📐 Design Space Definition (QbD)
This simulation defines the design space for a manufacturing process based on critical quality attributes (CQAs), ensuring that product quality is maintained within specified limits.
The Quality Target Product Profile — Anchoring QbD in the Desired Clinical Outcome
Quality by Design begins not with a process, but with a destination. The Quality Target Product Profile (QTPP) is a prospective, forward-looking summary of the quality characteristics a drug product should possess to be safe and effective for the patient — dosage form, route of administration, strength, dissolution profile, container closure, and stability. Every downstream QbD activity — CQA identification, risk assessment, DoE, and ultimately the design space itself — traces back to this single anchoring document.
- Q8(R2): ICH guideline defining QTPP (Pharmaceutical Development)
- 8–12: Typical QTPP elements (dosage form, strength, PK, stability…)
- Before: QTPP defined (formulation development begins)
- CQA → CPP → DS: Downstream artifacts anchored (full QbD chain)
What belongs in a Quality Target Product Profile
The QTPP is built from the intended clinical use of the product and translates clinical needs into a quantitative, testable specification set:
• Dosage form and route of administration: immediate-release oral tablet, sterile injectable, transdermal patch • Dosage strength(s): the therapeutic range the product must deliver • Pharmacokinetic attributes: dissolution/release rate needed to achieve target bioavailability, food effect tolerance • Drug product quality attributes appropriate for the intended market: sterility, purity, stability, physicochemical properties (assay, degradation products, water content, uniformity) • Container closure system: compatibility, protection from moisture/oxygen/light • Stability requirements: shelf-life target under labeled storage conditions
The QTPP is deliberately a "profile" and not a single number — it captures ranges and qualitative expectations that later analytical work will convert into hard numeric acceptance criteria for individual attributes. It is authored jointly by formulation science, clinical, regulatory affairs, and quality functions, because it must simultaneously reflect what the molecule can deliver, what the patient needs, and what a health authority will accept as evidence of that delivery.
Why the QTPP comes first
Working backward from a defined product goal — rather than forward from an arbitrarily chosen process — is the central philosophical shift of Quality by Design relative to traditional pharmaceutical development. Under the traditional paradigm, a process is fixed early, validated at three batches, and quality is verified by testing the finished product. Under QbD, understanding is built first: what does "quality" mean for this product, which measurable attributes control it, and which process inputs control those attributes.
Because the QTPP defines the destination, it also defines the "spec" that everything downstream must be shown to meet. A dissolution CQA specification of Q ≥ 80% at 30 minutes, for instance, exists because the QTPP established that a certain PK exposure and bioequivalence profile is required for clinical performance — not because 80%/30 min is an arbitrary industry convention.
A poorly defined QTPP propagates error through the entire QbD chain: if the profile omits or mis-states a clinically relevant attribute, the CQA list built from it will be incomplete, the risk assessment will study the wrong parameters, and the eventual design space — however statistically rigorous — will not actually guarantee the quality that matters to the patient.
The QTPP as a living document across development
Although the QTPP is defined early, ICH Q8(R2) treats it as subject to refinement as product and process knowledge accumulates — a Phase 1 QTPP built on limited PK data is typically tightened or adjusted once pivotal clinical and stability data become available. What does not change is its role as the single reference point that every later QbD artifact must be traceable back to: reviewers assessing a design space submission routinely ask a firm to show the unbroken chain from QTPP element, to CQA, to CPP, to the studied region of process-parameter space — a chain that only exists because the QTPP was written down explicitly, in testable terms, before formulation and process work began in earnest.
Critical Quality Attributes — Which Measurable Characteristics Actually Matter
A Critical Quality Attribute (CQA) is a physical, chemical, biological, or microbiological property or characteristic that must be within an appropriate limit, range, or distribution to ensure the desired product quality defined in the QTPP. Not every measurable characteristic of a drug product is critical — CQA identification is the disciplined process of separating the handful of attributes whose variability threatens safety or efficacy from the many that do not.
