Skip to content
Katalyze announces $10.5M seed round. Read the press release

How to digitize certificates of analysis from suppliers

Published October 5, 20263 min read

A stainless sight glass on a vessel, lit by red light

In brief

Digitizing a supplier certificate of analysis (CoA) means extracting the material, lot, tests, specifications, results, and methods into one schema, with each value linked to the certificate it came from, whatever layout the supplier used. The steps are to define one schema for every supplier, map each supplier's terms to it, extract, check the results against the specification, and review anything flagged. Structured certificate data makes it practical to trend a supplier's results across lots and to support the verification of supplier data that 21 CFR 211.84 requires.

Key takeaways

  • Every supplier formats certificates differently, so the key design decision is one schema that all certificates are mapped into.
  • 21 CFR 211.84(d)(2) allows a manufacturer to rely on a supplier's certificate only if it performs at least one identity test on each component and validates the supplier's results at appropriate intervals.
  • Supplier test names, units, and specification formats vary, so a mapping from each supplier's terms to the operation's own terms is part of the work.
  • Once certificates are structured, a team can trend reported results across lots and compare them with in-house testing.
  • This post covers extracting data from certificates received from suppliers, not creating a certificate for a product the operation releases.

Creating a certificate versus reading one

Search for "certificate of analysis software" and most results are about generating certificates: a manufacturer or lab producing its own certificate when it releases a lot. This post is about the other direction. A pharmaceutical manufacturer receives certificates from dozens or hundreds of suppliers, usually as PDFs, and needs the data inside them.

Why supplier certificate data matters

Under 21 CFR 211.84(d)(2), a manufacturer may accept a supplier's report of analysis in place of testing each attribute itself, but only if it runs at least one specific identity test on each component and establishes the reliability of the supplier's results through appropriate validation at appropriate intervals. That validation is ongoing work. It means comparing what suppliers report with what in-house testing finds, over time.

When certificates sit as PDFs, that comparison means retyping results into a spreadsheet. When they are structured, it becomes a query. The same data supports Raw Material Characterization, where material and lot variability is connected to process performance.

Step 1: Define one schema for every supplier

List what the operation needs from every certificate, regardless of who sent it:

  • Supplier, manufacturing site and material, with the operation's own material code
  • Lot or batch number, manufacture date and expiry or retest date
  • Each test, its specification, its result and its unit
  • The method or compendial reference for each test
  • Release date and the name or signature of the person releasing the lot

The schema belongs to the operation. Suppliers' certificates are mapped into it; the schema does not change to fit them.

Step 2: Map each supplier's terms to the schema

One supplier writes "Assay (HPLC)", another "Purity", a third "Content, % w/w". Some state specifications as ranges, some as "NLT 98.0%", some as "Conforms". Build a mapping from each supplier's test names, units, and specification formats to the operation's own terms. This is where most of the domain knowledge goes, and it is reused for every future certificate from that supplier.

Step 3: Extract every value with its location

Read the header fields and the results table on every page, including footnotes that qualify a result. Each value keeps its location on the certificate, so a reviewer can check it in one step. Certificates often run to more than one page, with the results table continuing across pages; the extraction has to treat that as one table.

Step 4: Check results against the specification

Rules catch what reading alone misses:

  • Every test the operation requires is present.
  • Each result falls within its specification, and "Conforms" results have a stated specification.
  • Units match the operation's expected unit, or are converted with the conversion recorded.
  • The lot number, dates, and material match the receiving record.
  • The certificate carries a release date and signature.

Step 5: Review flags

A reviewer sees each flagged value beside the certificate page it came from and confirms, corrects, or rejects it. Their decision is recorded. Values read with low confidence go through the same review. Nothing uncertain passes to downstream use without a person looking at it.

Step 6: Put the data to work

With certificates structured and approved, a team can:

  • Trend a supplier's reported results for a material across lots
  • Compare supplier results with in-house identity and other testing
  • Find lots that are within specification but out of trend
  • Answer which batches used a given lot, when certificate data is connected with batch records in the Context Layer

A worked example

Lot 2231-B of a raw material arrives with a two-page certificate. Page 1 has the header; page 2 continues the results table. The supplier reports "Assay (HPLC): 99.1%, spec 98.0 to 102.0%". The mapping assigns it to the operation's "Assay" test with unit "% w/w". A rule confirms it is within specification. A second rule flags that the residual solvents result is stated as "Complies" with no limit shown, and a reviewer resolves it from the supplier's specification sheet. Every value links back to its page.

Note: The values used in this example are illustrative only.

Questions

Can we rely on supplier certificates instead of testing every attribute?
Under 21 CFR 211.84(d)(2), yes, if the manufacturer performs at least one specific identity test on each component and establishes the reliability of the supplier's results through appropriate validation at appropriate intervals.
How do you handle certificates in many different layouts?
By extracting into one schema the operation defines and maintaining a mapping from each supplier's test names, units, and specification formats to that schema. The mapping is built once per supplier and reused.
What should happen to a result stated only as "Conforms"?
It should be flagged if the certificate does not state the specification it conforms to, so a reviewer can confirm the limit before the result is used.

Sources

  1. 21 CFR 211.84, Testing and approval or rejection of components, U.S. Code of Federal Regulations, October 6, 2026
  • A floral macro in blue and orange
    September 21, 2026Why unstructured records slow regulated operations

    In pharmaceutical operations, much of the evidence behind a batch sits in unstructured records: paper batch records, supplier certificates of analysis, lab reports and deviation records that no system can query. The records are complete and controlled, but answering a question across them means finding, reading, and retyping them by hand. That slows investigations, supplier qualification, and batch review, and it keeps experts on assembly work. Turning those records into structured, source-linked data removes that step without replacing the systems that hold them.

  • Tubes in a rack, close
    September 15, 2026The complete guide to pharmaceutical document digitization

    Pharmaceutical document digitization is the process of reading GxP records such as executed batch records and certificates of analysis into a defined schema, with every value linked back to the page it came from. A scan by itself is a picture, not data. Done well, digitization produces structured data that reviewers can check against the source, that meets the regulatory expectation for accurate and complete records, and that other work can build on. This guide covers how digitization works, what OCR is and how to evaluate its accuracy, and how to build trust with digitization technology.

  • A sample paper batch record
    October 2, 2026How to digitize paper batch records without losing the source

    Digitizing a paper batch record means reading every value on the executed record, including handwritten entries, corrections and signatures, and loading into a defined schema, with each value linked to the location it came from. The steps are to define the schema, capture a good image, extract, check against rules, have an expert review flags, and deliver the approved data. Keeping the link to the source at every step is what makes the result usable in regulated work.

Alyse Gonthier, PhDHead of Content

PhD in biomaterials; Science communication enthusiast

LinkedIn
Where this goes next

Document Intelligence

Turns records from suppliers, CROs, CDMOs and your labs into contextualized, source-linked data.

See How It Works
Highly Regulated

A weekly letter from Katalyze.

Book a demo

See Katalyze on your operation.

Bring the job you want to move forward and the records you'd like connected. Thirty minutes on how Katalyze would do the work, and where your experts come in.

Or, just a quick chat to run through the product, your call.