OQacceptance-criteriaqualificationtest-designvalidation

How to Set OQ Machine Parameters: Low, Nominal, High

Valiqa Team|August 19, 2026|10 min read|
How to Set OQ Machine Parameters: Low, Nominal, High

Set the low and high challenge points at the edges of the operating range the process will actually claim in production, and set nominal at the routine setpoint, because the point of the exercise is to bracket the window you intend to defend: for parameters whose effect moves in one direction across the range, if the equipment performs acceptably at both edges, the range between them is qualified, and production can move within it without revalidating. The numbers come from the process specification and development data, not from the machine's nameplate. A sealer that can physically reach 220 degrees Celsius but will never run above 165 in production gets challenged around the production window, not the machine's limit. EU GMP Annex 15 frames the OQ requirement exactly this way: tests developed from knowledge of the processes, systems, and equipment, including tests to confirm upper and lower operating limits, and/or worst case conditions. The GHTF process validation guidance for devices says the same thing in its vocabulary: challenge the process control limits. Neither asks you to stress the machine to failure. Both ask you to prove the window you will rely on.

Getting these three numbers right is most of OQ test design, and getting them wrong is expensive in both directions. Challenge points set at the machine's mechanical extremes generate failures that mean nothing about production and deviations that consume weeks. Challenge points set only at nominal qualify a single operating point, so the first process adjustment lands outside the qualified range and triggers work that a properly bracketed OQ would have absorbed. This article covers where each of the three values comes from, how to choose the parameters that need the treatment at all, how worst-case combinations fit in, what the acceptance criteria at each point should bound, and a worked example in the shape real OQ test steps take.

Three ranges, one decision

The confusion around low/nominal/high starts because three different ranges are in play, and the challenge points belong to only one of them.

The machine capability range is what the equipment can physically do: the servo will run 5 to 200 packs per minute, the heater will reach 220 degrees. This range belongs to the vendor and the design qualification, which confirmed the capability envelope contains the process you bought the machine for. It is not the OQ challenge range.

The process operating range is the window the process specification claims: seal temperature 150 to 165 degrees, line speed 40 to 80 packs per minute. This is the range production is allowed to use, the range operators can adjust within, and the range the OQ exists to qualify. Low and high challenge points sit at its edges.

The proven acceptable range is what exists after the OQ: the span between the challenged edges where performance is demonstrated. If the OQ challenged 150 and 165 and both passed, the proven range is 150 to 165, and any setpoint inside it is qualified ground. Setpoints outside it are not, which is what makes the original choice of edges consequential: qualify a window narrower than production needs and you will be back; qualify the honest window and routine adjustment never leaves it.

Nominal is the third point, and its job is different. Low and high demonstrate the edges hold. Nominal demonstrates the routine condition performs, anchors the comparison for the edge results, and doubles as the configuration most later testing, including PQ, will run at.

Where the numbers come from

Each challenge point should have a source you can name when an auditor asks, and the sources are different for each.

Low and high come from the process specification chain. The URS or process spec states the intended operating window, development or technology-transfer data justifies it, and the OQ challenges its edges. Where development data is thin, the vendor's recommended process window and engineering-run data fill the gap, documented as such. What cannot set the edges is improvisation at protocol-writing time: a challenge point with no upstream source is an acceptance criterion that will get flagged, because nothing traces it to a requirement.

Nominal comes from the intended routine setpoint, which by the time of OQ should be a settled number from development, not a guess. If nominal is still moving, that is a signal the process definition is not ready for qualification, and the OQ is about to qualify a window around a target that may drift out of it.

The parameter list itself comes from risk. Not every adjustable setting earns three-point treatment. The parameters that do are the ones whose variation can affect product quality: the critical process parameters and the key operating settings that influence them. A process FMEA is the standard tool for making that cut defensibly: parameters whose failure modes carry quality impact get challenged across the range; convenience settings that cannot affect the product get verified at nominal or left to commissioning. The general anatomy of an OQ covers where these tests sit among the protocol's other sections.

