

How a pharmaceutical manufacturer moved Certificate of Analysis creation off spreadsheets and onto a controlled system - product, grade, and test masters governing every certificate, validation applied as values are entered, a generator-reviewer-approver workflow with digital sign-off, and an issued PDF that can be verified from the document itself.

A Certificate of Analysis is a small document carrying a large claim: that this batch, tested against this specification, meets it. Produced in Excel, that claim rests on whoever built the file. Batch details are re-typed. Test values are entered with nothing checking them against the specification. And the template a colleague used last month has quietly diverged from the one in use today.
The consequences arrive later, and always at the worst moment. A customer queries a value and the version that was issued cannot be found. An auditor asks for the approval history of a certificate and there is an email chain where a record should be. And because approval moves by email and printout, a certificate takes days to clear at exactly the point the batch is ready to ship.
A Certificate of Analysis is a small document carrying a large claim. In Excel, that claim rests on whoever built the file.
We built a cloud system that governs the certificate before anyone starts typing. Product master data holds CAS numbers, chemical formulae, and molecular weights. A test master holds reusable test definitions and specification templates. A grade master carries customer-specific grades and pharmacopeial variations - USP, EP, BP - because the same product certified to a different pharmacopeia is a different specification, not a different label. Templates are held centrally too, in internal, customer-specific, and regulatory formats, so a certificate is assembled from controlled parts rather than copied from a colleague.
Creation is then a guided form. Batch details are entered once, the product brings its own data across, the grade decides the specification, and test results are checked as they are typed - range checking against the limits, format validation on CAS numbers, dates, and batch IDs, mandatory fields, and a cross-reference that will not allow an incompatible product and grade to be certified together. From there the certificate moves through draft, review, approval, and approved, across separated generator, reviewer, and approver roles, with each action timestamped against the person who took it. The issued PDF carries the approver signatures and a QR code, so whoever is holding the document can check it against the version that was actually approved.
Controlled inputs, guarded entry, and an issued document that can be checked.
The two figures below are the client’s own, from their deployment review. We have not added any others.
Validation runs while the certificate is being written - values against the specification, formats on CAS numbers and batch IDs, and a check that the product and grade are compatible at all. The client reports manual errors down by more than 90%.
The certificate travels through defined roles rather than an email chain, with the queue visible to everyone standing in it. The client reports approvals completing same-day, against three to five days before.
Every PDF carries its approver signatures and a QR code, and the full history sits behind it - who created, who reviewed, who approved, and when. Producing that trail for an auditor stopped being a search.
Cloud-hosted, with an API-first design so the system can extend into the ERP and LIMS already in use.
Certificates of analysis, batch records, specifications, deviation reports - anywhere a controlled document is being assembled in a spreadsheet. Tell us how yours are produced today and we will tell you honestly what would have to be governed before any of it could be automated.