Cleaning Validation in Pharma: MACO, HBEL, Swab & Rinse Explained
2026-06-29
Cleaning validation in pharma explained — MACO and HBEL/PDE limits, swab vs rinse sampling, recovery studies, hold times, and the mistakes that earn a 483.

A tank looks spotless. The operator signs "visually clean," the next product goes in, and a few micrograms of the last product's API ride along into a batch meant for a different patient. That carryover is invisible, it's the single biggest cross-contamination risk on a shared manufacturing line, and "it looked clean" is not a defence an inspector will accept. Cleaning validation is how you prove — with numbers, not eyes — that your cleaning procedure removes residues to a level that is safe for the next product.
This guide covers what cleaning validation actually is, the regulations behind it, how the acceptance limits are calculated (including the shift from the old 10 ppm / 0.001-dose rules to health-based limits), how you sample and test, and the mistakes that earn a 483.
What cleaning validation is — and what it proves
Cleaning validation is documented evidence that a cleaning procedure, performed as written, consistently reduces three things to acceptable levels:
- Product residue — the active ingredient (and degradants) of the previous product.
- Cleaning-agent residue — detergents, solvents or sanitisers used to clean.
- Microbial load — bioburden and, where relevant, endotoxin, especially after wet hold.
The key word is consistently. A one-off clean tells you nothing; validation demonstrates the procedure is robust and reproducible — the same logic behind any process validation exercise.
The regulations behind it
Cleaning validation is an explicit GMP requirement, not best practice:
- US FDA — 21 CFR 211.67 requires equipment to be cleaned at appropriate intervals; the FDA's Guide to Inspections of Validation of Cleaning Processes frames the expectations inspectors apply.
- EU GMP Annex 15 (Qualification & Validation) mandates cleaning validation and, since its 2015 revision, requires limits based on health-based exposure limits (HBEL).
- EMA HBEL Guideline (2014/2015) introduced the PDE (Permitted Daily Exposure) approach for shared facilities — the change that reshaped how limits are set.
- ICH Q9 (Quality Risk Management) underpins worst-case selection and grouping decisions.
- WHO GMP, PIC/S PI 006, and India's Revised Schedule M all expect documented cleaning validation with scientifically justified limits.
Setting acceptance criteria: from 10 ppm to HBEL
This is where most of the science lives. Historically, the Maximum Allowable Carryover (MACO) was set using the most stringent of three traditional criteria:
1. 0.1% (1/1000th) of the minimum therapeutic dose of the previous product appearing in the maximum daily dose of the next.
2. 10 ppm of the previous product in the next product.
3. Visually clean — no visible residue (a useful check, never a standalone limit).
The modern, regulator-expected approach is health-based: derive a PDE/ADE (Acceptable Daily Exposure) for the previous product from its toxicological and pharmacological data, then calculate MACO from it:
MACO = PDE(previous) × (minimum batch size of next product ÷ maximum daily dose of next product)
Per Annex 15 and the EMA guideline, the HBEL/PDE-based limit is the scientific basis; the old 10 ppm and 0.001-dose figures can still serve as practical alert levels, but they no longer justify a limit on their own. From MACO you derive the surface limit by dividing across the total shared product-contact area, then convert to a swab limit per sampled location — always corrected by your recovery factor.
Sampling: swab vs rinse (and why recovery matters)
Two complementary methods:
- Swab sampling — a direct, physical wipe of a defined surface area, targeting worst-case, hard-to-clean locations (corners, gaskets, dead legs, agitator blades). Best for specific residues.
- Rinse sampling — analysing the final rinse water; good for large or inaccessible surfaces (long pipework, tanks) that you can't reach with a swab.
Neither number means anything without a recovery study: spike a known amount of residue onto the surface material, swab/rinse, and measure what you actually recover. A 70% recovery means your result is corrected accordingly. Inspectors routinely cite firms that report swab results with no validated recovery factor — it's one of the most common findings.
Analytically, you pair a specific method (typically HPLC) for the target API with a non-specific method (TOC or conductivity) for total organic/ionic residue, plus microbial testing after hold.
Worst-case thinking: grouping, hold times, campaigns
You don't validate every product/equipment combination — you validate the worst case and bracket the rest, justified under quality risk management:
- Worst-case product — lowest solubility, highest potency/toxicity (lowest HBEL), hardest to clean. Group products into families that share equipment and a cleaning procedure.
- Worst-case equipment — the hardest-to-clean train and its hardest-to-clean parts.
- Dirty Hold Time (DHT) and Clean Hold Time (CHT) — validate the maximum time equipment can sit before cleaning and after cleaning (clean) before microbial limits are breached.
- Campaign limits — how many consecutive batches of the same product before a full clean is required.
Traditionally this is demonstrated over three consecutive successful runs; modern lifecycle thinking treats validation as ongoing, with routine monitoring feeding continued verification.
The lifecycle: when you must revalidate
Cleaning validation is not "done once." Trigger a review or revalidation when:
- A new product is introduced into the shared train (recalculate worst-case and MACO).
- The formulation, cleaning agent, procedure, or equipment changes — which should flow through change control.
- A cleaning OOS or deviation occurs.
- Periodic review (annual / APQR) flags a trend.
The hardest part in practice isn't the chemistry — it's catching the trigger. A formulation change three departments away can quietly invalidate your worst-case assumption, and nobody connects the two until an audit does.
Mistakes that earn a 483
- Visual-only acceptance with no quantitative limit.
- No (or poor) recovery studies behind swab results.
- Still using only 10 ppm / 0.001-dose where an HBEL-based limit is required.
- Unjustified worst-case — product or equipment grouping with no scientific rationale.
- DHT/CHT not validated — hold times assumed, not demonstrated.
- Records that don't hold up — missing raw data, unattributed entries, gaps that fail ALCOA+ data integrity.
- Revalidation triggers missed — changes made without re-evaluating cleaning impact.
Where this gets easier
Cleaning validation generates a lot of connected records — protocols, worst-case rationales, swab and rinse results against per-location limits, recovery factors, DHT/CHT studies, and a revalidation history per equipment train. Kept in spreadsheets and binders, the data is fine; the connections are what break — a change that should have triggered revalidation, a swab result trending toward its limit, a hold-time study that expired.
A connected quality system keeps each protocol, result and limit on one screen, ties revalidation to change control and deviations so a change can't be closed without flagging its cleaning impact, and shows the validated status of every equipment train at a glance — so you walk into an audit able to prove "clean" with numbers, not adjectives.
Flobri runs cleaning validation alongside change control, deviations, OOS and stability as one connected quality workflow — every protocol, swab result and revalidation trigger linked, so a change to one product can't silently invalidate the cleaning status of the line. See how it works.