Manav.id
Compliance · 4 min read

The QP certification nobody can verify: batch release across the EU supply chain

The QP certification nobody can verify: batch release across the EU supply chain

There is a person, named in a marketing authorisation, who is personally liable under EU law for each batch released to the European market. Their certification is the last gate before a medicine reaches a patient. It travels as an attachment.

Can a QP certification be verified across a supply chain?

Not by anyone downstream. A Qualified Person accepts personal legal liability for certifying each batch for EU release, and the artefact carrying that certification is a PDF or a register entry inside one company's system. A party receiving the product cannot test it.

Key takeaways
  • QP certification is a personal legal act recorded in a corporate system. Downstream parties inherit it without any means of independent verification.
  • Annex 16 permits reliance on assessments performed by others. A portable receipt must represent that reliance chain rather than obscure it.
  • Offline verification against a published key removes the need for a distributor or authority to contact the marketing authorisation holder.

The person, and what they carry

QP reviews the batchpersonal responsibilitylegalCertification recordedregister entry or PDFinternalProduct moves through the chainmultiple partiesunverifiableQuestion arises years laterwho certified?
The liability is on an individual. The evidence is a row in a company's system.

Meet the role rather than the regulation. A Qualified Person is a named individual, with defined qualifications, whose signature certifies that a batch has been manufactured and checked in accordance with the marketing authorisation and GMP. Under Directive 2001/83/EC they carry that responsibility personally. Not the company. The person.

In a modern supply chain that person may be in Dublin, certifying a batch manufactured in Hyderabad, tested in a contract laboratory in Milan, imported through a site in Amsterdam, and distributed through wholesalers in six countries. Each of those parties relies on the certification. None of them can check it.

What reliance looks like today

A wholesaler receiving product relies on documentation supplied by the seller. The documentation includes a certificate referencing the QP's certification. Verification, in practice, means recognising the letterhead and the relationship.

Where document signing is used, it usually verifies an organisational certificate — that the file came from a company — rather than the QP's personal act. That is a meaningful difference. The regulation places liability on an individual; the artefact attests to a corporation.

Why this matters more since the Falsified Medicines Directive. The FMD built serialisation infrastructure to verify that a pack is what it claims to be. It did not build anything to verify that the release decision behind that pack was made by the person who claims to have made it. The two problems are adjacent and only one has been solved.

The QP Certification Receipt

The design goal is a certification that travels with the product and verifies anywhere, decades later, without contacting anyone.

FieldContent
batchProduct, strength, batch number, manufacturing site
ma_referenceMarketing authorisation number and member state
certification_basisWhich elements the QP assessed personally and which were relied upon
reliance_chainReferences to the underlying confirmations relied on under Annex 16
qpThe QP's personal credential assertion, with their registration reference
issued_atTimestamp, RFC 3339

The third and fourth fields are the interesting ones and they are what makes this an Annex 16 design rather than a naive one.

Representing reliance honestly

Annex 16 explicitly contemplates that a QP may rely on assessments performed by others — on-site quality personnel, other QPs in the chain, contract laboratories — provided the reliance is documented and the QP retains ultimate responsibility.

A receipt that omitted this would misrepresent the act. A QP does not personally re-test every result; they certify on the basis of a documented chain. So the receipt carries the chain: each confirmation it relies on is itself a signed statement, referenced by hash. Verification then answers a richer question than the paper does today — not merely did the QP certify, but on what documented basis.

This is a case where making the artefact verifiable also makes it more honest, which is usually the sign that the design is right.

Who gains, in order

  1. The QP. Personal liability without personally verifiable evidence is an uncomfortable position. A signed receipt is the QP's own record, not their employer's.
  2. Wholesalers and importers. Verification stops being a relationship question.
  3. Competent authorities. Inspection and market surveillance gain an artefact that can be checked without a request to the MAH.
  4. The MAH. Fewer documentation disputes, faster release of held consignments.

The honest constraints

Two, stated plainly. First, a receipt is not a legal instrument recognised by any authority; certification remains governed by Annex 16 and national implementation, and this sits alongside rather than inside that framework. Second, adoption has a network property: a receipt only helps a downstream party who knows to check it, so early value comes from bilateral arrangements rather than from ecosystem effects.

Neither constraint prevents a single MAH from starting with one product family and one distribution channel, which is how every verifiable-document scheme that eventually worked actually began.

Why the QP is an unusual case

What makes this different from ordinary approval
PropertyConsequence
Personal legal liabilityThe individual, not only the company, is answerable
Named on a manufacturing authorisationTheir identity is a regulated fact
Decision is per batchHigh volume, individually consequential
Evidence held internallyNobody downstream can test it

The mismatch between personal liability and institutional evidence is the whole argument. A QP carrying personal responsibility should have an artefact they can produce independently of their employer's systems, including after they leave.

Objections and honest limits

“The register is the legal record.” It is, and it sits in a system the QP does not control and may lose access to. Their liability does not end with their employment.

“Downstream parties rely on the authorisation, not the batch.” For routine purposes, yes. When a batch is questioned, the specific certification becomes the artefact, and at that point its testability matters.

Making a certification portable

  1. Sign as the QP, not as an account. Personal credential, personal liability.
  2. Bind the batch record digest. So the certification covers what was reviewed.
  3. Give the QP a copy. Their liability outlives their employment.
  4. Publish the site key. So a downstream party can verify without contacting you.

Terms used here

Qualified Person
The individual who certifies batches for release in the EU, carrying personal legal responsibility.
Batch certification
The act permitting a batch to be placed on the market, performed per batch.
Manufacturing authorisation
The site licence naming the QPs, which makes their identity a regulated fact.

Frequently asked questions

Does this change the QP's legal responsibility? No. Responsibility is set by Directive 2001/83/EC and national implementation. The receipt changes only what can be demonstrated about the certification afterwards.

How does it handle reliance under Annex 16? By representing it explicitly: the receipt references the signed confirmations relied upon rather than implying the QP assessed everything personally.

Will it still verify in fifteen years? That is a design requirement, not an afterthought. Issuer keys are published with validity periods and retained historically, so a receipt verifies against the key that was valid at issuance.

Is this an alternative to serialisation? No. Serialisation verifies the pack; this verifies the release decision. They address different questions and are complementary.

Why should a QP hold their own copy? Because the liability is personal and outlives their employment, while the record sits in an employer's system they may lose access to.

Can downstream parties verify a certification today? No. It is an internal register entry or PDF, testable only by asking the manufacturer.

What should the signature bind? The batch record digest, so the certification demonstrably covers what the QP reviewed.

Where this fits in Manav

Manav binds the signer to the exact record being certified, on a credential under their sole control, and produces a receipt an inspector can verify years later without access to the manufacturing system.

See signature binding →

Sources and further reading