Insights
Before You Send the Validation Protocol to the Lab
Questions early-stage companies should resolve before committing samples, budget, and time to a high-consequence study.
A validation protocol is easy to approve and expensive to unwind.
Once samples are committed, a CRO is scheduled, reagents are allocated, and the study begins, the program starts generating a formal record.
If that record answers the wrong question, the company still owns the result.
That is why some of the most valuable validation work happens before the protocol leaves the sponsor.
The objective is not to make the protocol longer.
It is to make sure the study is designed to generate evidence the company can actually use.
1. What decision will this study support?
Before discussing precision, stability, sample numbers, or acceptance criteria, state the intended decision in one sentence.
Examples might include:
- determine whether the current bioanalytical method is suitable for analysis of clinical-study samples for a defined use;
- determine whether an assay is sufficiently characterized to advance into formal validation;
- determine whether an externally developed method can be adopted, transferred, or requires additional development;
- determine whether the existing analytical evidence is adequate to support a planned regulatory discussion;
- determine whether a diagnostic assay is ready to advance into its next verification or validation stage.
“We need to validate the assay” is not a decision.
It is a category of work.
A useful protocol should make clear:
what needs to be demonstrated, why it matters, and what the team will do with the conclusion.
ICH M10 describes the objective of bioanalytical method validation as demonstrating that the method is suitable for its intended purpose.1 That principle is the right place to begin.
2. Is the method actually ready for validation?
Validation should not be used as a substitute for unfinished method development.
FDA’s M10 guidance draws this distinction explicitly: method development establishes the design, operating conditions, limitations, and suitability of the method and is intended to ensure that the method is ready for validation.1
Before finalizing the validation protocol, ask whether important features are still changing, such as:
- sample preparation;
- extraction conditions;
- critical reagents;
- analytical range;
- calibration model;
- instrument settings;
- sample-handling procedures;
- dilution strategy;
- reportable result;
- data-processing approach.
Some refinement is inevitable.
But if fundamental assay conditions are still moving, a formal validation study may end up documenting a method the company no longer intends to use.
In that situation, a focused characterization study or gap assessment may create more value than premature validation.
A useful question is:
If this validation passes, will we still want to use this exact method afterward?
If the answer is uncertain, the method may not be ready.
3. Does the study reflect the way samples will actually be analyzed?
Validation should resemble the future sample-analysis workflow closely enough that the resulting evidence is meaningful.
For M10 bioanalysis, FDA recommends that validation assessments be relevant to the actual sample-analysis workflow and that the validation matrix match the study-sample matrix, including relevant anticoagulants and additives.1
That should prompt practical questions such as:
- Is the matrix representative?
- Does the planned range cover the concentrations expected in real samples?
- Are dilution procedures representative of future use?
- Are relevant sample-handling conditions included?
- Will the same number of wells, replicates, extraction procedures, or analytical sequence be used later?
- Are the stability conditions representative of actual collection, storage, shipping, and analysis?
A validation study can be technically successful and still have limited value if it demonstrates performance under conditions that do not resemble the eventual study.
4. Are the acceptance criteria predefined—and do they answer the right question?
Acceptance criteria should be established before the results are available.
That is important both scientifically and operationally.
But there are two separate questions:
Are the criteria consistent with applicable guidance or justified alternatives?
and
Are they appropriate to the method and intended use?
A number copied from a CRO template is not automatically a scientifically justified criterion.
Nor is a criterion automatically better because it is more stringent.
Overly permissive criteria can allow a study to “pass” while leaving the method unsuitable for its intended purpose.
Overly restrictive criteria can create avoidable failures, repeats, or additional work without materially improving the usefulness of the method.
The goal is not the tightest criterion.
The goal is a predefined and scientifically justified criterion that supports the intended decision.
