Structure, contents, and how to write one

How to build a validation master plan (VMP)

What is a validation master plan? And what should it entail? Learn how to build a plan that aligns with GMP Annex 15 and PIC/S – get a free template to build your own.

Get an overview of the different sections your VMP should entail.

Isometric illustration of a clipboard checklist with four teal checkmarks on a light blue gradient background

Note

This article is for educational purposes only and should not be seen as regulatory advice since the requirements vary. You should always work from the current version of your relevant guidance and quality management system.

What is a validation master plan?

A validation master plan (also known as an VMP) is the top-level document that defines how validation is planned, executed, and maintained across a facility. Validation is the documented evidence that a process, system, or piece of equipment consistently performs as intended, and the plan is where that evidence program is designed; it sets scope, assigns responsibility, states the approach, and records the rationale for what is validated and what is not.

The difference between VMP, validation plan, validation protocols, and quality manuals

Three documents get confused with the VMP often enough to be worth separating.

  • A validation plan: Covers one project, system, or product. It sits below the VMP and inherits its approach.
  • A validation protocol: Defines the tests for one system, with acceptance criteria. It sits below the validation plan.
  • A quality manual: Describes the quality management system as a whole. The VMP is one input into it, governed by it rather than replacing it.

In other words, the validation master plan sits above protocols and reports. Where a protocol proves one system performs as intended, the validation master plan explains why that system was in scope, the depth of testing it needed, and how its qualified state will be maintained.

Therefore, it is an important tool that should be created before your protocols. If a plan is written after the protocols are complete it becomes a description of what happened and not a statement of intent – and inspectors can usually tell the difference from the way the risk rationale is written.

Is a validation master plan legally required?

A VMP is not mentioned by name in most regulations. However, that does not make it irrelevant. On the contrary, it is often a practical, structured way to meet the requirements there are.

  • EU GMP Annex 15 requires that qualification and validation activities are planned and documented, and that the key elements of the program are clearly defined, and a validation master plan or a similar document is a common way to meet these requirements.
  • PIC/S PI 006 goes further and sets out recommended VMP contents directly, which is why many European sites treat it as the de facto structure.
  • 21 CFR Part 21 does not name a validation master plan. FDA expectations derive from the general requirement that processes and equipment are validated, from the 2011 process validation guidance, and from inspection practice. An inspector will often ask for the plan even though no clause names it.

This means that while the document is not required, large parts of the validation master plan are. As such, designing one is a practical way to document, unify, communicate, and explain your validation logic at inspections.

Also read: What is ISPE Validation 4.0? A practical guide for pharma quality teams

What goes in a validation master plan?

The content of your validation master plan varies by site and operational circumstances, but the same thirteen areas make up the core part of most plans.

  • Purpose and scope: Which sites, product types, and validation disciplines the plan governs.
  • Regulatory basis: The standards the plan is written against, matched to the markets you supply.
  • Organization and responsibilities: Roles rather than named individuals, with quality authority for approval separated from execution.
  • Scope table: Every facility, utility, equipment item, and computerized system, with in-scope status, validation approach, risk rationale, and ongoing verification method.
  • Validation approach: The lifecycle model, and how each qualification stage maps onto each system type.
  • Risk management: The methodology, who applies it, and how risk outcomes change validation depth.
  • Acceptance criteria: How criteria are set and approved, and how deviations are handled.
  • Documentation and data integrity: Record types, storage, retention, and how electronic records meet ALCOA+ and Annex 11 or 21 CFR Part 11 expectations.
  • Requalification and periodic review: The triggers, and the review cycle for the plan itself.
  • Change control: How changes to validated systems are assessed and revalidated.
  • Training: Competence requirements and where records are held.
  • Schedule and status: A reference to the validation schedule, held as a separate dynamic document rather than embedded here.
  • Glossary and references: Short, and only terms actually used in the plan.

Notes

  1. Order matters since the scope and risk should form the basis of the rest of the plan.
  2. The length of your plan depends on the content for each section, but if your plan becomes very long, check if it entails details that should be part of your protocols instead.

