Problem
A sponsor often knows more about its molecule than the CDMO. The CDMO knows more about its facility, equipment, cleaning history, operators, and failure modes. A valid assessment requires both bodies of knowledge.
The sponsor should provide either a complete, reviewable HBEL assessment or the data needed for the CDMO to perform one. EMA expects the assessment, data references, and relevant expert information to be available during inspection. The quality agreement should therefore define ownership and timing for:
- Provision and approval of the HBEL or toxicological monograph.
- Disclosure of new clinical, nonclinical, or pharmacovigilance information.
- Assessment of novel modalities, conjugates, linkers, payloads, or unusually potent mechanisms.
- Product and process characterization relevant to cleanability and detectability.
- Analytical reference standards and product-specific assays.
- Review of cleaning limits and product-family placement.
- Approval of shared-use, campaign, dedication, or exclusion decisions.
- Notification when new information could invalidate the existing assessment.
This exchange must occur before facility fit is approved and not after the batch slot has been commercially committed. A CDMO that accepts a product before it understands the patient-safety boundary has allowed scheduling to precede science.
Hazard Is Not Risk
Cross-contamination discussions often collapse hazard and risk into one concept. They are not the same.
Hazard is the inherent capacity of the contaminant to cause harm. For a biologic drug substance, that may arise from potent pharmacology, immune modulation, sensitization, tissue cross-reactivity, or biologically active variants. Risk depends on both that hazard and the probability and extent of patient exposure through a credible contamination pathway.
This distinction matters because two products with similar HBELs may require different controls. A readily soluble biolgic processed in a closed, disposable flow path presents a different exposure likelihood from a sticky, difficult-to-detect protein processed through open transfers and a complex reusable skid. Likewise, the same previous product may present different risks depending on the next product’s route, maximum daily dose, batch size, population, and shared surface area.
The risk question should therefore be written explicitly:
Given the hazard of the previous product, the vulnerability and exposure of the next product’s patient population, the manufacturing sequence, and all credible transfer routes, are the proposed controls capable of maintaining carryover below a scientifically justified safe level with an adequate operating margin, even when foreseeable failures occur?
That final clause is important. A risk assessment that assumes every procedure is followed perfectly is not assessing risk. It is describing the intended state.
Map Every Transfer Route
The assessment should follow contamination as though it were tracing dye through the facility. Product residue does not recognize departmental boundaries, validation packages, or ownership charts.
At minimum, evaluate these pathways:
- Direct product-contact carryover through shared tanks, columns, skids, piping, valves, pumps, sensors, transfer panels, and filling paths.
- Indirect transfer from external equipment surfaces, carts, tools, hoses, parts, balances, bins, and mobile equipment.
- Airborne transfer through aerosols, droplets, powders, open manipulations, pressure cascades, or HVAC recirculation.
- Personnel transfer through gloves, gowns, footwear, tools, notebooks, radios, and movement between suites.
- Material and waste transfer through staging areas, elevators, corridors, pass-throughs, cold rooms, and wash areas.
- Mix-up through labels, status identification, electronic recipes, tubing connections, sampling materials, and component reconciliation.
- Microbial or adventitious-agent transfer through shared utilities, insufficient segregation, retained moisture, open operations, or pre-viral and post-viral process crossover.
- Laboratory transfer through shared sample-preparation areas, instruments, standards, retain storage, or incorrect sample identity.
- Maintenance transfer through tools, removed components, lubricants, temporary hoses, bypasses, and post-maintenance restoration.
WHO guidance for biological products emphasizes QRM-based movement restrictions, logical and unidirectional flows, closed systems, qualified single-use components, and controls for open manipulations. It also warns against cross-use of certain reused components and highlights separation between activities with different biological risks.
The result should be a facility-wide contamination pathway map connected to process steps and equipment boundaries. A list of hazards without a spatial and temporal model of transfer is incomplete.
