Skip to main content

Quality control and batch release

📍 Where we are: Stop 20 of 21 — the medicine is made and sealed in vials, but no one can use it yet. First, we have to prove it is good, and someone has to sign their name to that promise.

Two scientists in lab coats and gloves working at the bench in an analytical laboratory; one holds up a sample tube. Analysts at work in a quality-control laboratory. Every batch is sampled and put through instrument tests like these before anyone signs it off for release. Scientists in an analytical laboratory. Image by USDA, public domain, via Wikimedia Commons.

We have a finished batch of medicine sitting in vials. But "finished" does not mean "approved." Before a single vial reaches a patient, the batch must pass a battery of laboratory tests and then survive a careful human review. This chapter is about that final gate — the place where weeks of cell culture, purification, and filling are either blessed for release or stopped cold.

The simple version

Imagine a brand-new car rolling off the assembly line. Before it can leave the factory, inspectors check the brakes, the lights, the engine, and the paint. Then a manager reads the whole inspection report and signs a release form. Only then does the car ship. Our medicine goes through the exact same thing: a multi-point inspection, then a signature from someone who is legally accountable for the call.

What this chapter covers

We will draw a clean line between the team that tests (Quality Control) and the team that decides (Quality Assurance). We will walk through the real release tests a monoclonal-antibody (mAb) batch must pass — identity, purity, potency, sterility, endotoxin, and appearance — and put real numbers and named standards on each one, because this is where vague intuition ("it must be pure") becomes a precise, legally binding specification ("aggregates no more than about 5 percent"). We will follow the results into the Certificate of Analysis and the disposition decision, see what actually happens when a batch fails, and end with the modern dream of releasing a batch in real time instead of waiting weeks for the lab.

QC tests, QA decides: the two teams and the framework

The two teams

Two different teams guard this gate, and it is important not to mix them up.

  • Quality Control (QC) is the lab that tests the medicine. They pull samples and run experiments to measure quality against written specifications.
  • Quality Assurance (QA) is the system — and the people — who make sure everything was done correctly, and who approve the batch for release. QC measures; QA judges.

The framework: ICH Q6B and cGMP

This is not a bureaucratic nicety. The international framework for what a biologic must demonstrate — and how to write those specifications — comes from ICH Q6B, the guideline on specifications for biotechnology products [1]. (ICH is the International Council for Harmonisation, the body that aligns drug-quality rules across the US, EU, Japan, and beyond.) Under cGMP — current Good Manufacturing Practice, the body of regulations that defines how medicines must be made and controlled — the laboratory that generates the data is deliberately kept separate from the authority that releases the batch, so that no single person both runs the test and decides to ship. In the United States, the laboratory controls that govern this work are written into law in 21 CFR Part 211, Subpart I (Sections 211.160 to 211.167), which requires written specifications, validated test methods, defined sampling plans, and a documented release decision for every batch [2].

Long before the end, QC has already been watching. Tests taken during manufacturing are called in-process controls (IPCs) — checks at each step, like measuring the temperature while you cook rather than only tasting the final dish. They catch problems early, while there is still time to react. The release tests at the very end are the final, formal confirmation.

The release tests, one by one

Each release test answers a simple question, but behind each question sits a defined method and a numeric limit that the product must hit. The set of attributes a mAb must demonstrate, and how to specify each one, follows the ICH Q6B framework introduced above [1]. The analytical methods themselves — peptide maps, SEC-HPLC, the bioassay — are the same instruments developed and qualified in analytical development and formulation; here we are running them as the final, GMP-controlled release panel rather than as development experiments.

Identity: the right antibody

Is this actually the right antibody? Before anything else, we confirm the molecule in the vial is the one we meant to make and not a mix-up from another product or batch. Identity is usually confirmed by methods such as peptide mapping (chopping the antibody into its short amino-acid pieces and checking the pieces match the expected sequence, like a fingerprint), charge-based separations (sorting molecules by their electrical charge, which is characteristic for a given antibody), or binding assays that recognize the specific antibody.

