Veritas Quality Consultants veritasqualityconsultants.com →
Veritas Quality Consultants · Training Academy

Related Substances and Unknown Impurities

Arc B — characterisation, and why it matters. The historical record, mutagenic impurities, nitrosamines, method design, and the adjacent elemental and solvent frameworks. Modules B1 to B5.

Arc B · 5 modules~85 minutes6 figures33 knowledge-check questions

What is in Arc B

  1. The case library — six incidents, 1937 to 2022, and why each escaped detection
  2. Structural alerts and mutagenic impurities — ICH M7, the TTC, and the point where percentages stop working
  3. Nitrosamines — the worked modern example, and the limits set in nanograms
  4. Finding what you do not know is there — specificity, orthogonality, and the detector's blind spot
  5. The adjacent frameworks — elemental impurities and residual solvents, and the logic that unifies all of it

Each module ends with a knowledge check. A cumulative assessment covering all five modules is issued separately.

A note on what this arc does and does not do

Arc B deals with impurities that have killed people. It shows what the alerting structures are, why they form under ordinary manufacturing conditions, and how they are detected and controlled. It gives no synthesis routes, no conditions optimised to produce these species, and no discussion of evading detection. The whole purpose of the material is control.

It is also careful with numbers. Several of these incidents are surrounded by casualty figures that circulate widely and cannot be traced to the body they are attributed to. Where that is the case this course says so, and quotes only what the named source actually published. A regulator's inability to attribute a death is itself a finding worth teaching.

Module B1

The case library

Six incidents across eighty-eight years. Every one involved a substance structurally close to something benign, and every one was invisible to the method in use at the time.

The argument of this course is contained in one observation about these six cases: in five of the six, the analytical test was working correctly. It ran as validated, it reported honestly, and it answered the question it was designed to answer. The question was the wrong one.

Figure B1.1 Six impurity incidents and the reason each escaped detection A table of six historical incidents from 1937 to 2022. For each, the impurity involved and the category of detection failure. In five of the six the analytical test was working correctly but was not looking for the substance that was present. WHY EACH ONE WAS MISSED YEAR CASE IMPURITY THE FAILURE 1937 Elixir Sulfanilamide Diethylene glycol No test existed No safety testing was required. The control lab checked flavour, appearance and fragrance. 1989 L-tryptophan “Peak 97” (DTAA) It WAS seen — unnamed Present at about 0.01%. Visible as a chromatographic peak, identified about a year later. 2007 Viracept Ethyl mesilate Right test, wrong point The acid was tested for EMS on receipt, but not after transfer into the hold tank. 2008 Heparin Oversulfated chondroitin sulfate Test it could satisfy The adulterant is itself anticoagulant, so it substituted for heparin in the clotting assay. 2018 Sartans, ranitidine Nitrosamines Not what the method sought Routine purity, identity and known-impurity tests are unlikely to detect nitrosamines. 2022 Paediatric syrups Diethylene glycol again Test that did not exclude it An identity test confirming glycerin is present does not exclude DEG, and certificates replaced testing. In five of the six the test was doing exactly what it was designed to do. Only in 1989 did the impurity appear in the chromatogram — and it still took about a year to name.
A specification is a description of what you looked for. Five of these six failures were not failures of execution — the method ran correctly and reported honestly on the wrong question.

B1.1  1937 — Elixir Sulfanilamide, and the birth of the modern FDA

The S. E. Massengill Company of Bristol, Tennessee dissolved sulfanilamide in diethylene glycol to make a liquid preparation. FDA's own account of what the laboratory did is the most instructive sentence in the whole episode:

“The company control lab tested the mixture for flavor, appearance, and fragrance and found it satisfactory.” “The new formulation had not been tested for toxicity.”FDA, Elixir Sulfanilamide Tragedy. source

There was no analytical failure, because there was no analytical requirement. Under the Food and Drugs Act of 1906 nothing obliged a manufacturer to establish that a product was safe before selling it. FDA seized the product on the only ground available — misbranding, because the word “elixir” implied an alcoholic solution and this was not one.

Requirement FDA publishes the toll two ways, and both are citable: its narrative history says the drug “was responsible for the deaths of more than 100 people in 15 states”, while its regulatory milestones document states it “kills 107 persons, many of whom are children”. The consequence is not disputed: the incident “hastened final enactment in 1938 of the Federal Food, Drug, and Cosmetic Act, the statute that today remains the basis for FDA regulation of these products.”

Everything in this course descends from that autumn. The requirement to establish safety before marketing exists because a solvent was chosen for its taste.

B1.2  1989 — the unnamed peak that was the whole story

This is the case that belongs at the centre of any course about unknown peaks, because the killer was an unknown peak. Users of L-tryptophan supplements developed eosinophilia-myalgia syndrome. CDC's investigators found the signal exactly where this course says to look:

“Several HPLC peaks (called peaks 97, 100, and 200) were identified that were predictive of case-associated LT lots.”CDC, MMWR 1990;39(34), 31 August 1990. source

Peak 97 was named by its retention index because nobody knew what it was. Structure came later, from NMR and high-resolution mass spectrometry: an exact mass of 434.2020, a molecular formula of C24H26N4O4 — “two tryptophan molecules and an additional C2H2” — resolving to the di-L-tryptophan aminal of acetaldehyde. CDC estimated its concentration at about 0.01% in a case-associated lot.

