Supplier qualification file
The file you keep on each supplier, kept living.
A state-board inspector grades the file you keep on each supplier as a living system, not a one-time onboarding folder. Veritura builds it as six structured elements, keeps each dated document current, and gates every order against it.
The six elements
Six structured elements, and what each one takes to satisfy.
The file is not a folder of attachments. Each element holds a named thing, has a stated way to be satisfied, and carries its own date.
Element 1
Manufacturer identity
Grey-market sellers borrow real manufacturers' names. Legal name, address, FDA registration and FEI number, confirmed against the openFDA registration snapshot when one is available, marked on file when it is not.
- What satisfies it
- The supplier's legal name and address, its FDA registration number and its FEI number. In the workspace the supplier name you run the qualification under seeds this element.
- The date it carries
- No expiry of its own. The name is resolved against a dated registration snapshot, and a name that does not resolve is surfaced for review rather than recorded as absent.
Element 2
Accreditation
Certificates lapse quietly, and lapsed is how an inspector finds them. NABP, VAWD, or equivalent held with its effective and expiry dates, so a lapsed certificate surfaces on the file before an order goes out against it.
- What satisfies it
- The accrediting body named, plus the certificate itself. Attach the document and the dates the document states are read off the page, which outrank a date typed in by hand.
- The date it carries
- An effective date and an expiry date. The element reads renewal due as the expiry approaches and expired once it has passed.
Element 3
FDA registration status
A firm's FDA record can change without anyone telling its buyers. Registration and listing checked against live openFDA enforcement and recall feeds, with any hit on the firm surfaced directly on the file.
- What satisfies it
- Public FDA source records, not a document the supplier hands you. This element is read from the source, so nobody has to attest to it.
- The date it carries
- No renewal date, because the check never stops. A firm clean at onboarding can pick up an enforcement record months later, and the hit lands on the file it belongs to.
Element 4
Quality agreement
Signed agreements get filed once and forgotten until the renewal has lapsed. The signed quality agreement and its renewal date are held on the file and tracked the same way as every other dated document you rely on.
- What satisfies it
- The executed agreement. Attach it and the renewal date the document itself states is read from the page.
- The date it carries
- A renewal date, on the same clock as accreditation: renewal due before it, expired after it.
Element 5
Documentation specifications
Every supplier says their COAs meet your spec; few packets get checked against it. Your required COA panels and document standards for the supplier, evaluated against what each packet actually contains, not assumed.
- What satisfies it
- The packets themselves. The COA read is this element: the panels you require are compared with the panels the document actually carries.
- The date it carries
- No date of its own. It is re-evaluated on every packet the supplier sends, so the element moves when their documentation moves.
Element 6
Ongoing review
A one-time onboarding stamp is stale the day after it's issued. A review cadence with a next-review date, so the file carries a living current, due, or overdue status instead of a stamp.
- What satisfies it
- The cadence you set, and a dated periodic review composed from what the file already holds: the element rollup, the firm-matched FDA enforcement records, and the lot history.
- The date it carries
- A next-review date. This is the element that makes the file living rather than an onboarding folder, and it is the one an inspector reads first.
The file publishes how many of the six elements are documented. Documented status per element, never an approval.
Dates and gaps
A date that has passed is the most useful thing on the file.
Every dated document on the file carries a living status. The gap is shown as a gap, and the element that has nothing on it says so instead of leaving the row blank.
The file's review status
Set on the ongoing-review element, and the one status a whole file carries. It is computed from the next-review date, never stamped by hand.
Current
The file is inside its review window.
Review due
The next review is up.
Review overdue
The next-review date has passed, and the file says so rather than going quiet.
No cadence set
No review cadence has been set yet, so the file does not claim to be current.
Each element's own label
One honest label per element, computed from what is on file and where it came from. Never a confusing double-label.
- On file
- The document is held on the file as the operator supplied it, and it is recorded that way.
- FDA-source matched
- The element resolved against an FDA source record rather than against a document the supplier sent.
- Confirmed at source
- The source itself confirmed it. Nothing weaker earns this label.
- Partial
- Some of what the element needs is present and some of it is not.
- Renewal due
- The dated document is approaching the date the document itself states.
- Expired
- The dated document is past the date the document itself states.
- Not provided
- Nothing has been supplied for this element. The file shows the gap instead of an empty row.