How to build the scope table

The scope table of a validation master plan often carries the most weight for the least page space, and it is where many findings originate. Every row makes four claims: That a system is in or out of scope, that a particular validation approach fits it, that a risk rationale supports both, and that a defined method will keep it in a qualified state. It is often a good idea to work through it in that order rather than filling columns left to right.

Start from the system inventory

Build the scope table from a system inventory rather than the equipment list. The equipment list is the obvious starting point but it will leave out the utilities, environments, and computerized systems your units depend on. Build the inventory from asset registers, calibration schedules, drawings, and the monitoring system itself.

Write the exclusion rationale first

Deciding what is out of scope forces the risk logic into the open, and, at the same time, a blank justification column against an excluded system is one of the first things an auditor questions. As such exclusions are a good place to start. Make sure your acceptable rationales are specific, for instance, no product contact, no impact on a critical quality attribute, no data used for release decisions.

Make the ongoing verification column produce evidence

This is the column that commits you to something after the plan is approved, and your entries should name a method, a frequency, and a data source. Compare these two entries for the same cold room:

Version
Ongoing verification entry for Cold room 1
Weak
Monitored routinely, reviewed periodically
Strong
Continuous mapping and monitoring across risk-assessed positions, alarm escalation on excursion, quarterly trend review, annual data-supported requalification decision

The first commits to nothing an inspector can check, whereas the second describes a method that generates records, which is what the plan is for.

Also read: Complete guide to thermal validation

Verification and validation: What is the difference?

Simply put, verification confirms that something meets its specification, and validation confirms that it meets its intended use.

A cold room can be verified as built to drawing and still fail validation if the drawing never accounted for how it performs when fully loaded on a warm afternoon with the door cycling.

In your validation master plan the distinction should be part of the qualification stages. Where installation and operational qualification largely verify against specification, performance qualification validates against real use under representative load, which is why it is the stage that often produces surprises and schedule slippage.

Also keep the distinction in mind when evaluating computerized systems. Supplier documentation that covers verification thoroughly but not intended use is frequent, but a vendor certificate confirming a monitoring platform meets its own specification does not establish that it meets yours.

How the qualification stages map onto the plan

The validation approach section explains which lifecycle stages apply to which system types. Keep this at the level of principle – the detail belongs in protocols – but be specific enough that someone can predict what a protocol will contain.

  • Design qualification documents that the design meets user and regulatory requirements and is where a user requirement specification earns its place.

  • Installation qualification verifies the system is installed as specified with correct components, correct location, utilities connected, documentation and calibration certificates.

  • Operational qualification ensures the system is fit during operation. This includes testing alarms, interlocks, and failure modes. For temperature-controlled units this is where you test door-open recovery, power failure recovery, and alarm setpoints.

  • Performance qualification demonstrates consistent performance under actual use conditions, over a period long enough to capture real variation. For storage units, mapping under representative load sits here.

The plan should state which stages apply to which risk categories. A low-risk ambient storage area may warrant installation and operational qualification with an abbreviated performance stage, but a cell therapy freezer bank at –80 °C / –112 °F will definitly not.

Also read: IQ, OQ, PQ in pharmaceuticals

Who writes and approves the validation master plan?

Usually, whoever owns validation to design the plan and for quality to approve it. In smaller organizations a validation manager may do both, but this weakens the plan since an approver who also wrote the scope rationale, of course, has no independent view of it.

If your site uses contractors for commissioning or qualification, your plan should state which activities may be delegated and who retains approval authority since approval should stay in-house.

Tip! It is a good idea to name roles, instead of people. If your plan lists individuals, it goes out of date on the next resignation, and an inspector reading an obsolete responsibility matrix will probably ask what else has not been maintained.

How often should a validation master plan be reviewed?

It is common practice to review the plan once a year, but no regulation defines a fixed interval. What matters more is that you define triggers for when the plan should be reviewed outside the cycle. If your plan is only reviewed based on the passing of 12 months, it can come off as if the review has nothing to do with your actual operation, whereas a revision history showing updates tied to documented changes shows it does.

