How to digitize certificates of analysis from suppliers

In brief
Digitizing a supplier certificate of analysis (CoA) means extracting the material, lot, tests, specifications, results, and methods into one schema, with each value linked to the certificate it came from, whatever layout the supplier used. The steps are to define one schema for every supplier, map each supplier's terms to it, extract, check the results against the specification, and review anything flagged. Structured certificate data makes it practical to trend a supplier's results across lots and to support the verification of supplier data that 21 CFR 211.84 requires.
Key takeaways
- Every supplier formats certificates differently, so the key design decision is one schema that all certificates are mapped into.
- 21 CFR 211.84(d)(2) allows a manufacturer to rely on a supplier's certificate only if it performs at least one identity test on each component and validates the supplier's results at appropriate intervals.
- Supplier test names, units, and specification formats vary, so a mapping from each supplier's terms to the operation's own terms is part of the work.
- Once certificates are structured, a team can trend reported results across lots and compare them with in-house testing.
- This post covers extracting data from certificates received from suppliers, not creating a certificate for a product the operation releases.
Creating a certificate versus reading one
Search for "certificate of analysis software" and most results are about generating certificates: a manufacturer or lab producing its own certificate when it releases a lot. This post is about the other direction. A pharmaceutical manufacturer receives certificates from dozens or hundreds of suppliers, usually as PDFs, and needs the data inside them.
Why supplier certificate data matters
Under 21 CFR 211.84(d)(2), a manufacturer may accept a supplier's report of analysis in place of testing each attribute itself, but only if it runs at least one specific identity test on each component and establishes the reliability of the supplier's results through appropriate validation at appropriate intervals. That validation is ongoing work. It means comparing what suppliers report with what in-house testing finds, over time.
When certificates sit as PDFs, that comparison means retyping results into a spreadsheet. When they are structured, it becomes a query. The same data supports Raw Material Characterization, where material and lot variability is connected to process performance.
Step 1: Define one schema for every supplier
List what the operation needs from every certificate, regardless of who sent it:
- Supplier, manufacturing site and material, with the operation's own material code
- Lot or batch number, manufacture date and expiry or retest date
- Each test, its specification, its result and its unit
- The method or compendial reference for each test
- Release date and the name or signature of the person releasing the lot
The schema belongs to the operation. Suppliers' certificates are mapped into it; the schema does not change to fit them.
Step 2: Map each supplier's terms to the schema
One supplier writes "Assay (HPLC)", another "Purity", a third "Content, % w/w". Some state specifications as ranges, some as "NLT 98.0%", some as "Conforms". Build a mapping from each supplier's test names, units, and specification formats to the operation's own terms. This is where most of the domain knowledge goes, and it is reused for every future certificate from that supplier.
Step 3: Extract every value with its location
Read the header fields and the results table on every page, including footnotes that qualify a result. Each value keeps its location on the certificate, so a reviewer can check it in one step. Certificates often run to more than one page, with the results table continuing across pages; the extraction has to treat that as one table.
Step 4: Check results against the specification
Rules catch what reading alone misses:
- Every test the operation requires is present.
- Each result falls within its specification, and "Conforms" results have a stated specification.
- Units match the operation's expected unit, or are converted with the conversion recorded.
- The lot number, dates, and material match the receiving record.
- The certificate carries a release date and signature.
Step 5: Review flags
A reviewer sees each flagged value beside the certificate page it came from and confirms, corrects, or rejects it. Their decision is recorded. Values read with low confidence go through the same review. Nothing uncertain passes to downstream use without a person looking at it.
Step 6: Put the data to work
With certificates structured and approved, a team can:
- Trend a supplier's reported results for a material across lots
- Compare supplier results with in-house identity and other testing
- Find lots that are within specification but out of trend
- Answer which batches used a given lot, when certificate data is connected with batch records in the Context Layer
A worked example
Lot 2231-B of a raw material arrives with a two-page certificate. Page 1 has the header; page 2 continues the results table. The supplier reports "Assay (HPLC): 99.1%, spec 98.0 to 102.0%". The mapping assigns it to the operation's "Assay" test with unit "% w/w". A rule confirms it is within specification. A second rule flags that the residual solvents result is stated as "Complies" with no limit shown, and a reviewer resolves it from the supplier's specification sheet. Every value links back to its page.
Note: The values used in this example are illustrative only.
Questions
- Can we rely on supplier certificates instead of testing every attribute?
- Under 21 CFR 211.84(d)(2), yes, if the manufacturer performs at least one specific identity test on each component and establishes the reliability of the supplier's results through appropriate validation at appropriate intervals.
- How do you handle certificates in many different layouts?
- By extracting into one schema the operation defines and maintaining a mapping from each supplier's test names, units, and specification formats to that schema. The mapping is built once per supplier and reused.
- What should happen to a result stated only as "Conforms"?
- It should be flagged if the certificate does not state the specification it conforms to, so a reviewer can confirm the limit before the result is used.
Sources
- 21 CFR 211.84, Testing and approval or rejection of components, U.S. Code of Federal Regulations, October 6, 2026
Read next
Document Intelligence
Turns records from suppliers, CROs, CDMOs and your labs into contextualized, source-linked data.
See How It Works