- Q8(R2): ICH guideline defining CQA ("appropriate limit, range or distribution")
- 4–6: Typical CQAs for oral solid dose (assay, dissolution, impurities, size…)
- Severity × Uncertainty: Criticality scoring basis (impact on safety/efficacy)
- 4: CQAs carried into risk assessment (this case study)
Screening candidate quality attributes for criticality
Every attribute measurable on a finished product is a candidate: assay (potency), dissolution/release rate, related substances and degradation products, residual solvents, water content, particle size distribution, content uniformity, hardness/friability, sterility, endotoxin. Each candidate is scored against the QTPP for:
• Impact on efficacy — does variation in this attribute change the delivered dose or exposure the patient receives? • Impact on safety — could variation produce a toxic degradant, an infection risk, or a dosing error? • Current knowledge/uncertainty — how well is the attribute-to-outcome relationship already understood?
Attributes scoring high on impact and impact-uncertainty are designated CQAs; attributes that are important to monitor but pose limited risk to safety/efficacy remain quality attributes without being "critical," and are typically controlled by good manufacturing practice rather than by the design space itself. Criticality is treated as a continuum, not a binary label — many organizations plot each candidate attribute on an impact-vs-uncertainty grid and draw the CQA cutoff as an explicit, documented decision rather than an implicit one.
Worked example — four CQAs for an oral solid dosage form
For a representative immediate-release tablet, criticality screening against the QTPP typically surfaces:
1. Assay (potency): must fall within 95–105% of label claim — directly determines delivered dose 2. Dissolution rate: Q ≥ 80% at 30 minutes — governs the rate of drug available for absorption; directly linked to the PK/bioavailability element of the QTPP 3. Related substances (impurities/degradants): individual and total degradation products below ICH Q3B thresholds — a direct patient safety consideration 4. Particle size distribution (D90): controls both dissolution rate and content uniformity — an upstream physical attribute that cascades into two other CQAs
These four CQAs become the fixed "outcome variables" that every subsequent risk assessment and DoE run will be measured against — the multidimensional design space established in Stage 5 is, by definition, the region of process-parameter space where all four CQAs simultaneously meet specification.
A CQA is not simply "anything measured" — it is anything whose variability could put a patient at risk if left uncontrolled. ICH Q8(R2) frames CQA identification as an iterative, risk-based exercise that is revisited as process and product knowledge matures throughout development.
From material attributes to product CQAs
CQA identification is not limited to the finished dosage form — ICH Q8(R2) explicitly extends "critical" thinking upstream to Critical Material Attributes (CMAs) of drug substance and excipients, since a raw-material property (API particle size entering granulation, excipient moisture content, polymer molecular weight) can itself be the true root cause behind variability observed in a finished-product CQA. Mapping CQAs back to candidate CMAs early prevents a risk assessment from mis-attributing a raw-material problem to a process parameter, which would otherwise send the DoE campaign in Stage 4 chasing the wrong variable entirely.
Critical Process Parameters — Prioritizing What to Study with Ishikawa and FMEA
With the CQAs fixed, attention turns to the manufacturing process itself: which of the dozens of process inputs — temperatures, speeds, times, forces, flow rates — actually have the potential to move a CQA out of specification? Risk assessment tools borrowed from quality engineering, principally the Ishikawa (fishbone) diagram and Failure Mode and Effects Analysis (FMEA), give development teams a structured, defensible way to prioritize a short list of Critical Process Parameters (CPPs) for expensive, time-consuming formal study.
- 15–25: Candidate process inputs screened (typical unit-operation count)
- 3–5: CPPs typically retained (for formal DoE study)
- S × O × D: FMEA risk score (severity × occurrence × detectability)
- 3: CPPs selected here (Temperature, mixing speed, compression force)
Ishikawa (fishbone) diagrams — structured brainstorming of potential causes
The Ishikawa diagram organizes every plausible source of CQA variability into major categories — commonly Man, Machine, Material, Method, Measurement, Environment — branching off a central spine pointing at the CQA of concern. For a granulation-and-compression unit operation feeding a dissolution CQA, branches might include: granulator impeller speed and binder addition rate (Machine/Method), raw material particle size and moisture content (Material), operator technique in blend sampling (Man), ambient humidity during compression (Environment), and dissolution apparatus calibration drift (Measurement).
The fishbone exercise is deliberately exhaustive rather than selective at this stage — its purpose is to surface every candidate cause before any is filtered out, preventing a parameter from being prematurely dismissed because it was simply never considered. Cross-functional participation (process engineering, analytical, quality, manufacturing operators) is essential: operators often surface real-world variability sources — equipment drift, seasonal humidity swings, shift-to-shift technique differences — that a purely desk-based review would miss.