Three corrections to the version of this story you will usually hear

The compound has three names and none of them is official. CDC used “peak 97”. Other laboratories called the same substance “Peak E” and “UV-5”. It is also written as DTAA and as 1,1'-ethylidenebis(L-tryptophan) or EBT. These are synonyms produced by different groups working in parallel on an unidentified peak — which is itself a good illustration of what happens before a compound has a name.

The casualty figures usually quoted could not be verified. The highest count published by CDC that we could confirm is 1,536 cases and 27 deaths reported as of 24 August 1990. Higher totals circulate widely. This course quotes CDC's.

Causation was never established by a regulator. CDC's own language stayed conditional — some lots “could contain a contaminant that is causally associated with EMS” — and a substantial literature published in 1996 contests the epidemiology, partly on the basis of cases among people who had not taken the product. Peak 97 remains an association supported by animal and in-vitro work, not a finding. Teach the uncertainty; it is more useful than a false certainty, and it is what an inspector would expect a competent scientist to know.

Practice The operational lesson stands regardless of the causation debate. An impurity at roughly 0.01% — below the reporting threshold for many products — was visible in routine chromatograms, went unnamed, and took about a year to identify after the outbreak began. The peak was never hidden. It was simply never asked about.

B1.3  2007 — Viracept, and the right test at the wrong point

Nelfinavir is formulated as a mesylate salt, using methanesulfonic acid. Ethanol was used to clean a hold tank. EMA's assessment report gives the mechanism with unusual candour:

“Following non-routine maintenance the hold tank was cleaned according to the SOP procedure (i.e. with ethanol) but, crucially, no drying was performed.” “The residual ethanol left in the tank reacted with MSA to form high levels of EMS contaminant.”EMA, Viracept EPAR assessment report lifting the suspension. source

Ethyl mesilate is an alkylating agent and a known genotoxic substance. Levels rose from “between 4 and 10 ppm” in 2004 to “up to 2300 ppm” in the January 2007 campaign, against a proposed safety threshold of 0.6 ppm.

Now the sentence that makes this case worth an hour of anyone's time:

“MSA is routinely tested on receipt from the supplier for its EMS content but not after transfer into the hold tank.”EMA, Viracept EPAR assessment report. source

The test existed. It was validated. It was specific for exactly the right compound. It was applied at the wrong point in the process. Practice A control strategy is not a list of tests; it is a set of tests attached to the points where the hazard can enter. Move the hazard downstream of the test and the test becomes decorative.

Viracept is also this course's most useful counter-example. Roche recalled the product across the EU on 6 June 2007, the marketing authorisation was suspended, and the suspension was lifted on 20 September 2007. By July 2008 EMA concluded there was no increased risk of cancer for patients who had taken the contaminated product. A major genotoxic impurity incident, a full regulatory response, and no verified clinical injury. Not every impurity event ends in harm — and a system that only acts when harm is proven is a system acting too late.

B1.4  2008 — heparin, and an assay the adulterant could pass

Oversulfated chondroitin sulfate is a semi-synthetic glycosaminoglycan. Heparin is a natural one. Both are highly sulfated polyanions, which is precisely why the compendial tests of the day could not separate them:

“Given the nature of this contaminant, traditional screening tests cannot differentiate between affected and unaffected lots.”Guerrini M, Beccati D, Shriver Z, et al., Nature Biotechnology 26(6), 2008. source

USP's own retrospective is blunter: the adulterant “was capable of meeting antiquated tests, including the USP clotting test for potency.” The mechanism matters. The monograph potency assay was clotting-time based, and OSCS is itself anticoagulant — so it did not dilute the measured potency, it substituted for heparin in the assay. A cheaper material that reads as the expensive one is the definition of an economically motivated adulterant.

What actually found it was proton NMR and capillary electrophoresis — techniques outside the monograph — with a diagnostic OSCS signal “at around 2.15 p.p.m.” FDA posted both screening methods on 6 March 2008 and named the contaminant on 17 March.

On the death toll — and why the honest answer is better teaching

Figures in the range of 80 to 250 deaths circulate freely and are routinely attributed to FDA. No such FDA figure could be found. The authoritative US government account is GAO-11-95, which records the opposite:

“FDA was unable to determine if any of the adverse events or deaths were linked to contaminated heparin because of data limitations and confounding factors regarding the individual patients” — in part because “the lot numbers of the heparin that these patients received were not reported in the AERS reports.”

What GAO does report FDA counting: 176 adverse events in February 2008 against 13 in February 2007, and analysis of 94 death reports. CDC separately confirmed 65 confirmed or probable cases of acute allergic-type reactions in dialysis patients across 12 states.

The traceability failure is the lesson. Lot numbers were missing from the adverse event reports, so the link between a specific patient and a specific contaminated lot could not be made. Everything a quality system does about batch traceability exists for the moment when somebody has to answer this question — and here, it could not be answered.