Purity: aggregates, HCP, leached Protein A, residual DNA, charge and glycan variants

How much unwanted material is left? A purified antibody is never perfectly alone, and the job here is to prove the leftovers are below safe limits. The main culprits, with the kinds of acceptance limits a typical mAb program targets [9]:

  • Aggregates — antibodies clumped together, which can trigger unwanted immune reactions in patients. These high-molecular-weight (HMW) species are measured by size-exclusion HPLC (a separation technique that sorts molecules by size), and a common specification is no more than about 5 percent aggregate — though a well-controlled process typically releases well below that, often under 1 to 2 percent. Because column interactions can distort the SEC number, aggregate is routinely confirmed orthogonally — that is, by a second, physically independent method that measures the same thing on a completely different principle, so the two cannot share the same blind spot — using analytical ultracentrifugation (AUC-SV, which spins the sample at high speed and watches how fast molecules of different sizes settle) or light-scattering (SEC-MALS). The size-variant story has a low-molecular-weight (LMW) counterpart too — fragments and clipped chains — caught by CE-SDS (capillary electrophoresis that sorts the antibody's chains by size), run both with and without a reagent that breaks the antibody into its component chains (non-reduced versus reduced), so an unexpected fragment shows up as an extra size band alongside the aggregate result.
  • Host cell protein (HCP) — leftover protein from the CHO cells that did the manufacturing. Limits are usually in the range of roughly 100 parts per million (ppm) or below, depending on the product's history and how well the process clears it. The total-HCP number hides a real trap: it comes from a polyclonal-sandwich ELISA — an antibody-based test (ELISA = enzyme-linked immunosorbent assay) that uses a mix of detector antibodies (that is the "polyclonal" part) raised to recognize the host cell's proteins (the "anti-CHO" antibody) to catch and count leftover CHO protein. The catch is that those detector antibodies can only count proteins they were actually raised to recognize, so they must truly cover the specific proteins in your process. A single problematic HCP — say, a lipase (a fat-splitting enzyme) that slowly degrades the formulation's polysorbate (the surfactant added to stop the antibody from sticking together) so that over months the protein begins to aggregate — can sit comfortably below the total-HCP limit yet still wreck shelf-life stability, which is why an orthogonal (independent, different-principle) mass-spectrometry HCP identification is increasingly used to find the dangerous individuals behind the total-HCP number.
  • Leached Protein A — a trace of the affinity resin used in the capture step can shed into the product; specifications typically hold this below about 10 ppm.
  • Residual DNA — stray genetic material from the production cells, controlled to very low levels, on the order of 10 nanograms per dose or less (the exact limit depends on the host cell type and route of administration). That 10 ng/dose figure, measured by qPCR (quantitative PCR, an assay that copies and counts the DNA present), is the conservative regulatory ceiling for continuous (immortalized, indefinitely dividing) cell lines like CHO, set by long-standing WHO cell-substrate guidance; a well-cleared modern mAb process typically drives residual DNA down to the picogram range, often with an accompanying fragment-size expectation (DNA cut below roughly 200 base pairs, so any residue cannot encode a functional gene).
  • Charge variants — slightly more acidic or basic forms of the antibody, produced by small chemical changes that add or remove charge: deamidation (an amino-acid group turning acidic over time), an extra positively-charged lysine residue left on the end of the chain (C-terminal lysine), or charged sialic-acid sugars on the glycan (sialylation). They are resolved and quantified by icIEF (imaged capillary isoelectric focusing — a method that lets each form drift to the spot where its net charge is zero, so the differently-charged forms line up at separate positions and can be counted) or cation-exchange chromatography (CEX) and reported as percent main, acidic, and basic species. These are a quantitative purity attribute in their own right, not just an identity check.
  • Glycan profile — the sugar structures attached to the antibody, measured as an N-glycan map. One species matters enough to call out: afucosylation, the fraction of glycans lacking core fucose, directly raises antibody-dependent cell-mediated cytotoxicity (ADCC — the antibody flagging a target cell so the body's own immune cells destroy it); removing that core fucose lets the antibody grip those immune cells more tightly, so it kills harder, and so this is tied straight to potency — a glycosylation CQA, not a cosmetic one.