FMEA — scoring and ranking candidate parameters
Failure Mode and Effects Analysis converts the fishbone's exhaustive candidate list into a ranked, numeric priority list. For each candidate process parameter, a cross-functional team scores three factors on (typically) a 1–10 scale:
• Severity (S): how serious is the impact on the CQA if this parameter drifts out of its normal range? • Occurrence (O): how likely is that drift to happen in routine manufacturing? • Detectability (D): how likely is the drift to be caught before affecting the finished product (inverted scale — harder to detect scores higher)?
Risk Priority Number (RPN) = S × O × D. Parameters above a pre-agreed RPN threshold are designated CPPs and carried forward into formal DoE study; parameters below threshold are typically controlled by standard operating ranges and periodic verification rather than by inclusion in the design space model itself.
For this case study, temperature, mixing speed, and compression force scored highest on RPN and were designated the three CPPs to be formally mapped against the four CQAs — the multidimensional space these three parameters define is exactly what the DoE stage and the resulting design space will characterize.
Prior knowledge and mechanistic understanding inform the score
Risk scores are never assigned from a blank slate. Platform knowledge from similar products, prior development-stage experiments, published literature, and first-principles process engineering (e.g., known relationships between mixing shear and particle attrition, or between compression force and tablet porosity) all inform the severity and occurrence estimates. This prior knowledge is explicitly documented alongside the FMEA output, because a regulator reviewing the eventual design space submission will expect to see the scientific rationale — not just the numeric score — behind why a given parameter was, or was not, elevated to CPP status.
Design of Experiments — Building the Response Surface Across CPP Ranges
With CPPs prioritized, a Design of Experiments (DoE) systematically varies each CPP across a pre-defined studied range — deliberately wider than the anticipated normal operating range — while holding or randomizing other factors, and measures the resulting CQAs for every run. Structured designs such as central composite, Box-Behnken, or full/fractional factorial designs let a modest number of runs (dozens rather than thousands) characterize curvature and interaction effects across the full multidimensional parameter space, producing a fitted response-surface model that predicts CQA outcomes anywhere within the studied region.
- CCD / Box-Behnken: Common DoE structure (captures curvature, not just linear trend)
- 20–30: Typical run count (3 CPPs) (incl. center-point replicates)
- Quadratic: Response model fitted (CQA ~ f(CPP₁, CPP₂, CPP₃, interactions))
- 24: Runs completed this study (temperature × mixing speed grid shown)
Choosing the studied range and the experimental grid
Each CPP is assigned a studied range deliberately wider than its expected operating window — typically the anticipated normal operating range expanded by a safety margin on each side — so the resulting model can be trusted right up to (and slightly beyond) the eventual design space boundary rather than only at its center. A wider studied range characterizes more of the parameter space in a single campaign but requires more runs (or coarser resolution) to hold statistical power constant; a narrower range needs fewer runs but risks leaving unexplored — and therefore unusable — territory just outside it.
Each experimental run sets every CPP to a specific combination of levels (e.g., temperature 38°C / mixing speed 220 rpm / compression force 12 kN) drawn from the design matrix, manufactures a small batch or sub-batch at that setting, and tests the resulting material against all four CQAs — assay, dissolution, related substances, particle size. The "Parameter Range Studied" control in this simulation reflects exactly this trade-off: widening it spreads DoE runs across a larger region of the temperature/mixing-speed plot, characterizing more territory but needing proportionally more runs to keep coverage dense enough to trust.
Fitting the multidimensional response surface
Once every run's CQA results are collected, a regression model — typically a second-order (quadratic) polynomial including two-factor interaction and curvature terms — is fitted for each CQA as a function of the CPPs:
CQA ≈ β₀ + Σβᵢ·CPPᵢ + Σβᵢⱼ·CPPᵢ·CPPⱼ + Σβᵢᵢ·CPPᵢ²
Each fitted model is validated (lack-of-fit test, R², residual diagnostics) and then evaluated across a fine grid spanning the entire studied range. At every grid point, all four CQA models are checked simultaneously against their specification limits — a point "passes" only if every CQA prediction, together with its associated prediction uncertainty, remains inside specification. The pattern of pass/fail grid points is exactly what accumulates, run by run, on the parameter-space plot: green points denote combinations where the fitted model (confirmed by the physical run) meets every CQA; red points denote combinations where at least one CQA specification is violated.