Requirement USP revised the monograph in stages: capillary electrophoresis and ¹H-NMR identity tests became official on 18 June 2008; from 1 October 2009 potency moved off the clotting assay onto antithrombin-mediated inhibition of factor Xa and factor IIa; a 2014 revision added an explicit “Absence of Oversulfated Chondroitin Sulfate” test and molecular-weight controls.

B1.5  2018 onward — nitrosamines

Treated in full in Module B3. Its place in this library is as the case where FDA stated the detection problem as a general principle: “Typical routine tests (e.g., high performance liquid chromatography) for API purity, identity, and known impurities are unlikely to detect the presence of nitrosamine impurities.”

B1.6  2021 onward — azido impurities, the second wave

Sartans again, different chemistry. The tetrazole ring in valsartan, losartan, irbesartan, candesartan and olmesartan is built by cycloaddition of an azide onto a nitrile. Residual azide can then displace a benzylic halide, producing AZBT — azidomethyl-biphenyl-tetrazole. Swissmedic states the origin plainly: AZBT “can form as a result of a starting material (azide) that is used to assemble a specific structural element (tetrazole ring)”.

Structurally it is the drug's own tetrazole fragment carrying an azidomethyl group — a process-related analogue of the API, which is why it co-elutes closely and why dedicated LC-MS/MS methods had to be built for it. EDQM issued advisories on 29 April and 29 September 2021; Health Canada ran recalls through 2021; Swissmedic had begun withdrawing batches in November 2020.

Practice The teaching point is that the nitrosamine episode was not a one-off. The same class of manufacturers, the same drug family, a different reagent, and a second mutagenic impurity class nobody was looking for — three years later. The playbook built for nitrosamines got reused, which is the argument for treating it as a template rather than an incident response.

B1.7  2022 to 2025 — diethylene glycol, again

Eighty-five years after Elixir Sulfanilamide, the same molecule, in paediatric syrups. WHO issued a series of Medical Product Alerts covering The Gambia, Indonesia, Uzbekistan, Cambodia, the Marshall Islands and Micronesia, Cameroon, Iraq, the Maldives, Pakistan, Belize, Fiji, Lao PDR and India. Contamination levels published in those alerts include DEG at 28.6% in one syrup, EG at 2.1% in another, and DEG at 48.6% w/v in a 2025 alert — against a limit of not more than 0.10%.

FigurePublished by
“more than 300 fatalities in three of these countries”, across “at least seven countries”, “most…under the age of five”WHO, 23 January 2023
The Gambia: “78 reported cases with 66 confirmed deaths”, July–September 2022WHO, reporting The Gambia's Ministry of Health
Indonesia and Uzbekistan: “a further 268 reported deaths”WHO / UNODC, 24 July 2025
“at least 25 documented incidents of excipient contamination…more than 1300 deaths worldwide” over ninety yearsWHO / UNODC, 24 July 2025

None of the WHO alerts themselves contains a death figure. Every number above belongs to the body named beside it, and this course does not merge them. A frequently quoted standalone Uzbekistan figure could not be verified — WHO publishes Indonesia and Uzbekistan only as a combined total.

Requirement FDA's response was the May 2023 guidance requiring specific identity testing of glycerin, propylene glycol, maltitol solution, hydrogenated starch hydrolysate, sorbitol solution and other high-risk components for DEG and EG, resting on 21 CFR 211.84. The failure mode it closes is the one from Arc A: an identity test that confirms the declared substance is present without excluding the lethal analogue, plus reliance on supplier certificates in place of testing.

Enforcement followed: warning letters to Zhao Qing Longda Biotechnology (September 2023), Dextrum Laboratories (December 2023), Glicerinas Industriales (January 2024), Bell International Laboratories (February 2024) and Landy International (June 2024), all citing DEG and EG testing failures.

Knowledge check

Module B1 — the case library

Seven questions.


Module B2

Structural alerts and mutagenic impurities

Where the percentage framework of Arc A stops working, and an entirely different unit takes over.

A structural alert is a substructure statistically associated with DNA reactivity — an aromatic nitro group, an epoxide, an alkyl halide, an N-nitroso group, an aromatic amine. It is not a prediction that a molecule is mutagenic. It is a reason to stop treating it as ordinary.

B2.1  ICH M7 and the threshold of toxicological concern

Requirement ICH M7(R2), Assessment and Control of DNA Reactive (Mutagenic) Impurities in Pharmaceuticals to Limit Potential Carcinogenic Risk, reached Step 4 on 3 April 2023 and was adopted by FDA in July 2023. It replaces the percentage thresholds with an absolute daily intake: a threshold of toxicological concern of 1.5 µg/day for lifetime exposure, corresponding to a theoretical one-in-100,000 excess lifetime cancer risk.