Select the Right Tool
No single risk tool is sufficient for the whole problem.
| Tool | Best use | Limitation |
| Process and contamination-pathway mapping | Shows where product, people, materials, waste, air, and equipment intersect | Does not quantify control strength by itself |
| FMEA or FMECA | Evaluates equipment- and step-specific failure modes | Risk-priority numbers can hide severe events and create false precision |
| HACCP | Identifies critical points where control is essential | Can become too linear for complex facility-wide transfer pathways |
| LOPA | Tests whether independent protection layers adequately reduce a defined scenario | Requires genuine independence and defensible failure assumptions |
| Fault-tree analysis | Works backward from a contamination outcome to combinations of causes | Can become resource-intensive and difficult to maintain |
| Bow-tie analysis | Connects threats, preventive controls, event, mitigations, and consequences | May oversimplify technical detail unless supported by deeper assessments |
ICH Q9(R1) permits different tools and degrees of formality but expects the approach to reflect uncertainty, importance, and complexity. In a multi-client CDMO, the most effective architecture is usually layered: pathway mapping at the facility level, FMEA for equipment and operations, and LOPA or bow-tie analysis for high-consequence scenarios.
Detectability should be used cautiously. A highly sensitive release test does not prevent cross-contamination, and routine product testing rarely provides enough sampling coverage to compensate for weak containment or cleaning. Detection controls can reduce uncertainty, but they should not be allowed to dominate the score merely because a method exists.

The Contamination Pathway and the Equipment Boundary
| Reusable stainless equipment | Single-use assembly |
|---|---|
| Fixed tank, piping, valves, CIP skid | Disposable bag, tubing, connectors, filters |
| Main risk: retained product residue | Main risks: assembly, integrity, E&L, mix-up |
| Primary assurance: validated cleaning | Primary assurance: supplier qualification and integrity |
| Key failure modes: dead legs, poor CIP coverage, failed valves | Key failure modes: leak, pinhole, wrong connection, package breach |
Reusable Equipment
Reusable stainless-steel systems make the contamination boundary visible. The previous product contacted the equipment; the equipment will contact the next product; therefore, the organization must demonstrate that the transition is safe.
The principal controls are equipment design, defined cleaning procedures, validated cleaning performance, validated sampling and analytical methods, controlled dirty and clean hold times, inspection, preventive maintenance, status control, and periodic verification. FDA expects written cleaning procedures, predefined protocols, sensitive analytical methods, recovery studies, documented results, and management-approved conclusions that residues have been reduced to acceptable levels.
A reusable system assessment should examine:
- Product-contact surface area and materials of construction.
- Dead legs, low points, shadowed spray areas, valve bodies, diaphragms, gaskets, seals, and instrument ports.
- Surface roughness, weld quality, drainability, slope, and retained-volume risk.
- CIP coverage, flow, turbulence, spray-device performance, temperature, chemistry, concentration, time, and final-rinse endpoints.
- Manual interventions and disassembly requirements.
- Ability to inspect hard-to-clean locations.
- Dirty-hold and clean-hold conditions.
- Residue degradation or fixation during heat, drying, storage, or cleaning.
- Microbial proliferation and endotoxin risk in retained moisture.
- Maintenance failure modes such as blocked traps, failed valves, misaligned spray devices, sensor drift, or recipe changes.
Worst-case selection must be multidimensional. The lowest HBEL may identify the most hazardous product, but it may not be the hardest to remove. The most difficult cleaning challenge may instead be driven by solubility, concentration, viscosity, aggregation, drying behavior, adsorption, equipment geometry, or interaction with the cleaning agent. Health Canada’s guidance identifies HBEL, cleanability, solubility, physical characteristics, and prior experience among relevant worst-case factors and expects cleaning methods to be capable of measuring residue below the selected limit.
Cleaning limits
The HBEL for the previous product is translated into a maximum safe carryover for the next product using next-product batch size and maximum daily dose. That allowable mass is then allocated across the actual shared product-contact surface and converted into swab, rinse, or other sampling limits. The calculation must account for the entire shared process train and avoid allocating the same allowable carryover independently to multiple pieces of equipment.
The final operational limit should be no higher than the health-based limit and may need to be lower because of analytical capability, process control, variability, visual detectability, or company policy. “Visually clean” remains useful as an immediate gross-failure check but cannot replace a health-based and analytically verified criterion for product changeover.
The cleaning validation package should integrate:
- Laboratory cleanability and degradation studies.
- Coupon recovery for each relevant material of construction.
- Swab and rinse method suitability.
- Product-specific or scientifically justified nonspecific analytical methods.
- Method specificity against degradants and cleaning-agent interference.