A three-range diagram showing a horizontal parameter axis with three nested brackets: the widest machine capability range from the vendor's nameplate, a narrower process operating range from the URS with low and high challenge markers at its edges and a nominal marker near its center, and the resulting proven acceptable range spanning the challenged edges, with a callout that setpoints inside the proven range are qualified ground

Worst case is a defined term, not a mood

Annex 15's glossary defines worst case as a condition or set of conditions encompassing upper and lower processing limits and circumstances, within standard operating procedures, which pose the greatest chance of product or process failure when compared to ideal conditions, and it adds that such conditions do not necessarily induce failure. Two parts of that definition do real work.

Within standard operating procedures. Worst case lives inside the claimed operating window, not beyond it. Running the sealer at a temperature production will never use is not worst case, it is a different process. The challenge edges are the worst case for a single parameter, because they are the allowed conditions farthest from ideal.

Combinations, not just single parameters. The conditions that pose the greatest chance of failure are usually joint: highest speed with lowest temperature and shortest dwell is the coldest, fastest seal the SOP permits, and it is a different challenge than any single parameter at its edge. A full factorial across every parameter is neither required nor useful; the risk assessment picks the small set of combinations that genuinely represent the hardest allowed conditions, and the protocol says why those. One or two justified worst-case combinations per quality attribute is a defensible norm; twenty unjustified permutations is sample-size theater.

The same logic explains what OQ challenge points are not: they are not capability studies, not process development, and not an attempt to find the failure edge. If development never established where the process stops working, that is development work. By OQ, the window is claimed, and the job is confirming it, a distinction that also keeps the OQ timeline from absorbing exploratory work it was never scoped for.

What the criteria bound at each point

The acceptance criteria at low, nominal, and high are where OQ discipline either holds or quietly collapses into PQ's job.

At each challenge point, the criteria bound two things. First, the parameter itself: the setpoint is achieved and held within its stated tolerance, the controller maintains 150 plus or minus 2 degrees at the low edge. Second, the immediate output of the function under challenge: the seal formed at the coldest, fastest allowed condition passes its integrity and strength checks, the filled volume at maximum speed stays within its tolerance. Both are phrased as quantitative pass/fail limits with units, and both trace to the requirement that set the window.

What the OQ criteria do not bound is sustained production performance: run-to-run consistency, routine operators, representative materials over time. That demonstration belongs to performance qualification, or at process level to the PPQ. An OQ that quietly takes on output-consistency criteria at nominal has annexed the PQ without its sample sizes; an OQ whose edge criteria only check that the setpoint was reached, without checking the output at that setpoint, has proven the knob works and nothing else.

Sample sizes at each point follow the same risk logic as the criteria: a fixed sample per condition per quality check, chosen from the attribute's risk and any applicable sampling standard, with the rationale stated per test category rather than per step, so the protocol carries a sample-size table the reviewer can audit in one place. Some programs add replicates at nominal as the anchor condition, but the statistically justified sample belongs wherever the risk assessment says failure is most likely, usually the challenge conditions.

A worked example in real test-step shape

A vertical form-fill-seal bagger packaging a non-sterile device. The process specification claims seal jaw temperature 150 to 165 degrees Celsius, dwell 0.25 to 0.45 seconds, line speed 40 to 80 bags per minute, nominal at 158 degrees, 0.35 seconds, 60 bags per minute. The OQ's parameter challenge section, in the shape generated test steps actually take:

Step 1, seal temperature low. Test item: seal integrity at minimum claimed jaw temperature. Setup: 150 degrees, nominal dwell and speed. Specification: temperature held at 150 plus or minus 2 degrees for the run; 10 consecutive bags pass dye-penetration seal integrity with zero channel defects; peel strength of 5 sampled seals within the specified range. Verification method: measurement plus functional test. Rationale: 150 degrees is the lower edge of the claimed operating window per the process specification; seal integrity is the quality attribute the parameter controls.

Step 2, seal temperature high. Same structure at 165 degrees, with burn-through and appearance criteria added, because the failure mode at the hot edge differs from the cold edge, and the criteria should chase the failure mode, not mirror the other step.