Figure B2.1 The five ICH M7 impurity classes and the less-than-lifetime acceptable intake staircase Upper panel: the five M7 classes with the control approach for each. Lower panel: a bar chart of acceptable daily intake against treatment duration, falling from 120 micrograms per day for one month or less to 1.5 micrograms per day for lifetime exposure. CLASSIFICATION — ICH M7(R2) TABLE 1 1 Known mutagenic carcinogens Compound-specific limit 2 Known mutagens, carcinogenic potential unknown TTC-based limit 3 Alerting structure unrelated to the drug substance, no data TTC-based limit, or test it 4 Alerting structure shared with a drug substance that tested negative Treat as non-mutagenic 5 No structural alert, or data showing no mutagenicity Treat as non-mutagenic ACCEPTABLE INTAKE BY DURATION OF TREATMENT 120 ≤ 1 month 20 > 1–12 months 10 > 1–10 years 1.5 > 10 years to lifetime µg/day The default TTC is the lifetime figure: 1.5 µg/day, a 1 in 100,000 excess lifetime cancer risk. Classes 1, 2 and 3 are controlled; Classes 4 and 5 are treated as ordinary impurities under Q3A/Q3B.
M7 replaces the percentage framework with an absolute daily intake. Note that the staircase is about duration of exposure, not dose — a clinical-trial impurity limit and a marketed-product limit differ by up to eighty-fold for the same molecule.

Note what the staircase varies. It is not dose — it is duration of exposure. The same impurity in the same molecule is permitted at 120 µg/day for a one-month clinical study and 1.5 µg/day in a marketed chronic medicine: an eightyfold difference driven entirely by how long a patient is exposed. Practice This is why an impurity limit agreed for a Phase I supply is not a precedent for the commercial specification, and why teams that assume otherwise get a surprise late in development.

B2.2  How far below the ordinary threshold this sits

Figure B2.2 The M7 threshold of toxicological concern compared with the Q3A identification threshold at five doses For each of five maximum daily doses, the ICH Q3A identification threshold expressed as a percentage is compared with the M7 threshold of toxicological concern of 1.5 micrograms per day expressed as a percentage of the same dose. The ratio between them grows with dose. Maximum daily dose 5 mg 50 mg 500 mg 1.5 g 2.5 g Ordinary impurity Q3A(R2) identification 0.1000% 0.1000% 0.1000% 0.0667% 0.0500% Mutagenic impurity M7 TTC, 1.5 µg/day 0.0300% 0.0030% 0.00030% 0.00010% 0.00006% How much stricter ×3 ×33 ×333 ×667 ×833 Above a dose of about 1.5 mg/day the mutagenic limit is the stricter of the two, and by 2.5 g/day it is 833 times stricter than the threshold an ordinary impurity would face. Applying the percentage tables to a mutagenic impurity produces a limit that is comfortably met and completely wrong.
The same molecule, judged two ways. The gap is not a refinement — it is three orders of magnitude at ordinary doses, and it widens as dose rises.

The crossover is at a dose of 1.5 mg/day. Below that, the ordinary Q3A identification threshold is the stricter of the two. Above it — which is to say, for almost every product — the mutagenic limit governs, and the gap widens with dose: ×3 at 5 mg/day, ×333 at 500 mg/day, ×833 at 2.5 g/day.

That is the practical meaning of “the percentage tables are the wrong tool”. An impurity at 0.05% in a 500 mg/day product is comfortably below every Q3A threshold and is 167 times over the mutagenic limit.

B2.3  The five classes

Requirement M7 sorts impurities into five classes, shown in Figure B2.1. The distinction that does the most work is between Class 3 and Class 4. Class 3 is an alerting structure unrelated to the drug substance, with no mutagenicity data — controlled at the TTC, or tested. Class 4 is an alerting structure shared with the drug substance, where the drug substance itself has been tested and found non-mutagenic — and is therefore treated as an ordinary impurity.

The logic is that if the parent carries the same substructure and is not mutagenic, the substructure is not driving mutagenicity in this chemical series. It is a genuinely useful argument and it is frequently the difference between a routine control and an expensive one.

B2.4  Two models, and why one is not enough

Requirement M7 is explicit about computational assessment:

“Two (Q)SAR prediction methodologies that complement each other should be applied. One methodology should be expert rule-based and the second methodology should be statistical-based.”ICH M7(R2), Step 4, 3 April 2023. source

The two families work differently on purpose. Expert rule-based systems encode human-curated structural alerts and reasoning — Derek Nexus is the dominant example, with ToxTree and Leadscope Genetox Expert Alerts also in use. Statistical systems learn from training-set data — Sarah Nexus, CASE Ultra, Leadscope Model Applier. Requiring one of each is a deliberate guard against the characteristic failure of either: a rule base is blind to what nobody has written a rule for, and a statistical model is unreliable outside its training domain.

Requirement The absence of alerts from both is sufficient to conclude no mutagenic concern and place the impurity in Class 5. But Practice expert review is not optional in practice — where the two models disagree, or where a prediction falls outside a model's applicability domain, a documented human assessment is what makes the conclusion defensible. A pair of software outputs stapled to a submission is not an assessment.

B2.5  The cohort of concern

Requirement M7 carves out three classes of compound from the generic TTC entirely: aflatoxin-like, N-nitroso, and alkyl-azoxy compounds. These require compound-specific assessment at substantially lower intakes. The 1.5 µg/day figure does not apply to them, and applying it is a serious error — nitrosamine limits are roughly four orders of magnitude below it.

Worth stating clearly, because it is widely misremembered: M7(R2) added nothing nitrosamine-specific. Its R2 content is seven new compound-specific monographs — acetaldehyde, 1,2-dibromoethane, ethyl bromide, epichlorohydrin, formaldehyde, styrene and vinyl acetate, none of them a nitrosamine — plus a reclassification of HIV treatment duration into the lifetime band. All nitrosamine limits live in regional FDA and EMA documents, not in ICH. An ICH addendum is in concept-paper stage with Step 4 projected for 2030.