- Worst-case locations selected from design and process knowledge.
- Hold-time studies.
- Automated recipe and alarm challenge.
- Replicate validation runs under defined worst-case conditions.
- Ongoing verification and periodic review of process capability.
A failed result cannot be repaired by repeated sampling until a passing value appears. FDA warns that routine “test until clean” behavior may demonstrate that the process is not validated rather than provide assurance of cleanliness.
Single-Use Systems
Single-use technology changes the risk architecture; it does not eliminate contamination control.
A fully disposable, closed product-contact path can sharply reduce the direct previous-product residue pathway because the contacted components are discarded rather than cleaned for the next product. It can also reduce cleaning-validation burden for those specific components. But the facility still contains reusable interfaces, support equipment, rooms, biosafety cabinets, external surfaces, transfer devices, sensors, exhaust pathways, and operators. The critical question becomes: Where does the disposable boundary begin and end?
EU GMP Annex 1 defines SUS broadly to include bags, filters, tubing, connectors, valves, bottles, and sensors and requires SUS-specific risks to be assessed within the contamination control strategy. Those risks include product-surface interactions, extractables and leachables, fragility relative to fixed systems, manual operations and connections, assembly complexity, holes and leakage, packaging opening, filter integrity, and particulate contamination.
A useful comparison is:
| Risk dimension | Reusable equipment | Single-use system |
| Previous-product residue | Controlled by validated cleaning | Reduced where the complete contacted path is discarded |
| Main validation burden | Cleaning process, sampling, analytical method, hold times, CIP performance | Supplier, sterilization, assembly, integrity, connection, shipping, installation, and use qualification |
| Typical hidden boundary | Valves, seals, dead legs, skid piping, probes | Reusable probes, housings, manifolds, pumps, clamps, transfer ports, support vessels |
| Human contribution | Manual cleaning, assembly, inspection, status control | Unpacking, inspection, installation, connection, manipulation, and line clearance |
| Material interaction | Corrosion, adsorption, surface condition, cleaning-agent compatibility | Extractables, leachables, adsorption, absorption, reactivity, and particles |
| Failure signature | Residue, retained liquid, ineffective cycle, maintenance degradation | Pinholes, leaks, misconnections, wrong assembly, compromised package, weld failure |
| Lifecycle dependence | Equipment maintenance and cleaning-state control | Supplier change control, lot consistency, irradiation or sterilization assurance, logistics |
The boundary problem
The term “single-use process” is often applied too casually. A disposable bag connected to a reusable chromatography skid is not a completely single-use process. Neither is a disposable bioreactor connected through reusable probes or a stainless transfer panel. Every reusable product-contact or potentially product-contact interface must be identified and assigned an appropriate cleaning, sterilization, dedication, or disposal strategy.
Hybrid systems deserve particular scrutiny because responsibility can fall between programs. The cleaning-validation team may assume the flow path is disposable, while the SUS qualification team may assume reusable interfaces are covered elsewhere. The risk assessment should include a boundary diagram showing:
- All direct product-contact components.
- Indirect contact and splash-exposure surfaces.
- Sterile boundaries and connection points.
- Reusable sensors, housings, and hardware.
- Components retained between campaigns.
- Components disposed after each batch, campaign, or product.
- Product-contact status following an integrity failure.

Integrity as contamination control
SUS integrity is both a sterility issue and a cross-contamination issue. A leak can release product into the room, contaminate equipment exteriors, expose operators, or create a pathway into another process. A loss of integrity may also allow environmental or adjacent-process contamination into the system.
Annex 1 expects SUS to maintain integrity under intended processing conditions and identifies extreme operations, including freezing, thawing, transport, and manipulation, as relevant challenges. Qualification should therefore address worst-case pressure, vacuum, agitation, temperature, duration, shipping, installation, connection, and operator handling, not merely supplier burst-test data.
Controls should include:
- Qualified component and assembly suppliers.
- Defined critical quality attributes and specifications.
- Verification of sterilization evidence for each received unit where applicable.
- Incoming inspection and packaging-integrity checks.
- Controlled storage and handling.
- Installation and connection instructions designed to prevent error.
- Pre-use and, where justified, post-use integrity testing.
- Leak response and contamination-boundary assessment.
- Weld and connector qualification.