Step 3, nominal. 158 degrees, 0.35 seconds, 60 bags per minute, larger sample, criteria identical in kind. This is the anchor condition and the configuration the PQ will later run under routine conditions.

Step 4, worst-case combinations. Maximum speed, minimum temperature, minimum dwell: the coldest, fastest, shortest seal the SOP permits. And its mirror: minimum speed, maximum temperature, maximum dwell, the hottest, longest exposure, challenged against burn-through and appearance criteria. Specification: all seal criteria pass at each combined condition. Rationale: the two joint worst cases for seal formation per the risk assessment; single-parameter edges do not cover the combinations, and each edge's failure mode gets its own hardest allowed condition.

Step 5, speed sweep. 40, 60, and 80 bags per minute at nominal sealing parameters, confirming bag forming, fill weight, and cutoff registration at each, because speed interacts with functions beyond the seal.

Five steps, three sourced numbers per parameter, every specification quantitative, every rationale naming its source. The full protocol wraps these in the OQ's other sections, but this pattern, repeated per critical parameter, is the core of the exercise. Passing it qualifies the claimed window; the combined-document formats then carry the same steps inside an IQ/OQ or IQ/OQ/PQ structure where that packaging fits the campaign.

A worked example diagram showing a form-fill-seal parameter challenge grid: three parameter rows for seal temperature, dwell time, and line speed, each with low, nominal, and high challenge chips positioned on its range bar, plus a worst-case combinations card pairing the cold case of minimum temperature, minimum dwell, and maximum speed with its mirrored hot case of maximum temperature, maximum dwell, and minimum speed, with sample counts per condition and a note that criteria chase the failure mode at each edge

The mistakes that void the exercise

Challenging the nameplate instead of the claim. The most common failure: low and high set from the machine's capability because those numbers were easy to find. Either the OQ fails at conditions production will never use, or it passes and implies a qualified range wider than the evidence honestly supports.

Only nominal. An OQ that runs every test at the routine setpoint qualifies a point, not a range. The first time production trims speed or temperature, the process is operating outside its demonstrated window, and the revalidation question arrives years earlier than it needed to.

Unbounded adjustable parameters. A parameter operators can adjust with no stated range cannot be bracketed, because there are no edges to challenge. Every operator-adjustable setting that can affect quality needs a claimed window before OQ, and the window then belongs in the SOP so the qualified range and the permitted range stay the same thing.

Edges without output checks. Steps that verify the controller reached 150 degrees but never test the seal made at 150 degrees prove instrumentation, not fitness. Every challenge point needs the output of the challenged function checked against its quality attribute.

Treating the qualified window as decoration. After OQ, a setpoint change outside the proven range is a change with validation impact, and moving nominal to the edge of the qualified window on a Friday afternoon is how ranges get exceeded quietly. The window earns its keep only if change control treats its edges as real.

The bracketing test

The compact version: name the window the process claims, put low and high at its edges, put nominal at the routine setpoint, add the few worst-case combinations the risk assessment actually supports, and bound both the parameter and its output at every point with quantitative criteria that trace to a source. Machine capability sets what the equipment could do; the process specification sets what you must prove; the OQ proves it at the edges so production can live anywhere between them. Three numbers per parameter, each with a named source, is the whole discipline.

Valiqa generates OQ protocols with low/nominal/high challenge steps built from the asset's actual performance parameters, including multi-condition tests for speed, temperature, and pressure dependent settings, quantitative specifications with units and tolerances, and per-category acceptance criteria and sample-size tables, so the bracketing structure arrives in the draft instead of being assembled by hand.

---

Valiqa is an AI-powered validation lifecycle platform for regulated manufacturing. Learn more at valiqa.io

Frequently Asked Questions

Ready to automate your validation documentation?

Generate audit-ready IQ/OQ/PQ protocols in minutes, not weeks.

Get Started

We use essential cookies for authentication and security. With your consent, we also use Microsoft Clarity, Google Analytics, and the LinkedIn Insight Tag on our marketing pages to understand how visitors navigate the site and to measure our advertising. Learn more.