Potency and bioassay: the 80–120% window

Does the medicine actually work? This is the most subtle and the most important test, and the place where the old short version of this story was misleading. Potency is not merely "does the antibody bind its target." It is measured by a bioassay — a relative-potency test (it compares the sample's biological activity against a trusted reference rather than reading an absolute number), often run on living cells so it captures whether the antibody truly does its job, that must be stability-indicating, meaning it can detect a subtle loss of function as the product ages on the shelf, not just confirm that the molecule is present. The result is reported as a percentage of a Reference Standard — a carefully characterized, archived lot that defines "100 percent active" — and the acceptance range is typically 80 to 120 percent of that standard. The validation expectations for such assays are spelled out in USP General Chapter <1033> on biological assay validation [6]. A binding test alone can pass while a damaged antibody has quietly lost the ability to do its job; a proper potency bioassay is designed to catch exactly that.

Sterility and endotoxin: two separate defenses

Are there any living microbes? Here the answer must be a flat zero. There is no "low" limit for sterility — a sterile product contains no living bacteria or fungi, full stop. The test is defined by USP General Chapter <71>, which uses either membrane filtration or direct inoculation of the sample into two growth media (Fluid Thioglycollate Medium, which favors bacteria that grow without oxygen, and Soybean–Casein Digest, which favors oxygen-loving bacteria and fungi) and then incubates for a minimum of 14 days to see whether anything grows [3]. The 14 days is the validated window for slow-growing organisms to multiply to a level a technician can actually detect; those two weeks of patient waiting are one of the main reasons a batch cannot ship the day it is filled.

Two caveats matter. First, the compendial culture is increasingly supplemented or replaced by validated rapid microbiological methods (RMM), which is what makes fast turnaround possible for short-dated products. Second, the test samples only a fraction of the batch, so it gives confidence, not proof.

In practice the finished batch of filled vials is placed in quarantine — physically held and barred from shipment — while a defined number of vials is pulled from across the run per a written sampling plan and carried to the lab; the rest of the batch cannot move until QA signs the disposition. This is exactly why sterility is built into the process (a closed system, plus sterilizing-grade 0.22 µm filtration — a pore size small enough to hold back bacteria as the fluid passes through) rather than tested into the product at the end.

Are there toxins shed by bacteria? This is a separate test from sterility, and the two are easy to confuse. An endotoxin is not a living microbe — it is lipopolysaccharide, a fever-causing (pyrogenic) molecule from the outer wall of gram-negative bacteria, which can remain dangerous even after the bacteria themselves are dead and filtered out. So you can be perfectly sterile and still fail for endotoxin.

The test, required for biologics under FDA 21 CFR 610.13 (the purity requirement, which covers the test for pyrogenic substances and bacterial endotoxins) and detailed in USP General Chapter <85>, classically uses Limulus Amebocyte Lysate (LAL) — a reagent made from the blood cells of horseshoe crabs, which clots in the presence of endotoxin [4]. Limits are set per patient dose and body weight. The general threshold for an injected (parenteral) drug is K = 5 endotoxin units (EU) per kilogram of body weight per hourK is simply the standard symbol the pharmacopeias use for this per-kilogram threshold constant.

The arithmetic is worth doing once: 5 EU/kg multiplied by a 70 kg adult gives 350 EU as the regulatory ceiling for a dose given in one hour. Companies then routinely set a tighter product-specific limit to leave headroom against that ceiling — here about 175 EU per dose, half of 350 — which is why the prose ceiling and the table's product limit differ. FDA's guidance on pyrogen and endotoxin testing lays out the acceptable methods and how to calculate these limits [5]. Unlike the 14-day sterility culture, an LAL result comes back in a few hours.

One current shift a 2026 reader should know: the horseshoe-crab-derived LAL reagent is increasingly being replaced by recombinant Factor C (rFC), now compendially recognized, for both supply-chain sustainability and crab-conservation reasons.

Sterility and endotoxin are two different gates

A sterile batch can still fail for endotoxin — and an endotoxin-clean batch can still fail sterility. Sterility asks "is anything alive?"; endotoxin asks "is there toxic debris from bacteria, dead or alive?" Passing one says nothing about the other, so both are released independently.

Appearance, concentration, and pH

Three checks, not one. These are genuinely separate measurements that older summaries sometimes mash together:

  • Appearance is a visual inspection for color, clarity, and visible particulates — a protein solution should be clear and free of floating matter.
  • Concentration (protein content) is quantified by an instrument, often UV absorbance or HPLC, to confirm the strength is correct.
  • pH is read with a pH electrode, because even small shifts in acidity can destabilize the antibody.

