Certificate of Analysis: Why the Document Proves Less Than You Think

Kognitos
A row of wireframe sample bottles sharing one dashed reference line, with the single solid lime bottle measured against its own lower fill level

TL;DR

A certificate of analysis is a batch-specific document reporting the test results for a material against its specification, issued by the supplier’s own quality control laboratory. It is evidence about the supplier’s testing rather than independent evidence about the material in front of you. Regulators treat it accordingly: a CoA is an input to verification, not a substitute for it, and relying on one without qualification is a recurring inspection finding.

Key Takeaways: A CoA reports actual numerical results for a specific batch, unlike a certificate of conformance which simply attests compliance. Reduced incoming testing based on a CoA is permitted only with documented supplier qualification, a recorded rationale, identity testing on every lot, and periodic full verification. Qualification means confirming the supplier’s numbers yourself first. The most common deficiency is treating supplier documentation as a replacement for verification.

What is a certificate of analysis?

A certificate of analysis, usually shortened to CoA, is a batch-specific document confirming that a material meets its predefined quality specifications, based on analytical testing. It is issued by a quality control laboratory, normally the manufacturer’s own or a contracted independent lab, after the required tests have been completed on samples from that specific batch.

It functions as the material’s quality passport. When an organization receives raw materials, active ingredients, excipients, packaging, or components, the CoA is the document stating what was tested, what the acceptance criteria were, and what the results actually came out as. Quality assurance, quality control, manufacturing, and regulatory teams all rely on it when deciding whether a batch can be released for use.

A properly constructed CoA contains material and product identification, batch or lot details, the specification for each attribute tested, the actual numerical results rather than a bare pass or fail, the test methods used, and the signature of an authorized reviewer.

Certificate of analysis versus certificate of conformance

These two get bundled together and are not equivalent.

A certificate of analysis reports actual test data: the measured values for each attribute against the specification.

A certificate of conformance, or CoC, is a shorter attestation that a lot meets its specification, without necessarily including the underlying results.

The difference matters when something goes wrong. A CoA lets you see how close to a limit a result sat, whether a trend is developing across lots, and whether the reported figures are plausible. A CoC tells you only that someone asserted conformity. Accepting a CoC where a CoA was expected is a common gap in supplier files.

What a CoA actually proves

Here is the point that reframes the rest of this article, and it is uncomfortable enough that most CoA guidance skips past it.

The certificate is a statement by the party that sold you the material.

That does not make it dishonest or worthless. Most CoAs are accurate and most suppliers are diligent. But it does mean the document is evidence about the supplier’s testing, not independent evidence about the material now sitting in your warehouse. The distinction is invisible when everything is normal and decisive when it is not.

Regulators treat it exactly this way. Under FDA current good manufacturing practice for finished pharmaceuticals, a manufacturer cannot simply file an incoming CoA and release the component on that basis. The receiving firm is expected to perform at least one confirmatory identity test on every lot, regardless of supplier history. Reduced testing for other attributes is permitted, but only where the firm has established and periodically re-validates the reliability of that supplier’s testing through a documented qualification program.

The dietary supplement rules make the logic even more explicit. Qualification means establishing the reliability of the supplier’s certificate by confirming the results of the supplier’s own tests. In plain terms: you test the material yourself first, and confirm the supplier’s numbers hold up, before you are entitled to rely on their paperwork for anything beyond identity.

So the regulatory position is not that CoAs are untrustworthy. It is that trust must be earned through verification and re-verified over time, and the document alone never carries that weight.

What relying on a CoA properly requires

Reduced testing based on supplier CoAs is a legitimate, widely used, and regulator-sanctioned approach. It is also conditional, and the conditions are where organizations get caught.

Documented supplier qualification. Evidence that you have confirmed this supplier’s testing reliability, not merely that you have bought from them for years.

A recorded rationale. Why reduced testing is appropriate for this material, calibrated to its risk and criticality.

Identity testing on every lot. Not risk-based, not sampled. Every lot.

Periodic full verification. Complete testing at defined intervals to confirm the supplier’s results still hold.

Ongoing monitoring. Trending of CoA results across lots, so drift or suspiciously invariant data is visible.

The failure pattern is consistent in inspection findings: organizations that implement the reduced testing without the qualification program, rationale, and periodic verification that justify it. The paperwork looks like compliance from the inside, and does not survive an inspector asking to see the qualification file.

Practical checks that catch problems

Beyond the formal program, several checks separate a defensible supplier file from a folder of PDFs.