Some typical triggers to review your validation master are:

  • facility or layout changes
  • new equipment or product introductions
  • HVAC modifications
  • repeated deviations on a system
  • adverse trend data
  • changes to applicable regulations

As well as any change to the ongoing verification method named in the scope table.

Eupry Validation Master Plan template document spread showing section pages with blue design and scope tableDownload

Validation master plan template

Download a free section-by-section template for creating a validation master plan.

Initializing ...

Should you use IQ/OQ/PQ or computer software assurance for software?

The qualification stages above were designed for physical equipment, and if you apply them unchanged to a piece of software, you end up with a lot of documentation without much added confidence. Luckily, this is why the FDA computer software assurance framework exists.

The idea is straightforward enough: Instead of running the same scripted test package over everything, you:

  1. establish what the system is actually used for
  2. assess the risk it carries to product quality and patient safety
  3. and match the assurance activity to that risk.

Some of it can be unscripted or exploratory testing, but some can also be supplier evidence you simply accept.

Note!

There is one scope point worth knowing before you write any of this into a plan. The FDA guidance, Computer Software Assurance for Production and Quality Management System Software, was finalized in February 2026, and it applies to medical device production and quality management system software under 21 CFR Part 820. It does not extend to drug manufacturing under Part 211. However, ISPE and PDA both support applying the same principles in pharmaceutical GMP environments, and it is a defensible position. However, it is a choice you are making rather than a rule you are following.

So if you are a device manufacturer, cite the guidance. If you are a pharmaceutical site, state which approach you apply to computerized systems and why.

Tip! If a system is already in a validated state, you do not need to go back and revalidate it. Computer software assurance applies going forward, to new implementations, changes, and ongoing assurance.

Also read: EU GMP Annex 11: What it requires for computerized systems

How to write a validation master plan across multiple sites

When you run a larger organization with multiple sites, maybe even scattered across multiple countries, running a single plan is not sustainable. Instead, a common structure is using three tiers:

Corporate validation policy

This sits above every site and holds the risk methodology, the definition of a critical system, the ongoing verification standard, and the approval hierarchy. The goal of this layer is to stop different sites reaching different conclusions about, for instance, the same freezer model.

Site validation master plan

This governs one site, and covers the site's infrastructure, equipment inventory, and routine requalification. This is often the document an inspector will ask for during a site inspection, and the one this page is mostly about.

Project validation master plan

Forcing a major expansion into the routine site plan clutters this document with detail that is obsolete once the project is finalized and makes the site plan harder to defend because the routine content is buried. Therefore, a project VMP is typically written for any major capital project or system implementation, such as a new facility, a warehouse expansion, or a monitoring system rollout across multiple units, and retired or folded back into the site plan when the project closes.

Note: Smaller single-site organizations can compress this, and one plan carrying corporate-level methodology and site-level scope is defensible if the methodology is stated. What does not work is a plan that reads as site-level but is applied to several sites, because the scope section cannot describe any of them accurately.

Also read: Temperature-controlled units in pharma: Qualification and monitoring

What are the data integrity requirements in the validation master plan?

Validation generates records that later support release decisions, so the plan has to state how those records stay trustworthy and should cover four things.

  1. First, which systems generate GxP-relevant data and where that data lives.
  2. Second, how ALCOA+ principles apply to it – attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring, and available.
  3. Third, how electronic records and signatures meet Annex 11 or 21 CFR Part 11 expectations, including audit trails, access control, and periodic audit trail review.
  4. Fourth, retention periods and the plan for retrieving data after a system is retired - this point if often missed.

For temperature data specifically, the chain runs from sensor to record to report. Manual transcription anywhere along that chain is a data integrity weakness because a transcribed value is no longer original.

Which errors are most frequent when designing validation master plans?

There are five problematic patterns that come up repeatedly when validation master plans are reviewed:

1. Exclusions without rationale

Systems marked out of scope without a justification. Every exclusion needs a reason tied to product impact or data criticality.

2. Ongoing verification stated as intent

"Periodic review" or "monitored routinely" with no defined method, frequency, or data source behind it. The plan commits you to producing evidence, and if the method cannot produce it, the commitment is the finding.