Every one of these tests maps back to a critical quality attribute (CQA) — the property, first defined back in analytical development and formulation, that must be right for the medicine to be safe and effective. (Its partner concept is the critical process parameter (CPP): a CQA is a property of the product you must hit, while a CPP is a knob in the process — a temperature, a pH, a flow rate — you control to land it there.) The release tests are how we confirm each CQA landed inside its pre-approved target window.

The link runs both ways, and naming the upstream knob makes each result less of a surprise. Several release CQAs trace directly back to a specific CPP set weeks earlier: the glycan profile (and its afucosylation fraction) is shaped largely by production bioreactor conditions — feed strategy, dissolved oxygen, pH, and temperature acting on the CHO cells; aggregate level is driven by the low-pH viral-inactivation hold and the polishing-and-formulation conditions the molecule sees; charge variants track culture duration and pH; and HCP and leached Protein A are set by how hard the capture and polishing steps are pushed. So a release result is rarely a verdict on the QC lab alone — it is the readout of process parameters chosen and held far upstream. That result → derived-from → batch → runs-on → method, and test → measures → CQA → controlled-by → CPP, is a typed chain of relationships; the ontology book makes those edges explicit and queryable in relations and genealogy and classes and taxonomy.

TestWhat it checksTypical acceptance limit
IdentityThe right antibodyMatches the reference (peptide map / binding)
AggregatesClumped antibodyabout 5% or less (by SEC-HPLC)
Host cell protein (HCP)Leftover CHO proteinroughly 100 ppm or below
Leached Protein AShed capture resinabout 10 ppm or below
Residual DNAStray cell DNA10 ng per dose ceiling, typically pg (by qPCR)
Charge variantsAcidic/basic speciespercent main / acidic / basic (icIEF or CEX)
Glycan profileN-glycans, afucosylationwithin profile window (ties to ADCC potency)
Fragments / clipsLow-mol-weight specieswithin limit (non-reduced CE-SDS)
PotencyIt still works80–120% of reference (bioassay)
SterilityLiving microbeszero growth (14-day culture)
EndotoxinBacterial pyrogenabout 175 EU per dose or less (LAL)
Appearance · concentration · pHLook, strength, acidityeach within spec

Several named standards govern this panel, and because they arrive scattered through the prose it helps to collect them in one place. Each code below is glossed where it first appears above; this is just a lookup index:

CodeWhat it governsWhere it bites here
ICH Q6Bspecifications for biotechnology productsthe whole release panel
ICH Q5Cstability testing of biotech productsexpiry date and release-vs-shelf-life limits
ICH Q1A(R2)long-term / accelerated study designhow the stability studies are run
USP <71>sterility testthe 14-day culture
USP <85>bacterial endotoxins testthe LAL / endotoxin limit
USP <1033>biological assay validationthe potency bioassay
21 CFR 211 Subpart Ilaboratory controls (specs, methods, sampling)how QC must run and document tests
21 CFR 610.13purity (pyrogen / endotoxin) for biologicsthe endotoxin requirement
21 CFR 211.165release for distribution (US)who signs the disposition
21 CFR Part 11electronic records and signaturesthe CoA signatures
EU GMP Annex 16Qualified Person certificationwho releases the batch in the EU

There is one more thing the tests depend on that beginners rarely see: the expiry date and the release limits themselves are set by stability data. For a biologic the governing guideline is ICH Q5C (stability testing of biotechnological products), which sits alongside the Q1A(R2) long-term, accelerated, and intermediate study-design framework: batches are placed on storage and tested over time to learn how fast quality drifts. This is also why many attributes carry two limits — a tighter release limit and a wider shelf-life (end-of-expiry) limit — with companies running internal alert and action limits inside the registered window to catch drift before a result actually goes out of specification. That tiering is what justifies, for example, why potency must release near the top of its range — so it can still be inside specification at the end of shelf life — and what ultimately defines how long the medicine can sit in a pharmacy before it must be discarded.