- Operator qualification for assembly and manipulation.
- Supplier change notification and comparability assessment.
Extractables and leachables
SUS removes one patient-safety concern, previous-product residue from reused contact surfaces, but introduces another: chemical species migrating from polymeric components. Annex 1 requires evaluation of product adsorption and reactivity under process conditions and assessment of extractable and leachable profiles, particularly for high-risk components, long contact times, or materials capable of absorbing process constituents.
The evaluation should consider the full process, including sterilization method and dose, contact time, temperature, pH, solvent characteristics, surface-area-to-volume ratio, agitation, storage, freezing and thawing, and cumulative contact across assemblies. Supplier extractables packages are inputs, not automatic proof of suitability. Their test conditions must be scientifically bridged to the actual process.
This is another point at which human safety expertise matters. A detected or predicted leachable should be evaluated against an appropriate toxicological threshold and clinical exposure scenario. The product-safety assessment for a multi-product facility therefore has two related but distinct jobs: establishing safe exposure to previous-product residues and evaluating patient exposure to process-material leachables.
Mix-up risk
SUS can reduce cleaning-related carryover while increasing configuration and mix-up risk. Multi-product facilities may hold visually similar bags, manifolds, filters, connectors, and tubing sets for several clients. A correct component assembled in the wrong orientation, or a wrong component with a compatible connection, can defeat the process while looking superficially acceptable.
Controls should include unique part numbers, electronic bill-of-material verification, barcode or equivalent identification, kitting, line clearance, independent verification of critical assemblies, connection maps, recipe interlocks where possible, and reconciliation of issued, used, and discarded components.
Facility and Process Controls
Equipment choice is only one layer. The facility must prevent contamination through the broader manufacturing environment.
EU GMP Chapter 5 identifies technical and organizational measures that may include dedicated premises or equipment, self-contained areas, closed systems, local extraction, pressure cascades, transfer controls, validated cleaning, waste management, protective clothing, campaign manufacture, and verification of control effectiveness. WHO similarly emphasizes technical and organizational controls, closed systems, cleaning validation, dedicated areas or equipment where justified, and periodic review of cross-contamination measures.
A hierarchy of controls is useful:
- Eliminate the pathway: Exclude an incompatible product, avoid open handling, or remove shared product contact.
- Physically contain or segregate: Use closed processing, dedicated suites, separate HVAC, barriers, isolators, or dedicated equipment.
- Engineer the interface: Use contained transfer, validated connectors, local extraction, pressure control, automation, and interlocks.
- Validate removal or inactivation: Apply reproducible cleaning and decontamination with adequate analytical verification.
- Control organization and sequence: Campaign, schedule, restrict personnel movement, segregate tools and materials, and perform line clearance.
- Detect loss of control: Use environmental, surface, residue, process, and maintenance monitoring targeted to credible failure modes.
Procedures and training are essential, but they are weaker than elimination, containment, and engineering controls. A risk assessment that accepts a high-consequence pathway because “operators are trained” is usually signaling that stronger controls were not seriously considered.
Campaigning
Campaign manufacture separates products in time, not space. It can reduce simultaneous exposure but does not remove residues already present in equipment, rooms, utilities, or shared support areas. Campaigning is acceptable only when paired with a validated and operationally controlled changeover capable of restoring the facility to the required state.
The campaign assessment should consider maximum campaign length, residue accumulation, microbial control, resin or membrane reuse, room and equipment cleaning, environmental persistence, maintenance during the campaign, and the likelihood that repeated setup creates normalized deviations.
Dedicated equipment
Dedication should be based on patient risk and control capability, not convention alone. Packed chromatography resins, membranes, or other retained components may be product-dedicated when they are difficult to clean, cannot be sampled representatively, retain product, or create unacceptable uncertainty. But a universal rule that every column or membrane must be dedicated is not a substitute for assessment.
Conversely, a low calculated carryover limit should not be used to justify sharing when the equipment cannot be cleaned, sampled, or verified with adequate margin. The decision to share requires alignment among toxicological acceptability, technical capability, analytical capability, and operational reliability.
Biological Hazards Beyond Product Residue
A cross-contamination assessment cannot stop at active-protein carryover. The process may contain host cells, cell-culture components, host-cell proteins, DNA, viruses or virus-like particles, mycoplasma, bacteria, fungi, endotoxin, cleaning agents, process additives, and product variants.
