Validation Artifact Mapping

Modified on Wed, 12 Aug at 3:19 PM

Understanding IQ/OQ/PQ

How Isolocity’s Documentation Maps to Your Validation Requirements


If your quality system or auditor requires Installation Qualification (IQ), Operational Qualification (OQ), and Performance Qualification (PQ) evidence for Isolocity, this guide explains what each of those terms means, what we provide as your software vendor, and what remains your responsibility as the customer.

Isolocity is a cloud-based (SaaS) platform;  we host, maintain, and secure the infrastructure your system runs on, rather than installing software on your local servers. This is an important distinction for validation purposes: it's what allows us to provide strong, centralized DQ and IQ evidence on your behalf (since the environment is the same for every customer), while OQ and PQ remain tied to how you specifically configure and use the system.

As a SaaS vendor, we can provide strong evidence for Design Qualification (DQ) and Installation Qualification (IQ); documentation covering how our system was designed, secured, and hosted. Operational Qualification (OQ) and Performance Qualification (PQ), however, must ultimately be executed and owned by you, the customer, because they validate that your specific configuration, your workflows, and your data behave as intended within your regulated process. We provide the tools, templates, and test suite to make that process fast and straightforward but we cannot validate your use of the system on your behalf.


The Four Qualification Stages, in Plain Language

Stage

What It Answers

Typically Owned By

Example Evidence

DQ

Was the system designed to meet the requirements?

Vendor

Architecture docs, security design, compliance certifications

IQ

Was the system installed/configured correctly in its environment?

Vendor

Cloud hosting, backup, disaster recovery, deployment records

OQ

Does the system operate correctly across its intended functions?

Customer (vendor-supported)

Test execution using the Isolocity Validation Test Suite

PQ

Does the system perform as intended in your real-world use?

Customer

Your UAT protocol/report, live-use evidence, training records


Artifacts We Provide — DQ & IQ Evidence

These documents demonstrate that Isolocity was designed and is hosted, secured, and maintained appropriately. You can submit these directly to satisfy DQ and IQ requirements.

Artifact

DQ

IQ

Notes

2025 Isolocity SOC 2 Type 2 Internal Audit Report

Internal controls & environment evidence

ISO 27001 Certification

Internal controls & environment evidence

Annex 11 Software Validation

Validation approach / system design evidence

AWS Security Practices, Features and Policies

Design & infrastructure evidence

Business Continuity Plan

 

IQ evidence for environment resilience

Data Residency and Hosting

 

Environment documentation

Disaster Recovery Plan

 

IQ evidence for recovery processes

FDA 21 CFR Part 11 Compliance

Regulatory design & environment support

INS_36 (Backup Validation)

 

IQ evidence for backup procedures

INS_65 (Deployment Validation)

 

IQ evidence for deployment & environment


Tools We Provide — To Support Your OQ Execution

OQ confirms the system operates correctly across its functions in your environment. We can't execute this on your behalf, but we provide a ready-made test suite so your team can run OQ efficiently rather than writing test cases from scratch.

Artifact

DQ

OQ

Notes

Isolocity Validation Test Suite

Provides testable requirements (DQ) and guides OQ execution; run and documented by you


What You'll Need to Generate — PQ Evidence

PQ confirms Isolocity performs as intended within your actual processes, data, and users; something only you can demonstrate. These artifacts are typically produced by your team, using the system we provide:

      User Acceptance Testing (UAT) protocol and report, executed in your production or validated environment

      Evidence of live-use performance under your standard operating procedures

      End-user training records

      Ongoing performance monitoring or periodic review records, where applicable


Questions?

If you'd like help interpreting this mapping for your specific audit or quality system, please contact our support team (support@isolocity.com).  Copies of the artifacts listed are available on our trust portal (trust.isolocity.com).

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article