For conventional M10 chromatography and ligand-binding applications, the guidance provides specific expectations for many performance characteristics and analytical-run acceptance rules.1 Biomarker assays may require a fit-for-purpose interpretation depending on intended use and platform.2
5. Separate validation acceptance from analytical-run acceptance
This distinction deserves more attention than it usually gets.
A validation study may contain multiple analytical runs.
Each run can have its own predefined requirements for:
- calibration standards;
- QCs;
- blanks;
- system suitability;
- other platform-specific controls.
Those criteria determine whether the analytical run is acceptable.
The validation protocol also contains broader criteria used to determine whether a particular validation parameter—and ultimately the method—meets the study objective.
These are related, but they are not the same thing.
M10 explicitly requires criteria for acceptance or rejection of analytical runs to be defined in the protocol, study plan, or SOP before analysis.1
A well-written protocol should therefore make it obvious:
- what causes a run to pass or fail;
- what causes an individual validation parameter to pass or fail;
- and how those outcomes contribute to the overall validation conclusion.
Without that separation, a team can end up debating the meaning of a failed run after the study is already underway.
6. What happens when the study does not go according to plan?
Something unexpected will eventually happen.
A run fails.
An instrument malfunctions.
A preparation error occurs.
A sample is lost.
A result falls outside the calibration range.
A deviation affects one subset of the data.
The protocol does not need to predict every possible event.
But it should establish the framework for responding to them.
At minimum, define how unexpected events will be:
identified
→ documented
→ investigated
→ assessed for impact
→ resolved
M10 expects contemporaneous documentation of deviations and unexpected events, investigation where appropriate, and assessment of their impact on study results.1
This is not administrative housekeeping.
It protects the interpretability of the study.
7. When can a sample be repeated or reanalyzed?
This is one of the easiest areas to handle poorly if the rules are not established in advance.
The protocol should address:
- reasons permitting reanalysis;
- reasons permitting reinjection;
- how many repeats are allowed;
- who authorizes the action;
- which result will ultimately be reported;
- how the original and repeat results will be documented.
M10 specifically recommends that reasons for study-sample reanalysis and the decision criteria for selecting the reportable value be predefined before analysis begins.1
The principle is simple:
Do not create repeat rules after seeing whether the first result is convenient.
A repeat should answer a defined technical problem—not function as a way to search for a preferred value.
8. Are the sample plan and range realistic?
The sample plan should be driven by the future use of the method.
Ask:
- Are the concentrations representative of what the method will actually encounter?
- Does the validation range cover the region where decisions will be made?
- Are the low and high ends sufficiently challenged?
- Is the matrix representative?
- Are relevant disease-state or endogenous-background effects considered?
- Are sufficient independent runs included to characterize reproducibility?
- Do analyst, reagent, instrument, day, or lot effects need to be represented?
For biomarker assays, this can be especially important because endogenous analyte, parallelism, matrix effects, and clinically relevant concentration ranges may not behave like conventional drug bioanalysis.
The study should test the analytical risks that matter in actual use—not simply satisfy a familiar template.
9. Who owns the scientific decisions?
A CRO or external laboratory may write the first draft of the protocol.
That can be completely reasonable.
It may have substantially more platform-specific experience than the sponsor.
But outsourcing execution should not transfer ownership of the development question.
The sponsor should still understand:
- what the study is intended to prove;
- why the experiments were selected;
- why the criteria are appropriate;
- what constitutes a meaningful deviation;
- when a repeat is justified;
- what data are necessary;
- and what conclusion the final package must support.
This is particularly important when the vendor’s standard workflow and the sponsor’s intended use are not perfectly aligned.
A CRO can execute the study.
The sponsor still owns the scientific intent.
10. Who reviews the raw and processed data?
“CRO will provide a final report” is not a sufficient data-review plan.
Define who will review:
- calibration performance;
- QC performance;
- chromatograms or equivalent raw analytical outputs;
- integration or processing decisions;
- calculations;
- failed runs;
- excluded data;
- repeats and reanalysis;
- deviations;
- investigations.
