The QP certification nobody can verify: batch release across the EU supply chain
There is a person, named in a marketing authorisation, who is personally liable under EU law for each batch released to the European market. Their certification is the last gate before a medicine reaches a patient. It travels as an attachment.
Can a QP certification be verified across a supply chain?
Not by anyone downstream. A Qualified Person accepts personal legal liability for certifying each batch for EU release, and the artefact carrying that certification is a PDF or a register entry inside one company's system. A party receiving the product cannot test it.
- QP certification is a personal legal act recorded in a corporate system. Downstream parties inherit it without any means of independent verification.
- Annex 16 permits reliance on assessments performed by others. A portable receipt must represent that reliance chain rather than obscure it.
- Offline verification against a published key removes the need for a distributor or authority to contact the marketing authorisation holder.
Part of Pharma and GxP identity
The person, and what they carry
Meet the role rather than the regulation. A Qualified Person is a named individual, with defined qualifications, whose signature certifies that a batch has been manufactured and checked in accordance with the marketing authorisation and GMP. Under Directive 2001/83/EC they carry that responsibility personally. Not the company. The person.
In a modern supply chain that person may be in Dublin, certifying a batch manufactured in Hyderabad, tested in a contract laboratory in Milan, imported through a site in Amsterdam, and distributed through wholesalers in six countries. Each of those parties relies on the certification. None of them can check it.
What reliance looks like today
A wholesaler receiving product relies on documentation supplied by the seller. The documentation includes a certificate referencing the QP's certification. Verification, in practice, means recognising the letterhead and the relationship.
Where document signing is used, it usually verifies an organisational certificate — that the file came from a company — rather than the QP's personal act. That is a meaningful difference. The regulation places liability on an individual; the artefact attests to a corporation.
The QP Certification Receipt
The design goal is a certification that travels with the product and verifies anywhere, decades later, without contacting anyone.
| Field | Content |
|---|---|
batch | Product, strength, batch number, manufacturing site |
ma_reference | Marketing authorisation number and member state |
certification_basis | Which elements the QP assessed personally and which were relied upon |
reliance_chain | References to the underlying confirmations relied on under Annex 16 |
qp | The QP's personal credential assertion, with their registration reference |
issued_at | Timestamp, RFC 3339 |
The third and fourth fields are the interesting ones and they are what makes this an Annex 16 design rather than a naive one.
Representing reliance honestly
Annex 16 explicitly contemplates that a QP may rely on assessments performed by others — on-site quality personnel, other QPs in the chain, contract laboratories — provided the reliance is documented and the QP retains ultimate responsibility.
A receipt that omitted this would misrepresent the act. A QP does not personally re-test every result; they certify on the basis of a documented chain. So the receipt carries the chain: each confirmation it relies on is itself a signed statement, referenced by hash. Verification then answers a richer question than the paper does today — not merely did the QP certify, but on what documented basis.
This is a case where making the artefact verifiable also makes it more honest, which is usually the sign that the design is right.
Who gains, in order
- The QP. Personal liability without personally verifiable evidence is an uncomfortable position. A signed receipt is the QP's own record, not their employer's.
- Wholesalers and importers. Verification stops being a relationship question.
- Competent authorities. Inspection and market surveillance gain an artefact that can be checked without a request to the MAH.
- The MAH. Fewer documentation disputes, faster release of held consignments.
The honest constraints
Two, stated plainly. First, a receipt is not a legal instrument recognised by any authority; certification remains governed by Annex 16 and national implementation, and this sits alongside rather than inside that framework. Second, adoption has a network property: a receipt only helps a downstream party who knows to check it, so early value comes from bilateral arrangements rather than from ecosystem effects.
Neither constraint prevents a single MAH from starting with one product family and one distribution channel, which is how every verifiable-document scheme that eventually worked actually began.
Why the QP is an unusual case
| Property | Consequence |
|---|---|
| Personal legal liability | The individual, not only the company, is answerable |
| Named on a manufacturing authorisation | Their identity is a regulated fact |
| Decision is per batch | High volume, individually consequential |
| Evidence held internally | Nobody downstream can test it |
The mismatch between personal liability and institutional evidence is the whole argument. A QP carrying personal responsibility should have an artefact they can produce independently of their employer's systems, including after they leave.
Objections and honest limits
“The register is the legal record.” It is, and it sits in a system the QP does not control and may lose access to. Their liability does not end with their employment.
“Downstream parties rely on the authorisation, not the batch.” For routine purposes, yes. When a batch is questioned, the specific certification becomes the artefact, and at that point its testability matters.
Making a certification portable
- Sign as the QP, not as an account. Personal credential, personal liability.
- Bind the batch record digest. So the certification covers what was reviewed.
- Give the QP a copy. Their liability outlives their employment.
- Publish the site key. So a downstream party can verify without contacting you.
Terms used here
- Qualified Person
- The individual who certifies batches for release in the EU, carrying personal legal responsibility.
- Batch certification
- The act permitting a batch to be placed on the market, performed per batch.
- Manufacturing authorisation
- The site licence naming the QPs, which makes their identity a regulated fact.
Frequently asked questions
Does this change the QP's legal responsibility? No. Responsibility is set by Directive 2001/83/EC and national implementation. The receipt changes only what can be demonstrated about the certification afterwards.
How does it handle reliance under Annex 16? By representing it explicitly: the receipt references the signed confirmations relied upon rather than implying the QP assessed everything personally.
Will it still verify in fifteen years? That is a design requirement, not an afterthought. Issuer keys are published with validity periods and retained historically, so a receipt verifies against the key that was valid at issuance.
Is this an alternative to serialisation? No. Serialisation verifies the pack; this verifies the release decision. They address different questions and are complementary.
Why should a QP hold their own copy? Because the liability is personal and outlives their employment, while the record sits in an employer's system they may lose access to.
Can downstream parties verify a certification today? No. It is an internal register entry or PDF, testable only by asking the manufacturer.
What should the signature bind? The batch record digest, so the certification demonstrably covers what the QP reviewed.
Where this fits in Manav
Manav binds the signer to the exact record being certified, on a credential under their sole control, and produces a receipt an inspector can verify years later without access to the manufacturing system.
Sources and further reading
- EudraLex Volume 4 — EU GMP guidelines
- Directive 2011/62/EU — Falsified Medicines Directive.
- 21 CFR Part 11 — electronic records and signatures