3. A schedule that has drifted

Overdue requalifications sitting in the status table with no deviation record.

4. Risk assessments that never change an outcome

If every assessment concludes full validation, the methodology is more decorative than functional and is not changing any decision. Risk-based validation means some systems get less, and the plan should show this.

5. A plan that no longer matches the facility

New equipment installed, a room repurposed, a monitoring system replaced – none of it reflected in the scope table. This is a change control failure that surfaces as a VMP finding, and it is why the change control section should explicitly require the scope table to be checked.

How continuous data changes what the plan can commit to

The scope table in your validation master plan should ask how a qualified state will be maintained between studies. For temperature-controlled storage, that answer has traditionally been a periodic re-mapping interval plus routine monitoring, and the two has been treated as separate activities that produce separate records.

Continuous mapping and monitoring (CMM) changes what the plan can honestly commit to.

The short version: One installation produces a data foundation that serves both monitoring and mapping requirements, which reduces – or even removes – the need for periodic re-mapping. The concept is not new (continuous process verification appears in ICH Q8 and in the FDA 2011 process validation guidanc) but the economics only recently made it practical at scale.

Writing the ongoing verification column around continuous data instead gives you a plan that keeps producing evidence instead of a snapshots.

Three qualifications are worth stating plainly, because this argument is often overstated.

  • First, mapping and routine monitoring are distinct functions. Mapping establishes spatial variation across the whole volume under seasonal and operational worst-case conditions. Monitoring tracks conditions at selected control points. Monitoring a does not qualify the space, and does not replace a mapping study. This is why the distinction between ordinary monitoring and CMM is important: The benefit comes from logger density and placement, not from the fact that data is collected continuously.

  • Second, the reduction is not automatic. It depends on logger placement justified by risk assessment under ICH Q9, on coverage sufficient to characterize the space rather than sample it, and on the data being retained and reviewable in the form an inspector expects.

  • Third, expect to defend the choice. Substituting continuous data for periodic requalification is a risk-based argument, and some auditors will challenge it. Write the justification into the plan at the outset.

Where it does apply, the effect on the plan is concrete. Requalification triggers become data-driven rather than calendar-driven, the schedule section shortens, and the periodic review has something to review.

Also read: How the continuous temperature mapping method works

Download a validation master plan template

The template gives you every section of a VMP, the scope table format, and a note on what an auditor looks for in each one.

Eupry Validation Master Plan template document pages fanned out showing sections on scope, risk management, and responsibilities
FAQ

Frequently asked questions about validation master plans

Is a validation master plan required by the FDA?

Not by name. 21 CFR Part 211 requires validation, and inspectors commonly expect a plan documenting how it is organized.

What is the difference between a VMP and a validation plan?

A VMP covers a site or program. A validation plan covers one project or system within it.

How long should a validation master plan be?

Long enough to cover every section without absorbing protocol detail. Length matters far less than whether every exclusion carries a rationale.

Who approves the validation master plan?

Quality, with authority independent of the people executing validation.

Does a VMP cover computerized systems?

Yes. Computerized systems fall in scope under Annex 11 and 21 CFR Part 11 and belong in the scope table.

How often must a VMP be updated?

Annual review is common, plus revision whenever a defined trigger occurs.

Can one VMP cover several sites?

Yes, usually with site-level annexes. Keep risk methodology and critical system definitions at corporate level.

Does computer software assurance replace IQ/OQ/PQ for software?

For medical device production and quality systems, it is the current FDA framework. For pharmaceutical GMP it is best practice rather than a requirement, so state which approach your plan applies.

What is a project validation master plan?

A plan covering one major capital project or system implementation, sitting below the site VMP and retired when the project closes.

One vendor for mapping, monitoring, and calibration

Eupry brings mapping, monitoring, and calibration into one GxP-compliant solution, so the ongoing verification column in your plan is backed by data that is already being collected.

Eupry temperature monitoring dashboard showing critical high alarm alert alongside Wi-Fi data loggers and display unit