Acceptance criteria stringency shapes the resulting boundary
The specification limits attached to each CQA — how tightly assay, dissolution, impurities, and particle size must be controlled — directly determine how large the eventual "all CQAs pass" region turns out to be. Tighter acceptance criteria (a narrower assay window, a lower impurity ceiling) shrink the region of CPP-space where every CQA model simultaneously stays inside spec, even though the underlying process behavior has not changed at all. The "Acceptance Criteria Stringency" control in this simulation reproduces that effect directly on the plotted boundary: stricter criteria pull the green/pass region inward, smaller and more conservative; looser criteria let it expand outward, closer to the full studied range.
The Design Space — ICH Q8's Multidimensional Region of Assured Quality
ICH Q8(R2) defines design space as "the multidimensional combination and interaction of input variables (e.g., material attributes) and process parameters that have been demonstrated to provide assurance of quality." Once the DoE response surfaces confirm a contiguous region of the studied CPP space where all four CQAs reliably meet specification, that region — verified, documented, and submitted in the regulatory dossier — becomes the approved design space. A smaller Normal Operating Range (NOR) is nested safely within it as the routine manufacturing setpoint window, leaving margin between everyday operation and the boundary itself.
- Q8(R2): ICH guideline defining design space ("assurance of quality")
- Not a change: Regulatory status of movement within DS (per ICH Q8/Q10 flexibility)
- Requires filing: Movement outside the design space (variation / regulatory submission)
- 100%: Space coverage verified (of studied CPP grid classified)
Why the design space is not a single "optimal" setpoint
Traditional process validation identifies a single validated setpoint per parameter (e.g., "38°C, 220 rpm, 12 kN") and treats any deviation as an excursion requiring investigation. The design space concept replaces that single point with a defensible region: any combination of temperature, mixing speed, and compression force lying inside the demonstrated boundary is understood — and regulator-accepted in advance — to reliably deliver product meeting every CQA. This is a fundamentally different regulatory object: it is a claim about an entire region of multidimensional space, backed by the mechanistic and statistical evidence generated in the DoE stage, not a claim about one favored recipe.
The Normal Operating Range nested inside the design space is where routine manufacturing actually runs day to day — narrower than the full design space, chosen to give operators margin for normal process variability (raw material lot-to-lot differences, equipment wear, seasonal humidity) without ever approaching the true boundary.
The regulatory flexibility payoff — operating vs. leaving the design space
This is the practical, commercially significant benefit that motivates the entire QbD exercise: per ICH Q8(R2) and the accompanying ICH Q10 pharmaceutical quality system, movement to any new operating point within an approved design space is not considered a regulatory change and does not require prior health-authority approval — it is documented under the firm's internal change control and pharmaceutical quality system instead. A manufacturer can shift mixing speed from 210 to 240 rpm to accommodate a new equipment train, or adjust temperature to compensate for a raw-material lot with different flow properties, without filing a variation, so long as the new point remains inside the approved boundary.
Moving outside the approved design space — into territory never demonstrated to reliably meet the CQAs — is treated as a change requiring a regulatory filing (a post-approval variation or supplement) before implementation. This asymmetry is precisely what converts the upfront investment in DoE characterization into ongoing manufacturing flexibility: continuous improvement and routine troubleshooting become possible without triggering the regulatory burden that would apply under a single-setpoint validation paradigm.
ICH Q8(R2), Annex: "Working within the design space is not considered as a change. Movement out of the design space is considered to be a change and would normally initiate a regulatory post-approval change process." This single sentence is the commercial core of the QbD design-space investment — it converts characterization work done once during development into standing manufacturing flexibility for the life of the product.
Design space verification and lifecycle maintenance
Establishing the boundary computationally from the DoE response surfaces is not the final step — regulatory guidance expects confirmatory runs at and near the proposed edge of the design space, demonstrating that the fitted model's predictions hold up under real manufacturing conditions and not merely inside the statistical model. Once approved, the design space is carried forward into the product's ongoing pharmaceutical quality system (ICH Q10): process analytical technology, continued process verification, and periodic review all feed back into whether the design space remains valid, whether the NOR should be adjusted within it, or whether new data eventually justifies petitioning to expand the boundary itself.
This simulation defines the design space for a manufacturing process based on critical quality attributes (CQAs), ensuring that product quality is maintained within specified limits.
2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install