QC Test Workflow Schematic: vial through six parallel test methods converging to CoA and Qualified Person disposition The cascade of release tests: a finished vial is sampled and tested in parallel across identity, purity, potency, sterility, endotoxin, and appearance, with results compiled into the Certificate of Analysis and final disposition decision by the Qualified Person. Original diagram by the authors, created with AI assistance.

From results to the CoA

Once every test reports back, the numbers do not release the batch by themselves. They are compiled, alongside the complete batch record — the full diary of how the batch was made, every weighing, every temperature, every operator initial — into one formal document: the Certificate of Analysis (CoA). The CoA lists each test, its specification, and the actual result side by side, and it is the attestation that the batch meets its registered standards. One row reads like a sentence — for example, Aggregates · NMT 5.0% · 1.2% · PASS — the test, the limit it had to beat ("not more than"), the measured value, and the verdict.

Anatomy of a Certificate of Analysis

The CoA is the batch's identity card. Read top to bottom, it names who the batch is (product, batch number, manufacturing and expiry dates), then lays out every release test as a row — the measured value, the specification window it had to land inside, and a pass/fail verdict — and finally carries the overall RELEASE verdict and the signatures that make it legally binding. Crucially, those signatures are not ink: under modern data-integrity rules they are 21 CFR Part 11 electronic signatures — the US rule that lets an electronic signature legally replace ink by binding one named person to the exact record they sign — each one binding a named human to a meaning ("I generated this data"; "I reviewed the record and certify the batch") with a tamper-evident timestamp. The same record exists downstream as data: the instant a technician records a measured value, that number becomes a tagged data point in the batch's data shadow — the growing digital twin of measurements that trails the physical lot. The data book traces this directly, from where the data is born at the instrument, through the data shadow that the batch accumulates, to the lifecycle of a data point as each result moves into systems of record; the open-source analytical lab, LIMS, and ELN chapter then shows the very lab.result row and audit chain that this paper certificate becomes in software, and the reference architecture shows where that row sits in a full free-software stack.

Anatomy of a Certificate of Analysis: a card showing batch identification, a table of release tests with measured value, specification window, and pass/fail verdict for each, an overall release verdict, and a dual electronic-signature block for the analyst and the QA releaser. The Certificate of Analysis as an identity card: batch identity, one row per release test (value, specification window, verdict), the overall release verdict, and the two Part 11 electronic signatures — analyst and QA releaser — that bind the batch to accountable people. Original diagram by the authors, created with AI assistance.

The disposition decision: release, reject, investigate

Then a human makes the disposition decision — the verdict to release or reject. Who that human is depends on where you are, and this is a real jurisdictional difference worth getting right:

  • In the European Union, the batch must be certified by a named, legally defined Qualified Person (QP). The QP is an individual with required pharmaceutical or scientific training and documented cGMP knowledge, who personally signs to certify or reject each batch and bears legal accountability for it. The QP's duties for reviewing the batch record and CoA and certifying the batch are set out in EU GMP Annex 16 [7].
  • In the United States, FDA does not mandate a single named "Qualified Person." Instead, release for distribution is approved under 21 CFR 211.165 by the quality unit, with the final signature typically coming from a senior QA or manufacturing leader [2].

Whichever jurisdiction you are in, the flow below traces every one of these paths from test results to a final disposition.

QC release flow: a finished batch goes through QC release tests into the Certificate of Analysis, which is also fed by the complete batch record; QA / Qualified Person review then either releases the batch to patients or rejects it, sending it to a deviation investigation that ends in approved reprocessing or destruction.

Only a batch that is released is allowed to ship. But notice that "reject" is not a single dead end. A failing or out-of-specification (OOS) batch first triggers a formal deviation investigation — a documented effort to find the root cause, which may even conclude the result was a laboratory error rather than a true product failure. From there, the batch might be approved for reprocessing under an already-validated procedure, handled through another defined regulatory pathway, or, yes, destroyed. Scrapping the batch is one possible outcome, not the automatic one. What is never allowed is shipping a batch that does not meet its specifications. A distinct, milder signal is an out-of-trend (OOT) result — one still inside specification but drifting away from the batch-to-batch norm; it does not block release but feeds the same investigation discipline. Either way, the investigation does not end at root cause: it closes through CAPA (corrective and preventive action), the formal loop that fixes the immediate problem and changes the process or procedure so the deviation cannot recur.