These labels describe documentation currency on one element. They are not an evidence posture, not a ClearGate decision, and not a receiving disposition, and none of them says anything about a product.
| Element | The dated item | What the file shows |
|---|---|---|
| Manufacturer identity | No expiry. Resolved against a dated registration snapshot. | Matched against the FDA source record, or held on file as supplied when no snapshot match is available. A name that does not resolve is surfaced for review. |
| Accreditation | Effective and expiry dates, read off the certificate when it is attached. | Renewal due before the expiry, expired after it, so a lapsed certificate surfaces before an order goes out against it. |
| FDA registration status | No renewal date. Checked against live enforcement and recall feeds. | Any hit on the firm is surfaced directly on the file, with the firm-matched records behind it. |
| Quality agreement | The renewal date on the signed agreement. | Tracked the same way as every other dated document you rely on: renewal due, then expired. |
| Documentation specifications | No date of its own. Re-evaluated against each packet. | Your required panels and document standards compared with what the packet actually contains, not assumed. |
| Ongoing review | The next-review date set by your cadence. | A living current, due, overdue status, recomputed as that date approaches and passes. |
The periodic review itself is one action. It composes the dated supplier review from what is already on the file, the element rollup, the firm-matched FDA enforcement records, and the lot history, signs it, and resets the cadence clock. Nothing is re-typed, so nothing is re-typed wrong.
Supplier qualification
Suppliers
| Supplier | Status | Qualification | Documentation score | Last check | File posture |
|---|---|---|---|---|---|
| Aurora Pharma SupplyDistributor | Active | 5 of 6 elements | 92 / 100 | Jul 24, 2026 | Evidence posture: Clear Ongoing review due Jul 30 |
| Meridian Compounding SourceDistributor | Active | 6 of 6 elements | 96 / 100 | Jul 23, 2026 | Evidence posture: Clear No open request |
| Keystone Peptide LabsLaboratory | Active | 4 of 6 elements | 74 / 100 | Jul 22, 2026 | Evidence posture: Review Sterility scope gap |
| BlueRiver API CoManufacturer | Under review | 3 of 6 elements | 58 / 100 | Jul 21, 2026 | Evidence posture: Hold Corrected source route requested |
The score grades the documentation evidence on file only. It is not an approval, a ranking, a certification, or a statement about any product.
ClearGate decision
One decision per order, against the policy you set.
ClearGate reads the file and your configured policy and returns one decision when an order is placed. You set the bar; we keep the record.
- ClearGate: Allow
Meets your policy
- ClearGate: Review
Needs review
- ClearGate: Hold
Does not meet policy
A ClearGate decision always means the documentation meets your policy. It never means Veritura approves the supplier.
The file is one of four rails an order screen fires.
Screening an order runs them together, and each rail reports its own result with the reason on the record.
Supplier ClearGate
The supplier's documentation measured against the policy you configured.
Substance eligibility
Whether the substance is eligible to compound for a facility type, against the current FDA lists.
Prescriber registry
The prescriber resolved against NPPES, live.
Six-element supplier qualification file
Your supplier record: the six elements and their dates, as they stand at the moment of the order.
Configurable presets and bounded custom rules, a tamper-evident signed decision log, and one endpoint.
- POST/v1/cleargate
- One call at order time returns one decision against your configured policy, with a tamper-evident signed record behind it.
Presets are Strict, Standard, or Lenient. A custom policy with per-rule toggles, thresholds, and operator-attested items is part of the Facility plan.
How the file gets built
Two ways in, and they are labeled differently for a reason.
A qualification you run yourself is automated end to end. A delivered diligence memo gets a reviewer's pass on the final language. The record always says which one it is.
Run a qualification in the workspace
The supplier name seeds the file
Name the supplier and, if you want to scope it, the API or product. The name seeds the manufacturer-identity element and the FDA lanes start from there.
Attach the packet
A COA, an SDS, a certificate of conformance, whatever you hold. The engine reads it and the elements fill from what the documents actually say.
Attach a document to a specific element
Attach the accreditation certificate or the quality agreement to its own element, and the dates the document states are read and used. A document's own dates outrank a typed one.
It re-checks itself
The file is re-verified against live FDA enforcement and recall records on every sweep, so a signal that lands after onboarding reaches the file it belongs to.
The reviewed diligence memo
Automated extraction is used for speed. Human review is used before the final memo so pharmacy-facing deliverables do not rely on unreviewed automation.
01
Packet intake
Supplier quote, COA, spec sheet, manufacturer statement, email text, and links are collected with source labels.
02
AI-assisted screen
Fields are drafted for API identity, supplier name, lot, lab, method, dates, purity value, file metadata, and verification links.
03
Archive comparison
Hashes, visual fingerprints, lots, lab and purity patterns, and supplier names are compared against the existing evidence index where coverage exists.
04
Human memo pass
An analyst checks the automated record for phrasing, source support, ambiguous fields, and could-not-verify limits before delivery.
05
Escalation list
The final memo separates observed facts, missing documentation, supplier follow-up questions, and limits that require lab or regulatory diligence.