ICH Q5A(R2) describes three complementary viral-safety controls for biotechnology products: selection and testing of cell lines and raw materials, demonstration of process clearance for adventitious and endogenous viruses, and testing at appropriate production stages. These controls do not replace facility cross-contamination controls. They address product viral safety, while the facility assessment must also prevent pre-clearance material, cell-culture fluids, or laboratory challenge material from crossing into post-clearance or unrelated operations.
The assessment should distinguish at least:
- Pre-viral-clearance from post-viral-clearance operations.
- Live-cell or harvest operations from purified-product operations.
- Product-specific residue from nonspecific organic residue.
- Microbial contamination from adventitious viral contamination.
- Endotoxin from viable organisms.
- Process organisms from environmental organisms.
- Laboratory viral-clearance studies from manufacturing operations.
Environmental monitoring can support control of viable and particulate contamination, but it is generally not the primary method for detecting product-to-productcarryover. Product-residue pathways require appropriately specific surface, rinse, process, or investigative methods. The monitoring strategy must match the contaminant and pathway.
Analytical Strategy
Analytical capability should be designed from the risk question, not selected because a platform method is already available.
For reusable equipment, the method must detect the residue or a justified surrogate at a level below the operational acceptance criterion, in the presence of cleaning agents, degradants, surface effects, and sampling losses. FDA expects evaluation of both method sensitivity and the ability of the sampling procedure to recover contamination from equipment surfaces.
Possible approaches include:
- Product-specific immunoassays.
- Total organic carbon where scientifically justified as a nonspecific measure.
- HPLC or UPLC methods.
- Mass spectrometric peptide or protein methods.
- Protein assays, conductivity, or other process-specific techniques when sufficiently sensitive and selective.
- PCR or sequencing for defined nucleic-acid or adventitious-agent questions.
- Microbial and endotoxin methods for relevant biological residues.
The analytical target profile should define intended use, analyte, matrix, required sensitivity, specificity, reportable range, precision, recovery, robustness, and decision threshold. For a CDMO platform, the strategy should explain when a platform method is acceptable, when a product-specific method is required, and how bridging will be performed.
Method capability should influence the manufacturing decision. If the safe carryover level is below what can be reliably sampled and measured, the answer is not to accept the analytical gap. The control strategy must change: through dedication, disposal, additional segregation, improved cleaning, a more sensitive method, or exclusion of the product from the facility.
Control Strength, Not Control Count
A long list of controls can create the illusion of safety. Ten weak, dependent controls are not equivalent to two strong, independent controls.
LOPA is useful here because it asks whether a protection layer is specific, independent, dependable, and auditable. For example, an operator verifying a hose connection and a second operator checking the same connection may be useful, but both controls depend on the same labeling, work environment, and human interpretation. They are not necessarily independent layers.
A stronger scenario might combine:
- Physically incompatible connectors.
- Electronic component verification.
- Recipe interlock.
- Independent line-clearance verification.
- Post-assembly integrity testing.
The assessment should document not only that a control exists but also:
- What failure it prevents or detects.
- Whether it is preventive or detective.
- Whether it is independent of other controls.
- How its effectiveness was established.
- What evidence demonstrates continued performance.
- What happens when it fails.
Regulatory inspection guidance for shared facilities similarly emphasizes documenting the process train and controls in enough detail to identify failure opportunities rather than assuming controls are effective.
Make the Risk Assessment Operational
A risk assessment should change how the facility operates. If it does not affect design, scheduling, qualification, training, monitoring, or release, it is probably only a document.
The output should establish:
- Whether the product is acceptable for the facility.
- Permitted suites, equipment trains, and scales.
- Reusable, disposable, and dedicated boundaries.
- Required campaign sequence and changeover.
- Cleaning and decontamination requirements.
- Product-specific analytical requirements.
- Personnel and material-flow restrictions.
- Environmental or surface-monitoring requirements.
- Required engineering modifications.
- Conditions that prohibit concurrent manufacture.
- Required controls for maintenance and intervention.
- Residual risks and formal acceptance authority.
- Triggers for reassessment.