The disposition is therefore best read as the small state machine sketched below: results become a CoA, QA reviews it, and the review opens onto three outcomes — release, reject, or investigate — with the OOS investigation looping cleanly back to a fresh disposition decision once its root cause is known.

Disposition state diagram: QC test results feed a Certificate of Analysis, which goes to QA or Qualified Person review; the review branches to release if all results are in spec, reject if there is a true product failure, or investigate if a result is out of specification, with the out-of-specification investigation looping back to the review for re-disposition.

Why it matters

You have now seen the full gate: QC measures against fixed limits, the results compile into the CoA, and QA dispositions the batch to release, reject, or investigate. That is the complete arc from a sealed vial to a medicine cleared to travel.

This is the last line of defense. Everything upstream — the cells, the production bioreactor, the polishing chromatography, the fill-finish — exists to produce a medicine that passes here. If a batch is wrong and slips through, a real person gets a dose that may be too weak to treat their disease, contaminated, or actively unsafe. So the gate is deliberately strict, and the decision is made by people who put their names to it.

One failed test can stop an entire batch

These tests are pass or fail against fixed limits. A single failed critical test — say, sterility — can halt an entire batch that took weeks to grow and purify and is worth millions of dollars. You cannot "patch" a sterility failure. This is exactly why getting every earlier step right, the first time, matters so much: the final gate has no way to add quality back in. It can only confirm whether the quality is already there.

Data-integrity failures in QC

The release gate is only as trustworthy as the data feeding it, and the QC laboratory is where some of the most damaging data-integrity failures in the industry have happened. These are not abstract risks — they are the recurring patterns behind real FDA warning letters and import alerts, and they all share one trait: they let a failing batch look like a passing one.

  • Suppressed out-of-specification (OOS) results. A test produces a failing number; rather than open the formal investigation, an analyst quietly discards the result, re-tests until a passing value appears, and reports only the "good" run. FDA's guidance on investigating OOS test results exists precisely to forbid this: a confirmed OOS cannot be invalidated without a documented, scientifically justified investigation, and you may not simply average it away or test into a pass [10].
  • Testing into compliance. A close cousin — running extra replicates or extra samples, with no pre-defined plan, until the average drifts inside the limit. The specification window stops being a real gate and becomes a target to be hit by repetition.
  • Disabled chromatography audit trails. Modern HPLC and other instrument software records every injection, integration, and reprocessing in an audit trail. Turning that audit trail off, or running the instrument under a configuration that lets results be deleted or re-integrated without a trace, destroys the ability to tell whether the reported chromatogram is the first one or the tenth. PIC/S guidance PI 041 on data integrity treats the audit trail as a required, reviewable control, not an optional feature [11].
  • Shared analyst logins. When several people sign in to the LIMS or the instrument under one shared username, attributability collapses: the record can no longer say who ran the test or who approved the result. This is why 21 CFR Part 11 requires unique, individual electronic identities and signatures for regulated records — the same signatures shown on the CoA above [12].

The defenses against all four are the ALCOA principles — data must be Attributable, Legible, Contemporaneous, Original, and Accurate — extended in current guidance (including the PIC/S PI 041 cited above) to ALCOA+, which adds that records also be Complete, Consistent, Enduring, and Available — enforced both by procedure and by the software itself. This is the physical-world origin of a thread the data and open-source books pick up directly: see Part 11 and Annex 11 for how electronic records and signatures are governed, and the open-source Part 11 and Annex 11 in open systems chapter for how a free software stack can be made to enforce unique logins and immutable audit trails on exactly this kind of lab.result record.

RTRT and PAT: the direction of travel

Classic release testing happens at the very end, after the whole batch is made — which means you can wait the better part of a month, largely because of that 14-day sterility incubation, to learn whether a batch passed. The modern direction is Process Analytical Technology (PAT): sensors and analyzers that measure quality attributes continuously, during manufacturing rather than only afterward. FDA formally introduced the PAT framework in 2004 as a way to build quality into the process instead of testing it in at the end [8].