The three questions a packet has to answer.
| The question | What is checked | Output |
|---|---|---|
| Can the COA be tied to this supplier and lot? | Whether API, lot, method, dates, lab name, supplier identity, and source text reconcile across the packet. | A source-backed reconciliation table. |
| What documentation is missing before escalation? | Observed evidence separated from gaps: manufacturer evidence, direct lab confirmation, method detail, quote and COA mismatch, and file-quality limits. | A missing-source and escalation list. |
| Has this document or signal appeared before? | Hashes, visible fields, verification links, and supplier records compared against the Veritura archive where coverage exists. | Archive and duplicate-signal notes. |
What lands in the internal file.
Source matrix, evidence IDs
Each source is labeled so findings can be traced back to reviewed material.
Reconciliation, fields and conflicts
API, lot, lab, method, purity, dates, supplier identity, and manufacturer evidence are compared.
Escalation, ask-next questions
Questions your team can send to the supplier or preserve internally before the next diligence step.
Veritura gives you a preserved record of what was reviewed and what should be asked next. It does not approve suppliers or products.
Where a stale file leaves you
Six gaps a folder leaves open and a living file closes.
These are the places a customer, an auditor, or an attorney can push, and the reason the file has to keep moving after onboarding.
Inconsistent COA coverage
Lots arriving without a lot-specific COA leave holes an auditor or customer can find.
What the file does
Every order missing a lot-matched COA is flagged before it ships, against the documentation specifications you set on the file.
No independent authenticity check
A filed COA isn't a verified one. Filing a document and checking it are different acts, and only one of them survives scrutiny.
What the file does
The issuing lab is resolved against a verify-portal registry with a ready-to-send confirmation email, and only a recorded lab reply flips a document to source-confirmed.
Weak order-to-lot traceability
If you can't tie a sale to its exact lot and COA on demand, every order is a question you can't answer fast.
What the file does
An Evidence Passport ties each order to its lot, COA, supplier packet, and reviewer, and the supplier's qualification snapshot rides with it.
Reused-COA blind spot
Suppliers sometimes reuse or lightly edit one COA across multiple lots; without a cross-lot check it goes unnoticed.
What the file does
Reuse and duplicate-document signals run on every review, and a supplier's new document is compared against the structure of their own prior documents.
Slow audit readiness
Scrambling to assemble proof under a deadline is exactly when gaps surface.
What the file does
One click builds an inspector-ready index of every saved check, supplier, lot, COA reference, the diligence performed, and each supplier qualification file current as of the pull.
No ongoing supplier monitoring
A supplier clean at onboarding can pick up a recall or enforcement action months later.
What the file does
Saved suppliers and lots are watched against FDA enforcement and recall feeds, with alerts when a new strong source or lot match needs review.
Limitation
This is a self-assessment of documentation exposure, not legal, regulatory, or safety advice, and not a determination about any specific supplier or product. Veritura performs independent document diligence only: we check that supplier documentation is complete, consistent, and free of reuse or tamper signals. We do not certify product quality, confirm safety, approve suppliers, or claim FDA approval.
Honest by construction
The file never overstates what was checked.
Every element carries where its evidence came from, so an inspector sees what was actually verified and when it was last checked.
Veritura evaluated
Read from the document or from a public source. The engine saw it itself.
Operator attested
You confirm what we cannot read. The element records that it was attested, not evaluated.
Every element is labeled Veritura evaluated, read from the document or a public source, or Operator attested, where you confirm what we cannot read.
What the file is for.
- Use before deciding whether a packet deserves physical sample testing.
- Use before wiring money or escalating a supplier packet internally.
- Use to preserve a document record and better supplier questions.
- Do not use as supplier approval, product certification, legal advice, or wet-lab testing.
Boundary
Veritura does not test medicine, approve suppliers, recommend purchases, or make medical, legal, product-safety, or FDA-approval determinations. There is no paid or subjective placement: suppliers cannot pay for a better result or a better position, no listing fee, no subscription, and no pay-to-rank. Where results are ordered rather than filtered, the order is set by a published documentation-coverage grade, and that grade is never a recommendation, a preference, or a statement about any product.
Boundary
Veritura verifies the completeness and consistency of documentation and sourcing, not product quality, safety, efficacy, legality, or FDA approval. A "Verified by Veritura" profile or check means the submitted paperwork was read for documentation completeness, consistency, and evidence status; it is not a certification, an approval, or a representation that any product is safe.
Boundary
AI may assist extraction and drafting. Delivered written diligence memos receive human QA. Self-serve checks, ClearGate decisions, and Passports are automated unless the record explicitly says otherwise, and no human sign-off is claimed on them.
Limitation
Not product testing. Reports are based on submitted documents, public pages, metadata, and snapshots. Veritura does not test physical material.
Limitation
Authenticity limits. A report may identify metadata, repeated file signals, links, and inconsistencies. It cannot prove document provenance unless an issuing lab or source independently confirms it.
Open a file on the supplier you buy from most.
Create your dashboard and run a qualification, or talk to us about your supplier base.
Six-element supplier qualification files, kept living, are part of the Clinic plan at $99 per month.