Supplier Quality & CoA Review

Catch the supplier exception before the material reaches production

Every incoming certificate is checked line by line against your approved specification, your supplier qualification status and that supplier’s own history, so an out-of-spec result, a missing test or a quietly changed method is caught at receiving rather than at release.

The highest-volume, lowest-attention check in the quality system

A receiving site can process hundreds of certificates a month, each a differently formatted PDF from a different supplier, each requiring a line-by-line comparison against an internal specification that lives in another system entirely.

In practice most CoAs are reviewed by pattern recognition. The reviewer scans for anything that looks unusual and signs. That works until it does not, and the failure modes are all invisible to a fast visual scan: a test your specification requires that is simply absent from the certificate, a result reported against a different method than the one you qualified, a limit quietly widened between revisions, values copied from the previous lot, or a manufacturing site on the certificate that is not the site you audited.

There is a second, quieter cost. Because the certificates end up as scans in a folder, nobody at the site can answer the question that actually matters: which of our suppliers is drifting?

How it works

What goes in
  • Supplier CoAs and CoCs in any format, PDF, scan, email attachment or portal download
  • Your approved incoming and raw material specifications
  • Approved supplier list and qualification status
  • Purchase orders and receiving records
  • Incoming inspection and identity test results
  • Every prior certificate from that supplier for that material
What Litewave does
  • Extracts each test, method, unit, specification and result as structured data
  • Normalizes units and method names across supplier formats
  • Matches material and grade to the correct current version of your specification
  • Compares against the history for that supplier and material
What you get
  • A pass or exception decision per certificate, every discrepancy cited
  • A receiving decision packet for the QA reviewer to sign
  • Structured CoA data feeding supplier trending
  • A supplier scorecard that updates as a byproduct of the review

What Litewave checks

Against your specification

  • Every test on your incoming specification is present on the certificate
  • Every result is within your limit, not just within the supplier limit
  • The supplier stated specification matches your approved specification, and both versions are current
  • The test method matches the method you qualified the supplier against
  • Units are normalized before comparison, so ppm against percent against mg/kg cannot hide a failure
  • Result precision and rounding checked against the limit rather than the reported value

Certificate integrity

  • Results identical to a prior lot, or inconsistent with the supplier own historical distribution
  • Dates that precede manufacture, or a missing authorized signature
  • Lot number, manufacture date, retest or expiry date and quantity reconciled against the PO and receiving record
  • Certificate of Analysis distinguished from Certificate of Conformance, so a CoC is not accepted where test data is required

Supplier status

  • Supplier is on the approved list, approved for this material and this receiving site
  • Qualification and audit are in date
  • The manufacturing site named on the certificate is the qualified site, not just the qualified company
  • Allergen, GMO, BSE and TSE, residual solvent, heavy metal and microbial statements present where your specification requires them

Trending

  • Results creeping toward the limit across lots
  • Variance tightening implausibly, which is its own signal
  • Rising exception rates and repeated method changes by supplier
  • Acceptance rate, lead time and change notification history per supplier

Why this check is legally load-bearing

The same review carries different statutory weight depending on what you make.

Industry

Pharmaceutical

What the rule requires

21 CFR 211.84 requires examination and testing of components, including identity testing on each lot. Reliance on a supplier report of analysis must be justified and periodically validated. ICH Q7 Section 7 covers the same ground for APIs.

Industry

Nutraceuticals

What the rule requires

21 CFR 111.75 requires at least one appropriate test to verify the identity of every incoming dietary ingredient. Reliance on a supplier certificate for other components is allowed only where you have qualified that supplier and periodically confirm the certificate.

Industry

Food & Beverage

What the rule requires

21 CFR Part 117 Subpart G supply-chain program, where a supplier certificate is an allowable verification activity for certain hazards, plus FSVP under 21 CFR Part 1 Subpart L for imported ingredients.

Industry

Cosmetics

What the rule requires

Raw material specifications and the safety substantiation file both rest on supplier data you did not generate.

Running in production today

99%Data extraction accuracy

Incoming CoA review is deployed and running in a live customer environment today. The extraction engine underneath it is the same one measured at 99% accuracy at the world’s largest sulfamethoxazole producer, on handwritten 150 page batch records, which is a materially harder document class than a printed certificate of analysis.

Questions we get asked

Our suppliers all send different formats. Does that break it?

No. Format variability is the problem this exists to solve. Litewave reads the certificate as a document rather than as a fixed template, so a new supplier layout does not require configuration.

Can it catch a falsified certificate?

It catches the signatures of falsification that are checkable: results identical to a previous lot, values inconsistent with the supplier historical distribution, dates that do not reconcile, and results that conflict with your own incoming testing. It cannot certify that a supplier ran the tests they say they ran. Nothing can, short of testing it yourself. What it does is make the anomaly visible in time to act on it.

Does this replace incoming identity testing?

No, and in several of these industries it legally cannot. Under 21 CFR Part 111 an identity test on each incoming dietary ingredient is required regardless of what the certificate says. Litewave reconciles your test result against the certificate rather than replacing the test.

Where does supplier scorecarding come from?

From the certificates themselves. Every CoA you process becomes structured data, so trending is a byproduct of doing the review rather than a separate exercise someone has to schedule.

Related

Built for validated environments

Your data stays where your auditors expect it

Deploy in your environment

Your cloud, your data center, on the plant floor, or fully air-gapped. The same agents run identically in all four.

Your data never trains our models

Documents are never sent to third-party AI providers and are never used to train any model, ours or anyone else’s.

21 CFR Part 11

Electronic records, electronic signatures and complete audit trails on every action, built to ALCOA+ data integrity principles.

EU GMP Annex 11

Meets European GMP expectations for computerised systems used in regulated manufacturing.

Evidence on every flag

Every extraction, check and recommendation links back to its source page. Nothing asserted is unverifiable.

Human in the loop by design

Agents propose, qualified people approve. Litewave never dispositions a batch on its own.

See it run on one of your own records

Bring something real. We will show you what Litewave finds in it and what it cites as evidence.