The Purpose of the Diagram — Not a Presentation Tool

Every pharma OT project produces a network diagram. Most produce one too early, in a visually polished but technically shallow form that looks good in a design review presentation but fails to serve its actual function: as a controlled engineering document that the IQ team uses on-site to verify the as-built network matches the approved design.

The IQ team's job with the network diagram is simple: look at the diagram, look at the system, confirm they match. For that comparison to be possible, every element on the diagram must correspond to a real device with a real tag number, IP address, and physical location. A box labelled "SCADA Server" with no IP address, no tag number, and no indication of which rack it sits in cannot be verified. A box labelled "SRV-SCADA-01 — 192.168.20.10 — MCP-01 Rack A U8" can be walked over to, identified, and confirmed against the HDS component register in under thirty seconds.

The HDS Appendix B Rule

The IQ-SYS-001 input documents table references "DWG-HDS-002 — Network Architecture Diagram (As-Built)" as a prerequisite document. This means the diagram must exist, must be at as-built revision before IQ execution begins, and must be formally controlled with a document number and revision. A hand-drawn sketch or an unsaved Visio file does not qualify. The diagram is a GMP document — it has a document number, a revision history, and it is approved under the same document control process as the HDS itself.

What the Diagram Must Show — The Mandatory Elements

The network architecture diagram for a pharma IQ must include the following elements. Every one of these is something an IQ team will look at and expect to find:

PHARMA IQ NETWORK DIAGRAM — ANNOTATED EXAMPLE (DWG-HDS-002) CORP IT ZONE Corporate LAN 172.16.0.0/16 FW-DMZ-01 172.16.1.1 DMZ ZONE DMZ-REP-01 10.10.10.5 JUMP-01 10.10.10.10 PATCH-SRV-01 10.10.10.20 FW-OT-01 192.168.30.1 OT-SUP — VLAN 20 SRV-SCADA-01 192.168.20.10 SRV-HIST-01 192.168.20.20 HMI-01, HMI-02 .30 / .31 OT-CTRL — VLAN 10 PLC-CPU-01 192.168.10.5 SW-OT-01 Cisco IE-3300 / .30.2 OPC-UA TCP:4840 LEGEND OT Supervision Zone OT Control Zone DMZ Zone Network connection (Ethernet) PROFINET / protocol label DOC: DWG-HDS-002 | REV: A | STATUS: AS-BUILT | SYSTEM: [System Name] | SITE: [Site Name] | DATE: [DD-MMM-YYYY] APPROVED BY: [Name / QA] | "Every device shown matches HDS-SYS-001 Section 1.3 component register"
ANNOTATED IQ NETWORK DIAGRAM — DWG-HDS-002 · Every device has its tag number and IP address. Zone boundaries labelled with VLAN IDs. Firewalls shown with tags. Protocol labels on key links. Legend and title block included.

What the Diagram Must Not Be

Understanding the failures is as useful as the specification. These are the most common reasons IQ teams reject or flag a network diagram as insufficient:

Generic device labels without tag numbers. "SCADA Server" is not an IQ-verifiable label. "SRV-SCADA-01" cross-references to the component register and can be physically located in the server rack.

IP addresses missing from the diagram. If IP addresses are only in a separate table in the HDS body, the IQ team must flip between two documents to verify a single device. Put the IP address on the diagram, adjacent to the device. The IQ team should be able to verify a device's identity, location, and network address from the diagram alone.

No zone boundaries or VLAN labels. A diagram that shows all devices on a flat topology without zone delineation cannot be used to verify that the segmentation architecture was implemented. The zones and VLANs are the compliance-critical part of the architecture — they must be visible.

No title block or document control. A network diagram without a document number, revision, and approval cannot be referenced as a controlled document in the IQ input documents list. It is not an approved engineering document.

Design-phase version used at IQ without as-built update. A diagram showing planned IP addresses that differ from the as-installed addresses generates a nonconformance at IQ. The diagram must reflect the as-built state before the IQ team walks on-site. This is the same as-built update requirement that applies to the full network IQ documentation package.

Tooling and Format — What Works

The diagram does not need to be produced with specialist network diagramming software. Microsoft Visio, draw.io (free, browser-based), or even PowerPoint with proper engineering discipline all produce acceptable output. What matters is the content and the document control — not the tool.

The format requirement from the IQ perspective is that the diagram is printed or rendered at a size where the device labels and IP addresses are readable. A diagram produced at A3 or A4 landscape with text sized at 7-8pt minimum is readable when printed. A diagram exported from a large canvas at low resolution, with 5pt text, is not. If the diagram is too complex to show all zones and devices at readable scale on a single page, split it — a logical topology overview diagram plus a detailed OT zone diagram is better than one illegible diagram that tries to show everything.

The diagram is referenced in the IQ as "DWG-HDS-002 — Network Architecture Diagram (As-Built) Rev A" — this means it needs a document number, a revision letter, and to be formally controlled in the project document management system alongside the HDS, IQ, and other GMP deliverables. It is signed off as part of the HDS package, not as a standalone document.

In the QLean Framework

HDS-SYS-001 Appendix B provides the network architecture diagram template with zones pre-defined, colour-coded by zone type (OT-SUP, OT-CTRL, DMZ, Corporate IT), and a title block matching the HDS document number series. Device placeholders are set up with tag-number and IP-address label format pre-applied. The IQ-SYS-001 input documents table explicitly lists DWG-HDS-002 as a mandatory prerequisite document, with the as-built revision requirement noted. The diagram produced as Appendix B is the IQ team's primary reference document for physical network topology verification.