The depth of sponsor review should be appropriate to the importance of the study and the contractual arrangement.
But someone on behalf of the sponsor should be capable of understanding how the final conclusions were produced.
This is especially important when the resulting data may later support a regulatory submission or another high-consequence development decision.
11. What data and records will the sponsor actually receive?
Do not assume that “data package” means the same thing to the sponsor and the vendor.
Before execution, define the expected deliverables.
Depending on the program, these may include:
- validation protocol and amendments;
- approved methods or SOPs;
- calibration and QC results;
- raw or source data;
- processed datasets;
- chromatograms or equivalent analytical output;
- calculation files;
- run summaries;
- sample-accountability records;
- deviations;
- investigation records;
- repeat/reanalysis records;
- validation report.
M10 devotes a substantial section to documentation for validation and bioanalytical reporting and expects records sufficient to describe deviations, investigations, repeat analyses, and the analytical basis for the reported results.1
A useful thought experiment is:
If the CRO disappeared two years from now, could we still understand what happened and why the conclusion was reached?
The answer should be appropriate to the significance of the study.
12. What must the final report actually establish?
I like to outline the validation report before the study begins.
Not because the conclusions are predetermined.
Because the structure of the final report reveals what evidence needs to be generated.
At a minimum, the report should allow a qualified reviewer to understand:
- what method was evaluated;
- what its intended purpose was;
- what studies were performed;
- what predefined criteria applied;
- what results were obtained;
- what deviations or investigations occurred;
- what limitations remain;
- and what conclusion the evidence supports.
If the protocol does not generate enough information to populate those sections, the study design may still have a gap.
13. Can someone trace the conclusion back to the requirement?
This is the final test.
For each important validation claim, a reviewer should be able to move through something like:
Intended use
→ analytical requirement
→ risk
→ validation experiment
→ acceptance criterion
→ result
→ conclusion
If one of those links is missing, the study may generate data without generating a complete argument.
This is why documentation matters before—not after—the study.
The purpose is not more paperwork.
It is preserving the reasoning that makes the evidence useful.
A practical pre-execution checklist
Before authorizing a high-consequence validation study, confirm that:
- The intended use and decision are explicit.
- The method is sufficiently developed and stable to validate.
- The study reflects the future sample-analysis workflow.
- Validation and analytical-run acceptance criteria are predefined.
- The sample matrix, range, and conditions are representative.
- Deviation, repeat, reanalysis, and investigation rules are defined.
- Sponsor and CRO decision responsibilities are clear.
- Raw-data and data-review expectations are established.
- The required deliverables are specified in the vendor scope.
- The final report can trace the evidence back to the intended requirement.
If several of those remain unresolved, the most efficient next step may not be starting validation.
It may be closing the gaps first.
The cost of preparation versus the cost of repetition
This is not an argument for slowing development unnecessarily.
It is an argument for putting structured attention in the least expensive part of the timeline.
Before the samples are consumed.
Before the CRO change order.
Before the protocol deviation.
Before someone asks why the acceptance criterion was selected.
Before a regulatory reviewer asks for a record the sponsor never requested.
A short period of disciplined review can be much less expensive than repeating a study whose technical execution was good but whose design did not support the intended decision.
The bottom line
A validation protocol is not simply a set of instructions for the laboratory.
It is a predefined agreement about the evidence the program intends to generate and how that evidence will be interpreted.
Before it goes to the lab, the team should know:
what needs to be shown,
why it matters,
what constitutes acceptable evidence,
what happens when execution deviates from plan,
and
what decision the completed study will support.
The goal is not to make validation more complicated.
It is to make the expensive part of validation easier to defend.
References
- U.S. Food and Drug Administration. M10 Bioanalytical Method Validation and Study Sample Analysis: Guidance for Industry. November 2022.
- U.S. Food and Drug Administration. Bioanalytical Method Validation for Biomarkers: Guidance for Industry. April 2026.