The decision should be made by a cross-functional team with authority and expertise in toxicology or pharmacology, quality assurance, manufacturing, MSAT, engineering, validation, microbiology, analytical science, EHS or industrial hygiene, supply chain, and the client’s product knowledge. Commercial stakeholders may contribute constraints and timing, but they should not define the patient-safety threshold.
Lifecycle Governance
The assessment cannot be frozen at technology transfer. ICH Q9(R1) includes risk review as an explicit element of QRM, and EMA expects periodic reassessment of the pharmacological and toxicological basis of HBELs.
Reassessment triggers should include:
- New clinical or nonclinical safety information.
- Change in dose, route, indication, or patient population.
- New product introduction or changed manufacturing sequence.
- Scale, batch-size, or equipment-train change.
- Change from reusable to single-use equipment or the reverse.
- New SUS component, material, supplier, sterilization process, or assembly design.
- Cleaning-agent, cycle, recipe, or analytical-method change.
- Facility, HVAC, pressure, flow, or room-use change.
- Repeated cleaning deviations or adverse process-capability trends.
- Integrity failures, leaks, or recurring connection errors.
- Maintenance findings affecting cleanability or containment.
- New organism or adventitious-agent information.
- Regulatory change or inspection commitment.
A facility-level product matrix should remain under controlled ownership and identify, for every product, its HBEL status, hazard characteristics, applicable equipment, cleaning family, analytical method, dedication requirements, incompatibilities, and approval status. The matrix should not become an uncontrolled scheduling aid; it is a lifecycle quality record.
What Good Looks Like
A mature CDMO can answer the following questions without assembling a crisis team:
- Which qualified expert established the HBEL, from what data, and when was it last reviewed?
- What critical effect drives the limit, and how does uncertainty affect the control strategy?
- Which product pair creates the most stringent carryover condition on each shared train?
- Where exactly are the reusable and disposable boundaries?
- Which SUS components carry the greatest integrity or leachables risk?
- What contamination pathways remain if the first control fails?
- Which controls are genuinely independent?
- Can the cleaning process repeatedly achieve the required limit with margin?
- Can the sampling and analytical methods detect failure at the required level?
- What happens after a leak, torn bag, failed connector, maintenance intervention, or incomplete line clearance?
- Which new information automatically reopens the assessment?
If those answers exist only in separate toxicology reports, validation protocols, supplier files, and local SOPs, the organization does not yet have an integrated cross-contamination control strategy. It has fragments.
The Hard Decision
The purpose of risk assessment is not to prove that every product can fit into the facility. Sometimes the scientifically correct conclusion is that it cannot.
A product may require dedicated equipment, a dedicated suite, a fully disposable flow path, additional containment, a different manufacturing sequence, or exclusion from the site because:
- The HBEL is extremely low or cannot be established with adequate confidence.
- The hazard includes sensitization, genotoxicity, potent immune activity, or another effect poorly controlled by ordinary cleaning assumptions.
- The safe residue level is below analytical or sampling capability.
- The molecule is not reliably removed or inactivated.
- The process requires open handling that creates an uncontrolled pathway.
- The facility cannot segregate pre- and post-clearance activities adequately.
- The SUS boundary contains unacceptable reusable interfaces.
- The organization cannot demonstrate control after foreseeable human or mechanical failure.
That decision is not evidence that the risk-management process failed. It is evidence that the process worked.
A Better Synthesis
Reusable equipment and single-use systems should not be treated as competing philosophies. They are different control architectures.
Reusable equipment concentrates the burden on cleanable design, validated removal, analytical evidence, maintenance, and disciplined changeover. Single-use systems reduce some direct carryover pathways but concentrate the burden on system boundaries, integrity, supplier oversight, sterilization assurance, material compatibility, extractables and leachables, configuration control, and human assembly.
The human product-safety assessment sits upstream of both. It defines the exposure boundary that gives every downstream control meaning. Without it, cleaning limits are arbitrary, dedication decisions are conventional, and facility-fit conclusions are little more than confidence statements.
For a multi-product CDMO, the strongest contamination control strategy is therefore not the one with the most controls or the greatest use of disposable technology. It is the one that can connect, without gaps:
patient hazard → safe exposure → contamination pathway → equipment boundary → control mechanism → verification evidence → lifecycle review.
That chain is the real product of the risk assessment. Everything else is documentation supporting it.


