Skip to content

COA validation

What is a COA validator? What it checks and its limits

A plain explanation of COA validator software: what it reads on a supplier's certificate of analysis, what it cannot tell you, where it sits between supplier qualification and the identity test, and the questions to ask before trusting one.

Short answer

A COA validator is software that reads a supplier's certificate of analysis and checks it as a document: whether it belongs to one batch, whether every expected test, limit and result is present, whether results sit within the limits, and whether dates and signatures agree. It supports a reviewer's decision; it does not test the material.

The definition, and what the name gets wrong

COA stands for certificate of analysis: the document a manufacturer or supplier issues for one batch of material, listing the tests performed, the acceptance limit for each test and the result obtained. A COA validator is software that takes that document, reads what it states, and compares it against what a certificate of that kind is expected to carry and against the standard the certificate itself claims to meet.

The name is slightly misleading. A validator does not make a batch valid, and it does not decide whether the material may be used. What it produces is a list of findings about the document: what is present, what is missing, and what does not add up. The decision to accept or reject the batch stays with the qualified person responsible for it.

What a COA validator checks

The checks follow the elements that ICH Q7 section 11.4 expects on a certificate for an active pharmaceutical ingredient, plus the internal logic any honest document should have. Grouped by the question each one answers:

  • Is this the right document? The material name, grade and batch number are present and consistent wherever they appear, and the certificate refers to one batch (ICH Q7 11.40 to 11.41).
  • Is every expected test there? The test list is complete against the standard the certificate claims, whether a pharmacopoeial monograph or an agreed specification (ICH Q7 11.42).
  • Are the limits the right limits? Each test has a printed acceptance limit, and that limit is not looser than the claimed standard's.
  • Do the results mean anything? Quantitative tests carry a number with a unit rather than the word "complies" (ICH Q7 11.42), and each result sits within its printed limit.
  • Are the dates present and possible? A release date, and an expiry date or a retest date (a retest date may appear on the label instead) (ICH Q7 11.41), consistent with each other.
  • Is someone accountable for it? A dated signature from the issuer's quality unit and the original manufacturer's name, address and telephone number; for a certificate re-issued by a repacker, agent or broker, the testing laboratory's name, address and telephone number, the original manufacturer, and the original certificate attached (ICH Q7 11.43 to 11.44).
  • Does the document agree with itself? Individual impurities against their stated total, values repeated in two places, units that change between rows.

What it cannot tell you

Every one of those checks is about the paper. None of them is about the material in the drum. A certificate can be complete, consistent and signed and still describe a batch other than the one delivered, or results that no laboratory produced. A COA validator cannot establish on its own that a certificate is genuine; it can show that a document lacks what a genuine certificate should carry, or contradicts itself, and those are reasons to ask the supplier precise questions.

It also does not replace the testing that stays with the manufacturer that uses the material. In the United States, 21 CFR 211.84(d)(1) requires at least one identity test on each component, and 211.84(d)(2) allows a supplier's report of analysis to stand in for the other tests only when the manufacturer establishes the reliability of the supplier's results at appropriate intervals. EU GMP Chapter 5 sections 5.35 and 5.36 set out the same principle for manufacturers of finished products, and ICH Q7 sections 7.30 and 7.31 for API manufacturers (with the exceptions in 7.32). A validator's report can be part of the evidence behind that reliance. It is not the reliance.

Where it sits when goods arrive

A document check is one step in a sequence, and it is most useful when everyone knows which step it is. The table shows a typical order for incoming active ingredients and excipients.

StepWho does itThe question it answers
Supplier qualificationQuality assurance, before purchaseIs this supplier's certificate worth relying on at all?
Document checkA reviewer, with or without a COA validatorDoes this certificate say what it should, for this batch, without contradicting itself?
Identity testThe manufacturer using the material, or its contract laboratoryIs the material what the label and certificate say it is?
Further testingAs the reliance status requiresDo the results the certificate reports hold up?
Acceptance or releaseThe quality unit of the company using the materialMay this batch be used?