Authenticity. Maintain a reference file of each key supplier’s typical CoA format, signature style, layout, and contact details. Train incoming QA to flag any deviation from the known format immediately. This simple visual comparison is what catches altered or fabricated certificates, which otherwise pass because they look approximately right.

Lot matching. Confirm the lot or batch number on the certificate matches the material physically received, not just that a certificate accompanied the delivery. Mismatches are common and are often clerical rather than sinister, but a certificate for a different lot is evidence of nothing.

Specification basis. Check the certificate reports against your specification, not merely against the supplier’s. A result within the supplier’s limits can sit outside yours.

Result plausibility and trend. Look across lots. Results that never vary, or that cluster implausibly close to a limit, are worth investigating.

Container and label inspection. Physical verification of the container against the certificate on every receipt, regardless of what the testing decision is.

Where automation fits

Notice what all of those checks have in common. Every one is reading a document and comparing it against something else: a specification, a purchase order, a physical delivery, a reference format, or the history of previous lots from the same supplier.

None of it is analytical chemistry. It is document work, performed at whatever volume the receiving dock generates, and its cost is broadly constant per certificate regardless of how critical the material is. That economics explains the observed behavior. Critical materials receive careful review. The long tail of routine receipts gets a glance, a filing, and a release, because checking each one properly against specification, purchase order, and supplier history is more effort than the individual receipt appears to justify.

Automation that can read documents and reason about their contents can apply the full check to every certificate rather than a sample: extracting the reported results, comparing them against your specification rather than the supplier’s, confirming lot numbers match the receipt and the purchase order, flagging deviations from that supplier’s established format, and trending results across lots to surface drift or implausible consistency.

Because these checks feed material release decisions and form part of the inspection record, each determination needs to be traceable and readable rather than asserted.

To be clear about scope, Kognitos is not a LIMS, a testing laboratory, or a quality management system. It does not perform analysis, hold your specifications as the system of record, or replace the qualification program, and it certainly does not remove the requirement for identity testing. What it addresses is the document comparison work sitting around those activities, operating alongside your QMS and ERP and producing a record of what was checked and why.

For related material, see our guides on quality management systems, 21 CFR Part 11, supplier statement reconciliation, vendor onboarding automation, and AI in pharma. To see how deterministic AI checks supplier documentation with a full audit trail, book a demo or try the platform.

Getting started

Two checks worth running.

Pull your reduced testing program and confirm that for each material on it you can produce the supplier qualification file, the documented rationale, and evidence of the most recent periodic verification. If any of those three is missing, the program is operating without the justification the regulations require, and that gap is what inspectors look for.

Then sample twenty recent certificates and check each one against the purchase order and your own specification rather than the supplier’s. The proportion that would have been accepted despite a mismatch tells you how much of your current assurance rests on the document looking right rather than being right.

Frequently Asked Questions

A certificate of analysis is a batch-specific document confirming that a material meets predefined quality specifications based on analytical testing, issued by a quality control laboratory after testing samples from that batch. It includes material identification, batch details, the specification for each attribute, the actual numerical results, the test methods used, and an authorized signature.
A certificate of analysis reports actual test data, giving measured values for each attribute against specification. A certificate of conformance is a shorter attestation that a lot meets its specification without necessarily including the underlying results. The difference matters because a CoA lets you see how close results sat to limits and whether trends are developing across lots, while a CoC only records an assertion.
Partially and conditionally. Regulations permit reduced incoming testing based on supplier CoAs, but require documented supplier qualification, a recorded rationale, identity testing on every lot regardless of supplier history, and periodic full verification testing. Qualification specifically means confirming the supplier’s own results yourself before relying on their certificates for other attributes.
Because the certificate is a statement by the party that sold you the material, making it evidence about the supplier’s testing rather than independent evidence about the material received. Relying on supplier CoAs without independent verification is a recurring finding in FDA inspections, and warning letters commonly trace the root cause to teams treating supplier documentation as a substitute for verification testing.
Confirm the lot or batch number matches the material physically received, that results are reported against your specification rather than only the supplier’s, and that the format matches that supplier’s established template, since deviations catch altered or fabricated certificates. Also trend results across lots to surface drift or implausibly invariant data, and inspect the container and label against the certificate on receipt.
A CoA is issued by a quality control laboratory, typically the manufacturer’s own laboratory or an independent testing agency contracted by them, after performing the required tests on samples from the specific batch. It must be signed by an authorized reviewer. Because the issuing party is usually the supplier, the certificate is an input to your verification rather than independent confirmation.

The next era of financial automation is already in production.

Kognitos turns your biggest bottlenecks into automations, live in hours, not months.