B2.6  What M7 says about products already on the market

This is the only guideline text anywhere that addresses a new impurity found in an approved product, and it is deliberately narrow:

“Application of this guideline may be warranted to marketed products if there is specific cause for concern… a newly discovered impurity that is a known Class 1 or Class 2 mutagen that is present in a marketed product could also be a cause for concern.”ICH M7(R2), section 4.4. source

Read the default carefully. Finding a new impurity in a legacy product is not, by itself, cause for action. The bar is a specific cause for concern, and the worked example given is a known Class 1 or Class 2 mutagen. Arc D returns to this sentence, because it is the entire published answer to a question that is about to get much larger.

Knowledge check

Module B2 — mutagenic impurities

Seven questions, two requiring a calculation.


Module B3

Nitrosamines

The modern worked example: a class of impurity that had been present for years, was invisible to routine testing, and reopened the entire approved portfolio.

In July 2018 valsartan was recalled worldwide. The impurity was N-nitrosodimethylamine, in active ingredient from Zhejiang Huahai, and it traced to a process change made in November 2011 to improve yield and lower cost. Seven years elapsed.

B3.1  Why nothing found it

FDA's guidance states the general problem, and it is the sentence to remember from this module:

“Typical routine tests (e.g., high performance liquid chromatography) for API purity, identity, and known impurities are unlikely to detect the presence of nitrosamine impurities.”FDA, Control of Nitrosamine Impurities in Human Drugs, Revision 2, September 2024. source

Three reasons compound. Nitrosamines are small, often volatile, and poorly retained on a reversed-phase column designed around the drug substance. They absorb weakly where the drug substance is monitored. And the levels that matter are three to four orders of magnitude below an ordinary impurity threshold — a region an HPLC-UV method has no reason to reach. Detection requires LC-MS/MS, GC-MS/MS, or LC-HRMS.

And, as Arc A recorded, at Huahai the peak was in fact visible in residual solvent chromatograms and was “considered…to be noise”.

B3.2  The limits, and the unit change

Figure B3.1 Nitrosamine acceptable intake limits and the five carcinogenic potency categories Left: acceptable intake limits in nanograms per day for six named nitrosamines. Right: the five potency categories of the carcinogenic potency categorisation approach, with FDA and EMA limits, which differ only in category one. NAMED NITROSAMINES — FDA ACCEPTABLE INTAKE NDMA 96 ng/day NMBA 96 ng/day NDEA 26.5 ng/day NMPA 26.5 ng/day NIPEA 26.5 ng/day NDIPA 26.5 ng/day CPCA POTENCY CATEGORIES Category FDA EMA 1 26.5 18 they diverge 2 100 100 3 400 400 4 1500 1500 5 1500 1500 ng/day. Categories 2–5 are harmonised. Potency Score = α-Hydrogen Score + Deactivating Feature Score + Activating Feature Score Fewer or more hindered α-hydrogens means a lower predicted potency, because α-hydroxylation is the activating step — so a higher score permits a higher intake. This is a regulator using a structure-based model to set an operative limit where no compound-specific carcinogenicity data exists. The Category 1 divergence is real and it bites: a globally marketed product with a Category 1 NDSRI faces 18 ng/day in Europe and 26.5 ng/day in the United States — a limit that is stricter abroad than at home. Sources: FDA NDSRI guidance (Aug 2023) and CDER AI limits page; EMA Appendix 2, EMA/451665/2023.
Nitrosamine limits are set in nanograms per day. Against those, a percentage threshold is not merely the wrong number — it is the wrong unit.

Requirement Acceptable intakes for named nitrosamines are set in nanograms per day: NDMA and NMBA at 96 ng/day; NDEA, NMPA, NIPEA and NDIPA at 26.5 ng/day. For scale, FDA found NDMA at up to 20.19 µg per tablet in recalled valsartan — roughly 210 times the daily limit in a single tablet.

Where no compound-specific carcinogenicity data exists — which is the normal situation for a nitrosamine drug substance-related impurity, an NDSRI formed from the drug's own amine — the limit is assigned by the Carcinogenic Potency Categorisation Approach. FDA describes the CPCA as “a categorical human expert rule-based structure-activity relationship model that predicts the carcinogenic potency of an N-nitrosamine compound and assigns it to 1 of 5 potency categories, each with a corresponding acceptable intake (AI) limit.”

The scoring is structural: Potency Score = α-Hydrogen Score + Deactivating Feature Score + Activating Feature Score. Because α-hydroxylation is the metabolic activating step, fewer or more hindered α-hydrogens mean lower predicted potency and a higher permitted intake.

Requirement Category 1 diverges between FDA and EMA — 26.5 ng/day against 18 ng/day. The framework is harmonised; the anchor value is not. A product marketed on both sides of the Atlantic with a Category 1 NDSRI faces a stricter European limit, and a control strategy built to the US number will not satisfy the EU.