PAT opens the door to real-time release testing (RTRT) — releasing a batch on the strength of data gathered as the medicine is made, using multivariate data analysis (MVDA) — statistical models that read many process variables together, rather than one at a time, to judge whether the overall pattern matches a known-good batch — to combine upstream, purification, and fill-finish measurements into a real-time judgment of quality. But this is emphatically not automatic. RTRT requires a pre-approved control strategy and demonstrated, regulator-accepted equivalence to traditional end-product testing before a company is allowed to skip a conventional final test. It is earned through years of development, not switched on.

This is where the broader push toward continuous, data-rich manufacturing meets the release gate. In continuous and intensified processes — the perfusion-and-multi-column-capture variant (perfusion keeps fresh medium flowing through the bioreactor and product flowing out continuously, and multi-column capture purifies that steady outflow, rather than the dominant fed-batch platform that grows one fixed tankful and harvests it all at once) that is the emerging modern alternative — quality data is generated as a steady stream rather than at a single endpoint, which is a natural fit for PAT and real-time release. The everyday reality across the industry, though, remains end-of-batch testing under the standards above; real-time release is the destination, not yet the default. The companion data and ML books pick this thread up where it becomes software: the lifecycle of a data point shows how a release-relevant measurement is captured and governed, and the ML book's QC and release chapter builds the multivariate monitoring and OOS-prediction models. A predictive model used in this regulated setting carries its own burden of proof, mirroring the equivalence demand above: it must be honestly validated (the ML book's models and validation chapter covers cross-validation and the applicability domain — knowing when a new batch falls outside the data the model was trained on, where its prediction should not be trusted) and then kept trustworthy over its whole service life (MLOps and lifecycle). The open-source stack operationalizes the dashboards that turn a stream of PAT data into a real-time release judgment.

Key terms

  • Quality Control (QC) — the lab that tests samples to measure a batch's quality against written specifications.
  • Quality Assurance (QA) — the system and people who verify everything was done correctly and approve the batch for release.
  • In-process control (IPC) — a quality test taken during manufacturing, not only at the end.
  • Release test — a final test the finished batch must pass before it can ship.
  • Potency / bioassay — a relative-potency, stability-indicating test (often cell-based) proving the medicine still functions, reported against a Reference Standard, typically 80 to 120 percent.
  • Sterility — the requirement that there are zero living microbes in the product, confirmed by a 14-day culture.
  • Endotoxin — lipopolysaccharide, a fever-causing molecule from gram-negative bacteria, controlled to a strict per-dose limit and detected by the LAL test; a separate concern from sterility.
  • Critical quality attribute (CQA) — a property that must be right for the medicine to be safe and effective.
  • Certificate of Analysis (CoA) — the formal document listing every release test, its specification, and the actual result for a batch.
  • Batch record — the complete written history of how a batch was made.
  • Disposition — the final decision to release or reject a batch.
  • Out-of-specification (OOS) result — a test result that falls outside its acceptance limit; it triggers a documented investigation and may never simply be discarded or re-tested into a pass.
  • Audit trail — the instrument or software record of every action taken on a result (injection, integration, reprocessing, deletion), used to prove the reported value was not quietly manipulated.
  • ALCOA / ALCOA+ — the data-integrity principles that records be Attributable, Legible, Contemporaneous, Original, and Accurate; current guidance (including PIC/S PI 041) extends these to ALCOA+, adding that records also be Complete, Consistent, Enduring, and Available.
  • Qualified Person (QP) — in the EU, the legally accountable named individual who certifies or rejects each batch; in the US, this role is filled by a senior quality unit signature rather than a single named QP.
  • Reference Standard — a well-characterized archived lot that defines "100 percent" for the potency assay.
  • Process Analytical Technology (PAT) — measuring quality attributes continuously during manufacturing.
  • Real-time release testing (RTRT) — releasing a batch on real-time process data instead of conventional end-product testing, only after proven equivalence and a pre-approved control strategy.
  • Data shadow — the growing collection of tagged digital measurements that trails a physical batch, beginning the instant each result is recorded.
  • Applicability domain — the region of input data a predictive model was trained on; a new batch falling outside it is a signal that the model's prediction should not be trusted.

Where this leads

A released batch is no longer just a product of the factory — it is a medicine cleared to travel. But a sterile, potent vial does no good if it spoils on the way to the patient. Next, in distribution, we follow the released batch out the door and through the cold chain that must keep it safe, intact, and within temperature all the way to the clinic.