Manual review or software

The logic is the same whether a person or software does the reading. Our step-by-step guide to checking a certificate of analysis sets out that logic in full, and a careful reviewer with the governing standard beside them can work through it by hand.

Software changes three things. It applies the same checks in the same order to every certificate, including the last one on a busy day. It writes every finding down, with the evidence, so the reasoning behind an acceptance can be read later. And it frees the reviewer's attention for the findings that need judgement, such as a supplier's explanation for a changed limit. What it cannot bring is context: knowledge of this supplier's history, of the intended use of the material, or of a telephone call last week.

How to judge a COA validator

A tool that reads regulated documents should be held to the same standard as the documents. Before trusting one, ask:

  • Does each finding name the requirement, the evidence on the page and the source of the requirement, so a reviewer can check it without re-reading the whole certificate?
  • Does it say plainly what it could not read, such as a blurred scan or a missing page, rather than passing over it?
  • Does it separate an element that is missing from a result that is out of limit? They call for different responses.
  • Does it claim to decide acceptance, or to establish that a certificate is genuine? A tool that makes either claim is promising more than a document check can deliver.
  • Can a qualified person review its output before a decision is made?
  • What happens to the certificates you upload? They carry your supplier's batch data and are often confidential.

Definitions

COA validator
Software that reads a certificate of analysis and reports, as findings, whether the document carries the expected elements, whether its results sit within its limits and whether it is internally consistent. It supports a reviewer's decision and does not test the material.
Certificate of analysis (COA, CoA)
A document issued for a batch of material listing the tests performed, the acceptance limits and the results, authorised by the issuer's quality unit.
Identity test
A test that establishes the material is what it is claimed to be. Under 21 CFR 211.84(d), a drug product manufacturer performs at least one on each component, whatever the certificate says.

Sources

  1. ICH Q7, Good Manufacturing Practice Guide for Active Pharmaceutical Ingredients (Step 4, 10 November 2000), International Council for Harmonisation (sections 7.30 to 7.32 and 11.40 to 11.44)
  2. 21 CFR 211.84, Testing and approval or rejection of components, drug product containers, and closures, U.S. Code of Federal Regulations (eCFR) (paragraphs (d)(1) and (d)(2))
  3. EudraLex Volume 4, EU Guidelines for GMP, Part I, Chapter 5: Production (revision in operation from 1 March 2015), European Commission (sections 5.35 and 5.36)

Primary sources are cited in preference to summaries. Where a source is licensed (for example a pharmacopoeial monograph) the reference is given and the text is not reproduced.

About the author

PharmaTrust Team

Written and reviewed by the PharmaTrust team against the primary sources cited above. Corrections are published, never made quietly.

Why we built this

Spotted an error or a newer figure? We correct within a week: info@pharmatrust.tech.

Frequently asked

Is a COA validator the same as software that creates certificates?

No. Laboratory systems that generate certificates are used by the issuer, to turn its own test data into a document. A COA validator is used by the recipient, to read a certificate someone else issued and check what it states.

Can a COA validator tell whether a certificate is fake?

Not on its own. It can show that a document contradicts itself, names no testing laboratory, or lacks what a genuine certificate should carry, which are good reasons to question the supplier. Whether a laboratory actually did the work is a matter for supplier audits and, where doubt is high, your own testing.

Does using a COA validator reduce the testing I must do?

No. For a manufacturer using the material, at least one identity test on each batch stays in-house under 21 CFR 211.84(d), EU GMP 5.35 and ICH Q7 7.30. Reduced testing beyond identity depends on a documented evaluation of the supplier and periodic comparison of full analyses against its certificates, not on the tool used to read them.

Who uses a COA validator?

Importers and distributors checking certificates before goods are accepted, quality control teams at manufacturers receiving active ingredients and excipients, and procurement bodies comparing certificates submitted by several suppliers.