B3.3  Two episodes worth knowing in detail

Ranitidine — the impurity that grows in the product

Mechanistically unlike the sartans. FDA's testing “confirmed that NDMA levels increase in ranitidine even under normal storage conditions”, that levels rise “significantly in samples stored at higher temperatures”, and that “the older a ranitidine product is…the greater the level of NDMA.” On 1 April 2020 FDA requested removal of all ranitidine products from the US market.

Practice The distinction to carry away: a process-formed nitrosamine is fixed at manufacture and can be controlled by the process. A nitrosamine that forms on storage is a degradation problem, and no amount of release testing will control it. Which one you have determines whether the answer is a route change or a shelf-life change.

Varenicline — a regulator trading two risks in public

N-nitroso-varenicline is an NDSRI, formed from the drug's own structure. The sequence is the clearest published example of a regulator balancing impurity risk against supply risk:

DateAction
2 July 2021Initial recall, nine lots
16 July 2021FDA will not object to distribution above the 37 ng/day limit but below an interim limit of 185 ng/day
17 September 2021Pfizer recalls all lots of Chantix
5 May 2022Flexibility ends; newly manufactured product must be at or below 37 ng/day

A fivefold relaxation, granted deliberately and withdrawn deliberately, because a smoking-cessation medicine being unavailable is also a harm. Practice Regulatory limits are not physical constants; they are judgements about acceptable risk, and they can move when the alternative risk moves. Rifampin makes the same point more starkly — FDA set interim limits and explicitly did not recall, because “the risk of not taking the medicine outweighs any potential risk”.

B3.4  What the industry was actually required to do

Requirement FDA's programme ran on four deadlines, all now passed: small-molecule risk assessment by 31 March 2021; small-molecule confirmatory testing and application changes by 1 October 2023; NDSRI risk assessment by 1 November 2023; NDSRI confirmatory testing and application changes by 1 August 2025. In June 2025 FDA acknowledged the last date was not achievable for all products and asked affected applicants for a progress update in the next annual report.

Two things about this programme are worth more than the dates. First, Revision 2 of the guidance moved the numeric limits off the guidance onto a maintained web page — so the guidance is no longer the source of truth for the numbers, and anyone quoting limits from the PDF is quoting a snapshot. Second, in the EU the fixed deadlines have been replaced by a rolling obligation: marketing authorisation holders are expected to implement corrective action within three years of a new acceptable intake limit being published. Every newly published limit starts a fresh clock on affected products. This is not an episode that closed.

A negative finding, stated because it matters

No FDA warning letter was found citing a firm for failing to perform or update a nitrosamine risk assessment. FDA has driven that obligation through application and drug master file review, not through CGMP enforcement. Anyone teaching this should not imply an enforcement record that does not exist — and should note that the absence of warning letters is not evidence the obligation is soft.

Knowledge check

Module B3 — nitrosamines

Seven questions.


Module B4

Finding what you do not know is there

Every method has a blind spot, and it is determined at the moment the method is designed.

The case library has one operational conclusion: methods do not fail by breaking. They fail by working perfectly on a question nobody asked. This module is about designing the question.

B4.1  The detector decides what exists

Figure B4.1 The same sample seen by an ultraviolet detector and by a charged aerosol detector Two stacked expanded chromatograms of the same sample. The ultraviolet trace shows two impurity peaks. The charged aerosol trace shows four, because two of the impurities have no chromophore and are almost invisible to ultraviolet detection. ULTRAVIOLET DETECTION off scale 0.388% 0.332% CHARGED AEROSOL DETECTION same sample, same injection off scale 0.413% 0.305% 0.541% 0.374% Two impurities visible Four impurities visible The two impurities the ultraviolet trace cannot see account for 0.91% of the sample by mass response. A method is not wrong for missing them. It was never asked to look for something without a chromophore.
Detection is a choice, and every choice has a blind spot. Ultraviolet absorbance is the workhorse of impurity analysis precisely because most drug substances absorb — which is exactly why impurities that have lost the chromophore are the ones it misses.

The two traces are the same sample, same injection. The ultraviolet trace shows two impurities. The charged aerosol trace shows four. The two additional peaks — 0.541% and 0.374% by mass response — have essentially no chromophore, and appear in the ultraviolet trace at 0.0109% and 0.0038%.

Together they account for 0.91% of the sample by mass response and 0.0147% by ultraviolet — an under-report of roughly 62-fold. An impurity comfortably above the qualification threshold is, to this method, invisible.

Practice Ultraviolet absorbance dominates impurity analysis because most drug substances absorb strongly, which makes it sensitive and cheap for the analyte of interest. That same property is the blind spot: the impurities it misses are precisely those that have lost the chromophore — saturated degradants, ring-opened products, counter-ions, sugars, many process residues. Charged aerosol and evaporative light scattering detection respond to mass rather than to a chromophore, which is why they appear where non-absorbing species are suspected. Charged aerosol detection carries its own constraint: the analyte must be non-volatile, and its response over wide ranges is non-linear, so single-point area percent across a wide range is not valid.

B4.2  Specificity is a claim about what is absent

Requirement A stability-indicating method must resolve the drug substance from its degradation products. That claim is established by forced degradation — the technique from Arc A — under acid, base, oxidation, heat, humidity and light, generating degradants deliberately so the method can be shown to separate them.

