Supplier Quality & CoA Review
Catch the supplier exception before the material reaches production
Every incoming certificate is checked line by line against your approved specification, your supplier qualification status and that supplier’s own history, so an out-of-spec result, a missing test or a quietly changed method is caught at receiving rather than at release.
The highest-volume, lowest-attention check in the quality system
A receiving site can process hundreds of certificates a month, each a differently formatted PDF from a different supplier, each requiring a line-by-line comparison against an internal specification that lives in another system entirely.
In practice most CoAs are reviewed by pattern recognition. The reviewer scans for anything that looks unusual and signs. That works until it does not, and the failure modes are all invisible to a fast visual scan: a test your specification requires that is simply absent from the certificate, a result reported against a different method than the one you qualified, a limit quietly widened between revisions, values copied from the previous lot, or a manufacturing site on the certificate that is not the site you audited.
There is a second, quieter cost. Because the certificates end up as scans in a folder, nobody at the site can answer the question that actually matters: which of our suppliers is drifting?
How it works
- Supplier CoAs and CoCs in any format, PDF, scan, email attachment or portal download
- Your approved incoming and raw material specifications
- Approved supplier list and qualification status
- Purchase orders and receiving records
- Incoming inspection and identity test results
- Every prior certificate from that supplier for that material
- Extracts each test, method, unit, specification and result as structured data
- Normalizes units and method names across supplier formats
- Matches material and grade to the correct current version of your specification
- Compares against the history for that supplier and material
- A pass or exception decision per certificate, every discrepancy cited
- A receiving decision packet for the QA reviewer to sign
- Structured CoA data feeding supplier trending
- A supplier scorecard that updates as a byproduct of the review
What Litewave checks
Against your specification
- Every test on your incoming specification is present on the certificate
- Every result is within your limit, not just within the supplier limit
- The supplier stated specification matches your approved specification, and both versions are current
- The test method matches the method you qualified the supplier against
- Units are normalized before comparison, so ppm against percent against mg/kg cannot hide a failure
- Result precision and rounding checked against the limit rather than the reported value
Certificate integrity
- Results identical to a prior lot, or inconsistent with the supplier own historical distribution
- Dates that precede manufacture, or a missing authorized signature
- Lot number, manufacture date, retest or expiry date and quantity reconciled against the PO and receiving record
- Certificate of Analysis distinguished from Certificate of Conformance, so a CoC is not accepted where test data is required
Supplier status
- Supplier is on the approved list, approved for this material and this receiving site
- Qualification and audit are in date
- The manufacturing site named on the certificate is the qualified site, not just the qualified company
- Allergen, GMO, BSE and TSE, residual solvent, heavy metal and microbial statements present where your specification requires them
Trending
- Results creeping toward the limit across lots
- Variance tightening implausibly, which is its own signal
- Rising exception rates and repeated method changes by supplier
- Acceptance rate, lead time and change notification history per supplier
Why this check is legally load-bearing
The same review carries different statutory weight depending on what you make.
Industry
Pharmaceutical
What the rule requires
21 CFR 211.84 requires examination and testing of components, including identity testing on each lot. Reliance on a supplier report of analysis must be justified and periodically validated. ICH Q7 Section 7 covers the same ground for APIs.
Industry
Nutraceuticals
What the rule requires
21 CFR 111.75 requires at least one appropriate test to verify the identity of every incoming dietary ingredient. Reliance on a supplier certificate for other components is allowed only where you have qualified that supplier and periodically confirm the certificate.
Industry
Food & Beverage
What the rule requires
21 CFR Part 117 Subpart G supply-chain program, where a supplier certificate is an allowable verification activity for certain hazards, plus FSVP under 21 CFR Part 1 Subpart L for imported ingredients.
Industry
Cosmetics
What the rule requires
Raw material specifications and the safety substantiation file both rest on supplier data you did not generate.
Running in production today
Incoming CoA review is deployed and running in a live customer environment today. The extraction engine underneath it is the same one measured at 99% accuracy at the world’s largest sulfamethoxazole producer, on handwritten 150 page batch records, which is a materially harder document class than a printed certificate of analysis.
Questions we get asked
Our suppliers all send different formats. Does that break it?
No. Format variability is the problem this exists to solve. Litewave reads the certificate as a document rather than as a fixed template, so a new supplier layout does not require configuration.
Can it catch a falsified certificate?
It catches the signatures of falsification that are checkable: results identical to a previous lot, values inconsistent with the supplier historical distribution, dates that do not reconcile, and results that conflict with your own incoming testing. It cannot certify that a supplier ran the tests they say they ran. Nothing can, short of testing it yourself. What it does is make the anomaly visible in time to act on it.
Does this replace incoming identity testing?
No, and in several of these industries it legally cannot. Under 21 CFR Part 111 an identity test on each incoming dietary ingredient is required regardless of what the certificate says. Litewave reconciles your test result against the certificate rather than replacing the test.
Where does supplier scorecarding come from?
From the certificates themselves. Every CoA you process becomes structured data, so trending is a byproduct of doing the review rather than a separate exercise someone has to schedule.
Related
Built for validated environments
Your data stays where your auditors expect it
Deploy in your environment
Your cloud, your data center, on the plant floor, or fully air-gapped. The same agents run identically in all four.
Your data never trains our models
Documents are never sent to third-party AI providers and are never used to train any model, ours or anyone else’s.
21 CFR Part 11
Electronic records, electronic signatures and complete audit trails on every action, built to ALCOA+ data integrity principles.
EU GMP Annex 11
Meets European GMP expectations for computerised systems used in regulated manufacturing.
Evidence on every flag
Every extraction, check and recommendation links back to its source page. Nothing asserted is unverifiable.
Human in the loop by design
Agents propose, qualified people approve. Litewave never dispositions a batch on its own.
See it run on one of your own records
Bring something real. We will show you what Litewave finds in it and what it cites as evidence.