Practice Two conventional guards on that claim. Mass balance: the loss in the main peak should be accounted for by the gain in the degradants, and a material shortfall means something is not being seen. Peak purity: a diode-array purity check compares spectra across a peak, but as the 2D-LC literature notes, it “cannot discern small spectral differences between structurally similar compounds”. A passing peak purity result is weak evidence when the co-eluting species is an analogue of the parent — which, for impurities, is the usual case.

The remedy is orthogonality: a second separation on a genuinely different retention mechanism. Two C18 columns with different mobile phases are not orthogonal in any useful sense. Reversed phase against HILIC, or ion exchange, or a different pH regime, are.

B4.3  Designing the question — ICH Q14

Requirement ICH Q14, Analytical Procedure Development, reached Step 4 on 1 November 2023 alongside the revised Q2(R2) on validation. It distinguishes a minimal approach — identify the attributes, select the technology, evaluate performance, document the procedure — from an enhanced approach adding risk assessment and prior knowledge, multivariate study of parameter interactions, and a defined control strategy that may include proven acceptable ranges or a method operable design region.

The construct that matters here is the Analytical Target Profile, defined as “a prospective summary of the performance characteristics describing the intended purpose and the anticipated performance criteria of an analytical measurement.” Writing an ATP forces the question this whole module is about: what must this method be able to detect, at what level, and how do we know? Submitting one is optional. Having answered the question is not.

Practice Q14 also makes a practical difference downstream. Defining a method operable design region and established conditions is what allows an impurity method to be improved after approval without a prior approval supplement — which matters a great deal once you accept that instruments keep getting better. Arc D takes that up.

B4.4  The reference standard problem

Arc A's quantitation section ends in a bind that this module has to name. To quantify a newly found impurity properly you want an authentic reference standard of it. By definition you do not have one — it has only just been found, it may exist nowhere in isolated form, and preparing and certifying it can take months.

Two routes out, both worth knowing. Charged aerosol detection gives near-uniform mass response, so an impurity can be quantified without an impurity-specific standard — subject to the linearity constraint above. Quantitative NMR is the more powerful answer: it can “allow measurement of the ratio of two chemical substances, without the use of a reference standard”, and can elucidate structure and quantify in the same experiment. Practice Neither is a routine QC technique in most laboratories, and that is the point — the tools that resolve a new impurity are usually not the tools that found it.

Knowledge check

Module B4 — detection and method design

Six questions.


Module B5

The adjacent frameworks

Elemental impurities and residual solvents are governed separately, analysed differently, and limited in different units. This module covers what they are, why they are separate, and the single logic that turns out to unify all of it.

Everything so far has concerned organic impurities — molecules related to the drug substance or arising alongside it. Two other classes sit next to them in every specification, and they are worth understanding as neighbours rather than as part of the same subject.

B5.1  Why they are carved out

Three reasons, and they are worth being explicit about because the separation is not arbitrary.

Different analysis. Organic impurities are a chromatography problem. Elemental impurities are an ICP-MS or ICP-OES problem — atomic spectroscopy, different instruments, different sample preparation, usually a different analyst. Residual solvents are a headspace GC problem. The three share a specification page and almost nothing else in the laboratory.

Different origin. An elemental impurity does not degrade and is not synthesised. It arrives from a catalyst, a reagent, the water, the container, or the manufacturing equipment itself — and once present it cannot be destroyed, only removed or excluded. A residual solvent is a deliberately added processing aid that failed to leave.

Different units and different logic. This is the one that matters. Both frameworks set permitted daily exposures in µg or mg per day, not percentages — because for these substances the toxicology is known. That distinction turns out to be the key to the whole picture.

B5.2  Elemental impurities — ICH Q3D

Requirement ICH Q3D(R2), current since 8 March 2022, classifies elements by toxicity and likelihood of occurrence, and sets permitted daily exposures by route of administration.

ClassDefinitionElements
1“human toxicants that have limited or no use in the manufacture of pharmaceuticals”As, Cd, Hg, Pb
2ARoute-dependent human toxicants, high probability of occurrenceCo, Ni, V
2BRoute-dependent human toxicants, reduced probability of occurrenceAg, Au, Ir, Os, Pd, Pt, Rh, Ru, Se, Tl
3“relatively low toxicities by the oral route…(high PDEs, generally > 500 µg/day)”Ba, Cr, Cu, Li, Mo, Sb, Sn

Oral permitted daily exposures, in µg/day: cadmium 5, lead 5, arsenic 15, mercury 30, cobalt 50, vanadium 100, nickel 200. Parenteral and inhalation limits are lower.

Requirement Q3D is explicitly a risk-assessment framework rather than a testing framework. The expectation is that a manufacturer identifies potential sources — drug substance, excipients, water, equipment, container-closure — assesses whether any could contribute meaningfully against the PDE, and tests only where the assessment says testing is warranted. Practice An assessment concluding “no significant contribution” without documented reasoning for each potential source is the common deficiency here; the conclusion is usually right and the file usually cannot show why.

USP implements this through ⟨232⟩ (limits, aligned to Q3D) and ⟨233⟩ (procedures — ICP-OES and ICP-MS, with validation requirements for alternatives). As with all USP text in this course, confirm the current official chapter before relying on it.

B5.3  Residual solvents — ICH Q3C

Requirement ICH Q3C(R9) classifies solvents by the harm they do, in three classes with strikingly different treatment.

ClassDefinitionTreatment
1“Known human carcinogens, strongly suspected human carcinogens, and environmental hazards”Avoid. Benzene 2 ppm; carbon tetrachloride 4 ppm; 1,2-dichloroethane 5 ppm; 1,1-dichloroethene 8 ppm
2“Non-genotoxic animal carcinogens or possible causative agents of other irreversible toxicity”Limit by PDE. Methanol 30 mg/day; toluene 8.9; dichloromethane 6.0; acetonitrile 4.1
3“Solvents with low toxic potential to man; no health-based exposure limit is needed”“50 mg per day or less (corresponding to 5000 ppm or 0.5% under Option 1) would be acceptable without justification”

Two options for Class 2. Option 1 uses standardised concentration limits assuming “a product mass of 10 g administered daily” — simple, conservative, and requiring no calculation where the daily dose does not exceed 10 g. Option 2 calculates against the actual daily dose: “the sum of the amounts of solvent per day should be less than that given by the PDE”. Practice Option 2 is more permissive for a low-dose product and is where most of the useful headroom lies, but it obliges you to hold the daily dose as an assumption in the file — and a dose change then invalidates the solvent limit, exactly as it does for the organic thresholds in Arc A.

USP implements Q3C through ⟨467⟩.

B5.4  The logic that unifies all of it

Now the payoff for having covered the carve-out rather than skipping it. Below is every limit discussed in Arcs A and B, converted to the same unit — micrograms per day — at a single common daily dose of 500 mg.

Figure B5.1 Every impurity limit expressed as micrograms per day for one 500 milligram daily dose A logarithmic scale comparing thirteen limits drawn from ICH Q3A, Q3C, Q3D, M7 and the nitrosamine guidances, all converted to micrograms per day at a common daily dose. The limits span nearly two million fold. ALL LIMITS AT ONE DOSE — 500 mg/day 0.1 1 10 100 1,000 10,000 µg/day Q3C Class 3 residual solvent 50 mg/day, no justification needed 50,000 Q3C Class 2 — methanol PDE 30 mg/day 30,000 Q3C Class 2 — acetonitrile PDE 4.1 mg/day 4,100 Q3A qualification threshold 0.15% of a 500 mg dose 750 Q3A identification threshold 0.10% of a 500 mg dose 500 Q3D nickel, oral PDE 200 µg/day 200 Q3D mercury, oral PDE 30 µg/day 30 Q3D arsenic, oral PDE 15 µg/day 15 Q3D lead / cadmium, oral PDE 5 µg/day 5.0 M7 TTC, lifetime 1.5 µg/day 1.5 Q3C Class 1 — benzene 2 ppm in a 500 mg dose 1.0 Nitrosamine — NDMA 96 ng/day 0.096 Nitrosamine — NDEA 26.5 ng/day 0.0265 These limits span roughly 1,886,792-fold, and every one of them is a legitimate impurity limit. Percentage limits are what you use when the toxicity is unknown. Absolute daily intake is what you use when it is known. Legend: grey — residual solvents · steel — organic impurities · navy — elemental impurities · brass — mutagens and the cohort of concern.
The single most clarifying picture in this course. Nothing here is inconsistent: each framework sets its limit by how much is known about the harm, not by how the substance is analysed.

They span roughly 1,886,792-fold, and not one of them is anomalous. Read from the top down and a single rule explains the entire spread:

The rule

A percentage limit is what you use when you do not know how toxic the substance is. The Q3A and Q3B thresholds are default positions on an unknown: they say that below a certain proportion of the dose, the risk from an unidentified organic compound is acceptable without further work. That is why they scale with dose, and why they carry the footnote about unusually toxic impurities.

An absolute daily intake limit is what you use when you do know. Every framework that has a named toxicology — elemental impurities, residual solvents, mutagenic impurities, nitrosamines — sets a limit in mass per day, independent of the dose of the drug, because the harm depends on how much of that substance the patient receives and not on what fraction of the tablet it represents.

So the sequence from 50 mg/day for a Class 3 solvent down to 26.5 ng/day for NDEA is not a hierarchy of strictness for its own sake. It is a map of how much is known, and how bad the answer turned out to be.

Practice The practical corollary is worth stating for anyone who reads specifications. When you see a limit expressed as a percentage, ask what is not known about that impurity. When you see one expressed in µg or ng per day, somebody has done the toxicology — and the number is not negotiable by dilution, because a bigger tablet does not make the intake smaller.

Knowledge check

Module B5 — the adjacent frameworks

Six questions.


What comes next

Arc B has established what these impurities are, what they have cost, and how the limits that govern them are set. Arc C turns to what you actually do when one appears — at the bench before release, in a product already distributed, and across a portfolio when a whole class is newly recognised. Arc D asks what happens as instruments continue to improve, and returns to the sentence in M7 section 4.4 that is the entire published answer to a question that keeps getting larger.

A cumulative assessment covering all five Arc B modules is issued as a separate document.